DI-NUOR-81408B
Aircraft Monitor and Control (AMAC) Preliminary Design Report (PDR) and Final Design Approval Report (FDAR)
The PDR and FDAR document the AMAC design, providing format and content preparation instructions for tasks described by MIL-STD-1822 related to aircraft avionics nuclear weapon interfaces.
Approval DateFebruary 17, 2015
AMSC NumberF9516
Preparing Activity27
Project NumberNUOR-2015-003
OPR—
DTIC Applicable—
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The PDR and FDAR document the AMAC design.
a. This data item description (DID) contains the format and content preparation instructions for the tasks described by MIL-STD-1822.
b. This DID is related to and contains aspects of the following documents: Specification Standard No. SYS 1001, System 1 Basic Interface Specifications, Specification Standard No. SYS 2001, System 2 Basic Interface Specifications, and DI-NUOR-81409 (Certification Requirements Plan (CRP), which defines the preparation task and submittal schedule for the PDR and FDAR. SYS 1001 and SYS 2001 are published by the AFNWC.
(Copies of the DID and MIL-STD-1822 are available online at http://assist.dla.mil/quicksearch/ or from the Standardization Document Order Desk, 700 Robbins Ave., Bldg 4D, Philadelphia PA 19111-5094 and copies of the AMAC POG System Specifications are available from the AFNWC, 8601 Frost Ave SE, Building 20203, Kirtland AFB, NM 87117-5624.)
Preparation Instructions
1Reference documents.The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices and revisions, shall be as specified in the solicitation or contract.
2Format.Contractor format is acceptable.
3Content.The PDR and FDAR will have different but similar content; the PDR will be a preliminary version of the FDAR. The PDR must contain a report of hardware and software/firmware information, which must describe and define the design concept to the extent that the components, as well as the operational capability of the system, are clearly understood. The PDR shall be completed prior to finalization of all design details and shall be completed by a time sufficiently in advance of final design submittal as to allow for design changes. The FDAR must contain a complete description and analysis for the AMAC system as installed on the operational aircraft. The detailed analysis shall include hardware and software/firmware designs. The analysis shall demonstrate compliance with the appropriate AMAC system interface specification, the Weapon Specific Addendum, and the Platform Store Interface Control document criteria. All FDAR content is kept up-to-date as changes are made to the AMAC hardware, software, and firmware, throughout the life of the aircraft system, as long as it is in the inventory. Definitions and analysis of changes to the AMAC hardware, firmware, and software will be provided as an addendum to the existing FDAR. Updates to software/firmware will be identified and detailed sufficiently as to present a clear understanding of the impacts due to the update. This addendum will be submitted to the AFNWC and Sandia National Laboratory for review and approval. The PDR and FDAR shall include the following:
3.1Introduction.The introductory section shall describe the requirement(s) that the PDR and FDAR will satisfy and the purpose and scope for the PDR and FDAR (i.e., any limitations on the description or analysis of the AMAC system). The introduction should briefly describe the contents of each section, addendum and appendix.
3.2Applicable documents.This section shall contain the following information:
3.2.1Applicability.This subsection defines the relevancy of the documents listed in the applicable documents section and the hierarchy of the applicable documents.
3.2.2Government documents.This subsection defines the applicable government reference documents that are pertinent to the descriptions and analyses in the PDR and FDAR.
3.2.3Contractor's documentation.This subsection defines the contractor's reference documentation that is applicable to the descriptions and analyses presented in the PDR and FDAR.
3.3AMAC configuration.This section shall describe the aircraft hardware and processor software incorporated in the AMAC system. This section shall contain the information defined in the following paragraphs:
3.3.1Overview.This subsection gives a functional overview of the complete AMAC system. This subsection briefly describes the role of each component in the AMAC system and the relative dedication of the component's function to the AMAC system function. Special points to consider in this subsection are: whether AMAC control in this aircraft is hardwired, whether the AMAC function is distributed throughout the avionics system or not, and the method of communications between all of the various components of the AMAC system (i.e., the message protocol involved).
3.3.2Aircraft avionics nuclear configuration.This subsection describes the nuclear configuration of the aircraft's avionic system. The nuclear configuration consists of the hardware and processor software/firmware that directly or indirectly controls the monitor in which the nuclear weapon interfaces. The components of the avionics system that are defined as the nuclear configuration must be subjected to the controls necessary to maintain nuclear weapon compatibility throughout the service life of the aircraft system. This subsection describes as part of the nuclear configuration any nuclear input devices and displays the aircrew uses to monitor the status of nuclear weapons or control nuclear weapons. This subsection includes a detailed text description of the function of each component of the nuclear configuration with figures and diagrams used to clarify the text portion, but not in lieu of a text description.
3.3.3System hardware configuration.This subsection describes the avionics hardware that constitutes the AMAC system of the aircraft. It describes the avionics hardware in the aircraft's navigation subsystem, weapons delivery subsystem, controls and displays subsystems, and the stores management subsystems as they relate to the AMAC system function. This subsection also describes the aircraft's avionics processors and their role in the AMAC system.
3.3.4System software/firmware configuration.This subsection describes the avionics flight software/firmware that participates in the tasks of controlling and monitoring the nuclear weapon interfaces. If the avionics flight software/firmware is stored on a nonvolatile media and then loaded into the avionics processor for operation, this subsection describes the transfer process and the initialization of the avionics processors until the avionics system is fully functional. This subsection describes the avionics system executive software/firmware, the weapon delivery system software/firmware, and the controls and displays software/firmware as they relate to the AMAC system function. Isolation of the AMAC functions will also be described.
3.4AMAC design analysis.This section shall contain the information described in paragraphs 3.4.1 through 3.4.4 below. The first and second subsections shall use the system hardware and software/firmware configurations to define where the appropriate AMAC requirements are satisfied and where they are not. The third and fourth subsection shall take a systems approach in the analysis of the avionic system to follow all design constraints in monitoring and controlling nuclear weapons. For the purposes of this DID, a system approach is defined as tracing each signal that goes into or comes out of the nuclear weapons connector through each hardware and software/firmware component of the AMAC functions that are integrated into the avionics system.
3.4.1System hardware design analysis.This subsection shall describe the hardware interaction and the sequence of events that take place from the time the aircrew member initiates an operator input to the controls and display subsystem of the aircraft's avionics, through the hardware interfaces, until that operator's input results in a signal which appears at the nuclear weapon interface. This design analysis shall cover all of the hardware components as they relate to each system interface requirement as a group, if the AMAC functions are distributed throughout various avionic subsystems. To demonstrate the ability of the AMAC system to meet the requirements of electrical loading with respect to one nuclear weapon interface only, in cases where the aircraft has a multi-station capability, the analysis of those weapon disconnect stations that could be used at the same time as the station being analyzed will also have loads applied. To demonstrate compliance, it is permissible to use maximum DC bus loadings that encompass future increases in aircraft bus loading in lieu of additional electrical station loads on multi-station nuclear weapon capable aircraft.
3.4.2System software/firmware design analysis.This subsection shall provide an analysis for the design of the avionics software/firmware as it relates to the AMAC of nuclear weapons. It shall also provide an analysis of the implementation of the authorization, safing, prearming, launch, and release signals in the avionic systems software/firmware (this includes avionic software executive program). The analysis shall describe how the implementation meets or fails the design criteria of SYS 1001 (System 1) or SYS 2001 (System 2) Specification. The analysis shall provide any underlying rationale or criteria used, if the analysis is used as the basis to recommend certification of software/firmware. A description of the software validation and qualification processes shall be provided. Compliance shall be shown by a description of hardware/software/firmware that controls the nuclear weapon interface.
3.4.3System monitor design analysis.This analysis shall describe the nuclear weapon monitor function as it exists in the aircraft's avionics system. The analysis shall show the software/firmware and hardware signal path from the aircrew members' input into the AMAC system to the response of that input at the weapons interface. The analysis shall also show the software/firmware signal path in the context of the hardware and physical interconnections that the software/firmware signals sequence through and the actions that the system hardware takes in response to those software commands.
3.4.4System control design analysis.This subsection shall describe the nuclear weapon control function as it exists in the aircrafts avionics system. The analysis shall show the software/firmware signal path in the context of the hardware and physical interconnections that the software/firmware signals sequence through and the actions that the system hardware takes in response to those software/firmware commands. This subsection shall show the software/firmware and hardware signal path from the aircrew members input into the AMAC system to the response of the input at the weapon's interface.
3.5Aircraft suspension and release equipment.This section shall describe and analyze the suspension and release equipment used on the aircraft and their relationship to the AMAC function. The requirements of this section pertain to internal aircraft suspension and release systems, like rotary launchers, and to the external carriage of nuclear munitions on pylons. The hardware and software/firmware analysis of the suspension and release equipment shall be the same as section 3.4.
3.6Test equipment.This section shall describe the test equipment used in the testing of the nuclear configuration components of the avionics system, weapon preload testing, and other nuclear weapon interface testing. This section shall also describe the configuration (hardware and software/firmware) of automatic testers used in the avionics testing, the type of testing, and the pass or fail criteria of the unit when testing nuclear configured line replaceable units. This section shall also describe the steps taken to prevent degradation of nuclear capability of the avionics when using testers.
3.7Appendices or addenda.To keep the main body of the PDR and FDAR as clear as possible appendices or addenda shall be used to present supporting design material. Information contained in existing documents shall be referenced rather than repeated. The following support design material is required:
3.7.1Avionics system (diagrams and text).
3.7.2Interface definition for the weapons interface unit(s) and the interface specifications for all interfaces that the software signal path analysis defines.
3.7.3Timelines (timing sequences and timing diagrams as they relate to the AMAC functions release of the nuclear weapons).
3.7.4Maintenance logic diagrams (for the key components of the nuclear weapon delivery system).
3.7.5Nuclear weapon delivery system line replaceable unit schematics.
3.7.6Software/firmware compatibility (listing Computer Program Identification Numbers (CPINs) for the avionics flight software/firmware versions currently in use at operational bases).The following items should also be included.
3.7.6.1Software/firmware signal path definition diagrams.
3.7.6.2An analysis of the AMAC compatibility of each software/firmware package listed in the CPIN list.This shall include:
3.7.6.2.1Software/firmware problems and analysis including technical order work-arounds, as appropriate.
3.7.6.2.2A review and analysis for all software/firmware patches and changes to the source code since the last recompile.
3.7.6.2.3A summary of software/firmware verification requirements, test requirements, test results and any test limitations.
3.7.6.3A description of all software/firmware documentation pertinent to the current avionics flight software/firmware packages in use at operational bases.
Schema v3.0Community-maintained · Verify against ASSIST