Search NASA⌕ Search

Engineering topics

Ersin Ancel

Publications and source records attributed to Ersin Ancel.

Testing of Advanced Capabilities to Enable In-time Safety Management and Assurance for Future Flight Operations

In order to refine an initial Concept of Operations, explore Concepts of Use, and expose/validate requirements for future In-Time Aviation Safety Management Systems (IASMS), testing architectures were created, along with a set of capabilities and underlying information exchange protocols. These systems were conceived and developed based on hazards associated with two envisioned urban area flight domains: (1) highly autonomous small uncrewed aerial systems (sUAS) operating at low altitudes, and (2) highly autonomous air taxis. The initial scope of this development is described in [1]; this report provides an update, focusing on the subsequent developments and test activities. As stated in [1], it is important to note that there are many capabilities already in use by the industry (or soon to be in use) that will play critical roles in future IASMS designs. Those reported here were developed to address a gap in the current state-of-the-art regarding specific hazards/risks, and/or to allow for investigation of the interplay between and across hazard types — particularly regarding how overall safety risk can be reduced or managed effectively. Results of testing and development activities are organized by the operational phase wherein a particular capability would be employed (i.e., preflight, in-flight, and post-flight/off-line). Pre-flight: A set of capabilities were developed to help mitigate safety risk prior to flight (e.g., during flight and mission planning). Results of testing summarize (1) validation activities to raise the Technology Readiness Level (TRL) and (2) evaluation activities where the capabilities were applied to flight/mission planning procedures and used by operators/pilots. For the latter, flight plans were automatically assessed, and operators/pilots were notified of hazardous flight segments so as to enable adjustment of the flight plan and re-evaluation, and/or to better inform go/no-go decisions. Capabilities addressed hazards associated with power consumption, third-party risk, wind, navigation system performance, radiofrequency interference, and proximity to geo-spatial threats (e.g., buildings, trees, and no-fly zones). In-flight: Flight experiments tested capabilities that detect and respond to hazards encountered during flight. In the first series, safety hazards were monitored and assessed onboard, and system-generated mitigation maneuvers were recorded (but not acted upon by the vehicle). In the second series, mitigation maneuver commands directed the aircraft in response to safety hazards (i.e., auto-mitigation). The sUAS used for testing is described in full, as is the test architecture, which included commercial avionics, research avionics, and onboard software designed to detect, assess, and respond to hazards. The onboard system was designed as a run-time assurance framework, consistent with [2] and supportive of both supervisory and automated modes. The primary functions included: real-time risk assessment (RTRA), auto-pilot monitoring, constraint monitoring, and contingency select/triggering. RTRA performs integrated risk assessment considering data from several hazard-related monitors (e.g., battery, motors, navigation, communications, population density, and loss-of-control). Post-flight/off-line: Data monitored and recorded during flights can enable IASMS capabilities that execute after flights have completed (or “off-line”). These include: (1) the ability to identify anomalies and trends that may only be observable when comparing data spanning a number of similar flights; (2) the ability to update and validate pre-flight and in-flight capabilities and any underlying models to improve their performance; (3) the ability to report anomalies/off-nominals that may indicate design changes or maintenance actions are needed; and (4) the ability for humans involved in operations to report safety-relevant observations to help in understanding the flight data and/or the operational context of a flight. Progress on three such capabilities is summarized; the first investigates anomaly detection given a limited set of flight logs and applies an approach previously used for space operations. The second explores what could be identified using a larger set of flight logs, including from web-based forums where flight logs are posted by sUAS autopilot users. The third creates a new means of collecting information on UAS incidents and accidents via the Aviation Safety Reporting System (ASRS).

sUAS↗

In-time Safety Management Capabilities for Wildland Fire Management Aircraft Operations - A Gap Assessment

This study assesses the in-time safety management services, functions, and capabilities (SFCs)being investigated by NASA’s System Wide Safety (SWS) project to determine applicability to the project’s planned safety demonstrator (SD-1) for wildland fire management. The purpose of this work is to evaluate how effectively existing SFCs address the different hazards presented by a safety demonstrator operating in a wildland fire management scenario. This will help inform decision makers which SFCs would provide the most cost-effective solutions to fill the hazard gaps for further research. Hazards for the safety demonstrator wildland fire management scenario were collated, and the SFCs were evaluated for each hazard based on how applicable and effective the unmodified SFCs are at addressing the hazard. The SFCs are also evaluated for the gap type that needs to be addressed to improve the SFC effectiveness for the given hazard. The key finding of this assessment is that all the existing SFCs require at least some research and development to adapt to the safety demonstrator. No single SFC fully addresses any of the safety demonstrator operation hazards. The result of this study will be used to determine the performance of current SFCs and suggest strategies to adapt existing SFCs or add new SFCs.

Patricia Revolinsky↗

TPSAS-NF1676L-18539-DND

Technical Challenges (TCs) are aligned to Program goals and Project objectives: - Provide research focus to solving aviation safety problems - Provide consistent framework to focus, direct, plan, execute, manage, and communicate Center-distributed research - Form basis for “contract” between Program and Project and Center

Ersin Ancel↗

3D Representation of UAV-obstacle Collision Risk Under Off-nominal Conditions

Safe operations of autonomous unmanned aerial vehicles (UAVs) in low-altitude airspace with beyond visual line-of-sight (BVLOS) flights demand robust risk monitoring of airspace as well as of people and property on ground. One of the safety critical factors for UAV flights is the risk of collision with static and dynamic obstacles in proximity to its flight path. This paper presents a detailed formulation of risk of obstacle collision incorporating the effects of off-nominal conditions introduced by component failures, degraded controllability and environmental disturbances such as wind gusts. The risk is represented in terms of a matrix with rows corresponding to the likelihood of occurrence of collision and columns representing severity of collision to the vehicle and surrounding structures. Risk likelihood is generated using a Bayesian Belief Network (BBN) that compiles knowledge from related Failure Modes and Effects Analysis (FMEAs) and Subject Matter Experts (SMEs) to determine the probability of collision based on on-board sensor measurements indicative of vehicle health and controllability. Risk severity is computed utilizing a point-mass 3D kinematic model of the vehicle in presence of wind. The proposed risk factor is demonstrated on real flight data from experimental flights of an octocopter at NASA Langley Research Center in presence of simulated obstacles and wind conditions. Effect of varying wind conditions, level of controllability and obstacle measurement noise on the risk factor is demonstrated. The proposed approach enables risk-informed decision making for timely mitigation of current and future unsafe events in autonomous systems.

risk analysis↗

3D Representation of UAV-obstacle Collision Risk under off-nominal conditions

Safe operations of autonomous unmanned aerial vehicles (UAVs) in low-altitude airspace with beyond visual line-of-sight (BVLOS) flights demand robust risk monitoring of airspace as well as of people and property on ground. One of the safety critical factors for UAV flights is the risk of collision with static and dynamic obstacles in proximity to its flight path. This paper presents a detailed formulation of risk likelihood of obstacle collision incorporating the effects of off-nominal conditions introduced by component failures, degraded controllability and environmental disturbances such as wind gusts. The deviation in the planned trajectory caused due to wind is computed utilizing a point-mass 3D kinematic simulation model of the vehicle. Likelihood of risk for the flight plan is then analyzed based on generating the probability of collision for each point in the trajectory. The proposed risk factor is demonstrated on real flight data from experimental flights of an octocopter at NASA Langley Research Center in presence of simulated obstacles and wind conditions. Effect of varying wind conditions, distance from obstacles, level of controllability and obstacle measurement noise on the risk factor is demonstrated. The proposed approach enables risk-informed decision making for timely mitigation of current and future unsafe events in autonomous systems.

Portia Banerjee↗

Flight Testing of In-Time Safety Assurance Technologies for UAS Operations

Ongoing research at NASA is driven by a strategic plan defined by the Aeronautics Research Mission Directorate and a vision for future In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. In both visions, system safety awareness and provision are expanded through increased access to relevant data; integrated analysis and predictive capabilities; improved real-time detection and alerting of domain-specific hazards; decision support, and in some cases, automated risk mitigation strategies. One primary research focus is to develop means by which more timely (i.e., “in-time”) actions may be taken to mitigate precursors, anomalies, or trends that are observed during operations. In this paper, we describe such means as a collection of Services, Functions, and Capabilities (SFCs) that are supported by an underlying information system. For example, an integrated risk assessment capability is envisioned that continuously monitors safety-related metrics and margins and recommends timely operational changes. Assessment functions and/or services can be based on data analytics and predictive models derived from heterogeneous data sets that span relevant indicator metrics and their time histories. Likewise, on-board functions can identify and reduce susceptibility to precursor conditions that have led (and can lead) to aircraft loss-of-control or out-of-control accidents. This paper summarizes development and testing of such an information system tailored to hazards anticipated for future highly autonomous flight missions near and over densely populated areas. Testing is accomplished via simulation and by using small, unmanned aircraft operating over a test range at NASA’s Langley Research Center. Flight plans and test scenarios are defined to emulate several use-cases, including package delivery; reconnaissance; fire management; and urban air taxi vertiport operations. Two test phases are summarized with Phase 1 occurring in (2019-2020) and Phase 2 ongoing (2021-present). Results focus on SFC performance, technology readiness level assessment, and requirements discovery/validation. Companion papers are cited throughout for additional details on the recent testing.

safety management↗

Design and Testing of an Approach to Automated In-Flight Safety Risk Management for sUAS Operations

An onboard risk management automation design is presented based on run-time assurance principles, as well as the concept for In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. The automation is designed to operate independently of the autopilot and perform real-time risk assessment spanning multiple classes of hazards, predict constraint violations, and track autopilot states. In the event of elevated risk conditions or predicted constraint violations, the automation will select from a set of available contingencies and trigger autopilot mode changes if necessary to mitigate risk exposure. The onboard automation also informs the remote operator/pilot of what the independent monitor is observing and any contingency decisions or actions that may arise during flight. Details of an implementation of this design and results of verification and validation activities, as required to meet stringent NASA software and system assurance standards, are also presented. This includes simulation and flight testing using small unmanned aircraft systems.

Ersin Ancel↗

Testing a Run-Time Assurance Framework Coupled with Integrated Risk Mitigation Capabilities for Autonomous Urban UAS Flights

The In-Time Aviation Safety Management System (IASMS) Concept of Operations (ConOps) envisions new capabilities to monitor, assess, and mitigate flight safety risks. Systems will be tailored to mission type, vehicle/equipage type, operational environment, and safety risk tolerance. Within an IASMS framework, several capabilities may be implemented spanning three operational phases (pre-flight, in-flight, and post-flight/off-line); and consisting of lower level functions and information services which may reside onboard the aircraft, on third-party server(s), and/or on ground/operator station(s). Each capability will be designed to produce and disseminate safety-relevant information; perform detection, diagnosis, and prediction of unsafe situations; and/or execute mitigation actions when hazardous events warrant such changes. This paper focuses on recent testing of airborne capabilities that demonstrate inflight aspects of the overarching concept for autonomous unmanned aircraft systems (UAS) operations in urban environments. A flight test architecture is described that applies run-time assurance principles (e.g., executes independent of the unassured autopilot), real-time risk assessment, and a technique to execute contingencies if necessary either automatically or via pilot intervention. Several tests using small UAS were conducted to verify the assured in-flight risk mitigation capability. The paper draws significantly from a larger NASA technical report and recent prior conference papers, providing additional details. Data is analyzed for two representative flights to illustrate the performance for various sequential and simultaneous hazards used during testing. During each automated flight, several hazards are encountered at various points along the flight path. At each point, the hazard is mitigated by the system, with the vehicle then continuing to subsequent points. The paper concludes with lessons-learned regarding relevant aspects of the overarching IASMS concept and how it may be updated and further advanced in the future.

population activity↗

Ground Risk Informed Operational Planning for Small Unmanned Aerial Systems

Increasing quantities of small Unmanned Aerial Systems (sUAS) operations present many challenges in terms of safe adoption and integration into existing airspace. The ability to study and quantify the risk to third parties on the ground prior to flight is an important step toward enabling Beyond Visual Line of Sight (BVLOS) operations. The Ground Risk Assessment Service Provider (GRASP) software is a capability developed by NASA to assist with third-party risk quantification and risk-informed flight planning. In this paper, two nominal flight paths intended to represent an infrastructure inspection mission are evaluated using the software to demonstrate its utility. A method is also introduced for adding other NASA-developed capabilities into a single architecture to assess a broader set of operational risks associated with BVLOS operations. These capabilities include a navigation system performance prediction tool, a high fidelity vehicle dynamics model, high resolution wind field data, and other information pertinent to operators. Data produced by these capabilities are combined to enable use of the Performance Based Navigation (PBN) concept borrowed from conventional aviation, providing quantified flight path uncertainty for where the sUAS is likely to be relative to its nominal flight plan. Ground risk is assessed within this region of uncertainty, giving a higher level of confidence in the solution compared to an analysis of only the nominal flight path.

Ground Risk↗