SlideShare a Scribd company logo
1 of 12
High Integrity Solutions
Dave Harper
Systems Engineer
4th February 2015
Introduction
• Implementation of a High Integrity NTP
system for Air Traffic Control
– Air Traffic Control
– Supporting Systems
– Safety Requirements
– Failure Modes
– Solution to provide NTP service
– Conclusion
Air Traffic Control System
Controller Screen: Heathrow Approach
Safety Requirements
• Depends on criticality of service
– Voice Comms
– Surveillance
• Probability of Failure <1 in 10,000,000 hours
• No undesirable failure modes
• Safety Management System
• Rarely achieved by COTS products
Reliability
• Electronic hardware – random
– Typical equipment MTBF 50k-100k hours
• Software – systematic
– For commercial software limit is 10k hours
• How do we meet the Safety Requirements?
– Bespoke
– Innovative use of commercially available
equipment.
Time Distribution
• Time data by serial interface
• Originally bespoke
• Network Time Protocol
• Improved performance at less cost
NTP Clock Strata
NTP Time Distribution Solution
NTP Servers
Switches
Routers with firewall
NTP clients
A B C
Aircraft Reliability
Conclusions
• NTP service for ATC
– Meets safety requirements using COTS
equipment.
– Better performance
– Less cost
• Sometimes only a bespoke solution will do.
Contact Details
• Email: d53harper@gmail.com
• Tel: 07771 805969

More Related Content

What's hot

Analysis and Design of PID controller with control parameters in MATLAB and S...
Analysis and Design of PID controller with control parameters in MATLAB and S...Analysis and Design of PID controller with control parameters in MATLAB and S...
Analysis and Design of PID controller with control parameters in MATLAB and S...MIbrar4
 
Atc Solution From Rittal
Atc Solution From RittalAtc Solution From Rittal
Atc Solution From Rittalabhinav
 
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...ManageEngine, Zoho Corporation
 
Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...
Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...
Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...adil raja
 
Rockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation
 
Jeda Hls Hlv Success Story V4
Jeda Hls Hlv Success Story V4Jeda Hls Hlv Success Story V4
Jeda Hls Hlv Success Story V4Chun Xia
 
Free OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automationFree OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automationManageEngine, Zoho Corporation
 
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...PROIDEA
 
FTView SE Alarm Notifications
FTView SE Alarm NotificationsFTView SE Alarm Notifications
FTView SE Alarm NotificationsESE, Inc.
 
Deltalink knowledge thursday 2014 QNAP solutions
Deltalink knowledge thursday 2014 QNAP solutionsDeltalink knowledge thursday 2014 QNAP solutions
Deltalink knowledge thursday 2014 QNAP solutionsDeltalink
 
Western Power Distribution Presentation Distributed Community Energy Low Carb...
Western Power Distribution Presentation Distributed Community Energy Low Carb...Western Power Distribution Presentation Distributed Community Energy Low Carb...
Western Power Distribution Presentation Distributed Community Energy Low Carb...The Future Economy Network
 

What's hot (18)

Analysis and Design of PID controller with control parameters in MATLAB and S...
Analysis and Design of PID controller with control parameters in MATLAB and S...Analysis and Design of PID controller with control parameters in MATLAB and S...
Analysis and Design of PID controller with control parameters in MATLAB and S...
 
PPT_16-9_Template
PPT_16-9_TemplatePPT_16-9_Template
PPT_16-9_Template
 
Atc Solution From Rittal
Atc Solution From RittalAtc Solution From Rittal
Atc Solution From Rittal
 
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
Understanding firewall-policies-their-effectiveness-in-defending-against-netw...
 
Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...
Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...
Implementation of a Non-Intrusive Speech Quality Assessment Tool on a Mid-Net...
 
TCL Control Systems
TCL Control SystemsTCL Control Systems
TCL Control Systems
 
Pierre
PierrePierre
Pierre
 
Rockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCARockwell Automation TechED 2017 - AP14 - MRWPCA
Rockwell Automation TechED 2017 - AP14 - MRWPCA
 
To be smart or not to be?
To be smart or not to be?To be smart or not to be?
To be smart or not to be?
 
Jeda Hls Hlv Success Story V4
Jeda Hls Hlv Success Story V4Jeda Hls Hlv Success Story V4
Jeda Hls Hlv Success Story V4
 
Risk assessment
Risk assessmentRisk assessment
Risk assessment
 
Free OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automationFree OpManager training Part 4 - Fault Management and IT automation
Free OpManager training Part 4 - Fault Management and IT automation
 
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
 
sairam_CV
sairam_CVsairam_CV
sairam_CV
 
FTView SE Alarm Notifications
FTView SE Alarm NotificationsFTView SE Alarm Notifications
FTView SE Alarm Notifications
 
Deltalink knowledge thursday 2014 QNAP solutions
Deltalink knowledge thursday 2014 QNAP solutionsDeltalink knowledge thursday 2014 QNAP solutions
Deltalink knowledge thursday 2014 QNAP solutions
 
Smart house web page
Smart house web pageSmart house web page
Smart house web page
 
Western Power Distribution Presentation Distributed Community Energy Low Carb...
Western Power Distribution Presentation Distributed Community Energy Low Carb...Western Power Distribution Presentation Distributed Community Energy Low Carb...
Western Power Distribution Presentation Distributed Community Energy Low Carb...
 

Similar to High Integrity Solutions 2

Methods for Improving NTP
Methods for Improving NTPMethods for Improving NTP
Methods for Improving NTPADVA
 
Introducing ultra-precise time for server-hosted applications
Introducing ultra-precise time for server-hosted applicationsIntroducing ultra-precise time for server-hosted applications
Introducing ultra-precise time for server-hosted applicationsADVA
 
Improving NTP Installed Base Time Accuracy
Improving NTP Installed Base Time AccuracyImproving NTP Installed Base Time Accuracy
Improving NTP Installed Base Time AccuracyADVA
 
Enabling Carrier-Grade Availability Within a Cloud Infrastructure
Enabling Carrier-Grade Availability Within a Cloud InfrastructureEnabling Carrier-Grade Availability Within a Cloud Infrastructure
Enabling Carrier-Grade Availability Within a Cloud InfrastructureOPNFV
 
FTC Group Presentation
FTC Group PresentationFTC Group Presentation
FTC Group PresentationArman Nasar
 
Lecture+9+-+SCADA+Systems.pdf
Lecture+9+-+SCADA+Systems.pdfLecture+9+-+SCADA+Systems.pdf
Lecture+9+-+SCADA+Systems.pdfSmritiGarg21
 
Fdp embedded systems
Fdp embedded systemsFdp embedded systems
Fdp embedded systemsKavya G
 
Time Critical Networks
Time Critical NetworksTime Critical Networks
Time Critical NetworksLars Bröhne
 
Siemens-profinet-rt-vs-irt-webinar-13oct2020.pdf
Siemens-profinet-rt-vs-irt-webinar-13oct2020.pdfSiemens-profinet-rt-vs-irt-webinar-13oct2020.pdf
Siemens-profinet-rt-vs-irt-webinar-13oct2020.pdfFranciscoVillar21
 
5G URLLC (Ultra Reliable Low Latency Communications)
5G URLLC (Ultra Reliable Low Latency Communications) 5G URLLC (Ultra Reliable Low Latency Communications)
5G URLLC (Ultra Reliable Low Latency Communications) Abhijeet Kumar
 
Himss 2000 talk satellitetelecom via dama
Himss 2000 talk satellitetelecom via damaHimss 2000 talk satellitetelecom via dama
Himss 2000 talk satellitetelecom via damaFrank Meissner
 
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSDeepak Shankar
 
FieldServer Overview 2015.r1
FieldServer Overview 2015.r1FieldServer Overview 2015.r1
FieldServer Overview 2015.r1Eric W Dunn
 
Lecture+9+-+SCADA+Systems.pptx
Lecture+9+-+SCADA+Systems.pptxLecture+9+-+SCADA+Systems.pptx
Lecture+9+-+SCADA+Systems.pptxsurangagw
 

Similar to High Integrity Solutions 2 (20)

Cip motion cip sync
Cip motion   cip sync Cip motion   cip sync
Cip motion cip sync
 
Methods for Improving NTP
Methods for Improving NTPMethods for Improving NTP
Methods for Improving NTP
 
Introducing ultra-precise time for server-hosted applications
Introducing ultra-precise time for server-hosted applicationsIntroducing ultra-precise time for server-hosted applications
Introducing ultra-precise time for server-hosted applications
 
Improving NTP Installed Base Time Accuracy
Improving NTP Installed Base Time AccuracyImproving NTP Installed Base Time Accuracy
Improving NTP Installed Base Time Accuracy
 
Enabling Carrier-Grade Availability Within a Cloud Infrastructure
Enabling Carrier-Grade Availability Within a Cloud InfrastructureEnabling Carrier-Grade Availability Within a Cloud Infrastructure
Enabling Carrier-Grade Availability Within a Cloud Infrastructure
 
FieldServer for Integrators Overview
FieldServer for Integrators OverviewFieldServer for Integrators Overview
FieldServer for Integrators Overview
 
Embedded
EmbeddedEmbedded
Embedded
 
Smart Networks for the Industrial Internet of Things
Smart Networks for the Industrial Internet of ThingsSmart Networks for the Industrial Internet of Things
Smart Networks for the Industrial Internet of Things
 
FTC Group Presentation
FTC Group PresentationFTC Group Presentation
FTC Group Presentation
 
SMC Corporate Overview
SMC Corporate OverviewSMC Corporate Overview
SMC Corporate Overview
 
Lecture+9+-+SCADA+Systems.pdf
Lecture+9+-+SCADA+Systems.pdfLecture+9+-+SCADA+Systems.pdf
Lecture+9+-+SCADA+Systems.pdf
 
Fdp embedded systems
Fdp embedded systemsFdp embedded systems
Fdp embedded systems
 
Chapter02
Chapter02Chapter02
Chapter02
 
Time Critical Networks
Time Critical NetworksTime Critical Networks
Time Critical Networks
 
Siemens-profinet-rt-vs-irt-webinar-13oct2020.pdf
Siemens-profinet-rt-vs-irt-webinar-13oct2020.pdfSiemens-profinet-rt-vs-irt-webinar-13oct2020.pdf
Siemens-profinet-rt-vs-irt-webinar-13oct2020.pdf
 
5G URLLC (Ultra Reliable Low Latency Communications)
5G URLLC (Ultra Reliable Low Latency Communications) 5G URLLC (Ultra Reliable Low Latency Communications)
5G URLLC (Ultra Reliable Low Latency Communications)
 
Himss 2000 talk satellitetelecom via dama
Himss 2000 talk satellitetelecom via damaHimss 2000 talk satellitetelecom via dama
Himss 2000 talk satellitetelecom via dama
 
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
 
FieldServer Overview 2015.r1
FieldServer Overview 2015.r1FieldServer Overview 2015.r1
FieldServer Overview 2015.r1
 
Lecture+9+-+SCADA+Systems.pptx
Lecture+9+-+SCADA+Systems.pptxLecture+9+-+SCADA+Systems.pptx
Lecture+9+-+SCADA+Systems.pptx
 

High Integrity Solutions 2

Editor's Notes

  1. Today we will be looking at the way we tackled the implementation of a new Time Distribution system for ATC, with very high integrity requirements.
  2. An example of data integration between systems. This is an example of a controller’s surveillance screen. Data from the FDP system is added to enable the controller to identify aircraft by flight number. Destination also, and cleared flight level.
  3. To devise a way to meet the safety requirements we need to consider how systems fail. System reliability includes all parts of the system, including hardware, software, supporting infrastructure (including critical external interfaces), operators and procedures. Hardware faults occur randomly due to component failures and are not usually related to how it is used; they are state independent. Hardware reliability is usually simply calculated but considers all failures to be equal – not realistic. Need further analysis to arrive at dangerous failures. Software faults are usually bugs, the result of unanticipated results of software operations. Reset it to get it working again, but it will reappear when the same situation occurs, hence they are systematic. Typical quoted reliability is 50k to 100k hours, short of our targets. If the system uses software (most do) the best you can claim is 10,000 hours (CAA/SRG figures – allowance for commercial systems) with systematic failures dominating. A typical requirement is 1 in 10E7, pretty difficult. Bespoke solutions are possible, and were common in the past, but very expensive and risky. What we need is an innovative solution using inexpensive equipment that meets the requirement.
  4. Many ATC systems need a time of day feed, ranging from wall and console clocks to Surveillance Data Processing. The latter has a major safety requirement of the order of 10^7. The earliest systems were bespoke designs and some are still in use today. Serial ASCII data was the norm, with specific cabling to each clock and system, different for each application and expensive to own. Network Time Protocol has now emerged as the standard for distribution of time of day. This has evolved from the internet world and is capable of giving a very accurate indication of time, even over packet networks. It is cheaper to implement since it is distributed over a WAN or LAN, with no dedicated cabling.
  5. Stratum 0 clocks are atomic clocks. GPS signals are based on atomic clocks. The NTP servers are at Stratum 1. Clients systems interface at Stratum 2 and may distribute to lower levels.
  6. Ways to use COTS. Put in two? No, because there are common cause failures due to software, so redundancy gains little and it gives NTP a problem if they disagree. That gives NTP a problem if they disagree. The answer is to put in three with minimal (and understood) common failure causes – different software, hardware, chipset, GPS engine, everything. How do you assess when there are suppliers who want to keep their designs secret? You source from the ones who co-operate! We arrive at a system design like this, a 1 out of 3 architecture. Three NTP servers are from different suppliers with a thorough assessment to satisfy ourselves that there are minimal common cause failures.
  7. So if ATC has difficult requirements, what about the customer? The wing is a critical component. Can only have one so it must be designed to be fit for purpose. Two engines, can fly on just one. Failures are usually independent – but common causes have been known. Like the 777 that just managed to glide into Heathrow after fuel had frozen causing both engines to stop. Airbus use a 1 out of 3 fly-by-wire system. Other on board systems use multiple instances to ensure reliability.
  8. Requirement achieved by using features of the protocol and a 1 out of 3 architecture.