2013年11月4日 星期一

Transitioning to DO-178C and ARP4754A for UAV software development using model design

With the FAA and EASA adopting aviation standards such as DO-178C and ARP4754A, UAV software developers should familiarize themselves with these standards, particularly when transitioning to model-based design.
Few applications place more importance on verification, or prescribe more process guidance, than aviation. The FAA and its European equivalent, EASA, provide guidance using standards such as ARP4754 for aircraft systems and DO-178B for flight software. These standards are often used outside of civil aviation, in whole or in part, for applications including military aircraft and land vehicles. Adoption for UAV programs is rapidly growing because of the FAA’s recent decision to require UAS and OPA certification via FAA Order 8130.34A. UAV systems are heterogeneous, and not restricted just to flight software. Therefore, other standards are used such as DO-254 for hardware and DO-278 for ground and space software.
With model-based design, UAV engineers develop and simulate system models comprised of hardware and software using block diagrams and state charts, as shown in Figures 1 and 2. They then automatically generate, deploy, and verify code on their embedded systems. With textual computation languages and block diagram model tools, one can generate code in C, C++, Verilog, and VHDL languages, enabling implementation on MCU, DSP[], FPGA[], and ASIC hardware. This lets system, software, and hardware engineers collaborate using the same tools and environment to develop, implement, and verify systems. Given their auto-nomous nature, UAV systems heavily employ closed-loop controls, making system modeling and closed-loop simulation, as shown in Figures 1 and 2, a natural fit.
ARP4754A addresses the complete aircraft development cycle from requirements to integration through verification for three levels of abstraction: aircraft, systems, and item. An item is defined as a hardware or software element having bounded and well defined interfaces. According to the standard, aircraft requirements are allocated to system requirements, which are then allocated to item requirements.
The fact that ARP4754A addresses allocation of system requirements to hardware and software components is significant to UAV developers, especially suppliers. Some suppliers might have claimed that UAV subsystem development was beyond the scope of the original ARP4754, even for complex subsystems containing hardware and software, but not anymore. ARP4754A also more clearly refers to DO-178 and DO-254 for item design. In fact, the introductory notes for ARP4754A acknowledge that its working groups coordinated with RTCA special committees to ensure that the terminology and approach being used are consistent with those being developed for the DO-178B update [DO-178C].
Given the high coupling among systems, hardware, and software for UAVs, it is helpful that the governing standards now clarify relationships between systems and hardware/software subsystems.
ARP4754A recommends the use of modeling and simulation for several process-integral activities involving requirements capture and requirements validation.
ARP4754A Table 6 recommends (R) analysis, modeling and simulation (tests) for validating requirements at the highest Development Assurance Levels (A and B). For Level C, modeling is listed as one of several recommendations. While ARP4754 made similar recommendations, ARP4754A provides more insight and states that a representative environment model, such as the plant model shown in Figure 1, is an essential part of a system model.
Also noted in ARP4754A is that a graphical representation or model can be used to capture system requirements. The standard now notes that a model can be reused for software and hardware design.
If engineers use models to capture requirements, ARP4754A recommends engineers consider the following:
1. Identify the use of models/modeling
2. Identify the intended tools and their usage during development
3. Define modeling standards and libraries
When using model-based design with ARP4754A and DO-178C, additional verification capabilities are often needed beyond in-the-loop testing described in Table 2. These including requirement tracing, model standard checking, model-to-code structural equivalence checking, and robustness analysis using formal methods. For UAVs, rigorous verification that includes multiple verification technologies is paramount given their autonomous nature and system complexity.
DO-178C
Not surprisingly, one of the first changes new in DO-178C is an explicit mention of ARP4754A in Section 2: System life-cycle processes can be found in other industry documents (for example, SAE ARP4754A).
Clarification updates aside, such as the one noted earlier, DO-178C does not differ significantly from DO-178B, at least at first glance. In fact, a casual reader might miss an item mentioned in Section 1.4: How to Use this Document: One or more supplements to this document exist and extend the guidance in this document to a specific technique… if a supplement exists for a specific technique, the supplement should be used …
In other words, the standard’s big changes are captured in the supplemental documents, such as RTCA DO-331, Model-Based Development and Verification Supplement to DO-178C and DO-278A.
Pertinent to this discussion, a long-standing issue with DO-178B for practitioners of model-based design is the uncertainty in mapping DO-178B objectives to model-based design artifacts. Addressing this mapping was a main goal of the DO-178C Sub-Group (SG-4) focused on model-based design. No single mapping sufficed, so several mappings are provided in DO-331. Some include the concept of a Specification model, which is a model separate from that of the one used for design and code generation. The other concept is a Design model, which serves as the detailed requirements used to generate code.

refer to:
http://mil-embedded.com/articles/transitioning-do-178c-arp4754a-uav-using-model-based-design/

2013年10月28日 星期一

Asia claims almost half of Industrial automation system solutions


In order to help businesses better understand how to take advantage of the current climate and increase their industrial automation sales in Asia, particularly China, the CC-Link Partner Association (CLPA) is hosting a seminar entitled ‘Gateway to China’. The event will take place on 24th September at the Mitsubishi Electric Europe Tokyo Conference Suite in Hatfield.
In light of the sensitive current economic climate, many Asian companies are taking a more careful approach to investment – they are becoming more demanding towards their suppliers and making more enquiries before purchasing. Furthermore, according to IHS’ research, several Chinese manufacturers are currently developing products which are in direct competition with the ones provided by Western suppliers of industrial automation. These are only a few of the obstacles facing European vendors who want to penetrate the Asian market to change the way they do business.

Flexibility and the ability to respond to very specific demands are becoming essential factors when dealing with the Asian market. Being able to offer technologies and solutions which are compatible with the needs of Asian clients is no longer an option, it’s a must.

refer to:http://www.connectingindustry.com/automation/asia-claims-almost-half-of-automation-sales.aspx

2013年10月22日 星期二

Salary increase comparison



Another expected data point is that the average salary of an employee gradually increases with the number of people reporting to him or her. With no direct reports, the average salary is $102,170. The average salary increases to more than $200,000 when the number of reports exceeds 500 people.

If you look around your office or attend any embedded computer events, you will notice the sheer lack of females in the automation profession. This year the percentage of female respondents crept up slightly from 5.1% last year to 6.3%. Along with that gender gap comes a salary gap of about $11,283. The average salary for a male is $107,487, while the average salary for a female is $96,204.

Does company size matter?Are you thinking of becoming an independent contractor? Our survey indicates that contractors make about $10,000 more per year than a direct employee. The average salary of a contractor (5.3% of respondents) is $116,636. That $10K may not be enough to cover the cost of insurance and other benefits available to direct employees, however.

There is a message here for employers. If you are paying less than the industry average, you could very likely lose your engineers. Based on data from industrial auto machines, a recruiting and contract staffing company based in Minnesota, there is a high demand for automation professionals, and high-quality candidates are hard to find. When companies do find good candidates, the candidates typically have multiple offers on the table. If your company employs high-quality professionals, pay them well, or you may lose them.

refer to: http://www.automation.com/factors-that-affect-your-salary-what-you-need-to-know

2013年10月1日 星期二

Tips 101: Safety options for automotive chips


Redundant critical on-chip modules like processor, ISO, DMA controller, internal clock generator, and communications peripherals can improve reliability should a primary hardware module become non-functional while the vehicle is running. Such a system can have in-built error detection mechanisms and on-the-fly switching to redundant hardware to mitigate threats to passenger safety.
But this kind of redundant hardware architecture comes with the penalty of increased area and higher power management in silicon. Area penalties can be minimized by intelligent selection of which functions need to be duplicated in silicon. Power can be minimized by adopting power and clock gating in the redundant modules. Some  in-vehicle computers can be implemented in lock-step of each other, where primary and redundant modules process the same input. Mismatch in the output of the lock-step modules indicates a defect in either of the modules. The system can switch itself off or take appropriate safety measures to avoid any real-time failure. Redundant hardware should be placed quite far in silicon from the primary embedded systems to avoid tampering of both modules together.


refer to: http://www.edn.com/design/automotive/4421704/Safety---security-architecture-for-automotive-ICs

2013年9月17日 星期二

IT Technology for industrial controls

It is the author’s opinion that integration of the controls networking  and the IT network is inevitable. It became inevitable the moment the controls industry chose to use Ethernet as the medium with which to communicate data. The controls industry may choose to be dragged kicking and screaming into the modern automation  era, or it can gracefully embrace the change. Embracing means the controls industry would be able to leverage the myriad rich, existing technologies that have been proven foolproof in the IT world. To be dragged kicking and screaming into the modern communications era would do a terrible injustice to those who have worked diligently to bring it about. This could quite possibly add an entirely new facet to the fieldbus wars, which I hope have not been forgotten.
With that said, the controls world is going to be moving with an industry that has a definite consumer bias, with product development and release cycles of six months or less. In an industry where the average life expectancy of an automotive production line is eight years, it is impossible to expect the networking in an industrial setting to keep up with modern IT standards. Therefore, we turn our attention to the technologies that have existed the longest, with the most open standards and the very best support. These are the protocols we wish to use and keep, and this article highlights and explains some of these technologies.
refer to:
http://www.automation.com/leveraging-it-technology-for-industrial-controls-applications

2013年9月10日 星期二

Security and reliability is an utter-most issue


A factory is only as strong as its weakest link, so every Internet of Things client in the factory needs protection from viruses, malware, and hacking to prevent costly interruptions to factory operation. The 4th generation Intel Core processor adds a number of features to its security portfolio, including McAfee’s Deep Defender technology, which resides between the memory and embedded system to perform real-time memory and CPU monitoring without impacting overall system performance. (McAfee is an Associate member of the Alliance.) As shown in Figure 5 (page 22), additional security elements include multiple solutions. TenAsys also offers the INtime RTOS family, which can run as a stand-alone RTOS or alongside Microsoft Windows as shown in Figure 3. Both products enable users to partition a multicore platform to run mixed fanless embedded systems, making better use of the processor’s advanced features to provide highly integrated  solutions. (Microsoft and TenAsys are both Associate members of the Alliance.)


refer to:

Intel Core processor family is coming soon!


Throughout history, new fanless embedded systems have transformed the manufacturing industry. From the invention of steam engines to the introduction of computerized controls, these technologies have led to enormous leaps in productivity and quality. Today we are at another turning point. The introduction of embedded systems and Internet of Things technology are enabling unprecedented data sharing and analysis, turning previously disconnected manufacturing systems into an efficient, highly responsive whole.

The 4th generation Intel Core processor family is bringing the Internet of Things to the factory floor. With 2x faster signal processing, the processors support analytics applications like machine vision and equipment monitoring. Newly solutions secure communications tie together the factory floor, control room, and supply chain. And the up to 60 percent faster graphics and flexible I/O permit industrial equipment manufacturers to combine previously separate hardware, reducing cost and complexity.

refer to: