Search NASA⌕ Search

SEARCH · Search NASA

Results for “Mission Operations Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Radiation and Plasma Environments for Lunar Missions

Space system design for lunar orbit and extended operations on the lunar surface requires analysis of potential system vulnerabilities to plasma and radiation environments to minimize anomalies and assure that environmental failures do not occur during the mission. Individual environments include the trapped particles in Earth s radiation belts, solar energetic particles and galactic cosmic rays, plasma environments encountered in transit to the moon and on the lunar surface (solar wind, terrestrial magnetosheath and magnetotail, and lunar photoelectrons), and solar ultraviolet and extreme ultraviolet photons. These are the plasma and radiation environments which contribute to a variety of effects on space systems including total ionizing dose and dose rate effects in electronics, degradation of materials in the space environment, and charging of spacecraft and lunar dust. This paper provides a survey of the relevant charged particle and photon environments of importance to lunar mission design ranging from the lowest (approx.few 10 s eV) photoelectron energies to the highest (approx.GeV) cosmic ray energies.

Minow, Joseph I.↗

NASA Support for Commercial Crew Launch Capabilities

Since the earliest days of U.S. human spaceflight, NASA’s Marshall Space Flight Center in Huntsville, Alabama, has played a key role in American crew launch capability, from engineering support for the first Mercury-Redstone launches, to the Saturn launches to the Moon, through Shuttle and now Artemis. Today, Marshall brings that expertise gained through decades of crewed space launches to NASA’s Commercial Crew Program (CCP), providing launch vehicle engineering and programmatic support. The team’s responsibilities have included human certification of commercial launch systems for the CCP missions, including Atlas V and Falcon 9, and verifying each launch vehicle complies with flight certification. MSFC provides expertise in nearly all aspects of launch vehicle design and performance including solid motors and liquid engines, stage propulsion, thrust vector control, structural and dynamics, safety and mission assurance. During each commercial crew launch, an engineering support team is on console at Marshall’s Huntsville Operations Support Center, which has provided launch operations support since Apollo, providing real-time oversight to safety standards for the vehicle and verifying data. Launch vehicle support for Commercial Crew has come as a paradigm shift for the MSFC team, inspiring new approaches that leverage expertise and best practices from past NASA-developed launch vehicle missions, while at the same time providing new synergies from work with commercial partners on CCP. This paper will explore the role that the Marshall launch vehicle services team plays in the Commercial Crew Program, as well as lessons learned from the program that will continue to benefit a new era of spaceflight partnerships.

Commercial Crew↗

Systems engineering and integration processes involved with manned mission operations

This paper will discuss three mission operations functions that are illustrative of the key principles of operations SE&I and of the processes and products involved. The flight systems process was selected to illustrate the role of the systems product line in developing the depth and cross disciplinary skills needed for SE&I and providing the foundation for dialogue between participating elements. FDDD was selected to illustrate the need for a structured process to assure that SE&I provides complete and accurate results that consistently support program needs. The flight director's role in mission operations was selected to illustrate the complexity of the risk/gain tradeoffs involved in the development of the flight techniques and flight rules process as well as the absolute importance of the leadership role in developing the technical, operational, and political trades.

Kranz, Eugene F.↗

Tailoring of NASA-STD-3001 to Lunar Gateway Program Requirements

The Gateway Program must meet NASA's Agency-level human rating requirements, which are intended to accommodate human capabilities and limitations while protecting the safety of the crew, and providing to the maximum extent practical, the capability to safely recover the crew from hazardous situations. Human systems integration represents a key human rating component of Moon to Mars systems to support the execution of Artemis missions, including compliance with mandatory standards for Health and Medical, Safety and Mission Assurance, and Engineering. The human system requirements, together with the human systems integration plan, medical operations requirements, and Gateway sub-system specifications, represent the flow-down of NASA Health and Medical Standards (NASA-STD-3001, Volumes 1 and 2) into the Gateway system. This paper discusses how these documents and other human systems integration activities provide full consideration of human capabilities and limitations as part of the total system design trade space, serving as an example on how the human must be effectively integrated as part of the system in order to achieve mission success. At a bigger scale, the paper con-tributes to the application of systems engineering standards to cutting-edge space exploration initiatives and to the dialogue on how systems engineering can continue to evolve to meet the needs of such ambitious projects.

Systems engineering↗

Automation of orbit determination functions for National Aeronautics and Space Administration (NASA)-supported satellite missions

The Flight Dynamics Facility (FDF) at Goddard Space Flight Center (GSFC) provides spacecraft trajectory determination for a wide variety of National Aeronautics and Space Administration (NASA)-supported satellite missions, using the Tracking Data Relay Satellite System (TDRSS) and Ground Spaceflight and Tracking Data Network (GSTDN). To take advantage of computerized decision making processes that can be used in spacecraft navigation, the Orbit Determination Automation System (ODAS) was designed, developed, and implemented as a prototype system to automate orbit determination (OD) and orbit quality assurance (QA) functions performed by orbit operations. Based on a machine-resident generic schedule and predetermined mission-dependent QA criteria, ODAS autonomously activates an interface with the existing trajectory determination system using a batch least-squares differential correction algorithm to perform the basic OD functions. The computational parameters determined during the OD are processed to make computerized decisions regarding QA, and a controlled recovery process isactivated when the criteria are not satisfied. The complete cycle is autonomous and continuous. ODAS was extensively tested for performance under conditions resembling actual operational conditions and found to be effective and reliable for extended autonomous OD. Details of the system structure and function are discussed, and test results are presented.

Mardirossian, H.↗

Automation of orbit determination functions for National Aeronautics and Space Administration (NASA)-supported satellite missions

The Flight Dynamics Facility (FDF) at Goddard Space Flight Center (GSFC) provides spacecraft trajectory determination for a wide variety of National Aeronautics and Space Administration (NASA)-supported satellite missions, using the Tracking Data Relay Satellite System (TDRSS) and Ground Spaceflight and Tracking Data Network (GSTDN). To take advantage of computerized decision making processes that can be used in spacecraft navigation, the Orbit Determination Automation System (ODAS) was designed, developed, and implemented as a prototype system to automate orbit determination (OD) and orbit quality assurance (QA) functions performed by orbit operations. Based on a machine-resident generic schedule and predetermined mission-dependent QA criteria, ODAS autonomously activates an interface with the existing trajectory determination system using a batch least-squares differential correction algorithm to perform the basic OD functions. The computational parameters determined during the OD are processed to make computerized decisions regarding QA, and a controlled recovery process is activated when the criteria are not satisfied. The complete cycle is autonomous and continuous. ODAS was extensively tested for performance under conditions resembling actual operational conditions and found to be effective and reliable for extended autonomous OD. Details of the system structure and function are discussed, and test results are presented.

Mardirossian, H.↗

Postlanding optimum designs for the assured crew return vehicle

The optimized preliminary engineering design concepts for postlanding operations of a water-landing Assured Crew Return Vehicle (ACRV) during a medical rescue mission are presented. Two ACRVs will be permanently docked to Space Station Freedom, fulfilling NASA's commitment to Assured Crew Return Capability in the event of an accident or illness. The optimized configuration of the ACRV is based on an Apollo command module (ACM) derivative. The scenario assumes landing a sick or injured crewmember on water with the possibility of a delayed rescue. Design emphasis is placed on four major areas. First is the design of a mechanism that provides a safe and time-critical means of removing the sick or injured crewmember from the ACRV. Support to the assisting rescue personnel is also provided. Second is the design of a system that orients and stabilizes the craft after landing so as to cause no further injury or discomfort to the already ill or injured crewmember. Third is the design of a system that provides full medical support to a sick or injured crewmember aboard the ACRV from the time of separation from the space station to rescue by recovery forces. Last is the design of a system that provides for the comfort and safety of the entire crew after splashdown up to the point of rescue. The four systems are conceptually integrated into the ACRV.

Hosterman, Kenneth C.↗

Rapid Application of Space Effects for the Small Satellites Systems and Services Symposium

NASA Ames Research Center (ARC) has engaged Military Branches, the Department of Defense, and other Government Agencies in successful partnerships to design, develop, deliver and support various space effects capabilities and space vehicles on timeline of need. Contracts with Industry are in place to execute operational and enabler missions using physical and informational infrastructures including Responsive Manufacturing capabilities and Digital Assurance. The intent is to establish a secure, web-enabled "store front" for ordering and delivering any capabilities required as defined by the users and directed by NASA ARC and Partner Organizations. The capabilities are envisioned to cover a broad range and include 6U CubeSats, 50-100 kg Space Vehicles, Modular Space Vehicle architecture variations, as well as rapid payload integration on various Bus options. The paper will discuss the efforts underway to demonstrate autonomous manufacturing of low-volume, high-value assets, to validate the ability of autonomous digital techniques to provide Mission Assurance, and to demonstrate cost savings through the identification, characterization, and utilization of Responsive Space components. The culmination of this effort will be the integration of several 6U satellites and their launch in 2016.

Small Satellite Systems↗

Mars Express Interplanetary Navigation from Launch to Mars Orbit Insertion: The JPL Experience

The National Aeronautics and Space Administration (NASA) Jet Propulsion Laboratory (JPL) played a significant role in supporting the safe arrival of the European Space Agency (ESA) Mars Express (MEX) orbiter to Mars on 25 December 2003. MEX mission is an international collaboration between member nations of the ESA and NASA, where NASA is supporting partner. JPL's involvement included providing commanding and tracking service with JPL's Deep Space Network (DSN), in addition to navigation assurance. The collaborative navigation effort between European Space Operations Centre (ESOC) and JPL is the first since ESA's last deep space mission, Giotto, and began many years before the MEX launch. This paper discusses the navigational experience during the cruise and final approach phase of the mission from JPL's perspective. Topics include technical challenges such as orbit determination using non-DSN tracking data and media calibrations, and modeling of spacecraft physical properties for accurate representation of non-gravitational dynamics. Also mentioned in this paper is preparation and usage of DSN Delta Differential Oneway Range ((Delta)DOR) measurements, a key element to the accuracy of the orbit determination.

Deep Space Network (DSN)↗

Guiding Integration of Formal Verification in Assurance Cases

Assurance cases are being increasingly acknowledged as away to build trust in complex systems with autonomous capabilities. An assurance case is a comprehensive, defensible, and valid justification that a system will function as intended for a specific mission and operating environment. Formal verification is often reserved for the most critical components of such systems. However, formal verification tools are often complex, and their usage is subject to many constraints and contextual dependencies. This can raise challenges both for performing the verification as well as reflecting the verification results appropriately in the assurance case, especially for non-expert users of the verification tool. To address these challenges, we present a tool-supported methodology for integrating formal verification results in an assurance case by capturing key verification method information in a rigorously constructed assurance case. In particular, we capture the tool specification in terms of its inputs, outputs, and assurance constraints as assumptions over inputs and guarantees provided over its outputs. The tool specification is parametrized over the inputs and outputs to both guide the intended application of the tool, as well as to check that the tool has been applied following the stated assumptions and that the guarantees hold. We define a generic tool assurance argument pattern that enables integration of the verification results in the assurance case by allowing custom refinement and automated instantiation for each tool use. We demonstrate our methodology on two formal verification tools and their applications to the verification of neural network properties for the aircraft domain.

Assurance Cases↗

Safety and Mission Assurance: A NASA Perspective

Manned spaceflight is an incredibly complex and inherently risky human endeavor. As the result of the lessons learned through years of triumph and tragedy, the National Aeronautics and Space Administration (NASA) has embraced a comprehensive and integrated approach to the challenge of ensuring safety and mission success. This presentation will provide an overview of some of the techniques employed in this effort, with a focus on the processing operations performed at the Kennedy Space Center (KSC).

comprehensive↗

Formal design specification of a Processor Interface Unit

This report describes work to formally specify the requirements and design of a processor interface unit (PIU), a single-chip subsystem providing memory-interface bus-interface, and additional support services for a commercial microprocessor within a fault-tolerant computer system. This system, the Fault-Tolerant Embedded Processor (FTEP), is targeted towards applications in avionics and space requiring extremely high levels of mission reliability, extended maintenance-free operation, or both. The need for high-quality design assurance in such applications is an undisputed fact, given the disastrous consequences that even a single design flaw can produce. Thus, the further development and application of formal methods to fault-tolerant systems is of critical importance as these systems see increasing use in modern society.

Fura, David A.↗

Perspectives on Risk in Space System Development

This presentation provides an overview of a range of perspectives on risk in the development and operation of space systems. It also introduces the concept of risk-based safety and mission assurance.

Leitner, Jesse↗

Shielding Considerations for CubeSat Structures During Solar Maximum

The purpose of this lessons learned is to communicate the utility of shielding in small spacecraft planning for the support of mission assurance and reliability. Numerous SmallSats have been flying in polar low earth orbit for scientific, communications, technology demonstrations, and imaging with academic, commercial, and government interests. Shielding has been part of mission assurance and reliability from the advent of long duration spacecraft missions. The Shields-1 CubeSat has been operating in polar low earth orbit since 16 December 2018 with atomic number (Z)-grade radiation shielding and demonstrates shielding effectiveness. Shields-1 has collected a representative example of solar minimum data in 2019 with 8 Teledyne dosimeters over varying shielding effectiveness. It serves as current experimental data and has been compared with NOVICE Shielding estimates using the AP8 –AE8 trapped radiation model with the Shields-1 CAD and generic CubeSat 3 unit (U) models. Using NOVICE model radiation analysis coding, the shielding effectiveness's, based on a generic CubeSat 3U structure with 4 electronic boards, were estimated for aluminum wall thicknesses ranging from 0.204 cmto4.44 cm (0.550 g/cm2–12.0 g/cm2) thick aluminum. For modeled polar orbiting spacecraft, solar maximum total ionizing dose (TID)increases by nearly a magnitude for thin-walled aluminum 0.550g/cm2-0.686 g/cm2(0.204 cm –0.254 cm) typical CubeSat structures. The shielding effectiveness by NOVICE Sigma estimates, which is a shielding sphere approximation around a detector, showed a linear relationship with wall thickness, which increased over the wall thickness by a ratio of 1.43 determined by linear regression analysis. Using NOVICE Adjoint Monte-Carlo Modeling of solar minimum and solar maximum with the inclusion of a worst-case solar particle event over a one year mission without geomagnetic shielding, the TID for minimum and maximum conditions for a generic 3U with a wall thickness of 0.254 cm is 158 RAD and 1540 RAD, respectively. The modeled total solar maximum TID is over estimated, because at low orbital latitudes a spacecraft will have shielding from Earth's magnetic field. However, TID will still be significant at high latitudes over the poles, where a spacecraft is exposed in a solar particle event. In contrast, to a thin walled generic 3U CubeSat, Shields-1 electronics enclosure has a shielding effectiveness of 21.3 g/cm2from NOVICE Sigma modeling and is expected to show reduced total ionizing dose increases during the present active Solar Cycle 25 period. Because solar particle events during solar maximum increase TID on electronic parts with thin-walled shielding in short periods of time, it is a mission assurance and reliability consideration on the spacecraft’s mission value versus adding shielding for risk reduction of premature spacecraft or instrument payload loss. Since the volumes of many instruments and system electronics have reduced with small spacecraft, shielding material costs and weight penalties have diminished. A small spacecraft project budget and schedule may limit traditional radiation-hardened part use and radiation testing requirements, where shielding can contribute to mission assurance and reliability with reduced costs.

Shields-1↗

Shielding Considerations for CubeSat Structures During Solar Maximum

The purpose of this lessons learned paper is to communicate the utility of shielding in small spacecraft planning for the support of mission assurance and reliability. Numerous SmallSats have been flying in polar low Earth orbit for science, communications, technology demonstrations, and imaging with academic, commercial, and government interests. Shielding has been part of mission assurance and reliability from the advent of long duration spacecraft missions. The Shields-1 CubeSat has been operating in polar low Earth orbit since 16 December 2018 with atomic number (Z)-grade radiation shielding and demonstrates shielding effectiveness. Shields-1 has collected a representative example of solar minimum data in 2019 with eight Teledyne µDosimeters over varying shielding effectivenesses. It serves as current experimental data and has been compared with NOVICE Shielding estimates using the AP8 – AE8 trapped radiation model with the Shields-1 CAD and generic CubeSat three unit (3U) models. Using NOVICE model radiation analysis coding, the shielding effectivenesses, based on a generic CubeSat 3U structure with four electronic boards, were estimated for aluminum wall thicknesses ranging from 0.204 cm to 4.44 cm (0.550 g/cm 2 to 12.0 g/cm 2 ). For modeled polar orbiting spacecraft, solar maximum total ionizing dose (TID) increases by nearly a magnitude for thin-walled aluminum 0.550-g/cm 2 - 0.686-g/cm 2 (0.204-cm – 0.254-cm) typical CubeSat structures. The shielding effectiveness estimated by NOVICE Sigma, which is a shielding sphere approximation around a detector, showed a linear relationship with wall thickness, which increased over the wall thickness by a ratio of 1.43 determined by linear regression analysis. Using NOVICE Adjoint Monte-Carlo Modeling of solar minimum and solar maximum with the inclusion of a worst-case solar particle event over a one-year mission without geomagnetic shielding, the TID for minimum and maximum conditions for a generic 3U with a wall thickness of 0.254 cm is 158 RAD and 1540 RAD, respectively. The modeled total solar maximum TID is over estimated, because at low orbital latitudes a spacecraft will have shielding from the Earth’s magnetic field. However, TID will still be significant at high latitudes over the poles, where a spacecraft is exposed in a solar particle event. In contrast to a thin-walled generic 3U CubeSat, the Shields-1 electronics enclosure has a shielding effectiveness of 21.3 g/cm 2 from NOVICE Sigma modeling and is expected to show reduced total ionizing dose increases during the present active Solar Cycle 25 period. Because solar particle events during solar maximum increase TID on electronic parts with thin-walled shielding in short periods of time, it is a mission assurance and reliability consideration on the mission value of the spacecraft versus adding shielding for risk reduction of premature spacecraft or instrument payload loss. Since the volumes of many instruments and system electronics have reduced with small spacecraft, shielding material costs and weight penalties have diminished. A small spacecraft project budget and schedule may limit traditional radiation-hardened part use and radiation testing requirements, where shielding can contribute to mission assurance and reliability with reduced costs.

Shields-1↗

Dynamic Assurance of Autonomous Systems through Ground Control Software

Assurance cases are being increasingly acknowledged as a way to build trust in complex systems with autonomous capabilities [1]. An assurance case is a comprehensive, defensible, and valid justification that a system will function as intended for the specific mission and operating environment. Such justifications for systems with autonomous capabilities are often based on various probabilistic quantifications [2]. Due to the dynamic nature of the environmental conditions in which these systems operate, as well as the changing nature of the autonomous systems themselves, these probabilistic quantifications cannot be simply estimated once during design time. Rather, they need to be continually evaluated during systems operations to ensure that the assurance case justifications are valid. We refer to the assurance case that combines both the static and dynamic elements as a Dynamic Assurance Case (DAC). Such complex systems with autonomous capabilities are often deployed with a Ground Control Software (GCS) component to enable remote operation. Whether the system is composed of a single unit or a fleet of units, deployed distributed or in remote environments, GCS acts as a window into the behavior of the deployed system. It receives telemetry from the system, issues commands to the system and provides various functionalities to visualize the system performance. We propose a dynamic assurance framework where the GCS acts as a relay between the autonomous system and its DAC. GCS can be used to measure both unit-specific as well as system-wide probabilistic quantifications using the incoming telemetry. We embed these quantifications throughout the DAC as variables that can be updated by external sources. We use the GCS to periodically update these variables, which allows us to continually evaluate the formally defined assurance case justifications. We demonstrate our dynamic assurance framework in the NASA Ames project Troupe1 that aims at developing a fleet of rovers capable of au- tonomously mapping their environment. The rovers work cooperatively, each collecting data for different parts of the environment. Each rover runs an identical core Flight System (cFS) [4] application. Troupe1 uses OpenC3 Cosmos [5] as the ground system, and AdvoCATE [3] to capture the system DAC. We show how we can measure both rover-specific and system-wide quantifications in Cosmos using its Ruby scripting editor and pass them into the DAC modelled in AdvoCATE. Then, we show how these incoming variables can be embedded in different parts of the DAC and how effects of their updates can be observed

Irfan Sljivo↗

Dynamic Assurance of Autonomous Systems through Ground Control Software∗

Assurance cases are being increasingly acknowledged as a way to build trust in complex systems with autonomous capabilities [1]. An assurance case is a comprehensive, defensible, and valid justification that a system will function as intended for the specific mission and operating environment. Such justifications for systems with autonomous capabilities are often based on various probabilistic quantifications [2]. Due to the dynamic nature of the environmental conditions in which these systems operate, as well as the changing nature of the autonomous systems themselves, these probabilistic quantifications cannot be simply estimated once during design time. Rather, they need to be continually evaluated during systems operations to ensure that the assurance case justifications are valid. We refer to the assurance case that combines both the static and dynamic elements as a Dynamic Assurance Case (DAC).

dynamic assurance case↗