Search NASA⌕ Search

SEARCH · Search NASA

Results for “Critical Function Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

A proven approach for more effective software development and maintenance

Modern space flight mission operations and associated ground data systems are increasingly dependent upon reliable, quality software. Critical functions such as command load preparation, health and status monitoring, communications link scheduling and conflict resolution, and transparent gateway protocol conversion are routinely performed by software. Given budget constraints and the ever increasing capabilities of processor technology, the next generation of control centers and data systems will be even more dependent upon software across all aspects of performance. A key challenge now is to implement improved engineering, management, and assurance processes for the development and maintenance of that software; processes that cost less, yield higher quality products, and that self-correct for continual improvement evolution. The NASA Goddard Space Flight Center has a unique experience base that can be readily tapped to help solve the software challenge. Over the past eighteen years, the Software Engineering Laboratory within the code 500 Flight Dynamics Division has evolved a software development and maintenance methodology that accommodates the unique characteristics of an organization while optimizing and continually improving the organization's software capabilities. This methodology relies upon measurement, analysis, and feedback much analogous to that of control loop systems. It is an approach with a time-tested track record proven through repeated applications across a broad range of operational software development and maintenance projects. This paper describes the software improvement methodology employed by the Software Engineering Laboratory, and how it has been exploited within the Flight Dynamics Division with GSFC Code 500. Examples of specific improvement in the software itself and its processes are presented to illustrate the effectiveness of the methodology. Finally, the initial findings are given when this methodology was applied across the mission operations and ground data systems software domains throughout Code 500.

Pajerski, Rose↗

Designing Crane Controls with Applied Mechanical and Electrical Safety Features

The use of overhead traveling bridge cranes in many varied applications is common practice. In particular, the use of cranes in the nuclear, military, commercial, aerospace, and other industries can involve safety critical situations. Considerations for Human Injury or Casualty, Loss of Assets, Endangering the Environment, or Economic Reduction must be addressed. Traditionally, in order to achieve additional safety in these applications, mechanical systems have been augmented with a variety of devices. These devices assure that a mechanical component failure shall reduce the risk of a catastrophic loss of the correct and/or safe load carrying capability. ASME NOG-1-1998, (Rules for Construction of Overhead and Gantry Cranes, Top Running Bridge, and Multiple Girder), provides design standards for cranes in safety critical areas. Over and above the minimum safety requirements of todays design standards, users struggle with obtaining a higher degree of reliability through more precise functional specifications while attempting to provide "smart" safety systems. Electrical control systems also may be equipped with protective devices similar to the mechanical design features. Demands for improvement of the cranes "control system" is often recognized, but difficult to quantify for this traditionally "mechanically" oriented market. Finite details for each operation must be examined and understood. As an example, load drift (or small motions) at close tolerances can be unacceptable (and considered critical). To meet these high functional demands encoders and other devices are independently added to control systems to provide motion and velocity feedback to the control drive. This paper will examine the implementation of Programmable Electronic Systems (PES). PES is a term this paper will use to describe any control system utilizing any programmable electronic device such as Programmable Logic Controllers (PLC), or an Adjustable Frequency Drive (AID) 'smart' programmable motion controller. Therefore the use of the term Programmable Electronic Systems (PES) is an encompassing description for a large spectrum of programmable electronic control devices.

Lytle, Bradford P.↗

Run Time Assurance for Electric Vertical Takeoff and Landing Aircraft

NASA is conducting research to demonstrate and evaluate the application of Run Time Assurance (RTA) as a means to assure safety in Electric Vertical Takeoff and Landing (eVTOL) aircraft with highly automated or autonomous flight capability supervised by a single onboard pilot. The work described in this report demonstrates an application of RTA and examines the implications for design and analysis of aircraft functions and systems; aircraft safety hazards; safety assurance; development assurance; and pilot tasks and performance. This research effort also seeks to assess the efficacy of the combined application of traditional Functional Hazard Analysis (FHA) and the more modern System Theoretic Process Analysis (STPA) techniques to perform hazard analyses on aircraft with complex automated and autonomous systems and an onboard pilot. During the research effort we developed architectural designs of two alternate eVTOL aircraft, generally following the process characterized in the SAE standards ARP4754 and ARP4761. The design has focused on the control architectures of these aircraft, which are identical except that one incorporates RTA techniques to reduce the criticality of some key software components. Artifacts of this process include a taxonomy of aircraft-level functions, aircraft-level architecture diagrams, aircraft-level functional hazard assessments (AFHA), function allocations onto aircraft systems and subsystems, functional block diagrams for a select set of control-related functions, and system-level functional hazard assessments (SFHA) for those functions. This project has highlighted the notion that DAL D is something of a sweet spot for low-confidence controllers in an RTA-based design. Among the many activities described in DO-178C, the activities related to requirement verifiability, algorithmic accuracy, and test coverage can be the most challenging for the kinds of advanced control techniques that may be desirable in novel UAM designs, such as adaptive control, machine-learning, artificial intelligence, numerical search, and Monte Carlo based algorithms. Moreover, the standard requires that development teams demonstrate that errors leading to unacceptable failure conditions have been removed from the software. The RTA architecture, which cordons off the low-confidence function, makes it much easier to show this for these kinds of algorithms. With regard to the use of STPA and FHA as complementary hazard analysis techniques, our research effort led us to the conclusion that STPA should be used to derive requirements for hardware and software systems and/or components. Also, STPA is a natural complement to other processes in ARP4754A involving design studies and iteration.

Run-time assurance↗

R2U2: Tool Overview

R2U2 (Realizable, Responsive, Unobtrusive Unit) is an extensible framework for runtime System HealthManagement (SHM) of cyber-physical systems. R2U2 can be run in hardware (e.g., FPGAs), or software; can monitorhardware, software, or a combination of the two; and can analyze a range of different types of system requirementsduring runtime. An R2U2 requirement is specified utilizing a hierarchical combination of building blocks: temporal formula runtime observers (in LTL or MTL), Bayesian networks, sensor filters, and Boolean testers. Importantly, the framework is extensible; it is designed to enable definitions of new building blocks in combination with the core structure. Originally deployed on Unmanned Aerial Systems (UAS), R2U2 is designed to run on a wide range of embedded platforms, from autonomous systems like rovers, satellites, and robots, to human-assistive ground systems and cockpits. R2U2 is named after the requirements it satisfies; while the exact requirements vary by platform and mission, the ability to formally reason about realizability, responsiveness, and unobtrusiveness is necessary for flight certifiability, safety-critical system assurance, and achievement of technology readiness levels for target systems. Realizability ensures that R2U2 is suficiently expressive to encapsulate meaningful runtime requirements while maintaining adaptability to run on different platforms, transition between different mission stages, and update quickly between missions. Responsiveness entails continuously monitoring the system under test, real-time reasoning, reporting intermediate status, and as-early-as-possible requirements evaluations. Unobtrusiveness ensures compliance with the crucial properties of the target architecture: functionality, certifiability, timing, tolerances, cost, or other constraints.

Rozier, Kristin Y.↗

Risky Business

During my internship I worked on two major projects, recommending improvements for the Center's Risk Management Workshop and helping with the strategic planning efforts for Safety and Mission Assurance (S&MA). The risk management improvements is the key project I worked on this semester through my internship, while the strategic planning is the secondary assignment. S&MA Business Office covers both aspects in its delegation, getting both spans some of the work done in the office. A risk is a future event with a negative consequence that has some probability of occurring. Safety and Mission Assurance identifies, analyzes, plans, and tracks risk. The directorate offers the Center a Risk Management Workshop, and part of the ongoing efforts of S&MA is to make continuous improvements to the RM Workshop. By using the Project Management Institute's (PMI) Standard for Risk Management, I performed a gap analysis to make improvements for our materials. I benchmarked the PMI's Risk Management Standard, compared our Risk Management Workshop materials to PMI's standard, and identified any gaps in our material. My major findings were presented to the Business Office of S&MA for a decision on whether or not to incorporate the improvements. These suggestions were made by attending JSC working group meetings, Health, Safety and Environment (HSE) panel reviews and various risk review meetings. The improvements provide better understanding of risk management processes and enhanced risk tracking knowledge and skills. Risk management is an integral part of any engineering discipline, getting exposed to this section of engineering will greatly help shape my career in the future. Johnson Space Center is a world leader in risk management processes; learning risk management here gives me a huge advantage over my peers, as well as understanding decision making in the context of risk management will help me to be a well-rounded engineer. Strategic planning is an area I had not previously studied. Helping with the strategic planning efforts in S&MA has taught me how organizations think and function as a whole. S&MA is adopting a balanced scorecard approach to strategic planning. As part of this planning method strategic themes, objectives, and initiatives are formed. I attended strategic theme team workshops that formed the strategy map for the directorate and gave shape to the plan. Also during these workshops the objectives were discussed and built. Learning the process for strategic planning has helped me better understand how organizations and businesses function, which also helps me to be a more effective employee. Other assignments I had during my internship included completing the Safety and Mission Assurance Technical Excellent Program (STEP) Level 1, as well as doing a two week rotation through the Space Exploration division in S&MA, specifically working with a thermal protection systems (TPS) engineer. While working there, I learned about the Orion capsule and the SpaceX Dragon cargo capsule. I attended meetings to prepare the engineers for the upcoming Critical Design Reviews for both capsules and reviewed test data. Learning risk management, strategic planning, and working in the Space Exploration division has taught me about many aspects of S&MA. My internship at NASA has given me new experiences and taught me numerous subjects that I would have otherwise not learned. This opportunity has expanded my educational horizons and is helping me to become a more useful engineer and employee.

Yarbrough, Katherine↗

Development of an Optical Library for Coevaporated CdSe x Te 1– x

The conversion efficiency of CdTe solar cells may be improved by bandgap engineering, i.e., changing the bandgap value through the addition of Se in the absorber. The Se alloying enables a short-circuit current density improvement, as it leads to a bandgap energy value decrease. Furthermore, it has been associated with increased minority carrier lifetimes, assuring high open-circuit voltage values. An Se gradient profile control can further optimize the solar cell performance. Thus, an optical model baseline of the CdSe x Te 1–x (CST) compound was developed. Spectroscopic ellipsometry measurements were conducted to accurately extract the optical constants of ten CST layers deposited through coevaporation with x varying from 0 to 1. Using the measured dielectric function spectra from the discrete CST layers with varying x, and considering the composition-induced shift in the critical point energies, an energy-shift model was employed to develop the accurate optical library for the CST compound for any x value to provide data for future modeling and optimization. Furthermore, the library accuracy was validated through optical simulations of the quantum efficiency of a graded CST solar cell using the finite-difference time-domain method by replicating the Se profile in the absorber layer measured through secondary ion mass spectrometry.

14 SOLAR ENERGY↗

Microbiology operations and facilities aboard restructured Space Station Freedom

With the restructure and funding changes for Space Station Freedom, the Environmental Health System (EHS)/Microbiology Subsystem revised its scheduling and operational requirements for component hardware. The function of the Microbiology Subsystem is to monitor the environmental quality of air, water, and internal surfaces and, in part, crew health on board Space Station. Its critical role shall be the identification of microbial contaminants in the environment that may cause system degradation, produce unsanitary or pathogenic conditions, or reduce crew and mission effectiveness. EHS/Microbiology operations and equipment shall be introduced in concert with a phased assembly sequence, from Man Tended Capability (MTC) through Permanently Manned Capability (PMC). Effective Microbiology operations and subsystem components will assure a safe, habitable, and useful spacecraft environment for life sciences research and long-term manned exploration.

Cioletti, Louis A.↗

A Distributed Trajectory-Oriented Approach to Managing Traffic Complexity

In order to handle the expected increase in air traffic volume, the next generation air transportation system is moving towards a distributed control architecture, in which ground-based service providers such as controllers and traffic managers and air-based users such as pilots share responsibility for aircraft trajectory generation and management. While its architecture becomes more distributed, the goal of the Air Traffic Management (ATM) system remains to achieve objectives such as maintaining safety and efficiency. It is, therefore, critical to design appropriate control elements to ensure that aircraft and groundbased actions result in achieving these objectives without unduly restricting user-preferred trajectories. This paper presents a trajectory-oriented approach containing two such elements. One is a trajectory flexibility preservation function, by which aircraft plan their trajectories to preserve flexibility to accommodate unforeseen events. And the other is a trajectory constraint minimization function by which ground-based agents, in collaboration with air-based agents, impose just-enough restrictions on trajectories to achieve ATM objectives, such as separation assurance and flow management. The underlying hypothesis is that preserving trajectory flexibility of each individual aircraft naturally achieves the aggregate objective of avoiding excessive traffic complexity, and that trajectory flexibility is increased by minimizing constraints without jeopardizing the intended ATM objectives. The paper presents conceptually how the two functions operate in a distributed control architecture that includes self separation. The paper illustrates the concept through hypothetical scenarios involving conflict resolution and flow management. It presents a functional analysis of the interaction and information flow between the functions. It also presents an analytical framework for defining metrics and developing methods to preserve trajectory flexibility and minimize its constraints. In this framework flexibility is defined in terms of robustness and adaptability to disturbances and the impact of constraints is illustrated through analysis of a trajectory solution space with limited degrees of freedom and in simple constraint situations involving meeting multiple times of arrival and resolving a conflict.

Idris, Husni↗

Flat H Frangible Joint Evolution

Space vehicle staging and separation events require pyrotechnic devices. They are single-use mechanisms that cannot be tested, nor can failure-tolerant performance be demonstrated in actual flight articles prior to flight use. This necessitates the implementation of a robust design and test approach coupled with a fully redundant, failure-tolerant explosive mechanism to ensure that the system functions even in the event of a single failure. Historically, NASA has followed the single failure-tolerant (SFT) design philosophy for all human-rated spacecraft, including the Space Shuttle Program. Following the end of this program, aerospace companies proposed building the next generation human-rated vehicles with off-the-shelf, non-redundant, zero-failure-tolerant (ZFT) separation systems. Currently, spacecraft and launch vehicle providers for both the Orion and Commercial Crew Programs (CCPs) plan to deviate from the heritage safety approach and NASA's SFT human rating requirements. Both programs' partners have base-lined ZFT frangible joints for vehicle staging and fairing separation. These joints are commercially available from pyrotechnic vendors. Non-human-rated missions have flown them numerous times. The joints are relatively easy to integrate structurally within the spacecraft. In addition, the separation event is debris free, and the resultant pyro shock is lower than that of other design solutions. It is, however, a serious deficiency to lack failure tolerance. When used for critical applications on human-rated vehicles, a single failure could potentially lead to loss of crew (LOC) or loss of mission (LOM)). The Engineering and Safety & Mission Assurance directorates within the NASA Johnson Space Center took action to address this safety issue by initiating a project to develop a fully redundant, SFT frangible joint design, known as the Flat H. Critical to the ability to retrofit on launch vehicles being developed, the SFT mechanisms must fit within the same three-dimensional envelope as current designs as well as meet structural loads requirements. There is increased mass associated with the redundant design, and the goal is to minimize the weight impact as much as possible. These requirements presented significant challenges, both technically and financially; these challenges will be explored in this paper. Perhaps greater than the technical issues confronted during this design process, were the financial considerations. These were a significant part of the story of this design and development plan. Insufficient financial and labor resources were formidable barriers to completing this project. Nevertheless, JSC personnel successfully conducted several test series at JSC with very useful results. The many lessons learned drove design improvements, performance efficiency, and increased functional reliability. This paper examines the significant technical and financial challenges that these requirements posed to the project team. It discusses the evolution of the SFT frangible joint design, including optimization, testing, and successful partnering of the Johnson Space Center (JSC) engineering and JSC safety organizations, to enhance the flight safety margin for America's next generation of human-rated space vehicles.

Diegelman, Thomas E.↗

The AMACStar ASIC for the HL-LHC ATLAS ITk Strip detector: design, verification, testing, and quality assurance

For the high-luminosity upgrade to the LHC (HL-LHC), the ATLAS detector at CERN requires an all-new inner detector, the Inner Tracker (ITk). The ITk Strip subdetector is made up of silicon modules, which include three types of radiation-hard ASICs. One of these is the Autonomous Monitor and Control (AMAC). The AMAC is manufactured by Global Foundries using 130 nm CMOS8RF DM technology and is approximately 3 by 5 mm in size. This ASIC autonomously monitors the temperatures, voltages, and currents in the module components while controlling critical values in order to prevent these quantities from reaching dangerous levels. The final design, AMACStar, was verified, tested, and ensured to perform all necessary functions. A quality control procedure using an in-house probe station set-up was developed in order to ensure that every individual chip on each wafer of AMACStars required by the ITk Strip project met performance requirements. The average per wafer yield of usable AMACStars is 92.33%, exceeding the design-specific 90% yield estimated for project costing. This estimate was based on actual yields for similar designs in this process.

Analogue electronic circuits↗

A Methodology for Writing High Quality Requirements Specification and Evaluating Existing Ones

Requirements development and management have always been critical in the implementation of software systems; engineers are unable to build what analysts can't define. It is generally accepted that the earlier in the life cycle potential risks are identified the easier it is to eliminate or manage the conditions that introduce that risk. Problems that are not found until testing are approximately 14 times more costly to fix than if the problem was found in the requirement phase. The requirements specification, as the first tangible representation of the capability to be produced, establishes the basis for all of the project's engineering management and assurance functions. If the quality of the requirements specification is poor it can give rise to risks in all areas of the project. Recently, automated tools have become available to support requirements management. The use of these tools not only provides support in the definition and tracing of requirements, but it also opens the door to effective use of metrics in characterizing and assessing the quality of the requirement specifications.

Rosenberg, Linda↗

Reducing Bolt Preload Variation with Angle-of-Twist Bolt Loading

Critical high-pressure sealing joints on the Space Shuttle reusable solid rocket motor require precise control of bolt preload to ensure proper joint function. As the reusable solid rocket motor experiences rapid internal pressurization, correct bolt preloads maintain the sealing capability and structural integrity of the hardware. The angle-of-twist process provides the right combination of preload accuracy, reliability, process control, and assembly-friendly design. It improves significantly over previous methods. The sophisticated angle-of-twist process controls have yielded answers to all discrepancies encountered while the simplicity of the root process has assured joint preload reliability.

Thompson, Bryce↗

A Methodology for Writing High Quality Requirement Specifications and for Evaluating Existing Ones

Requirements development and management have always been critical in the implementation of software systems-engineers are unable to build what analysts can not define. It is generally accepted that the earlier in the life cycle potential risks are identified the easier it is to eliminate or manage the conditions that introduce that risk. Problems that are not found until testing are approximately 14 times more costly to fix than if the problem was found in the requirement phase. The requirements specification, as the first tangible representation of the capability to be produced, establishes the basis for all of the project's engineering management and assurance functions. If the quality of the requirements specification is poor it can give rise to risks in all areas of the project. Recently, automated tools have become available to support requirements management. The use of these tools not only provides support in the definition and tracing of requirements, but it also opens the door to effective use of metrics in characterizing and assessing the quality of the requirement specifications.

Rosenberg, Linda↗

Recommendations on the Use of Commercial-Off-The-Shelf (COTS) Electrical, Electronic, and Electromechanical (EEE) Parts for NASA Missions - Phase II

This assessment had two Phases. Phase I captured NASA Centers’ current practices for commercial-off-the-shelf (COTS) Electrical, Electronic, and Electromechanical (EEE) parts 1 used in spaceflight systems and ground support equipment (available at https://ntrs.nasa.gov/citations/20205011579) [ref. 1]. The Phase II report provides guidance for selecting and using COTS parts in NASA missions. The approaches proposed in this report differ from current agency practices. This top-level executive summary touches on these new approaches for using COTS parts but does not provide the detailed information that is critical in understanding the rationale behind these new approaches. Readers will need to read the entire report to gain full understanding and effectively use the recommendations herein. NASA’s historical approach to selecting and applying parts has been to define certain parts, primarily specific classes of military specification (MIL-SPEC) parts, as “standard”, leaving all others, including COTS parts, as nonstandard. Standard parts typically are used without further testing (“use-as-is”). Nonstandard parts are subjected to initial screening and subsequent lot acceptance testing of representative samples from each procured lot per MIL-SPEC or similar requirements. Decades later, top-tier commercial part manufacturers have evolved significant manufacturing, statistical control, and technological improvements that can now provide parts as reliable or more reliable than MIL-SPEC parts, when used within their datasheet limits. Concurrently, the space science and exploration community’s needs demand technological advances unavailable with MIL-SPEC parts. This ongoing change necessitates using COTS parts for space missions. Properly selected COTS parts in appropriate applications can offer performance and supply availability advantages compared to MIL-SPEC parts. Their utility and demonstrated reliability result from large volumes and automated production and testing processes. However, careful review and a thorough understanding of their specifications (i.e., datasheet limitations) is needed, and verifying that manufacturer specifications and reliability meet space hardware application needs are necessary. This report recommends MIL-SPEC screening and non-radiation-related lot acceptance testing be reduced or eliminated in cases where evidence of sufficient quality and reliability exists for COTS parts. The extent of NASA's insight into COTS manufacturers and the amount and nature of the needed evidence will differ by mission and will likely be driven by a mission's resources and associated risk posture. To facilitate this goal, two new terminologies have been defined and described: “Industry Leading Parts Manufacturer (ILPM)” and “Established COTS parts.” An ILPM is a COTS manufacturer that produces high quality and reliable parts. Some parts produced by ILPMs, defined as Established COTS parts, do not need any additional MIL-SPEC or NASA screening and lot acceptance testing to be used in space applications. This report provides guidance for selecting, procuring, and applying COTS parts and for performing part-, board-, and system-level COTS parts verification. The recommendation to select Established COTS parts from ILPMs will assure those COTS parts will have comparable quality to corresponding MIL-SPEC parts. Selecting, applying, and verifying Established COTS parts from ILPMs requires a holistic team approach, engaging parts engineers, circuit designers, quality, reliability, and systems engineers, procurement specialists, radiation specialists, avionics leads, and program/project managers. A mission-specific approach tailored to a project’s Mission, Environment, Applications and Lifetime (MEAL) [ref. 2] requirements should be developed and approved by program/project managers. Any associated risks should be clearly identified, quantified, mitigated, and/or accepted. Different approaches are recommended according to program/project Risk Classes A, B, C, and D [ref. 3] and human-rated missions [ref. 4]: 1. Recommend Classes A and B and human-rated missions consider a “MIL-SPEC parts- based design” approach. ”MIL-SPEC parts-based design” approach is one in which most parts are MIL-SPEC parts and Established COTS parts from ILPMs are used only when an equivalent MIL-SPEC part does not meet functional or size, weight, and power (SWaP) or performance requirements, or is not available. 2. Recommend Classes D and Sub-D missions consider a “System of COTS” approach. “System of COTS” approach is one which most parts are Established COTS parts from ILPMs. 3. Recommend Class C missions determine which approach is the best for their projects; that is, use either a “MIL-SPEC parts-based design” approach, “System of COTS” approach, or a combined approach utilizing elements of both. This report intends to provide guidance in using COTS parts for NASA missions with risk classifications of A through D and human-rated missions; but it does not address the costs of using COTS parts. Costs of using COTS parts in different NASA mission classes can vary significantly even if the same parts are used in different risk postures, due to differing verification levels needed. The guidance does not distinguish between critical or non-critical systems, and a given project will need to apply the appropriate guidance based on their risk posture. The intended audience of this report are NASA personnel and commercial practitioners who support NASA’s spaceflight missions, including spaceflight program or project managers, parts engineers, parts manufacturers, radiation engineers, avionics engineers, system engineers, circuit design engineers, reliability engineers, safety and mission assurance (SMA) personnel, and parts procurement specialists. The NEPP Program will perform a pathfinder study to explore implementing the guidance in this NESC report. An ILPM verification process is not the same as conventional vendor qualification processes performed according to military standards and specifications. This NESC report intends to provide guidance in utilizing available parts data from ILPM manufacturers for parts assurance assessments needed for NASA missions. The report also captured the current practices from DoD and Federal Aviation Administration (FAA) in Section 10. Note each DoD and FAA report was provided by the corresponding agencies regarding their practices, which are independent from the NESC recommendations in the report.

Commercial-Off-The-Shelf↗

W/V-Band RF Propagation Experiment Design

The utilization of frequency spectrum for space-to-ground communications applications has generally progressed from the lowest available bands capable of supporting transmission through the atmosphere to the higher bands, which have required research and technological advancement to implement. As communications needs increase and the available spectrum in the microwave frequency bands (3 30 GHz) becomes congested globally, future systems will move into the millimeter wave (mm-wave) range (30 300 GHz). While current systems are operating in the Ka-band (20 30 GHz), systems planned for the coming decades will initiate operations in the Q-Band (33 50 GHz), V-Band (50 75 GHz) and W Band (75 110 GHz) of the spectrum. These bands offer extremely broadband capabilities (contiguous allocations of 500 MHz to 1GHz or more) and an uncluttered spectrum for a wide range of applications. NASA, DoD and commercial missions that can benefit from moving into the mm-wave bands include data relay and near-Earth data communications, unmanned aircraft communications, NASA science missions, and commercial broadcast/internet services, all able to be implemented via very small terminals. NASA Glenn Research Center has a long history of performing the inherently governmental function of opening new frequency spectrum by characterizing atmospheric effects on electromagnetic propagation and collaborating with the satellite communication industry to develop specific communications technologies for use by NASA and the nation. Along these lines, there are critical issues related to W/V-band propagation that need to be thoroughly understood before design of any operational system can commence. These issues arise primarily due to the limitations imposed on W/V-band signal propagation by the Earth s atmosphere, and to the fundamental lack of understanding of these effects with regards to proper system design and fade mitigation. In this paper, The GRC RF propagation team recommends measurements that are required to assure that the risk associated with the use of mm-wave is minimized. We develop first order beacon and transponder system payload requirements and beacon terminal requirements. We will suggest and discuss a possible hardware implementation for the space segment, as well for the ground segment. A discussion on a propagation measurement campaign for taking relevant statistical data is also included.

Acosta, Roberto J.↗

The Second European Service Module (ESM-2) Evolutions, Production and Challenges

This paper presents an overview of the Second European Service Module (ESM-2), the second in a series of European Service Modules produced as part of the Barter agreement between NASA and ESA for the Orion Program. The European Industrial consortium is led by the ESA prime contractor Airbus Defence and Space in Bremen. ESA and Airbus signed the ESM-2 contract on 16 February 2017, for this key element of the Orion Exploration Mission 2 (EM-2). EM-2 is the first crewed mission for Orion and will take astronauts farther into the solar system than humanity has ever travelled. EM-2 will also be a historic mission for Europe, as the ESM-2 will be the first European spacecraft to be part of a human transportation system carrying humans beyond low Earth orbit. ESM-2 is mainly a recurring production following ESM-1. Nevertheless, there are a number of important changes being implemented, for example, to incorporate upgrades to further enhance safety and reliability. The challenging delivery schedule for ESM-2 has driven the need to commence manufacturing prior to completion of the qualification on ESM-1. In addition, some requirement deviations and non-compliances approved for ESM-1 have resulted in modifications for ESM-2. In order to manage the competing constraints effectively, the ESM-2 Team has put in place a number of novel approaches to manage schedule, risk, and technical changes. Airbus has set up multi-functional teams according to an approach known as "Major Spacecraft Deliveries" consisting of quality assurance, engineering and procurement. The risk of starting manufacturing prior to qualification is managed through a special risk share agreement. This agreement necessitates rigorous risk reviews across the board for all manufacturing, assembly, integration and test milestones. The ESM-2 changes are managed by Configuration Management, but Airbus has also introduced the Technical Baseline Matrix to provide a transparent top-level overview of the changes from ESM-1 to ESM-2. The tool provides the basis for ESM-2 design and development needs, decisions, as well as the input for the Orion EM-2 Critical Design Review (CDR). The main technical evolutions, status of the production and the novel management approaches for ESM-2 are presented and discussed in the paper.

Orion European Service Module Programme↗

A Comparison of Bus Architectures for Safety-Critical Embedded Systems

We describe and compare the architectures of four fault-tolerant, safety-critical buses with a view to deducing principles common to all of them, the main differences in their design choices, and the tradeoffs made. Two of the buses come from an avionics heritage, and two from automobiles, though all four strive for similar levels of reliability and assurance. The avionics buses considered are the Honeywell SAFEbus (the backplane data bus used in the Boeing 777 Airplane Information Management System) and the NASA SPIDER (an architecture being developed as a demonstrator for certification under the new DO-254 guidelines); the automobile buses considered are the TTTech Time-Triggered Architecture (TTA), recently adopted by Audi for automobile applications, and by Honeywell for avionics and aircraft control functions, and FlexRay, which is being developed by a consortium of BMW, DaimlerChrysler, Motorola, and Philips.

Rushby, John↗

NASA's Software Safety Standard

NASA relies more and more on software to control, monitor, and verify its safety critical systems, facilities and operations. Since the 1960's there has hardly been a spacecraft launched that does not have a computer on board that will provide command and control services. There have been recent incidents where software has played a role in high-profile mission failures and hazardous incidents. For example, the Mars Orbiter, Mars Polar Lander, the DART (Demonstration of Autonomous Rendezvous Technology), and MER (Mars Exploration Rover) Spirit anomalies were all caused or contributed to by software. The Mission Control Centers for the Shuttle, ISS, and unmanned programs are highly dependant on software for data displays, analysis, and mission planning. Despite this growing dependence on software control and monitoring, there has been little to no consistent application of software safety practices and methodology to NASA's projects with safety critical software. Meanwhile, academia and private industry have been stepping forward with procedures and standards for safety critical systems and software, for example Dr. Nancy Leveson's book Safeware: System Safety and Computers. The NASA Software Safety Standard, originally published in 1997, was widely ignored due to its complexity and poor organization. It also focused on concepts rather than definite procedural requirements organized around a software project lifecycle. Led by NASA Headquarters Office of Safety and Mission Assurance, the NASA Software Safety Standard has recently undergone a significant update. This new standard provides the procedures and guidelines for evaluating a project for safety criticality and then lays out the minimum project lifecycle requirements to assure the software is created, operated, and maintained in the safest possible manner. This update of the standard clearly delineates the minimum set of software safety requirements for a project without detailing the implementation for those requirements. This allows the projects leeway to meet these requirements in many forms that best suit a particular project's needs and safety risk. In other words, it tells the project what to do, not how to do it. This update also incorporated advances in the state of the practice of software safety from academia and private industry. It addresses some of the more common issues now facing software developers in the NASA environment such as the use of Commercial-Off-the-Shelf Software (COTS), Modified OTS (MOTS), Government OTS (GOTS), and reused software. A team from across NASA developed the update and it has had both NASA-wide internal reviews by software engineering, quality, safety, and project management. It has also had expert external review. This presentation and paper will discuss the new NASA Software Safety Standard, its organization, and key features. It will start with a brief discussion of some NASA mission failures and incidents that had software as one of their root causes. It will then give a brief overview of the NASA Software Safety Process. This will include an overview of the key personnel responsibilities and functions that must be performed for safety-critical software.

Ramsay, Christopher M.↗