Saturday, February 7, 2015

No One In The Cockpit

There are still studies going forward about letting large aircraft fly with passengers and cargo, with one or no pilots. Some people say it is inevitable, thinking back to the days of professional drivers, or elevator operators, pilots are just an extra expense the airlines can get by without. Technology has improved, it does seem like the pilots don't need to fly the airplane as much as they used to. I've explained how software reliability has improved, and the tools needed to build new autopilots are getting better.

Looking at Air France 447 might be a good place to start. That airplane was apparently flown into the ocean by a pilot, that was confused. The autopilot should have done better, one would think. If the timeline is followed, it will show that the autopilot was confused, and gave up as well (alternate law), relinquishing control to the human pilots. The airspeed sensors (pitot tubes) apparently iced over, causing the automated systems to not have enough correlated information to process the data it had. The pilots left in the cockpit to monitor the systems were not experienced enough to know what to do in this situation.

Talking to most pilots, they will tell you about automation failures all the time. Sometimes stuff just breaks. I know two pilots that were flying back and forth Houston to Austin one day for an airline, and they decided to hand fly the trips and let a flight attendant judge who flew smoother. The next day the one pilot had to take that same airplane from Houston to Orlando, and it turned out the autopilot had failed sometime the day before, and no one knew it broke. He had to hand fly the plane from Houston to Orlando.

The idea of a single pilot in the cockpit is probably just as bad as no pilots. Sometimes pilots have troubles, including health (getting sick, incapacitated, etc), alertness, and just plain forgetfulness. Using a second pilot on the ground might seem like a great idea, one pilot can monitor several flights and "take over" if there is a need. The trouble with the ground pilot is the need for 100% reliable automation, and datalinks. If the part that fails in the autopilot is the same part that the ground pilot will be using for controlling the aircraft (IE servo) it won't help to have someone on the ground wanting to control it, the part is broken for whoever is trying to use it.

Thoughts about using pilotless cargo aircraft are perhaps more palatable, since no one will get killed if the automation fails. That will make sense, if everything being shipped has no value. Things shipped by air a typically worth more than things shipped by truck or train (per Cubic Foot). The pilotless aircraft may still crash, and there will be no heroes on board to steer the aircraft away from the stadium full of people.

Economics probably won't make a pilotless aircraft worth it. Certainly automated systems can be built to make things seem to be cheaper. Certainly pilots are paid well, and have health insurance, pensions and vacation pay that must be paid for by customers. An automated system should eliminate the pilots pay from this picture. There will probably be more maintenance, and a higher price for the initial aircraft purchase. Then the insurance picture may remove all the financial benefits.

Oh, and according to the U.S. Labor Department’s Census of Fatal Occupational Injuries, about 27 people per year are killed in elevator accidents in the US.

What is a life worth?










Wednesday, January 14, 2015

DO-260B ... well it is compliant

Ok there is compliant, and there is useful. DO-260B is certainly the former, and not likely the latter. ADS-B is full of challenges, and opportunities. Upgrading equipment is expensive. Some equipment is really close to usable, and some just flat out needs to be replaced. The mode S transponder certainly is one of those items.

If an aircraft has a mode S transponder on it, it can almost do ADS-B out. The payload on a stock mode S transponder can only be 56bits. For ADS-B out, the transponder needs to send 112 bits. The extended squitter (ES) is the change needed to make a mode S transponder ADS-B out compliant. DO-260B is the standard needed to "convert" mode S to mode  S with ES.

ADS-B out is needed by 2020, and if an aircraft has a mode S transponder, getting the transponder updated to DO-260B will  make the aircraft compliant. ADS-B out will make the aircraft as functional as it is today in a RADAR environment. There is no additional functionality available to the pilots on the aircraft. The big win for the pilots is ADS-B in. DO-260B has no provision for IN, only out.

Most 1090ES transponders are only transmitting the ADS-B message. To receive the ADS-B message, a separate receiver is needed. Usually jets will will have the TCAS system as a transponder receiver. This unit has the ability to receive all 1090MHz transponder messages. Using the TCAS receiver may allow an aircraft to have ADS-B in, if it has the proper facilities to send the message to a display, or computer for displaying.

Yes, 2020 seemed a long time away when the FAA said we all need ADS-B out. DO-260B might seem a tempting quick answer for older aircraft. It could be cheap, but likely it will cost a bunch to get a WAAS enabled GPS feeding the mode S transponder with ES. UAT's won't cut it for jets, so the right answer will probably be a new transponder that will do a proper job of handling ADS-B messages, along with a modern WAAS GPS receiver.

I am open to arguments, but overall it is going to cost a lot of money to equip for ADS-B in any aircraft.


Sunday, January 4, 2015

Gate to Gate

Over the last couple years, I have written about many bits of technology that aircraft use. I really haven't discussed too much what bits are used when, and for what. This post, I will try and tie all the items and their use into a comprehensive post. I'll use a commercial airliner (Part 121) for the discussion, both because they typically use more technology, and because that is what my background is. I will also base most of this on flights in the US, to keep it simpler.

We can start a few hours before the flight actually leaves. As the flight approaches it's scheduled time to leave, a group of folks have started planning for the flight. Sure, there is network planning, they set up the schedules and try to be sure the flight will make money, and provide continuity, and such, but that is usually done months in advance. There are also the simulators that the pilots use for proficiency checks, and training, but that is on going and not related to a particular flight, but important none the less.

Dispatchers and meteorologists are considering the situation between the origin and the destination of the flight. The meteorologists are generalists, looking at the weather over the country, where dispatchers are more concerned with the weather along the route between the cities. The dispatcher needs to consider the situation at the specific airports, for runway closures, and other challenges unrelated to weather. There is a tool called Collaborative Decision Making (CDM), where the dispatchers work with the other airlines so everyone can utilize the airports and airspace as optimally as possible.

The dispatchers can use CDM to look for areas to avoid when selecting a route between the two cities. If there is a bad thunderstorm along the optimum route and all the other airlines are avoiding it to the south, the dispatcher may pick a northern route to stay out of everyone elses way. Once the dispatcher selects a route, they need to build the rest of the flight plan. The dispatcher will build a flight plan using many tools. The dispatcher may allow the flight planning engine to select routes, or the amount of fuel. Depending on aircraft maintenance situation, and MEL deferrals and such the flight planning engine can accurately predict the fuel burn based on weather and route.

Once the dispatchers are happy with route and fuel selected, they will file a flight plan. The flight plan will be filed with the Air Navigation Service Provider (ANSP) for both the origin and the destination. For the US the ANSP is the FAA, in Canada is is NavCanada, and in the UK it is NATS. The ANSP handles all the RADAR and air traffic control (ATC) functions. The flight plan will give the ATC controllers a heads up on what the aircraft was planning on doing once in the air.

As the pilots get to the aircraft, one will typically do a walk around of the outside of the aircraft making sure the aircraft looks safe and no damage is visible. The other pilot will typically go to the cockpit and begin setting things up. There may be a the initialization of the FMS, maybe a RAIM check of the GPS, and entering the flight plan prepared by the dispatcher into the FMS. The dispatcher provided flight plan will usually include weather information for the route, and any other non weather realted information for the route (IE ATC changes, etc), The flight plan will also contain fuel and time information that the pilot can double check, insuring the dispatcher hasn't made any mistakes.

When the pilot know the fuel situation, they may confer with the fueler to adjust any fuel amounts to be put on board. The pilot will also need to know how many bags and passengers are on the flight, so they may make proper weight and balance calculations. Some airlines have a load planner who takes care of the weight and balance, others still let the pilot take care of this. Depending on the aircraft, it may be necessary to have a person dedicated to making the load calculations.

As all the passengers are seated, and the pilot is about to move the aircraft, they will ask for permission to move. There may be a ground controller dedicated to the gate area, and there will need to be taxi clearances and such needed from them. Other airports everything is controlled from the tower, and any movement must be cleared through the tower controllers. An ACARs message may be sent requesting the Pre Departure Clearance (PDC), that will be a version of the flight plan sent to the ATC with any ATCneeded changes to the plan. The PDC will also contain the code the pilot needs to enter into the transponder. The pilot must acknowledge receipt of the message.

After the aircraft is taxied to the runway, the pilot will ask the tower for the final airport clearance, by announcing "ready for takeoff". Once the ATC controller gives the pilot final instructions the pilot can access the runway and start the takeoff. The ATC instructions will be the route the pilot should take to get from the runway to the beginning of the flight plan route. Every bit of the instructions and plans for the takeoff are there in case there is a failure. If there is a radio failure either from ATC or the Aircraft, the instructions given are good enough for the pilot to take off, fly the planned route, and approach the destination. It is a safety situation, should the plan be the safest and most expeditious way to fly the route.

Once the aircraft is above about 300 ft, depending on the  airport, the aircraft will appear on RADAR. The first RADAR that will show the aircraft is the TRACON, who will control the aircraft after tower hands off the aircraft. The TRACON controller will control the aircraft until it is more than 30-50 miles from the airport. The TRACON will hand the aircraft off the enroute controllers who will control the flight until it is 30-60 miles from the destination airport. The RADAR data will be collected and sent to the FAA command center for others to view, and use the ADSI information. As we move into NextGen, there may be more ADS/B position reporting, instead of RADAR.

Once the aircraft is on the route, the pilots will typically engage the autopilot. The autopilot will help maintain the route of flight, altitude and throttle settings to insure the aircraft flies the route planned, and uses the fuel planned. The pilot must monitor the autopilot to be sure it is engaged, and doing the right thing the whole flight. Occasionally pilots will hand fly the aircraft, for practice. Once in a while the autopilot will fail, and the pilots must had fly the aircraft. The systems in the aircraft are designed for certain reliability levels.

During the enroute portion of the flight, there may be messages the pilots need to send to the company operations center. The pilots will usually send a text message over ACARS if they don't have a lot of urgency to the message. The pilots also have an option for voice communication using company assigned frequencies. If there were to be a medical emergency, the voice communications will be used, if a pilot is looking for a weather report for 400 miles ahead, they will use ACARS.

As the aircraft gets closer to the destination, ATC will typically begin having the aircraft start to descend. Newer approaches follow a continuous descent profile, where the pilots set the throttles to idle at altitude, and basically use the potential energy to glide the aircraft to the runway, reducing noise, fuel burn and pollution.

Current approaches typically are designed for the aircraft to provide it's own guidance. That is there are airs on the ground (or satellite) to provide the aircraft the information it needs to know where it is, and fly to the runway. Features like DME and ILS radions are on the ground, and GPS satellites are in the air.

The enroute controller will hand the flight off to the TRACON controller about 50 miles from the airport, where the aircraft will be below about 10,000ft. The TRACON controller will clear the flight for the approach that it will use to get to the airport. At about 5 miles out, the pilot will be told to contact the tower, and the tower and the pilot will make the final checks and be cleared for the runway to land on. Once on the ground, the pilot will talk to the ground controllers to get to the proper parking area, and maybe a gate controller for certain airports. Once the wheels are chocked, and the engines shutdown, the pilots are mostly done with the flight.

Yes, there is a bit of technology going on between each gate, and a little before. Ever think about that before.

Wednesday, July 30, 2014

The Connected Cockpit

The internet of things (IoT) is kind of the current discussion in many publications. The idea behind the internet of things is that everything will be connected to the internet, allowing monitoring and control of those things. As things are going, it is still too expensive to connect everything to the internet, and there many implications of connecting everything to the internet.



Many aircraft are getting WiFi in the cabin, people think the next step is putting an iPad in the cockpit, and connecting to the cabin WiFi and that should do it. Get all the flight plans, updates, weather and other data from headquarters we are all done. The trouble is, and was pointed out in the first post of this blog, there are security thoughts that need to be considered.

On transport aircraft, most of the cockpit is connected. Well connected, in that the FMS talks to the airopilot, and the EFIS may talk to the ACARS system, and the radios share a common bus. The trouble is, the cockpit is not talking IP, so it isn't easy to connect it to the WiFi, and it probably isn't a good idea.

In your GA business jet, it might be OK to connect the cabin to the cockpit. The people in the aircraft are usually well vetted, and may actually own it. They have a serious reason to be riding in the aircraft to the destination. Smaller aircraft may not have the means to get WiFi to the ground, but WiFi or other Ethernet connections could actually be done allowing the GPS to talk to the ADS-B transciever, and the MFD in the panel.

Allowing the cabin WiFi be connected to the cockpit of a part 121 transport aircraft is probably a bad idea. Probably the biggest problem would be if the aircraft were in a place with weak connection to the ground, and bandwidth was limited, who would get priority, the passenger watching Netflix or the cockpit needing a new route around some weather. The marketing department might argue the passengers, but flight operations department might argue the cockpit should have priority.

The other reason connecting the cockpit to the cabin using WiFi is a bad idea would be straight up security. There would be 100 people in the back bored wondering what is going on in the flight. It may be a curiosity for some, or a goal for others, they may just want to look at things, and manage to get access to say the current flight plan, in the FMS, and accidentally adjust it. Sure there could be firewalls and whitelists and other techniques to keep only the cockpit in the cockpit network, but there are ways for others to get in.

Having a separate cockpit connection to the ground is probably the right answer to the security question. having an isolated cockpit will make it harder to keep the cabin people out of the cockpit network.  It will be important to consider all the connections to the cockpit, and how secure they may be. If there is only an unsecured connection to the cockpit, then the cabin can probably still get to it through some ground station. Worse, if the cockpit doesn't have a secure connection to the ground, now there may be thousands of bored people trying to see what is going on in the aircraft.

Security has to be the first thought when building cockpit connected interfaces. Security through obscurity isn't real security, so proprietary standards won't be a long term solution. Bored people look at proprietary standards as a new challenge, and eventually they get figured out. Using industry best practices will be the only way to insure interoperability along with proper security.

It may be that the aircraft cockpits are only connected using one vendor (IE ARINC as things are today), where they provide an isolated network that only they can get to the aircraft. The messages will have to pass though a filter, and have proper originator white lists. All messages would be encrypted such that only known originators and destinations can see and use the messages. Certainly ARINC can't let Southwest Airlines read Delta Airlines messages, as well as some random person on the ground should not be able to sent messages to any aircraft.

It will take a bit of time for things to shake out, but eventually the cockpits will be connected.

Saturday, July 19, 2014

Thoughts On Cockpit Electronics

Recently I was playing an EFB type app. I think I've mentioned it on my other blog, and I am mostly happy with Avare. This app will allow weather downloads, and is a moving map and can display charts of most types (Sectional, WAC, IFR Low and High, etc). It has built in AF/D, can display approach plates, and topographical data.



While using it, I was surprised by a few things, and it occured to me you cannot just buy the latest technology and go out and blindly rely on it. You really need to know how it works, and test it out for a while.

I flew with the Avare app on a Samsung Note 10.1, and found a few anomalies with the system, and I am sure other apps and tablets have similar anomalies. I was testing the app out while riding in the back of a 737, and the GPS was mostly unusable back there. On takeoff it seemed to work well and I could see the acceleration down the runway, and the climbout was displaying nice. But about the first turn, and suddenly the GPS wasn't working at all. No speed, no heading, nothing. Then it was intermittent the rest of the flight.

Avare, like most moving map applications can take another GPS source as the input. There are several manufacturers that offer standalone GPS source devices (IE Garmin). Avare even offers an app you can run on another device (IE phone) to use that GPS source to feed the application. On my next flight, I ran the external app on my phone, and was feeding Avare with the GPS output from my phone. The phone was in my pocket, and I had a window seat, so it worked almost 100% of the flight.

Since the my phone GPS wasn't 100% reliable, it was a good test. I've mentioned Kalman filters in other posts, I wanted to see if this app had any coast mode, where the application would predict the location based on flight plan and last few samples, but it didn't. When the GPS signal was lost, the airplane on the magenta line would point straight north, and stop updating. This by itself was a good thing to know, since GPS isn't 100% reliable in any situation (see the RAIM predication post), and it is good to know what indication is out there when the GPS signal isn't there. When the GPS data was available again, the airplane symbol oriented itself to the flight path the aircraft was following.

Another test I found out about, the hard way, was the chart updating. The charts are generally current for a period of time, some are 28-56 days (IE approach plates) and others up to about 6 months  (IE sectionals). Some of my charts were out of date. The app has a nice feature allowing bulk downloads of charts, but not while out of WiFi range. Most charts are big files, that take a while to download. Even a 737 with WiFi on board isn't the best place to bulk download charts, since most of the flight may have taken place by the time it updates everything (depending on how many plates are out of date). It is best to do the bulk update the day before the trip, to allow time to make sure everything downloads, and the WiFi at the hotel is reliable, the FAA didn't change anything  and everything else works.

Another problem I found, the 10.1 inch tablet might be too big for a cockpit. If I was flying an A380, it might be fine, but even in the seat in the back of the plane, occasionally it got in the way. It would be nice to try an 8 inch tablet next time. The 10.1 inch tablet is about an inch wider than my knee board on all sides. It might be nice to find a knee board adapter for a tablet. Knowing were it is, and what happens when accidentally touched might be a good thing to know. I tapped the screen multiple times on the flight, and sometimes the screen would go off center, I would have to punch the button to set the center again.

Entering a flight plan on the flight was frustrating at best. For the flights I was on, I could look at the route on flightaware.com, and see what waypoints to enter. I was on a flight from DAL to MSP, that stopped in STL. I needed to enter two separate flight plans, which would have worked much better in the terminal rather than in my seat. Then when I got done, I needed to activate the correct one. At first I had forgotten activate the first plan I entered, so the magenta line didn't show up. The Distance Next and Estimated Time Next were updating as if we were flying a single leg flight.

When we began our approach to the middle airport, I thought I could click on the approach plate, and the app would plot the current position on the plate. It didn't, which made sense after I thought about it, since the approach plates aren't always drawn to scale nor have consistent references, and SIDS and STARS never are drawn to scale. The app was smart, since it knew where we were, and punching the "plate" button brought up the correct airport diagram, and I could select the approach, SID or STAR I wanted to use.  A split screen feature might be nice, especially on a STAR.

The weather feature is nice, since it loads most of the standard weather products, (IE METARs, TAFs, PIREPS) for areas along the route. It wouldn't make sense to get a METAR for Chicago if I am going from Dallas to St Louis, and this seems to do a good job. The weather isn't updated if there is no data connection. Some apps will work with a FIS-B receiver, but even those messages may not be as timely as pilots need in a dynamic system. Talking with Flight Service is still the best way in busy weather systems.

I really enjoyed using the app. I can see it being a tool to rely on. I can also see I need to work with it a bit more, and read the manual. Other similar apps are probably just as good, and will need careful integration into any flying procedures. The FAA doesn't allow using handheld GPS devices for primary navigation in IFR conditions, but for VFR, there should be nothing wrong with using this for navigation.

What do you use?







Monday, June 16, 2014

RAIM and GPS


Wow, I can't believe I haven't written this post yet. I have mentioned RAIM in other posts, but I haven't explicitly explained RAIM. RAIM used to mean Redundant Autonomous Integrity Monitoring it was a technology built into many GPS receivers. TSO-C129 required GPS receivers to have RAIM built in. It would monitor the quality of the GPS signal, and if things were bad enough, the RAIM system would alert the pilot that things aren't working.



If you go back to the NextGen post I did a little more than a year ago, I mentioned RAIM, and the FAA's RAIM prediction tool: http://www.raimprediction.net this tool will predict places in the CONUS where the RAIM alert will go off in the future.

The GPS signal is just telling you what the time was when the satellite sent the signal. The satellites also send location information along with the time. The almanac is the location of all the satellites in the constellation. Knowing the time the satellite sent it's signal, and knowing where the satellite was when the signal was sent, the GPS receivers are able to triangulate (sphere-iate?) their location.

The satellite time message is sent every few minutes, and is susceptible to all kinds of problems. The message may bounce off buildings, mountains or other vehicles causing a wrong distance to be calculated. Other times the satellites will be down for maintenance, and testing, so it won't be available for measurements. Knowing the current status of the constellation is critical to make a valid prediction. Knowing local terrain will help make predictions more accurate.

With GPS Helpers, RAIM prediction is not needed. Using satellite or ground based augmentation systems (IE WAAS, LAAS) the number of satellites isn't as critical. Knowing the WAAS system health is required, and the FAA will issue NOTAMs if the WAAS system isn't up to snuff.

As you can see RAIM has its use, and can make older GPSs more usable.

Saturday, June 7, 2014

FAA and UAS

The FAA has a huge challenge, they need to get it right the first time. If they screw it up, and a UAS and a passenger aircraft have an issue, where people get hurt, there will be no more UAS allowed! Of course, the UAS industries are clamoring for changes now. Claims of huge employment are dubious, since it will only transition pilots and maintenance from manned aircraft to unmanned (peopled, what is the right non-gender word).

If people think everything under 400ft (1000ft, 2000ft, whatever) should be unregulated, what happens when a traffic accident occurs, and a medical helicopter has to thread it’s way through 5 local TV stations with their quad copters filming the carnage? What are the rules around an airport? The rules have to at least match the controlled/uncontrolled/class A/B/C/D rules that exist for manned aircraft. Rules need to be established, such that assistance cannot be delayed.

Quad copters and other UAS devices are easy to fly when the weather is nice and there is little wind and turbulence. What happens when there is turbulence, or dust or other weather that makes visual queues, and control difficult. How about a slightly damaged older device that isn’t well maintained, and the operator is inexperienced. The innocent people on the sidewalk should expect a reasonable amount of safety near these devices.

Many of the smaller quad-copters are only controllable indoors, and some of the larger ones are controllable in moderate winds. Larger UAS systems are less prone to weather, but are more dangerous to people around them. What happens when an editor or producer is clamoring for a news story on a stormy day? What is the poor UAS operator to do, fly anyway? The operators will be glad to have an FAA regulation that says it isn't safe, so they won't have to stress about it.

There will need to be right of way rules. Right of way rules make knowing what to expect from the other aircraft. It is all great to have see and avoid, but what is the understood direction to avoid things? Most R/C fliers operate with one aircraft in the pattern at a time, so they don't have too many right of way issues. Much of this will be new territory to UAS operators.

For commercial UAS operators, there will need to be maintenance programs designed. Basic maintenance will need to be regulated to insure the craft is controllable, as well as structurally sound. Having a UAS disassemble in flight will make the situation for the operator inconvenient. Inspections, and preventative maintenance programs will have to be defined. 

There will be all kinds of other regulations that most people haven’t considered.
Pilot licensing being one. If a UAS is to be operated in the same airspace as a manned system, the operator MUST know the same rules as the manned aircraft, at least to know what everyone will expect in right of way situations. 

The FAA could mess all this up and not regulate it properly, and people will get hurt. The FAA is already granting exceptions for certain groups, but this sets a bad precedence. They could rush, or some manufacturer could lobby congress to get the FAA out of the way, and people would get hurt. If a UAS took down a 737 you will see congress act!

Everyone needs to be a little more patient, and let the process work it’s way out.