Search NASASearch

SEARCH · Search NASA

Results for “fault protection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Toward a Model-Based Approach to Flight System Fault Protection

Fault Protection (FP) is a distinct and separate systems engineering sub-discipline that is concerned with the off-nominal behavior of a system. Flight system fault protection is an important part of the overall flight system systems engineering effort, with its own products and processes. As with other aspects of systems engineering, the FP domain is highly amenable to expression and management in models. However, while there are standards and guidelines for performing FP related analyses, there are not standards or guidelines for formally relating the FP analyses to each other or to the system hardware and software design. As a result, the material generated for these analyses are effectively creating separate models that are only loosely-related to the system being designed. Development of approaches that enable modeling of FP concerns in the same model as the system hardware and software design enables establishment of formal relationships that has great potential for improving the efficiency, correctness, and verification of the implementation of flight system FP. This paper begins with an overview of the FP domain, and then continues with a presentation of a SysML/UML model of the FP domain and the particular analyses that it contains, by way of showing a potential model-based approach to flight system fault protection, and an exposition of the use of the FP models in FSW engineering. The analyses are small examples, inspired by current real-project examples of FP analyses.

Day, John

Subsystem testing of Galileo's attitude and articulation control fault protection

This paper discusses the fault protection tesing of the Attitude and Articulation Control Subsystem (AACS) of the Galileo spacecraft. The need for an autonomous fault protection system on an interplanetary spacecraft is discussed. Galileo requirements for the detection and response of specific hardware failures is discussed along with the fault protection software design and implementation. The test beds and test methods used for fault protection testing are described. The paper concludes with a presentation of the results of this testing with an emphasis on requirement and design changes that were made as a result of these tests.

Anderson, L. L.

The Soil Moisture Acttive Passive Mission: Fault Protection Performance and Lessons Learned

Fault protection as a discipline involves a collection of flight software logic and operational processes for detecting unacceptable anomalous behavior, responding prior to reaching criticality, restricting the propagation of a failure beyond a fault containment region, and recovering the vehicle back to full or degraded functionality if possible. The System Fault Protection (SFP) design for the SMAP Earth orbiter was put to the test during its 90-day vehicle commissioning activities. During this time, the SFP software autonomously protected the vehicle from multiple faults to critical hardware, and the operations team successfully returned the observatory to its science state. The SFP also performed well in the presence of anomalous behavior below true safety limits by not taking unnecessary response actions, instead allowing the operations team time to monitor the behavior. Certain aspects of the SFP design were modified during operations via both parameter updates and a full flight software update in order to better match the vehicle behavior in the flight environment. An evaluation of the SMAP SFP performance during vehicle Commissioning will be provided in this paper, as well as a set of lessons learned largely focused on visibility, SFP mutability in operations, responses to peripheral device faults, and Safe Mode recovery and design. By capturing some of the knowledge gained during SMAP Commissioning, it is intended that this paper provide guidance for making future System Fault Protection designs more robust and supportive of operations.

Clark, Jessica

Photovoltaic system grounding and fault protection

The grounding and fault protection aspects of large photovoltaic power systems are studied. Broadly, the overlapping functions of these two plant subsystems include providing for the safety of personnel and equipment. Grounding subsystem design is generaly governed by considerations of personnel safety and the limiting of hazardous voltages to which they are exposed during the occurrence of a fault or other misoperation of equipment. A ground system is designed to provide a safe path for fault currents. Metal portions of the modules, array structures, and array foundations are used as a part of the ground system, provided that they and their interconnection are designed to be suitably reliable over the life of the plant. Several alternative types of fault protection and detection equipment are designed into the source circuits and dc buses feeding the input terminals of the subfield power conditioner. This design process requires evaluation of plausible faults, equipment, and remedial actions planned to correct faults. The evaluation should also consider life cycle cost impacts.

Stolte, W. J.

GN&C fault protection

Addressing fault tolerance for spacecraft Guidance, Navigation, and Control has never been easy. Even under normal conditions, these systems confront a remarkable blend of complex issues across many disciplines, with primary implications for most essential system functions. Moreover, GN&C must deal with the peculiarities of spacecraft configurations, disturbances, environment, and other physical mission-unique constraints that are seldom under its full control, all while promising consistently high performance.

Rasmussen, Robert D.

System Fault Protection Design for the Cassini Spacecraft

Fault protection can include a wide range of topics, ranging from fault prevention to autonomous fault detection and recovery. This paper will address a portion of the autonomous fault detection and recovery implemented onboard the Cassini spacecraft. Specifically, the topic is system fault protection design, as opposed to subsystem fault protection design.

Cassini

A Model-Based Architecture for a Small Flexible Fault Protection System

In this paper we will give a brief overview of how different missions implemented the fault protection application and the improvements along the way. We will then propose an architecture that supports the direct implementation of state-chart models into flight code. These state-chart models can be used to formally and naturally specify the behavior of all the major fault protection components - monitors, fault protection engine, and fault responses. The goal is a flexible, light-weight implementation of a traditional fault protection software system that is inexpensive to implement, reliable and understandable for both system and software developers.

Watney, Garth

MER surface fault protection system

The Mars Exploration Rovers surface fault protection design was influenced by the fact that the solar-powered rovers must recharge their batteries during the day to survive the night. the rovers needed to autonomously maintain thermal stability, initiate safe and reliable communication with orbiting assets or directly to Earth, while maintaining energy balance. This paper will describe the system fault protection design for the surface phase of the mission.

system fault protection

Attitude control fault protection - The Voyager experience

The length of the Voyager mission and the communication delay caused by the distances involved made fault protection a necessary part of the Voyager Attitude and Articulation Control Subsystem (AACS) design. An overview of the Voyager attitude control fault protection is given and flight experiences relating to fault protection are provided.

Litty, E. C.

ASTERIA Operations Demonstrates the Value of Combining the Mission Assurance and Fault Protection Roles on CubeSats

On November 20, 2017, ASTERIA (Arcsecond Space Telescope Enabling Research in Astrophysics), a 6U CubeSat performing a technology demonstration of astrophysical measurements, deployed from the ISS. The technology demonstration goals to achieve precision photometry via arcsecond-level line-of-sight pointing error and highly stable focal plane temperature control were met by February 2018. Extended mission operations are ongoing, with the primary focus on observing nearby stars for transiting exoplanets. Throughout development and operations, the roles of mission assurance and fault protection have proven critical to achieving the primary technical goals and to maintaining a healthy spacecraft through multiple extended missions. Given the budget and schedule constraints typical of a CubeSat, innovative tailoring of processes has been critical to success throughout both development and operations of ASTERIA. Mission assurance plays an important role in identifying and evaluating risk and developing cost-effective mitigations. Flexibility in the fault protection design offers a variety of options for implementing risk mitigations as risks have been uncovered both in pre-delivery testing and in mission operations. This paper will discuss the approach taken on ASTERIA to implement mission assurance and fault protection and the resulting benefits to operational efficiency and success. It will briefly address the advantages of this approach during development, in which the combination of the roles provided mission assurance significant insight to system risks, which feeds back into testing methodologies and directly into fault protection design. Operations will be discussed in detail. During this phase, the roles merge to identify in-flight fault protection updates to efficiently respond to anomalies and improve the likelihood of successful technology demonstrations. The paper will also detail the tools that are used to analyse data, identify anomalies, and develop the updates to uplink to the spacecraft. Finally, the general operational approach will be discussed to highlight the usefulness of the ASTERIA processes and their applicability to future CubeSat missions.

Knapp, Mary

MER Surface Phase; Blurring the Line Between Fault Protection and What is Supposed to Happen

An assessment on the limitations of communication with MER rovers and how such constraints drove the system design, flight software and fault protection architecture, blurring the line between traditional fault protection and expected nominal behavior, and requiring the most novel autonomous and semi-autonomous elements of the vehicle software including communication, surface mobility, attitude knowledge acquisition, fault protection, and the activity arbitration service.

surface operations

Fault protection design for unmanned interplanetary spacecraft

The difficulties encountered in designing a redundancy management system are discussed and strategies for minimizing the cost and schedule impacts associated with fault protection are provided. Specific examples from the Magellan project are used with emphasis placed on control system fault protection. The major problem areas are the following: (1) the interaction between two semiindependent fault protection systems, (2) the response to faults which are detected by monitoring variables with long time constants, and (3) the design of the 'action scheduler'.

Johnson, Stephen B.

Fault protection techniques in JPL Spacecraft

While every JPL spacecraft requires some unique mission specific fault protection, there are many requirements which are common to all spacecraft configurations. These consist of protecting command and data processing & attitude control computers, protection against communication loss with the spacecraft, ensuring that safe external and internal temperature levels are maintained, and recovery from power overloads. Additionally, most JPL spacecraft are equipped with a general-purpose 'Safe Mode' response algorithm which configures the spacecraft to a lower power state which is safe and predictable so that diagnosis of more complex faults can be addressed by the Operations Team. This paper details the generic application of fault protection techniques which are implemented into most JPL spacecraft designs.

fault protection

JPL Fault Protection Software Experiences

This objectives of this slide presentation are to: (1) Share JPL experiences by describing the evolution of fault protection during its history in deep space exploration, (2) Examine issues of fault protection scope and implementation that affect missions today, and (3) Discuss solutions for the problems of today and tomorrow.

Flight Software(FSW)complexity

Validation of the Mars 2020 Fault Protection Design: Navigating the Infinity of the Off-Nominal

On July 30th 2020, the Mars 2020 mission successfully launched out of Cape Canaveral, Florida, passed through the Earth’s shadow, and began its short cruise to Mars. Less than seven months later, the Perseverance rover touched down safely in Jezero Crater to begin its ambitious mission that includes looking for signs of ancient life and collecting samples for future return to Earth. Getting to the successful landing, or “Tango Delta Nominal,” could not have been achieved without also considering the off-nominal. One of the teams supporting this ambitious mission is the fault protection (FP) team. This team is tasked with assessing the various failures, or faults, that could prevent mission success and with ensuring that the autonomous behaviors built into the software and hardware can detect faults and recover the vehicle to a safe state. As part of its charter, the FP team designed a test campaign to provide confidence in the system’s robustness to off-nominal scenarios across all of Mars 2020’s mission phases. The greatest challenge associated with designing such a validation campaign was reducing the infinite number of anomalous scenarios into a finite test suite. In addition, the tests needed to be executed efficiently in order to utilize the team’s limited test venue access, but still needed to maintain a level of rigor that guaranteed confidence in the test outcomes. Given that each test scenario generated massive amounts of data, the team also developed methods for quickly ascertaining whether the autonomous fault protection behaviors maintained vehicle safety in the presence of an anomaly. This paper summarizes the processes that the Mars 2020 fault protection team employed to execute its off-nominal validation campaign. It captures both the methods of generating a suite of off-nominal tests, as well as reducing it to a subset that can be realistically executed within schedule and resource constraints. It also describes the various processes and philosophies that the team utilized to execute the tests efficiently, including creating a standardized procedure template, keeping the test cases modular so that they could be easily interchanged, and capturing common fault injections in a change-controlled database. Finally, it will describe the tools and processes for assessing the test data, focusing in particular on a tool that evaluated vehicle state using “secondary” sources of data to validate that the software had truly configured the spacecraft to the expected safe state.

Morantz, Chaz

The Curiosity Mars Rover's Fault Protection Engine

The Curiosity Rover, currently operating on Mars, contains flight software onboard to autonomously handle aspects of system fault protection. Over 1000 monitors and 39 responses are present in the flight software. Orchestrating these behaviors is the flight software's fault protection engine. In this paper, we discuss the engine's design, responsibilities, and present some lessons learned for future missions.

flight software

JPL Fault Protection Experiences - Case Studies

This slide presentation shows several case studies for fault protection. The cases involve a discovery-class mission to excavate material from a comet, rendezvous with two asteroids and develop a prototype system for a next-generation Deep Space Network consisting of ndca large array of small antennas.

fault protection