HomeAircraftHow the Boeing 777’s Fly-by-Wire System Uses Primary Flight Computers and Actuator...

How the Boeing 777’s Fly-by-Wire System Uses Primary Flight Computers and Actuator Control Electronics

The original Boeing 777 introduced Boeing’s first digital fly-by-wire primary flight-control system on a commercial transport. Instead of a conventional arrangement in which cockpit controls are linked through long mechanical runs to every primary control surface, the 777 uses electronic computing and signal paths to interpret pilot-control movement and command hydraulically powered surface actuators. Boeing engineer Ying C. “Bob” Yeh described fly-by-wire, the ARINC 629 data bus and deferred maintenance as key flight-control avionics technologies selected for the 777 programme. [1]

The architecture is best understood as a chain rather than as one computer “flying the aircraft”. Pilot-control transducers and aircraft sensors provide inputs. Primary Flight Computers, or PFCs, calculate control commands according to the flight-control laws. Actuator Control Electronics, or ACEs, provide interfaces between the electronic command system and the hydraulic actuation that physically moves the surfaces. A detailed technical description in The Avionics Handbook identifies three PFCs and four ACE units in the classic 777 primary flight-control system and explains their complementary digital and analogue roles. [2]

The scope: the classic 777, not an assumption about every 777X system

This article principally describes the architecture documented for the 777-200, 777-200ER, 777-300, 777-300ER and 777F generation. That distinction matters because the 777-9 uses a later integrated flight-control electronics architecture. Boeing’s 2026 FAA proposed Master Minimum Equipment List for the 777-9 describes Flight Control Modules, Actuation Control Electronics and Integrated Flight Control Electronics cabinets rather than simply reproducing the original 777 arrangement. It would therefore be technically unsafe to assume that every detail of the classic 777 PFC/ACE architecture applies unchanged to the 777X. [3]

Why Boeing moved to fly-by-wire

Fly-by-wire replaces much of the direct mechanical command transmission between the pilot controls and aerodynamic surfaces with electrical signalling and computer processing. In the 777, the flight-control computers can therefore interpret control-column, wheel and pedal inputs in the context of aircraft state before generating surface commands. Yeh’s Boeing paper emphasises that the design problem was not merely computing the desired response but achieving the required functional integrity and availability despite hardware faults and other failure mechanisms. [1]

This does not mean hydraulics disappeared. The 777’s large elevators, ailerons, rudder and spoilers still require powerful actuators. Fly-by-wire changes how those actuators are commanded. The PFC/ACE architecture carries the command electronically until the actuation stage, where hydraulic power produces the force needed to move the surface. The Avionics Handbook description specifically assigns the ACEs the task of controlling primary flight-control actuation through analogue servo loops, while the PFCs calculate control-law commands. [2]

What the Primary Flight Computers do

The PFCs are the central digital computing element of the classic 777 primary flight-control system. The technical literature describes three PFCs operating in parallel, with the architecture built around extensive redundancy. The PFCs receive data needed to calculate commanded aircraft response, execute the flight-control laws and send resulting commands toward the ACEs. They also perform monitoring and maintenance-related functions described in the system literature. [1] [2]

A control law is not simply an autopilot command. Even with the pilot manually flying, a fly-by-wire control system must turn a physical cockpit input into an appropriate command for the aircraft’s surfaces. The PFC therefore sits between the pilot’s desired manoeuvre and the detailed actuator commands that create it. Exactly how gains, schedules and protections are implemented is defined by Boeing’s approved design data; public technical descriptions support the general functional split but are not a substitute for proprietary or approved flight-control documentation. [2]

What the Actuator Control Electronics do

The ACEs occupy a different layer. The classic system uses four ACE units, commonly identified as L1, L2, C and R in technical descriptions. They interface with pilot-control transducers and with the primary-flight-control actuation system. In simplified terms, the ACEs sit close to the boundary between the digital control-law world and the physical hydraulic-actuator world: they receive commands, provide actuator-control functions and return relevant information through the system. [2]

The separation is important for fault containment. If every sensor interface, control-law computation and actuator servo function lived in one undivided computer, a single internal failure could have a much wider effect. The 777 instead distributes functions among multiple computers, communication paths, power sources and hydraulic systems. Yeh’s Boeing paper describes triple redundancy as a central concept across computing, electrical power, hydraulic power and communication resources, while also stressing that redundancy is useful only when faults can be contained. [1]

Why three PFCs are not simply three identical votes

Redundancy in safety-critical avionics has to address more than the obvious failure of one box. Boeing’s published engineering paper discusses fail-passive behaviour, common-mode faults, generic errors, near-coincident faults and design dissimilarity as issues that shaped the 777 flight-control computer architecture. The point is that three channels do not automatically provide protection if the same defect can cause all three to fail in the same way. The architecture therefore has to consider independence and fault containment as well as numerical redundancy. [1]

The 777 system’s use of several independent resources also supports continued operation after certain failures. FAA flight-standardisation material for the 777 specifically requires pilot training on the interaction between fly-by-wire mechanical pilot controls, Actuator Control Electronics and Primary Flight Computers, and on degraded flight-control modes. That requirement reflects an operational reality: crews must understand how aircraft handling and system behaviour can change when parts of the normal flight-control architecture are unavailable. [4]

ARINC 629 was part of the original design story

The classic 777’s primary flight-control system was designed alongside the ARINC 629 digital data-bus architecture. Yeh identifies ARINC 629 as one of the programme’s major flight-control avionics technologies and describes multiple communication paths as part of the overall redundancy concept. A digital data bus allows multiple avionics units to exchange information without requiring a dedicated point-to-point wire pair for every individual signal, although safety-critical design still requires rigorous control of bus access, timing, integrity and failure effects. [1]

It is therefore misleading to picture the PFC as a desktop-style computer connected directly to a single motor. Aircraft state information, pilot-control information and computed commands move through a distributed avionics system. The PFCs calculate; the ACEs provide the actuation interfaces and servo-control layer; hydraulic actuators move the surfaces; and feedback allows the system to monitor what the hardware is doing. This functional description is supported by Boeing-authored and avionics reference material, even though the complete aircraft implementation contains considerably more detail than can be represented in a simple block diagram. [1] [2]

The pilot still has conventional-looking controls

Boeing retained a conventional control wheel, column and rudder pedals in the 777 flight deck. Their presence can give the impression that the aircraft has a conventional mechanical primary-control system, but FAA training material explicitly refers to the interaction of the fly-by-wire mechanical pilot flight controls with the ACEs and PFCs. The cockpit control movement is therefore an input into the electronic control architecture rather than a simple cable command running directly to the control surface. [4]

The mechanical feel and behaviour of those controls are themselves part of the human-machine design. The FAA Flight Standardization Board material calls out the flight-control wheel/column break-out function and requires training in normal, Secondary and Direct flight-control modes. Those mode names indicate that the system can reconfigure when normal computing capability is reduced. This article does not attempt to reproduce pilot procedures for those modes; the authoritative source for operation is the approved flight crew documentation and training programme. [4]

Normal, Secondary and Direct modes

FAA 777 standardisation material identifies Normal, Secondary and Direct flight-control modes as training subjects. The existence of those modes illustrates a key principle of the architecture: the aircraft does not treat every loss of normal functionality as an all-or-nothing event. Depending on the failures present, the system can retain a different level of computation and augmentation. The exact triggers, indications and available functions belong in type-specific manuals, but the broad concept is that degraded modes preserve controllability with fewer normal functions when necessary. [4]

This layered response is closely related to the availability objectives discussed by Yeh. A safety-critical fly-by-wire system must not only reject erroneous outputs; it also has to remain available after failures that the certification safety analysis requires it to tolerate. Boeing’s paper therefore treats functional integrity and functional availability as separate but connected design goals. [1]

Hydraulic redundancy remains essential

Although the command path is electronic, the classic 777 still relies on hydraulic power for primary control-surface actuation. Yeh’s discussion explicitly includes hydraulic power among the hardware resources for which the fly-by-wire architecture uses redundancy. This is an important correction to a common misunderstanding: “fly-by-wire” describes command and control architecture, not an absence of hydraulic systems. Electrical computers can decide where a surface should move, but the physical force to move a large surface under aerodynamic load must still come from an actuator and its energy source. [1]

The distribution of ACE-controlled functions across the actuation system means the electronics and hydraulics have to be designed together. A flight-control command is only useful if the receiving actuation channel has the power and hardware to carry it out. Conversely, a healthy hydraulic actuator needs valid command information. System safety therefore depends on how computers, buses, electrical supplies, hydraulic sources and actuators interact, not on the reliability of any one box viewed in isolation. [1] [2]

Monitoring is as important as commanding

A flight-control computer cannot simply transmit commands and assume that every downstream component has behaved correctly. The 777 architecture includes monitoring and fault-detection functions, and the PFC description in the technical literature includes system monitoring, crew annunciation and onboard maintenance capabilities. This lets the architecture compare expected and observed behaviour, isolate certain faults and provide information used by the crew and maintenance organisation. [2]

Yeh’s discussion of fail-passive electronics is relevant here. In broad engineering terms, a fail-passive element is designed so that a detected internal failure does not continue producing an uncontrolled active output that compromises the remaining system. The Boeing paper presents such fault containment as necessary before hardware redundancy can deliver the intended safety benefit. It should not be interpreted as meaning every possible failure has no operational effect; rather, it is part of the architecture used to manage defined failures within the safety assessment. [1]

Why the 777-9 is a useful warning against overgeneralising

The 777-9 shows how a family name can span substantially different generations of electronics. Boeing’s FAA proposed MMEL material describes four Integrated Flight Control Electronics cabinets, three Flight Control Modules and multiple Actuation Control Electronics elements. It states that the Flight Control Modules perform complex computations including trusted sensor-value calculation and control-surface position commands, while the ACEs provide interfaces to sensors and actuation equipment. The document also describes multiple voting and redundancy arrangements. Those are manufacturer statements in an FAA MMEL proposal and should be attributed accordingly. [3]

That later architecture performs recognisably similar high-level jobs — sensing, computing, voting, commanding and actuating — but with different equipment names and integration. For that reason, technical discussions should always identify which 777 generation they mean. The original 777 PFC/ACE architecture remains historically significant, but it is not sound practice to transfer every unit count, data-bus detail or failure mode directly to the 777-9 without type-specific evidence. [3] [1]

A distributed system rather than a single electronic pilot

The most accurate mental model of the classic 777 fly-by-wire system is therefore a distributed safety-critical control architecture. Pilot inputs and aircraft-state data enter redundant electronics. Three Primary Flight Computers perform the central control-law calculations described in the technical literature. Four Actuator Control Electronics units provide interfaces and servo-control functions for the actuation system. Hydraulic power moves the surfaces. Redundant electrical, hydraulic and communication resources are arranged so that defined failures can be contained and the required control capability retained. [1] [2]

That is more sophisticated than saying the 777 “uses computers instead of cables”. The engineering achievement lies in making the electronic path sufficiently predictable, monitorable, redundant and fault tolerant for primary flight control. Boeing’s own published engineering work makes clear that redundancy, fail-passive design, dissimilarity and common-mode-fault considerations were central to the problem. The PFCs and ACEs are the visible names in that architecture, but their safety value comes from how the complete system is integrated. [1]

Verified Sources / References

  1. Ying C. (Bob) Yeh, Boeing Commercial Airplane Group — “Design Considerations in Boeing 777 Fly-By-Wire Computers”, HASE 1998, IEEE. Boeing-authored engineering paper on the original 777 fly-by-wire architecture, redundancy and fault-tolerance design.
  2. The Avionics Handbook, Chapter 11 — Boeing 777 Primary Flight Control System. Technical reference describing PFC and ACE functions and unit counts.
  3. Boeing-hosted FAA Proposed Master Minimum Equipment List — Boeing 777-9, 26 February 2026. Manufacturer/FAA material describing the later 777-9 integrated flight-control electronics architecture.
  4. FAA Flight Standardization Board Report — Boeing 777, Revision 12 Draft. FAA flightcrew training and standardisation material covering flight-control modes and PFC/ACE interaction.

Editorial Notice

Editorial Notice: This article was prepared using information considered reliable and publicly available at the time of publication. Every reasonable effort has been made to ensure accuracy; however, aviation requirements, technical standards and operational guidance may change as further information or revised regulation becomes available. This article is for general aviation education and reporting and is not a substitute for approved aircraft manuals, operator procedures, regulatory material or professional training. Cockpit King does not allege fault or responsibility against any person or organisation unless confirmed by an authoritative source. If you believe any material is inaccurate, misleading, improperly attributed or should be reviewed for amendment or removal, please contact us with the article title, the specific passage concerned and supporting evidence. We will assess legitimate requests promptly and, where appropriate, correct, clarify, update or remove the material.