BlueFlash
teach preview

(2) Determining the Average Probability per Flight Hour of each Failure… — Page 41, Lesson 59

(2) Determining the Average Probability per Flight Hour of each Failure… — Page 41, Lesson 59BlueFlash
Let’s pick this up right where the regulatory logic gets concrete. We’re inside CS 25.1309, the certification rule that governs the safety of aeroplane systems, and I want to walk you through the two structured methods you’d actually use to prove compliance, then the specific means of compliance the rule lays out. First, the two methods for determining the average probability per flight hour of each failure condition. The first is Fault Tree Analysis. That’s a top-down, deductive method. You start with the failure condition you’re worried about — the top event — and you work backwards, breaking it down through logic gates like AND and OR into the basic component failures that could cause it. It’s excellent for showing how combinations of failures combine to produce a single unwanted outcome. The second is Markov Analysis. This is a state-based method. You model the system as a set of discrete states — fully operational, degraded, failed — and you define transition rates between those states. Then you solve for the long-run probability of being in each state, which gives you the average probability per flight hour of the failure condition. It handles systems with complex dependencies and repair or reconfiguration logic very well. The third is Dependency Diagrams, sometimes called block diagrams. Here you draw the system as a series of blocks representing components, connected in series or parallel, and you compute the overall reliability from the reliability of each block. It’s a simpler, more intuitive method, good for systems where failures are largely independent. Now, the critical acceptance criterion. You must demonstrate that the sum of the average probabilities per flight hour of all Catastrophic Failure Conditions caused by systems is of the order of 10⁻⁷ or less. That’s one in ten million per flight hour. Note the word “sum” — you’re not just showing each individual catastrophic condition is below that number; you’re adding up all of them together, and that total must be of the order of 10⁻⁷ or less. And the excerpt points you to paragraph 6a for the background on why that number was chosen. Now let’s move to paragraph 9, which is titled “Compliance with CS 25.1309.” This paragraph describes specific means of compliance — that is, acceptable ways to show you meet the rule. And there’s a key procedural point right up front: the applicant should obtain early concurrence of the certification authority on the choice of an acceptable means of compliance. In plain terms, don’t wait until the end of the programme to tell the regulator how you plan to prove safety. Go to them early, agree on the method, and get their sign-off. That saves enormous pain later. Then we get into the detail of compliance with CS 25.1309(a). Sub-paragraph (1) covers equipment covered by 25.1309(a)(1). That equipment must be shown to function properly when installed. So it’s not enough that the component works on the bench — it must work in the aeroplane, in the installation. Now, what conditions must that proper functioning be demonstrated over? The aeroplane operating and environmental conditions. And the excerpt is very specific about what that includes. First, the full normal operating envelope of the aeroplane as defined by the Aeroplane Flight Manual — that’s the AFM, the document that defines the certified limits of the aircraft. Plus any modification to that envelope associated with abnormal or emergency procedures. So if an emergency procedure expands the envelope — say, a higher speed for a rapid descent — the equipment must function properly in that expanded regime too. Then there are the external environmental conditions the aeroplane is reasonably expected to encounter. The excerpt names them explicitly: atmospheric turbulence, HIRF, lightning, and precipitation. HIRF stands for High Intensity Radiated Fields — that’s electromagnetic energy from sources like ground-based radars or broadcast transmitters that can interfere with avionics. So you must consider turbulence, HIRF, lightning, and precipitation. But there’s a limit on severity. The severity of the external environmental conditions which should be considered is limited to those established by certification standards and precedence. In other words, you don’t have to design for conditions beyond what the certification standards define, or beyond what established practice — precedence — has already accepted. There’s a boundary to how extreme you must go. Then sub-paragraph (2) adds the internal environment. In addition to the external conditions, you must consider the effect of the environment within the aeroplane. And the excerpt lists what those internal effects should include: vibration and acceleration loads, variations in fluid pressure and electrical power, and fluid or vapour contamination. And that contamination can arise either from the normal environment or from accidental causes. So think about hydraulic fluid leaking, fuel vapour, water — anything that could contaminate a system — you must consider it, whether it comes from normal operation or from an accident scenario. So the full picture is: external conditions — the AFM envelope, abnormal and emergency modifications, turbulence, HIRF, lightning, precipitation, bounded by certification standards — plus internal conditions — vibration, acceleration, fluid pressure and electrical power variations, and contamination from normal or accidental sources. All of that defines the environment over which your equipment must be shown to function properly when installed. That’s the foundation of the compliance argument. The next part of the paragraph will go deeper into how you actually demonstrate that proper functioning, but this is the scope you must cover first.

This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.

Continue in BlueFlash