Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Protection Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Radio-hosted Flight / Ground Interface for Operations Standardization

The interface between a spacecraft and its ground operations segment includes the flow of commands, configuration, and sequencing elements to the spacecraft, and the flow of telemetry and data products from the spacecraft. Creating and implementing a complete definition of this interface simplifies and standardizes mission operations, allowing easy sharing of operations personnel across missions. Early spacecraft featured a simple flight / ground interface (FGI) using hardware command decoding in the radio, driven by technological limitations of the time. Modern spacecraft use command and data handling (CDH) avionics on which flight software executes, which in turn controls and configures the mission, executes subsystem and instrument instructions, and implements critical fault protection actions. Deep space missions feature advanced operations software for running sequenced activities over a period of weeks, which allows them to function with only infrequent ground contact. This approach comes at the cost of increased complexity in the FGI, requiring expensive modifications to heritage flight software and ground systems. By hosting the interface in the radio instead of the CDH avionics, modern missions can approximate the FGI design simplicity of early spacecraft, with significant advantages for vendor competition, lowered costs, standardization of operations, and reduction of implementation risk.

Lock, Patricia D.↗

SVM-Based Synchronized Fault Detection for 100% Renewable Microgrids

Traditional protection schemes face significant challenges when applied to microgrids with high penetrations of renewables with inverter-based resources (IBRs). The proliferation of advanced sensing and communication technologies has generated copious data, offering an opportunity to overcome these limitations using data-driven machine learning approaches. This work proposes a novel approach based on a support vector machine (SVM) for detecting faults within a 100% renewable microgrid. The approach encompasses a systematic offline training stage for the development of a linear SVM-based fault detection algorithm. This process covers offline data collection from the microgrid under study, the extraction of features such as positive- and negative-sequence components and the total harmonic distortion of the voltage and current measurements of the relays, and the design of the linear SVM-based classifier. During the online implementation, however, different classifiers can exhibit asynchronicity in detecting the fault inception at different subcycle-to-cycle period-level delays. To circumvent this asynchronicity issue, a separate algorithm is developed for each relay to estimate the fault inception time as close to the real fault time. The performance of the proposed SVM-based synchronized fault detection method is evaluated using online time-domain simulation studies on a microgrid test system. The results corroborate the reliability of the fault detection scheme when tested under various fault cases (fault types, locations, and impedances) and non-fault cases during both grid-tied and islanded operation modes.

100% microgrid↗

SVM-Based Synchronized Fault Detection for 100% Renewable Microgrids: Preprint

Traditional protection schemes face significant challenges when applied to microgrids with high penetrations of renewables with inverter-based resources (IBRs). The proliferation of advanced sensing and communication technologies has generated copious data, offering an opportunity to overcome these limitations using data-driven machine learning approaches. This work proposes a novel approach based on a support vector machine (SVM) for detecting faults within a 100% renewable microgrid. The approach encompasses a systematic offline training stage for the development of a linear SVM-based fault detection algorithm. This process covers offline data collection from the microgrid under study, the extraction of features such as positive- and negative-sequence components and the total harmonic distortion of the voltage and current measurements of the relays, and the design of the linear SVM-based classifier. During the online implementation, however, different classifiers can exhibit asynchronicity in detecting the fault inception at different subcycle-to-cycle period-level delays. To circumvent this asynchronicity issue, a separate algorithm is developed for each relay to estimate the fault inception time as close to the real fault time. The performance of the proposed SVM-based synchronized fault detection method is evaluated using online time-domain simulation studies on a microgrid test system. The results corroborate the reliability of the fault detection scheme when tested under various fault cases (fault types, locations, and impedances) and non-fault cases during both grid-tied and islanded operation modes.

100% microgrid↗

Feature Acquisition with Imbalanced Training Data

This work considers cost-sensitive feature acquisition that attempts to classify a candidate datapoint from incomplete information. In this task, an agent acquires features of the datapoint using one or more costly diagnostic tests, and eventually ascribes a classification label. A cost function describes both the penalties for feature acquisition, as well as misclassification errors. A common solution is a Cost Sensitive Decision Tree (CSDT), a branching sequence of tests with features acquired at interior decision points and class assignment at the leaves. CSDT's can incorporate a wide range of diagnostic tests and can reflect arbitrary cost structures. They are particularly useful for online applications due to their low computational overhead. In this innovation, CSDT's are applied to cost-sensitive feature acquisition where the goal is to recognize very rare or unique phenomena in real time. Example applications from this domain include four areas. In stream processing, one seeks unique events in a real time data stream that is too large to store. In fault protection, a system must adapt quickly to react to anticipated errors by triggering repair activities or follow- up diagnostics. With real-time sensor networks, one seeks to classify unique, new events as they occur. With observational sciences, a new generation of instrumentation seeks unique events through online analysis of large observational datasets. This work presents a solution based on transfer learning principles that permits principled CSDT learning while exploiting any prior knowledge of the designer to correct both between-class and withinclass imbalance. Training examples are adaptively reweighted based on a decomposition of the data attributes. The result is a new, nonparametric representation that matches the anticipated attribute distribution for the target events.

Thompson, David R.↗

Analysis of a Landing System for Planetary Payloads Utilizing Passive Energy Absorbing Composite Structure

Delivery of a payload from space to a planetary surface currently requires the development of an application specific landing system to protect the payload from forces imparted during impact with the planet surface. Often, active energy attenuating systems such as retro-rockets, deployable parachutes, and airbags are utilized within these landing systems to reduce landing impact energy. Unfortunately, these active systems come at a cost; active energy attenuating systems are susceptible to system faults which may limit or completely negate their energy attenuating capability. Additionally, components needing to be stowed such as fuel, parachutes, and airbags increase design complexity, cost, and weight. To overcome these limitations, this study examines the potential of passive energy attenuation through energy absorbing structural design and composite materials to mitigate landing loads for small payload planetary delivery. Researchers at the National Aeronautics and Space Administration (NASA) Langley Research Center (LaRC) have conducted extensive research into developing energy absorbing structures and components for the attenuation of impact energy under various loading conditions including aircraft crash and spacecraft impact. The current study leverages this research to design a lightweight planetary delivery system which utilizes unique outer mold line (OML) geometry and passive energy absorbing structural design to limit landing loads across potential planetary surface environments. The OML geometry is designed to control impact orientation and provide self-righting capabilities for slopped impact surfaces. The internal structure is composed of composite material structures arranged to provide energy absorption which is robust to impact angle and impact velocity. The developed planetary delivery design concept will be evaluated using finite element (FE) model analysis. Simulations of landing impacts with representative soil surface environments will be used to characterize the energy absorbing capabilities of the landing system. Sensitivity of predicted impact force to landing environment, impact angle, and impact velocity will be assessed to identify capabilities and limitations of the initial structural design. Results will be used to determine the feasibility of a lightweight composite structure to passively absorb landing energy for robust planetary payload delivery.

Crashworthiness↗

Mars Surveyor '98 Landers MVACS Robotic Arm Control System Design Concepts

This paper describes the control system design concepts for the Mars Volatiles and Climate Surveyor (MVACS) Robotic Arm which supports the scientific investigations to be conducted as part of the Mars Surveyor '98 Lander project. Solutions are presented to some of the problems encountered in this demanding space application with its tight constraints on mass, power, volume, and computing resources. Problems addressed include 4-DOF forward and inverse kinematics, trajectory planning to minimize potential impact damage, joint drive train protection, Lander tilt prevention, hardware fault monitoring, and collision avoidance.

Bonitz, Robert G.↗

The Unparalleled Systems Engineering of MSL's Backup Entry, Descent, and Landing System: Second Chance

Second Chance (SECC) was a bare bones version of Mars Science Laboratory's (MSL) Entry Descent & Landing (EDL) flight software that ran on Curiosity's backup computer, which could have taken over swiftly in the event of a reset of Curiosity's prime computer, in order to land her safely on Mars. Without SECC, a reset of Curiosity's prime computer would have lead to catastrophic mission failure. Even though a reset of the prime computer never occurred, SECC had the important responsibility as EDL's guardian angel, and this responsibility would not have seen such success without unparalleled systems engineering. This paper will focus on the systems engineering behind SECC: Covering a brief overview of SECC's design, the intense schedule to use SECC as a backup system, the verification and validation of the system's "Do No Harm" mandate, the system's overall functional performance, and finally, its use on the fateful day of August 5th, 2012.

fault protection↗

Enhancing the Cassini Mission Through FP Applications After Launch

Although rigorous pre-emptive measures are taken to preclude failures and anomalous conditions from occurring in JPL spacecraft missions prior to launch, unforeseeable problems can still surface after liftoff. In the case of the Cassini/Huygens Mission-to-Saturn spacecraft, several problems were observed post-launch: 1) immediately after takeoff, the collected engineering/science data stored on the Solid State Recorders (SSR) contained a significantly higher number of corrupted bits than was expected (considerably over spec) due to human error in the memory mapping of these devices, 2) numerous Solid State Power Switches (SSPS) sporadically tripped off throughout the mission due to cosmic ray bombardment from the unique space environment, and 3) false assumptions in the pressure regulator design in combination with missing heritage test data led to inaccurate design conclusions, causing the issuance of two waivers for the regulator to close properly (a potentially mission catastrophic single-point failure which occurred 24 days after launch) - amongst other problems. For Cassini, some of these anomalies led to arduous work-arounds or required continuous monitoring of telemetry variables by the ground-based Spacecraft Operations Flight Support (SOFS) team in order to detect and fix fault occurrences as they happened. Fortunately, sufficient funding and schedule margin allowed several Fault Protection (FP) solutions to be implemented into post-launch Flight Software (FSW) uploads to help resolve these issues autonomously, reducing SOFS ground support efforts while improving anomaly recovery time in order to preserve maximum science capture. This paper details the FP applications used to resolve the above issues as well as to optimize solutions for several other problems experienced by the Cassini spacecraft during its fight, in order to enhance the spacecraft's overall mission success throughout the 18 years of its 20 year expedition to and within the Saturnian system.

fault protection↗

NASA Tech Briefs, March 2014

Topics include: Data Fusion for Global Estimation of Forest Characteristics From Sparse Lidar Data; Debris and Ice Mapping Analysis Tool - Database; Data Acquisition and Processing Software - DAPS; Metal-Assisted Fabrication of Biodegradable Porous Silicon Nanostructures; Post-Growth, In Situ Adhesion of Carbon Nanotubes to a Substrate for Robust CNT Cathodes; Integrated PEMFC Flow Field Design for Gravity-Independent Passive Water Removal; Thermal Mechanical Preparation of Glass Spheres; Mechanistic-Based Multiaxial-Stochastic-Strength Model for Transversely-Isotropic Brittle Materials; Methods for Mitigating Space Radiation Effects, Fault Detection and Correction, and Processing Sensor Data; Compact Ka-Band Antenna Feed with Double Circularly Polarized Capability; Dual-Leadframe Transient Liquid Phase Bonded Power Semiconductor Module Assembly and Bonding Process; Quad First Stage Processor: A Four-Channel Digitizer and Digital Beam-Forming Processor; Protective Sleeve for a Pyrotechnic Reefing Line Cutter; Metabolic Heat Regenerated Temperature Swing Adsorption; CubeSat Deployable Log Periodic Dipole Array; Re-entry Vehicle Shape for Enhanced Performance; NanoRacks-Scale MEMS Gas Chromatograph System; Variable Camber Aerodynamic Control Surfaces and Active Wing Shaping Control; Spacecraft Line-of-Sight Stabilization Using LWIR Earth Signature; Technique for Finding Retro-Reflectors in Flash LIDAR Imagery; Novel Hemispherical Dynamic Camera for EVAs; 360 deg Visual Detection and Object Tracking on an Autonomous Surface Vehicle; Simulation of Charge Carrier Mobility in Conducting Polymers; Observational Data Formatter Using CMOR for CMIP5; Propellant Loading Physics Model for Fault Detection Isolation and Recovery; Probabilistic Guidance for Swarms of Autonomous Agents; Reducing Drift in Stereo Visual Odometry; Future Air-Traffic Management Concepts Evaluation Tool; Examination and A Priori Analysis of a Direct Numerical Simulation Database for High-Pressure Turbulent Flows; and Resource-Constrained Application of Support Vector Machines to Imagery.

Source record↗

HAPPA: A Modular Platform for HPC Application Resilience Analysis with LLMs Embedded

High-performance computing (HPC) systems are increasingly vulnerable to soft errors, which pose significant challenges in maintaining computational accuracy and reliability. Predicting the resilience of HPC applications to these errors is crucial for robust code protection and detailed resilience analysis. In this study, we present HAppA, a modular platform designed for HPC Application Resilience Analysis. Embedding Large Language Models (LLMs), HAppA addresses understanding the context information of long code sequences typical in HPC applications. HAppA implements a novel code representation module that chunks the code into fixed-size segments and aggregates the embeddings of these segments. Three aggregation methods have been explored: MeanPooling, MaxPooling, and LSTM-based techniques. We built a DAtaset for REsilience analysis using Fault Injection (FI), named DARE. Using our DARE dataset, HAppA is trained for regression prediction tasks. Our evaluation results demonstrate the predictive accuracy of HAppA compared to other models, particularly noting that the LSTM-based aggregation method -- HAppA-LSTM -- achieves a mean squared error (MSE) of 0.078 for SDC prediction, surpassing the existing state-of-the-art PARIS model, which recorded an MSE of 0.1172. Additionally, HAppA with the KeyBERT model extracts a list of keywords representing the source code. A comprehensive importance analysis of these keywords further elucidates the code patterns contributing to the error rate. These findings highlight the effectiveness of HAppA in analyzing the resilience of HPC applications and establish a new benchmark for predictive accuracy in resilience.

Jiang, Hailong [Kent State University]↗

An Investigative Redesign of the ECG and EMG Signal Conditioning Circuits for Two-fault Tolerance and Circuit Improvement

An investigation was undertaken to make the elctrocardiography (ECG) and the electromyography (EMG) signal conditioning circuits two-fault tolerant and to update the circuitry. The present signal conditioning circuits provide at least one level of subject protection against electrical shock hazard but at a level of 100 micro-A (for voltages of up to 200 V). However, it is necessary to provide catastrophic fault tolerance protection for the astronauts and to provide protection at a current level of less that 100 micro-A. For this study, protection at the 10 micro-A level was sought. This is the generally accepted value below which no possibility of microshock exists. Only the possibility of macroshock exists in the case of the signal conditioners. However, this extra amount of protection is desirable. The initial part deals with current limiter circuits followed by an investigation into the signal conditioner specifications and circuit design.

Obrien, Edward M.↗

Design analysis and computer-aided performance evaluation of shuttle orbiter electrical power system. Volume 1: Summary

Studies were conducted to develop appropriate space shuttle electrical power distribution and control (EPDC) subsystem simulation models and to apply the computer simulations to systems analysis of the EPDC. A previously developed software program (SYSTID) was adapted for this purpose. The following objectives were attained: (1) significant enhancement of the SYSTID time domain simulation software, (2) generation of functionally useful shuttle EPDC element models, and (3) illustrative simulation results in the analysis of EPDC performance, under the conditions of fault, current pulse injection due to lightning, and circuit protection sizing and reaction times.

Source record↗

A Framework for Extending the Science Traceability Matrix: Application to the Planned Europa Mission

One of the most critical functions of the systems engineering requirements process for a large multi-instrument science-driven space mission is to successfully communicate customer expectations into a comprehensive and traceable science requirements flowdown. These requirements are essential to communicating the constraints on the scope of the science investigations and clarifying how multiple instruments contribute to a given science goal. They also provide insight into how the science goals of the whole mission are affected by design choices. There is little specific guidance available on best practices for developing this science-driven flowdown. A unified Science Traceability Matrix (USTM) contains a significant amount of information that can be leveraged for that purpose, but the USTM was not designed to directly produce a complete science requirements flowdown. Thus, starting with the principles codified in a USTM, the authors propose a framework that directly maps into the requirements flowdown and supports broader systems engineering processes while retaining its meaning to the science team. This Science Traceability and Alignment Framework, or STAF, defines a set of common definitions and valid relationships to structure communication across the project. In addition, STAF populates a network of information that can be useful to support complex mission analysis activities such as fault protection. This work discusses the highest-level implementation of the STAF, the project-domain or P-STAF, which describes an approach to decomposing customer requirements into science requirements. The planned Europa Mission is used as a case study for the implementation of this framework and its potential benefits to a project.

Susca, Sara↗

Power processor for a 20CM ion thruster

A power processor breadboard for the JPL 20CM Ion Engine was designed, fabricated, and tested to determine compliance with the electrical specification. The power processor breadboard used the silicon-controlled rectifier (SCR) series resonant inverter as the basic power stage to process all the power to the ion engine. The breadboard power processor was integrated with the JPL 20CM ion engine and complete testing was performed. The integration tests were performed without any silicon-controlled rectifier failure. This demonstrated the ruggedness of the series resonant inverter in protecting the switching elements during arcing in the ion engine. A method of fault clearing the ion engine and returning back to normal operation without elaborate sequencing and timing control logic was evolved. In this method, the main vaporizer was turned off and the discharge current limit was reduced when an overload existed on the screen/accelerator supply. After the high voltage returned to normal, both the main vaporizer and the discharge were returned to normal.

Biess, J. J.↗

On reliability modeling and analysis of ultrareliable fault-tolerant digital systems.

The processes of protective redundancy, namely, standby replacement (SR) redundancy and hybrid redundancy (a combination of SR and multiple-line voting redundancy), find application in the architecture of fault-tolerant digital computers and enable them to be ultrareliable and self-repairing. The claims to ultrareliability lead to the challenge of quantitatively evaluating and assigning a value to the probability of survival as a function of the mission durations intended. This note presents various mathematical models, and derives and displays quantitative evaluations of system reliability as a function of various mission parameters of interest to the system designer.

Mathur, F. P.↗

Autonomic Management of Space Missions

With NASA s renewed commitment to outer space exploration, greater emphasis is being placed on both human and robotic exploration. Even when humans are involved in the exploration, human tending of assets becomes cost-prohibitive or in many cases is simply not feasible. In addition, certain exploration missions will require spacecraft that will be capable of venturing where humans cannot be sent. Early space missions were operated manually from ground control centers with little or no automated operations. In the mid-l980s, the high costs of satellite operations prompted NASA, and others, to begin automating as many functions as possible. In our context, a system is autonomous if it can achieve its goals without human intervention. A number of more-or-less automated ground systems exist today, but work continues with the goal being to reduce operations costs to even lower levels. Cost reductions can be achieved in a number of areas. Ground control and spacecraft operations are two such areas where greater autonomy can reduce costs. As a consequence, autonomy is increasingly seen as a critical approach for robotic missions and for some aspects of manned missions. Although autonomy will be critical for the success of future missions (and indeed will enable certain kinds of science data gathering approaches), missions imbued with autonomy must also exhibit autonomic properties. Exploitation of autonomy alone, without emphasis on autonomic properties, will leave spacecraft vulnerable to the dangerous environments in which they must operate. Without autonomic properties, a spacecraft may be unable to recognize negative environmental effects on its components and subsystems, or may be unable to take any action to ameliorate the effects. The spacecraft, though operating autonomously, may then sustain a degradation of performance of components or subsystems, and consequently may have a reduced potential for achieving mission objectives. In extreme cases, lack of autonomic properties could leave the spacecraft unable to recover from faults. Ensuring that exploration spacecraft have autonomic properties will increase the survivability and therefore the likelihood of success of these missions. In fact, over time, as mission requirements increased demands on spacecraft capabilities and longevity, designers have gradually built more autonomicity into spacecraft. For example, a spacecraft in low-earth orbit may experience an out-of-bounds perturbation of its attitude (orientation) due to increased drag caused by increased atmospheric density at its altitude as a result of a sufficiently large solar flare. If the spacecraft was designed to recognize the excessive attitude perturbation, it could decide to protect itself by going into a safe-hold mode where its internal configuration and operation are altered to conserve power and its coarse attitude is adjusted to point its solar panels toward the Sun to maximize power generation. This is an example of a simple type of autonomic behavior that has actually occurred. Future mission concepts will be increasingly dependent on space system survivability enabled by more advanced types of autonomic behaviors

Hinchey, Michael G.↗

Three Axis Control of the Hubble Space Telescope Using Two Reaction Wheels and Magnetic Torquer Bars for Science Observations

The Hubble Space Telescope (HST) is renowned for its superb pointing accuracy of less than 10 milli-arcseconds absolute pointing error. To accomplish this, the HST relies on its complement of four reaction wheel assemblies (RWAs) for attitude control and four magnetic torquer bars (MTBs) for momentum management. As with most satellites with reaction wheel control, the fourth RWA provides for fault tolerance to maintain three-axis pointing capability should a failure occur and a wheel is lost from operations. If an additional failure is encountered, the ability to maintain three-axis pointing is jeopardized. In order to prepare for this potential situation, HST Pointing Control Subsystem (PCS) Team developed a Two Reaction Wheel Science (TRS) control mode. This mode utilizes two RWAs and four magnetic torquer bars to achieve three-axis stabilization and pointing accuracy necessary for a continued science observing program. This paper presents the design of the TRS mode and operational considerations necessary to protect the spacecraft while allowing for a substantial science program.

Hur-Diaz, Sun↗

Assurance of Fault Management: Risk-Significant Adverse Condition Awareness

Fault Management (FM) systems are ranked high in risk-based assessment of criticality within flight software, emphasizing the importance of establishing highly competent domain expertise to provide assurance for NASA projects, especially as spaceflight systems continue to increase in complexity. Insight into specific characteristics of FM architectures seen embedded within safety- and mission-critical software systems analyzed by the NASA Independent Verification Validation (IVV) Program has been enhanced with an FM Technical Reference (TR) suite. Benefits are aimed beyond the IVV community to those that seek ways to efficiently and effectively provide software assurance to reduce the FM risk posture of NASA and other space missions. The identification of particular FM architectures, visibility, and associated IVV techniques provides a TR suite that enables greater assurance that critical software systems will adequately protect against faults and respond to adverse conditions. The role FM has with regard to overall asset protection of flight software systems is being addressed with the development of an adverse condition (AC) database encompassing flight software vulnerabilities.Identification of potential off-nominal conditions and analysis to determine how a system responds to these conditions are important aspects of hazard analysis and fault management. Understanding what ACs the mission may face, and ensuring they are prevented or addressed is the responsibility of the assurance team, which necessarily should have insight into ACs beyond those defined by the project itself. Research efforts sponsored by NASAs Office of Safety and Mission Assurance defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs, and allowing queries based on project, mission type, domain component, causal fault, and other key characteristics. The repository has a firm structure, initial collection of data, and an interface established for informational queries, with plans for integration within the Enterprise Architecture at NASA IVV, enabling support and accessibility across the Agency. The development of an improved workflow process for adaptive, risk-informed FM assurance is currently underway.

Software Verification & Validation↗