Module 5 — Digital Techniques / Electronic Instrument Systems
5.1 — Electronic Instrument Systems
On this page (5)
Electronic instrument systems have replaced traditional analogue "steam gauge" instruments in modern aircraft. These systems use computers, digital data buses, and electronic displays to present flight, engine, and systems information to the crew. Understanding the architecture, components, and layout of these systems is essential for any aircraft maintenance engineer working on current-generation aircraft.
Evolution from Analogue to Digital
Traditional cockpits used individual electromechanical instruments — each driven by a dedicated sensor and displaying a single parameter on a dial or pointer. A typical analogue cockpit might contain over 100 individual instruments.
Modern glass cockpits replace these with a small number of large electronic displays driven by digital computers. This provides:
- Reduced weight and space — fewer instruments, less wiring.
- Improved reliability — fewer moving parts.
- Flexibility — displays can be reconfigured, and information presentation can change with flight phase.
- Reduced pilot workload — integrated displays combine related information.
- Built-in test — digital systems can continuously monitor themselves and report faults.
Why the One-Instrument-One-Parameter Cockpit Ran Out of Room
The limit on an electromechanical flight deck is geometry, not electronics. Every dial needs a panel cut-out inside the seated pilot's reach and visual scan, its own transducer, its own wiring run from that transducer to the panel, its own integral lighting and its own supply. Panel area is fixed by where the pilot's eyes and hands are, so adding a system means shrinking or deleting something already there. Weight, wiring length and the number of items that can fail all rise roughly in proportion to the number of parameters displayed. That proportionality is why the last generation of large analogue aeroplanes needed a third crew member sitting at a dedicated systems panel: the indications would not fit in front of two pilots. The Boeing 747-400 deleted the flight engineer's station that the earlier 747 required, and it did so by drawing the engineer's parameters on shared electronic displays instead of giving each one a gauge.
An electronic display breaks that proportionality because it is a general-purpose drawing surface. What it can present is limited by the data the computers behind it receive, not by how many holes are cut in the panel, so adding a parameter becomes a software and data-bus task rather than a structural one and costs no extra panel area. The same property is what allows a single screen to change its content with flight phase, which no dial can do.
Aviation context: electronic instrument systems replaced the indicators, not the sensing. Pitot and static pressure, total air temperature probes, thermocouples, tachometer probes, synchros and gyros are all still fitted. What changed is that their outputs are digitised, sent over a data bus and drawn as symbology, rather than being wired directly to a movement in a dial. This is worth holding on to when troubleshooting: a wrong indication on a screen has exactly the same sensing chain behind it as a wrong indication on a gauge, plus several computers.
Three Generations of Flight Deck
A line engineer meets all three of these, sometimes on the same ramp, and the fault-finding method differs sharply between them. The distinction that matters is not how old the aeroplane looks but where the information is turned into a picture.
| Generation | How the indication is produced | How data reaches the panel | Fault-finding character |
|---|---|---|---|
| Direct-reading and electromechanical | Capsules, bourdon tubes, gyros, moving-coil and synchro-driven movements inside each instrument | Pneumatic lines, thermocouple leads and individual analogue wiring runs, one chain per indication | The faulty indication identifies its own chain: one sensor, one wire, one instrument |
| Early electronic and hybrid | First-generation EFIS: colour CRT attitude and navigation displays, with conventional airspeed, altimeter and engine instruments alongside them | Digital data buses appear alongside analogue signalling; sensor data is concentrated into computers before it reaches a display | Split personality — some indications are still one-to-one, others already pass through a computer |
| Integrated glass | Large flat-panel displays drawing every flight, navigation and system indication, reconfigurable in flight | High-rate switched data networks feeding shared computing cabinets that host many functions as software | The indication no longer identifies the unit at fault; the chain must be traced through buses, computers and software configuration |
First-generation EFIS is the generation the classic exam questions describe, and it is worth being precise about what it did and did not replace. It substituted two cathode ray tubes for the attitude director indicator and the horizontal situation indicator in front of each pilot, but it left the airspeed indicator and altimeter as separate mechanical instruments. The fully integrated primary flight display — attitude in the centre with airspeed and altitude presented as moving tapes flanking it — belongs to the following generation. That history explains why exam questions about the electronic attitude director indicator list decision height, radio altitude, autoland status and flight director bars but not airspeed: on the aircraft the question was written for, airspeed was not on that tube.
From Cathode Ray Tube to Active-Matrix LCD
The display unit itself went through its own generational change, and both technologies still fly. A colour CRT display unit works exactly as a colour television tube does: three electron guns, one per primary colour, fire beams that are steered by magnetic deflection coils and land on a screen coated with triads of red, green and blue phosphor dots. A perforated metal shadow mask sits just behind the phosphor layer so that each gun's beam can only strike its own colour of dot. The anode operates at tens of kilovolts to accelerate the beams, and that high tension is the single most important hazard the unit presents to a maintenance engineer.
Two quite different writing methods are used, often on the same tube in the same picture:
- Stroke writing (also called cursive or calligraphic) steers the beam directly along the outline of the symbol to be drawn, in the way a pen is moved on paper. It produces bright, smooth, high-contrast lines with no stair-stepping, which is what attitude scales, pointers, alphanumerics and pitch ladders need.
- Raster writing scans the beam over the whole screen in a fixed pattern of horizontal lines, exactly as a television does, and modulates its brightness as it goes. It is the only practical way to fill an area, so it is what produces weather radar returns, a shaded sky-ground horizon, terrain shading and any video image.
Neither method alone is sufficient, so display units interleave them: a raster field paints the filled areas, then a stroke field overwrites the symbology on top of it, and the eye integrates the two into one picture. This is the reason the classic description of an electronic flight instrument display lists a raster and stroke generator as one of its four building blocks, alongside the mode or control panel that selects the format, the processor that decides what to draw, and the sensor data inputs that tell it the values.
An active-matrix liquid crystal display works on an entirely different principle. It emits no light of its own: a backlight illuminates the panel from behind, and each pixel acts as a controllable shutter. The liquid crystal layer sits between two polarisers, and applying a voltage across a pixel changes the twist of the crystal and therefore how much light that pixel passes. "Active matrix" means each pixel has its own thin-film transistor holding its state, which is what allows a large, sharp, flicker-free colour picture without the crosstalk that a passively addressed panel suffers.
| Property | Colour CRT display unit | Active-matrix LCD display unit |
|---|---|---|
| Depth, weight and panel area | Deep and heavy — the tube's length sets the depth, which limits how large the visible area can be made | Flat and light; the visible area can be made large enough to be divided into several independent windows |
| Supply | Needs an extra-high-tension supply of tens of kilovolts; significant power draw and heat | Low-voltage electronics; most of the power goes into the backlight |
| Susceptibility | Beam position is set magnetically, so an external magnetic field can distort the geometry or upset the colour purity of the picture | Immune to magnetic deflection effects; sensitive instead to temperature at the cold end of the range |
| Ageing and wear | Phosphor ages and a static symbol can leave a ghost of itself burned into it; cathode emission falls with hours, so brightness decays | Backlight output falls with hours and individual pixels can fail; the crystal itself does not wear in the same way |
| Typical degraded symptom | Dim, discoloured or defocused picture, convergence errors showing as coloured fringes on symbols | Overall dimming with correct symbology, slow response when cold, isolated dead or stuck pixels |
| Maintenance consequence | Treat as a high-voltage unit even when disconnected; never open the case in the field | Treat as a sealed optical assembly — the face carries an optical coating and the electronics behind it are static-sensitive |
Cold-temperature behaviour is the one respect in which the flat panel is the more delicate of the two. Liquid crystal becomes sluggish as it cools, so a panel left cold-soaked overnight can be slow, smeared or blank at first power-up. Display units therefore contain heaters, and the correct action after a cold night is to allow the specified warm-up before condemning a unit that is simply not yet at temperature. Reporting such a display as failed, when the maintenance manual allows several minutes of warm-up, is a common way to generate an unnecessary component removal.
High tension: a cathode ray tube display unit holds a charge on its final anode after power has been removed, and the tube is also an evacuated glass envelope that can implode if it is struck or scratched. Do not open, probe or attempt bench repair of a display unit on the aircraft, and handle a removed CRT unit by its case with the screen protected. Flat-panel units carry no such high tension but are static-sensitive assemblies, so the electrostatic-discharge precautions covered elsewhere in this module apply to them and to the cards inside the computers that drive them.
What Gets Harder
The advantages listed at the start of this section are real, and they are bought at a price that an engineer needs to understand as clearly as the benefits:
- Common-mode failure replaces independent failure. A hundred separate instruments fail one at a time and for a hundred separate reasons. A set of identical display units running identical software can, in principle, all be affected by the same design or software error at the same moment. Certification answers this with dissimilarity and with an independent standby chain rather than by adding more of the same unit.
- Configuration becomes part of the aircraft's identity. A display unit is defined by the software part number loaded into it and by its position programming as well as by the part number on its label. Two physically identical units are not necessarily interchangeable until the right configuration is in place.
- Everything depends on electrical power and on cooling. Dial instruments driven pneumatically or by a self-contained gyro keep working when the busbar does not. Electronic displays do not, which is why the powering arrangements and the standby chain covered in the last section of this note are as much a part of the instrument system as the screens.
- Diagnosis moves upstream. A parameter now travels sensor → data bus → computer → symbol generator → display unit. A wrong or missing indication identifies a chain, not a component, and the skill the job now demands is deciding which link owns the symptom.
- Obsolescence bites the display, not the aeroplane. Display hardware follows the commercial electronics lifecycle, which is far shorter than an airframe's, so a display system will typically be re-equipped at least once during the aircraft's service life.
Typical Glass Cockpit Layout
A modern transport aircraft cockpit typically features the following main displays:
| Display | Abbreviation | Function | Typical Location |
|---|---|---|---|
| Primary Flight Display | PFD | Attitude, airspeed, altitude, vertical speed, heading, flight director, ILS deviation | Directly in front of each pilot |
| Navigation Display | ND | Map, route, waypoints, weather radar, TCAS traffic, VOR/DME information | Beside each PFD (inboard) |
| Engine/Systems Display | EICAS or ECAM | Engine parameters (N1, N2, EGT, fuel flow), crew alerting, systems status | Centre panel, upper |
| Multi-Function Display | MFD | Secondary systems pages, checklists, synoptic diagrams | Centre panel, lower |
The Four Zones of a Transport Flight Deck
Display units are only part of the picture. A transport flight deck is organised into four zones, and knowing which zone owns which function saves a great deal of time when locating equipment or interpreting a defect report:
- Glareshield — the autopilot and autothrust target selector (Boeing calls it the mode control panel, Airbus the flight control unit), the electronic flight instrument control panels, and the master warning and master caution lights and their reset switches. Everything here is placed for a hand reaching forward without leaving the seat.
- Main instrument panel — the primary flight and navigation displays for each pilot, the centre displays carrying engine and systems information, the standby instruments, the landing gear lever and the primary annunciators. This is the zone the eyes live in.
- Centre pedestal — the flight management control and display units, radio and transponder panels, engine start controls, thrust levers, speed brake, flap lever and trim.
- Overhead panel — the switches and indicators that configure the aircraft systems: electrical, hydraulic, pneumatic and air conditioning, fuel, ice and rain protection, lighting, oxygen, APU and engine start selection.
The overhead panel is worth a sentence of its own because it is often assumed that glass cockpits did away with it. They did not, and the reason is a clean division of labour: the displays show the state of a system, while the overhead panel commands its configuration. Removing it would mean routing every valve and pump selection through a menu on a screen, which is slower and less certain than a switch that can be found by touch. What did change is how the panel is read. Modern overhead panels follow a dark-cockpit philosophy: when the aircraft is correctly configured for the phase of flight, no light is lit. The crew scan for illuminated captions rather than reading each switch position, and an engineer restoring a system after maintenance is not finished until the panel is dark again.
The Basic T Survived the Change
Instrument panels have been standardised around the basic T arrangement since long before electronic displays: attitude at the top centre, airspeed to its left, altimeter to its right, and the heading indication directly below the attitude indicator. The arrangement exists because the pilot's scan radiates from attitude, and the four parameters needed most often should be one short eye movement away.
The primary flight display did not discard that geometry, it absorbed it. The attitude picture occupies the centre of the screen, the airspeed tape runs vertically down its left-hand edge, the altitude tape down its right-hand edge, and a heading or track scale sits across the bottom. A pilot trained on dials therefore uses the same scan pattern on glass, and an engineer looking at an unfamiliar type can find the four primary parameters immediately. Understanding this also explains why the primary flight display is never the screen chosen to carry a systems synoptic: its content is fixed by the scan it has to support.
Inside the Primary Flight Display
Beyond the four basic-T parameters, the primary flight display gathers everything needed to fly a precision approach without looking away:
- Attitude — a pitch ladder and horizon against a fixed aircraft symbol, a bank angle scale with a pointer, and a slip and skid indication beneath it.
- Airspeed tape — the current speed in a reading window with the scale moving past it, a speed trend vector showing the speed that will be reached in the next few seconds at the present acceleration, take-off and manoeuvring speed bugs, the selected speed, and low- and high-speed limit bands.
- Altitude tape — altitude with the selected altitude bug, the barometric reference setting in use, and the vertical speed indication adjacent to it.
- Flight mode annunciation — a band across the top of the display stating which autothrust, lateral and vertical modes are armed and which are engaged, plus the autopilot and flight director status. This has no equivalent on a dial cockpit, and it is the single most important addition the primary flight display made: with automation flying the aeroplane, knowing which mode is actually engaged matters more than any individual parameter.
- Approach information — localiser and glideslope deviation scales, radio altitude, the selected decision height or minimum, and autoland or approach capability status.
- Guidance — the flight director command bars, and the flight path vector or bird on types that provide one.
- Failure indications — flags and removed symbology when a source becomes invalid, which the last section of this note deals with in detail.
Inside the Navigation Display
Where the primary flight display answers "how is the aircraft flying", the navigation display answers "where is it, relative to what". Its content is selectable, and the modes offered are broadly the same across manufacturers even though the names on the selector differ:
| Mode | Orientation and centring | Typical picture | Weather radar overlay |
|---|---|---|---|
| Expanded arc (full arc) | Heading or track up, aircraft symbol at the bottom, compass shown as a forward arc | The forward sector at the selected range, with route, navaids, traffic and terrain | Available |
| Rose (VOR or ILS) | Heading up, aircraft symbol in the centre of a full 360° compass rose | Raw radio navigation data — VOR bearing and deviation, or localiser and glideslope deviation | Available |
| Map | Heading or track up, aircraft symbol at the bottom or centred | The flight-management route with waypoints, airports, navaids, altitude and speed constraints, wind, ground speed and distance to go | Available |
| Plan | North up, centred on a selected flight-plan waypoint, not on the aircraft | A static, chart-like view of the route used to check the programmed flight plan waypoint by waypoint | Not available |
The one mode that cannot carry weather radar is plan, and the reason is geometric rather than arbitrary. The radar antenna scans a sector ahead of the aircraft, so every return it produces is referenced to the aircraft's own position and heading. All the other modes are drawn around the aircraft symbol, so the returns can be laid straight onto them. Plan mode is oriented to north and centred on a waypoint that may be hundreds of miles away, so there is no correct place to put a return that was measured relative to the aeroplane. The radar picture is therefore suppressed rather than shown in the wrong place.
Range selection deserves the same care. The range control sets the scale of the picture and therefore also the depth of the radar sweep that is displayed, so a cell that is plainly visible at a long range disappears from the screen when a short range is selected — not because the weather has gone, but because the display is no longer drawing that far ahead. A defect report of "weather radar not displaying" is very often a range or mode selection, and the check costs nothing.
The Multi-Function Display and Its Controls
A multi-function display is defined by what it can be told to become. Its content is selected by the crew from a menu of pages, and the mechanisms for making that selection are worth knowing by name because they appear in defect reports:
- Bezel or line-select keys — physical switches arranged around the edge of the screen. Each one does a different job on each page, because the label that defines its current function is drawn on the display immediately beside it. A key that appears dead may simply be on a page where it has no function assigned.
- Display partitioning — dividing one physical screen into independent windows so that, for example, a navigation map, an engine page and a checklist can be shown side by side. Partitioning is what makes a large flat panel worth fitting: the screen is not one indication made bigger, it is several indications made simultaneous.
- Cursor control device — a trackball or touchpad, usually on the pedestal or the armrest, that moves a pointer across the displays so the crew can open menus and select items exactly as a mouse does. It appeared for a structural reason: once displays absorbed enough functions, the number of dedicated switches needed to reach them would have started growing again, and a pointer is the general-purpose control that matches a general-purpose display. Its human-factors weakness is precision pointing in turbulence, which is why cursor devices are mounted with a hand or wrist rest and why on-screen targets are made deliberately large.
- Touchscreen — direct interaction by touching the displayed control. Found on the most recent flight decks and widely on business aircraft, it removes a layer of hardware but shares the same turbulence problem, and it obliges the crew to look at what they are touching.
- Multi-purpose control and display unit — the keyboard and screen on the pedestal used to load the flight plan, performance data and radio frequencies into the flight management system, and on many types also to interrogate the maintenance computer.
Head-Down, Head-Up and Enhanced Vision
Everything described so far is a head-down display: a screen mounted in the instrument panel, read by looking down and inside. A head-up display puts a second, smaller set of symbology on a transparent combiner glass mounted between the pilot's eyes and the windscreen. Two properties make it more than a convenience. The image is collimated, that is, focused at optical infinity, so the eye does not have to refocus between the symbology and the outside world; and the symbology can be drawn conformally, so that a flight path marker sits on the point on the ground the aircraft is actually going to, and a runway outline overlays the real runway. That combination is what allows a head-up display to be credited for low-visibility take-off and approach operations.
Two related systems are frequently confused, and the difference is the source of the picture:
- Synthetic vision builds a computer-generated three-dimensional view of terrain, obstacles and runways from a stored database, positioned and oriented using the aircraft's own navigation and attitude data, and draws it as the background of the primary flight display. It shows what the database says is there, in any weather and in the dark, and its integrity depends entirely on position accuracy and database currency.
- Enhanced vision presents a real-time image from a sensor — typically infrared or millimetre-wave — so it shows what is actually there, including traffic and vehicles that no database contains, but only to the extent the sensor can penetrate the conditions.
Both feed the same displays, and combined installations exist, but for maintenance purposes they are different animals: a synthetic vision complaint points at navigation sources and database loading, an enhanced vision complaint points at a sensor, its window and its alignment.
Where the Standby Instruments Sit
The standby instruments are part of the panel layout, not an afterthought bolted to it. They are placed in the centre of the main instrument panel, low enough to leave the primary displays unobstructed but inside the scan of both pilots, because either pilot may have to fly on them. Their content and their independence are dealt with in the final section of this note; what belongs here is that the layout reserves that space deliberately, and that anything mounted so as to obstruct the standby indications — a tablet mount, a placard, a temporary installation — is a certification and safety issue rather than a cosmetic one.
Aviation context: examiners test the split of information between the attitude display and the navigation display more often than any other point in this paragraph, and the discriminator is reliable. Anything referenced to the horizon or to the approach path — pitch and roll, flight director bars, slip, radio altitude, decision height, autoland status, glideslope and localiser deviation — is on the attitude display. Anything referenced to the ground plan — compass rose, selected heading, waypoints, distance to go, weather radar returns, traffic and terrain — is on the navigation display. If an answer option pairs a compass rose or weather radar with the attitude display, it is describing the navigation display.
EFIS — Electronic Flight Instrument System
EFIS is the system that generates and displays the primary flight information. A typical EFIS installation includes:
- Display units — LCD screens showing PFD and ND information.
- Symbol generators (SGs) — computers that receive sensor data, process it, and generate the display imagery. A typical installation has fewer SGs than display units: each side's displays are normally driven by their own SG, with a further SG held as a standby that can be switched in to replace either one.
- EFIS control panel — allows the pilot to select ND range, mode (MAP, VOR, ILS, PLAN), and display options (weather, traffic, terrain).
- Sensor inputs — air data computers (ADCs), inertial reference systems (IRS), radio navigation receivers, FMS.
EADI, EHSI and Today's PFD and ND
Two sets of names are in use for the same two screens, and both appear in examinations. The older set names the instruments the tubes replaced: the electronic attitude director indicator (EADI) and the electronic horizontal situation indicator (EHSI). The current set names what the screens do: the primary flight display and the navigation display. A basic electronic flight instrument system is therefore correctly described as the attitude display, the navigation display and the symbol generators that drive them — the control panels and the sensors are associated equipment feeding that core, not part of it. A complete installation is a matched pair of these: an independent set for the captain and another for the first officer, each with its own displays and its own symbol generator, so that a failure on one side leaves the other side flying.
The attitude display carries an aircraft symbol that is fixed to the case as the datum; the horizon line and pitch ladder move behind it. This is inherited directly from the mechanical attitude director indicator and it is the reverse of what an untrained eye expects, because the aeroplane appears stationary while the world moves. Everything else on the display — flight director bars, deviation pointers, the rising runway — is positioned relative to that fixed symbol.
| Information | Which display carries it | Why it belongs there |
|---|---|---|
| Pitch and roll attitude | Attitude display (EADI / PFD) | The reference every other attitude-related cue is drawn against |
| Flight director command bars | Attitude display | They command a pitch and roll, so they must be read against the horizon |
| Slip and skid indication | Attitude display | Balance is flown with the same control inputs as bank |
| Radio altitude and decision height | Attitude display | Read during the last stage of an approach, when the eyes cannot leave the attitude picture |
| Autoland and approach capability status | Attitude display | Tells the crew what the automatics are currently able to do on this approach |
| Rising runway symbol | Attitude display | A height-above-ground cue tied to the approach |
| Glideslope and localiser deviation | Attitude display (also selectable as raw data on the navigation display in rose mode) | Flown by attitude changes; the navigation display can additionally present the raw signal |
| Airspeed, altitude, vertical speed and Mach | Attitude display on an integrated primary flight display | This is why air data computer outputs are routed to the attitude display; on the earliest systems these parameters were still on separate mechanical instruments |
| Compass rose, selected heading, bearing pointers | Navigation display (EHSI / ND) | A plan view of the horizontal situation. The primary flight display carries only a short heading or track strip, never a rose |
| Waypoints, route, distance to go, ground speed, wind | Navigation display | Flight-management information is inherently a plan-view picture |
| Weather radar returns, terrain, traffic | Navigation display | All three are measured or predicted around the aircraft's ground track |
| Traffic-alert resolution advisory pitch guidance | Attitude display | A resolution advisory commands a vertical rate, so the guidance is flown on the attitude display while the traffic that caused it is plotted on the navigation display |
From Sensor to Screen
Every symbol on the screen has travelled the same road: sensor → data bus → computer → symbol generator → display unit. Knowing the road is what makes structured fault-finding possible, because each stage can be interrogated separately. The principal sources feeding the symbol generators are:
- Air data computer — takes pitot pressure, static pressure and total air temperature and computes calibrated airspeed, Mach number, barometric altitude, vertical speed, true airspeed and static air temperature. It is a computing unit, not a repeater: its outputs are corrected for position error and compressibility, which is exactly why the same static source can feed both the computer and a standby altimeter and give slightly different readings.
- Inertial reference system — provides attitude, heading, position, ground speed and track. It must be aligned while the aircraft is stationary, during which it finds true north by gyrocompassing and takes its starting position from the crew or the flight management system.
- Attitude and heading reference system — the lighter alternative, using solid-state gyros and accelerometers with a magnetometer or flux valve for heading. It supplies pitch, roll and heading but not position or velocity, which is the practical difference from an inertial reference system.
- Radio navigation receivers — VOR, ILS or GLS, DME, ADF and the radio altimeter.
- Flight management system — the route, waypoints, constraints, computed position and predictions drawn on the map.
- Weather radar, terrain awareness and traffic collision avoidance computers — the overlays.
- Engine and systems computers — where the same display system also drives the engine and systems screens.
Reduced to its essentials, an electronic flight instrument display is built from four things: the mode or control panel that selects what is to be shown, the data inputs that supply the values, a processor that decides what to draw, and the raster and stroke generation that actually puts it on the screen. Everything else — air data computers, weather radar processors, navigation receivers — is a source feeding that display, not a part of it. Examination questions frequently mix the two categories, and the test is simple: if removing the box would leave the screen drawing a picture with one item missing, it is a source; if it would leave no picture at all, it is part of the display system.
Data Validity: How a Display Knows Not to Draw
A dial instrument that loses its input tends to fall to a stop or wander. A digital display has a far better option: it can decline to show anything. Every parameter arriving at a symbol generator is accompanied by information about its own trustworthiness, and the system is designed to be fail-passive — the wrong picture is more dangerous than no picture, so a doubtful parameter is removed and replaced by a flag, a dashed field or a cross rather than displayed.
On a typical transport aircraft the data arrives on ARINC 429 buses, and two fields in each 32-bit word do this work. A sign/status matrix lets the transmitting equipment label its own output as normal operation, functional test, failure warning, or no computed data — the last meaning "I am working, but I cannot compute this right now", as an inertial system reports during alignment. A parity bit in the last bit position guards the word against corruption in transit. ARINC 429 uses odd parity: the transmitter sets that bit so that the total number of logic ones across the whole word is odd, and the receiver counts them and rejects the word if the count comes out even.
Worked example — setting and checking an odd parity bit
Suppose the first 31 bits of a word (label, source identifier, data and status fields) happen to contain twelve logic ones. Twelve is even, so to make the total odd the transmitter sets the parity bit to 1, giving thirteen ones in the complete 32-bit word. The receiver counts thirteen, finds it odd, and accepts the word.
Now corrupt any single bit in transit. If a one is read as a zero the count falls to twelve; if a zero is read as a one it rises to fourteen. Both are even, so the receiver rejects the word — a single-bit error is always caught. If the first 31 bits had instead contained thirteen ones, the transmitter would have set the parity bit to 0, because the total is already odd.
Note what this does and does not buy. Parity detects an error, it cannot correct it, and it cannot see two errors in the same word because the second flip restores the odd count. That is acceptable here only because the data is repetitive: a rejected word is simply replaced by the next transmission of the same label a few tens of milliseconds later. If words keep failing, the receiving equipment declares the input invalid and the affected symbology is removed from the screen.
Symbol Generators: One Pool, Many Screens
The symbol generator is the heart of the system. It receives the digital data, checks it, decides what the currently selected format requires, and converts the numbers into the graphical symbols, scales, pointers, tapes and text that appear on the screen. Manufacturers give the function different names — symbol generator, display management computer, display processing computer, display controller — but the role is the same: it is the unit that turns data into a picture. The display unit itself contributes remarkably little intelligence; it accepts the generated video and drives the screen.
There are normally fewer symbol generators than display units, and this is a deliberate architecture rather than an economy. The Airbus A320 family, for example, drives its six display units from three display management computers. In normal operation each side of the flight deck is fed by its own generator — number one for the captain, number two for the first officer — and the third is a standby that is not routinely displaying anything. It is not a comparison channel and it is not a permanently active primary; it exists to be switched in to either side when a primary generator fails, which is precisely why the architecture is worth more than simply fitting one generator per screen: a spare that can serve either side covers twice as many failures as a spare dedicated to one side.
Because any generator can be routed to any display, the failure cases degrade gracefully rather than in steps. Only when every other generator has failed do both the left and right displays end up being fed by the same single generator, and that condition is the last resort rather than a normal configuration — it restores the picture on both sides but removes the independence between them.
Worked example — losing a symbol generator in flight
A three-generator system is in the normal configuration: number one driving the captain's displays, number two driving the first officer's, number three in standby.
Generator one fails. The captain's displays lose their picture while the first officer's are unaffected — that asymmetry alone identifies the failure as being on the captain's side of the architecture rather than in a shared sensor. Selecting the standby source on the captain's switching panel routes generator three to those displays and the picture returns. Both crew now have independent displays again, but there is no longer a spare.
Generator three then also fails. The only remaining source is number two. Selecting it to feed both sides restores symbology on all four screens, but the two sides are now drawing from one computer. The cross-comparison between them is meaningless, because a fault inside that generator would produce the same wrong picture on both sides simultaneously. The crew's remaining independent reference is the standby instrument set, and this is exactly the case those instruments exist for.
The maintenance lesson from the same sequence: a report of "captain's displays blank, restored by switching" is a symbol generator or its supply, not a display unit, because switching the source changed nothing about the screens themselves.
Comparators and Cross-Monitoring
Independence is only useful if somebody checks that the two sides agree. That checking is done by comparators inside the symbol generators, not in the display units and not in a separate box: each generator receives both its own side's data and the other side's, compares the two channels parameter by parameter, and raises an annunciation when a difference exceeds a set threshold and persists for a set time. Typical comparator annunciations cover airspeed, altitude, attitude, heading and, on approach, localiser and glideslope deviation.
A comparator warning says only that two sources disagree; on its own it cannot say which one is wrong. This is why the number of independent sources matters so much in this kind of architecture. With two sources a disagreement can be detected but not resolved. With three, the system can identify the outlier by majority and disregard it, which is the reason large transports carry three air data and inertial reference sources rather than two. Where only two are available, the resolution has to come from outside the pair — the standby instruments, or a parameter derived a different way.
Two Control Panels, Two Different Jobs
An electronic flight instrument system presents the crew with two distinct panels, and confusing them is a common examination error. One is the display control panel, which selects the format: navigation display mode and range, which overlays are shown, the barometric reference, and the decision height or minimum. The other is the source or switching panel, which selects where the information comes from: which symbol generator drives which display, and on many types which air data and inertial reference source feeds each side. Neither is a brightness control and neither is a spare copy of the other: the first decides what the picture looks like, the second decides who draws it.
The source panel is the one that matters most to maintenance, because it is the only control on the flight deck that can silently change the architecture the aircraft is flying on. Its switches are normally left in a normal or automatic position, and a display fed from a transferred source looks exactly like a display fed from its own — which is why the position of these selectors is treated as part of the aircraft configuration in the closing section of this note.
Colour and Symbology Conventions
Colour on an electronic display is a coding system, not decoration, and it is applied consistently enough across manufacturers to be examinable. The conventional assignments are:
| Colour | Meaning | Typical use on the flight displays |
|---|---|---|
| Red | Warning — unusable, or requiring immediate action | Warning messages, failure flags, barber-pole speed limits, a resolution advisory |
| Amber | Caution — abnormal, requiring awareness and timely action | Caution messages, comparator annunciations, a traffic advisory |
| Green | Normal operation, engaged and active | Engaged mode annunciations, normal system states, active values |
| Magenta | Computed or commanded — what the aircraft is being asked to do | Flight director command bars, ILS localiser and glideslope deviation pointers, selected values and bugs, the active flight-plan leg |
| Cyan | Selected, preselected or inactive information | Selected altitude and heading readouts, inactive route segments, advisory data |
| White | Present status, scales and labels | Compass and tape scales, unit labels, memo-type messages |
The magenta convention is the one candidates most often lose a mark on: it marks information that has been computed for the pilot to fly to, which is why both the flight director command bars and the ILS deviation pointers are drawn in it. Individual types vary in the details of their symbology, so the aircraft's own description of its displays is always the authority, but the underlying logic — red and amber reserved for alerting, magenta for commanded guidance — is common ground.
Flight Director Command Bars
The command bars show the required flight path with respect to the actual flight path. That direction matters and is easy to invert. The bars are not a display of what the aircraft is doing; the attitude picture behind them already does that. They are the output of the flight director computation, which takes the selected mode and target — a heading, a track, an altitude, a glideslope — compares it with what the aircraft is currently achieving, and displays the pitch and roll that would remove the difference. The pilot or the autopilot flies to centre the bars on the fixed aircraft symbol. Following the bars satisfies the required path; the bars themselves never show a bank angle for its own sake.
On an electromechanical attitude director indicator the bars are physically positioned by servos, and two feedback terms in that servo loop are examined separately because they control different things:
- Position feedback sets where the bars come to rest. The servo compares the bar's actual position with the demanded position and drives until that error is nulled, so the bars settle precisely on the commanded value instead of stopping short or overshooting it.
- Rate or velocity feedback sets how fast they get there. A signal proportional to the speed of movement is fed back in opposition to the drive, which damps the loop. Increase the rate feedback and the bars move more slowly and settle without oscillating; remove it and they chase the demand, overshoot and hunt about it.
On an electronic display the bars are drawn rather than driven, so there is no servo to fail, but the same two terms survive inside the computation as gain and damping. The distinction remains a fair examination question because it is really about control loops rather than about instruments.
Reading an ILS Approach on the Attitude Display
Deviation indications on the attitude display follow one rule, and applying it mechanically prevents the reversal candidates most often make: the pointer shows where the beam is, relative to the aircraft. The aircraft symbol is fixed, so the pointer moves and the pilot flies towards it.
- Glideslope pointer below the centre mark: the glidepath is below the aircraft, so the aircraft is above the glideslope and must descend to recapture it.
- Glideslope pointer above the centre mark: the glidepath is above the aircraft, so the aircraft is below it and must reduce its rate of descent.
- Localiser pointer displaced to the left: the runway centreline lies to the left of the aircraft, so the aircraft is right of the centreline and must turn left.
The rising runway symbol on the attitude display works on the same fly-towards-it principle but is driven by a different source. Its vertical position comes from the radio altimeter, not from pressure altitude and not from rate of descent, and it appears only in the low band where the radio altimeter is meaningful. As the aircraft descends the radio height decreases and the symbol rises towards the fixed aircraft symbol, so the two meet at touchdown. Test that against the opposite case to be sure of the direction: if the symbol is seen moving down during the final stages of an approach, the radio height must be increasing — the aircraft is going the wrong way relative to the ground and must be flown down.
Aviation context: the rising runway also gives the engineer a free functional check. Because it is driven by radio altitude, its behaviour during a radio altimeter test tracks the height the test set is injecting. A rising runway that does not follow the injected height, or that appears at the wrong height band, points at the radio altimeter chain rather than at the display.
Traffic and Weather Symbology
The two most heavily coded overlays on the navigation display are traffic and weather, and both use shape and colour together so that the picture can be read without interpretation.
Airborne collision avoidance symbology escalates through four steps. Other traffic within the display's selection criteria is drawn as an open white or cyan diamond; traffic closing to within the proximate band is the same diamond filled in; a traffic advisory is shown as a filled amber circle, telling the crew to look for the aircraft; and a resolution advisory becomes a filled red square, at which point the vertical guidance to resolve it is flown on the attitude display while the traffic itself remains plotted on the navigation display. Each symbol carries the relative altitude in hundreds of feet, with a sign showing above or below, and an arrow when the intruder is climbing or descending.
Weather radar returns are coloured by the strength of the echo, which corresponds to the rate of precipitation the beam is being reflected from:
| Colour on the display | What it represents |
|---|---|
| Black | No significant return — either clear air, or nothing reaching the antenna |
| Green | Light returns |
| Amber or yellow | Moderate returns |
| Red | Heavy returns — the core of a severe cell, shown as a red area against the black of the surrounding clear air |
| Magenta | Turbulence, on radars with the Doppler processing needed to detect it |
Black deserves a caution rather than comfort. The radar sees precipitation, so a black area may be clear air, or it may be an area the beam never reached because a nearer cell attenuated it — a shadow behind heavy rain looks exactly like clear weather. This is a limitation of the sensor rather than of the display, but it is displayed information that an engineer investigating a "radar not painting" report has to understand before deciding whether there is a defect at all.
Brightness, Readability and Night Operations
A display that cannot be read is a failed display, and the range of conditions it has to be readable in is extreme: direct sunlight over the glareshield at one end, and a night approach at the other where any excess brightness destroys the crew's dark adaptation. Three mechanisms work together.
Automatic compensation. A light-dependent sensor mounted on the flight deck measures the ambient lighting and its signal is fed in parallel to the display units, so that all of the screens track the cockpit lighting together and none of them ends up brighter or dimmer than its neighbours. Using one flight-deck sensor for all displays rather than a separate sensor inside each unit is deliberate: what matters to the crew is that the screens are consistent with one another, and a sensor buried in one instrument panel position would read a different local light level from the others. The crew retain a manual brightness control to override the automatic setting.
Sunlight readability. Being bright is not sufficient by itself, because in daylight the dominant problem is reflected light washing out the image rather than a lack of emitted light. Sunlight-readable units combine a high-luminance backlight or beam current with anti-reflective and anti-glare treatment of the screen surface, and the glareshield above the panel exists for the same reason. The coating on the face of a display unit is therefore a functional part of it rather than a finish, with the consequences for handling and cleaning set out in the closing section of this note.
Night operations. Dimming for night reduces brightness so that the screens do not impair night vision, and on aircraft required to operate with night vision goggles a further constraint applies. Goggles amplify light in the near-infrared as well as the visible band, so an ordinary display emitting in the near-infrared saturates them and destroys the intensified image of the outside world. Compatibility is achieved by filtering the emitted spectrum of the displays and of the panel lighting to suppress that band, not by simply turning the brightness down. A cockpit modified for goggle use therefore has display and lighting components that are not interchangeable with the standard parts, however identical they look.
EICAS and ECAM
| System | Manufacturer | Primary Function | Key Feature |
|---|---|---|---|
| EICAS | Boeing | Engine parameters + crew alerting; modern implementations also provide system synoptic pages and electronic checklists | Messages colour-coded by severity (red = warning, amber = caution, amber and indented one space = advisory; white = memo/comm) |
| ECAM | Airbus | Engine parameters + crew alerting + system synoptics | Automatically displays the relevant system page when a fault occurs; provides interactive checklists |
One Job, Two Design Philosophies
Whatever the badge on the front, an engine and systems display has the same four jobs: keep the parameters needed to operate the engines permanently in view, tell the crew when something needs attention and how urgently, make the detail of any system available when it is wanted, and hand what happened to maintenance afterwards. The two families differ in how the crew are brought to the information and in how the computing is divided up, and those differences are what an engineer notices when moving between fleets.
| Aspect | Boeing practice (EICAS) | Airbus practice (ECAM) |
|---|---|---|
| Upper centre display | Primary engine parameters and the crew alert message list | Engine/warning display — primary engine parameters, fuel on board, slat and flap position, the warning and caution messages, and memo items |
| Lower centre display | Secondary engine parameters, system synoptics, checklists, status | System display — one system synoptic page at a time, plus the status page |
| How a page is chosen | Crew selection from the display select panel is the normal route; secondary parameters can appear automatically when one goes out of limits | The relevant page is called up automatically by the failure or by the phase of flight; the crew can override the selection manually |
| Where the alerting logic lives | Interface units on earlier types, and a shared computing cabinet on later ones, feeding the display processing | Flight warning computers generate the warnings, the aural alerts and the message text; system data acquisition concentrators gather the system data used for cautions and synoptics; display management computers draw the result |
| Crew procedure presentation | Alert message plus an electronic checklist called up for the failure | The message line itself expands into the actions to be carried out, item by item, cleared as they are completed |
| Redundancy of the alerting function | Duplicated interface or core computing, with the display set able to be reconfigured | Two flight warning computers and two data concentrators; the most critical warnings are generated by the warning computers from inputs taken directly, so they survive the loss of the concentrators |
The automatic page call-up is the genuine philosophical difference and it is worth stating carefully, because it is easy to overstate into a false contrast. Both families provide system synoptics, both provide status information, and both provide electronic checklists on current implementations. What differs is who decides when the crew see the relevant system page: on one the failure brings the page up, on the other the crew go and get it. Everything else in the comparison is a matter of layout and naming rather than capability.
Alert Levels and How They Are Prioritised
Crew alerting is built on a hierarchy of urgency, because an undifferentiated list of messages would leave the crew doing the triage at exactly the moment they have least capacity for it. Three levels are used, and each is defined by the response it demands rather than by the system it comes from:
| Level | What it means | Attention-getter | Expected crew response |
|---|---|---|---|
| Warning (red) | A condition requiring immediate action | Red master warning light plus an aural alert — a continuous repetitive chime, or a dedicated sound such as the fire bell | Act now, then read |
| Caution (amber) | A condition requiring immediate crew awareness and subsequent action | Amber master caution light plus a single chime | Note it, complete the current task, then deal with it |
| Advisory | A condition requiring crew awareness only, with monitoring rather than action | No master light and no aural alert — the indication is the message or the automatic appearance of the affected page | Monitor; no immediate procedure |
Note how the attention-getters are graded with the level: an aural alert cannot be ignored and is therefore reserved for the conditions that must not be missed, while an advisory has no attention-getter at all because getting attention is not what it is for. The certification requirement behind this is CS-25.1322, which prescribes red for warnings and amber or yellow for cautions and permits any colour except red or green for advisories. Within that framework each manufacturer has its own scheme, so the colour a message is drawn in tells you the level only once you know whose flight deck you are standing on.
Two further behaviours are common to both families and are regularly examined:
- Ordering. Messages are listed by priority class, warnings above cautions above advisories, and within a class the most recent message appears at the top of that class. The crew therefore always read the most urgent condition first, regardless of the order in which things went wrong.
- Phase-related inhibition. Alerts that are not immediately actionable are suppressed during the highest-workload moments — the take-off roll and rotation, and the final stage of the landing — so that the crew are not presented with a message at the point where their attention must be outside. The inhibited alerts are not lost; they appear once the aircraft is clear of the inhibited phase. An engineer running an engine or a systems test on the ground should expect a different set of messages from the same fault depending on the phase logic the aircraft believes it is in.
The ECAM Colour Code
The Airbus scheme is the most systematic of the two and is worth learning as a set, because the same code is used on the warning display, the system pages and the status page:
| Colour | Meaning in the ECAM code |
|---|---|
| Red | A configuration or failure requiring immediate action |
| Amber | A condition the crew must be aware of, but with no immediate action |
| Green | Normal operation, and the memo items reminding the crew of a normally selected configuration |
| White | Titles and guidance text, and the items remaining to be completed |
| Blue (cyan) | Actions to be carried out and limitations to be observed |
| Magenta | Particular messages, such as an indication that an alert has been inhibited |
Reading the code changes how a page is used. On a system synoptic, green means a component is doing its job and amber means it is not, so a page can be scanned for colour long before any label is read — which is the whole point of drawing systems as pictures. On the warning display, a line of white text is something still to be done and a line of blue text is the action itself, so the crew's place in a procedure is visible at a glance.
Aviation context: the two schemes are both correct and they are not interchangeable. Boeing's alert list keeps advisories in the caution colour and distinguishes them by indenting them one space, with white reserved for memo and communication messages that are not crew alerts at all. Airbus keeps the alert list to red and amber and uses green, white, blue and magenta elsewhere in the code, so an advisory-level condition typically shows itself by calling up the affected page and pulsing the parameter concerned rather than by adding a coloured line. Learn one scheme thoroughly and know that the other exists; do not assume a colour carries the same meaning across the ramp.
Engine Indication
Engine parameters are split into two groups, and the split is about what must never be off the screen rather than about importance in the abstract:
- Primary parameters — the thrust-setting parameter (fan speed or engine pressure ratio, depending on the engine), exhaust gas temperature, core speed and fuel flow. These are needed on every take-off and every thrust change, so they are displayed permanently on the upper centre screen and cannot be deselected.
- Secondary parameters — oil pressure, oil temperature, oil quantity, vibration and similar. They are needed when a question arises rather than continuously, so they live on the lower screen. On many types they appear automatically if one of them goes out of limits, which is a small but revealing piece of design: the system decides that a parameter has become primary the moment it stops being normal.
Exceedance is shown by colour on the scale and on the digital readout: a normal band, an amber band where a limit is being approached or a time-limited region entered, and a red limit beyond which the parameter must not go. The readout itself changes colour and is usually boxed when it enters those regions, so the crew see the exceedance in the number as well as on the scale. On electronic displays the same parameter can be drawn as a round dial, an arc, a vertical tape or a bare digital readout on different types, and none of those is more correct than another — the format is chosen for the scan, and the underlying signal is identical.
System Synoptics and Status
A synoptic page is a schematic of one system drawn to be read as a picture: tanks, pumps, valves, ducts and electrical paths in their real topology, coloured by their current state rather than annotated with numbers. Valve symbols are drawn in line with the duct they sit in when they are open and across it when they are shut, so a fuel or bleed configuration can be verified in a single glance. Flow paths in a normal condition are drawn in the normal-operation colour, and a faulty or unpowered item changes colour where it sits, so the eye is taken to the location of the fault rather than to a list.
Some parameters are colour-banded on these pages in the same way engine limits are. Brake temperature is the standard example: each brake's temperature is displayed with the colour changing as the temperature rises through defined bands, so the crew can see at a glance which brake is hot and how hot, without comparing numbers against a limit in a manual. That is a genuinely different design choice from displaying one fixed colour with a numeric value beside it: different temperatures are shown in different colours, and the colour is the indication rather than a decoration on it.
The status page is the one an engineer meets most often. It lists what is still inoperative and what limitations remain after all the actions have been completed — the residue of the failure rather than the failure itself. It is the crew's dispatch reference and it is also the fastest way, on arrival, to find out what the aircraft thinks is wrong with it before opening any manual.
Electronic Checklists
Electronic checklist systems present procedures on a centre display or a dedicated screen, covering both normal procedures and non-normal ones. Their significant feature is that many items are sensed: the system reads the actual state of the system concerned and marks the item complete by itself, so a switch that has been selected shows as done without the crew touching the checklist. Items that cannot be sensed — anything the aircraft has no way of detecting — must be actioned and closed by the crew. Items that cannot be completed now can be deferred and remain visible as outstanding.
The value is not that it saves reading. It is that the checklist state and the aircraft state cannot silently diverge: a paper checklist can be ticked while the switch is still in the wrong position, and a sensed electronic one cannot. It also links directly to the alert list, so the procedure for a failure is one selection away from the message announcing it.
What the Alerting System Hands to Maintenance
The crew see a cockpit effect: a warning, a caution, a flag, a lost indication. The maintenance system sees a fault message: the failure the monitoring detected, identified down to a unit or a wiring interface. The two are not the same and the whole value of the maintenance interface lies in the correlation between them — one root failure can produce several cockpit effects, and several cockpit effects reported by the crew can turn out to be one message in the maintenance record.
Fault messages are classified by their operational consequence. A fault with an associated cockpit effect is the highest class and normally has to be dealt with before further flight; a fault with no cockpit effect but a bearing on dispatch capability forms the next class, to be rectified within a defined period; and faults with neither are recorded for trend purposes only. Alongside this, aircraft condition monitoring records performance data and produces reports used for trend monitoring rather than for immediate rectification.
For the engineer, the practical consequence is a discipline: record the cockpit effect exactly as the crew saw it, and read the fault messages separately. A crew report of "engine display blank" and a maintenance message naming a data bus are two halves of the same event, and rectifying one without confirming it explains the other is how an aircraft leaves with the defect still latent.
Aviation context: Modern aircraft have reversionary capability — if a display fails, its information can be transferred to another screen. For example, the captain's PFD information can be displayed on the centre MFD. Some aircraft also retain a small set of analogue standby instruments (attitude, airspeed, altitude) as an ultimate backup.
Redundancy and Reliability
Electronic instrument systems use multiple levels of redundancy:
- Dual (or triple) symbol generators — if one fails, another takes over.
- Display switching — any display unit can show information from any SG.
- Independent power supplies — displays fed from different electrical buses.
- Standby instruments — independent analogue or self-contained electronic instruments for attitude, airspeed, and altitude.
- BITE (Built-In Test Equipment) — continuous self-monitoring with fault logging for maintenance.
What the Redundancy Has to Achieve
The layers listed above are not there to improve dispatch reliability, although they do. They exist because the airworthiness requirements grade every failure condition by its effect and then demand a probability to match: the more severe the consequence, the less often it may be allowed to happen. Total loss of the primary flight information presented to both pilots is at the catastrophic end of that scale, so it must be shown to be extremely improbable — of the order of \( 10^{-9} \) per flight hour — and no single failure may be permitted to cause it.
That requirement drives the whole architecture, and it explains a distinction that is easy to miss. Duplicating equipment only helps if the duplicates cannot be taken out by the same event. Two display units fed by one air data computer are not two sources of airspeed, they are one source shown twice; two symbol generators supplied from the same busbar are not independent of a busbar failure; and two identical computers running identical software are not independent of an error in that software. Real independence therefore has to be built at four levels at once — the sensing, the computing, the electrical supply and the physical routing — and it is backed up by a standby chain that is dissimilar rather than merely additional.
Independent Sources, Not Just Independent Boxes
Behind the displays sit multiple independent sensing chains. A large transport typically carries three air data and inertial reference sources rather than two, and separate pitot and static systems for the left side, the right side and the standby instruments, with their probes physically separated on the airframe so that one impact, one bird or one blocked drain cannot affect them all. Heating is applied to each independently for the same reason.
Three is a deliberate number rather than generosity: as the discussion of comparators earlier in this note sets out, two sources can be compared but not adjudicated, and the third is what resolves the ambiguity. The source selection switches on the flight deck exist to make use of that: if one air data or inertial source is known to be faulty, the affected side can be transferred to a healthy one, which restores a valid picture without waiting for maintenance. The cost is that the two sides may then be sharing a source, and the crew have to know that their cross-check has become weaker.
Electrical Segregation and Power
Electronic displays stop when the electrical supply stops, so the powering arrangement is part of the instrument system rather than a separate subject. The displays and their symbol generators are split deliberately across different busbars, so that the loss of any one bus cannot darken both pilots' screens. The essential or emergency bus is arranged to keep a minimum flying set alive — typically one pilot's primary flight and navigation displays plus one engine and systems display — and that bus is the one that stays alive on the battery when normal generation is lost, through a static inverter where an alternating-current supply is still needed, and on many types on a ram air turbine driving an emergency generator.
The standby instruments are then arranged one level further out again, on the battery bus with their own internal reserve, so that they survive the loss of everything else for a defined period. When tracing a display defect it is always worth establishing which bus the affected unit is on before suspecting the unit, because the pattern of what is lost and what survives usually identifies the supply immediately: a fault that takes out one pilot's screens and nothing else is on that side's bus or that side's equipment, while a fault that takes out screens on both sides is upstream of the split.
Reversion and Switching in Practice
Reversionary capability is what makes a display failure an inconvenience rather than an emergency. In a reversionary mode the essential information from a failed screen is transferred onto a screen that is still working, so the crew keep attitude, airspeed, altitude and the engine indications even though there are fewer screens to put them on. The consequence to understand is that the surviving display is now doing two jobs, so the format is compacted: something has to give way, and what gives way is the information the crew can most afford to lose. A reverted display therefore shows less than the two displays it replaced, and that is a design choice rather than a fault.
Two separate switching layers are involved and they are often confused in reports. Selecting a different source changes which symbol generator or sensor drives a display, and the picture stays where it was. Selecting a reversionary format changes what a display draws, moving information from one screen to another. A crew report that mentions switching should always be read carefully to establish which of the two was done, because they point at different halves of the system.
Recognising a Failure on the Flight Deck
Because everything travels the sensor, bus, computer, generator, display chain described earlier in this note, the pattern of what is missing localises the failure before any test equipment is connected. The reasoning is always the same: whatever is still working tells you which parts of the chain are healthy, and the fault must lie in something common to everything that is not working.
| What is seen | Where the fault most probably lies | Why the symptom says so |
|---|---|---|
| One screen completely dark, the others normal | That display unit, its supply or its cooling | Nothing common to the other screens is affected, and a dark screen is not drawing anything at all |
| Screen alive but showing only a large cross | The symbol generator feeding it, or the switching to it | The display unit is healthy enough to draw the diagnostic cross — what it is not receiving is valid symbology |
| Part of one display missing, the rest correct | The symbol generator handling that symbology, or the input sensor supplying that parameter | The display unit and the basic generation are proven alive by everything still drawn around the gap |
| The same single item missing from every display | Something common to all of them — the display controller and symbol generator function, or the single source or bus that feeds that item to all of them | A fault inside one display unit cannot reach the others; only a shared element can remove one item everywhere |
| A flag in view, a dashed field or a boxed cross over one window | The source of that parameter, which is declaring its own data invalid | The data is being refused, not lost; the display is doing exactly what it should |
| Comparator caution such as airspeed, altitude or attitude | One of the two compared sources — not yet identified | The comparison only proves disagreement; the third source or the standby instruments identify the outlier |
| Correct symbology but a dim or discoloured picture on one unit | The display unit itself — backlight or tube ageing | The data is plainly arriving and being drawn correctly |
| All screens lost together | Power or cooling, upstream of everything | Independent units do not fail simultaneously; a common service does |
The flag convention behind the flag-in-view row is old and worth stating explicitly because it is counter-intuitive at first: warning flags are biased into view and are pulled out of view by the system when the data being monitored is valid. A heading flag that is out of sight therefore means the heading information is good, and a flag in view means it is invalid or is not being monitored. The arrangement is deliberately fail-safe — lose the power or the signal that holds the flag away and it falls into view by itself, so the failure state is the default and no loss of supply or drive can leave the flag hidden while the data it monitors is invalid.
Standby Instruments
The standby set is the last line, and its value lies entirely in being unlike everything else. It provides the three parameters needed to fly the aircraft safely — attitude, airspeed and altitude — from its own sensing, over its own wiring, on its own supply, so that no failure of the display system, its computers, its buses or its normal power can affect it. On many current types the three functions are combined in a single integrated standby unit with a small electronic screen of its own, which typically adds a heading indication and ILS deviation, and which contains its own attitude sensor and its own reserve battery. The unit needs a short alignment on the ground before its attitude output is usable, which is why it is switched on early rather than at the last minute.
The dissimilarity is the point. An integrated standby unit is a screen, like the ones it backs up, but it does not share their sensors, their computers or their supply, and it comes from a separate design rather than being another copy of the one it backs up. That is what makes it a genuine backup rather than a fourth copy of the same failure. Note also what it does not provide: no navigation picture, no engine or systems indications, no flight director. It is the minimum needed to keep the aircraft the right way up and within its speed and altitude limits, and nothing more.
Built-In Test and the Maintenance Trail
Continuous self-monitoring is what allows this much redundancy to be managed at all: with several units able to cover for each other, the aircraft could otherwise dispatch with hidden failures that only reveal themselves when the last healthy unit goes. Built-in test works at three levels — a power-up test that exercises the unit before flight, continuous monitoring during operation that is what raises flags and comparator alerts in the first place, and an interactive ground test that the engineer initiates through the maintenance system.
Three practical points repay attention:
- Faults are stored by flight leg. The record is what makes an intermittent fault tractable, because a failure that will not repeat on the ground still leaves its trace. Reading the stored record before disturbing anything is nearly always the right first action, and clearing it before it has been read destroys the evidence.
- The test tells you which monitor tripped, not always which unit failed. A unit reporting a missing or invalid input is reporting a symptom whose cause lies upstream in the transmitting equipment or the wiring between them. Treating the reporting unit as the faulty one is the classic way to replace a serviceable box.
- Ground tests need the aircraft in the configuration the test assumes. Systems must be powered and pressurised as the manual requires, and safety precautions such as gear pins, area clearance and control-surface warnings apply, because a display test can command real system responses.
Line Maintenance of Display Units and Symbol Generators
Display units and symbol generators are line-replaceable, and on most current types the display units are identical hardware whose role — primary flight display, navigation display, engine display — is set by software configuration or by position programming in the rack rather than by the part number of the unit. That is why one spare covers several positions, and it is also why fitting a unit is not finished when the fasteners are torqued: an incorrectly configured display can power up and look entirely convincing while presenting the wrong format for its position.
- Confirm the configuration and the software standard, not just the part number on the label. Two physically identical units can hold different software.
- Restore every source-select and reversion switch to its normal position before signing, and confirm it visually. A transferred selector left over from troubleshooting leaves an aircraft dispatching in a degraded configuration that shows nothing abnormal on the screens.
- Cross-check the new unit against the opposite side with the aircraft powered: identical parameters, identical formats, no comparator annunciations. This is the test that proves the whole chain, where a self-test only proves the unit.
- Check the cooling. Display units and their computers are cooled by forced air, and a blocked filter or a failed fan produces overheating symptoms — dimming, automatic shedding or a shutdown — that mimic a failing unit.
- Clean only with the agent named in the maintenance manual. The face of a display carries an anti-reflective and anti-glare coating that solvents and household cleaners will attack, and a damaged coating permanently degrades sunlight readability on a unit that is otherwise perfectly serviceable.
- Apply the electrostatic-discharge precautions covered elsewhere in this module to the units and, above all, to any card handled inside them.
- Judge failed pixels against the published criterion in the maintenance manual, which sets how many may be tolerated and whether their position and clustering matter, rather than against an impression that the screen looks imperfect.
Aviation context: because the system is so redundant, an aircraft can often be dispatched with a display unit or a symbol generator inoperative under the minimum equipment list, subject to its conditions and to any placarding and crew notification the list requires. Two consequences follow for the engineer. First, the aircraft leaves with one layer of protection already spent, so the deferral has to be recorded accurately — the next failure is not the first one the crew will have handled. Second, the remaining serviceable units are now doing more work: a fleet that habitually defers display defects will show it in a rising rate of consequential findings, which is exactly the sort of trend the recorded fault data exists to reveal.
Maintenance note: When performing display unit or symbol generator replacements, always follow the aircraft maintenance manual (AMM) procedures for initialisation, alignment, and testing. After installation, the display configuration may need to be programmed and a full functional test performed before return to service.
Printing is not available
Please view study notes online at part66online.com