Standard Practice for Methods to Safely Bound Flight Behavior of Unmanned Aircraft Systems Containing Complex Functions

SCOPE
1.1 This standard practice defines design and test best practices that if followed, would provide guidance to an applicant for providing evidence to the civil aviation authority (CAA) that the flight behavior of an unmanned aircraft system (UAS) containing complex function(s) is constrained through a run-time assurance (RTA) architecture to maintain an acceptable level of flight safety.  
1.2 This practice will have the benefit of enabling highly automated UAS operations. It is envisioned that applicants will use this practice as a means of compliance for safe implementation of complex functions for routine operations.  
1.3 Verification of complex functions is considered too challenging to use conventional software assurance methods such as RTCA DO-178C or IEC 61508. Certification challenges under these standards include generating required artifacts, such as requirements, elimination of unintended functionality, traceability/coverage, and test cases required for verification.  
1.4 There is significant interest from industry and CAAs to have a standard practice to enable flight operations for UAS containing complex functions. Developing a certification path for these UAS technologies could also advance safety in General Aviation.  
1.5 The following design tenets are offered to provide guidance to the UAS manufacturer as to the intended application of this standard.  
1.5.1 The RTA Architecture is intended to be used for Complex Functions that would require an amount of effort that is beyond reasonably practicable to pass CAA conventional certification requirements.  
1.5.2 The UAS manufacturer should engage in appropriate design, test, and validation activities to enable the Complex Function to perform as intended.  
1.5.3 The complexity of the Recovery Control Function (RCF) deterministic commands should be minimized insofar as practicable.  
1.5.4 Repeated invocation of an RCF during a single mission may be considered an indication of improper Complex Function performance.  
1.5.5 An RTA design with multiple RCFs should consider the aircraft state, relative outcomes, and differences in RTA recovery times in prioritizing the recovery actions in the safety monitor.  
1.5.6 The UAS manufacturer should strive to minimize false or nuisance triggers of one or more RCFs as these false alarms undermine user confidence in the system and impact operational efficiency.  
1.6 This standard does not purport to address all of the safety concerns, if any, associated with its use. It is the responsibility of the user of this standard to establish appropriate safety, health, and environmental practices and determine the applicability of regulatory limitations prior to use.  
1.7 This international standard was developed in accordance with internationally recognized principles on standardization established in the Decision on Principles for the Development of International Standards, Guides and Recommendations issued by the World Trade Organization Technical Barriers to Trade (TBT) Committee.

General Information

Status
Historical
Publication Date
31-Aug-2017
Drafting Committee
Current Stage
Ref Project

Buy Standard

Standard
ASTM F3269-17 - Standard Practice for Methods to Safely Bound Flight Behavior of Unmanned Aircraft Systems Containing Complex Functions
English language
9 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)

NOTICE: This standard has either been superseded and replaced by a new version or withdrawn.
Contact ASTM International (www.astm.org) for the latest information
Designation: F3269 − 17
Standard Practice for
Methods to Safely Bound Flight Behavior of Unmanned
1
Aircraft Systems Containing Complex Functions
This standard is issued under the fixed designation F3269; the number immediately following the designation indicates the year of
original adoption or, in the case of revision, the year of last revision. A number in parentheses indicates the year of last reapproval. A
superscript epsilon (´) indicates an editorial change since the last revision or reapproval.
1. Scope 1.5.3 The complexity of the Recovery Control Function
(RCF)deterministiccommandsshouldbeminimizedinsofaras
1.1 This standard practice defines design and test best
practicable.
practices that if followed, would provide guidance to an
1.5.4 Repeated invocation of an RCF during a single mis-
applicant for providing evidence to the civil aviation authority
sion may be considered an indication of improper Complex
(CAA) that the flight behavior of an unmanned aircraft system
Function performance.
(UAS)containingcomplexfunction(s)isconstrainedthrougha
1.5.5 An RTA design with multiple RCFs should consider
run-time assurance (RTA) architecture to maintain an accept-
the aircraft state, relative outcomes, and differences in RTA
able level of flight safety.
recovery times in prioritizing the recovery actions in the safety
1.2 This practice will have the benefit of enabling highly
monitor.
automatedUASoperations.Itisenvisionedthatapplicantswill
1.5.6 The UAS manufacturer should strive to minimize
use this practice as a means of compliance for safe implemen-
false or nuisance triggers of one or more RCFs as these false
tation of complex functions for routine operations.
alarms undermine user confidence in the system and impact
operational efficiency.
1.3 Verification of complex functions is considered too
challenging to use conventional software assurance methods 1.6 This standard does not purport to address all of the
safety concerns, if any, associated with its use. It is the
such as RTCA DO-178C or IEC 61508. Certification chal-
lenges under these standards include generating required responsibility of the user of this standard to establish appro-
priate safety, health, and environmental practices and deter-
artifacts, such as requirements, elimination of unintended
functionality, traceability/coverage, and test cases required for mine the applicability of regulatory limitations prior to use.
1.7 This international standard was developed in accor-
verification.
dance with internationally recognized principles on standard-
1.4 There is significant interest from industry and CAAs to
ization established in the Decision on Principles for the
have a standard practice to enable flight operations for UAS
Development of International Standards, Guides and Recom-
containing complex functions. Developing a certification path
mendations issued by the World Trade Organization Technical
for these UAS technologies could also advance safety in
Barriers to Trade (TBT) Committee.
General Aviation.
2. Referenced Documents
1.5 The following design tenets are offered to provide
2
guidance to the UAS manufacturer as to the intended applica-
2.1 ASTM Standards:
tion of this standard.
F3201 Practice for Ensuring Dependability of Software
1.5.1 The RTA Architecture is intended to be used for
Used in Unmanned Aircraft Systems (UAS)
Complex Functions that would require an amount of effort that
F3178 Practice for Operational Risk Assessment of Small
is beyond reasonably practicable to pass CAA conventional
Unmanned Aircraft Systems (sUAS)
certification requirements.
2.2 Civil Standards, Policy, and Guidance:
1.5.2 The UAS manufacturer should engage in appropriate
IEC 61508 Functional Safety of Electrical/Electronic/
3
design, test, and validation activities to enable the Complex
Programmable Electronic Safety-Related Systems
Function to perform as intended.
2
For referenced ASTM standards, visit the ASTM website, www.astm.org, or
contact ASTM Customer Service at service@astm.org. For Annual Book of ASTM
1
This practice is under the jurisdiction ofASTM Committee F38 on Unmanned Standards volume information, refer to the standard’s Document Summary page on
Aircraft Systems and is the direct responsibility of Subcommittee F38.01 on the ASTM website.
3
Airworthiness. Available from International Electrotechnical Commission (IEC), 3, rue de
Current edition approved Sept. 1, 2017. Published September 2017. DOI: Varembé, 1st Floor, P.O. Box 131, CH-1211, Geneva 20, Switzerland, http://
10.1520/F3269-17. www.iec.ch.
Copyright © ASTM International, 100 Barr Harbor Drive, PO Box C700, West Conshohocken, PA 19428-2959. United States
1

---------------------- Page: 1 ----------------------
F3269 − 17
RTCA DO-178C Software Considerations in Airborne Sys- is taken before the UAS violates a pre-define
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.