Search NASA⌕ Search

SEARCH · Search NASA

Results for “Level of Automation”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

NASA Langley's Formal Methods Research in Support of the Next Generation Air Transportation System

This talk will provide a brief introduction to the formal methods developed at NASA Langley and the National Institute for Aerospace (NIA) for air traffic management applications. NASA Langley's formal methods research supports the Interagency Joint Planning and Development Office (JPDO) effort to define and develop the 2025 Next Generation Air Transportation System (NGATS). The JPDO was created by the passage of the Vision 100 Century of Aviation Reauthorization Act in Dec 2003. The NGATS vision calls for a major transformation of the nation s air transportation system that will enable growth to 3 times the traffic of the current system. The transformation will require an unprecedented level of safety-critical automation used in complex procedural operations based on 4-dimensional (4D) trajectories that enable dynamic reconfiguration of airspace scalable to geographic and temporal demand. The goal of our formal methods research is to provide verification methods that can be used to insure the safety of the NGATS system. Our work has focused on the safety assessment of concepts of operation and fundamental algorithms for conflict detection and resolution (CD&R) and self- spacing in the terminal area. Formal analysis of a concept of operations is a novel area of application of formal methods. Here one must establish that a system concept involving aircraft, pilots, and ground resources is safe. The formal analysis of algorithms is a more traditional endeavor. However, the formal analysis of ATM algorithms involves reasoning about the interaction of algorithmic logic and aircraft trajectories defined over an airspace. These trajectories are described using 2D and 3D vectors and are often constrained by trigonometric relations. Thus, in many cases it has been necessary to unload the full power of an advanced theorem prover. The verification challenge is to establish that the safety-critical algorithms produce valid solutions that are guaranteed to maintain separation under all possible scenarios. Current research has assumed perfect knowledge of the location of other aircraft in the vicinity so absolute guarantees are possible, but increasingly we are relaxing the assumptions to allow incomplete, inaccurate, and/or faulty information from communication sources.

Butler, Ricky W.↗

Supporting Increased Autonomy for a Mars Rover

This paper presents an architecture and a set of technology for performing autonomous science and commanding for a planetary rover. The MER rovers have outperformed all expectations by lasting over 1100 sols (or Martian days), which is an order of magnitude longer than their original mission goal. The longevity of these vehicles will have significant effects on future mission goals, such as objectives for the Mars Science Laboratory rover mission (scheduled to fly in 2009) and the Astrobiology Field Lab rover mission (scheduled to potentially fly in 2016). Common objectives for future rover missions to Mars include the handling of opportunistic science, long-range or multi-sol driving, and onboard fault diagnosis and recovery. To handle these goals, a number of new technologies have been developed and integrated as part of the CLARAty architecture. CLARAty is a unified and reusable robotic architecture that was designed to simplify the integration, testing and maturation of robotic technologies for future missions. This paper focuses on technology comprising the CLARAty Decision Layer, which was designed to support and validate high-level autonomy technologies, such as automated planning and scheduling and onboard data analysis.

autonomous science↗

Software Model Checking Without Source Code

We present a framework, called AIR, for verifying safety properties of assembly language programs via software model checking. AIR extends the applicability of predicate abstraction and counterexample guided abstraction refinement to the automated verification of low-level software. By working at the assembly level, AIR allows verification of programs for which source code is unavailable-such as legacy and COTS software-and programs that use features-such as pointers, structures, and object-orientation-that are problematic for source-level software verification tools. In addition, AIR makes no assumptions about the underlying compiler technology. We have implemented a prototype of AIR and present encouraging results on several non-trivial examples.

Chaki, Sagar↗

Making Human Spaceflight Practical and Affordable: Spacecraft Designs and their Degree of Operability

As we push toward new and diverse space transportation capabilities, reduction in operations cost becomes increasingly important. Achieving affordable and safe human spaceflight capabilities will be the mark of success for new programs and new providers. The ability to perceive the operational implications of design decisions is crucial in developing safe yet cost competitive space transportation systems. Any human spaceflight program - government or commercial - must make countless decisions either to implement spacecraft system capabilities or adopt operational constraints or workarounds to account for the lack of such spacecraft capabilities. These decisions can benefit from the collective experience that NASA has accumulated in building and operating crewed spacecraft over the last five decades. This paper reviews NASA s history in developing and operating human rated spacecraft, reviewing the key aspects of spacecraft design and their resultant impacts on operations phase complexity and cost. Specific examples from current and past programs - including the Space Shuttle and International Space Station - are provided to illustrate design traits that either increase or increase cost and complexity associated with spacecraft operations. These examples address factors such as overall design performance margins, levels of redundancy, degree of automated failure response, type and quantity of command and telemetry interfaces, and the definition of reference scenarios for analysis and test. Each example - from early program requirements, design implementation and resulting real-time operations experience - to tell the end-to-end "story" Based on these experiences, specific techniques are recommended to enable earlier and more effective assessment of operations concerns during the design process. A formal method for the assessment of spacecraft operability is defined and results of such operability assessments for recent spacecraft designs are provided. Recent experience in applying these techniques to Orion spacecraft development is reviewed to highlight the direct benefits of early operational assessment and collaborative development efforts.

Crocker, Alan R.↗

Compatibility Assessment Tool

In support of ground system development for the Space Launch System (SLS), engineers are tasked with building immense engineering models of extreme complexity. The various systems require rigorous analysis of pneumatics, hydraulic, cryogenic, and hypergolic systems. There are certain standards that each of these systems must meet, in the form of pressure vessel system (PVS) certification reports. These reports can be hundreds of pages long, and require many hours to compile. Traditionally, each component is analyzed individually, often utilizing hand calculations in the design process. The objective of this opportunity is to perform these analyses in an integrated fashion with the parametric CADCAE environment. This allows for systems to be analyzed on an assembly level in a semi-automated fashion, which greatly improves accuracy and efficiency. To accomplish this, component specific parameters were stored in the Windchill database to individual Creo Parametric models based on spec control drawings. These parameters were then accessed by using the Prime Analysis within Creo Parametric. MathCAD Prime spreadsheets were created that automatically extracted these parameters, performed calculations, and generated reports. The reports described component compatibility based on local conditions such as pressure, temperature, density, and flow rates. The reports also determined component pairing compatibility, such as properly sizing relief valves with regulators. The reports stored the input conditions that were used to determine compatibility to increase traceability of component selection. The desired workflow for using this tool would begin with a Creo Schematics diagram of a PVS system. This schematic would store local conditions and locations of components. The schematic would then populate an assembly within Creo Parametric, using Windchill database parts. These parts would have their attributes already assigned, and the MathCAD spreadsheets could begin running through database parts to determine which components would be suited for specific locations within the assembly. This eliminates a significant amount of time from the design process, and makes initial analysis assessments more accurate. Each component that would be checked for a location within the assembly would generate a report, showing whether the component was compatible. These reports could be used to generate the PVS report without the need to perform the same analysis multiple times. This process also has the potential to be expanded upon to further automate PVS reports. The integration of software codes or macros could be used to automatically check through hundreds of parts for each location on the schematic. If the software could recognize which type of component would be necessary for each location, it is possible that simply starting the macro could completely choose all the components needed for the schematic, and in turn the system. This would save many hours of work initially selecting components, which could end up saving money. Overall, this process helps to automate initial component selections for PVS systems to fit local design specifications. These selections will automatically generate reports showing how the design criteria are met by the specific component that was chosen. These reports will contribute to easier compilation of the PVS certification reports, which currently take a great amount of time and effort to produce.

Egbert, James Allen↗

Crew Performance Support System to Aid in Anomaly Resolution: Concept of Operations

As missions progress into deep space, communication delays and disruptions will disenable the crew’s reliance on Earth experts. There are also limitations in the amount of data that can be downlinked to the ground. It is prudent to assume that critical, complex vehicle or habitat sub-systems will malfunction at a time when a lunar or Mars’ crew cannot rely on the Earth-Support team to detect, diagnose and resolve the problem and it is impractical to expect a small crew to step-in with the same level of expertise as 50+ authorities. The crew will need novel processes and advanced technological support to independently identify and resolve safety- and time-critical anomalies. That a self-reliant crew is unable to respond appropriately to time-critical anomalies is a significant risk to crew safety and mission success. This risk is driven by several factors; novel and unanticipated anomalies would not have been trained pre-flight, the crew could forget their pre-flight training or spaceflight stressors could impair the crew’s problem-solving ability. At last year’s IWS, Beard reported that a single spaceflight stressor (elevated CO2) could undermine the crew’s ability to independently respond to emergencies. Concept of Operations (ConOps) provide a common view of future system functions to all stakeholders. For the current project, a ConOps was developed that describes the operational processes, practices and capabilities needed by a crew of astronauts on deep space missions to autonomously respond to anticipated and unanticipated anomalies. It is crucial to recognize that, as of August 2018 existing technologies are unable to effectively support crew anomaly response to unanticipated events. “Intelligent technology” has not reached a maturity level that permits generalizing a solution to novel situations. For example, to train intelligent technology requires volumes of data that do not exist. The complexities involved in a manned mission to Mars cannot be compared to sending rovers to Mars using scripted software. This ConOps proposes a Crew Performance Support System (CPSS) that will push NASA and its industry partners toward what will be required for a safe and successful manned mission to Mars. Anomaly resolution during a deep space mission will take place within a dynamic, or changing, context. The figure to the left shows five broad contextual variables: the organizational culture, mission context, system characteristics, team characteristics and individual characteristics. The yellow arrow indicates that spaceflight and task-related stressors can affect system, team and individual crewmember characteristics and therefore anomaly response potential. The figure depicts a protective umbrella of Human-System Integration (HSI) principles that should be instituted during CPSS development including a balanced workload, shared situation awareness and building an appropriate level of trust in the automation. The figure also depicts two interrelated and cooperative components, an HSI Data System and other Enabling Capabilities will be required to support crew anomaly response and Earth-Support situation awareness. As we journey from ISS to Gateway to Mars, multiple, simultaneous and integrated research and development efforts (i.e., support systems co-evolution) must be implemented to meet the problem-solving challenges a self-reliant crew will face on a Mars’ mission. The crossovers between the capabilities are just as important as the discrete capabilities themselves. As the capabilities mature, the lines between the support subdomains will blur and an integrated system will emerge. The ConOps summarizes current knowledge about how highly trained people solve anomalies in safety- and time-critical situations, describes a group of capabilities that could help to reduce the extant risk and documents requirements levied on additional systems that provides critical inputs to the CPSS. Scenarios are used to promote a shared understanding of processes, practices and technological goals needed for safe and productive manned missions beyond LEO.

HSIA risk↗

Automated Conflict Resolution For Air Traffic Control

The ability to detect and resolve conflicts automatically is considered to be an essential requirement for the next generation air traffic control system. While systems for automated conflict detection have been used operationally by controllers for more than 20 years, automated resolution systems have so far not reached the level of maturity required for operational deployment. Analytical models and algorithms for automated resolution have been traffic conditions to demonstrate that they can handle the complete spectrum of conflict situations encountered in actual operations. The resolution algorithm described in this paper was formulated to meet the performance requirements of the Automated Airspace Concept (AAC). The AAC, which was described in a recent paper [1], is a candidate for the next generation air traffic control system. The AAC's performance objectives are to increase safety and airspace capacity and to accommodate user preferences in flight operations to the greatest extent possible. In the AAC, resolution trajectories are generated by an automation system on the ground and sent to the aircraft autonomously via data link .The algorithm generating the trajectories must take into account the performance characteristics of the aircraft, the route structure of the airway system, and be capable of resolving all types of conflicts for properly equipped aircraft without requiring supervision and approval by a controller. Furthermore, the resolution trajectories should be compatible with the clearances, vectors and flight plan amendments that controllers customarily issue to pilots in resolving conflicts. The algorithm described herein, although formulated specifically to meet the needs of the AAC, provides a generic engine for resolving conflicts. Thus, it can be incorporated into any operational concept that requires a method for automated resolution, including concepts for autonomous air to air resolution.

Erzberger, Heinz↗

General aviation single pilot IFR autopilot study

Five levels of autopilot complexity were flown in a single engine instrument flight rules (IFR) simulation for several different IFR terminal operations. A comparison was made of the five levels of complexity ranging from no-autopilot to a fully coupled lateral and vertical guidance mode to determine the relative benefits vs. complexity/cost of state of the art autopilot capability in the IFR terminal area. Of the five levels tested, the heading select mode made the largest relative difference in decreasing workload and simplifying the approach task. It was also found that the largest number of blunders was detected with the most highly automated mode. The data also showed that, regardless of the autopilot mode, performance during an IFR approach was highly dependent on the type of approach being flown. These results indicate that automation can be useful when making IFR approaches in a high workload environment, but also that some disturbing trends are associated with some of the higher levels of automation found in state of the art autopilots.

Bergeron, H. P.↗

General aviation single pilot IFR autopilot study

Five levels of autopilot complexity were flown in a single engine IFR simulation for several different IFR terminal operations. A comparison was made of the five levels of complexity ranging from no autopilot to a fully coupled lateral and vertical guidance mode to determine the relative benefits versus complexity/cost of state-of-the-art autopilot capability in the IFR terminal area. Of the five levels tested, the heading select mode made the largest relative difference in decreasing workload and simplifying the approach task. It was also found that the largest number of blunders was detected with the most highly automated mode. The data also showed that, regardless of the autopilot mode, performance during an IFR approach was highly dependent on the type of approach being flown. These results indicate that automation can be useful when making IFR approaches in a high workload environment, but also that some disturbing trends are associated with some of the higher levels of automation found in state-of-the-art autopilots.

Bergeron, H. P.↗

DRS: Derivational Reasoning System

The high reliability requirements for airborne systems requires fault-tolerant architectures to address failures in the presence of physical faults, and the elimination of design flaws during the specification and validation phase of the design cycle. Although much progress has been made in developing methods to address physical faults, design flaws remain a serious problem. Formal methods provides a mathematical basis for removing design flaws from digital systems. DRS (Derivational Reasoning System) is a formal design tool based on advanced research in mathematical modeling and formal synthesis. The system implements a basic design algebra for synthesizing digital circuit descriptions from high level functional specifications. DRS incorporates an executable specification language, a set of correctness preserving transformations, verification interface, and a logic synthesis interface, making it a powerful tool for realizing hardware from abstract specifications. DRS integrates recent advances in transformational reasoning, automated theorem proving and high-level CAD synthesis systems in order to provide enhanced reliability in designs with reduced time and cost.

Bose, Bhaskar↗

Effects of a psychophysiological system for adaptive automation on performance, workload, and the event-related potential P300 component

The present study examined the effects of an electroencephalographic- (EEG-) based system for adaptive automation on tracking performance and workload. In addition, event-related potentials (ERPs) to a secondary task were derived to determine whether they would provide an additional degree of workload specificity. Participants were run in an adaptive automation condition, in which the system switched between manual and automatic task modes based on the value of each individual's own EEG engagement index; a yoked control condition; or another control group, in which task mode switches followed a random pattern. Adaptive automation improved performance and resulted in lower levels of workload. Further, the P300 component of the ERP paralleled the sensitivity to task demands of the performance and subjective measures across conditions. These results indicate that it is possible to improve performance with a psychophysiological adaptive automation system and that ERPs may provide an alternative means for distinguishing among levels of cognitive task demand in such systems. Actual or potential applications of this research include improved methods for assessing operator workload and performance.

Task Performance and Analysis↗

A method of measuring fault latency in a digital flight control system

This paper describes the motivation, conduct, and analysis of some 2500 low-level hardware fault cases applied in automated testing at the NASA Ames Reconfigurable Digital Flight Control System Facility. Fault detection was correlated with hardware and software fault monitoring and, in limited cases, with sensitivity to flight program execution modes. The results are statistically assessed to ascertain system-level reliability implications based on a single-fault model. Extension to multiple-fault models is addressed. The overall methodology/facility itself is judged to be a promising enhancement to current practice.

Mcgough, John↗

An Experimental System for Strategic Flight Path Management in Advanced Air Mobility

In the concept envisioned for Urban Air Mobility (UAM) operations, fleets of electric vertical takeoff and landing (eVTOL) vehicles would operate between vertiports distributed within a densely populated area. These operations would be largely independent from the existing air traffic control system and would place the responsibility for flight planning and aircraft separation on fleet operators. The fourth major level on the UAM Maturity Level scale, UML-4, relies on “collaborative and responsible” automation to enable operations in non-visual conditions with medium traffic density (hundreds of aircraft in one metropolitan region) and medium complexity. This level of service places many requirements on automation systems to assist the operators of these aircraft. NASA has developed the Autonomous Operations Planner (AOP), a reference prototype Flight Path Management automation system, and has modified AOP to support research of anticipated UML-4 operations. AOP creates a four-dimensional flight plan conforming to the constraints of these operations, evaluates and modifies the flight plan during flight as conditions and constraints evolve, and coordinates the flight plan with other airspace users and with service providers. This version of AOP has been integrated into the Sikorsky Autonomy Research Aircraft and used in a flight test activity. In this paper we discuss anticipated characteristics of UAM operations, modifications that were made to AOP to adapt to that environment or to support the flight test, and observations of software and aircraft performance during the flight test. The aircraft achieved four-dimensional conformance with the flight plan and AOP provided adequate planning in almost all cases. We discuss improvements that could be made to AOP to address deficiencies that were observed.

Autonomous Operations Planner↗

An Experimental System for Strategic Flight Path Management in Advanced Air Mobility

In the concept envisioned for Urban Air Mobility (UAM) operations, fleets of electric vertical takeoff and landing (eVTOL) vehicles would operate between vertiports distributed within a densely populated area. These operations would be largely independent from the existing air traffic control system and would place the responsibility for flight planning and aircraft separation on fleet operators. The fourth major level on the UAM Maturity Level scale, UML-4, relies on “collaborative and responsible” automation to enable operations in non-visual conditions with medium traffic density (hundreds of aircraft in one metropolitan region) and medium complexity. This level of service places many requirements on automation systems to assist the operators of these aircraft. NASA has developed the Autonomous Operations Planner (AOP), a reference prototype Flight Path Management automation system, and has modified AOP to support research of anticipated UML-4 operations. AOP creates a four-dimensional flight plan conforming to the constraints of these operations, evaluates and modifies the flight plan during flight as conditions and constraints evolve, and coordinates the flight plan with other airspace users and with service providers. This version of AOP has been integrated into the Sikorsky Autonomy Research Aircraft and used in a flight test activity. In this paper we discuss anticipated characteristics of UAM operations, modifications that were made to AOP to adapt to that environment or to support the flight test, and observations of software and aircraft performance during the flight test. The aircraft achieved four-dimensional conformance with the flight plan and AOP provided adequate planning in almost all cases. We discuss improvements that could be made to AOP to address deficiencies that were observed.

Autonomous Operations Planner↗

Hardware fault insertion and instrumentation system: Mechanization and validation

Automated test capability for extensive low-level hardware fault insertion testing is developed. The test capability is used to calibrate fault detection coverage and associated latency times as relevant to projecting overall system reliability. Described are modifications made to the NASA Ames Reconfigurable Flight Control System (RDFCS) Facility to fully automate the total test loop involving the Draper Laboratories' Fault Injector Unit. The automated capability provided included the application of sequences of simulated low-level hardware faults, the precise measurement of fault latency times, the identification of fault symptoms, and bulk storage of test case results. A PDP-11/60 served as a test coordinator, and a PDP-11/04 as an instrumentation device. The fault injector was controlled by applications test software in the PDP-11/60, rather than by manual commands from a terminal keyboard. The time base was especially developed for this application to use a variety of signal sources in the system simulator.

Benson, J. W.↗

Bayesian Safety Risk Modeling of Human-Flightdeck Automation Interaction

Usage of automatic systems in airliners has increased fuel efficiency, added extra capabilities, enhanced safety and reliability, as well as provide improved passenger comfort since its introduction in the late 80's. However, original automation benefits, including reduced flight crew workload, human errors or training requirements, were not achieved as originally expected. Instead, automation introduced new failure modes, redistributed, and sometimes increased workload, brought in new cognitive and attention demands, and increased training requirements. Modern airliners have numerous flight modes, providing more flexibility (and inherently more complexity) to the flight crew. However, the price to pay for the increased flexibility is the need for increased mode awareness, as well as the need to supervise, understand, and predict automated system behavior. Also, over-reliance on automation is linked to manual flight skill degradation and complacency in commercial pilots. As a result, recent accidents involving human errors are often caused by the interactions between humans and the automated systems (e.g., the breakdown in man-machine coordination), deteriorated manual flying skills, and/or loss of situational awareness due to heavy dependence on automated systems. This paper describes the development of the increased complexity and reliance on automation baseline model, named FLAP for FLightdeck Automation Problems. The model development process starts with a comprehensive literature review followed by the construction of a framework comprised of high-level causal factors leading to an automation-related flight anomaly. The framework was then converted into a Bayesian Belief Network (BBN) using the Hugin Software v7.8. The effects of automation on flight crew are incorporated into the model, including flight skill degradation, increased cognitive demand and training requirements along with their interactions. Besides flight crew deficiencies, automation system failures and anomalies of avionic systems are also incorporated. The resultant model helps simulate the emergence of automation-related issues in today's modern airliners from a top-down, generalized approach, which serves as a platform to evaluate NASA developed technologies

Ancel, Ersin↗

Learning Automation Update

This presentation provides a brief update on the national-level airport and airspace clustering work that is being conducted in support of the learning automation component of the EFICA RTT.

data mining↗

Automated Air Traffic Control Operations with Weather and Time-Constraints: A First Look at (Simulated) Far-Term Control Room Operations

In this paper we discuss results from a recent high fidelity simulation of air traffic control operations with automated separation assurance in the presence of weather and time-constraints. We report findings from a human-in-the-loop study conducted in the Airspace Operations Laboratory (AOL) at the NASA Ames Research Center. During four afternoons in early 2010, fifteen active and recently retired air traffic controllers and supervisors controlled high levels of traffic in a highly automated environment during three-hour long scenarios, For each scenario, twelve air traffic controllers operated eight sector positions in two air traffic control areas and were supervised by three front line managers, Controllers worked one-hour shifts, were relieved by other controllers, took a 3D-minute break, and worked another one-hour shift. On average, twice today's traffic density was simulated with more than 2200 aircraft per traffic scenario. The scenarios were designed to create peaks and valleys in traffic density, growing and decaying convective weather areas, and expose controllers to heavy and light metering conditions. This design enabled an initial look at a broad spectrum of workload, challenge, boredom, and fatigue in an otherwise uncharted territory of future operations. In this paper we report human/system integration aspects, safety and efficiency results as well as airspace throughput, workload, and operational acceptability. We conclude that, with further refinements. air traffic control operations with ground-based automated separation assurance can be an effective and acceptable means to routinely provide very high traffic throughput in the en route airspace.

Prevot, Thomas↗