Search NASASearch

Engineering topics

Nikora, Allen

Publications and source records attributed to Nikora, Allen.

Demonstrations of System-Level Autonomy for Spacecraft

System-level autonomy refers to autonomously meeting the crosscutting needs of a system through awareness and coordinated control spanning the system's breadth of capabilities. In contrast to function-level autonomy, which focuses on capabilities required to achieve a specific function such as surface navigation or image recognition, system-level autonomy addresses the needs to coordinate and manage activities and resources, and estimate the state, across subsystems. This paper describes demonstrations that were conducted on a spacecraft workstation testbed. The autonomy was provided by system-level planning and execution integrated with system-level estimators of orbit knowledge and spacecraft hardware health. These components are embedded in a system-level framework defining how goals are formed and executed, which elements exist, and how control authority is distributed among components. The planning and execution system at the heart of the framework has the capability to schedule, execute and monitor completion of tasks, as well as plan around unexpected events including new science opportunities and anomalies. The planning and scheduling system is the Multi-mission EXECutive (MEXEC), supported by the system-level health state estimator Model-Based Off-Nominal State Identification and Detection (MONSID), and Autonomous Navigation (AutoNav) algorithms, which determine the orbital system state based on optical observation of other targets. These components are applicable to many kinds of missions on different platforms. These demonstrations were elaborations of earlier experiments conducted on the ASTERIA (Arcsecond Space Telescope Enabling Research In Astrophysics) CubeSat, described in a companion submission [1]. The spacecraft’s extended mission served as an in-flight test platform, during which some individual autonomous capabilities were flown successfully. The autonomy experiments described here were performed on the ASTERIA workstation testbed.

Prather, Maurice

On-Board Model Based Fault Diagnosis for CubeSat Attitude Control Subsystem: Flight Data Results

Self-sufficient, robotic spacecraft require estimates of their hardware health state in order to project future system state and plan actions toward achieving mission goals. In this paper, we report on integration of a Model-Based Fault Diagnosis (MBFD) model and reasoning engine into flight software leveraging the Arcsecond Space Telescope Enabling Research in Astrophysics (ASTERIA) mission, including test results against captured flight data using the ASTERIA system testbed. Our effort integrated the Model-based Off-Nominal State Identification and Detection (MONSID) model-based reasoning system, developed by Okean Solutions, into ASTERIA flight software using the F Prime software framework. The MONSID engine was supplied with a model of the Blue Canyon Technologies XACT attitude control system (ACS) and tested against flight data and seeded fault tests. While we were unable to conduct an on-board experiment due to the premature loss of ASTERIA, our effort proved the feasibility of on-board model-based fault management, demonstrating reliable and accurate diagnosis using captured data, and further supporting a closed-loop spacecraft autonomy demonstration including autonomous navigation in off-nominal conditions.

Prather, Maurice

Demonstrating Assurance of Model-Based Fault Diagnosis Systems on an Operational Mission

Developers of robotic scientific and commercial spacecraft are trending towards use of onboard autonomous capabilities for responding quickly to dynamic environments and rapidly changing situations. These capabilities need to know the state of the spacecraft’s health. Model-based fault diagnosis (MBFD) is an approach to estimating health by continuously verifying accurate behavior and diagnosing off-nominal behavior. Proper functioning of MBFD depends on 1) the quality of the diagnostic system model that is analyzed and compared to commands and onboard measurements to estimate a system’s health state, and 2) the correct functionality of the diagnosis engine interrogating the model and comparing its analyses to observed system behavior. Our goal is to develop Verification and Validation (V&V) techniques for MBFD to provide future missions sufficient confidence in its functionality and performance to deploy it on the systems they develop. Our work has been focused on infusing the techniques we developed earlier to an operational mission. First, we are constructing diagnostic models of a spacecraft attitude control system and updating our diagnostic engine so they can be demonstrated aboard the Arcsecond Space Telescope Enabling Research in Astrophysics (ASTERIA) mission, an operational spacecraft for which experiments in autonomy are being planned and executed, using the V&V techniques we have previously developed to assure they are both correct and complete. Since it is nearing the end of its life, ASTERIA provides a unique opportunity to demonstrate MBFD since the monitored components are expected to fail. Our demonstration will give system developers additional confidence to make timely, informed MBFD deployment decisions. Second, we will be completing performance assessments of the diagnostic engine/diagnostic model ensemble both on the flight system and ground-based testbeds to gain confidence in MBFD’s ability to run successfully in a spacecraft’s resource-constrained environment without adversely affecting other on-board activities. Finally, we are capturing our experience in preparing this demonstration in a set of checklists and guidance documents. Current practice includes high-level institutional guidance documents and standards, but at a high level of abstraction that does not necessarily address specific MBFD concerns. The purpose of the new checklists is to provide future mission developers clear, unambiguous, procedure-oriented guidance on assuring MBFD. This paper describes our work in these areas. For the first area, we describe the diagnostic models and updated diagnostic engine that will be used for the on-board demonstration. We describe how the V&V techniques we developed earlier are used to assure model and engine correctness and completeness. For the second area, we identify the performance measurement and assessment techniques used to characterize the diagnostic engine and diagnostic models, and discuss the effect of measured performance on overall mission operation. Finally, we present the checklist and guidance documents and describe how they meet the goals of providing system developers with clear, unambiguous, procedure-oriented guidance on MBFD assurance. We show how the techniques we have developed map into those artifacts.

Nikora, Allen

Assurance of Model-Based Fault Diagnosis

Autonomy is an increasingly important technology for robotic scientific and commercial spacecraft. An important motivation for developing onboard autonomy is to enable quick response to dynamic environment and situations, including fault conditions that a spacecraft may encounter. The reliability of such autonomous capabilities depends on the quality of their knowledge of a spacecraft’s health state. Model-based approaches to fault management, i.e. model-based fault diagnosis (MBFD), is one approach to continuously verify correct behavior in addition to diagnosing symptoms to estimate the spacecraft’s health state. The proper functioning of MBFD is dependent on 1) the quality of the model that is analyzed and compared to the outputs of onboard sensors to estimate the system’s health state, and 2) the correct functioning of the diagnosis engine that interrogates the model and compares its analysis to observed system behavior. We are currently developing Verification and Validation (V&V) approaches to provide the necessary confidence that MBFD systems are correctly estimating the health of on-board spacecraft components and systems. Our work is intended to narrow the gap between the rapidly maturing field of ModelBased System Engineering (including MBFD) and the less-well understood area of identifying and applying appropriate V&V techniques to MBFD. Our effort is investigating three areas: 1) developing V&V techniques for the diagnostic model, 2) developing V&V techniques for the diagnostic engine in isolation, and 3) developing V&V techniques for the diagnostic engine and model in combination. This paper describes the work we have completed in the first area. We describe our approach to selecting a system to be represented by a model, the approach to modeling the system, the verification approach we developed for the model, and the results of the verification activity. We conclude with a description of the work remaining in the last two areas, which will be addressed over the next two years.

Chung, Seung

Experiences with Text Mining Large Collections of Unstructured Systems Development Artifacts at JPL

Often repositories of systems engineering artifacts at NASA's Jet Propulsion Laboratory (JPL) are so large and poorly structured that they have outgrown our capability to effectively manually process their contents to extract useful information. Sophisticated text mining methods and tools seem a quick, low-effort approach to automating our limited manual efforts. Our experiences of exploring such methods mainly in three areas including historical risk analysis, defect identification based on requirements analysis, and over-time analysis of system anomalies at JPL, have shown that obtaining useful results requires substantial unanticipated efforts - from preprocessing the data to transforming the output for practical applications. We have not observed any quick 'wins' or realized benefit from short-term effort avoidance through automation in this area. Surprisingly we have realized a number of unexpected long-term benefits from the process of applying text mining to our repositories. This paper elaborates some of these benefits and our important lessons learned from the process of preparing and applying text mining to large unstructured system artifacts at JPL aiming to benefit future TM applications in similar problem domains and also in hope for being extended to broader areas of applications.

text mining

Failure Assessment

Three questions to which software developers want accurate, precise answers are "How can the software system fail?", "mat bad things will happen if the software fails?t', and "How many failures will the software experience?". Numerous techniques have been devised to answer these questions; three of the best known are: 1) Software Fault Tree Analysis (SFTA) 2) Software Failure Modes, Effects, and Criticality Analysis (SFMECA 3) Software Fault/Failure Modeling. SFTA and SFMECA have been successfully used to analyze the flight software for a number of robotic planetary exploration missions, including Galileo, Cassini, and Deep Space 1. Given the increasing interest in reusing software components from mission to mission, one of us has developed techniques for reusing the corresponding portions of the SFTA and SFMECA, reducing the effort required to conduct these analyses. SFTA has also been shown to be effective in analyzing the security aspects of software systems; intrusion mechanisms and effects can easily be modeled using these techniques. The Bi- Directional Safety Analysis (BDSA) method combines a forward search (similar to SFMECA) from potential failure modes to their effects, with a backward search (similar to SFTA) from feasible hazards to the contributing causes of each hazard. BDSA offers an efficient way to identify latent failures. Recent work has extended BDSA to product-line applications such as flight-instrumentation displays and developed tool support for the reuse of the failure-analysis artifacts within a product line. BDSA has also been streamlined to support those projects having tight cost and/or schedule constraints for their failure analysis efforts. We discuss lessons learned from practice, describe available tools, and identi@ some future directions for the topic. A substantial amount of research has been devoted to estimating the number of failures that a software system will experience during test and operations, as well as the number of faults that have been inserted into that system during its development. One of us has found that the amount of structural change to a system during its development is strongly related to the number of faults inserted into it. Using techniques requiring no additional effort on the part of the development organization, the required measurements of structural evolution can be easily obtained from a development effort's configuration management system and readily transformed into an estimate of fault content. So far, structure-fault relationships have been identified for source code; current work seeks to examine artifacts available earlier in the lifecycle to determine if similar relationships between structure and fault content can be found. In particular, relationships between requirements change requests and the number of faults inserted into the implemented system would provide a significant improvement in our ability to control software quality during the early development phases.

fault tree

Software For Computing Reliability Of Other Software

Computer Aided Software Reliability Estimation (CASRE) computer program developed for use in measuring reliability of other software. Easier for non-specialists in reliability to use than many other currently available programs developed for same purpose. CASRE incorporates mathematical modeling capabilities of public-domain Statistical Modeling and Estimation of Reliability Functions for Software (SMERFS) computer program and runs in Windows software environment. Provides menu-driven command interface; enabling and disabling of menu options guides user through (1) selection of set of failure data, (2) execution of mathematical model, and (3) analysis of results from model. Written in C language.

Nikora, Allen