Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Protection Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Mars 2020 Entry, Descent, and Landing System Software Implementation

On February 18th, 2021, the Mars 2020 project's Perseverance Rover successfully touched down on the Martian surface after nearly eight years of development. The Mars 2020 Entry, Descent, and Landing (EDL) System largely leveraged heritage from the Mars Science Laboratory (MSL) EDL System while employing targeted technological advancements. The landing process is autonomously directed by a software behavior implemented in the rover's primary flight computer called the EDL Timeline that assumes control of the vehicle six days before atmospheric entry. This paper first walks through the basics of the EDL Timeline mechanics and how the behavior is designed to account for internal system variations and environmental unknowns. It then summarizes the interactions between the EDL timeline and other high-level system behaviors like spacecraft mode transitions and system fault protection, focusing on the complications that arise when passing spacecraft control between executive functions. Although the MSL-inherited EDL System is reliable and capable, targeted updates and a thorough verification and validation program were required for Mars 2020. This paper discusses changes made to close vulnerabilities discovered during both MSL and Mars 2020 development cycles, landing system capability enhancements that were enabling for Mars 2020's mission, and how these updates were integrated with the heritage system. It then describes how both analysis and testing campaigns were utilized to verify and validate all aspects of EDL and system behaviors that run during the six days before landing, as well as the operational workarounds that were needed to address problems found during the development and commissioning process. Finally, this paper imparts lessons learned from Mars 2020 EDL development, implementation, and operations, emphasizing how systems designed to conduct time-critical mission events with low margin of error can be improved in the future.

Stehura, Aaron↗

Mars 2020 Entry, Descent, and Landing Software Implementation

On February 18th, 2021, the Mars 2020 project's Perseverance Rover successfully touched down on the Martian surface after nearly eight years of development. The Mars 2020 Entry, Descent, and Landing (EDL) System largely leveraged heritage from the Mars Science Laboratory (MSL) EDL System while employing targeted technological advancements. The landing process is autonomously directed by a software behavior implemented in the rover's primary flight computer called the EDL Timeline that assumes control of the vehicle six days before atmospheric entry. In addition to performing the critical function of landing the rover on the Martian surface, the EDL timeline behavior must co-exist in a non-partitioned software and system environment with other high-level functions that accomplish the goals for the rest of the mission. Due to the criticality of EDL, the potential for loss of mission, and a need for complete system autonomy, the standard for how the EDL Timeline interacts with other functions in the system is highly constrained. This paper first walks through the basics of the EDL Timeline mechanics and how the behavior is designed to account for internal system variations and environmental unknowns. It then summarizes the interactions between the EDL timeline and other high-level system behaviors like spacecraft mode transitions and system fault protection, focusing on the complications that arise when passing spacecraft control between executive functions. Although the MSL-inherited EDL System is reliable and capable, targeted updates and a thorough verification and validation program were required for Mars 2020. This paper discusses changes made to close vulnerabilities discovered during both MSL and Mars 2020 development cycles, landing system capability enhancements that were enabling for Mars 2020's mission, and how these updates were integrated with the heritage system. It then describes how both analysis and testing campaigns were utilized to verify and validate all aspects of EDL and system behaviors that run during the six days before landing, as well as the operational workarounds that were needed to address problems found during the development and commissioning process. Finally, this paper imparts lessons learned from Mars 2020 EDL development, implementation, and operations, emphasizing how systems designed to conduct time-critical mission events with low margin of error can be improved in the future.

Stehura, Aaron↗

Experience report: Using formal methods for requirements analysis of critical spacecraft software

Formal specification and analysis of requirements continues to gain support as a method for producing more reliable software. However, the introduction of formal methods to a large software project is difficult, due in part to the unfamiliarity of the specification languages and the lack of graphics. This paper reports results of an investigation into the effectiveness of formal methods as an aid to the requirements analysis of critical, system-level fault-protection software on a spacecraft currently under development. Our experience indicates that formal specification and analysis can enhance the accuracy of the requirements and add assurance prior to design development in this domain. The work described here is part of a larger, NASA-funded research project whose purpose is to use formal-methods techniques to improve the quality of software in space applications. The demonstration project described here is part of the effort to evaluate experimentally the effectiveness of supplementing traditional engineering approaches to requirements specification with the more rigorous specification and analysis available with formal methods.

Lutz, Robyn R.↗

NASA Tech Briefs, July 2007

Topics covered include: Miniature Intelligent Sensor Module; "Smart" Sensor Module; Portable Apparatus for Electrochemical Sensing of Ethylene; Increasing Linear Dynamic Range of a CMOS Image Sensor; Flight Qualified Micro Sun Sensor; Norbornene-Based Polymer Electrolytes for Lithium Cells; Making Single-Source Precursors of Ternary Semiconductors; Water-Free Proton-Conducting Membranes for Fuel Cells; Mo/Ti Diffusion Bonding for Making Thermoelectric Devices; Photodetectors on Coronagraph Mask for Pointing Control; High-Energy-Density, Low-Temperature Li/CFx Primary Cells; G4-FETs as Universal and Programmable Logic Gates; Fabrication of Buried Nanochannels From Nanowire Patterns; Diamond Smoothing Tools; Infrared Imaging System for Studying Brain Function; Rarefying Spectra of Whispering-Gallery-Mode Resonators; Large-Area Permanent-Magnet ECR Plasma Source; Slot-Antenna/Permanent-Magnet Device for Generating Plasma; Fiber-Optic Strain Gauge With High Resolution And Update Rate; Broadband Achromatic Telecentric Lens; Temperature-Corrected Model of Turbulence in Hot Jet Flows; Enhanced Elliptic Grid Generation; Automated Knowledge Discovery From Simulators; Electro-Optical Modulator Bias Control Using Bipolar Pulses; Generative Representations for Automated Design of Robots; Mars-Approach Navigation Using In Situ Orbiters; Efficient Optimization of Low-Thrust Spacecraft Trajectories; Cylindrical Asymmetrical Capacitors for Use in Outer Space; Protecting Against Faults in JPL Spacecraft; Algorithm Optimally Allocates Actuation of a Spacecraft; and Radar Interferometer for Topographic Mapping of Glaciers and Ice Sheets.

Source record↗

Experience Report: Using Formal Methods for Requirements Analysis of Critical Spacecraft Software

Formal specification and analysis of requirements continues to gain support as a method for producing more reliable software. However, the introduction of formal methods to a large software project is difficult, due in part to the unfamiliarity of the specification languages and the lack of graphics. This paper reports results of an investigation into the effectiveness of formal methods as an aid to the requirements analysis of critical, system-level fault-protection software on a spacecraft currently under development. Our experience indicates that formal specification and analysis can enhance the accuracy of the requirements and add assurance prior to design development in this domain.

Formal↗

Toward a Model-Based Approach to Flight System Fault Protection

Fault Protection (FP) is a distinct and separate systems engineering sub-discipline that is concerned with the off-nominal behavior of a system. Flight system fault protection is an important part of the overall flight system systems engineering effort, with its own products and processes. As with other aspects of systems engineering, the FP domain is highly amenable to expression and management in models. However, while there are standards and guidelines for performing FP related analyses, there are not standards or guidelines for formally relating the FP analyses to each other or to the system hardware and software design. As a result, the material generated for these analyses are effectively creating separate models that are only loosely-related to the system being designed. Development of approaches that enable modeling of FP concerns in the same model as the system hardware and software design enables establishment of formal relationships that has great potential for improving the efficiency, correctness, and verification of the implementation of flight system FP. This paper begins with an overview of the FP domain, and then continues with a presentation of a SysML/UML model of the FP domain and the particular analyses that it contains, by way of showing a potential model-based approach to flight system fault protection, and an exposition of the use of the FP models in FSW engineering. The analyses are small examples, inspired by current real-project examples of FP analyses.

Day, John↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification Validation (IVV) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASA's Office of Safety and Mission Assurance defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domaincomponent, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IVV enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

Fault management↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification & Validation (IV&V) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASAs Office of Safety and Mission Assurance (OSMA) defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domain/component, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IV&V enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

IV&V↗

Study of a High Voltage Ion Engine Power Supply

A complete laboratory breadboard version of a ion engine power converter was built and tested. This prototype operated on a line voltage of 80-120 Vdc, and provided output ratings of 1100 V at 1.8 kW, and 250 V at 20 mA. The high-voltage (HV) output voltage rating was revised from the original value of 1350 V at the beginning of the project. The LV output was designed to hold up during a 1-A surge current lasting up to 1 second. The prototype power converter included a internal housekeeping power supply which also operated from the line input. The power consumed in housekeeping was included in the overall energy budget presented for the ion engine converter. HV and LV output voltage setpoints were commanded through potentiometers. The HV converter itself reached its highest power efficiency of slightly over 93% at low line and maximum output. This would dip below 90% at high line. The no-load (rated output voltages, zero load current) power consumption of the entire system was less than 13 W. A careful loss breakdown shows that converter losses are predominately Metal-Oxide-Semiconductor Field Effect Transistor (MOSFET) conduction losses and HV rectifier snubbing losses, with the rectifier snubbing losses becoming predominant at high line. This suggests that further improvements in power efficiency could best be obtained by either developing a rectifier that was adequately protected against voltage overshoot with less snubbing, or by developing a pre-regulator to reduced the range of line voltage on the converter. The transient testing showed the converter to be fully protected against load faults, including a direct short-circuit from the HV output to the LV output terminals. Two currents sensors were used: one to directly detect any core ratcheting on the output transformer and re-initiate a soft start, and the other to directly detect a load fault and quickly shut down the converter for load protection. The finished converter has been extensively fault tested without failure. The finished converter has been packaged suitable for use as a laboratory prototype for further testing. The finished converter is readily transportable. An article on design issues for high voltage converters for ion engines is included as an attachement.

Stuart, Thomas A.↗

Soft-Fault Detection Technologies Developed for Electrical Power Systems

The NASA Glenn Research Center, partner universities, and defense contractors are working to develop intelligent power management and distribution (PMAD) technologies for future spacecraft and launch vehicles. The goals are to provide higher performance (efficiency, transient response, and stability), higher fault tolerance, and higher reliability through the application of digital control and communication technologies. It is also expected that these technologies will eventually reduce the design, development, manufacturing, and integration costs for large, electrical power systems for space vehicles. The main focus of this research has been to incorporate digital control, communications, and intelligent algorithms into power electronic devices such as direct-current to direct-current (dc-dc) converters and protective switchgear. These technologies, in turn, will enable revolutionary changes in the way electrical power systems are designed, developed, configured, and integrated in aerospace vehicles and satellites. Initial successes in integrating modern, digital controllers have proven that transient response performance can be improved using advanced nonlinear control algorithms. One technology being developed includes the detection of "soft faults," those not typically covered by current systems in use today. Soft faults include arcing faults, corona discharge faults, and undetected leakage currents. Using digital control and advanced signal analysis algorithms, we have shown that it is possible to reliably detect arcing faults in high-voltage dc power distribution systems (see the preceding photograph). Another research effort has shown that low-level leakage faults and cable degradation can be detected by analyzing power system parameters over time. This additional fault detection capability will result in higher reliability for long-lived power systems such as reusable launch vehicles and space exploration missions.

Button, Robert M.↗

The evolution of power management architecture for missions to the outer planets

Outer planet spacecraft have unique requirements that differentiate them from inner planet and Earth orbiter spacecraft. To meet these requirements, the Voyager and Galileo Power Management And Distribution (PMAD) architectures employed shunt regulation and carried on the Mariner tradition of AC power distribution to many of the user loads. Also, autonomous fault recovery was achieved by automatic responses in hardware and software recovery routines. Finally, power distribution switching was expanded to allow for removal of the most trivial load element as the nuclear source depleted itself. The design cycle has begun for a third generation spacecraft set named Comet Rendezvous Asteroid Flyby (CRAF) and Cassini (a saturn orbiter). In their power systems, AC power distribution, relay/fuse load switching, and fault protection will give way to the advantages of DC power and solid state load switches.

Detwiler, R. C.↗

NASA Tech Briefs, August 2004

Topics covered include: Data Relay Board with Protocol for High-Speed, Free-Space Optical Communications; Software and Algorithms for Biomedical Image Data Processing and Visualization; Rapid Chemometric Filtering of Spectral Data; Prioritizing Scientific Data for Transmission; Determining Sizes of Particles in a Flow from DPIV Data; Faster Processing for Inverting GPS Occultation Data; FPGA-Based, Self-Checking, Fault-Tolerant Computers; Ultralow-Power Digital Correlator for Microwave Polarimetry; Grounding Headphones for Protection Against ESD; Lightweight Stacks of Direct Methanol Fuel Cells; Highly Efficient Vector-Inversion Pulse Generators; Estimating Basic Preliminary Design Performances of Aerospace Vehicles; Framework for Development of Object-Oriented Software; Analyzing Spacecraft Telecommunication Systems; Collaborative Planning of Robotic Exploration; Tools for Administration of a UNIX-Based Network; Preparing and Analyzing Iced Airfoils; Evaluating Performance of Components; Fuels Containing Methane of Natural Gas in Solution; Direct Electrolytic Deposition of Mats of MnxOy Nanowires; Bubble Eliminator Based on Centrifugal Flow; Inflatable Emergency Atmospheric-Entry Vehicles; Lightweight Deployable Mirrors with Tensegrity Supports; Centrifugal Adsorption Cartridge System; Ultrasonic Apparatus for Pulverizing Brittle Material; Transplanting Retinal Cells using Bucky Paper for Support; Using an Ultrasonic Instrument to Size Extravascular Bubbles; Coronagraphic Notch Filter for Raman Spectroscopy; On-the-Fly Mapping for Calibrating Directional Antennas; Working Fluids for Increasing Capacities of Heat Pipes; Computationally-Efficient Minimum-Time Aircraft Routes in the Presence of Winds; Liquid-Metal-Fed Pulsed Plasma Thrusters; Personal Radiation Protection System; and Attitude Control for a Solar-Sail Spacecraft.

Source record↗

Development of Design Standards and Guidelines for Electromagnetic Compatibility and Lightning Protection for Spacecraft Utilizing Composite Materials

This final report presents information concerning technical accomplishments by Tec-Masters, Inc. (TMI) for this contract effort. This effort included the accomplishment and/or submission by TMI of the following items: (1) Literature Survey Report, Electrical Properties of Non-Metallic Composites by Mr. Hugh W. Denny; (2) Interim Report, Composite Materials - Conductivity, Shielding Effectiveness, and Current Carrying Capability by Mr. Ross W. Evans; (3) Fault Current Test Plan by Mr. Ross W. Evans (4) Fault Current Test Procedure by Mr. Ross W. Evans (5) Test Report, Fault Current Through Graphite Filament Reinforced Plastic, NASA CR-4774, Marshall Space Flight Center, Alabama, September 1996, by Mr. Ross W. Evans; (6) Test Plan, Lightning Effects on Composite Materials by Mr. Ross W. Evans; (7) Test Report, Lightning Effects on Composite Materials, NASA CR-4783, Marshall Space Flight Center, Alabama, February 1997, by Mr. Ross W. Evans; (8) Design Guidelines for Shielding Effectiveness, Current Carrying Capability, and the Enhancement of Conductivity of Composite Materials, NASA CR-4784, Marshall Space Flight Center, Alabama, September 1996, by Mr. Ross W. Evans. These items are not attached but are considered to be a part of this final report. Efforts on two additional items were accomplished at no increase in cost to NASA/MSFC. These items consisted of updating the 'MSFC EMC Design and Interference Control Handbook,' and revising the 'Design Guidelines for Shielding Effectiveness, Current Carrying Capability, and the Enhancement of Conductivity of Composite Materials.'

Camp, Dennis W.↗

The Multi-Mission Earth Entry Vehicle for Sample Return Missions – Past, Present, and Future

The Multi-Mission Earth Entry Vehicle (MMEEV) is an enabling technology developed at NASA’s Langley Research Center (LaRC) over the last two decades for returning samples to Earth across a wide array of space science missions. Currently, the MMEEV is being considered for NASA’s Mars Sample Return (MSR) mission. The original vehicle concept, the Earth Entry Vehicle (EEV), was innovated at LaRC in 1998 as a robust solution to return Mars soil samples to Earth under stringent backward contamination requirements. These backward contamination requirements drove the EEV to have higher reliability than any capsule previously designed for a return-to-Earth sample return mission. The EEV achieved this high reliability by employing a passive (no active systems) vehicle architecture optimized for fault tolerance in a compact, low-mass configuration that is extensible to virtually any sample return mission. The original EEV concept utilized a carbon-carbon primary structure with high-density carbon phenolic thermal protection system. The capsule had a 60-degree sphere-cone forebody and a backshell geometry uniquely tailored to produce aerodynamics that would passively re-orient the vehicle if it entered the atmosphere with an off-nominal attitude. Contrary to every other sample return capsule conceived at the time, the EEV was designed to land without a parachute. The vehicle incorporated an integral energy-absorbing crushable structure that protected the Mars sample for landings on surfaces ranging from soft soil to solid concrete. This paper describes 20 years of technological advancements LaRC has incorporated into the EEV architecture to evolve it from the original, MSR-enabling vehicle, to a true multi-mission capability relevant to any sample return mission. The vehicle’s unique Integrated Composite Stiffener Structure (ICoSS) has been optimized for specific strength - supporting high-G atmospheric entries with steep entry angles that produce precise landing footprints on the ground. The vehicle geometry has been refined through wind tunnel testing and computational fluid dynamics simulations to improve the vehicle’s aerodynamic stability and robustness to off-nominal conditions from hypersonic to subsonic flight. The resulting configuration of the current MMEEV architecture is described, with details provided on its sample carrying capacity and atmospheric entry trajectory capabilities. The upgraded vehicle performance is mapped into current space science objectives, showing how the MMEEV supports future sample return missions and continues to be an enabling technology for NASA’s vision to return samples from Mars.

J M Corliss↗

Probabilistic Risk Assessment for Decision Making During Spacecraft Operations

Decisions made during the operational phase of a space mission often have significant and immediate consequences. Without the explicit consideration of the risks involved and their representation in a solid model, it is very likely that these risks are not considered systematically in trade studies. Wrong decisions during the operational phase of a space mission can lead to immediate system failure whereas correct decisions can help recover the system even from faulty conditions. A problem of special interest is the determination of the system fault protection strategies upon the occurrence of faults within the system. Decisions regarding the fault protection strategy also heavily rely on a correct understanding of the state of the system and an integrated risk model that represents the various possible scenarios and their respective likelihoods. Probabilistic Risk Assessment (PRA) modeling is applicable to the full lifecycle of a space mission project, from concept development to preliminary design, detailed design, development and operations. The benefits and utilities of the model, however, depend on the phase of the mission for which it is used. This is because of the difference in the key strategic decisions that support each mission phase. The focus of this paper is on describing the particular methods used for PRA modeling during the operational phase of a spacecraft by gleaning insight from recently conducted case studies on two operational Mars orbiters. During operations, the key decisions relate to the commands sent to the spacecraft for any kind of diagnostics, anomaly resolution, trajectory changes, or planning. Often, faults and failures occur in the parts of the spacecraft but are contained or mitigated before they can cause serious damage. The failure behavior of the system during operations provides valuable data for updating and adjusting the related PRA models that are built primarily based on historical failure data. The PRA models, in turn, provide insight into the effect of various faults or failures on the risk and failure drivers of the system and the likelihood of possible end case scenarios, thereby facilitating the decision making process during operations. This paper describes the process of adjusting PRA models based on observed spacecraft data, on one hand, and utilizing the models for insight into the future system behavior on the other hand. While PRA models are typically used as a decision aid during the design phase of a space mission, we advocate adjusting them based on the observed behavior of the spacecraft and utilizing them for decision support during the operations phase.

dynamic fault trees↗

Neural Net Safety Monitor Design

The National Aeronautics and Space Administration (NASA) at the Dryden Flight Research Center (DFRC) has been conducting flight-test research using an F-15 aircraft (figure 1). This aircraft has been specially modified to interface a neural net (NN) controller as part of a single-string Airborne Research Test System (ARTS) computer with the existing quad-redundant flight control system (FCC) shown in figure 2. The NN commands are passed to FCC channels 2 and 4 and are cross channel data linked (CCDL) to the other computers as shown. Numerous types of fault-detection monitors exist in the FCC when the NN mode is engaged; these monitors would cause an automatic disengagement of the NN in the event of a triggering fault. Unfortunately, these monitors still may not prevent a possible NN hard-over command from coming through to the control laws. Therefore, an additional and unique safety monitor was designed for a single-string source that allows authority at maximum actuator rates but protects the pilot and structural loads against excessive g-limits in the case of a NN hard-over command input. This additional monitor resides in the FCCs and is executed before the control laws are computed. This presentation describes a floating limiter (FL) concept1 that was developed and successfully test-flown for this program (figure 3). The FL computes the rate of change of the NN commands that are input to the FCC from the ARTS. A window is created with upper and lower boundaries, which is constantly floating and trying to stay centered as the NN command rates are changing. The limiter works by only allowing the window to move at a much slower rate than those of the NN commands. Anywhere within the window, however, full rates are allowed. If a rate persists in one direction, it will eventually hit the boundary and be rate-limited to the floating limiter rate. When this happens, a persistent counter begins and after a limit is reached, a NN disengage command is generated. The tunable metrics for the FL are (1) window size, (2) drift rate, and (3) persistence counter. Ultimate range limits are also included in case the NN command should drift slowly to a limit value that would cause the FL to be defeated. The FL has proven to work as intended. Both high-g transients and excessive structural loads are controlled with NN hard-over commands. This presentation discusses the FL design features and presents test cases. Simulation runs are included to illustrate the dramatic improvement made to the control of NN hard-over effects. A mission control room display from a flight playback is presented to illustrate the neural net fault display representation. The FL is very adaptable to various requirements and is independent of flight condition. It should be considered as a cost-effective safety monitor to control single-string inputs in general.

Larson, Richard R.↗

Implementation of an Adaptive Controller System from Concept to Flight Test

The National Aeronautics and Space Administration (NASA) at the Dryden Flight Research Center (DFRC) has been conducting flight-test research using an F-15 aircraft (figure 1). This aircraft has been specially modified to interface a neural net (NN) controller as part of a single-string Airborne Research Test System (ARTS) computer with the existing quad-redundant flight control system (FCC) shown in figure 2. The NN commands are passed to FCC channels 2 and 4 and are cross channel data linked (CCDL) to the other computers as shown. Numerous types of fault-detection monitors exist in the FCC when the NN mode is engaged; these monitors would cause an automatic disengagement of the NN in the event of a triggering fault. Unfortunately, these monitors still may not prevent a possible NN hard-over command from coming through to the control laws. Therefore, an additional and unique safety monitor was designed for a single-string source that allows authority at maximum actuator rates but protects the pilot and structural loads against excessive g-limits in the case of a NN hard-over command input. This additional monitor resides in the FCCs and is executed before the control laws are computed. This presentation describes a "floating limiter" (FL) concept that was developed and successfully test-flown for this program (figure 3). The FL computes the rate of change of the NN commands that are input to the FCC from the ARTS. A window is created with upper and lower boundaries, which is constantly "floating" and trying to stay centered as the NN command rates are changing. The limiter works by only allowing the window to move at a much slower rate than those of the NN commands. Anywhere within the window, however, full rates are allowed. If a rate persists in one direction, it will eventually "hit" the boundary and be rate-limited to the floating limiter rate. When this happens, a persistent counter begins and after a limit is reached, a NN disengage command is generated. The tunable metrics for the FL are (1) window size, (2) drift rate, and (3) persistence counter. Ultimate range limits are also included in case the NN command should drift slowly to a limit value that would cause the FL to be defeated. The FL has proven to work as intended. Both high-g transients and excessive structural loads are controlled with NN hard-over commands. This presentation discusses the FL design features and presents test cases. Simulation runs are included to illustrate the dramatic improvement made to the control of NN hard-over effects. A mission control room display from a flight playback is presented to illustrate the neural net fault display representation. The FL is very adaptable to various requirements and is independent of flight condition. It should be considered as a cost-effective safety monitor to control single-string inputs in general.

Larson, Richard R.↗