Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Protection Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

The evolution of power management architecture for missions to the outer planets

Outer planet spacecraft have unique requirements that differentiate them from inner planet and Earth orbiter spacecraft. To meet these requirements, the Voyager and Galileo Power Management And Distribution (PMAD) architectures employed shunt regulation and carried on the Mariner tradition of AC power distribution to many of the user loads. Also, autonomous fault recovery was achieved by automatic responses in hardware and software recovery routines. Finally, power distribution switching was expanded to allow for removal of the most trivial load element as the nuclear source depleted itself. The design cycle has begun for a third generation spacecraft set named Comet Rendezvous Asteroid Flyby (CRAF) and Cassini (a saturn orbiter). In their power systems, AC power distribution, relay/fuse load switching, and fault protection will give way to the advantages of DC power and solid state load switches.

Detwiler, R. C.↗

NASA Tech Briefs, August 2004

Topics covered include: Data Relay Board with Protocol for High-Speed, Free-Space Optical Communications; Software and Algorithms for Biomedical Image Data Processing and Visualization; Rapid Chemometric Filtering of Spectral Data; Prioritizing Scientific Data for Transmission; Determining Sizes of Particles in a Flow from DPIV Data; Faster Processing for Inverting GPS Occultation Data; FPGA-Based, Self-Checking, Fault-Tolerant Computers; Ultralow-Power Digital Correlator for Microwave Polarimetry; Grounding Headphones for Protection Against ESD; Lightweight Stacks of Direct Methanol Fuel Cells; Highly Efficient Vector-Inversion Pulse Generators; Estimating Basic Preliminary Design Performances of Aerospace Vehicles; Framework for Development of Object-Oriented Software; Analyzing Spacecraft Telecommunication Systems; Collaborative Planning of Robotic Exploration; Tools for Administration of a UNIX-Based Network; Preparing and Analyzing Iced Airfoils; Evaluating Performance of Components; Fuels Containing Methane of Natural Gas in Solution; Direct Electrolytic Deposition of Mats of MnxOy Nanowires; Bubble Eliminator Based on Centrifugal Flow; Inflatable Emergency Atmospheric-Entry Vehicles; Lightweight Deployable Mirrors with Tensegrity Supports; Centrifugal Adsorption Cartridge System; Ultrasonic Apparatus for Pulverizing Brittle Material; Transplanting Retinal Cells using Bucky Paper for Support; Using an Ultrasonic Instrument to Size Extravascular Bubbles; Coronagraphic Notch Filter for Raman Spectroscopy; On-the-Fly Mapping for Calibrating Directional Antennas; Working Fluids for Increasing Capacities of Heat Pipes; Computationally-Efficient Minimum-Time Aircraft Routes in the Presence of Winds; Liquid-Metal-Fed Pulsed Plasma Thrusters; Personal Radiation Protection System; and Attitude Control for a Solar-Sail Spacecraft.

Source record↗

Development of Design Standards and Guidelines for Electromagnetic Compatibility and Lightning Protection for Spacecraft Utilizing Composite Materials

This final report presents information concerning technical accomplishments by Tec-Masters, Inc. (TMI) for this contract effort. This effort included the accomplishment and/or submission by TMI of the following items: (1) Literature Survey Report, Electrical Properties of Non-Metallic Composites by Mr. Hugh W. Denny; (2) Interim Report, Composite Materials - Conductivity, Shielding Effectiveness, and Current Carrying Capability by Mr. Ross W. Evans; (3) Fault Current Test Plan by Mr. Ross W. Evans (4) Fault Current Test Procedure by Mr. Ross W. Evans (5) Test Report, Fault Current Through Graphite Filament Reinforced Plastic, NASA CR-4774, Marshall Space Flight Center, Alabama, September 1996, by Mr. Ross W. Evans; (6) Test Plan, Lightning Effects on Composite Materials by Mr. Ross W. Evans; (7) Test Report, Lightning Effects on Composite Materials, NASA CR-4783, Marshall Space Flight Center, Alabama, February 1997, by Mr. Ross W. Evans; (8) Design Guidelines for Shielding Effectiveness, Current Carrying Capability, and the Enhancement of Conductivity of Composite Materials, NASA CR-4784, Marshall Space Flight Center, Alabama, September 1996, by Mr. Ross W. Evans. These items are not attached but are considered to be a part of this final report. Efforts on two additional items were accomplished at no increase in cost to NASA/MSFC. These items consisted of updating the 'MSFC EMC Design and Interference Control Handbook,' and revising the 'Design Guidelines for Shielding Effectiveness, Current Carrying Capability, and the Enhancement of Conductivity of Composite Materials.'

Camp, Dennis W.↗

Evaluating Protection System Performance for a Real-World Weak Grid Area With High Inverter-Based Resources

This paper evaluates an existing protection scheme implemented in a real-world weak grid area with a high penetration of inverter-based resources (IBRs). The study aims to assess the reliability and adequacy of protection schemes originally designed for traditional synchronous machine systems and determine whether they can continue to operate reliably in systems with high levels of IBRs. Hardware relays are tested using a controller-hardware-in-the-loop setup. PSCAD electromagnetic transient simulation with an IBR original equipment manufacturer black-box model is used to perform fault studies and generate COMTRADE data, which are replayed by a realtime digital simulator (RTDS) to feed input to the hardware relays. Three scenarios are analyzed: normal operation, an N-1 contingency, and an IBR-only scenario. The evaluation results reveal the following: 1) the protection scheme remains reliable under normal conditions and N-1 contingencies and 2) in IBRonly scenarios, differential protection (87L) continues to operate reliably, whereas local protection elements, such as distance and directional elements, fail because of the lack of regulated negative sequence current contributed by IBRs. These findings provide utilities with valuable insights for improving their protection systems in high-IBRs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Evaluating Protection System Performance for a Real-World Weak Grid Area With High Inverter-Based Resources: Preprint

This paper evaluates an existing protection scheme implemented in a real-world weak grid area with a high penetration of inverter-based resources (IBRs). The study aims to assess the reliability and adequacy of protection schemes originally designed for traditional synchronous machine systems and determine whether they can continue to operate reliably in systems with high levels of IBRs. Hardware relays are tested using a controller-hardware-in-the-loop setup. PSCAD electromagnetic transient simulation with an IBR original equipment manufacturer black-box model is used to perform fault studies and generate COMTRADE data, which are replayed by a real-time digital simulator (RTDS) to feed input to the hardware relays. Three scenarios are analyzed: normal operation, an N-1 contingency, and an IBR-only scenario. The evaluation results reveal the following: 1) the protection scheme remains reliable under normal conditions and N-1 contingencies and 2) in IBR-only scenarios, differential protection (87L) continues to operate reliably, whereas local protection elements, such as distance and directional elements, fail because of the lack of regulated negative sequence current contributed by IBRs. These findings provide utilities with valuable insights for improving their protection systems in high-IBRs.

24 POWER TRANSMISSION AND DISTRIBUTION↗

The Multi-Mission Earth Entry Vehicle for Sample Return Missions – Past, Present, and Future

The Multi-Mission Earth Entry Vehicle (MMEEV) is an enabling technology developed at NASA’s Langley Research Center (LaRC) over the last two decades for returning samples to Earth across a wide array of space science missions. Currently, the MMEEV is being considered for NASA’s Mars Sample Return (MSR) mission. The original vehicle concept, the Earth Entry Vehicle (EEV), was innovated at LaRC in 1998 as a robust solution to return Mars soil samples to Earth under stringent backward contamination requirements. These backward contamination requirements drove the EEV to have higher reliability than any capsule previously designed for a return-to-Earth sample return mission. The EEV achieved this high reliability by employing a passive (no active systems) vehicle architecture optimized for fault tolerance in a compact, low-mass configuration that is extensible to virtually any sample return mission. The original EEV concept utilized a carbon-carbon primary structure with high-density carbon phenolic thermal protection system. The capsule had a 60-degree sphere-cone forebody and a backshell geometry uniquely tailored to produce aerodynamics that would passively re-orient the vehicle if it entered the atmosphere with an off-nominal attitude. Contrary to every other sample return capsule conceived at the time, the EEV was designed to land without a parachute. The vehicle incorporated an integral energy-absorbing crushable structure that protected the Mars sample for landings on surfaces ranging from soft soil to solid concrete. This paper describes 20 years of technological advancements LaRC has incorporated into the EEV architecture to evolve it from the original, MSR-enabling vehicle, to a true multi-mission capability relevant to any sample return mission. The vehicle’s unique Integrated Composite Stiffener Structure (ICoSS) has been optimized for specific strength - supporting high-G atmospheric entries with steep entry angles that produce precise landing footprints on the ground. The vehicle geometry has been refined through wind tunnel testing and computational fluid dynamics simulations to improve the vehicle’s aerodynamic stability and robustness to off-nominal conditions from hypersonic to subsonic flight. The resulting configuration of the current MMEEV architecture is described, with details provided on its sample carrying capacity and atmospheric entry trajectory capabilities. The upgraded vehicle performance is mapped into current space science objectives, showing how the MMEEV supports future sample return missions and continues to be an enabling technology for NASA’s vision to return samples from Mars.

J M Corliss↗

The SAS4A/SASSYS-1 Version 5.8 Safety Analysis Code System

SAS4A/SASSYS-1 is a software simulation tool used to perform deterministic analysis of anticipated events as well as design basis and beyond design basis accidents for advanced nuclear reactors. Detailed, mechanistic models of steady-state and transient thermal, hydraulic, kinetic, and mechanical phenomena are employed to describe the response of the reactor core, the reactor primary and secondary coolant loops, the reactor control and protection systems, and the balance-of-plant to accidents caused by changes in coolant flow, loss of heat rejection, or reactivity insertion. The consequences of single and double-fault accidents can be modeled, including fuel and coolant heating, fuel and cladding mechanical behavior, core reactivity feedbacks, coolant loop performance including natural circulation, and decay heat removal. Analyses are typically terminated upon demonstration of reactor and plant shutdown to permanently coolable conditions, or upon violation of design basis margins. The objective of the analysis is to quantify accident consequences as measured by the transient behavior of system performance parameters, such as fuel and cladding temperatures, reactivity, and cladding strain. Originally developed for analysis of sodium cooled reactors with oxide fuel clad by stainless steel, the models were subsequently extended and specialized to metallic fuel clad with advanced alloys and to several other coolant options, including lead, LBE, and water.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Probabilistic Risk Assessment for Decision Making During Spacecraft Operations

Decisions made during the operational phase of a space mission often have significant and immediate consequences. Without the explicit consideration of the risks involved and their representation in a solid model, it is very likely that these risks are not considered systematically in trade studies. Wrong decisions during the operational phase of a space mission can lead to immediate system failure whereas correct decisions can help recover the system even from faulty conditions. A problem of special interest is the determination of the system fault protection strategies upon the occurrence of faults within the system. Decisions regarding the fault protection strategy also heavily rely on a correct understanding of the state of the system and an integrated risk model that represents the various possible scenarios and their respective likelihoods. Probabilistic Risk Assessment (PRA) modeling is applicable to the full lifecycle of a space mission project, from concept development to preliminary design, detailed design, development and operations. The benefits and utilities of the model, however, depend on the phase of the mission for which it is used. This is because of the difference in the key strategic decisions that support each mission phase. The focus of this paper is on describing the particular methods used for PRA modeling during the operational phase of a spacecraft by gleaning insight from recently conducted case studies on two operational Mars orbiters. During operations, the key decisions relate to the commands sent to the spacecraft for any kind of diagnostics, anomaly resolution, trajectory changes, or planning. Often, faults and failures occur in the parts of the spacecraft but are contained or mitigated before they can cause serious damage. The failure behavior of the system during operations provides valuable data for updating and adjusting the related PRA models that are built primarily based on historical failure data. The PRA models, in turn, provide insight into the effect of various faults or failures on the risk and failure drivers of the system and the likelihood of possible end case scenarios, thereby facilitating the decision making process during operations. This paper describes the process of adjusting PRA models based on observed spacecraft data, on one hand, and utilizing the models for insight into the future system behavior on the other hand. While PRA models are typically used as a decision aid during the design phase of a space mission, we advocate adjusting them based on the observed behavior of the spacecraft and utilizing them for decision support during the operations phase.

dynamic fault trees↗

Neural Net Safety Monitor Design

The National Aeronautics and Space Administration (NASA) at the Dryden Flight Research Center (DFRC) has been conducting flight-test research using an F-15 aircraft (figure 1). This aircraft has been specially modified to interface a neural net (NN) controller as part of a single-string Airborne Research Test System (ARTS) computer with the existing quad-redundant flight control system (FCC) shown in figure 2. The NN commands are passed to FCC channels 2 and 4 and are cross channel data linked (CCDL) to the other computers as shown. Numerous types of fault-detection monitors exist in the FCC when the NN mode is engaged; these monitors would cause an automatic disengagement of the NN in the event of a triggering fault. Unfortunately, these monitors still may not prevent a possible NN hard-over command from coming through to the control laws. Therefore, an additional and unique safety monitor was designed for a single-string source that allows authority at maximum actuator rates but protects the pilot and structural loads against excessive g-limits in the case of a NN hard-over command input. This additional monitor resides in the FCCs and is executed before the control laws are computed. This presentation describes a floating limiter (FL) concept1 that was developed and successfully test-flown for this program (figure 3). The FL computes the rate of change of the NN commands that are input to the FCC from the ARTS. A window is created with upper and lower boundaries, which is constantly floating and trying to stay centered as the NN command rates are changing. The limiter works by only allowing the window to move at a much slower rate than those of the NN commands. Anywhere within the window, however, full rates are allowed. If a rate persists in one direction, it will eventually hit the boundary and be rate-limited to the floating limiter rate. When this happens, a persistent counter begins and after a limit is reached, a NN disengage command is generated. The tunable metrics for the FL are (1) window size, (2) drift rate, and (3) persistence counter. Ultimate range limits are also included in case the NN command should drift slowly to a limit value that would cause the FL to be defeated. The FL has proven to work as intended. Both high-g transients and excessive structural loads are controlled with NN hard-over commands. This presentation discusses the FL design features and presents test cases. Simulation runs are included to illustrate the dramatic improvement made to the control of NN hard-over effects. A mission control room display from a flight playback is presented to illustrate the neural net fault display representation. The FL is very adaptable to various requirements and is independent of flight condition. It should be considered as a cost-effective safety monitor to control single-string inputs in general.

Larson, Richard R.↗

Implementation of an Adaptive Controller System from Concept to Flight Test

The National Aeronautics and Space Administration (NASA) at the Dryden Flight Research Center (DFRC) has been conducting flight-test research using an F-15 aircraft (figure 1). This aircraft has been specially modified to interface a neural net (NN) controller as part of a single-string Airborne Research Test System (ARTS) computer with the existing quad-redundant flight control system (FCC) shown in figure 2. The NN commands are passed to FCC channels 2 and 4 and are cross channel data linked (CCDL) to the other computers as shown. Numerous types of fault-detection monitors exist in the FCC when the NN mode is engaged; these monitors would cause an automatic disengagement of the NN in the event of a triggering fault. Unfortunately, these monitors still may not prevent a possible NN hard-over command from coming through to the control laws. Therefore, an additional and unique safety monitor was designed for a single-string source that allows authority at maximum actuator rates but protects the pilot and structural loads against excessive g-limits in the case of a NN hard-over command input. This additional monitor resides in the FCCs and is executed before the control laws are computed. This presentation describes a "floating limiter" (FL) concept that was developed and successfully test-flown for this program (figure 3). The FL computes the rate of change of the NN commands that are input to the FCC from the ARTS. A window is created with upper and lower boundaries, which is constantly "floating" and trying to stay centered as the NN command rates are changing. The limiter works by only allowing the window to move at a much slower rate than those of the NN commands. Anywhere within the window, however, full rates are allowed. If a rate persists in one direction, it will eventually "hit" the boundary and be rate-limited to the floating limiter rate. When this happens, a persistent counter begins and after a limit is reached, a NN disengage command is generated. The tunable metrics for the FL are (1) window size, (2) drift rate, and (3) persistence counter. Ultimate range limits are also included in case the NN command should drift slowly to a limit value that would cause the FL to be defeated. The FL has proven to work as intended. Both high-g transients and excessive structural loads are controlled with NN hard-over commands. This presentation discusses the FL design features and presents test cases. Simulation runs are included to illustrate the dramatic improvement made to the control of NN hard-over effects. A mission control room display from a flight playback is presented to illustrate the neural net fault display representation. The FL is very adaptable to various requirements and is independent of flight condition. It should be considered as a cost-effective safety monitor to control single-string inputs in general.

Larson, Richard R.↗

Design Guidelines for Shielding Effectiveness, Current Carrying Capability, and the Enhancement of Conductivity of Composite Materials

These guidelines address the electrical properties of composite materials which may have an effect on electromagnetic compatibility (EMC). The main topics of the guidelines include the electrical shielding, fault current return, and lightning protection capabilities of graphite reinforced polymers, since they are somewhat conductive but may require enhancement to be adequate for EMC purposes. Shielding effectiveness depends heavily upon the conductivity of the material. Graphite epoxy can provide useful shielding against RF signals, but it is approximately 1,000 times more resistive than good conductive metals. The reduced shielding effectiveness is significant but is still useful in many cases. The primary concern is with gaps and seams in the material just as it is with metal. Current carrying capability of graphite epoxy is adequate for dissipation static charges, but fault currents through graphite epoxy may cause fire at the shorting contact and at joints. The effect of lightning on selected graphite epoxy material and mating surfaces is described, and protection methods are reviewed.

Evans, R. W.↗

Power Actuation and Switching Module Development

The Deep Space Avionics (DSA) Project is developing a Power Actuation and Switching Module (PASM). This component enables a modular and scalable design approach for power switching applications, which can result in a wide variety of power switching architectures using this simple building block. The PASM is designed to provide most of the necessary power switching functions of spacecraft for various Deep Space missions including future missions to Mars, comets, Jupiter and its moons. It is fabricated using an A SIC process that is tolerant of high radiation. The development includes two application specific integrated circuits (ASICs) and support circuitry all packaged using High Density Interconnect (HDI) technology. It can be operated in series or parallel with other PASMs, It can be used as a high-side or low-side switch and it can drive thruster valves, pyrotechnic devices such as NASA standard initiators, bus shunt resistors, and regular spacecraft component loads. Each PASM contains two independent switches with internal current limiting and over-current trip-off functions to protect the power subsystem from load faults. During turnon and turnoff each switch can limit the rate of current change (di/dt) to a value determined by the user. Threeway majority-voted On/Off commandability and full switch status telemetry (both analog and digital) are built into the module. This paper describes the development process used to design, model, fabricate, and test these compact and versatile power switches. Preliminary test results from prototype HDI PASM hardware are also discussed.

Power Actuation and Switching Module (PASM)↗

Forming Human-Robot Teams Across Time and Space

NASA pushes telerobotics to distances that span the Solar System. At this scale, time of flight for communication is limited by the speed of light, inducing long time delays, narrow bandwidth and the real risk of data disruption. NASA also supports missions where humans are in direct contact with robots during extravehicular activity (EVA), giving a range of zero to hundreds of millions of miles for NASA s definition of "tele". . Another temporal variable is mission phasing. NASA missions are now being considered that combine early robotic phases with later human arrival, then transition back to robot only operations. Robots can preposition, scout, sample or construct in advance of human teammates, transition to assistant roles when the crew are present, and then become care-takers when the crew returns to Earth. This paper will describe advances in robot safety and command interaction approaches developed to form effective human-robot teams, overcoming challenges of time delay and adapting as the team transitions from robot only to robots and crew. The work is predicated on the idea that when robots are alone in space, they are still part of a human-robot team acting as surrogates for people back on Earth or in other distant locations. Software, interaction modes and control methods will be described that can operate robots in all these conditions. A novel control mode for operating robots across time delay was developed using a graphical simulation on the human side of the communication, allowing a remote supervisor to drive and command a robot in simulation with no time delay, then monitor progress of the actual robot as data returns from the round trip to and from the robot. Since the robot must be responsible for safety out to at least the round trip time period, the authors developed a multi layer safety system able to detect and protect the robot and people in its workspace. This safety system is also running when humans are in direct contact with the robot, so it involves both internal fault detection as well as force sensing for unintended external contacts. The designs for the supervisory command mode and the redundant safety system will be described. Specific implementations were developed and test results will be reported. Experiments were conducted using terrestrial analogs for deep space missions, where time delays were artificially added to emulate the longer distances found in space.

Hambuchen, Kimberly↗

Proton pulse charge calculation algorithm in Beam Power Limiting System at Spallation Neutron Source

A proton pulse charge calculation algorithm in the Beam Power Limiting System (BPLS) at the Spallation Neutron Source (SNS) was developed and implemented in an FPGA. The algorithm calculates one-minute running average of the pulse charges and issues a fault to the Personal Protection System (PPS) and the Machine Protection System (MPS) when a limit is reached. A bit-accurate model of the algorithm was first developed and tested in Matlab® and then implemented and simulated in VHDL using Vivado® design environment. Finally, the algorithm was verified on a µTCA-based hardware platform.

Bobrek, Miljko [ORNL] (ORCID:0000000332763451)↗

Test plan. GCPS task 7, subtask 7.1: IHM development

The overall objective of Task 7 is to identify cost-effective life cycle integrated health management (IHM) approaches for a reusable launch vehicle's primary structure. Acceptable IHM approaches must: eliminate and accommodate faults through robust designs, identify optimum inspection/maintenance periods, automate ground and on-board test and check-out, and accommodate and detect structural faults by providing wide and localized area sensor and test coverage as required. These requirements are elements of our targeted primary structure low cost operations approach using airline-like maintenance by exception philosophies. This development plan will follow an evolutionary path paving the way to the ultimate development of flight-quality production, operations, and vehicle systems. This effort will be focused on maturing the recommended sensor technologies required for localized and wide area health monitoring to a technology readiness level (TRL) of 6 and to establish flight ready system design requirements. The following is a brief list of IHM program objectives: design out faults by analyzing material properties, structural geometry, and load and environment variables and identify failure modes and damage tolerance requirements; design in system robustness while meeting performance objectives (weight limitations) of the reusable launch vehicle primary structure; establish structural integrity margins to preclude the need for test and checkout and predict optimum inspection/maintenance periods through life prediction analysis; identify optimum fault protection system concept definitions combining system robustness and integrity margins established above with cost effective health monitoring technologies; and use coupons, panels, and integrated full scale primary structure test articles to identify, evaluate, and characterize the preferred NDE/NDI/IHM sensor technologies that will be a part of the fault protection system.

Greenberg, H. S.↗

Fault Management Guiding Principles

Regardless of the mission type: deep space or low Earth orbit, robotic or human spaceflight, Fault Management (FM) is a critical aspect of NASA space missions. As the complexity of space missions grows, the complexity of supporting FM systems increase in turn. Data on recent NASA missions show that development of FM capabilities is a common driver for significant cost overruns late in the project development cycle. Efforts to understand the drivers behind these cost overruns, spearheaded by NASA's Science Mission Directorate (SMD), indicate that they are primarily caused by the growing complexity of FM systems and the lack of maturity of FM as an engineering discipline. NASA can and does develop FM systems that effectively protect mission functionality and assets. The cost growth results from a lack of FM planning and emphasis by project management, as well the maturity of FM as an engineering discipline, which lags behind the maturity of other engineering disciplines. As a step towards controlling the cost growth associated with FM development, SMD has commissioned a multi-institution team to develop a practitioner's handbook representing best practices for the end-to-end processes involved in engineering FM systems. While currently concentrating primarily on FM for science missions, the expectation is that this handbook will grow into a NASA-wide handbook, serving as a companion to the NASA Systems Engineering Handbook. This paper presents a snapshot of the principles that have been identified to guide FM development from cradle to grave. The principles range from considerations for integrating FM into the project and SE organizational structure, the relationship between FM designs and mission risk, and the use of the various tools of FM (e.g., redundancy) to meet the FM goal of protecting mission functionality and assets.

principles↗

Asynchronous Message Service Reference Implementation

This software provides a library of middleware functions with a simple application programming interface, enabling implementation of distributed applications in conformance with the CCSDS AMS (Consultative Committee for Space Data Systems Asynchronous Message Service) specification. The AMS service, and its protocols, implement an architectural concept under which the modules of mission systems may be designed as if they were to operate in isolation, each one producing and consuming mission information without explicit awareness of which other modules are currently operating. Communication relationships among such modules are self-configuring; this tends to minimize complexity in the development and operations of modular data systems. A system built on this model is a society of generally autonomous, inter-operating modules that may fluctuate freely over time in response to changing mission objectives, modules functional upgrades, and recovery from individual module failure. The purpose of AMS, then, is to reduce mission cost and risk by providing standard, reusable infrastructure for the exchange of information among data system modules in a manner that is simple to use, highly automated, flexible, robust, scalable, and efficient. The implementation is designed to spawn multiple threads of AMS functionality under the control of an AMS application program. These threads enable all members of an AMS-based, distributed application to discover one another in real time, subscribe to messages on specific topics, and to publish messages on specific topics. The query/reply (client/server) communication model is also supported. Message exchange is optionally subject to encryption (to support confidentiality) and authorization. Fault tolerance measures in the discovery protocol minimize the likelihood of overall application failure due to any single operational error anywhere in the system. The multi-threaded design simplifies processing while enabling application nodes to operate at high speeds; linked lists protected by mutex semaphores and condition variables are used for efficient, inter-thread communication. Applications may use a variety of transport protocols underlying AMS itself, including TCP (Transmission Control Protocol), UDP (User Datagram Protocol), and message queues.

Burleigh, Scott C.↗