Search NASA⌕ Search

Engineering topics

Andrew J Moore

Publications and source records attributed to Andrew J Moore.

Testing of Advanced Capabilities to Enable In-time Safety Management and Assurance for Future Flight Operations

In order to refine an initial Concept of Operations, explore Concepts of Use, and expose/validate requirements for future In-Time Aviation Safety Management Systems (IASMS), testing architectures were created, along with a set of capabilities and underlying information exchange protocols. These systems were conceived and developed based on hazards associated with two envisioned urban area flight domains: (1) highly autonomous small uncrewed aerial systems (sUAS) operating at low altitudes, and (2) highly autonomous air taxis. The initial scope of this development is described in [1]; this report provides an update, focusing on the subsequent developments and test activities. As stated in [1], it is important to note that there are many capabilities already in use by the industry (or soon to be in use) that will play critical roles in future IASMS designs. Those reported here were developed to address a gap in the current state-of-the-art regarding specific hazards/risks, and/or to allow for investigation of the interplay between and across hazard types — particularly regarding how overall safety risk can be reduced or managed effectively. Results of testing and development activities are organized by the operational phase wherein a particular capability would be employed (i.e., preflight, in-flight, and post-flight/off-line). Pre-flight: A set of capabilities were developed to help mitigate safety risk prior to flight (e.g., during flight and mission planning). Results of testing summarize (1) validation activities to raise the Technology Readiness Level (TRL) and (2) evaluation activities where the capabilities were applied to flight/mission planning procedures and used by operators/pilots. For the latter, flight plans were automatically assessed, and operators/pilots were notified of hazardous flight segments so as to enable adjustment of the flight plan and re-evaluation, and/or to better inform go/no-go decisions. Capabilities addressed hazards associated with power consumption, third-party risk, wind, navigation system performance, radiofrequency interference, and proximity to geo-spatial threats (e.g., buildings, trees, and no-fly zones). In-flight: Flight experiments tested capabilities that detect and respond to hazards encountered during flight. In the first series, safety hazards were monitored and assessed onboard, and system-generated mitigation maneuvers were recorded (but not acted upon by the vehicle). In the second series, mitigation maneuver commands directed the aircraft in response to safety hazards (i.e., auto-mitigation). The sUAS used for testing is described in full, as is the test architecture, which included commercial avionics, research avionics, and onboard software designed to detect, assess, and respond to hazards. The onboard system was designed as a run-time assurance framework, consistent with [2] and supportive of both supervisory and automated modes. The primary functions included: real-time risk assessment (RTRA), auto-pilot monitoring, constraint monitoring, and contingency select/triggering. RTRA performs integrated risk assessment considering data from several hazard-related monitors (e.g., battery, motors, navigation, communications, population density, and loss-of-control). Post-flight/off-line: Data monitored and recorded during flights can enable IASMS capabilities that execute after flights have completed (or “off-line”). These include: (1) the ability to identify anomalies and trends that may only be observable when comparing data spanning a number of similar flights; (2) the ability to update and validate pre-flight and in-flight capabilities and any underlying models to improve their performance; (3) the ability to report anomalies/off-nominals that may indicate design changes or maintenance actions are needed; and (4) the ability for humans involved in operations to report safety-relevant observations to help in understanding the flight data and/or the operational context of a flight. Progress on three such capabilities is summarized; the first investigates anomaly detection given a limited set of flight logs and applies an approach previously used for space operations. The second explores what could be identified using a larger set of flight logs, including from web-based forums where flight logs are posted by sUAS autopilot users. The third creates a new means of collecting information on UAS incidents and accidents via the Aviation Safety Reporting System (ASRS).

sUAS↗

Demonstration of Two Extended Visual Line of Sight Methods for Urban UAV Operations

This report describes two extended visual line of sight (EVLOS) methods developed and utilized during two flight campaigns over the campus of NASA Langley Research Center (LaRC): a chase vehicle method and a radio controlled (RC) pilot handoff method. These campaigns were performed to (a) evaluate small unmanned aerial system (sUAS) flight beyond the visual line of sight (BVLOS) of the ground control station operator and (b) test technologies under development to enable a transition from EVLOS to BVLOS operations. While an autonomous waypoint-based operational approach enabled minimal pilot intervention in both methods, range containment was enforced (a) manually via continual pilot visual monitoring and (b) autonomously via on-board contingency landing autonomy triggerable at the boundary of stay-in geofences. In the thirty-nine flights which utilized the chase vehicle, the pilot followed the sUAS flying a 1.2 km path at 40m altitude over urban streets. In the fifteen flights which utilized pilot handoff, a pilot at one end of a 1.5 km path initiated the flight at 120m altitude over buildings and trees, and at the midway point of the path transferred radio control to a pilot at the other end. In comparison, the chase vehicle method requires less ground crew and simpler avionics, while the pilot handoff method avoids schedule risk arising from street traffic congestion but better replicates actual direct routing for BVLOS flights. Collision risk with another aircraft was introduced in both campaigns and mitigated with the same manual and autonomous methods. Results from these campaigns serve as a basis for planned BVLOS operations at NASA LaRC.

Nicholas Rymer↗

Volume Raycasting of GNSS Signals through Ground Structure Lidar for UAV Navigational Guidance and Safety Estimation

Autonomous UAS navigation at low altitudes is often hindered by degradation of GNSS position estimates. The line of sight from the UAS to orbital satellites may be intersected by foliage (which attenuates the received signal) and by buildings (which block the signal). Since the geometric ray from the presumed UAS position to each GNSS satellite orbital location is predictable, if a 3D survey of ground structures is available, the degree of blockage of each GNSS signal can be estimated. In this study we show raycasting from a UAS location to GNSS satellites at two flight locations: one with overlying structures and bordered by tall trees, and another in an arboreal canyon bordered by tall trees. We confirm the intermittent blockage of satellites in the first location sufficient to lose GNSS position fix. We demonstrate low-altitude GNSS fidelity forecasting via the raycasting method at the second location that can be used to plan navigable flight locations and altitudes. Finally, we match the GNSS signal strength with raycast-derived foliage obstruction depth at hundreds of observation times from 55 recordings collected over 14 days from November 2018 to February 2021 at the second location. This matching confirms that signal attenuation varies with the depth of foliage blockage along a saturating exponential curve, as found in prior continuous-wave RF studies. The exponent and saturation value are species dependent and therefore vary from site to site; once determined empirically, they can be used to characterize foliage along a particular flight path, and refine GNSS fidelity forecasts of flights along that path. The techniques described in this study show the feasibility of a survey method to construct low-altitude navigation safety maps and forecasts.

Navigation↗

Testing a Run-Time Assurance Framework Coupled with Integrated Risk Mitigation Capabilities for Autonomous Urban UAS Flights

The In-Time Aviation Safety Management System (IASMS) Concept of Operations (ConOps) envisions new capabilities to monitor, assess, and mitigate flight safety risks. Systems will be tailored to mission type, vehicle/equipage type, operational environment, and safety risk tolerance. Within an IASMS framework, several capabilities may be implemented spanning three operational phases (pre-flight, in-flight, and post-flight/off-line); and consisting of lower level functions and information services which may reside onboard the aircraft, on third-party server(s), and/or on ground/operator station(s). Each capability will be designed to produce and disseminate safety-relevant information; perform detection, diagnosis, and prediction of unsafe situations; and/or execute mitigation actions when hazardous events warrant such changes. This paper focuses on recent testing of airborne capabilities that demonstrate inflight aspects of the overarching concept for autonomous unmanned aircraft systems (UAS) operations in urban environments. A flight test architecture is described that applies run-time assurance principles (e.g., executes independent of the unassured autopilot), real-time risk assessment, and a technique to execute contingencies if necessary either automatically or via pilot intervention. Several tests using small UAS were conducted to verify the assured in-flight risk mitigation capability. The paper draws significantly from a larger NASA technical report and recent prior conference papers, providing additional details. Data is analyzed for two representative flights to illustrate the performance for various sequential and simultaneous hazards used during testing. During each automated flight, several hazards are encountered at various points along the flight path. At each point, the hazard is mitigated by the system, with the vehicle then continuing to subsequent points. The paper concludes with lessons-learned regarding relevant aspects of the overarching IASMS concept and how it may be updated and further advanced in the future.

population activity↗