BlueFlash
teach preview

First, Redundancy or Backup Systems — Page 37, Lesson 49

First, Redundancy or Backup Systems — Page 37, Lesson 49BlueFlash
I want to walk you through the design principles that keep an aeroplane safe when things go wrong. We're looking at the list of safety techniques that a designer uses, and I'll take them one by one because each one is a distinct tool. First, Redundancy or Backup Systems. This is the idea that you build in more than one way to perform a critical function, so that after any single failure — or some other defined number of failures — the system can still keep working. The classic examples are two or more engines, or multiple hydraulic systems, or multiple flight control systems. If one engine fails, the others keep the aeroplane flying. That's redundancy. Next, Isolation and/or Segregation of Systems, Components, and Elements. The goal here is that the failure of one system does not cause the failure of another. Isolation means physically separating them so a fire or a rupture in one doesn't spread. Segregation means keeping redundant channels apart — for example, running the two hydraulic systems on opposite sides of the aeroplane so a single event can't take out both. Then we have Proven Reliability. This is the statistical side. The idea is that we want multiple, independent failures to be unlikely to occur during the same flight. If each component is individually reliable, then the chance of two independent failures happening together in one flight becomes very small. That's what makes redundancy work — you're betting that a second failure won't coincide with the first. Next, Failure Warning or Indication, which provides detection. You can't respond to a failure you don't know about. So the aeroplane is fitted with systems that tell the crew something has failed — that's the detection function. That leads directly to Flight crew Procedures specifying corrective action for use after failure detection. Once the warning tells you something has failed, you need a defined procedure — a checklist, a sequence of actions — that tells you exactly what to do about it. Then we have Checkability: the capability to check a component's condition. This is about maintenance. A component should be designed so you can actually inspect it and determine whether it's still in a serviceable state. If you can't check it, you can't manage its condition. Next, Designed Failure Effect Limits, including the capability to sustain damage. This is about limiting the safety impact or effects of a failure. You design the structure and systems so that even if something fails, the damage is contained and the safety impact is bounded — the aeroplane can sustain a certain amount of damage without catastrophic consequences. Closely related is the Designed Failure Path, which controls and directs the effects of a failure in a way that limits its safety impact. This is about steering the failure — making sure that if something breaks, the energy or the damage goes in a direction that's less harmful, rather than into a critical area. Then we have Margins or Factors of Safety, which allow for any undefined or unforeseeable adverse conditions. This is the design cushion. We build the structure stronger than the calculated loads require, so that if something unexpected happens — a gust you didn't predict, a manufacturing variation — there's still a margin of safety to absorb it. Finally, Error-Tolerance, which considers the adverse effects of foreseeable errors during the aeroplane's design, test, manufacture, operation, and maintenance. This is about human error. The design should tolerate mistakes — so that a foreseeable error made by a pilot, a mechanic, or even during manufacturing, doesn't lead to a catastrophic outcome. Now, let me move to the second part, which is about Highly Integrated Systems. This is a concern that arose about the efficiency and coverage of the techniques used for assessing safety aspects of highly integrated systems. These are systems that perform complex and interrelated functions, particularly through the use of electronic technology and software-based techniques. The concern is this: the design and analysis techniques that were traditionally applied to deterministic risks — that is, risks you can predict and calculate with certainty — or to conventional, non-complex systems, may not provide adequate safety coverage for more complex systems. In other words, the old methods were fine for simple, predictable systems, but they may not catch all the failure modes of a highly integrated, software-driven system. So the answer is that other assurance techniques are needed, such as development assurance, which utilises a combination of process assurance and verification. Process assurance means you assure the quality of the process by which the system is developed — you make sure the development itself is rigorous. And verification means you check that the final product actually meets its requirements. Together, these give you confidence in a system that's too complex for traditional deterministic analysis alone. That's the full picture of these safety design principles. Each one is a separate layer of defence, and together they're what make a modern aeroplane safe even when failures occur.

This is one saved preview. Continue from this exact book or paper with BlueFlash voice AI.

Continue in BlueFlash