Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Protection Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Current limiting remote power control module

The power source for the Space Station Freedom will be fully utilized nearly all of the time. As such, any loads on the system will need to operate within expected limits. Should any load draw an inordinate amount of power, the bus voltage for the system may sag and disrupt the operation of other loads. To protect the bus and loads some type of power interface between the bus and each load must be provided. This interface is most crucial when load faults occur. A possible system configuration is presented. The proposed interface is the Current Limiting Remote Power Controller (CL-RPC). Such an interface should provide the following power functions: limit overloading and resulting undervoltage; prevent catastrophic failure and still provide for redundancy management within the load; minimize cable heating; and provide accurate current measurement. A functional block diagram of the power processing stage of a CL-RPC is included. There are four functions that drive the circuit design: rate control of current; current sensing; the variable conductance switch (VCS) technology; and the algorithm used for current limiting. Each function is discussed separately.

Hopkins, Douglas C.↗

A Generic and Multifunctional Electromagnetic Transient Model for Grid-Following Inverters

This paper presents a generic and multifunctional electromagnetic transient (EMT) dynamic model of grid-following (GFL) inverter-based resources (IBRs) using the PSCAD software platform. The features of the model include flexibility in selecting various types and combinations of DC sources covering photovoltaic modules, battery modules, and ideal DC-source modules as well as flexibility in selecting either switching or averaged models of the inverter. This model also covers exhaustive lists of controller algorithm, including open-loop/closed-loop PQ dispatch control, DC voltage and AC terminal voltage control, and conventional current control designed in the dq-domain, the ..alpha....beta.. -domain, and the positive-/negative-sequence domain. Moreover, this model is equipped with flexibility in selecting various types of current-limiting schemes, including saturation-based and latching-based current limiters, and anti-windup protection. Also, the EMT model is agnostic to the MVA rating and is suitable for interfacing transmission systems by complying with IEEE Std. 2800. The generality in the power circuits and the multifunctional options in the operation and control of the developed EMT model make it suitable for both academia and industry to study various power system aspects, including, but not limited to, the fault behavior of GFL IBRs, the impacts on the protection system, and the transient stability of a system interfaced with large numbers of GFL IBRs.

integrated circuit modeling↗

Transient fault behavior in a microprocessor: A case study

An experimental analysis is described which studies the susceptibility of a microprocessor based jet engine controller to upsets caused by current and voltage transients. A design automation environment which allows the run time injection of transients and the tracing from their impact device to the pin level is described. The resulting error data are categorized by the charge levels of the injected transients by location and by their potential to cause logic upsets, latched errors, and pin errors. The results show a 3 picoCouloumb threshold, below which the transients have little impact. An Arithmetic and Logic Unit transient is most likely to result in logic upsets and pin errors (i.e., impact the external environment). The transients in the countdown unit are potentially serious since they can result in latched errors, thus causing latent faults. Suggestions to protect the processor against these errors, by incorporating internal error detection and transient suppression techniques, are also made.

Duba, Patrick↗

A Generic and Multifunctional Electromagnetic Transient Model for Grid-Following Inverters

This article presents a generic and multi-functional electromagnetic transient (EMT) dynamic model of grid following (GFL) inverter-based resource (IBR) using the PSCAD software platform. The features of the developed model includes the flexibility in selecting various types and combinations of DC sources covering PV modules, battery modules, ideal DC source module, as well as flexibility in selecting either switched or averaged model of inverter. This model also covers exhaustive lists of controller logic covering open-loop/closed-loop PQ dispatch control, DC voltage and AC terminal voltage control along with the conventional current control designed in dq-domain, ate- domain and positive-negative sequence domain. Moreover, this model is equipped with the flexibility in selecting various types of current limiting schemes that includes saturation-based as well as latching-based current limiter, anti-windup protection. Moreover, the EMT model is agnostic to the MVA rating and is suitable for interfacing transmission systems by being complaint with the IEEE Std. 2800. The generality in the power circuits and the multi-functional options in operation and control of the developed EMT model makes it suitable for both academia and industry to study various power system aspects not limited to but such as fault behavior of GFL IBR and impacts on protection system, transient stability of a system interfaced with large number of GFL IBRs etc.

14 SOLAR ENERGY↗

A Generic and Multi-Functional Electromagnetic Transient Model for Grid-Following Inverter: Preprint

This article presents a generic and multi-functional electromagnetic transient (EMT) dynamic model of grid following (GFL) inverter-based resource (IBR) using the PSCAD TM software platform. The features of the developed model includes the flexibility in selecting various types and combinations of DC sources covering PV modules, battery modules, ideal DC source module, as well as flexibility in selecting either switched or averaged model of inverter. This model also covers exhaustive lists of controller logic covering open-loop/closed-loop PQ dispatch control, DC voltage and AC terminal voltage control along with the conventional current control designed in dq-domain, aB- domain and positive-negative sequence domain. Moreover, this model is equipped with the flexibility in selecting various types of current limiting schemes that includes saturation-based as well as latching-based current limiter, anti-windup protection. Moreover, the EMT model is agnostic to the MVA rating and is suitable for interfacing transmission systems by being complaint with the IEEE Std. 2800. The generality in the power circuits and the multi-functional options in operation and control of the developed EMT model makes it suitable for both academia and industry to study various power system aspects not limited to but such as fault behavior of GFL IBR and impacts on protection system, transient stability of a system interfaced with large number of GFL IBRs etc.

grid following inverter↗

Power conditioning equipment for a thermoelectric outer planet spacecraft, volume 1, book 1

Equipment was designed to receive power from a radioisotope thermoelectric generator source, condition, distribute, and control this power for the spacecraft loads. The TOPS mission, aimed at a representative tour of the outer planets, would operate for an estimated 12 year period. Unique design characteristics required for the power conditioning equipment results from the long mission time and the need for autonomous on-board operations due to large communications distances and the associated time delays of ground initiated actions. The salient features of the selected power subsystem configuration are: (1) The PCE regulates the power from the radioisotope thermoelectric generator power source at 30 vdc by means of a quad-redundant shunt regulator; (2) 30 vdc power is used by certain loads, but is more generally inverted and distributed as square-wave ac power; (3) a protected bus is used to assure that power is always available to the control computer subsystem to permit corrective action to be initiated in response to fault conditions; and (4) various levels of redundancy are employed to provide high subsystem reliability.

Andrews, R. E.↗

T-Type Modular DC Circuit Breaker (T-Breaker) for Future DC Networks

The developed T-Type Modular DC Circuit Breaker (T-Breaker) technology offers an all-in-one solution to challenges in DC networks. This includes swift fault detection and protection, power transient stability, and power quality improvement, achieved through the utilization of wide bandgap (WBG) power semiconductors and energy storage devices. The T-Breaker not only facilitates rapid fault current detection and interruption but also implements fault current limiting through active insertion of storage devices or by operating WBG devices in the saturation region. Additionally, with the assistance of energy storage devices, potential overvoltage issues on power devices induced by control signal misalignment can be mitigated. The T-Breaker can be regulated to perform shunt current injection/absorption using the vertical arm and series voltage insertion via the horizontal arm, thereby enhancing DC system stability during voltage or load power fluctuation transients. The OSU team and Raytheon team actively worked together on designing, fabricating, assembling, and testing of two T-Breaker prototypes. The first prototype is rated at 1 kV, 500 A with half-bridge (unipolar) structure to validate the T-Breaker concept. The second prototype is rated at 20 kV, 50 A with full-bridge (bipolar) topology which can reach an efficiency of 99.977%, realize a power density of 60.2 MW/m3, and eliminate the 500-A fault current with a fault response time of around 20 µs. The prototypes show great feasibility of adopting this technology in multiple applications including electrified aircraft, super charging stations, data centers, etc.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Integral Battery Power Limiting Circuit for Intrinsically Safe Applications

A circuit topology has been designed to guarantee the output of intrinsically safe power for the operation of electrical devices in a hazardous environment. This design uses a MOSFET (metal oxide semiconductor field-effect transistor) as a switch to connect and disconnect power to a load. A test current is provided through a separate path to the load for monitoring by a comparator against a preset threshold level. The circuit is configured so that the test current will detect a fault in the load and open the switch before the main current can respond. The main current passes through the switch and then an inductor. When a fault occurs in the load, the current through the inductor cannot change immediately, but the voltage drops immediately to safe levels. The comparator detects this drop and opens the switch before the current in the inductor has a chance to respond. This circuit protects both the current and voltage from exceeding safe levels. Typically, this type of protection is accomplished by a fuse or a circuit breaker, but in order for a fuse or a circuit breaker to blow or trip, the current must exceed the safe levels momentarily, which may be just enough time to ignite anything in a hazardous environment. To prevent this from happening, a fuse is typically current-limited by the addition of the resistor to keep the current within safe levels while the fuse reacts. The use of a resistor is acceptable for non-battery applications where the wasted energy and voltage drop across the resistor can be tolerated. The use of the switch and inductor minimizes the wasted energy. For example, a circuit runs from a 3.6-V battery that must be current-limited to 200 mA. If the circuit normally draws 10 mA, then an 18-ohm resistor would drop 180 mV during normal operation, while a typical switch (0.02 ohm) and inductor (0.97 ohm) would only drop 9.9 mV. From a power standpoint, the current-limiting resistor protection circuit wastes about 18 times more power than the switch and the inductor configuration. In the fault condition, both the resistor and the inductor react immediately. The resistor reacts by allowing more current to flow and dropping the voltage. Initially, the inductor reacts by dropping the voltage, and then by not allowing the current to change. When the comparator detects the drop in voltage, it opens the switch, thus preventing any further current flow. The inductor alone is not sufficient protection, because after the voltage drop has settled, the inductor would then allow the current to change, in this example, the current would be 3.7 A. In the fault condition, the resistor is flowing 200 mA until the fuse blows (anywhere from 1 ms to 100 s), while the switch and inductor combination is flowing about 2 A test current while monitoring for the fault to be corrected. Finally, as an additional safety feature, the circuit can be configured to hold the switch opened until both the load and source are disconnected.

Burns, Bradley M.↗

PASP, a high voltage array/plasma interaction experiment

The author discusses the photovoltaic array space power (PASP) experiment, which is designed to obtain data on the interaction between high-voltage photovoltaic arrays and the polar, low-earth plasma environment. Up to six small test arrays (three each of planar and concentrator designs) can be voltage biased over a range of +/- 500 V. During the bias voltage sequence, the array current leakage is measured and array arc events are monitored. If any arcing occurs the arc characteristics will be measured by a transient pulse monitor. An emitter is included to allow voltage bias to be applied to a plasma-charged or uncharged spacecraft. Similarly, the frames of the concentrator arrays can be left floating or can be tied to the negative array terminal. An environmental data scan is made before each bias voltage sequence. This scan collects information on the plasma, array-current-versus-voltage curves, and neutral particle partial pressure. The requirement for high voltages created problems which were met by circuit isolation and logical fault protection.

Burger, Dale R.↗

Power Actuation and Switching Module Test Results

The X2000 Power System Electronics (PSE) is a Jet Propulsion Laboratory (JPL) task to develop a new generation of power system building blocks for use on future deep-space missions. The effort includes the development of electronic components and modules that can be used as building blocks in the design of generic spacecraft power systems. All X2000 avionics components and modules are designed for use in centralized or distributed spacecraft architectures. The Power Actuation and Switching Module (PASM) has been developed under the X2000 program. This component enables a modular and scalable design approach for power switching applications, which can result in a wide variety of power switching architectures using this simple building block. The PASM is designed to provide most of the necessary power switching functions of spacecraft for various Deep Space missions including future missions to Mars, comets, Jupiter and its moons. It is fabricated using an ASIC process that is tolerant of high radiation. The development included two application specific integrated circuits (ASICs) and support circuitry all packaged using High Density Interconnect (HDI) technology. It can be operated in series or parallel with other PASMs. It can be used as a high-side or low-side switch and it can drive thruster valves, pyrotechnic devices such as NASA standard initiators, bus shunt resistors, and regular spacecraft component loads. Each PASM contains two independent switches with internal current limiting and over-current trip-off functions to protect the power subsystem from load faults. During turnon and turnoff each switch can limit the rate of current change (di/dt) to a value determined by the user. Three-way majority-voted On/Off commandability and full switch status telemetry (both analog and digital) are built into the module. This paper is a follow up to the one presented at he IECEC 2004 conference that will include the lessons learned and test results from the development.

X2000↗

Hubble Space Telescope On-orbit NiH2 Battery Performance

This paper summarizes the Hubble Space Telescope (HST) nickel-hydrogen (NiH2) battery performance from launch to the present time. Over the life of HST vehicle configuration, charge system degradation and failures together with thermal design limitations have had a significant effect on the capacity of the HST batteries. Changes made to the charge system configuration in order to protect against power system failures and to maintain battery thermal stability resulted in undercharging of the batteries. This undercharging resulted in decreased usable battery capacity as well as battery cell voltage/capacity divergence. This cell divergence was made evident during on-orbit battery capacity measurements by a relatively shallow slope of the discharge curve following the discharge knee. Early efforts to improve the battery performance have been successful. On-orbit capacity measurement data indicates increases in the usable battery capacity of all six batteries as well as improvements in the battery cell voltage/capacity divergence. Additional measures have been implemented to improve battery performance, however, failures within the HST Power Control Unit (PCU) have prevented verification of battery status. As this PCU fault prevents the execution of on-orbit capacity testing, the HST Project has based the battery capacity on trends, which utilizes previous on-orbit battery capacity test data, for science mission and servicing mission planning. The Servicing Mission 38 (SM-3B) in March 2002 replaced the faulty PCU. Following the servicing mission, on-orbit capacity test resumed. A summary of battery performance is reviewed since launch in this paper.

Rao, Gopalakrishna M.↗

Intelligent, grid-friendly, modular extreme fast charging system with solid-state DC protection

The development of electric vehicle (EV) charging infrastructure is crucial for the widespread adoption of electric transportation. However, implementing such infrastructure is a complex task that requires consideration of factors such as space limitations, adherence to industry standards, grid capacity, and other technical and policy issues. This project seeks to create a framework for the efficient design of compact medium voltage (MV) extreme fast charging (XFC) stations for EVs. The station design involves the use of a solid-state transformer (SST) that connects to the MV distribution network, delivering power to a shared DC bus. This innovative approach eliminates the need for a step-down transformer to provide low-voltage service by connecting directly to the MV distribution network. Eliminating the low-frequency transformer not only reduces the system footprint and losses but also eliminates inrush currents during grid black-start. Additionally, placing power electronics directly on the distribution system allows for high-bandwidth filtering and power factor correction. The inclusion of a shared DC bus enables multiple charging dispensers and DC storage/generation units to connect, forming a DC microgrid. This setup facilitates power sharing with minimal conversion stages. The project showcases a DC distribution network protected by intelligent solid-state (SS) DC circuit breakers (DCCB) capable of isolating the smallest section of the faulted circuit much faster than existing mechanical solutions.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Compact, Reliable EEPROM Controller

A compact, reliable controller for an electrically erasable, programmable read-only memory (EEPROM) has been developed specifically for a space-flight application. The design may be adaptable to other applications in which there are requirements for reliability in general and, in particular, for prevention of inadvertent writing of data in EEPROM cells. Inadvertent writes pose risks of loss of reliability in the original space-flight application and could pose such risks in other applications. Prior EEPROM controllers are large and complex and do not provide all reasonable protections (in many cases, few or no protections) against inadvertent writes. In contrast, the present controller provides several layers of protection against inadvertent writes. The controller also incorporates a write-time monitor, enabling determination of trends in the performance of an EEPROM through all phases of testing. The controller has been designed as an integral subsystem of a system that includes not only the controller and the controlled EEPROM aboard a spacecraft but also computers in a ground control station, relatively simple onboard support circuitry, and an onboard communication subsystem that utilizes the MIL-STD-1553B protocol. (MIL-STD-1553B is a military standard that encompasses a method of communication and electrical-interface requirements for digital electronic subsystems connected to a data bus. MIL-STD- 1553B is commonly used in defense and space applications.) The intent was to both maximize reliability while minimizing the size and complexity of onboard circuitry. In operation, control of the EEPROM is effected via the ground computers, the MIL-STD-1553B communication subsystem, and the onboard support circuitry, all of which, in combination, provide the multiple layers of protection against inadvertent writes. There is no controller software, unlike in many prior EEPROM controllers; software can be a major contributor to unreliability, particularly in fault situations such as the loss of power or brownouts. Protection is also provided by a powermonitoring circuit.

Katz, Richard↗

AC and DC Fault Management for Megawatt Electrified Aircraft Electrical Powertrains - Task 2: Power Quality Filtering Using Nanocrystalline Soft Magnetic Inductor

The NASA RTAPS program on AC and DC Fault Management for Megawatt Electrified Power Train is a multi-year joint project with Pratt & Whitney (P&W), Collins Aerospace (CA), and RTX Technology Research Center (RTRC). This research program focuses on the high-voltage distribution issues that present a significant technological obstacle in the adoption of Electrified Aviation Propulsion (EAP) systems. One challenge to the adoption of high-voltage distribution systems with power electronic converters is the need for filter elements to limit the generation and propagation of noise, protect the cable systems from premature aging and prevent against excessive heating within subcomponents due to high-frequency induced currents. While increased distribution voltages aide in reducing the cable mass for a fixed power system, the associated mass with the filtering elements for power electronic converter can grow with increasing distribution voltages – thereby mitigating any benefit associated with increasing the distribution system voltage. To enable high-voltage distribution systems with high system specific power densities, new magnetic materials must be developed. Therefore, the second task of the NASA RTAPS program is associated with the design and application of advanced soft magnetic components for Megawatt class electric propulsion systems, specifically the motor drive system. This report covers the collaborative work between NASA Glenn Research Center (GRC), RTRC, P&W and CA in the development of three types of magnetic components over the span of the three-year program. These critical magnetic components are the DC side EMI filter, which limits the propagation of harmful electromagnetic noise to the rise of the distribution system, and the AC side damping with the dv/dt filter, which limits the fast rise time of the power electronic converter output voltage to limit the degradation on the cable/motor insulation systems. Each of these components are investigated from component level design and are optimized at the system level with a combined modelling and testing effort. In the final experimental evaluation of the NASA developed soft magnetic material with a dv/dt filter, a commercial-off-the-shelf (COTS) magnetic core and the GRC magnetic core are optimized and loaded at 320Arms to evaluate their difference in performance. After a run time of 30 minutes in a MW-class motor driver at RTRC, the NASA GRC cores were found to not only offer a lower temperature rise of nearly 25°𝐶, but also a reduction in measured core loss of 25% (12.75W to 9.5W).

Elecrified Aircraft Propulsion↗

Chandra Space Flight Software: Using Software to Autonomously Operation the Largest and Most Sensitive X-Ray Telescope in the World

Chandra is the world's largest and most sensitive X-ray telescope. The Chandra X-ray Observatory is the third in NASA's family of "Great Observatories." The Chandra X-ray Observatory, launched by Space Shuttle Columbia on July 23, 1999, is NASA's newest Great Observatory. The Chandra space flight software is the operational software, which controls and directs the Chandra X-ray Observatory. The Chandra flight software has executed faultlessly for over 13,000 hours on-orbit. The Chandra flight software directly controls the Pointing, Aspect Determination, Electrical Power Subsystem, Propulsion system, and the Command, Communications, and Data Management subsystems. The software controls the spacecraft operations during all phases of the mission. The software also performs thermal control of the telescope to maintain pointing accuracy and monitors radiation levels throughout the orbit so that the Science Instruments can be safed if radiation thresholds are exceeded. The efficient operation of Chandra flight software has enabled the gathering of crucial science data. The Chandra flight software fault protection is the key to early detection and prevention of science instrument or spacecraft damage in an operating platform/environment, which is completely unforgiving. Permanently open Sun Shade Door and ACIS focal plane radiator sensitivity exposes science instruments and mirrors to damage for pointing anomalies causing an attitude excursion. The Chandra flight software must prevent these attitude excursions from occurring for ANY failure. Another example is that the power system has an unregulated bus, which imposes severe operating requirements on Chandra flight software to control array pointing and battery connection/disconnect using a unique algorithmic and logic approach. The Chandra flight software has enabled a truly autonomous vehicle with greater than 99% of all mission data collected as planned. Less than 15% of spacecraft operations are conducted in view (1 hour out of 8) leading to very extended periods without ground contact. The Chandra flight software implements the flexible mission plan during this out of view period, manages the solid state recorder capacity, controls all pointing and maneuvers, provides fault detection for all satellite subsystems, and initiates communications with the ground at the appropriate time. This paper will describe the software architecture features, key design elements and software testing techniques that have facilitated Chandra's success.

Crumbley, Tim↗

Automated Generation and Assessment of Autonomous Systems Test Cases

This slide presentation reviews some of the issues concerning verification and validation testing of autonomous spacecraft routinely culminates in the exploration of anomalous or faulted mission-like scenarios using the work involved during the Dawn mission's tests as examples. Prioritizing which scenarios to develop usually comes down to focusing on the most vulnerable areas and ensuring the best return on investment of test time. Rules-of-thumb strategies often come into play, such as injecting applicable anomalies prior to, during, and after system state changes; or, creating cases that ensure good safety-net algorithm coverage. Although experience and judgment in test selection can lead to high levels of confidence about the majority of a system's autonomy, it's likely that important test cases are overlooked. One method to fill in potential test coverage gaps is to automatically generate and execute test cases using algorithms that ensure desirable properties about the coverage. For example, generate cases for all possible fault monitors, and across all state change boundaries. Of course, the scope of coverage is determined by the test environment capabilities, where a faster-than-real-time, high-fidelity, software-only simulation would allow the broadest coverage. Even real-time systems that can be replicated and run in parallel, and that have reliable set-up and operations features provide an excellent resource for automated testing. Making detailed predictions for the outcome of such tests can be difficult, and when algorithmic means are employed to produce hundreds or even thousands of cases, generating predicts individually is impractical, and generating predicts with tools requires executable models of the design and environment that themselves require a complete test program. Therefore, evaluating the results of large number of mission scenario tests poses special challenges. A good approach to address this problem is to automatically score the results based on a range of metrics. Although the specific means of scoring depends highly on the application, the use of formal scoring - metrics has high value in identifying and prioritizing anomalies, and in presenting an overall picture of the state of the test program. In this paper we present a case study based on automatic generation and assessment of faulted test runs for the Dawn mission, and discuss its role in optimizing the allocation of resources for completing the test program.

Testing challenges↗

Concatenated dual displacement code for continuous-variable quantum error correction

The continuous-variable (CV) Gaussian no-go theorem fundamentally limits the suppression of Gaussian displacement errors using only Gaussian gates and states. Prior studies have employed Gottesman-Kitaev-Preskill (GKP) states as ancillary qumodes to suppress small Gaussian displacement errors. However, when the displacement magnitude becomes large, inevitable lattice-crossing errors arise beyond the correctable range of the GKP state. To address this issue, we concatenate the Gaussian-noise-suppression circuit with an outer analog Steane code that corrects such occasional lattice-crossing events as well as other abrupt displacement errors. Contrary to conventional concatenation, which primarily aims to reduce logical error rates, the Steane-GKP duality in encoding provides complementary protection against displacement errors at different scales: The inner GKP layer employs non-Gaussian resources to suppress continuous Gaussian noise and reduce residual variance, while the outer analog Steane code corrects discrete lattice-crossing events that exceed the GKP correctable range. It is precisely this separation of error-mitigation roles that enables CV error correction. In contrast to prior work on concatenating GKP and repetition codes to establish error correction for discrete qubit/qudit encoding, we provide correction in the continuous encoding space. Analytical studies show that, under infinite squeezing, the concatenated code suppresses the variance of Gaussian displacement errors acting on all qumodes by up to 50%, while enabling unbiased correction of lattice-crossing errors with a success probability determined by the ratio between the residual Gaussian error standard deviation and the lattice-crossing magnitude. Even with finite squeezing, the proposed architecture still provides Gaussian-error suppression and lattice-crossing correction. Moreover, the presence of the outer analog Steane code relaxes the squeezing requirement of the inner GKP states, indicating near-term experimental feasibility. This work establishes a viable route toward fault-tolerant continuous-variable quantum computation and provides insight into the design of concatenated CV error-correcting architectures.

quantum error correction↗

Application of Fault Management Theory to the Quantitative Selection of a Launch Vehicle Abort Trigger Suite

The theory of System Health Management (SHM) and of its operational subset Fault Management (FM) states that FM is implemented as a "meta" control loop, known as an FM Control Loop (FMCL). The FMCL detects that all or part of a system is now failed, or in the future will fail (that is, cannot be controlled within acceptable limits to achieve its objectives), and takes a control action (a response) to return the system to a controllable state. In terms of control theory, the effectiveness of each FMCL is estimated based on its ability to correctly estimate the system state, and on the speed of its response to the current or impending failure effects. This paper describes how this theory has been successfully applied on the National Aeronautics and Space Administration's (NASA) Space Launch System (SLS) Program to quantitatively estimate the effectiveness of proposed abort triggers so as to select the most effective suite to protect the astronauts from catastrophic failure of the SLS. The premise behind this process is to be able to quantitatively provide the value versus risk trade‐off for any given abort trigger, allowing decision makers to make more informed decisions. All current and planned crewed launch vehicles have some form of vehicle health management system integrated with an emergency launch abort system to ensure crew safety. While the design can vary, the underlying principle is the same: detect imminent catastrophic vehicle failure, initiate launch abort, and extract the crew to safety. Abort triggers are the detection mechanisms that identify that a catastrophic launch vehicle failure is occurring or is imminent and cause the initiation of a notification to the crew vehicle that the escape system must be activated. While ensuring that the abort triggers provide this function, designers must also ensure that the abort triggers do not signal that a catastrophic failure is imminent when in fact the launch vehicle can successfully achieve orbit. That is, the abort triggers must have low false negative rates to be sure that real crew‐threatening failures are detected, and also low false positive rates to ensure that the crew does not abort from non‐crew‐threatening launch vehicle behaviors. The analysis process described in this paper is a compilation of over six years of lessons learned and refinements from experiences developing abort triggers for NASA's Constellation Program (Ares I Project) and the SLS Program, as well as the simultaneous development of SHM/FM theory. The paper will describe the abort analysis concepts and process, developed in conjunction with SLS Safety and Mission Assurance (S&MA) to define a common set of mission phase, failure scenario, and Loss of Mission Environment (LOME) combinations upon which the SLS Loss of Mission (LOM) Probabilistic Risk Assessment (PRA) models are built. This abort analysis also requires strong coordination with the Multi‐Purpose Crew Vehicle (MPCV) and SLS Structures and Environments (STE) to formulate a series of abortability tables that encapsulate explosion dynamics over the ascent mission phase. The design and assessment of abort conditions and triggers to estimate their Loss of Crew (LOC) Benefits also requires in‐depth integration with other groups, including Avionics, Guidance, Navigation and Control(GN&C), the Crew Office, Mission Operations, and Ground Systems. The outputs of this analysis are a critical input to SLS S&MA's LOC PRA models. The process described here may well be the first full quantitative application of SHM/FM theory to the selection of a sensor suite for any aerospace system.

Lo, Yunnhon↗