We present an approach for protected contingency online planning in high-risk environments with strict regulatory boundary conditions. For this purpose, we integrate a deterministic online planning method into a UAM path planning framework, which operates within precomputed convex regions of obstacle-free space. As part of an offline planning phase, a database of trajectories and convex, obstacle-free regions along these trajectories are computed. During the online phase, transitions between any two preplanned trajectories inside the same region can be computed using a planning method with performance-guaranteed maneuvres. Within a given envelope of environmental disturbances, our method guarantees to contain the flight path inside its convex region, while ensuring deterministic attributes. We demonstrate the method in a scenario representing the intended application and give estimations for offline computation time on desktop-grade hardware.
We present a novel approach to enable provably safe contingency path planning in complex high-risk environments within a strict regulatory framework. We decompose the flight planning task between a network of vertiports into an offline and an online phase. This work focuses on the offline phase covering the flight planning, which can be validated to fulfill regulatory boundary conditions and target safety levels before flight. In the online phase the planning task is collapsed to a trajectory selection problem, which is low dimensional and provides only solutions with guaranteed feasibility. The proposed method computes a tree of trajectories with constant time separation of branches and leading to both the destination and diversion vertiports from each fork point. We further extend the planning tree with motion primitives to enable transitions between flight levels and local holding patterns for temporal deconfliction without a change of the lateral flight profile. We demonstrate the method in a realistic urban scenario and provide metrics for memory and time complexity of the algorithm.
In this paper, we present an approach for simplified path planning for unmanned aerial vehicles (UAVs) in obstacle-dense high-risk areas. We reduce the complexity of the 3D planning problem to that of a 2D planning problem by leveraging regulatory restrictions and guidelines as well as mission-specific boundary conditions to simplify the configuration space. This is achieved through strict limitations and a projection of the search space into a quasi-2D plane. We further suggest a modular motion planning architecture of multiple planners, each of which is taylored to a specific flight phase and displays deterministic behaviour in memory and runtime complexity. Through the integration of regulatory considerations, we seek to provide a planning result that complies with future regulations for flights over congested areas beyond the visual line of sight (BVLOS) and allows feasible solutions for dense multi-vehicle operation of urban routes. In addition to the methodological approach, we introduce the application of image processing techniques to the generation of roadmaps from available maps. We apply the method to a mission scenario of realistic extend and show how it scales to obstacle-dense environments. The results indicate that efficient pre-processing of environment data can enable regulation-compliant path-planning for UAVs in urban environments on consumer hardware.
Unmanned Aerial System (UAS) operations in Europe are possible under the so-called Open, Specific and - in the future - Certified Category. The Specific Category is inherently coupled with the Specific Operation Risk Assessment (SORA) as Acceptable Means of Compliance (AMC). We leverage the existing methodology of SORA as an AMC to propose a novel method for high risk operations over congested areas with a modular data-driven approach. Due to the amount of data and risk classes involved, this is a difficult problem, which requires the fusion of the available information in order to generate feasible solutions. Hence, we propose an approach, which employs heterogeneous geospatial data sets from dissimilar sources to derive metrics for operational risk. Aircraft and mission specific parameters, as well as regulatory requirements are modeled into each risk layer. This process allows for highly accurate and multi-dimensional models of risks associated with the intrinsic mission parameters. As a potential application, we evaluate the effect of high-dimensional risk models on the UAS path planning process of risk-minimal paths in realistic scenarios. We demonstrate the proposed method using commonly available APIs to derive 3D risk maps based on a variety of data classes. Test results show that comprehensive mission and vehicle specific risk data bases covering areas greater 100 km(2) can be generated on consumer hardware within a sub-hour timeframe.
This paper presents a performance assessment of a method to generate trajectories for a small unmanned rotorcraft within an obstacle field using a standardized set of benchmark scenarios. The dynamics of the rotorcraft are discretized into a set of motion primitives. For the generation of these primitives a formulation of a path-tracking optimal control problem is used. This optimal control problem has been previously shown to achieve trajectories that can be flown very accurately in flight tests. The generated primitives are used to convert the original task within the obstacle field into a discretized planning problem using sequential decision making that is solved using an optimal graph search algorithm (e.g., Dijkstra). This algorithm selects from and combines the available motion primitives to achieve the transition between a start and a goal waypoint in minimum time. We present results of this planning approach and include a scaling analysis for simple artificial as well as more complex urban environments.
Recent regulatory efforts from EASA introduced the new concept of a specific category that allows a stepwise adaptation of certification requirements. Based on a specific operation risk assessment, this category enables new aircraft system architectures and mission designs. The concept allows for operational restrictions, defined in the concept of operations, to maintain overall operation safety. Therefore, the description of the concept of operations is one of the key elements for the approval of a UAS operation. This description will be used by pilots, operators, certification authorities and possibly additional stakeholders, e.g., for publishing operation into databases. Standardization of this document seems mandatory. In addition to this, we discuss the formalization of this document for easy distribution amongst stakeholders and establishment of tool support. To support this, we use recent developments regarding standardization of simulation modeling. The American Institute of Aeronautics and Astronautics Modeling and Simulation Technical Committee recently launched a working group towards the development of a standard scenario definition language for aviation. In this paper, we extend this language specification in order to define specific operation safety boundaries of a system. Thereby, we aim at creating a dialect of the simulation scenario definition language that can be used to describe safe scenarios for a particular system of interest. We further discuss the challenges and benefits of such a formalization of the concept of operations by adapting the simulation scenario definition language.
Civil Aviation Authorities are elaborating a new regulatory framework for the safe operation of Unmanned Aircraft Systems (UAS). Current proposals are based on the analysis of the specific risks of the operation as well as on the definition of some risk mitigation measures. In order to achieve the target level of safety, we propose increasing the level of automation by providing the on-board system with Automated Contingency Management functions. The aim of the resulting Safe Mission Manager System is to autonomously adapt to contingency events while still achieving mission objectives through the degradation of mission performance. In this paper, we discuss some of the architectural issues in designing this system. The resulting architecture makes a conceptual differentiation between event monitoring, decision-making on a policy for dealing with contingencies and the execution of the corresponding policy. We also discuss how to allocate the different Safe Mission Manager components to a partitioned, Integrated Modular Avionics architecture. Finally, determinism and predictability are key aspects in contingency management due to their overall impact on safety. For this reason, we model and verify the correctness of a contingency management policy using formal methods.
Future unmanned aircraft are expected to be autonomous, perform missions automatically, and act intelligently when unforeseen events or degraded situations occur. This results in enormous complexity for modeling and computing the system states, system behavior, and environmental data. Furthermore, the aerospace domain is a safety-critical domain, enforcing specific levels of safety and compliance to extensive standards. Therefore, software has to be of high quality and free of safety-critical errors. But the verification and validation of a complex system, especially the high-level software components, is a critical element. Because of software complexity and the fact that the state-space of theoretically possible executions cannot be covered by testing, a holistic testing concept, utilizing complementary test methodologies, is required. This chapter discusses the high-level autonomous capabilities of the German Aerospace Center (DLR) Autonomous Research Testbed for Intelligent Systems (ARTIS) framework and focuses on the challenges and best practice approach for verification and certification for autonomous unmanned aircraft. One of the first challenges for developing an intelligent unmanned aircraft is the development of a high-quality set of requirements that describes the autonomous behavior of the system. Furthermore, this work proposes the development of a generic set of high-level requirements describing the targeted level of autonomy. To complement traditional verification methodologies, which also play an important role, model checking is also used to proof consistency of behavior and compliance to the requirements. Another way to assure safety, specifically for autonomous behavior, is to utilize runtime monitoring concepts. The idea is to supervise the execution and escalate any error as soon as it occurs to a high-level decision-making unit, such as a pilot. Furthermore, it is commonly understood that self-awareness, maintenance of information about the system status, is necessary to be able to act intelligently.
This work proposes a novel risk-based geo-fencing approach. Multiple, adjacent geo-fences are each assigned a specific risk level. An UAS with a low confidence level would be restricted to an area with no or very low risk. However, an UAS with a high confidence level could be allowed to exit such a geo-fence and cross over to another geo-fence with a different risk level. This approach enables different scenarios for the use of geo-fences and requirements for entering, flying, and leaving geo-fences of specific risk. Moreover, using runtime monitoring, the UAS can be assigned a dynamic confidence level, which represents the current and prior system health, system performance, or possibly environmental conditions. This results in a structured methodology for the independent assurance of geo-fences corresponding to specific and possibly dynamic confidence levels of an UAS. The geo-fencing problem as well as the risk-based approach is formalized in the specification language Lola, which provides a concise unambiguous mathematical foundation. Specified properties can be checked at runtime due to automatically generated monitors. This results in a trustworthy implementation, possibly enabling cost-effective UAS operation in accordance to upcoming regulations. Finally, a simulation is used as proof of concept to show the feasibility of the presented approach.
System health management is an important feature of autonomy, enhancing consistency checks, overall system robustness and even some degree of self-awareness. Seemingly unrelated, debugging and analysis of such complex systems is another challenge during development that should not be underrated. We propose that the so-called runtime monitoring of relevant properties and system requirements is a viable technique to support both aforementioned concepts. A suitable monitoring approach for a cyber-physical system has to be efficient and capable of supervising various specifications, possibly relating different data sources and data history. We present a formal approach for log-analysis and monitoring for the DLR ARTIS framework using the stream-based specification language LOLA, currently developed at Saarland University, for the runtime monitoring of formal specifications. We have evaluated this approach by specifying relevant properties as LOLA stream equations. While we have identified a number of possible improvements in the specification language, we have demonstrated, even with the current language, that online and offline monitoring of relevant properties is indeed possible and gives engineers a powerful tool for debugging as well as implementing health management concepts.
Unmanned Aircraft Systems (UAS) with autonomous decision-making capabilities are of increasing interest for a wide area of applications such as logistics and disaster recovery. In order to ensure the correct behavior of the system and to recognize hazardous situations or system faults, we applied stream runtime monitoring techniques within the DLR ARTIS (Autonomous Research Testbed for Intelligent System) family of unmanned aircraft. We present our experience from specification elicitation, instrumentation, offline log-file analysis, and online monitoring on the flight computer on a test rig. The debugging and health management support through stream runtime monitoring techniques have proven highly beneficial for system design and development. At the same time, the project has identified usability improvements to the specification language, and has influenced the design of the language.
Contingency management is a key aspect in safe operation of manned aviation. Motivated by previous work, we continue to explore how an Automated Contingency Management could be integrated into unmanned aircraft. We first discuss architectural considerations that can be integrate from the start into an unmanned aircraft system design and its derived software components. Therefore, the first part of this paper focuses on contingency management as an integral part of a system and software architecture. Due to the overall impact on functionality correctness, determinism and predictability are key aspects of contingency management. Furthermore, compliance to existing regulations in manned aviation is important for a consistent air traffic management. As a result, our approach supports high quality requirements for these contingency procedures by formalization and their validation. One way to support the formalization process is to clearly represent these requirements in a structured and pseudo formal way, which is the second focus of this paper.
Dieser Bericht umfasst die Beschreibung und die Ergebnisse der Studie Stabile Navigation und Gelandefolgeflug fur VTOL UAS, welche im Zeitraum 2013-2017 durchgefuhrt wurde. Zielrichtung dieser Studie ist die Untersuchung und Beschreibung von Methoden zur Steigerung der Automation im Bereich der Flugfuhrung von VTOL UAS. Dadurch kann der Operateur entlastet und z.B. in die Lage versetzt werden, mehr Kapazitat auf den Einsatz der UAV-Nutzlast verwenden zu konnen. Neben der Methodenentwicklung erfolgt die Erprobung und Validierung der neuen Verfahren auf einem unbemannten Versuchstrager.
This work proposes an approach to create a set of generic mission automation requirements as well as a generic execution model for unmanned aircraft. Even at the highest requirement level, regulations for unmanned aircraft are dissimilar across different countries and thus regulation still comprises lack of requirements. Due to the comparably young domain of todays unmanned vehicles, the scientific and commercial communities have difficulties to define adequate safety requirements and system requirements. This is especially the case for highly automated software functions. There is no straightforward transition from existing automation in manned aviation’s pilot assistance systems into a timely and spatially contained autonomous function. Additionally pilot abilities must be transformed into software functions. However, for unmanned aircraft certification with today’s standards the corresponding validation and verification activities are expected to require a lot of resource intensive software activities like manual inspection efforts. To support requirement validation at early development stages with respect to acceptability, we present an approach that is based on a generic autonomous systems taxonomy of capabilities. Therefore, we propose a shared set of generic high-level requirements as well as a generic mission execution model for automated mission task elements that can be performed by many types of unmanned aircraft. This way, our approach tries to support the unmanned aircraft community by a common understanding of unmanned aircraft capabilities by using existing inherited terms and concepts. Moreover, the derived requirements and models are meant to facilitate the design of automated functions that are already in use by academia and industry research today.
Onboard and online flight path planning for small-scale unmanned rotorcraft requires efficient algorithms in order to meet real-time constraints. In a priori unknown environment, rapid replanning is necessary in order to maintain a safe clearance when new obstacles are detected. The complexity of the planning problem varies vastly with the required flight path qualities and the complexity of the environment. In most scenarios flight paths should be smooth and time-efficient and always feasible to fly. Therefore, the rotorcraft's flight dynamics must be accounted for. Decoupled planning approaches have been proven to solve this problem very efficiently by dividing the problem into sequentially solvable subproblems. However, this computational efficiency comes at the cost of having to compromise on the flight path quality. In this work, we present a decoupled planning approach that has been integrated with our midiARTIS helicopter in order to perform onboard path planning when flying through a priori unknown environment. The approach involves roadmap-based global path planning and local path refinement with cubic splines. It allows to plan safe, dynamically feasible and time-efficient flight paths with limited onboard processing power. We present simulation results from a set of benchmark scenarios in complex urban terrain as well as results from flight testing of a closed-loop obstacle avoidance maneuver with virtual obstacle mapping. Our results demonstrate that close-to-optimal flight paths can be planned with a decoupled planning approach, if heuristics and simplifications for each planning step are carefully chosen.
The aerospace domain is a safety-critical domain. Therefore software has to be of high quality. Software development and testing in safety-critical domains is regulated by standards, such as DO-178B and DO-178C for the aerospace domain. However, the test approach in these standards is stochastic in nature, which means that errors in the code are tried to be identified by a large set of test cases. The trust in such software products and the overall quality is achieved by traceability to requirements and strict coverage criteria as well as general conformance to processes and rigorous documentation, but any absence of errors can usually not be proved. On the other hand, the use of formal methods for software, which is now standardized by the introduction of the Supplement DO-333, promises a true validation of certain safety-critical properties. This paper shows how formal requirements and model-checking were introduced to our test strategy for an automated planning and guidance software module. The requirements for an existing software artifact were elicited and then formalized into Linear Temporal Logic and Computation Tree Logic, which are two derivatives of temporal logic. A formal model for the software was developed and NuSMV was used as a model-checking tool to analyze the requirements in regards to the model. Furthermore, the corresponding certifcation considerations for this formal method are discussed according to the relevant standards.