Search NASA⌕ Search

SEARCH · Search NASA

Results for “Critical Function Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Challenges in Continuous In-Field Critical Current Testing of High-Temperature Superconducting Tapes: Thermal and Mechanical Perspectives

High-temperature superconductors (HTS) are essential for ultra-high-field applications requiring exceptional current-carrying capacity under extreme conditions. However, systematic characterization of critical current in long-length conductors remains challenging due to complex thermal, electromag netic, and mechanical interactions during continuous testing. This study reports the development of a continuous in-field magnetization testing system for position-dependent critical current measurement in HTS tapes at 20 K under 7.5 T fields applied normal to the tape plane, enabling identification of performance-limiting regions that could compromise magnet stability. Here, the system addresses two fundamental challenges inherent to cryogenic reel to-reel testing. First, thermal management requires continuous cooling of a moving conductor to 20 K, achieved through liquid nitrogen precooling combined with a 100 W@20 K Gifford McMahon cryocooler. Second, screening currents in high fields generate Lorentz forces that induce twisting, bowing, and potential delamination. To mitigate these risks, we propose mechanical reinforcement and active current density suppression strategies. Numerical simulations using the stream function formulation reveal four primary failure modes: frictional heating at guide interfaces, unstable equilibria causing deformation, transverse current-induced stresses at guide transitions, and unsupported forces in vertical spans. Our mitigation strategies include PTFE coated guides to minimize friction, spring-loaded stabilization mechanisms to maintain tape alignment, controlled pre-heating using the liquid nitrogen thermal jacket to suppress critical current at stress points, and optimized guide positioning to minimize force accumulation. The experimental system is nearing completion, with testing planned to commence within two months. Preliminary validation at 65 K under 0.5 T demonstrates strong correlation between simulation-predicted mechanical instabilities and observed critical current variations during conductor tran sitions through the measurement region. These findings establish a robust foundation for quality assurance protocols essential to next-generation superconducting magnet applications.

Chen, Siwei [Princeton Plasma Physics Laboratory (↗

A manual for pyrotechnic design, development and qualification

Although pyrotechnic devices have been singularly responsible for the success of many of the critical mechanical functions in aerospace programs for over 30 years, ground and in-flight failures continue to occur. Subsequent investigations reveal that little or no quantitative information is available on measuring the effects on performance of system variables or on determining functional margins. Pyrotechnics are considered to be readily available and, therefore, can be managed by any subsystem in which they are applied, such as structure, propulsion, electric power, or life support. The primary purpose of this manual is to alter the concept that the use of pyrotechnics is an art and refute 'justifications' that applications do not need to be understood by providing information on pyrotechnic design, development, and qualification on an engineering basis. Included are approaches to demonstrate functional reliability with less than 10 units, how to manage pyrotechnic-unique requirements, and methods to assure that the system is properly assembled and will perform the required tasks.

Bement, Laurence J.↗

Re-Engineering the ISS Payload Operations Control Center During Increased Utilization and Critical Onboard Events

With an increase in the utilization and hours of payload operations being executed onboard the International Space Station (ISS), upgrading the NASA Marshall Space Flight Center (MSFC) Huntsville Operations Support Center (HOSC) ISS Payload Control Area (PCA) was essential to gaining efficiencies and assurance of current and future payload health and science return. PCA houses the Payload Operations Integration Center (POIC) responsible for the execution of all NASA payloads onboard the ISS. POIC Flight Controllers are responsible for the operation of voice, stowage, command, telemetry, video, power, thermal, and environmental control in support of ISS science experiments. The methodologies and execution of the PCA refurbishment were planned and performed within a four month period in order to assure uninterrupted operation of ISS payloads and minimal impacts to payload operations teams. To vacate the PCA, three additional HOSC control rooms were reconfigured to handle ISS realtime operations, Backup Control Center (BCC) to Mission Control in Houston, simulations, and testing functions. This involved coordination and cooperation from teams of ISS operations controllers, multiple engineering and design disciplines, management, and construction companies performing an array of activities simultaneously and in sync delivering a final product with no issues that impacted the schedule. For each console operator discipline, studies of Information Technology (IT) tools and equipment layouts, ergonomics, and lines of sight were performed. Infusing some of the latest IT into the project was an essential goal in ensuring future growth and success of the ISS payload science returns. Engineering evaluations led to a state of the art media wall implementation and more efficient ethernet cabling distribution providing the latest products and the best solution for the POIC. These engineering innovations led to cost savings for the project. Constraints involved in the management of the project included executing over 450 crew-hours of ISS real-time payload operations including a major onboard communications upgrade, SpaceX un-berth, a Soyuz launch, roll-out of ISS live video and interviews from the POIC, annual BCC certification and hurricane season, and ISS simulations and testing. Continuous ISS payload operations were possible during the PCA facility modifications with the reconfiguration of four control rooms and standup of two temporary control areas. Another major restriction to the project was an ongoing facility upgrade that included a NASA Headquarters mandated replacement of all electrical and mechanical systems and replacement of an external generator. These upgrades required a facility power outage during the PCA upgrades. The project also encompassed console layout designs and ordering, amenities selections and ordering, excessing of old equipment, moves, disposal of old IT equipment, camera installations, facility tour re-schedules, and contract justifications. These were just some of the tasks needed for a successful project.

Marsh, Angela L.↗

Re-Engineering the ISS Payload Operations Control Center During Increased Utilization and Critical Onboard Events

With an increase in utilization and hours of payload operations being executed onboard the International Space Station (ISS), upgrading the NASA Marshall Space Flight Center (MSFC) Huntsville Operations Support Center (HOSC) ISS Payload Control Area (PCA) was essential to gaining efficiencies and assurance of current and future payload health and science return. PCA houses the Payload Operations Integration Center (POIC) responsible for the execution of all NASA payloads onboard the ISS. POIC Flight Controllers are responsible for the operation of voice, stowage, command, telemetry, video, power, thermal, and environmental control in support of ISS science experiments. The methodologies and execution of the PCA refurbishment were planned and performed within a four-month period in order to assure uninterrupted operation of ISS payloads and minimal impacts to payload operations teams. To vacate the PCA, three additional HOSC control rooms were reconfigured to handle ISS real-time operations, Backup Control Center (BCC) to Mission Control in Houston, simulations, and testing functions. This involved coordination and cooperation from teams of ISS operations controllers, multiple engineering and design disciplines, management, and construction companies performing an array of activities simultaneously and in sync delivering a final product with no issues that impacted the schedule. For each console operator discipline, studies of Information Technology (IT) tools and equipment layouts, ergonomics, and lines of sight were performed. Infusing some of the latest IT into the project was an essential goal in ensuring future growth and success of the ISS payload science returns. Engineering evaluations led to a state of the art Video Wall implementation and more efficient ethernet cabling distribution providing the latest products and the best solution for the POIC. These engineering innovations led to cost savings for the project. Constraints involved in the management of the project included executing over 450 crew-hours of ISS real-time payload operations including a major onboard communications upgrade, SpaceX un-berth, a Soyuz launch, roll-out of ISS live video and interviews from the POIC, annual BCC certification and hurricane season, and ISS simulations and testing. Continuous ISS payload operations were possible during the PCA facility modifications with the reconfiguration of four control rooms and standup of two temporary control areas. Another major restriction to the project was an ongoing facility upgrade that included a NASA Headquarters mandated replacement of all electrical and mechanical systems and replacement of an external generator. These upgrades required a facility power outage during the PCA upgrades. The project also encompassed console layout designs and ordering, amenities selections and ordering, excessing of old equipment, moves, disposal of old IT equipment, camera installations, facility tour re-schedules, and contract justifications. These were just some of the tasks needed for a successful project. This paper describes the logistics and lessons learned in upgrading a control center capability in the middle of complex real-time operations. Combining the efficiencies of controller interaction and new technology infusion were prime drivers for this upgrade to handle the increased utilization of science research on ISS. The success of this project could not jeopardize the current operations while these facility upgrades occurred.

Dudley, Stephanie R. B.↗

The SMART-NAS Testbed

The SMART-NAS Testbed for Safe Trajectory Based Operations Project will deliver an evaluation capability, critical to the ATM community, allowing full NextGen and beyond-NextGen concepts to be assessed and developed. To meet this objective a strong focus will be placed on concept integration and validation to enable a gate-to-gate trajectory-based system capability that satisfies a full vision for NextGen. The SMART-NAS for Safe TBO Project consists of six sub-projects. Three of the sub-projects are focused on exploring and developing technologies, concepts and models for evolving and transforming air traffic management operations in the ATM+2 time horizon, while the remaining three sub-projects are focused on developing the tools and capabilities needed for testing these advanced concepts. Function Allocation, Networked Air Traffic Management and Trajectory Based Operations are developing concepts and models. SMART-NAS Test-bed, System Assurance Technologies and Real-time Safety Modeling are developing the tools and capabilities to test these concepts. Simulation and modeling capabilities will include the ability to assess multiple operational scenarios of the national airspace system, accept data feeds, allowing shadowing of actual operations in either real-time, fast-time and/or hybrid modes of operations in distributed environments, and enable integrated examinations of concepts, algorithms, technologies, and NAS architectures. An important focus within this project is to enable the development of a real-time, system-wide safety assurance system. The basis of such a system is a continuum of information acquisition, analysis, and assessment that enables awareness and corrective action to detect and mitigate potential threats to continuous system-wide safety at all levels. This process, which currently can only be done post operations, will be driven towards "real-time" assessments in the 2035 time frame.

Trajectory Based Operations↗

IEEE PES GM Poster - Cyber-Informed Engineering Approach to Mitigating BESS Supply Chain Concerns

Battery energy storage systems (BESS) are increasingly important to meet the needs of grid resilience and reliability. BESS provide critical grid services, maintaining stability of the grid with increased variable conditions. However, there are significant geopolitical and security concerns regarding their operation in critical infrastructure, due to lack of a domestic supply chain and prevalence of foreign entity of concern (FEOC) components in BESS and associated inverter-based resources. The supply chain challenge is dually exacerbated by a lack of alternative suppliers who can meet the economic targets for energy delivery and a potentially adversarial supply chain. Solutions are needed to secure components, addressing mixed layers of risk and engineering controls. This paper presents a specific application of Cyber-Informed Engineering (CIE) principles for BESS and recommends an alternative strategy to blocking the supply chain, ensuring that grid modernization targets can be met despite lack of a validated or secure supply chain. This study focuses on the United State (U.S.) use case, but the process can be applied globally to address supply chain security challenges. CIE practices represent the next step in functional assurance and risk mitigation, ensuring optimal resource allocation and enhancing security measures to safeguard the future of energy in the U.S. and beyond.

25 - ENERGY STORAGE↗

An advanced generation land mobile satellite system and its critical technologies

A conceptual design for a Land Mobile Satellite System (LMSS) for the 1990s is presented. LMSS involves small tranceivers accessing satellites directly, with ground reception through small car-top antennas. The satellite would have a large antenna and blanket coverage areas in the UHF. The call may originate from a home, be carried by wire to a gateway, transmitted to satellite on the S-band, converted to UHF on the satellite, and transmitted to the vehicle. The system design is constrained by the number of users in an area during the busiest hours, Shuttle storage, controllability factors, and the total area served. A 55-m antenna has been selected, with 87 spot beams and two 10 MHz UHF bands in the 806-890 MHz band. A 17 dB interbeam isolation level is required, implying that sufficient sub-bands can be generated to assure 8265 total channels. The mobile satellite (MSAT) would have an 83 m mast lower segment, a 34 m upper segment, and a second, 10 m antenna made of a deployable mesh. Various antenna function modes are considered.

Naderi, F.↗

Convergence in simulating global soil organic carbon by structurally different models after data assimilation

Abstract Current biogeochemical models produce carbon–climate feedback projections with large uncertainties, often attributed to their structural differences when simulating soil organic carbon (SOC) dynamics worldwide. However, choices of model parameter values that quantify the strength and represent properties of different soil carbon cycle processes could also contribute to model simulation uncertainties. Here, we demonstrate the critical role of using common observational data in reducing model uncertainty in estimates of global SOC storage. Two structurally different models featuring distinctive carbon pools, decomposition kinetics, and carbon transfer pathways simulate opposite global SOC distributions with their customary parameter values yet converge to similar results after being informed by the same global SOC database using a data assimilation approach. The converged spatial SOC simulations result from similar simulations in key model components such as carbon transfer efficiency, baseline decomposition rate, and environmental effects on carbon fluxes by these two models after data assimilation. Moreover, data assimilation results suggest equally effective simulations of SOC using models following either first‐order or Michaelis–Menten kinetics at the global scale. Nevertheless, a wider range of data with high‐quality control and assurance are needed to further constrain SOC dynamics simulations and reduce unconstrained parameters. New sets of data, such as microbial genomics‐function relationships, may also suggest novel structures to account for in future model development. Overall, our results highlight the importance of observational data in informing model development and constraining model predictions.

54 ENVIRONMENTAL SCIENCES↗

Acoustic Emission Health Monitoring of Fill Purge COPV's Used in Aerospace and Automotive Applications and Designed for Long Cycle Life

Cumulative composite damage in composite pressure vessels (CPVs) currently is not monitored on-orbit. Consequently, hazards due to catastrophic burst before leak (BBL) or compromised CPV reliability cannot be ascertained or mitigated, posing a risk to crew and mission assurance. The energy associated with CPV rupture can be significant, especially with high pressure gases are under containment, and the energy releases can be severe enough to cause injury, death, loss of assets or mission. Dual-Use Rationale: CPVs similar to those used by NASA on ISS, for example, are finding increasing use in automotive and transportation industry applications. These CPVs generally have a nonload sharing liner and are repeatedly filled over their service lifetime, typically with hydrogen or compressed natural gas (CNG). The same structural health monitoring equipment and software developed by NASA WSTF for evaluating, in real-time, the health of NASA CPVs on ISS will be used to evaluate the health of automotive CPVs, the only differences being the type and design of the CPV, and the in-service lifetime pressure histories. HSF Need(s)/Performance Characteristic(s) Supported: 1) Enable on-board vehicle systems management for mission critical functions at destinations with > 3 second time delay 2) Enable autonomous nominal operations and FDIR for crewed and un-crewed systems 3) Reduce on-board crew time to sustain and manage vehicle by factor of 2x at destinations with > 6 second time delay (see Crew Autonomy sheet) 4) Reduce earth-based mission ops "back room engineering" requirements for distant mission support delay (see Mission Autonomy sheet)

Waller, Jess↗

A Verification Framework for Runtime Assurance of Autonomous UAS

Runtime Assurance (RTA) is a design-time architecture for safety-critical systems where an internal monitor acts upon detecting a violation of a property. The simplex architecture is an instance of RTA, where the action taken is to hand control of the overall system to a trusted controller when an untrusted one violates a safety property. Simplex RTA is emerging as a method for allowing AI/ML and other unverified software to be integrated into safety-critical applications like aircraft. To this end, the American Society for Testing and Materials (ASTM) and NASA have each published guidelines on the use of RTA in such systems. In the simplex RTA framework, a system has an advanced controller (AC) and a reversionary controller (RC). The system is allowed to operate with the AC until a runtime monitor detects that some property has been violated and then the RC takes over. Assuming that the sample rate of the monitor will detect improper functioning with enough time for the RC to correct the impending problem, and that the RC is trusted, the system will operate as intended. This use of the simplex RTA framework can allow for the integration of untrusted, but possibly more performant, controllers in a safe way. This paper presents a formalization of a simplex RTA framework in the Prototype Verification System (PVS) theorem prover using an embedding of differential dynamic logic (DDL) called Plaidypvs. A novel feature of this framework is that it can be instantiated at different levels of abstraction. This feature allows for the formal verification of a system with an untrusted black box component, such as an AI/ML controller. This paper does not address the many difficulties in deploying RTA in an industrial-level system. Instead, the focus is on the formal verification of the simplex RTA framework in the language of hybrid programs. Hybrid programs are programs that include both discrete and continuous dynamics and can be used to model complex cyber-physical systems. Plaidypvs is a tool that enables formalization of hybrid programs in the PVS theorem prover. Plaidypvs enables the verification of the general simplex RTA framework and then, by specializing some components of the hybrid program, verifying instances of the framework while treating the untrusted component as a black box. A selection of Unmanned Aircraft Systems (UAS) operations are shown as instances of the general RTA framework in PVS. This offers the benefit of design time verification of relevant safety properties to the system, and it also gives requirements on the sample rate of sensors that determine the time interval in which the ‘switch’ property of the RTA framework is checked.

PVS↗

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) Software for Depletion and Fuel Management

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) software is being developed in the Research and Test Reactor (RTR) Program at Argonne National Laboratory to meet the reactor design and analysis needs of the Conversion Program. ADDER is a flexible tool that (1) provides a depletion capability through coupling external neutronics codes with a built-in CRAM solver or external depletion code and (2) provides a user-friendly interface to perform fuel management and criticality search operations. The ADDER software is a Python 3 application written using modern software development practices subject to a compliant implementation of NQA-1 and applicable Department of Energy software quality assurance standards. This report is the user guide for the software release referred to as ADDER v1.1.0. The motivation for a software to have flexible capabilities that ADDER possesses is the need to support a wide variety of geometries that are commonly required in analysis of research and test reactors. These reactors can have complex fuel, experiment, or control material shuffling patterns that persist over several years with many fuel management and partial refueling intervals. The scale of fuel management analysis can require tracking of an inventory that is multiple times the core loading. Many reactors, both power and non-power reactors of various types, will find the features of ADDER useful to facilitate key tasks that a fuel or core design engineer must perform with the convenience of concise input and validated functionality.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) Software for Depletion and Fuel Management

The Advanced Dimensional Depletion for Engineering of Reactors (ADDER) software is being developed in the Research and Test Reactor (RTR) Program at Argonne National Laboratory to meet the reactor design and analysis needs of the Conversion Program. ADDER is a flexible tool that (1) provides a depletion capability through coupling external neutronics codes with a built-in CRAM solver or external depletion code and (2) provides a user-friendly interface to perform fuel management and criticality search operations. The ADDER software is a Python 3 application written using modern software development practices subject to a compliant implementation of NQA-1 and applicable Department of Energy software quality assurance standards. This report is the user guide for the software release referred to as ADDER v1.1.0. The motivation for a software to have flexible capabilities that ADDER possesses is the need to support a wide variety of geometries that are commonly required in analysis of research and test reactors. These reactors can have complex fuel, experiment, or control material shuffling patterns that persist over several years with many fuel management and partial refueling intervals. The scale of fuel management analysis can require tracking of an inventory that is multiple times the core loading. Many reactors, both power and non-power reactors of various types, will find the features of ADDER useful to facilitate key tasks that a fuel or core design engineer must perform with the convenience of concise input and validated functionality.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Technical Reference Suite Addressing Challenges of Providing Assurance for Fault Management Architectural Design

Research into complexities of software systems Fault Management (FM) and how architectural design decisions affect safety, preservation of assets, and maintenance of desired system functionality has coalesced into a technical reference (TR) suite that advances the provision of safety and mission assurance. The NASA Independent Verification and Validation (IV&V) Program, with Software Assurance Research Program support, extracted FM architectures across the IV&V portfolio to evaluate robustness, assess visibility for validation and test, and define software assurance methods applied to the architectures and designs. This investigation spanned IV&V projects with seven different primary developers, a wide range of sizes and complexities, and encompassed Deep Space Robotic, Human Spaceflight, and Earth Orbiter mission FM architectures. The initiative continues with an expansion of the TR suite to include Launch Vehicles, adding the benefit of investigating differences intrinsic to model-based FM architectures and insight into complexities of FM within an Agile software development environment, in order to improve awareness of how nontraditional processes affect FM architectural design and system health management. The identification of particular FM architectures, visibility, and associated IV&V techniques provides a TR suite that enables greater assurance that critical software systems will adequately protect against faults and respond to adverse conditions. Additionally, the role FM has with regard to strengthened security requirements, with potential to advance overall asset protection of flight software systems, is being addressed with the development of an adverse conditions database encompassing flight software vulnerabilities. Capitalizing on the established framework, this TR suite provides assurance capability for a variety of FM architectures and varied development approaches. Research results are being disseminated across NASA, other agencies, and the software community. This paper discusses the findings and TR suite informing the FM domain in best practices for FM architectural design, visibility observations, and methods employed for IV&V and mission assurance.

Fitz, Rhonda↗

Modeling in the State Flow Environment to Support Launch Vehicle Verification Testing for Mission and Fault Management Algorithms in the NASA Space Launch System

Analysis methods and testing processes are essential activities in the engineering development and verification of the National Aeronautics and Space Administration's (NASA) new Space Launch System (SLS). Central to mission success is reliable verification of the Mission and Fault Management (M&FM) algorithms for the SLS launch vehicle (LV) flight software. This is particularly difficult because M&FM algorithms integrate and operate LV subsystems, which consist of diverse forms of hardware and software themselves, with equally diverse integration from the engineering disciplines of LV subsystems. M&FM operation of SLS requires a changing mix of LV automation. During pre-launch the LV is primarily operated by the Kennedy Space Center (KSC) Ground Systems Development and Operations (GSDO) organization with some LV automation of time-critical functions, and much more autonomous LV operations during ascent that have crucial interactions with the Orion crew capsule, its astronauts, and with mission controllers at the Johnson Space Center. M&FM algorithms must perform all nominal mission commanding via the flight computer to control LV states from pre-launch through disposal and also address failure conditions by initiating autonomous or commanded aborts (crew capsule escape from the failing LV), redundancy management of failing subsystems and components, and safing actions to reduce or prevent threats to ground systems and crew. To address the criticality of the verification testing of these algorithms, the NASA M&FM team has utilized the State Flow environment6 (SFE) with its existing Vehicle Management End-to-End Testbed (VMET) platform which also hosts vendor-supplied physics-based LV subsystem models. The human-derived M&FM algorithms are designed and vetted in Integrated Development Teams composed of design and development disciplines such as Systems Engineering, Flight Software (FSW), Safety and Mission Assurance (S&MA) and major subsystems and vehicle elements such as Main Propulsion Systems (MPS), boosters, avionics, Guidance, Navigation, and Control (GN&C), Thrust Vector Control (TVC), liquid engines, and the astronaut crew office. Since the algorithms are realized using model-based engineering (MBE) methods from a hybrid of the Unified Modeling Language (UML) and Systems Modeling Language (SysML), SFE methods are a natural fit to provide an in depth analysis of the interactive behavior of these algorithms with the SLS LV subsystem models. For this, the M&FM algorithms and the SLS LV subsystem models are modeled using constructs provided by Matlab which also enables modeling of the accompanying interfaces providing greater flexibility for integrated testing and analysis, which helps forecast expected behavior in forward VMET integrated testing activities. In VMET, the M&FM algorithms are prototyped and implemented using the same C++ programming language and similar state machine architectural concepts used by the FSW group. Due to the interactive complexity of the algorithms, VMET testing thus far has verified all the individual M&FM subsystem algorithms with select subsystem vendor models but is steadily progressing to assessing the interactive behavior of these algorithms with LV subsystems, as represented by subsystem models. The novel SFE applications has proven to be useful for quick look analysis into early integrated system behavior and assessment of the M&FM algorithms with the modeled LV subsystems. This early MBE analysis generates vital insight into the integrated system behaviors, algorithm sensitivities, design issues, and has aided in the debugging of the M&FM algorithms well before full testing can begin in more expensive, higher fidelity but more arduous environments such as VMET, FSW testing, and the Systems Integration Lab7 (SIL). SFE has exhibited both expected and unexpected behaviors in nominal and off nominal test cases prior to full VMET testing. In many findings, these behavioral characteristics were used to correct the M&FM algorithms, enable better test coverage, and develop more effective test cases for each of the LV subsystems. This has improved the fidelity of testing and planning for the next generation of M&FM algorithms as the SLS program evolves from non-crewed to crewed flight, impacting subsystem configurations and the M&FM algorithms that control them. SFE analysis has improved robustness and reliability of the M&FM algorithms by revealing implementation errors and documentation inconsistencies. It is also improving planning efficiency for future VMET testing of the M&FM algorithms hosted in the LV flight computers, further reducing risk for the SLS launch infrastructure, the SLS LV, and most importantly the crew.

Trevino, Luis↗

Overview of Micrometeoroid and Orbital Debris Analysis Process for Mars Sample Return Earth Entry System

Introduction: Micrometeoroid and orbital debris (MMOD) risk analyses for the Mars Sample Return (MSR) Earth Entry System (EES) have been significantly more rigorous than previously flown missions because of its categorization as a Class V restricted return mission. This means the returned samples present significant concern for biogenic contamination. These analyses seek to determine if a micrometeoroid or orbital debris strike would result in loss of containment assurance and are summarized in the flowchart in Fig. 1. Methodology: The mission is considered in two MMOD phases: a pre-release phase where the EES is protected by a Micrometeoroid Protection System (MMPS) and a post-release phase called “free-flight” where the EES is exposed directly to the MMOD environment. These phases correspond to interplanetary cruise and imminent re-entry, respectively. To inform the MMPS design, a 30-shot high velocity impact testing (HVIT) series on candidate configurations at NASA White Sands Test Facility was completed in the summer of 2022. Sample post-shot images are shown in Fig 2 [1]. These data are used to baseline the MMPS design and to tune the hydrocode simulations. ALE3D, CTH, and SPHC are the hydrocodes that simulate physics of high-speed impacts [2]. Results generated with these populate a penetration depth versus energy space beyond the testable velocity regime of HVIT (~7 km/s). The penetration depth versus energy space data are used to define a critical projectile diameter function called a Ballistic Limit Equation (BLE), where the projectile “criticality” is determined by zone dependent failure criteria defined a-priori [3]. For example, the nose of the heatshield has a failure criterion of 50% TPS penetration, assigned because the landing loads are concentrated on that region and no substructure damage is permitted. The BLEs for each vehicle material zone are input into the BUMPER 3 code, along with the vehicle surface mesh and the corresponding space environment model, to calculate a probability of penetration or number of penetrations. The environment models, MEM3 for MM and ORDEM 3.2 for OD, simulate the meteoroid environment from 0.2 to 2 au based on the Grün flux equation, and the debris environment up to 40,000 km altitude from Earth surface, respectively [4,5]. Presentation Focus: The presentation or poster will present the results to-date focusing on the full risk analysis process flow seen in Fig. 1. Details on the derivation of the failure criteria will be discussed, along with HVIT results and how these influenced the MMPS configuration baseline decision. Further, results of hydrocode simulations will be presented and the tuning to HVIT outputs will be described. Finally, the strategies that direct the BLE formulation will be reviewed, specifically, for the EES elements that are most exposed to the MMOD environment.

mmod↗

Case Study: Test Results of a Tool and Method for In-Flight, Adaptive Control System Verification on a NASA F-15 Flight Research Aircraft

Adaptive control technologies that incorporate learning algorithms have been proposed to enable autonomous flight control and to maintain vehicle performance in the face of unknown, changing, or poorly defined operating environments [1-2]. At the present time, however, it is unknown how adaptive algorithms can be routinely verified, validated, and certified for use in safety-critical applications. Rigorous methods for adaptive software verification end validation must be developed to ensure that. the control software functions as required and is highly safe and reliable. A large gap appears to exist between the point at which control system designers feel the verification process is complete, and when FAA certification officials agree it is complete. Certification of adaptive flight control software verification is complicated by the use of learning algorithms (e.g., neural networks) and degrees of system non-determinism. Of course, analytical efforts must be made in the verification process to place guarantees on learning algorithm stability, rate of convergence, and convergence accuracy. However, to satisfy FAA certification requirements, it must be demonstrated that the adaptive flight control system is also able to fail and still allow the aircraft to be flown safely or to land, while at the same time providing a means of crew notification of the (impending) failure. It was for this purpose that the NASA Ames Confidence Tool was developed [3]. This paper presents the Confidence Tool as a means of providing in-flight software assurance monitoring of an adaptive flight control system. The paper will present the data obtained from flight testing the tool on a specially modified F-15 aircraft designed to simulate loss of flight control faces.

Jacklin, Stephen A.↗

Physicochemical and biological characterization of a bispecific antibody in a CrossMab/KIH format that targets EGFR and VEGF-A

Introduction Bispecific antibodies (BsAbs) are a class of antibody therapeutics engineered in various molecular formats to bind two distinct antigens and potentially mediate multiple biological effects. These molecular formats are tailored to mediate specific mechanisms of action and possess unique physicochemical and biological properties that are necessary to assure product quality. In ovarian cancer (OC), both EGFR- and VEGF-A-mediated signaling pathways are often upregulated and cooperate to promote tumor growth and angiogenesis. Thus, inhibiting of EGFR- and VEGF-A pathways with a BsAb may provide synergistic anti-tumor activity. Methods Using publicly available sequences and applying immunoglobulin domain crossover (CrossMab) and knobs-into-holes (KIH) technologies, we generated a BsAb to simultaneously bind EGFR and VEGF-A (designated as anti-EGFR/VEGF-A BsAb). This BsAb served as a model for physiochemical and biological characterization of quality attributes that would be critical for the BsAb’s mechanisms of action. Our goal was to gain fundamental insights into BsAbs designed to target a receptor with one arm and a soluble ligand with the other, to support bioassay development and inform quality control strategies. Results Our data demonstrated that the CrossMab/KIH platform successfully produced a correctly assembled BsAb during cell culture. Characterization confirmed that the anti-EGFR/VEGF-A BsAb bound both EGFR and VEGF-A with comparable activity and affinity to the respective parental monoclonal antibodies. Functionally, the BsAb disrupted both EGF/EGFR and VEGF-A/VEGFR2 signaling pathways in OC and human umbilical vein endothelial cell (HUVEC) models. Furthermore, the BsAb effectively blocked angiogenic signaling driven by VEGF-A secreted from OC cells in a paracrine manner. Discussion Based on the combinatorial mechanism of action and our characterization findings, we concluded that two or more bioassays may be needed to accurately assess the activity of both arms of this type of BsAb.

Immunology↗

Recommendations on Evidence and Process for Certification of Learning-enabled Components in Aerospace Systems

This report primarily identifies a collection of relevant and necessary evidence for assurance of machine learnt components (MLCs)—also known as learning-enabled components—integrated into aircraft systems, and gives preliminary suggestions on the elements of a certification process that invoke the identified evidence. The main focus is on feedforward neural networks that are static and trained offline through supervised learning. A brief background on the generic elements of the lifecycle of an MLC is given to contextualize the assurance considerations and, consequently, the evidence that is relevant and necessary to support certification. At the level of an MLC, those considerations relate to: (i) the consistency and correctness of MLC contributions to system functions in the context of a validated functional intent; and (ii) the absence of MLC contributions to aircraft-level failure conditions. At an ML model level, confidence in model and data properties contribute to assurance of the containing MLC, in particular: (a) generalizability and robustness of models, in the presence of inputs not previously seen during training, disturbances to inputs, and unexpected inputs; and (b) valid data, i.e., data that are at least representative, relevant, complete, and accurate. Evidence for the above span the elements of the ML lifecycle, and includes, at a minimum, lifecycle artifacts that pertain to: (1) properties of requirements capturing functional intent, safety constraints, and aspects of the intended use and operating environment; (2) model performance, model complexity and design, and algorithm choice; (3) achievement of required performance at the levels of a trained model during model development, a trained model after model development is complete, and a trained model that is transformed into an executable equivalent; (4) model implementation aspects necessary for transforming a trained model into the executable equivalent; (5) integration of the executable trained model into the containing MLC, and eventually the larger system; and, (6) lastly, the verification and validation (V&V) of each of the above. Such V&V lifecycle artifacts themselves include: aspects of coverage, e.g., of various levels of requirements by the input space of the model and the data; traceability (where applicable); application of formal methods for property specification, analysis, and checking. Examples of evidence generation methods and tools further ground the discussion on what constitutes evidence, and the contribution to assurance during certification. The identified assurance considerations and supporting evidence is not a comprehensive set. Additionally, neither what should be considered as sufficient evidence relative to the assigned criticality of an MLC, nor how criticality ought to be determined and adjusted, have been considered in this report. However, suggestions are made for potential activities of the ML lifecycle that are aimed at providing confidence that an MLC can be relied upon when integrated into its containing (aircraft) system. Those activities are proposed as candidate elements of a certification process for MLCs. The main purpose of this report to inform regulatory guidance and consensus standards that may be used to meet the safety intent of the applicable regulations.

Aviation safety↗