Search NASA⌕ Search

Engineering topics

Steven Young

Publications and source records attributed to Steven Young.

A High-Performance Computing Predictive GNSS Performance Monitor for Autonomous Air Vehicles in Urban Environments

This report offers analysis and design insights for leveraging High-Performance Computing (HPC) to predict line-of-sight (LOS) Global Navigation Satellite System (GNSS) availability in a city. This work is motivated by the emerging fields of Advanced and Urban Air Mobility (AAM/UAM), where regulatory authorities are seeking city-scale, meter-resolution risk forecasting in order to safely integrate new flight missions with existing urban life and infrastructure. This work addresses the technical challenge of efficiently computing urban GNSS satellite visibility to predict GNSS performance metrics under these requirements. We present a new HPC-optimized shadow casting algorithm variant as a ray-based approach to forecasting satellite visibility. We apply this algorithm variant in a software-defined prognostic service which generates a GNSS navigation risk-correlated map as a path planning-style potential field. We detail dominant computational burdens, viable simplifying assumptions, and different algorithmic implementations, intending to demonstrate a baseline of computation time needed by each stage in such a service. We conclude by analyzing the prototype service’s prediction accuracy compared to receiver data from Corpus Christi, Texas. This informs design trade-offs along the dimensions of hardware, computation time, and tolerable forecasting error (including proportions of false positives and false negatives).

GNSS↗

Testing of Advanced Capabilities to Enable In-time Safety Management and Assurance for Future Flight Operations

In order to refine an initial Concept of Operations, explore Concepts of Use, and expose/validate requirements for future In-Time Aviation Safety Management Systems (IASMS), testing architectures were created, along with a set of capabilities and underlying information exchange protocols. These systems were conceived and developed based on hazards associated with two envisioned urban area flight domains: (1) highly autonomous small uncrewed aerial systems (sUAS) operating at low altitudes, and (2) highly autonomous air taxis. The initial scope of this development is described in [1]; this report provides an update, focusing on the subsequent developments and test activities. As stated in [1], it is important to note that there are many capabilities already in use by the industry (or soon to be in use) that will play critical roles in future IASMS designs. Those reported here were developed to address a gap in the current state-of-the-art regarding specific hazards/risks, and/or to allow for investigation of the interplay between and across hazard types — particularly regarding how overall safety risk can be reduced or managed effectively. Results of testing and development activities are organized by the operational phase wherein a particular capability would be employed (i.e., preflight, in-flight, and post-flight/off-line). Pre-flight: A set of capabilities were developed to help mitigate safety risk prior to flight (e.g., during flight and mission planning). Results of testing summarize (1) validation activities to raise the Technology Readiness Level (TRL) and (2) evaluation activities where the capabilities were applied to flight/mission planning procedures and used by operators/pilots. For the latter, flight plans were automatically assessed, and operators/pilots were notified of hazardous flight segments so as to enable adjustment of the flight plan and re-evaluation, and/or to better inform go/no-go decisions. Capabilities addressed hazards associated with power consumption, third-party risk, wind, navigation system performance, radiofrequency interference, and proximity to geo-spatial threats (e.g., buildings, trees, and no-fly zones). In-flight: Flight experiments tested capabilities that detect and respond to hazards encountered during flight. In the first series, safety hazards were monitored and assessed onboard, and system-generated mitigation maneuvers were recorded (but not acted upon by the vehicle). In the second series, mitigation maneuver commands directed the aircraft in response to safety hazards (i.e., auto-mitigation). The sUAS used for testing is described in full, as is the test architecture, which included commercial avionics, research avionics, and onboard software designed to detect, assess, and respond to hazards. The onboard system was designed as a run-time assurance framework, consistent with [2] and supportive of both supervisory and automated modes. The primary functions included: real-time risk assessment (RTRA), auto-pilot monitoring, constraint monitoring, and contingency select/triggering. RTRA performs integrated risk assessment considering data from several hazard-related monitors (e.g., battery, motors, navigation, communications, population density, and loss-of-control). Post-flight/off-line: Data monitored and recorded during flights can enable IASMS capabilities that execute after flights have completed (or “off-line”). These include: (1) the ability to identify anomalies and trends that may only be observable when comparing data spanning a number of similar flights; (2) the ability to update and validate pre-flight and in-flight capabilities and any underlying models to improve their performance; (3) the ability to report anomalies/off-nominals that may indicate design changes or maintenance actions are needed; and (4) the ability for humans involved in operations to report safety-relevant observations to help in understanding the flight data and/or the operational context of a flight. Progress on three such capabilities is summarized; the first investigates anomaly detection given a limited set of flight logs and applies an approach previously used for space operations. The second explores what could be identified using a larger set of flight logs, including from web-based forums where flight logs are posted by sUAS autopilot users. The third creates a new means of collecting information on UAS incidents and accidents via the Aviation Safety Reporting System (ASRS).

sUAS↗

Demonstration of Two Extended Visual Line of Sight Methods for Urban UAV Operations

This report describes two extended visual line of sight (EVLOS) methods developed and utilized during two flight campaigns over the campus of NASA Langley Research Center (LaRC): a chase vehicle method and a radio controlled (RC) pilot handoff method. These campaigns were performed to (a) evaluate small unmanned aerial system (sUAS) flight beyond the visual line of sight (BVLOS) of the ground control station operator and (b) test technologies under development to enable a transition from EVLOS to BVLOS operations. While an autonomous waypoint-based operational approach enabled minimal pilot intervention in both methods, range containment was enforced (a) manually via continual pilot visual monitoring and (b) autonomously via on-board contingency landing autonomy triggerable at the boundary of stay-in geofences. In the thirty-nine flights which utilized the chase vehicle, the pilot followed the sUAS flying a 1.2 km path at 40m altitude over urban streets. In the fifteen flights which utilized pilot handoff, a pilot at one end of a 1.5 km path initiated the flight at 120m altitude over buildings and trees, and at the midway point of the path transferred radio control to a pilot at the other end. In comparison, the chase vehicle method requires less ground crew and simpler avionics, while the pilot handoff method avoids schedule risk arising from street traffic congestion but better replicates actual direct routing for BVLOS flights. Collision risk with another aircraft was introduced in both campaigns and mitigated with the same manual and autonomous methods. Results from these campaigns serve as a basis for planned BVLOS operations at NASA LaRC.

Nicholas Rymer↗

Assured Contingency Landing Management for Advanced Air Mobility

Advanced Air Mobility (AAM) is quickly developing as a new air transportation system that moves people and packages in the regions previously not / less served by the current aviation systems. Such AAM must operate safely despite the potential to encounter hazards and experience anomalies and failures in-flight. It becomes especially important to have systematic auto-mitigation strategies to perform safe contingency actions in AAM flight operations, as pilots have limited Situational Awareness (SA) and limited time to make prompt decisions when encountering failures/anomalies in high-density low altitude airspace. This paper presents Assured Contingency Landing Management (ACLM) with an online landing strategy selection to decide between the following three options when a contingency landing is required: (1) Return-to-launch landing site, (2) Land immediately at a nearby clear but unprepared site, (3) Land at a prepared landing site from the approximate footprint. Our presented algorithm shows a real-time auto-mitigation loop with multiple threads that run simultaneously to check controllability, reachability, and intermediate decisions to hold/ loiter or continue the flight plan as the landing strategy solution is being computed. Case study simulation is demonstrated with the safety-critical propulsion system and battery system and shows how different failure scenarios impact the landing strategy selection.

Autonomous Mitigation↗

Establishing the Assurance Efficacy of Automated Risk Mitigation Strategies

Verification and validation of increasingly autonomous aviation systems is a major challenge. Traditional techniques for the assurance of high-confidence, safety-critical systems are not equipped to handle the complexity, uncertainty, and lack of predictability inherent in non-deterministic systems. Techniques such as run time monitoring, formal methods, and testing and simulation have been applied to some effect, but it is difficult to properly assess the success of such measures. The authors propose the concept of Assurance Efficacy to address this gap. Assurance Efficacy is seen as a parameter, criteria, or perspective by which to evaluate, identify and explore safety risk mitigation strategies and operational assurance architectures. Validation of the utility of this concept through flight testing is a first step in determining its potential role in assessing the overall safety of complex, increasingly autonomous systems that cannot be fully assured in the design phase.

system safety↗

Accuracy Assessment of Two Gps Fidelity Prediction Services in Urban Terrain

Low altitude flight in urban areas is susceptible to degraded GNSS-based navigation system performance due to terrain interference with radio signals from orbital positioning satellites. Predictive navigation performance fidelity tools are needed a) in preflight planning to assist in the creation of safe flight paths and b) in-flight to provide contingency management agents with the navigation risk of proximal flight corridors. Two navigation fidelity prediction services are validated by comparison with over 6000 readings from GNSS sensors collected along a five-mile path through urban areas of Corpus Christi, Texas, on three dates in 2022. Predictions are based on satellite line of sight through 3D terrain data collected in 2018. Each service predicts a set of navigation fidelity metrics over a user-specified time period. One metric estimated by both is the number of visible satellites. A direct comparison of the number of predicted visible satellites with the number sensed by the receiver is used to validate the prediction services. Results show an exact match in the number of predicted satellites for 60% of the measurements, and a match within +/- 4 satellites for 95% of the measurements. As expected, agreement improves away from vertical blocking terrain. Most cases of mismatch are due a lower predicted count than measured (false negatives), and can be accounted for by receiver pickup of stray signals caused by multipath propagation. About 10% of mismatches are false positives and are mostly accounted for by foliage effects. The two services predict visibility of the same set of satellites 80% of the time, differ by two or less satellites 95% of the time, and can compute predictions for one hour of observations in one minute or less. Validation is analyzed statistically and in detailed case studies of selected observation times. The prediction services validated in this study run fast enough for preflight safety planning. The more stringent challenge of inflight navigation fidelity prediction for contingency management requires both a speedup of the current level of modeling and equally fast stray signal modeling.

Andrew Moore↗

Accuracy Assessment of Two GPS Fidelity Prediction Services in Urban Terrain

Low altitude flight in urban areas is susceptible to degraded GNSS-based navigation system performance due to terrain interference with radio signals from orbital positioning satellites. Predictive navigation performance fidelity tools are needed a) in preflight planning to assist in the creation of safe flight paths and b) in-flight to provide contingency management agents with the navigation risk of proximal flight corridors. Two navigation fidelity prediction services are validated by comparison with over 6000 readings from GNSS sensors collected along a five-mile path through urban areas of Corpus Christi, Texas, on three dates in 2022. Predictions are based on satellite line of sight through 3D terrain data collected in 2018. Each service predicts a set of navigation fidelity metrics over a user-specified time period. One metric estimated by both is the number of visible satellites. A direct comparison of the number of predicted visible satellites with the number sensed by the receiver is used to validate the prediction services. Results show an exact match in the number of predicted satellites for 60% of the measurements, and a match within +/- 4 satellites for 95% of the measurements. As expected, agreement improves away from vertical blocking terrain. Most cases of mismatch are due a lower predicted count than measured (false negatives), and can be accounted for by receiver pickup of stray signals caused by multipath propagation. About 10% of mismatches are false positives and are mostly accounted for by foliage effects. The two services predict visibility of the same set of satellites 80% of the time, differ by two or less satellites 95% of the time, and can compute predictions for one hour of observations in one minute or less. Validation is analyzed statistically and in detailed case studies of selected observation times. The prediction services validated in this study run fast enough for preflight safety planning. The more stringent challenge of inflight navigation fidelity prediction for contingency management requires both a speedup of the current level of modeling and equally fast stray signal modeling.

Andrew J. Moore↗