Search NASASearch

SEARCH · Search NASA

Results for “Safe”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Local practically safe extremum seeking with assignable rate of attractivity to the safe set

We present Assignably Safe Extremum Seeking (ASfES), an algorithm designed to minimize a measured, static objective function while maintaining a measured, static metric of safety (a control barrier function or CBF) to be positive in a practical sense. We ensure that for trajectories with safe initial conditions, the violation of safety can be made arbitrarily small through appropriately chosen design constants. We also guarantee an assignable “attractivity” rate: from unsafe initial conditions, the trajectories approach the safe set, in the sense of the measured CBF, at a rate no slower than a user-assigned rate. Similarly, from safe initial conditions, the trajectories approach the unsafe set, in the sense of the CBF, no faster than the assigned attractivity rate. The feature of assignable attractivity is not present in the semiglobal version of safe extremum seeking, where the semiglobality of convergence is achieved by slowing the adaptation. We also demonstrate local convergence of the parameter to a neighborhood of the minimum of a quadratic objective function constrained to the safe set with a linear CBF. The ASfES algorithm and analysis are multivariable, but we also extend the algorithm to a Newton-Based ASfES scheme which we show is only useful in the scalar case. The proven properties of the designs are illustrated through simulation examples.

42 ENGINEERING

Investigation of safe-life fail-safe criteria for the space shuttle

An investigation was made to determine the effects of a safe-life design approach and a fail-safe design approach on the space shuttle booster vehicle structure, and to recommend any changes to the structural design criteria. Two configurations of the booster vehicle were considered, one incorporating a delta wing (B-9U configuration) and the other a swept wing (B-16B configuration). Several major structural components of the booster were studied to determine the fatigue life, safe-life, and fail-safe capabilities of the baseline design. Each component was investigated to determine the practicability of applying a safe-life or fail-safe design philosophy, the changes such design approaches might require, and the impact of these changes on weight, cost, development plans, and performance.

Source record

End-to-End Demonstrator of the Safe Affordable Fission Engine (SAFE) 30: Power Conversion and Ion Engine Operation

The Safe Affordable Fission Engine (SAFE) test series addresses Phase 1 Space Fission Systems issues in particular non-nuclear testing and system integration issues leading to the testing and non-nuclear demonstration of a 400-kW fully integrated flight unit. The first part of the SAFE 30 test series demonstrated operation of the simulated nuclear core and heat pipe system. Experimental data acquired in a number of different test scenarios will validate existing computational models, demonstrated system flexibility (fast start-ups, multiple start-ups/shut downs), simulate predictable failure modes and operating environments. The objective of the second part is to demonstrate an integrated propulsion system consisting of a core, conversion system and a thruster where the system converts thermal heat into jet power. This end-to-end system demonstration sets a precedent for ground testing of nuclear electric propulsion systems. The paper describes the SAFE 30 end-to-end system demonstration and its subsystems.

Hrbud, Ivana

Safe Affordable Fission Engine-(SAFE-) 100a Heat Exchanger Thermal and Structural Analysis

A potential fission power system for in-space missions is a heat pipe-cooled reactor coupled to a Brayton cycle. In this system, a heat exchanger (HX) transfers the heat of the reactor core to the Brayton gas. The Safe Affordable Fission Engine- (SAFE-) 100a is a test program designed to thermally and hydraulically simulate a 95 Btu/s prototypic heat pipe-cooled reactor using electrical resistance heaters on the ground. This Technical Memorandum documents the thermal and structural assessment of the HX used in the SAFE-100a program.

Steeve, B. E.

A comparison of reliability and conventional estimation of safe fatigue life and safe inspection intervals

Both the conventional and reliability analyses for determining safe fatigue life are predicted on a population having a specified (usually log normal) distribution of life to collapse under a fatigue test load. Under a random service load spectrum, random occurrences of load larger than the fatigue test load may confront and cause collapse of structures which are weakened, though not yet to the fatigue test load. These collapses are included in reliability but excluded in conventional analysis. The theory of risk determination by each method is given, and several reasonably typical examples have been worked out, in which it transpires that if one excludes collapse through exceedance of the uncracked strength, the reliability and conventional analyses gave virtually identical probabilities of failure or survival.

Hooke, F. H.

Safe Affordable Fission Engine (SAFE 30) Module Conductivity Test Thermal Model Correlation

Two SAFE 30 modules were tested to determinate the thermal conductivity efficiency of the tri-cusps filled between the heat pipe and the heater cores. The modules consisted of four one-inch diameter tubes with heaters joined to an empty 1 inch diam. tube. The test was conducted on a vacuum chamber with 4 configurations: tri-cusps filled with and without radiation shielding and non-filled tri-cusps with and without radiation shielding. The tri-cusps material helps the bonding of the heat pipe to the four electric heater cores, filling the gap between the pipes. The baseline configuration is a brazed joint between the pipe. The test consisted of controlling the power applied to the heaters until a set surface temperature is reach. The temperatures varied between a max. of 800 C to 500 C. Test data, input energy and chamber surface temperature from each individual test, was used as boundary conditions for the model. Nodes located on the same location as the test thermocouples were plotted again test data to determinate the accuracy of the analysis. The unknown n variables on the analysis are the radiation emissivity of the pipe and chamber and the radiation view factor between the module and the chamber. A correlation was determined using a parametric analysis varying the surface emissivity and view factor until a good match was reach.

Roman, Jose

Safety Goals at NASA: How Safe is Safe Enough and How to Get There

NASA is developing and implementing safety improvements in all its activities including mission design, mission operations, and occupational safety. Decisions regarding where and how improvements are implemented to optimally enhance safety are discussed.

Stamatelatos, Michael

Lunar Reconnaissance Orbiter (LRO) Sun Safe Mode

The Lunar Reconnaissance Orbiter (LRO), a spacecraft designed and built at the National Aeronautics and Space Administration s (NASA) Goddard Space Flight Center (GSFC) in Greenbelt, MD, was launched on June 18, 2009 from Cape Canaveral. It is currently in orbit about the Moon taking detailed science measurements and providing a highly accurate mapping of the suface in preparation for the future return of astronauts to a permanent moon base. Onboard the spacecraft is a complex set of algorithms designed by the attitude control engineers at GSFC to control the pointig for all operational events, including anomalies that require the spacecraft to be put into a well known attitude configuration for a sufficiently long duration to allow for the investigation and correction of the anomaly. GSFC level requirements state that each spacecraft s control system design must include a configuration for this pointing and lso be able to maintain a thermally safe and power positive attitude. This stable control algorithm for anomalous events is commonly referred to as the safe mode and consists of control logic thatwill put the spacecraft in this safe configuration defined by the spacecraft s hardware, power and environment capabilities and limitations. The LRO Sun Safe mode consists of a coarse sun-pointing set of algorithms that puts the spacecraft into this thermally safe and power positive attitude and can be achieved wihin a required amount of time from any initial attitude, provided that the system momentum is within the momentum capability of the reaction wheels. On LRO the Sun Safe mode makes use of coarse sun sensors (CSS), an inertial reference unit (IRU) and reaction wheels (RW) to slew the spacecraft to a solar inertial pointing. The CSS and reaction wheels have some level of redundancy because of their numbers. However, the IRU is a single-point-failure piece of hardware. Without the rate information provided by the IRU, the Sun Safe control algorithms could not maintain the required pointing, so a sub-mode of the Sun Safe mode that does not use the IRU was designed. This submode, referred to as the Sun Safe Gyroless control mode, consists of an algorithm that estimates rate information from the CSS and the RW measurements. RW momentum information is used to estimate the body rate parallel to the target sunline, which CSS alone would not be able to observe. Sun Safe can be autonomously, or via ground command, entered from any other control mode and in the event the IRU is not providing rate information, the control mode is switched to the gyroless submode. This paper looks at the design of the Sun Safe modes and discusses the constraints placed on the algorithm and how the mode wored around these constraints. Items of particular interest include CSS placement on the Solar Array (SA) and its implications to design, estimation of body rate information for the Sun Safe Gyroless control mode, and the effect of solar eclipse on each of the Sun Safe modes. Placing CSS on the SA was necessary for the means to put the Sun along the targeted sun-line, nominally normal to the SA panels, for all operational considerations. This had design implications for determining a sun vector during normal SA operations, if one or both gimbals become inoperable and when the SA is in a stowed configuration. The ability of body rate estimation in Sun Safe Gyroless not only uses CSS sun vector data but requires RW momentum measuremens to estimate rates parallel to the sun-line. LRO encounters solar eclipses of some length for most of its orbits about the Moon. With the lack of CSS measurement data a design was implemented in both Sun Safe and Sun Safe Gyroless, they differ because of having or not having IRU measurement data, to carry the spacecraft through these eclipse periods. This paper also includes some discussion of sun avoidance and how it affected design decisions during nominal and eclipse perids for each of the Sun Safe modes.

Garrick, Joseph

Evolution of the Hubble Space Telescope Safing Systems

The Hubble Space Telescope (HST) was launched on April 24 1990, with an expected lifespan of 15 years. Central to the spacecraft design was the concept of a series of on-orbit shuttle servicing missions permitting astronauts to replace failed equipment, update the scientific instruments and keep the HST at the forefront of astronomical discoveries. One key to the success of the Hubble mission has been the robust Safing systems designed to monitor the performance of the observatory and to react to keep the spacecraft safe in the event of equipment anomaly. The spacecraft Safing System consists of a range of software tests in the primary flight computer that evaluate the performance of mission critical hardware, safe modes that are activated when the primary control mode is deemed inadequate for protecting the vehicle, and special actions that the computer can take to autonomously reconfigure critical hardware. The HST Safing System was structured to autonomously detect electrical power system, data management system, and pointing control system malfunctions and to configure the vehicle to ensure safe operation without ground intervention for up to 72 hours. There is also a dedicated safe mode computer that constantly monitors a keep-alive signal from the primary computer. If this signal stops, the safe mode computer shuts down the primary computer and takes over control of the vehicle, putting it into a safe, low-power configuration. The HST Safing system has continued to evolve as equipment has aged, as new hardware has been installed on the vehicle, and as the operation modes have matured during the mission. Along with the continual refinement of the limits used in the safing tests, several new tests have been added to the monitoring system, and new safe modes have been added to the flight software. This paper will focus on the evolution of the HST Safing System and Safing tests, and the importance of this evolution to prolonging the science operations of the telescope.

Pepe, Joyce

Fail-Safe Logic Design Strategies Within Modern FPGA Architectures

Fail-safe computing refers to computing systems that revert to a non-operational safe state when a fault occurs. In this paper, we investigate a circuit level technique as mitigation for single event upsets (SEUs) and fault injection attacks on field programmable gate arrays (FPGAs), and analyze the effectiveness of the technique as a fail-safe monitor for an encryption algorithm. The propagation of fault effects through FPGA primitives including lookup tables (LUTs) and programmable interconnect points (PIPs) is assessed within an FPGA architecture created using an open source tool, and validated using fault injection experiments on an FPGA. The analysis reveals additional vulnerabilities exist within reconfigurable architectures over those in equivalent fail-safe application specific integrated circuit (ASIC), thus requiring a more elaborate network of redundant circuits and checking logic. The configuration memory bits (CMBs), which configure routing and designate logic functions within the LUTs of the FPGA, add complexity to fail-safe design strategies by introducing additional fault conditions and fault propagation paths. A resource-efficient fail-safe circuit design technique called DEsign for Fail-safe in reCONfigurable systems (DEFCON) is proposed. The benefits and limitations associated with DEFCON are described in the context of fault injection experiments carried out as simulations and in FPGA hardware.

Bhakta, Priya A. [Univ. of New Mexico, Albuquerque

Curiosity's Autonomous Surface Safing Behavior Design

The safing routines on all robotic deep-space vehicles are designed to put the vehicle in a power and thermally safe configuration, enabling communication with the mission operators on Earth. Achieving this goal is made a little more difficult on Curiosity because the power requirements for the core avionics and the telecommunication equipment exceed the capability of the single power source, the Multi-Mission Radioisotope Thermoelectric Generator. This drove the system design to create an operational mode, called "sleep mode", where the vehicle turns off most of the loads in order to charge the two Li-ion batteries. The system must keep the vehicle safe from over-heat and under-heat conditions, battery cell failures, under-voltage conditions, and clock failures, both while the computer is running and while the system is sleeping. The other goal of a safing routine is to communicate. On most spacecraft, this simply involves turning on the receiver and transmitter continuously. For Curiosity, Earth is above the horizon only a part of the day for direct communication to the Earth, and the orbiter overpass opportunities only occur a few times a day. The design must robustly place the Rover in a communicable condition at the correct time. This paper discusses Curiosity's autonomous safing behavior and describes how the vehicle remains power and thermally safe while sleeping, as well as a description of how the Rover communicates with the orbiters and Earth at specific times.

MSL

A model for a space shuttle safing and failure-detection expert

The safing and failure-detection expert (SAFE) is a prototype for a malfunction detection, diagnosis, and safing system for the atmospheric revitalization subsystem (ARS) in the Space Shuttle orbiter. SAFE, whose knowledge was extracted from expert-provided heuristics and documented procedures, automatically manages all phases of failure handling: detection, diagnosis, testing procedures, and recovery instructions. The SAFE architecture allows it to handle correctly sensor failures and multiple malfunctions. Since SAFE is highly interactive, it was used as a test bed for the evaluation of various advanced human-computer interface (HCI) techniques. The use of such expert systems in the next generation of space vehicles would increase their reliability and autonomy to levels not achievable before.

Zeilingold, Daphna

Safe Grid

The biggest users of GRID technologies came from the science and technology communities. These consist of government, industry and academia (national and international). The NASA GRID is moving into a higher technology readiness level (TRL) today; and as a joint effort among these leaders within government, academia, and industry, the NASA GRID plans to extend availability to enable scientists and engineers across these geographical boundaries collaborate to solve important problems facing the world in the 21 st century. In order to enable NASA programs and missions to use IPG resources for program and mission design, the IPG capabilities needs to be accessible from inside the NASA center networks. However, because different NASA centers maintain different security domains, the GRID penetration across different firewalls is a concern for center security people. This is the reason why some IPG resources are been separated from the NASA center network. Also, because of the center network security and ITAR concerns, the NASA IPG resource owner may not have full control over who can access remotely from outside the NASA center. In order to obtain organizational approval for secured remote access, the IPG infrastructure needs to be adapted to work with the NASA business process. Improvements need to be made before the IPG can be used for NASA program and mission development. The Secured Advanced Federated Environment (SAFE) technology is designed to provide federated security across NASA center and NASA partner's security domains. Instead of one giant center firewall which can be difficult to modify for different GRID applications, the SAFE "micro security domain" provide large number of professionally managed "micro firewalls" that can allow NASA centers to accept remote IPG access without the worry of damaging other center resources. The SAFE policy-driven capability-based federated security mechanism can enable joint organizational and resource owner approved remote access from outside of NASA centers. A SAFE enabled IPG can enable IPG capabilities to be available to NASA mission design teams across different NASA center and partner company firewalls. This paper will first discuss some of the potential security issues for IPG to work across NASA center firewalls. We will then present the SAFE federated security model. Finally we will present the concept of the architecture of a SAFE enabled IPG and how it can benefit NASA mission development.

Chow, Edward T.

A Self Contained Method for Safe and Precise Lunar Landing

The return of humans to the Moon will require increased capability beyond that of the previous Apollo missions. Longer stay times and a greater flexibility with regards to landing locations are among the many improvements planned. A descent and landing system that can land the vehicle more accurately than Apollo with a greater ability to detect and avoid hazards is essential to the development of a Lunar Outpost, and also for increasing the number of potentially reachable Lunar Sortie locations. This descent and landing system should allow landings in more challenging terrain and provide more flexibility with regards to mission timing and lighting considerations, while maintaining safety as the top priority. The lunar landing system under development by the ALHAT (Autonomous precision Landing and Hazard detection Avoidance Technology) project is addressing this by providing terrain-relative navigation measurements to enhance global-scale precision, an onboard hazard-detection system to select safe landing locations, and an Autonomous GNC (Guidance, Navigation, and Control) capability to process these measurements and safely direct the vehicle to this landing location. This ALHAT landing system will enable safe and precise lunar landings without requiring lunar infrastructure in the form of navigation aids or a priori identified hazard-free landing locations. The safe landing capability provided by ALHAT uses onboard active sensing to detect hazards that are large enough to be a danger to the vehicle but too small to be detected from orbit, given currently planned orbital terrain resolution limits. Algorithms to interpret raw active sensor terrain data and generate hazard maps as well as identify safe sites and recalculate new trajectories to those sites are included as part of the ALHAT System. These improvements to descent and landing will help contribute to repeated safe and precise landings for a wide variety of terrain on the Moon.

Paschall, Stephen C., II

Managing Cassini Safe Mode Attitude at Saturn

The Cassini spacecraft was launched on October 15, 1997 and arrived at Saturn on June 30, 2004. It has performed detailed observations and remote sensing of Saturn, its rings, and its satellites since that time. In the event safe mode interrupts normal orbital operations, Cassini has flight software fault protection algorithms to detect, isolate, and recover to a thermally safe and commandable attitude and then wait for further instructions from the ground. But the Saturn environment is complex, and safety hazards change depending on where Cassini is in its orbital trajectory around Saturn. Selecting an appropriate safe mode attitude that insures safe operation in the Saturn environment, including keeping the star tracker field of view clear of bright bodies, while maintaining a quiescent, commandable attitude, is a significant challenge. This paper discusses the Cassini safe table management strategy and the key criteria that must be considered, especially during low altitude flybys of Titan, in deciding what spacecraft attitude should be used in the event of safe mode.

Attitude Control

Eye-Safe 1.5 and 2.0 Micron Laser Power Conversion Using Metamorphic InGaAs Photovoltaic Devices

Laser power transmission at 1.5 and 2.0 microns are considered eye-safe up to 0.1 W/cm2 irradiance. Further, the atmospheric bands at these two wavelengths may provide the highest optical transmission through the atmosphere in hazy conditions. By slowly changing the lattice-constant of InGaAs with a Compositionally Graded Buffer (CGB), we have fabricated InGaAs photovoltaic (PV) devices over a wide range of bandgaps useful for multijunction concentrating photovoltaic devices, thermophotovoltaic devices, and Laser Power Converters (LPC). Here, we have demonstrated monochromatic power conversion of 1.5-micron light with an eye-safe efficiency of 39.8% at 0.1 W/cm2 with InGaAs devices lattice-matched to InP with an Antireflection Coating (ARC). We have also demonstrated 30.2% and 24.5% eye-safe LPC efficiency of metamorphic InGaAs devices grown on GaAs substrates using GaInP and AlGaAsP CGBs, respectively. Finally, we have demonstrated metamorphic InGaAs devices grown on InP and GaAs substrates that are estimated to have eye-safe LPC efficiencies at 2.0 microns of 27.4% and 20.9% respectively. The efficiencies of all these LPC devices continues to increase up to about 30-70 times the eye-safe irradiance.

eye-safe

Integral Battery Power Limiting Circuit for Intrinsically Safe Applications

A circuit topology has been designed to guarantee the output of intrinsically safe power for the operation of electrical devices in a hazardous environment. This design uses a MOSFET (metal oxide semiconductor field-effect transistor) as a switch to connect and disconnect power to a load. A test current is provided through a separate path to the load for monitoring by a comparator against a preset threshold level. The circuit is configured so that the test current will detect a fault in the load and open the switch before the main current can respond. The main current passes through the switch and then an inductor. When a fault occurs in the load, the current through the inductor cannot change immediately, but the voltage drops immediately to safe levels. The comparator detects this drop and opens the switch before the current in the inductor has a chance to respond. This circuit protects both the current and voltage from exceeding safe levels. Typically, this type of protection is accomplished by a fuse or a circuit breaker, but in order for a fuse or a circuit breaker to blow or trip, the current must exceed the safe levels momentarily, which may be just enough time to ignite anything in a hazardous environment. To prevent this from happening, a fuse is typically current-limited by the addition of the resistor to keep the current within safe levels while the fuse reacts. The use of a resistor is acceptable for non-battery applications where the wasted energy and voltage drop across the resistor can be tolerated. The use of the switch and inductor minimizes the wasted energy. For example, a circuit runs from a 3.6-V battery that must be current-limited to 200 mA. If the circuit normally draws 10 mA, then an 18-ohm resistor would drop 180 mV during normal operation, while a typical switch (0.02 ohm) and inductor (0.97 ohm) would only drop 9.9 mV. From a power standpoint, the current-limiting resistor protection circuit wastes about 18 times more power than the switch and the inductor configuration. In the fault condition, both the resistor and the inductor react immediately. The resistor reacts by allowing more current to flow and dropping the voltage. Initially, the inductor reacts by dropping the voltage, and then by not allowing the current to change. When the comparator detects the drop in voltage, it opens the switch, thus preventing any further current flow. The inductor alone is not sufficient protection, because after the voltage drop has settled, the inductor would then allow the current to change, in this example, the current would be 3.7 A. In the fault condition, the resistor is flowing 200 mA until the fuse blows (anywhere from 1 ms to 100 s), while the switch and inductor combination is flowing about 2 A test current while monitoring for the fault to be corrected. Finally, as an additional safety feature, the circuit can be configured to hold the switch opened until both the load and source are disconnected.

Burns, Bradley M.