Search NASA⌕ Search

SEARCH · Search NASA

Results for “reversionary control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Reversionary Control Modes for the Mitigation of Failures in a Partially Turboelectric Aircraft Propulsion System

In support of emission and fuel burn reduction goals, the aviation industry is actively pursuing the advancement of electrified aircraft propulsion (EAP) technology. This includes turboelectric and hybrid electric propulsion designs that combine gas turbine engine and electrical system hardware. Such architectures exhibit a high degree of coupling between subsystems. This drives the need for system-level control strategies to ensure the safe, coordinated, and efficient operation of all subsystems. The design and certification of any aircraft propulsion system requires that all potential subsystem failures are identified, and the hazards posed by these failures are appropriately mitigated. This requirement is particularly challenging for EAP systems due to their integrated nature. One approach to assist in EAP failure mitigation is the inclusion of automated reconfiguration capabilities within the propulsion control system. Such control modes, referred to as reversionary control modes, are designed to automatically detect failures and activate backup control modes upon failure detection. This paper covers the design and evaluation of reversionary control mode logic developed for a partially turboelectric propulsion concept. Test results from a real-time hardware-in-the-loop evaluation of the concept are also presented and discussed. The results show that the developed reversionary control logic can successfully detect and mitigate subsystem failures in a representative environment that includes actual electrical system hardware.

Electrified Aircraft Propulsion↗

Reversionary Control Modes for the Mitigation of Failures in a Partially Turboelectric Aircraft Propulsion System

In support of emission and fuel burn reduction goals, the aviation industry is actively pursuing the advancement of electrified aircraft propulsion (EAP) technology. This includes turboelectric and hybrid electric propulsion designs that combine gas turbine engine and electrical system hardware. Such architectures exhibit a high degree of coupling between subsystems. This drives the need for system-level control strategies to ensure the safe, coordinated, and efficient operation of all subsystems. The design and certification of any aircraft propulsion system requires that all potential subsystem failures are identified, and the hazards posed by these failures are appropriately mitigated. This requirement is particularly challenging for EAP systems due to their integrated nature. One approach to assist in EAP failure mitigation is the inclusion of automated reconfiguration capabilities within the propulsion control system. Such control modes, referred to as reversionary control modes, are designed to automatically detect failures and activate backup control modes upon failure detection. This paper covers the design and evaluation of reversionary control mode logic developed for a partially turboelectric propulsion concept. Test results from a real-time hardware-in-the-loop evaluation of the concept are also presented and discussed. The results show that the developed reversionary control logic can successfully detect and mitigate subsystem failures in a representative environment that includes actual electrical system hardware.

Electrified Aircraft Propulsion↗

Reversionary Control Modes for the Mitigation of Failures in a Partially Turboelectric Aircraft Propulsion System

In support of emission and fuel burn reduction goals, the aviation industry is actively pursuing the advancement of electrified aircraft propulsion (EAP) technology. This includes turboelectric and hybrid electric propulsion designs that combine gas turbine engine and electrical system hardware. Such architectures exhibit a high degree of coupling between subsystems. This drives the need for system-level control strategies to ensure the safe, coordinated, and efficient operation of all subsystems. The design and certification of any aircraft propulsion system requires that all potential subsystem failures are identified, and the hazards posed by these failures are appropriately mitigated. This requirement is particularly challenging for EAP systems due to their integrated nature. One approach to assist in EAP failure mitigation is the inclusion of automated reconfiguration capabilities within the propulsion control system. Such control modes, referred to as reversionary control modes, are designed to automatically detect failures and activate backup control modes upon failure detection. This paper covers the design and evaluation of reversionary control mode logic developed for a partially turboelectric propulsion concept. Test results from a real-time hardware-in-the-loop evaluation of the concept are also presented and discussed. The results show that the developed reversionary control logic can successfully detect and mitigate subsystem failures in a representative environment that includes actual electrical system hardware.

Electrified Aircraft Propulsion↗

Electrified Aircraft Propulsion Systems: Gas Turbine Control Considerations for the Mitigation of Potential Failure Modes and Hazards

This paper provides a high-level review of the potential failure modes and hazards to which electrified aircraft propulsion (EAP) systems are susceptible, along with potential gas turbine control-based strategies to assist in the mitigation of those failures. To introduce the types of failures that an EAP system may experience, a generic EAP system is considered, consisting of gas turbine engines, mechanical drives, electric machines, power electronics and distribution systems, energy storage devices, and motor driven propulsors. The functionality provided by each of these EAP subsystems is discussed, along with their potential failure modes, and possible strategies for mitigating those failures. To further illustrate the role of gas turbine controls in mitigating EAP failure modes, an example based on a simulated EAP concept aircraft proposed by NASA is given. The effects of failures are discussed, along with turbomachinery control strategies, including reversionary control modes, and control limit logic.

Donald L Simon↗

Electrified Aircraft Propulsion Systems: Gas Turbine Control Considerations for the Mitigation of Potential Failure Modes and Hazards

This presentation provides a high-level review of the potential failure modes and hazards to which electrified aircraft propulsion (EAP) systems are susceptible, along with potential gas turbine control-based strategies to assist in the mitigation of those failures. To further illustrate the role of gas turbine controls in mitigating EAP failure modes, an example based on a simulated EAP concept aircraft proposed by NASA is given. The effects of failures are discussed, along with turbomachinery control strategies, including reversionary control modes, and control limit logic.

Electrified Aircraft Propulsion↗

Electrified Aircraft Propulsion Systems: Gas Turbine Control Considerations for the Mitigation of Potential Failure Modes and Hazards

This paper provides a high-level review of the potential failure modes and hazards to which electrified aircraft propulsion (EAP) systems are susceptible along with potential gas turbine control-based strategies to assist in the mitigation of those failures. To introduce the types of failures that an EAP system may experience, a generic EAP system is considered consisting of gas turbine engines, mechanical drives, electric machines, power electronics and distribution systems, energy storage devices, and motor driven propulsors. The functionality provided by each of these EAP subsystems is discussed along with their potential failure modes and possible strategies for mitigating those failures. To further illustrate the role of gas turbine controls in mitigating EAP failure modes, an example based on a simulated EAP concept aircraft proposed by NASA is given. The effects of failures are discussed, along with turbomachinery control strategies, including reversionary control modes, and control limit logic

Electrified Aircraft Propulsion↗

Failure Behavior and Control-Based Mitigation for a Parallel Hybrid Propulsion System

NASA is pursuing research to advance Electrified Aircraft Propulsion (EAP) technologies that address fuel burn and emission reduction goals. EAP brings the potential for improved performance over the state of the art. However, for these systems to be practical and certifiable, they need to possess adequate robustness to adverse conditions including a variety of system failures that are not applicable to conventional turbofans today. Numerous EAP concepts interface gas turbine engines with an electrical power system that includes electric machines and sometimes electrical energy storage. The expansion of the powertrain increases the probability of encountering a failure and introduces new failure modes. Failures within the electrical power system may also impact the gas turbine engine(s) to which the electrical powertrain is coupled. This effort investigates failures originating in the electrical power system and their impact on the parallel hybrid propulsion system. Reversionary control strategies are also demonstrated to reduce the impact of the failures. Failure mitigation strategies were devised and employed in simulation. Various failure scenarios were simulated including those occurring during steady state operation, transients, and takeoff and landing scenarios. The timing of the failure and delay in failure identification and activation of mitigation strategies are noteworthy variables in the study. While the system remained stable throughout all failure scenarios, delays in failure identification could result in undesirable conditions such as increased operating temperatures and reduced stall margin. The results demonstrate successful mitigation of failures through reversionary control modes and help to generate confidence in the robustness of the conceptual parallel hybrid propulsion system.

Failure behavior↗

Failure Behavior and Control Based Mitigation for a Parallel Hybrid Propulsion System

NASA is pursuing research to advance Electrified Aircraft Propulsion (EAP) technologies that address fuel burn and emission reduction goals. EAP brings the potential for improved performance over the state of the art. However, for these systems to be practical and certifiable, they need to possess adequate robustness to adverse conditions including a variety of system failures that are not applicable to conventional turbofans today. Numerous EAP concepts interface gas turbine engines with an electrical power system that includes electric machines and sometimes electrical energy storage. The expansion of the powertrain increases the probability of encountering a failure and introduces new failure modes. Failures within the electrical power system may also impact the gas turbine engine(s) to which the electrical powertrain is coupled. This effort investigates failures originating in the electrical power system and their impact on the parallel hybrid propulsion system. Reversionary control strategies are also demonstrated to reduce the impact of the failures. Failure mitigation strategies were devised and employed in simulation. Various failure scenarios were simulated including those occurring during steady state operation, transients, and takeoff and landing scenarios. The timing of the failure and delay in failure identification and activation of mitigation strategies are noteworthy variables in the study. While the system remained stable throughout all failure scenarios, delays in failure identification could result in undesirable conditions such as increased operating temperatures and reduced stall margin. The results demonstrate successful mitigation of failures through reversionary control modes and help to generate confidence in the robustness of the conceptual parallel hybrid propulsion system.

Failure behavior↗

A Verification Framework for Runtime Assurance of Autonomous UAS

Runtime Assurance (RTA) is a design-time architecture for safety-critical systems where an internal monitor acts upon detecting a violation of a property. The simplex architecture is an instance of RTA, where the action taken is to hand control of the overall system to a trusted controller when an untrusted one violates a safety property. Simplex RTA is emerging as a method for allowing AI/ML and other unverified software to be integrated into safety-critical applications like aircraft. To this end, the American Society for Testing and Materials (ASTM) and NASA have each published guidelines on the use of RTA in such systems. In the simplex RTA framework, a system has an advanced controller (AC) and a reversionary controller (RC). The system is allowed to operate with the AC until a runtime monitor detects that some property has been violated and then the RC takes over. Assuming that the sample rate of the monitor will detect improper functioning with enough time for the RC to correct the impending problem, and that the RC is trusted, the system will operate as intended. This use of the simplex RTA framework can allow for the integration of untrusted, but possibly more performant, controllers in a safe way. This paper presents a formalization of a simplex RTA framework in the Prototype Verification System (PVS) theorem prover using an embedding of differential dynamic logic (DDL) called Plaidypvs. A novel feature of this framework is that it can be instantiated at different levels of abstraction. This feature allows for the formal verification of a system with an untrusted black box component, such as an AI/ML controller. This paper does not address the many difficulties in deploying RTA in an industrial-level system. Instead, the focus is on the formal verification of the simplex RTA framework in the language of hybrid programs. Hybrid programs are programs that include both discrete and continuous dynamics and can be used to model complex cyber-physical systems. Plaidypvs is a tool that enables formalization of hybrid programs in the PVS theorem prover. Plaidypvs enables the verification of the general simplex RTA framework and then, by specializing some components of the hybrid program, verifying instances of the framework while treating the untrusted component as a black box. A selection of Unmanned Aircraft Systems (UAS) operations are shown as instances of the general RTA framework in PVS. This offers the benefit of design time verification of relevant safety properties to the system, and it also gives requirements on the sample rate of sensors that determine the time interval in which the ‘switch’ property of the RTA framework is checked.

PVS↗

Flight Simulator Demonstration and Certification Implications of Powertrain Failure Mitigation in a Partial Turboelectric Aircraft

The Single-aisle Turboelectric AiRCraft with Aft Boundary Layer propulsor (STARC ABL) is a concept aircraft with a partial turboelectric powertrain. The complexity and integrated nature of the partial turboelectric powertrain architecture presents failure modes and hazards not found in conventional aircraft propulsion designs. Previously, various electrical and mechanical faults and associated recovery modes were demonstrated in a dynamic model of the powertrain. It was shown that certain faults were catastrophic without recovery logic, due specifically to the interaction of the subsystems. However, in each case, the logic, known as a reversionary control mode, enabled continued operation with assumed sufficient thrust to maintain safe flight. The current work evaluates the powertrain faults and recovery strategies using a full aircraft model in a piloted flight simulator, and places it in the context of current regulatory practice. Faults initiated in flight were successfully mitigated, with the accommodated aircraft subsequently evaluated against certification requirements for three-engine aircraft, which were shown to be appropriate for the STARC-ABL configuration.

STARC-ABL↗

Flight Simulator Demonstration and Certification Implications of Powertrain Failure Mitigation in a Partial Turboelectric Aircraft

The Single-aisle Turboelectric AiRCraft with Aft Boundary Layer propulsor (STARC ABL) is a concept aircraft with a partial turboelectric powertrain. The complexity and integrated nature of the partial turboelectric powertrain architecture presents failure modes and hazards not found in conventional aircraft propulsion designs. Previously, various electrical and mechanical faults and associated recovery modes were demonstrated in a dynamic model of the powertrain. It was shown that certain faults were catastrophic without recovery logic, due specifically to the interaction of the subsystems. However, in each case, the logic, known as a reversionary control mode, enabled continued operation with assumed sufficient thrust to maintain safe flight. The current work evaluates the powertrain faults and recovery strategies using a full aircraft model in a piloted flight simulator, and places it in the context of current regulatory practice. Faults initiated in flight were successfully mitigated, with the accommodated aircraft subsequently evaluated against certification requirements for three-engine aircraft, which were shown to be appropriate for the STARC-ABL configuration.

STARC-ABL↗

Flight Simulator Demonstration and Certification Implications of Powertrain Failure Mitigation in a Partial Turboelectric Aircraft

The Single-aisle Turboelectric AiRCraft with Aft Boundary Layer propulsor (STARC ABL) is a concept aircraft with a partial turboelectric powertrain. The complexity and integrated nature of the partial turboelectric powertrain architecture presents failure modes and hazards not found in conventional aircraft propulsion designs. Previously, various electrical and mechanical faults and associated recovery modes were demonstrated in a dynamic model of the powertrain. It was shown that certain faults were catastrophic without recovery logic, due specifically to the interaction of the subsystems. However, in each case, the logic, known as a reversionary control mode, enabled continued operation with assumed sufficient thrust to maintain safe flight. The current work evaluates the powertrain faults and recovery strategies using a full aircraft model in a piloted flight simulator, and places it in the context of current regulatory practice. Faults initiated in flight were successfully mitigated, with the accommodated aircraft subsequently evaluated against certification requirements for three-engine aircraft, which were shown to be appropriate for the STARC-ABL configuration.

certification↗

Runtime Assurance Protection for Advanced Turbofan Engine Control

This paper describes technical progress made in the application of run time assurance (RTA) methods to turbofan engines with advanced propulsion control algorithms that are employed to improve engine performance. It is assumed that the advanced algorithms cannot be fully certified using current verification and validation approaches and therefore need to be continually monitored by an RTA system that ensures safe operation. However, current turbofan engine control systems utilize engine protection logic for safe combustion dynamics and stable airflow through the engine. It was determined that the engine protection logic should continue to be used to provide system safety and should be considered as a part of the overall RTA system. The additional function that an RTA system provides is to perform diagnostics on anomalous conditions to determine if these conditions are being caused by errors in the advanced controller. If this is the case, the RTA system switches operation to a trusted reversionary controller. Initial studies were performed to demonstrate this benefit. The other focus was to improve the performance of the engine protection logic, which was deemed too conservative and reduced engine performance during transient operations. It was determined that the conservative response was due to poor tuning of one of the controller channels within the protection logic. An automatic tuning algorithm was implemented to optimize the protection logic control gains based on minimizing tracking error. Improved tracking responses were observed with no change to the existing protection logic control architecture.

runtime monitoring↗

Exploration of the Versatile Electrically Augmented Turbine Engine Gearbox Concept

Integration of electric machines with the shafts of gas turbine engines is implied in various electrified aircraft propulsion concepts. This includes implementation of the Turbine Electrified Energy Management (TEEM) concept, a motivator for the Versatile Electrically Augmented Turbine Engine (VEATE) gearbox. The VEATE gearbox is a mechanical power transmission concept that seeks to interface electric machines with a gas turbine engine in a synergistic manner. It enables a hybrid electro-mechanical approach for managing power in a gas turbine engine. It is hypothesized that the mechanical design of the VEATE gearbox could be leveraged to enhance the versatility of the present electrical hardware. The VEATE gearbox concept is first introduced and applied to an electrified two-spool advanced geared turbofan meant for powering a single-aisle commercial aircraft. A modeling approach for the gearbox is presented and studies are conducted to investigate the potential application to TEEM and power extraction. There is evidence that the VEATE gearbox could help to reduce the size of the TEEM power system, provide flexibility in power extraction implementation, and exhibit fail-safe design attributes.

Electrified Aircraft Propulsion↗

Exploration of the Versatile Electrically Augmented Turbine Engine Gearbox Concept

Integration of electric machines with the shafts of gas turbine engines is implied in various electrified aircraft propulsion concepts. This includes implementation of the Turbine Electrified Energy Management (TEEM) concept, a motivator for the Versatile Electrically Augmented Turbine Engine (VEATE) gearbox. The VEATE gearbox is a mechanical power transmission concept that seeks to interface electric machines with a gas turbine engine in a synergistic manner. It enables a hybrid electro-mechanical approach for managing power in a gas turbine engine. It is hypothesized that the mechanical design of the VEATE gearbox could be leveraged to enhance the versatility of the present electrical hardware. The VEATE gearbox concept is first introduced and applied to an electrified two-spool advanced geared turbofan meant for powering a single-aisle commercial aircraft. A modeling approach for the gearbox is presented and studies are conducted to investigate the potential application to TEEM and power extraction. There is evidence that the VEATE gearbox could help to reduce the size of the TEEM power system, provide flexibility in power extraction implementation, and exhibit fail-safe design attributes.

Versatile Electrically Augmented Turbine Engine Ge↗

Capability Description for NASA's F/A-18 TN 853 as a Testbed for the Integrated Resilient Aircraft Control Project

The NASA F/A-18 tail number (TN) 853 full-scale Integrated Resilient Aircraft Control (IRAC) testbed has been designed with a full array of capabilities in support of the Aviation Safety Program. Highlights of the system's capabilities include: 1) a quad-redundant research flight control system for safely interfacing controls experiments to the aircraft's control surfaces; 2) a dual-redundant airborne research test system for hosting multi-disciplinary state-of-the-art adaptive control experiments; 3) a robust reversionary configuration for recovery from unusual attitudes and configurations; 4) significant research instrumentation, particularly in the area of static loads; 5) extensive facilities for experiment simulation, data logging, real-time monitoring and post-flight analysis capabilities; and 6) significant growth capability in terms of interfaces and processing power.

Hanson, Curt↗

AirSTAR Hardware and Software Design for Beyond Visual Range Flight Research

The National Aeronautics and Space Administration (NASA) Airborne Subscale Transport Aircraft Research (AirSTAR) Unmanned Aerial System (UAS) is a facility developed to study the flight dynamics of vehicles in emergency conditions, in support of aviation safety research. The system was upgraded to have its operational range significantly expanded, going beyond the line of sight of a ground-based pilot. A redesign of the airborne flight hardware was undertaken, as well as significant changes to the software base, in order to provide appropriate autonomous behavior in response to a number of potential failures and hazards. Ground hardware and system monitors were also upgraded to include redundant communication links, including ADS-B based position displays and an independent flight termination system. The design included both custom and commercially available avionics, combined to allow flexibility in flight experiment design while still benefiting from tested configurations in reversionary flight modes. A similar hierarchy was employed in the software architecture, to allow research codes to be tested, with a fallback to more thoroughly validated flight controls. As a remotely piloted facility, ground systems were also developed to ensure the flight modes and system state were communicated to ground operations personnel in real-time. Presented in this paper is a general overview of the concept of operations for beyond visual range flight, and a detailed review of the airborne hardware and software design. This discussion is held in the context of the safety and procedural requirements that drove many of the design decisions for the AirSTAR UAS Beyond Visual Range capability.

Laughter, Sean↗