Search NASA⌕ Search

SEARCH · Search NASA

Results for “Flight Control System Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

468 records · Page 26

Formal Safety Certification of Aerospace Software

In principle, formal methods offer many advantages for aerospace software development: they can help to achieve ultra-high reliability, and they can be used to provide evidence of the reliability claims which can then be subjected to external scrutiny. However, despite years of research and many advances in the underlying formalisms of specification, semantics, and logic, formal methods are not much used in practice. In our opinion this is related to three major shortcomings. First, the application of formal methods is still expensive because they are labor- and knowledge-intensive. Second, they are difficult to scale up to complex systems because they are based on deep mathematical insights about the behavior of the systems (t.e., they rely on the "heroic proof"). Third, the proofs can be difficult to interpret, and typically stand in isolation from the original code. In this paper, we describe a tool for formally demonstrating safety-relevant aspects of aerospace software, which largely circumvents these problems. We focus on safely properties because it has been observed that safety violations such as out-of-bounds memory accesses or use of uninitialized variables constitute the majority of the errors found in the aerospace domain. In our approach, safety means that the program will not violate a set of rules that can range for the simple memory access rules to high-level flight rules. These different safety properties are formalized as different safety policies in Hoare logic, which are then used by a verification condition generator along with the code and logical annotations in order to derive formal safety conditions; these are then proven using an automated theorem prover. Our certification system is currently integrated into a model-based code generation toolset that generates the annotations together with the code. However, this automated formal certification technology is not exclusively constrained to our code generator and could, in principle, also be integrated with other code generators such as RealTime Workshop or even applied to legacy code. Our approach circumvents the historical problems with formal methods by increasing the degree of automation on all levels. The restriction to safety policies (as opposed to arbitrary functional behavior) results in simpler proof problems that can generally be solved by fully automatic theorem proves. An automated linking mechanism between the safety conditions and the code provides some of the traceability mandated by process standards such as DO-178B. An automated explanation mechanism uses semantic markup added by the verification condition generator to produce natural-language explanations of the safety conditions and thus supports their interpretation in relation to the code. It shows an automatically generated certification browser that lets users inspect the (generated) code along with the safety conditions (including textual explanations), and uses hyperlinks to automate tracing between the two levels. Here, the explanations reflect the logical structure of the safety obligation but the mechanism can in principle be customized using different sets of domain concepts. The interface also provides some limited control over the certification process itself. Our long-term goal is a seamless integration of certification, code generation, and manual coding that results in a "certified pipeline" in which specifications are automatically transformed into executable code, together with the supporting artifacts necessary for achieving and demonstrating the high level of assurance needed in the aerospace domain.

Denney, Ewen↗

Automation Bias and Countermeasures in Flight Crews

Results of recent research investigating the use of automated systems have indicated the presence of automation bias, a term describing errors made when decision makers rely on automated cues as a heuristic replacement for vigilant information seeking and processing. Automation commission errors, i.e., errors made when decision makers take inappropriate action because they over-attend to automated information or directives, and automation omission errors, i.e., errors made when decision makers do not take appropriate action because they are not informed of an imminent problem or situation by automated aids, can result from this tendency. In a series of studies, participants who perceived themselves as "accountable" for their strategies of interaction with automation were significantly more likely to verify its correct functioning, and committed significantly fewer automation-related errors than those who did not report this perception. In this study, we focus on two manipulations to encourage verification behaviors within cockpit crews. The first, an information/training manipulation, will focus on explicit information on automation bias, and training for verification of automated functioning. The second manipulation will consist of display prompts to verify automated functioning. Participants (glass-cockpit crews) will fly a series of approaches on the Mini-ACFS, a two-person pan-task flight simulator. Approach scenarios include several automation "events," that is, glitches, malfunctions, or inappropriate recommendations, that can be caught if cross-checked with other cockpit indicators. We anticipate that these manipulations will ameliorate automation bias. Final data analysis will be completed prior to the OSU symposium, and is expected to support the hypotheses that: a) reduced errors are associated with verification behaviors; b) crews will be more likely to verify under training/display conditions than when in the control condition; and c) effects will persist when subjects return for a follow-up exercise 6-9 weeks after their first session. Implications for training and automation design will be discussed.

Mosier, Kathleen, L.↗

Flight Software Dictionary Development for the Mars2020 Rover

The Mars2020 project, developed and operated by the Jet Propulsion Laboratory (JPL), successfully landed the Perseverance rover and its flying companion Ingenuity on the surface of Mars on February 18th 2021. Perseverance combines heritage and cutting-edge flight software and hardware to accomplish crucial mission requirements related to Martian surface sampling. The design, development, and operation of NASA’s large strategic science missions require the ability to communicate spacecraft capabilities to hundreds of engineers across multiple disciplines. The interaction between flight and ground software development, Verification and Validation (V&V), Assembly, Test, and Launch Operations (ATLO), and management each demand quick understanding of unique slices of information for each discipline. This information includes the current capabilities of the flight system as well as future capabilities and their status as they are developed and tested. Despite the fundamental and critical nature of this information, the flight software dictionaries used to track it are a stumbling block for many projects. These dictionaries provide the cornerstone for the interpretation of data sent from the spacecraft, allowing for quick comprehension by engineers on the ground. During both spacecraft development and operations, flight software dictionary management includes significant challenges due to the large number of interfacing systems and the subtle yet distinct needs of each.The engineering of flight software dictionaries for Mars2020 had numerous challenges, most-notably: parallel dictionary development to support simultaneous separate flight software build campaigns for each mission phase (cruise and surface), managing requests for operations-enabling information without perturbing the heritage interface with the rover, and the introduction of new tools by the dictionary stakeholders that forced the dictionary team to innovate and redesign the heritage tool chain. These challenges generated guiding principles for the dictionary development effort: emphasize coding best practices and unit testing in the dictionary code development tool chain, use institutionally provided COTS (commercial-off-the-shelf) tools whenever possible, and maintain the heritage flight-ground interface all while advancing operations-enabling information via a loosely coupled interface.Throughout development and operations, the Mars2020 dictionary toolchain included IBM DOORS Next Generation, GitHub, Microsoft Excel, Docker, Jenkins, and a significant custom-built Python codebase. Significant interfaces included JPL’s command and control software, heritage flight software team tools and processes, and the many cloud-based ground tools developed for the mission.This paper will discuss the requirements for the Mars2020 dictionary development, the development team’s response to those requirements, lessons learned throughout the process, steps taken towards automated deliveries and continuous integration of stakeholder inputs, potential toolchain improvements for Mars2020, and key takeaways that could be applied to future missions.

Pyrzak, Guy↗

Space shuttle Production Verification Motor 1 (PV-1) static fire

All inspection and instrumentation data indicate that the PV-1 static test firing conducted 18 Aug. 1988 was successful. With the exception of the intentionally flawed joints and static test modifications, PV-1 was flight configuration. Fail-safe flaws guaranteeing pressure to test the sealing capability of primary O-rings were included in the aft field joint, case-to-nozzle joint, and nozzle internal Joint 5. The test was conducted at ambient conditions, with the exception of the field joints and case/nozzle joints which were maintained at a minimum of 75 F. Ballistics performance values were within specification requirements. The PV-1 motor exhibited chamber pressure oscillations similar to previously tested Space Shuttle redesigned solid rocket motors, particularly QM-7. The first longitudinal mode oscillations experienced by PV-1 were the strongest ever measured in a Space Shuttle motor. Investigation into this observation is being conducted. Joint insulation performed as designed with no evidence of gas flow within unflawed forward field joints. The intentionally flawed center and aft case field joint insulation performance was excellent. There was no evidence of hot gas past the center field joint capture feature O-ring, the case-to-nozzle joint primary O-ring, or the aft field joint primary O-ring. O-ring seals and barriers with assured pressure at the flaws showed erosion and heat effect, but all sealed against passage of hot gases with the exception of the aft field joint capture feature O-ring. There was no evidence of erosion, heat effect, or blowby on any O-ring seals or barriers at the unflawed joints. Nozzle performance was nominal with typical erosion. Post-test examination revealed that the forward nose ring was of the old high performance motor design configuration with the 150-deg ply angle. All nozzle components remained intact for post-test evaluation. The thrust vector control system operated correctly. The water deluge system, CO2 quench, and other test equipment performed as planned during all required test operations.

Source record↗

Hardware Development Process for Human Research Facility Applications

The simple goal of the Human Research Facility (HRF) is to conduct human research experiments on the International Space Station (ISS) astronauts during long-duration missions. This is accomplished by providing integration and operation of the necessary hardware and software capabilities. A typical hardware development flow consists of five stages: functional inputs and requirements definition, market research, design life cycle through hardware delivery, crew training, and mission support. The purpose of this presentation is to guide the audience through the early hardware development process: requirement definition through selecting a development path. Specific HRF equipment is used to illustrate the hardware development paths. The source of hardware requirements is the science community and HRF program. The HRF Science Working Group, consisting of SCientists from various medical disciplines, defined a basic set of equipment with functional requirements. This established the performance requirements of the hardware. HRF program requirements focus on making the hardware safe and operational in a space environment. This includes structural, thermal, human factors, and material requirements. Science and HRF program requirements are defined in a hardware requirements document which includes verification methods. Once the hardware is fabricated, requirements are verified by inspection, test, analysis, or demonstration. All data is compiled and reviewed to certify the hardware for flight. Obviously, the basis for all hardware development activities is requirement definition. Full and complete requirement definition is ideal prior to initiating the hardware development. However, this is generally not the case, but the hardware team typically has functional inputs as a guide. The first step is for engineers to conduct market research based on the functional inputs provided by scientists. CommerCially available products are evaluated against the science requirements as well as modifications needed to meet program requirements. Options are consolidated and the hardware development team reaches a hardware development decision point. Within budget and schedule constraints, the team must decide whether or not to complete the hardware as an in-house, subcontract with vendor, or commercial-off-the-shelf (COTS) development. An in-house development indicates NASA personnel or a contractor builds the hardware at a NASA site. A subcontract development is completed off-site by a commercial company. A COTS item is a vendor product available by ordering a specific part number. The team evaluates the pros and cons of each development path. For example, in-bouse developments utilize existing corporate knowledge regarding bow to build equipment for use in space. However, technical expertise would be required to fully understand the medical equipment capabilities, such as for an ultrasound system. It may require additional time and funding to gain the expertise that commercially exists. The major benefit of subcontracting a hardware development is the product is delivered as an end-item and commercial expertise is utilized. On the other hand, NASA has limited control over schedule delays. The final option of COTS or modified COTS equipment is a compromise between in-house and subcontracts. A vendor product may exist that meets all functional requirements but req uires in-house modifications for successful operation in a space environment. The HRF utilizes equipment developed using all of the paths described: inhouse, subcontract, and modified COTS.

Bauer, Liz↗

Making or Breaking a Rover: System Engineering Parameters On-Board the Mars 2020 Perseverance Rover

On February 18, 2021, Perseverance, NASA’s Jet Propulsion Laboratory’s (JPL’s) Mars 2020 Rover, successfully landed on Mars with all systems nominal, despite the risk surrounding the over 200,000 internal flight parameters that had to be properly configured. The Perseverance team defines these parameters as software variables that are configurable, commandable and retrievable from Earth. In 2015, the Mars 2020 project leaders focused on improving systems engineering of parameters based on their experiences from parameter management on previous Mars rovers (Curiosity, Opportunity, Spirit, and Pathfinder) and parameter failures of past missions, such as the mission-ending parameter of the Mars Climate Orbiter. The new rigorous development process allowed for efficient certification and effective implementation of the parameters, allowing the rover to approach and land on the red planet (the most challenging phase of the mission) with zero parameter issues. Although successful, the Perseverance team learned many lessons for how to better manage parameters for the continued surface operations of the Mars 2020 mission and future missions. This paper will discuss eight parameter-management topics for the Perseverance Mission. The first is parameter definition: how we define parameters on our mission, where they are physically located on the vehicle, and why we have so many of them. The second topic is the updated parameter flight software module from Curiosity, including details on the 99% reduction in parameter commands, new bulk configuration capabilities, and improved parameter traceability. The third topic is parameter selection for different mission phases; this includes improving and tweaking our preferred parameter settings until they become certification candidates and managing parameter configurations based on test venue throughout the mission life cycle. The fourth topic is our flight certification process; this includes certification of flight values for four different epochs in the mission: Launch, Entry Decent and Landing (EDL) - 6days, Landing + 5 Sols (Martian Days, still on Cruise Flight Software), and once are on Surface Flight Software (FSW). The fifth topic covers in-flight command implementation, along with details on testing, validation, and verification of those commands. In the sixth section, we will explain our use of open-source management tools, including how we used GitHub for version control and management approvals. The seventh topic will describe the ground tools used in operations, including capabilities of the in-house built tool called Parasol. The eighth and final topic will dig into lessons learned for improving parameter management in the future of this mission and others.

Roth, Brian↗

Making or Breaking a Rover- Systems Engineering Parameters On-Board the Mars 2020 Perseverance Rover

On February 18, 2021, Perseverance, NASA’s Jet Propulsion Laboratory’s (JPL’s) Mars 2020 Rover, successfully landed on Mars with all systems nominal, despite the risk surrounding the over 200,000 internal flight parameters that had to be properly configured. The Perseverance team defines these parameters as software variables that are configurable, commandable and retrievable from Earth. In 2015, the Mars 2020 project leaders focused on improving systems engineering of parameters based on their experiences from parameter management on previous Mars rovers (Curiosity, Opportunity, Spirit, and Pathfinder) and parameter failures of past missions, such as the mission-ending parameter of the Mars Climate Orbiter. The new rigorous development process allowed for efficient certification and effective implementation of the parameters, allowing the rover to approach and land on the red planet (the most challenging phase of the mission) with zero parameter issues. Although successful, the Perseverance team learned many lessons for how to better manage parameters for the continued surface operations of the Mars 2020 mission and future missions. This paper will discuss eight parameter-management topics for the Perseverance Mission. The first is parameter definition: how we define parameters on our mission, where they are physically located on the vehicle, and why we have so many of them. The second topic is the updated parameter flight software module from Curiosity, including details on the 99% reduction in parameter commands, new bulk configuration capabilities, and improved parameter traceability. The third topic is parameter selection for different mission phases; this includes improving and tweaking our preferred parameter settings until they become certification candidates and managing parameter configurations based on test venue throughout the mission life cycle. The fourth topic is our flight certification process; this includes certification of flight values for four different epochs in the mission: Launch, Entry Decent and Landing (EDL) - 6days, Landing + 5 Sols (Martian Days, still on Cruise Flight Software), and once are on Surface Flight Software (FSW). The fifth topic covers in-flight command implementation, along with details on testing, validation, and verification of those commands. In the sixth section, we will explain our use of open-source management tools, including how we used GitHub for version control and management approvals. The seventh topic will describe the ground tools used in operations, including capabilities of the in-house built tool called Parasol. The eighth and final topic will dig into lessons learned for improving parameter management in the future of this mission and others.

Roth, Brian↗

Development and Qualification of the Primary Structure of the Orion European Service Module

This paper presents an overview of the development and qualification test campaign for the primary structure of the European Service Module of ORION, the NASA spacecraft which will serve the future human exploration missions to the Moon, Mars and beyond. Under an agreement between NASA and ESA, the ORION will be powered by a European Service Module (ESM), providing also water and oxygen for astronauts' life sustainability. The development and qualification of the European Service Module (ESM) is under ESA responsibility with Airbus Defense and Space as the prime contractor. Thales Alenia Space Italia is responsible for design development, manufacturing, assembly and qualification of the Structure subsystem. The European Service Module, installed onto the launch adapter, shall support the crew module with its adapter and a launch abort system. It shall sustain: - A combination of global and local launch loads during lift off and ascent phases, - On orbit loads induced by engine firing for orbital transfers and attitude control. The ESM structure is based on a core made of Composite Fiber Reinforced Polymer (CFRP) sandwich panels complemented by aluminum alloy platforms, longerons and secondary structures. A development campaign has been implemented in order to define and validate composite parts' strength allowable values for design: coupon tests at material level, test at component level up to breadboards tests performed on main structural components (composite to metallic joints, and at panels' discontinuities). An incremental approach as defined in [1] has been followed. A qualification static test campaign at primary structure assembly level has been implemented in order to validate the design against static stiffness and ultimate strength as well as to correlate the structural Finite Element Model (FEM) used for sizing and confirm the margins of safety. The tests have been performed successfully by Thales Alenia Space Italia (TAS-I) on two flight representative structural models (STA1, STA2), in Turin facilities (Italy) between August 2015 and March 2017, with engineering support of technical representatives from Airbus, ESA, NASA and LMCO. The main development and qualification test activities and associated results are presented and discussed in the paper

Structural Testing↗

Supporting Crew Autonomy in Deep Space Exploration: Preliminary Onboard Capability Requirements and Proposed Research Questions. Technical Report of the Autonomous Crew Operations Technical Interchange Meeting

Communication delays are a critical challenge posed by long duration deep space exploration. Space missions historically have relied on an ever-present Mission Control Center (MCC) to direct operations in near real-time. As unanticipated anomalies that defeat fault detection and resolution systems do arise, the lack of real-time communication will significantly weaken what the MCC support represents: a reliable safety net for the flight crew through its deep and diverse areas of expertise and investigative resources. As a consequence, future space vehicles and habitats need to be equipped with capabilities to support the flight crew to operate with little or no ground support. Considerations must be given to vehicle and mission designs that will fortify the traditionally ground-centered safety net and forge new support systems, when communication delays exist. In August 2018, NASA’s Human Research Program, through its Human Factors and Behavioral Performance Element, convened a Technical Interchange Meeting (TIM) on Autonomous Crew Operations at NASA Ames Research Center. The goal of the meeting was to gather input from NASA centers, industry, academia, and branches of the Department of Defense (DoD) to address how intelligent technologies can be applied to augment onboard capabilities to support crew anomaly response. The TIM featured 24 presentations by 29 speakers and hosted a total of 59 attendees, including 43 from 5 NASA centers (Ames, Johnson, Langley, Marshall, and Jet Propulsion Lab) and 4 from the DoD (3 from Army Research Lab and 1 from Naval Postgraduate School), with remaining attendees from academia (e.g., UC Davis, CMU) and industry (e.g., IBM, Siemens). Discussions were centered around three themes: standards and guidelines, lessons learned in analog environments, and technologies. To help provide a framework for discussion, a concept matrix describing anomaly response processes was created prior to the TIM (Figure 1, page 6). The matrix captures the steps involved (monitoring and detection, diagnosis, solution development and evaluation, solution implementation and verification, resolution documentation) as well as the resources and capabilities required to support these steps (data, knowledge, analysis, synthesis, resource management). A wallpaper size printout of the matrix was utilized at the TIM to solicit attendee inputs along the three themes; the activity garnered 108 submissions of ideas. Overall, what emerged from TIM discussions was a picture of mismatch between crew anomaly response needs and support that can be provided by existing intelligent technologies. The needs are broad, spanning multiple steps and processes/resources, with many of which lacking support from existing technologies, such as knowledge management throughout the steps of problem solving (especially in resolution documentation) and manpower management. The solutions provided by existing intelligent technologies are specific to the steps/processes that they are designed to support and constrained to solving only problems similar to those that have occurred before. What is lacking from technologies is typically made up by humans, specifically their complex critical thinking, creative problem solving, and domain expertise. In the end, the TIM highlighted the pressing need to support responses to onboard anomalies during autonomous crew operations, particularly those that have eluded the system tests, inspection, and other assurance processes. Such anomalies can potentially threaten crew and vehicle safety, as well as significantly impact overall operations with additional workload. These fairly rare events are difficult to anticipate and prepare for, given the state-of-the-art in intelligent technologies. This is true even for anomalies that stem from “unknown knowns”—cases in which there is sufficient external information to characterize the problem but the overall pattern fails to be recognized by the problem solver, or in which the internal knowledge needed to solve a problem is held tacitly and potentially accessible by the problem solver but not articulated. It follows that the ability to tackle anomalies lies not only with the availability of relevant information and knowledge but also their accessibility in times of need. To that end, we propose research questions along the following three broad themes: • How intelligent technologies can help make relevant knowledge and information available? • How intelligent technologies can help make relevant knowledge and information accessible? • How intelligent technologies can help support the crew operating as a team in anomaly response processes?

autonomous crew operations↗

Decision Making In A High-Tech World: Automation Bias and Countermeasures

Automated decision aids and decision support systems have become essential tools in many high-tech environments. In aviation, for example, flight management systems computers not only fly the aircraft, but also calculate fuel efficient paths, detect and diagnose system malfunctions and abnormalities, and recommend or carry out decisions. Air Traffic Controllers will soon be utilizing decision support tools to help them predict and detect potential conflicts and to generate clearances. Other fields as disparate as nuclear power plants and medical diagnostics are similarly becoming more and more automated. Ideally, the combination of human decision maker and automated decision aid should result in a high-performing team, maximizing the advantages of additional cognitive and observational power in the decision-making process. In reality, however, the presence of these aids often short-circuits the way that even very experienced decision makers have traditionally handled tasks and made decisions, and introduces opportunities for new decision heuristics and biases. Results of recent research investigating the use of automated aids have indicated the presence of automation bias, that is, errors made when decision makers rely on automated cues as a heuristic replacement for vigilant information seeking and processing. Automation commission errors, i.e., errors made when decision makers inappropriately follow an automated directive, or automation omission errors, i.e., errors made when humans fail to take action or notice a problem because an automated aid fails to inform them, can result from this tendency. Evidence of the tendency to make automation-related omission and commission errors has been found in pilot self reports, in studies using pilots in flight simulations, and in non-flight decision making contexts with student samples. Considerable research has found that increasing social accountability can successfully ameliorate a broad array of cognitive biases and resultant errors. To what extent these effects generalize to performance situations is not yet empirically established. The two studies to be presented represent concurrent efforts, with student and professional pilot samples, to determine the effects of accountability pressures on automation bias and on the verification of the accurate functioning of automated aids. Students (Experiment 1) and commercial pilots (Experiment 2) performed simulated flight tasks using automated aids. In both studies, participants who perceived themselves as accountable for their strategies of interaction with the automation were significantly more likely to verify its correctness, and committed significantly fewer automation-related errors than those who did not report this perception.

Mosier, Kathleen L.↗

Maiden Voyage of the Rodent Habitat on ISS: Opportunities for Investigating Molecular Mechanisms and Biomedical Consequences of Long Duration Spaceflight

Research using rodents is an essential tool for advancing biomedical research on Earth and in space. The National Research Counsel’s Decadal survey (1) emphasized the importance of expanding NASAs life sciences research to perform long duration, rodent experiments on the International Space Station (ISS). To accomplish this objective, flight hardware, operations, and science capabilities were developed at NASA ARC to support both commercial and government-sponsored research. In preparation for the maiden voyage of the Rodent Habitat hardware and operations system (Rodent Research-1), and in close consultation with a Science Working Group comprised of veterinarians and experienced spaceflight investigators, we modified existing Animal Enclosure Module hardware, developed new hardware, operations, and science activities, and performed a series of ground-based verification tests. Preflight, ground based hardware tests included a simulation of SpaceX Dragon launch conditions (vibration and hypergravity) using the Transporter, and also two long-term biocompatibility tests (32 and 92 days) using the Habitat developed for long term housing on the ISS. The launch simulation test showed that adult mice housed in Transporter hardware adapted well, even if launch simulation was followed by a period of simulated weightlessness (via hind limb unloading). The biocompatibility tests demonstrated that the Habitat successfully supported animal health and also provided a useful video imaging system that enables frequent monitoring of animal health and behavior by veterinary and scientific experts on the ground, independent of ISS crew intervention. At the conclusion of all tests, mice were deemed healthy and suitable for conducting biological research. Additional preflight analyses of tissues preserved by freezing or fixation for gene expression analyses revealed that spleen and liver tissues recovered under conditions that simulated on-orbit activities yielded high quality RNA (RIN values 8-10) and liver enzyme activities and protein content (e.g. catalase). In addition, new methods were developed to optimize future science return by dissecting tissues post-euthanasia and storage. Various tissues were harvested from either intact or partially dissected, frozen carcasses after storage for ~2-6 months; most of the tissues (brain, heart, kidney, eye, adrenal glands and skeletal muscle) were of high RNA quality for science return, whereas some tissues (small intestine, bone marrow and bones) were not. These data demonstrated the protocols developed for future flight experiments supported science return despite delayed preservation post-euthanasia or prolonged storage, and furthermore, that high-quality RNA samples from many different tissues can be recovered by dissection following prolonged storage of the tissue in situ at -80˚C. The first flight experiments carrying 20 mice were launched on Sept 21, 2014 in an unmanned Dragon Capsule, SpaceX4; Rodent Research-1 is dedicated to achieving both NASA validation and CASIS science objectives. Ground based control groups (housed in flight hardware or standard cages) were maintained in environmental chambers at Kennedy Space Center. Crewmembers previously trained in animal handling transferred mice from the Transporter into Habitats under simultaneous veterinary supervision by video streaming and were deemed healthy. Health and behavior of all mice on the ISS was monitored by video feed on a daily basis. The 10 mice for validation (16wk old, female C57Bl6/J) ambulated freely and actively throughout the Habitat, relying heavily on their forelimbs for locomotion. The first on-orbit dissections of mice were performed successfully on Oct 12 and 13, 2014, and the validation mice will reside on ISS for up to 30 days. In conclusion, new capability for long duration rodent research is under development, including in-flight sample collection (which avoids the complication of reentry); results obtained to date will be described. This new Rodent Research system enables achievement of both basic science and translational research objectives to advance human exploration of space.

maiden voyage↗

Dynamics of Superfluid Helium in Low-Gravity

This report summarizes the work performed under a contract entitled 'Dynamics of Superfluid Helium in Low Gravity'. This project performed verification tests, over a wide range of accelerations of two Computational Fluid Dynamics (CFD) codes of which one incorporates the two-fluid model of superfluid helium (SFHe). Helium was first liquefied in 1908 and not until the 1930s were the properties of helium below 2.2 K observed sufficiently to realize that it did not obey the ordinary physical laws of physics as applied to ordinary liquids. The term superfluidity became associated with these unique observations. The low temperature of SFHe and it's temperature unifonrmity have made it a significant cryogenic coolant for use in space applications in astronomical observations with infrared sensors and in low temperature physics. Superfluid helium has been used in instruments such as the Shuttle Infrared Astronomy Telescope (IRT), the Infrared Astronomy Satellite (IRAS), the Cosmic Background Observatory (COBE), and the Infrared Satellite Observatory (ISO). It is also used in the Space Infrared Telescope (SIRTF), Relativity Mission Satellite formally called Gravity Probe-B (GP-B), and the Test of the Equivalence Principle (STEP) presently under development. For GP-B and STEP, the use of SFHE is used to cool Superconducting Quantum Interference Detectors (SQUIDS) among other parts of the instruments. The Superfluid Helium On-Orbit Transfer (SHOOT) experiment flown in the Shuttle studied the behavior of SFHE. This experiment attempted to get low-gravity slosh data, however, the main emphasis was to study the low-gravity transfer of SFHE from tank to tank. These instruments carried tanks of SFHE of a few hundred liters to 2500 liters. The capability of modeling the behavior of SFHE is important to spacecraft control engineers who must design systems that can overcome disturbances created by the movement of the fluid. In addition instruments such as GP-B and STEP are very sensitive to quasi-steady changes in the mass distribution of the liquid. The CFD codes were used to model the fluid's dynamic motion. Tests in one-g were performed with the main emphasis on being able to compute the actual damping of the fluid. A series of flights on the NASA Lewis reduced gravity DC-9 aircraft were performed with the Jet Propulsion Laboratory (JPL) Low Temperature Flight Facility and a superfluid Test Cell. The data at approximately 0.04g, lg and 2g were used to determine if correct fundamental frequencies can be predicted based on the acceleration field. Tests in zero gravity were performed to evaluate zero gravity motion.

Frank, David J.↗

Progress on LISA Colloid Microthruster Technology Development

Colloid microthrusters have been operated successfully in flight, providing drag-free and precision control for spacecraft that can be used for future applications such as gravity wave and exoplanet observatories. The Space Technology 7 Disturbance Reduction System (ST7- DRS) technology demonstration payload included eight Busek Colloid Micro-Newton Thrusters (CMNTs) as part of the Laser Interferometer Space Antenna (LISA) Pathfinder mission that launched in December of 2015. The CMNTs provided full attitude and precision drag-free control of the spacecraft with <10 nm/√Hz stability along the most sensitive axis during commissioning, nominal, and extended mission phases through April of 2017. Performance requirements (≤0.1 μN/√Hz) were met and models were validated based on on- orbit measurements of test mass motion and actuation during the 60-day nominal and 30-day extended missions. In 2018, the European Space Agency (ESA) selected LISA to be the agency’s next “large-class” mission, currently in Phase A, with a launch scheduled for 2034 and a 12.5-year duration, including the transfer (1.5 years), commissioning (1 year), nominal (4 or 6 years), and extended (6 or 4 years) phases of the mission, which sets the lifetime and consumables requirement. NASA is considering a significant contribution of hardware to the ESA-led mission, potentially including colloid microthrusters. In preparation, NASA is developing five technologies to TRL 5 and 6, including the colloid microthrusters, to be ready for infusion into LISA by the mission adoption review (MAR), currently scheduled for 2024. While ST7-DRS effectively brought the CMNTs to TRL 7, additional lower-TRL flow control components must be developed for full redundancy, reducing the system-level TRL back to 4. Key to the future of the colloid microthruster technology will be to use lessons learned and keep as much of the heritage from the ST7 design as possible while updating the system to support redundancy and lifetime requirements of a flagship-class mission. This paper describes the technology plan and progress to reach TRL 6 by the MAR, focusing on near- term plans to reach TRL 5 by the end of March 2022 for the LISA Colloid Microthrusters (CMTs). Work includes requirements development and sizing studies, breadboard and brassboard hardware developments at Busek, including relevant lifetime and environment testing, and lifetime modeling, verification and validation efforts at JPL, UCLA, and UCI.

Gamero-Castaño, Manuel↗

Pick-and-Eat Space Crop Production Flight Testing on the International Space Station

Growing fresh, nutritious, palatable produce for crew consumption during spaceflight may provide health-promoting, bioavailable nutrients and enhance the astronaut dietary experience as we move toward longer-duration missions. However, requirements to support consistent growth of a variety of high-quality crops under spaceflight environmental conditions remain unclear. This study explores the potential to grow crops for consumption on the International Space Station (ISS) using Veggie, NASA’s vegetable production chamber system. VEG-04A and VEG-04B were two flight tests with ground components conducted with the leafy green crop mizuna mustard. In each location, mizuna was grown in two Veggie units simultaneously, with the chambers set to different red-to-blue-to-green light formulations. Preflight verification testing with various lighting treatments was conducted to down-select two treatments that contributed to the best desirable growth and sensory qualities in mizuna mustard. For the flight tests, one Veggie was programmed as “red-rich” with an average of 270 μmol m-2 s-1 of 630 nm red light, 30 μmol m-2 s-1 of 455 nm blue light, and 30 μmol m-2 s-1 of 530 nm green light. The second Veggie was “blue-rich” with an average of 150 µmol m-2 s-1 of 630 nm red light, 150 µmol m-2 s-1 of 455 nm blue light, and 30 µmol m-2 s-1 of 530 nm green light. Light quality is known to impact plant growth, nutrition, microbiology, and sensory characteristics on Earth, and the Veggie flight tests examined how these impacts might differ in microgravity. VEG-04A, a 35-day growth test with a single harvest, was initiated in June and harvested in July 2019. VEG-04B, a 56-day test with three harvests from the same plants, assessed sustained productivity. Preflight testing for VEG-04B was conducted after the VEG-04A flight test to improve the operations, approaches, and watering requirements, which resulted in better crop establishment in the VEG-04B flight test. VEG-04B was initiated in October 2019 with harvests at four, six, and eight weeks after initiation. At all of the harvests, the astronauts froze half of the edible plant tissue to return to Earth and weighed the remaining half using the Mass Measurement Device (MMD). Weighed samples were then cleaned with produce-sanitizing wipes, and consenting crew members participated in sensory evaluations of the fresh produce. The remaining sanitized produce was available for crew consumption as desired. Frozen flight samples were returned to Earth for chemical and microbial analyses to assess nutritional quality and food safety. Flight-grown mizuna was generally more acceptable to the crew and had higher nutrient levels, although mizuna grown in the ground control performed better in terms of higher yield and lower microbial load. This presentation will focus on results from the nutritional and sensory analyses, including how nutrients identified as key for supplementing the crew diet varied across lighting treatments, harvest approaches, and spaceflight versus ground conditions. It is our hope that these tests on the ISS will help mitigate the risk of an inadequate food supply for long-duration missions by adding fresh vegetables to the crew diet. This study was supported by NASA’s Human Research and Space Biology Programs through the HERO NNJ13ZSA002N-ILSRA grant solicitation.

Jess Bunchek↗

SpaceCube v2.0 Space Flight Hybrid Reconfigurable Data Processing System

This paper details the design architecture, design methodology, and the advantages of the SpaceCube v2.0 high performance data processing system for space applications. The purpose in building the SpaceCube v2.0 system is to create a superior high performance, reconfigurable, hybrid data processing system that can be used in a multitude of applications including those that require a radiation hardened and reliable solution. The SpaceCube v2.0 system leverages seven years of board design, avionics systems design, and space flight application experiences. This paper shows how SpaceCube v2.0 solves the increasing computing demands of space data processing applications that cannot be attained with a standalone processor approach.The main objective during the design stage is to find a good system balance between power, size, reliability, cost, and data processing capability. These design variables directly impact each other, and it is important to understand how to achieve a suitable balance. This paper will detail how these critical design factors were managed including the construction of an Engineering Model for an experiment on the International Space Station to test out design concepts. We will describe the designs for the processor card, power card, backplane, and a mission unique interface card. The mechanical design for the box will also be detailed since it is critical in meeting the stringent thermal and structural requirements imposed by the processing system. In addition, the mechanical design uses advanced thermal conduction techniques to solve the internal thermal challenges.The SpaceCube v2.0 processing system is based on an extended version of the 3U cPCI standard form factor where each card is 190mm x 100mm in size The typical power draw of the processor card is 8 to 10W and scales with application complexity. The SpaceCube v2.0 data processing card features two Xilinx Virtex-5 QV Field Programmable Gate Arrays (FPGA), eight memory modules, a monitor FPGA with analog monitoring, Ethernet, configurable interconnect to the Xilinx FPGAs including gigabit transceivers, and the necessary voltage regulation. The processor board uses a back-to-back design methodology for common parts that maximizes the board real estate available. This paper will show how to meet the IPC 6012B Class 3A standard with a 22-layer board that has two column grid array devices with 1.0mm pitch. All layout trades such as stack-up options, via selection, and FPGA signal breakout will be discussed with feature size results. The overall board design process will be discussed including parts selection, circuit design, proper signal termination, layout placement and route planning, signal integrity design and verification, and power integrity results. The radiation mitigation techniques will also be detailed including configuration scrubbing options, Xilinx circuit mitigation and FPGA functional monitoring, and memory protection.Finally, this paper will describe how this system is being used to solve the extreme challenges of a robotic satellite servicing mission where typical space-rated processors are not sufficient enough to meet the intensive data processing requirements. The SpaceCube v2.0 is the main payload control computer and is required to control critical subsystems such as autonomous rendezvous and docking using a suite of vision sensors and object avoidance when controlling two robotic arms.

Xilinx FPGA↗

VEG-05 Tomato Crop Testing on the International Space Station

Production of fresh, nutritious, and tasty produce for astronauts during spaceflight may provide health-promoting, bioavailable nutrients, enhance the dietary experience, and reduce menu fatigue as we move into longer-duration missions. Growing and caring for plants may also reduce the psychological stresses associated with spaceflight and enhance connection to Earth. A diversity of crops will be required to provide nutrition, variety, and resiliency, however requirements for consistent growth under spaceflight environmental conditions remain unclear. VEG-05 is part of a series of experiments with pick-and-eat salad crops to better define best practices for crop production in space. VEG-05 and predecessor experiments VEG-04A and VEG-04B, grew salad crops in the Veggie vegetable production facilities on the International Space Station using different lighting treatments. In VEG-05 we grew ‘Red Robin’ dwarf cherry tomatoes under two different red: blue lighting spectra. Light can impact the growth habit, yield, nutritional composition, microbial levels, and even flavor attributes within crops, and our goal was to assess these characteristics in ‘Red Robin’ tomatoes during VEG-05. Considerable pre-flight verification testing was performed prior to launch in Nov. 2022. Prior to the flight and ground experiments, lighting in both Veggie units on ISS was measured and lights were standardized between flight and ground hardware. VEG-05 flight operations ran between December 2022 and March 2023, with a ground control initially 48 hours delayed. Due to environmental challenges of very low humidity during the first week of the experiment, seed germination was low for both flight and ground plants. The flight experiment ultimately had 4 - 5 plants per treatment out of the planned 6 plants, but the initial ground control had only three plants in one treatment and none in the other, so this ground control was restarted at the beginning of Feb. 2023 and ran through May, with successful growth of all 12 plants. Both flight and ground control ran 100 days, with harvests of fruit at day 83, day 90, and day 100. Flight plants had uneven growth, and following the early drying events, excess water was frequently observed, which led to a variety of plant stress responses including uneven plant growth, excess adventitious root formation, flower and fruit abortion, and visible microbial growth. In total, from the five surviving red-rich lighted plants, only 5 ripe fruit were produced, and from the four surviving blue-rich lighted plants, 10 fruit were produced with only 6 of these ripe by day 100. Because of the small fruit number and the unsatisfactory growth, crew members were not allowed to consume the tomatoes, and all fruit, as well as large branches with leaves, samples of the adventitious roots, two plant rooting pillows from each treatment, microbial sampling swabs, and some water samples were returned for analysis. Because of the small sample sizes and factors affecting growth on the ISS, objectives of assessing light quality effect (red: blue light treatments) will not be achieved. Revised objectives of this study include to compare stressed flight plants with normal ground plants to determine the impact of plant overwatering stress in space on food safety and the plant microbial community, to determine nutrient content changes in fruit and leaves from stressed plants, and to evaluate stress metabolism changes in returned tissue by transcriptomic analysis. Postflight analysis is underway with the following analyses being conducted: A. culturable microbiology and food safety as well as molecular microbial community analysis of 1. ripe fruit, 2. leaves, stems, and adventitious roots, 3. pillow components (roots, wicks, and substrates), 4. swabs, and 5. water samples from root mats before and after growth. B. transcriptomics of leaf tissue and adventitious roots, and C. elemental analysis of leaf tissue. If sufficient tissue remains elemental analyses will also be conducted on fruit. While not generating the desired information on spaceflight growth responses of healthy crops, our team is hopeful that these analyses will shed light on tomato responses to stress in this environment as plant overwatering stress is a mission-relevant condition that could occur in future space crop growth systems. This research was co-funded by the Human Research Program and Space Biology (MTL#1075) in the ILSRA 2015 NRA call.

Gioia D. Massa↗

Integrated Simulation Design Challenges to Support TPS Repair Operations

During the Orbiter Repair Maneuver (ORM) operations planned for Return to Flight (RTF), the Shuttle Remote Manipulator System (SRMS) must grapple the International Space Station (ISS), undock the Orbiter, maneuver it through a long duration trajectory, and orient it to an EVA crewman poised at the end of the Space Station Remote Manipulator System (SSRMS) to facilitate the repair of the Thermal Protection System (TPS). Once repair has been completed and confirmed, then the SRMS proceeds back through the trajectory to dock the Orbiter to the Orbiter Docking System. In order to support analysis of the complex dynamic interactions of the integrated system formed by the Orbiter, ISS, SRMS, and SSMS during the ORM, simulation tools used for previous ‘nominal’ mission support required substantial enhancements. These upgrades were necessary to provide analysts with the capabilities needed to study integrated system performance. Prevalent throughout this ORM operation is a dynamically varying topology. In other words, the ORM starts with the SRMS grappled to the mated Shuttle/ISS stack (closed loop topology), moves to an open loop chain topology consisting of the Shuttle, SRMS, and ISS, and then, at the repair configuration, extends the chain topology to one consisting of the Shuttle, SMS, ISS, and SSRMS/EVA crewman. The resulting long dynamic chain of vehicles and manipulators may exhibit significant motion between the Shuttle worksite and the EVA crewman due to the system flexibility throughout the topology (particularly within the SRMS/SSRMS joints and links). Since the attachment points of both manipulators span the flexible structure of the ISS, simulation analysis may also need to take that into consideration. Moreover, due to the lengthy time duration associated with the maneuver and repair, orbital effects become a factor and require the ISS vehicle control system to maintain active attitude control. Several facets of the ORM operation make the associated analytical efforts different from previous mission support, including: (1) the magnitude of the SRMS handled payload (Le., Orbiter class), (2) the orbital effects induced on the integrated system consisting of the large Shuttle and ISS masses connected by a light flexible SRMS, (3) long duration environmental consequences due to the lengthy operational times associated with the maneuver and repair of the TPS, (4) active attitude control (as opposed to free drift) interacting with the SRMS and SSRMS manipulators (also due to the length of the maneuver and repair), (5) relative dynamics between the EVA crewman and thc worksite influenced by the extended flexible topology. In order to meet these analysis challenges, an ORM simulation architecture was developed leveraging upon numerous pre-existing simulation elements to analyze the various subsystems individually. For example, core manipulator subsystem simulations for both the SRMS and SSRMS were originally combined to provide the dual-arm dynamics topology simulation (in the absence of orbital dynamics and vehicle control). This capability was later merged with the simulation used to analyze SRMS loading with a heavy payload in the orbital environment with an active payload control system (in this case, the ISS Attitude Control System (ACS)), configured for the ORM. The resulting worksite dynamics simulation, based off of the modified ORM simulation, provided the extended topological chain of vehicles and manipulators, while taking into account the orbital effects of both the Shuttle and ISS (as well as its ACS). Verification and validation (V&V) of these integrated simulations became a challenge in itself. A systematic approach needed to be developed such that integration simulation results could be tested against previous constituent simulations upon which these simulations were built. General V&V categories included: (1) core orbital state propagation, (2), stand-alone SRMS, (3) stand-alone SSRMS, (4) stand-alone ISS ACS, (5) integrated Shuttle, SRMS, ISS (with active ACS) in the orbital environment, and (5) dual-arm SRMS/SSRMS dynamics topology. Integrated simulation V&V run suites were created and correlated to verification runs from subsystem simulations, in order to establish the validity of the results. This paper discusses the simulation design challenges encountered while developing simulation capabilities to mirror the ORM operations. The paper also describes the incremental build approach that was utilized, starting with the subsystem simulation elements and integration into increasing more complex simulations until the resulting ORM worksite dynamics simulation had been assembled. Furthermore, the paper presents an overall integrated simulation V&V methodology based upon a subsystem level testing, integrated comparisons, and phased checkout.

Thermal Protection System↗

Dynamics of Sheared Granular Materials

This work focuses on the properties of sheared granular materials near the jamming transition. The project currently involves two aspects. The first of these is an experiment that is a prototype for a planned ISS (International Space Station) flight. The second is discrete element simulations (DES) that can give insight into the behavior one might expect in a reduced-g environment. The experimental arrangement consists of an annular channel that contains the granular material. One surface, say the upper surface, rotates so as to shear the material contained in the annulus. The lower surface controls the mean density/mean stress on the sample through an actuator or other control system. A novel feature under development is the ability to 'thermalize' the layer, i.e. create a larger amount of random motion in the material, by using the actuating system to provide vibrations as well control the mean volume of the annulus. The stress states of the system are determined by transducers on the non-rotating wall. These measure both shear and normal components of the stress on different size scales. Here, the idea is to characterize the system as the density varies through values spanning dense almost solid to relatively mobile granular states. This transition regime encompasses the regime usually thought of as the glass transition, and/or the jamming transition. Motivation for this experiment springs from ideas of a granular glass transition, a related jamming transition, and from recent experiments. In particular, we note recent experiments carried out by our group to characterize this type of transition and also to demonstrate/ characterize fluctuations in slowly sheared systems. These experiments give key insights into what one might expect in near-zero g. In particular, they show that the compressibility of granular systems diverges at a transition or critical point. It is this divergence, coupled to gravity, that makes it extremely difficult if not impossible to characterize the transition region in an earth-bound experiment. In the DE modeling, we analyze dynamics of a sheared granular system in Couette geometry in two (2D) and three (3D) space dimensions. Here, the idea is to both better understand what we might encounter in a reduced-g environment, and at a deeper level to deduce the physics of sheared systems in a density regime that has not been addressed by past experiments or simulations. One aspect of the simulations addresses sheared 2D system in zero-g environment. For low volume fractions, the expected dynamics of this type of system is relatively well understood. However, as the volume fraction is increased, the system undergoes a phase transition, as explained above. The DES concentrate on the evolution of the system as the solid volume fraction is slowly increased, and in particular on the behavior of very dense systems. For these configurations, the simulations show that polydispersity of the sheared particles is a crucial factor that determines the system response. Figures 1 and 2 below, that present the total force on each grain, show that even relatively small (10 %) nonuniformity of the size of the grains (expected in typical experiments) may lead to significant modifications of the system properties, such as velocity profiles, temperature, force propagation, and formation shear bands. The simulations are extended in a few other directions, in order to provide additional insight to the experimental system analyzed above. In one direction, both gravity, and driving due to vibrations are included. These simulations allow for predictions on the driving regime that is required in the experiments in order to analyze the jamming transition. Furthermore, direct comparison of experiments and DES will allow for verification of the modeling assumptions. We have also extended our modeling efforts to 3D. The (preliminary) results of these simulations of an annular system in zero-g environment will conclude the presentation.

Kondic, Lou↗