Search NASASearch

SEARCH · Search NASA

Results for “contingency software”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Work Experience Report

The NASA Platform for Autonomous Systems (NPAS) toolkit is currently being used at the NASA John C. Stennis Space Center (SSC) to develop the INSIGHT program, which will autonomously monitor and control the Nitrogen System of the High Pressure Gas Facility (HPGF) on site. The INSIGHT program is in need of generic timing capabilities in order to perform timing based actions such as pump usage timing and sequence step timing. The purpose of this project was to develop a timing module that could fulfill these requirements and be adaptable for expanded use in the future. The code was written in Gensym G2 software platform, the same as INSIGHT, and was written generically to ensure compatibility with any G2 program. Currently, the module has two timing capabilities, a stopwatch function and a countdown function. Although the module has gone through some functionality testing, actual integration of the module into NPAS and the INSIGHT program is contingent on the module passing later checks.

Guo, Daniel

Proximity operations considerations affecting spacecraft design

Proximity operations can be defined as the maneuvering of two or more spacecraft within 1 nautical mile range, with relative velocity less than 10 feet per second. The passive vehicle is nontranslating and should provide for maintenance of the desired approach attitude. It must accommodate the active (translating) vehicle induced structural loads and performance characteristics (mating hardware tolerances), and support sensor compatibility (transponder, visual targets, etc.). The active vehicle must provide adequate sensor systems (relative state information, field-of-view, redundancy), flight control hardware (thruster sizing, minimal cross-coupling, performance margins, redundancy) and software (reconfigurable, attitude/rate modes, translation and rotation fine control authority) characteristic, and adequate non-propulsive consumables such as power. Operational concerns must be considered. These include the following: (1) the desired approach trajectory and relative orientation; (2) the active vehicle thruster plume effects (forces, torques, contamination) on the passive vehicle; and (3) procedures for contingencies such as loss of communications, sensor or propulsion failures, and target vehicle loss of control.

Staas, Steven K.

AERCam Autonomy: Intelligent Software Architecture for Robotic Free Flying Nanosatellite Inspection Vehicles

The NASA Johnson Space Center has developed a nanosatellite-class Free Flyer intended for future external inspection and remote viewing of human spacecraft. The Miniature Autonomous Extravehicular Robotic Camera (Mini AERCam) technology demonstration unit has been integrated into the approximate form and function of a flight system. The spherical Mini AERCam Free Flyer is 7.5 inches in diameter and weighs approximately 10 pounds, yet it incorporates significant additional capabilities compared to the 35-pound, 14-inch diameter AERCam Sprint that flew as a Shuttle flight experiment in 1997. Mini AERCam hosts a full suite of miniaturized avionics, instrumentation, communications, navigation, power, propulsion, and imaging subsystems, including digital video cameras and a high resolution still image camera. The vehicle is designed for either remotely piloted operations or supervised autonomous operations, including automatic stationkeeping, point-to-point maneuvering, and waypoint tracking. The Mini AERCam Free Flyer is accompanied by a sophisticated control station for command and control, as well as a docking system for automated deployment, docking, and recharge at a parent spacecraft. Free Flyer functional testing has been conducted successfully on both an airbearing table and in a six-degree-of-freedom closed-loop orbital simulation with avionics hardware in the loop. Mini AERCam aims to provide beneficial on-orbit views that cannot be obtained from fixed cameras, cameras on robotic manipulators, or cameras carried by crewmembers during extravehicular activities (EVA s). On Shuttle or International Space Station (ISS), for example, Mini AERCam could support external robotic operations by supplying orthogonal views to the intravehicular activity (IVA) robotic operator, supply views of EVA operations to IVA and/or ground crews monitoring the EVA, and carry out independent visual inspections of areas of interest around the spacecraft. To enable these future benefits with minimal impact on IVA operators and ground controllers, the Mini AERCam system architecture incorporates intelligent systems attributes that support various autonomous capabilities. 1) A robust command sequencer enables task-level command scripting. Command scripting is employed for operations such as automatic inspection scans over a region of interest, and operator-hands-off automated docking. 2) A system manager built on the same expert-system software as the command sequencer provides detection and smart-response capability for potential system-level anomalies, like loss of communications between the Free Flyer and control station. 3) An AERCam dynamics manager provides nominal and off-nominal management of guidance, navigation, and control (GN&C) functions. It is employed for safe trajectory monitoring, contingency maneuvering, and related roles. This paper will describe these architectural components of Mini AERCam autonomy, as well as the interaction of these elements with a human operator during supervised autonomous control.

Fredrickson, Steven E.

Computerized atmospheric trace contaminant control simulation for manned spacecraft

Buildup of atmospheric trace contaminants in enclosed volumes such as a spacecraft may lead to potentially serious health problems for the crew members. For this reason, active control methods must be implemented to minimize the concentration of atmospheric contaminants to levels that are considered safe for prolonged, continuous exposure. Designing hardware to accomplish this has traditionally required extensive testing to characterize and select appropriate control technologies. Data collected since the Apollo project can now be used in a computerized performance simulation to predict the performance and life of contamination control hardware to allow for initial technology screening, performance prediction, and operations and contingency studies to determine the most suitable hardware approach before specific design and testing activities begin. The program, written in FORTRAN 77, provides contaminant removal rate, total mass removed, and per pass efficiency for each control device for discrete time intervals. In addition, projected cabin concentration is provided. Input and output data are manipulated using commercial spreadsheet and data graphing software. These results can then be used in analyzing hardware design parameters such as sizing and flow rate, overall process performance and program economics. Test performance may also be predicted to aid test design.

Perry, J. L.

A launch window study for GEOTAIL's double lunar swingby trajectory

The GEOTAIL spacecraft of the International Solar-Terrestrial Physics Program will use a series of paired lunar swingbys to explore distant parts of the earth's magnetic tail. A 21-day launch window has been calculated for GEOTAIL, in July and August 1992, to start its distant-tail phase with a first lunar swingby (S1) on September 8, 1992. The main launch window in July utilizes 4.5 revolutions in a transfer orbit to S1, with a mid-August contingency window that uses 2.5 transfer-orbit revolutions before S1. Designing a good distant-tail trajectory, and then accurately matching it at S1 for every day in the launch window, seems to be the easiest and most reliable strategy. However, the total delta-V costs of the current designs can probably be reduced, possibly with the help of new interactive software that can be run on personal computers.

Dunham, David W.

Control of Technology Transfer at JPL

Controlled Technology: 1) Design: preliminary or critical design data, schematics, technical flow charts, SNV code/diagnostics, logic flow diagrams, wirelist, ICDs, detailed specifications or requirements. 2) Development: constraints, computations, configurations, technical analyses, acceptance criteria, anomaly resolution, detailed test plans, detailed technical proposals. 3) Production: process or how-to: assemble, operated, repair, maintain, modify. 4) Manufacturing: technical instructions, specific parts, specific materials, specific qualities, specific processes, specific flow. 5) Operations: how-to operate, contingency or standard operating plans, Ops handbooks. 6) Repair: repair instructions, troubleshooting schemes, detailed schematics. 7) Test: specific procedures, data, analysis, detailed test plan and retest plans, detailed anomaly resolutions, detailed failure causes and corrective actions, troubleshooting, trended test data, flight readiness data. 8) Maintenance: maintenance schedules and plans, methods for regular upkeep, overhaul instructions. 9) Modification: modification instructions, upgrades kit parts, including software

Jet Propulsion Laboratory (JPL)

m:N ConOps/R&R Remote Simulation

This presentation details the experimental design of an investigation of small unmanned aircraft system (sUAS) operations involving multiple vehicle management by a remote operator. The study is part of an ongoing effort to explore multiple vehicle control by multiple operators, i.e., the control of N vehicles by m operators (m:N operations). For this effort, NASA and collaborators have developed prototypes of a concept of operations (ConOps), roles and responsibilities (R&R) for operators and supervisors, and a ground control station (GCS), including software displays and interfaces. Participants in this study acted as the pilot-in-command of twelve aircraft flying pre-approved routes in a simulation of a food delivery operation utilizing sUAS in the San Diego, CA area. Each participant experienced four experimental trials. Twice within the course of each trial, participants were responsible for responding to a sudden, unanticipated, and high-priority contingency: an airspace restriction for sUAS operations known as a UAS Volume Reservation (UVR). Upon issuance of a UVR, pilots were expected to reroute affected vehicles around the airspace. The level of automation (LoA) and workload of the flight rerouting task were varied. The LoA was manipulated by providing reroute suggestions ("auto" condition) for aircraft or by requiring pilots to manually reroute ("manual" condition) affected vehicles. Workload was varied as a function of the number of vehicles affected by the UVR contingencies: 2 vehicles ("low workload" condition) versus 4 vehicles ("high workload" condition). Additionally, some vehicles required pilots to adjust for terrain conflicts while avoiding the UVR region. Due to the COVID-19 pandemic, in-person data collection for this study was not possible. Researchers adapted to this circumstance through the development of remote data collection protocol. Participants were able to view adapted GCS displays using the Microsoft Teams teleconferencing platform and responded to events by using a verbal protocol developed for the experiment. Using this protocol, participants provided instructions for actions to a researcher, referred to as the surrogate, to carry out on their behalf. This presentation describes the experiment design, including special details for remote data collection via a subject-surrogate configuration, and concludes with planned data analysis and results to be presented at a later date.

multi-UAS

Statistical and Probabilistic Extensions to Ground Operations' Discrete Event Simulation Modeling

NASA's human exploration initiatives will invest in technologies, public/private partnerships, and infrastructure, paving the way for the expansion of human civilization into the solar system and beyond. As it is has been for the past half century, the Kennedy Space Center will be the embarkation point for humankind's journey into the cosmos. Functioning as a next generation space launch complex, Kennedy's launch pads, integration facilities, processing areas, launch and recovery ranges will bustle with the activities of the world's space transportation providers. In developing this complex, KSC teams work through the potential operational scenarios: conducting trade studies, planning and budgeting for expensive and limited resources, and simulating alternative operational schemes. Numerous tools, among them discrete event simulation (DES), were matured during the Constellation Program to conduct such analyses with the purpose of optimizing the launch complex for maximum efficiency, safety, and flexibility while minimizing life cycle costs. Discrete event simulation is a computer-based modeling technique for complex and dynamic systems where the state of the system changes at discrete points in time and whose inputs may include random variables. DES is used to assess timelines and throughput, and to support operability studies and contingency analyses. It is applicable to any space launch campaign and informs decision-makers of the effects of varying numbers of expensive resources and the impact of off nominal scenarios on measures of performance. In order to develop representative DES models, methods were adopted, exploited, or created to extend traditional uses of DES. The Delphi method was adopted and utilized for task duration estimation. DES software was exploited for probabilistic event variation. A roll-up process was used, which was developed to reuse models and model elements in other less - detailed models. The DES team continues to innovate and expand DES capabilities to address KSC's planning needs.

Trocine, Linda

Development of a Smart Release Algorithm for Mid-Air Separation of Parachute Test Articles

The Crew Exploration Vehicle Parachute Assembly System (CPAS) project is currently developing an autonomous method to separate a capsule-shaped parachute test vehicle from an air-drop platform for use in the test program to develop and validate the parachute system for the Orion spacecraft. The CPAS project seeks to perform air-drop tests of an Orion-like boilerplate capsule. Delivery of the boilerplate capsule to the test condition has proven to be a critical and complicated task. In the current concept, the boilerplate vehicle is extracted from an aircraft on top of a Type V pallet and then separated from the pallet in mid-air. The attitude of the vehicles at separation is critical to avoiding re-contact and successfully deploying the boilerplate into a heatshield-down orientation. Neither the pallet nor the boilerplate has an active control system. However, the attitude of the mated vehicle as a function of time is somewhat predictable. CPAS engineers have designed an avionics system to monitor the attitude of the mated vehicle as it is extracted from the aircraft and command a release when the desired conditions are met. The algorithm includes contingency capabilities designed to release the test vehicle before undesirable orientations occur. The algorithm was verified with simulation and ground testing. The pre-flight development and testing is discussed and limitations of ground testing are noted. The CPAS project performed a series of three drop tests as a proof-of-concept of the release technique. These tests helped to refine the attitude instrumentation and software algorithm to be used on future tests. The drop tests are described in detail and the evolution of the release system with each test is described.

Moore, James W.

The Essence of Cryptol: A Denotational Cryptol Interpreter in Coq for Foundational Assurances for Quantum Resistant Cryptosystems

Systems of the utmost consequence need a means to establish authenticity of software and data. Cryptosystems implement authentication, but can be vulnerable to cryptographic and implementation attacks. With the threat of quantum cryptographic attacks, “post-quantum” cryptosystems (PQCs) must be henceforth used in these systems. However, the new cryptography needs new ways to, rigorously and machine-checkably, prove systems free of vulnerabilities. We propose a retargetable capability to rapidly instantiate proven correct postquantum cryptosystems through novel proof-carrying synthesis and proof-automation technique, extending those proven successful on existing systems. This capability is crucial to meeting the cryptographic requirements for future high-consequence systems. Since specifications for high consequence cryptography are presently captured in a domain specific language known as Cryptol. While this can enable convenient fully automated reasoning about Cryptol specificaitons and implementations via the Software Analysis Workbench (SAW), Cryptol has expressivity gaps, so that cryptosystems with probabilistic programming features like Falcon cannot be fully expressed in the language. Moreover, SAW’s automation fails for programs and specificaitons with inductive and recursive structure, as in the Sphincs+ PQC. Finally, Cryptol and SAW together represent some 200,000 lines of unverified Haskell, so that the any guarantees about high consequence cryptography are presently contingent on a large, unverified, yet trusted computing base. The first step of the larger project of agile, assured crpytography is therefore to provide a formal, mechanized semantics for Cryptol, so that the specifications expressed by cryptographers in Cryptol can be reasoned about and compiled into performant implementations with a foundational, machine checkable certificate of correctness. This report describes our work on this first step, culminating in the design of a certified denotational interpreter, in Coq, for core Cryptol.

97 MATHEMATICS AND COMPUTING

Development of a Two-Wheel Contingency Mode for the MAP Spacecraft

In the event of a failure of one of MAP's three reaction wheel assemblies (RWAs), it is not possible to achieve three-axis, full-state attitude control using the remaining two wheels. Hence, two of the attitude control algorithms implemented on the MAP spacecraft will no longer be usable in their current forms: Inertial Mode, used for slewing to and holding inertial attitudes, and Observing Mode, which implements the nominal dual-spin science mode. This paper describes the effort to create a complete strategy for using software algorithms to cope with a RWA failure. The discussion of the design process will be divided into three main subtopics: performing orbit maneuvers to reach and maintain an orbit about the second Earth-Sun libration point in the event of a RWA failure, completing the mission using a momentum-bias two-wheel science mode, and developing a new thruster-based mode for adjusting the inertially fixed momentum bias. In this summary, the philosophies used in designing these changes is shown; the full paper will supplement these with algorithm descriptions and testing results.

Starin, Scott R.

SIMSAT: An object oriented architecture for real-time satellite simulation

Real-time satellite simulators are vital tools in the support of satellite missions. They are used in the testing of ground control systems, the training of operators, the validation of operational procedures, and the development of contingency plans. The simulators must provide high-fidelity modeling of the satellite, which requires detailed system information, much of which is not available until relatively near launch. The short time-scales and resulting high productivity required of such simulator developments culminates in the need for a reusable infrastructure which can be used as a basis for each simulator. This paper describes a major new simulation infrastructure package, the Software Infrastructure for Modelling Satellites (SIMSAT). It outlines the object oriented design methodology used, describes the resulting design, and discusses the advantages and disadvantages experienced in applying the methodology.

Williams, Adam P.

Investigation of a Verification and Validation Tool with a Turbofan Aircraft Engine Application

The development of more advanced control architectures for turbofan aircraft engines can yield gains in performance and efficiency over the lifetime of an engine. However, the implementation of these increasingly complex controllers is contingent on their ability to provide safe, reliable engine operation. Therefore, having the means to verify the safety of new control algorithms is crucial. As a step towards this goal, CoCoSim, a publicly available verification tool for Simulink, is used to analyze C-MAPSS40k, a 40,000 lbf class turbo-fan engine model developed at NASA for testing new control algorithms. Due to current limitations of the verification software, several modifications are made to C-MAPSS40k to achieve compatibility with CoCoSim. Some of these modifications sacrifice fidelity to the original model. Several safety and performance requirements typical for turbofan engines are identified and constructed into a verification framework. Preliminary results using an industry standard baseline controller for these requirements are presented. While verification capabilities are demonstrated, a truly comprehensive analysis will require further development of the verification tool.

V&

Operational radiological support for the US manned space program

Radiological support for the manned space program is provided by the Space Radiation Analysis Group at NASA/JSC. This support ensures crew safety through mission design analysis, real-time space environment monitoring, and crew exposure measurements. Preflight crew exposure calculations using mission design information are used to ensure that crew exposures will remain within established limits. During missions, space environment conditions are continuously monitored from within the Mission Control Center. In the event of a radiation environment enhancement, the impact to crew exposure is assessed and recommendations are provided to flight management. Radiation dosimeters are placed throughout the spacecraft and provided to each crewmember. During a radiation contingency, the crew could be requested to provide dosimeter readings. This information would be used for projecting crew dose enhancements. New instrumentation and computer technology are being developed to improve the support. Improved instruments include tissue equivalent proportional counter (TEPC)-based dosimeters and charged particle telescopes. Data from these instruments will be telemetered and will provide flight controllers with unprecedented information regarding the radiation environment in and around the spacecraft. New software is being acquired and developed to provide 'smart' space environmental data displays for use by flight controllers.

Golightly, Michael J.

Volatile Organic Analyzer (VOA) in 2006: Repair, Revalidation, and Restart of Elektron Even

The Volatile Organic Analyzer (VOA) had been providing valuable data on trace contaminants in the atmosphere of the International Space Station (ISS) from January 2002 through May 2003. Component temperature errors, detected by the VOA s software, shut down the unit in May 2003, but in early 2005 on orbit diagnostics verified fuse failures had disabled both VOA channels. An in-flight maintenance (IFM) session in December 2005 returned the VOA to an operational mode by January 2006. This paper will present the on-orbit data from 2006 that were used to revalidate the VOA, and provide an overview of the VOA s contributions during the Elecktron contingency event that occurred on ISS in September 2006.

Limero, Thomas

The SAX Italian scientific satellite. The on-board implemented automation as a support to the ground control capability

This paper presents the capabilities implemented in the SAX system for an efficient operations management during its in-flight mission. SAX is an Italian scientific satellite for x-ray astronomy whose major mission objectives impose quite tight constraints on the implementation of both the space and ground segment. The most relevant mission characteristics require an operative lifetime of two years, performing scientific observations both in contact and in noncontact periods, with a low equatorial orbit supported by one ground station, so that only a few minutes of communications are available each orbit. This operational scenario determines the need to have a satellite capable of performing the scheduled mission automatically and reacting autonomously to contingency situations. The implementation approach of the on-board operations management, through which the necessary automation and autonomy are achieved, follows a hierarchical structure. This has been achieved adopting a distributed avionic architecture. Nine different on-board computers, in fact, constitute the on-board data management system. Each of them performs the local control and monitors its own functions while the system level control is performed at a higher level by the data handling applications software. The SAX on-board architecture provides the ground operators with different options of intervention by three classes of telecommands. The management of the scientific operations will be scheduled by the operation control center via dedicated operating plans. The SAX satellite flight mode is presently being integrated at Alenia Spazio premises in Turin for a launch scheduled for the end of 1995. Once in orbit, the SAX satellite will be subject to intensive check-out activities in order to verify the required mission performances. An overview of the envisaged procedure and of the necessary on-ground activities is therefore depicted as well.

Martelli, Andrea

Mars Sample Return Using Commercial Capabilities: ERV Trajectory and Capture Requirements

Mars Sample Return was presented as the highest priority planetary science mission of the next decade [1]. Lemke et al. [2] present a Mars Sample Return mission concept in which the sample is returned directly from the surface of Mars to an Earth orbit. The sample is recovered in Earth Orbit instead of being transferred between spacecraft in Mars Orbit. This paper provides the details of this sample recovery in Earth orbit and presents as such a sub-element of the overall Mars sample return concept given in [2]. We start from the assumption that a Mars Ascent Vehicle (MAV), initially landed on Mars using a modified SpaceX Dragon capsule, has successfully delivered the sample, already contained within an Earth Return Vehicle (ERV), to a parking orbit around Mars. From the parking orbit, the ERV imparts sufficient Delta-V to inject itself into an earthbound trajectory and to be captured into an Earth orbit eventually. We take into account launch window and Delta-V considerations as well as the additional constraint of increased safety margins imposed by planetary protection regulations. We focus on how to overcome two distinct challenges of the sample return that are driven by the issues of planetary protection: (1) the design of an ERV trajectory meeting all the requirements including the need to avoid contamination of Earth's atmosphere; (2) the concept of operations for retrieving the Martian samples in Earth orbit in a safe way. We present an approach to retrieve the samples through a rendezvous between the ERV and a second SpaceX Dragon capsule. The ERV executes a trajectory that brings it from low Mars orbit (LMO) to a Moon-trailing Earth orbit at high inclination with respect to the Earth-Moon plane. After a first burn at Trans-Earth Injection (TEI), the trajectory uses a second burn at perigee during an Earth flyby maneuver to capture the ERV in Earth orbit. The ERV then uses a non-propulsive Moon flyby to come to a near-circular Moon-trailing orbit. To perform the Earth Orbit Rendezvous (EOR), a second Dragon capsule is then launched from Earth and a similar lunar flyby is performed to rendezvous with the ERV. The requirements for rendezvous, close proximity operations and capture of the sample canister are described. A concept of operations for sample retrieval is presented along with design specifications of the ERV, the required modifications to the Dragon capsule, as well as the hardware, software, sensors, actuators, and capture mechanisms used. In our concept, a container is mounted to the front hatch of Dragon, capable of accommodating the sample canister and sealing it from the rest of the capsule. The sample canister is captured using a robotic arm with a magnetic grappling mechanism. Dragon then performs a propulsive maneuver to return to Earth for a controlled re-entry while the ERV (sans sample container) is left in the Moon trailing orbit. Contingency cases and related mitigation strategies are also discussed, including the advantages and disadvantages of performing the ERV rendezvous with a crew.

Faber, Nicolas F.

An expert system for simulating electric loads aboard Space Station Freedom

Space Station Freedom will provide an infrastructure for space experimentation. This environment will feature regulated access to any resources required by an experiment. Automated systems are being developed to manage the electric power so that researchers can have the flexibility to modify their experiment plan for contingencies or for new opportunities. To define these flexible power management characteristics for Space Station Freedom, a simulation is required that captures the dynamic nature of space experimentation; namely, an investigator is allowed to restructure his experiment and to modify its execution. This changes the energy demands for the investigator's range of options. An expert system competent in the domain of cryogenic fluid management experimentation was developed. It will be used to help design and test automated power scheduling software for Freedom's electric power system. The expert system allows experiment planning and experiment simulation. The former evaluates experimental alternatives and offers advice on the details of the experiment's design. The latter provides a real-time simulation of the experiment replete with appropriate resource consumption.

Kukich, George