Airborne Electronic Hardware Design Assurance
eBook - ePub

Airborne Electronic Hardware Design Assurance

A Practitioner's Guide to RTCA/DO-254

  1. 249 pages
  2. English
  3. ePUB (mobile friendly)
  4. Available on iOS & Android
eBook - ePub

Airborne Electronic Hardware Design Assurance

A Practitioner's Guide to RTCA/DO-254

About this book

Written by a Federal Aviation Administration (FAA) consultant designated engineering representative (DER) and an electronics hardware design engineer who together taught the DO-254 class at the Radio Technical Commission for Aeronautics, Inc. (RTCA) in Washington, District of Columbia, USA, Airborne Electronic Hardware Design Assurance: A Practitioner's Guide to RTCA/DO-254 is a testimony to the lessons learned and wisdom gained from many years of first-hand experience in the design, verification, and approval of airborne electronic hardware.

This practical guide to the use of RTCA/DO-254 in the development of airborne electronic hardware for safety critical airborne applications:

  • Describes how to optimize engineering processes and practices to harmonize with DO-254
  • Addresses the single most problematic aspect of engineering and compliance to DO-254—poorly written requirements
  • Includes a tutorial on how to write requirements that will minimize the cost and effort of electronic design and verification
  • Discusses the common pitfalls encountered by practitioners of DO-254, along with how those pitfalls occur and what can be done about them
  • Settles the ongoing debate and misconceptions about the true definition of a derived requirement
  • Promotes embracing DO-254 as the best means to achieve compliance to it, as well as the best path to high-quality electronic hardware

Airborne Electronic Hardware Design Assurance: A Practitioner's Guide to RTCA/DO-254 offers real-world insight into RTCA/DO-254 and how its objectives can be satisfied. It provides engineers with valuable information that can be applied to any project to make compliance to DO-254 as easy and problem-free as possible.

Frequently asked questions

Yes, you can cancel anytime from the Subscription tab in your account settings on the Perlego website. Your subscription will stay active until the end of your current billing period. Learn how to cancel your subscription.
No, books cannot be downloaded as external files, such as PDFs, for use outside of Perlego. However, you can download books within the Perlego app for offline reading on mobile or tablet. Learn more here.
Perlego offers two plans: Essential and Complete
  • Essential is ideal for learners and professionals who enjoy exploring a wide range of subjects. Access the Essential Library with 800,000+ trusted titles and best-sellers across business, personal growth, and the humanities. Includes unlimited reading time and Standard Read Aloud voice.
  • Complete: Perfect for advanced learners and researchers needing full, unrestricted access. Unlock 1.4M+ books across hundreds of subjects, including academic and specialized titles. The Complete Plan also includes advanced features like Premium Read Aloud and Research Assistant.
Both plans are available with monthly, semester, or annual billing cycles.
We are an online textbook subscription service, where you can get access to an entire online library for less than the price of a single book per month. With over 1 million books across 1000+ topics, we’ve got you covered! Learn more here.
Look out for the read-aloud symbol on your next book to see if you can listen to it. The read-aloud tool reads text aloud for you, highlighting the text as it is being read. You can pause it, speed it up and slow it down. Learn more here.
Yes! You can use the Perlego app on both iOS or Android devices to read anytime, anywhere — even offline. Perfect for commutes or when you’re on the go.
Please note we cannot support devices running on iOS 13 and Android 7 or earlier. Learn more about using the app.
Yes, you can access Airborne Electronic Hardware Design Assurance by Randall Fulton,Roy Vandermolen in PDF and/or ePUB format, as well as other popular books in Computer Science & Electrical Engineering & Telecommunications. We have over one million books available in our catalogue for you to explore.
1
Introduction to RTCA/DO-254
RTCA DO-254 (also known as EUROCAE ED-80), Design Assurance Guidance for Airborne Electronic Hardware,1 was prepared jointly by RTCA Special Committee 180 and EUROCAE Working Group 46, and was subsequently published by RTCA and EUROCAE in April 2000. These industry working groups were formed in the 1990s and took seven years to create DO-254.
DO-254 is not a technical manual, nor is it an engineering cookbook. It does not prescribe the design characteristics of electronic circuits or components, nor does it contain design standards. In fact, it contains virtually no technical information that an engineer can use to guide a circuit design. Instead, it provides guidance on the processes and methodologies that should be applied in the development and verification of electronic hardware to achieve an acceptable level of confidence that the end hardware functions correctly and will be in compliance with airworthiness requirements. While it can be argued that some aspects of a design can be influenced by the desire to facilitate the design and verification methodologies contained in DO-254, there are actually no design features that must or must not exist solely because of the need to comply with it.
The guidance in DO-254 represents industry consensus on the best practices that will ensure that electronic hardware is developed and verified in a way that is appropriate for its design assurance level (DAL)—often shortened to “Level”—and will ensure, to a realistic level, a safe and reliable product. The supporting processes defined in DO-254 (configuration management, process assurance, and validation/verification) are particularly effective in controlling the introduction of design errors as well as identifying errors that are inevitably introduced despite best efforts to the contrary. DO-254 describes the objectives for each phase of a typical electronic hardware development life cycle and describes the activities usually associated with the life cycle phase.
The genesis of DO-254 stems from concerns that as electronics technology rapidly evolved, enabling systems to become more complex and to host more functionality, proving that these systems were safe and reliable was becoming more and more difficult. Most of the electronic systems and programmable logic devices (PLDs) that are used on modern aircraft are well beyond our ability to prove safe through quantitative analysis, and in the absence of this avenue of design assurance, the only other viable means of establishing the necessary design assurance is to use structured and disciplined processes and methodologies during their development. The advantages of using this means are, first, that the processes and methodologies force designers to create a design in a logical and systematic (and therefore repeatable) manner, and second, they create a type of transparency in the design and its project by enforcing a high level of documentation and traceability that, while inconvenient on the surface, has repeatedly proven its worth over the long-term life of a design. Like them or not, the best practices in DO-254 can, particularly in the long run, be a project’s best friend.
The guidance in DO-254 was written to apply to all complex electronic hardware that performs safety-critical system functions. While DO-254 discusses PLDs, they are considered within the context of system and equipment development, and not necessarily as the only aspect of the system that should use the guidance in DO-254. When the Federal Aviation Administration (FAA) published its Advisory Circular (AC) 20-152,2 which approved DO-254 as an acceptable (but not the only) means of satisfying the Federal Aviation Regulations (FARs) for PLDs, it essentially reduced the application of DO-254’s guidance to a small subset of its original scope.
Narrowing the focus of DO-254 from the system level to the component level can be problematic due to the need to interpret and apply electronic system guidance to singular components within the system. Examples of potential problems include determining the scope of the life cycle data, determining how to interpret and apply DO-254 Table A-1 to PLD life cycle data, and sorting out which activities and aspects apply at the component level as opposed to the system level (such as acceptance tests, environmental tests, functional failure path analysis, and traceability to elements in the hardware implementation, none of which are entirely practical at the component level). There are also boundary issues that arise: much of DO-254’s overall effectiveness relies upon implementing all of its guidance to all levels of a system, which creates a seamless interconnection and flow of processes and data between all levels of the system (line replaceable unit [LRU], sub-assemblies, circuit card assemblies [CCA], and component [typically a PLD]). When one level of the system is singled out for the isolated application of DO-254, it loses this flow to the other levels, creating a discontinuity in both processes and data that can, if not properly anticipated, potentially render much of the design assurance activities ineffective or meaningless. Applying DO-254 only at the PLD level can be made to work through judicious interpretation and tailoring, but in the end the document is most easily comprehended and most effectively applied according to the perspective for which it was conceived and written, and ultimately for which it was intended to be applied, in other words throughout the entire system.
DESIGN ASSURANCE LEVEL
DO-254 defines five levels for the design assurance of airborne electronic systems. These five design assurance levels are defined as levels A through E, where A is the most stringent and E is the least. These five levels correspond to the five classifications of failure conditions defined in the regulatory materials that govern the certification of airborne systems and equipment.
Table 1.1 identifies the five hazard classifications and maps them to their corresponding design assurance level, the required probability of failure per flight hour for equipment of each level, and a description of the hazard. The hazard classifications are described with respect to the effect that a failure of the system or equipment will have on the aircraft, its occupants, its safety margins, and the ability of its crew to deal with adverse operating conditions. The most severe classification is catastrophic (level A), indicating that a failure of level A equipment will, for all practical purposes, result in a catastrophic hull loss of the aircraft. The least sever...

Table of contents

  1. Cover
  2. Half Title
  3. Title Page
  4. Copyright Page
  5. Table of Contents
  6. Preface
  7. Acknowledgments
  8. Authors
  9. Chapter 1 Introduction to RTCA/DO-254
  10. Chapter 2 Regulatory Background
  11. Chapter 3 Planning
  12. Chapter 4 Requirements
  13. Chapter 5 Validation
  14. Chapter 6 Philosophy 101—Design Assurance Through Design Practice
  15. Chapter 7 Verification
  16. Chapter 8 Process Assurance
  17. Chapter 9 Configuration Management
  18. Chapter 10 Additional Considerations
  19. Chapter 11 Summary
  20. Index