System Design 1 - Guest lecture

07 May 2025, Björn Annighöfer

Is the previously developed architecture according to regulations and is it safe enough, is it's safety level neccessary?

Safety Assessment Process

architecture

The Safety V (according to ARP 4754 [3] & 4761 [4])

AHFA: Aircraft functional hazard assessment - Enumerate all failure conditions of the aircraft independent of the technical realization and judge their severity
PASA: Preliminary aircraft safety assessment - Map functions to systems and elaborate interdependance and common resources
SFHA: System functional hazard assessment
PSSA: Preliminary system safety assessment
CCA: Common cause analysis

Goal: safety requirements for my system, equipment and hardware

Activities of safety verification

SSA: System Safety Assessment ASA: Aircraft Safety Assessment CCA: Common Cause Analysis

Goal: Provide evidence that the actual implementation is as safe as required (get the aircraft certified)

Diagram on slide 13

Practical Safety Assessment Walkthrough for Elevator Control System

Aircraft Type

CS-25 boundary conditions

AFHA

FHA

Functions

Failure modes

Flight phases

Remark: Those are only suggestions and shall be modified and defined as needed

architecture

The full AFHA - too many entries

PASA

Goal: Find a safe mapping of aircraft functions to systems (repeat if insufficient)

SFHA

PSSA

Goal: Ensure that the planned system will fulfill the safety requirements

SSA

Failure Effect system equipment sometimes is defined by the manufacturer
Otherwise experiments have to be made

Start at the lowest level of individual electrical components
End at the equipment top-level

FMEA