Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “multiple building systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

An Accelerated Development, Reduced Cost Approach to Lunar/Mars Exploration Using a Modular NTR-Based Space Transportation System

The results of integrated systems and mission studies are presented which quantify the benefits and rationale for developing a common, modular lunar/Mars space transportation system (STS) based on nuclear thermal rocket (NTR) technology. At present NASA's Exploration Program Office (ExPO) is considering chemical propulsion for an 'early return to the Moon' and NTR propulsion for the more demanding Mars missions to follow. The time and cost to develop these multiple systems are expected to be significant. The Nuclear Propulsion Office (NPO) has examined a variety of lunar and Mars missions and heavy lift launch vehicle (HLLV) options in an effort to determine a 'standardized' set of engine and stage components capable of satisfying a wide range of Space Exploration Initiative (SEI) missions. By using these components in a 'building block' fashion, a variety of single and multi-engine lunar and Mars vehicles can be configured. For NASA's 'First Lunar Outpost' (FLO) mission, an expendable NTR stage powered by two 50 klbf engines can deliver approximately 96 metric tons (t) to translunar injection (TLI) conditions for an initial mass in low earth orbit (IMLEO) of approximately 198 t compared to 250 t for a cryogenic chemical TLI stage. The NTR stage liquid hydrogen (LH2) tank has a 10 m diameter, 14.5 m length, and 66 t LH2 capacity. The NTR utilizes a UC-ZrC-graphite 'composite' fuel with a specific impulse (Isp) capability of approximately 900 s and an engine thrust-to-weight ratio of approximately 4.3. By extending the size and LH2 capacity of the lunar NTR stage to approximately 20 m and 96 t, respectively, a single launch Mars cargo vehicle capable of delivering approximately 50 t of surface payload is possible. Three 50 klbf NTR engines and the two standardized LH2 tank sizes developed for lunar and Mars cargo vehicle applications would be used to configure the Mars piloted vehicle for a mission as early as 2010. The paper describes the features of the 'common' NTR-based moon/Mars STS, examines performance sensitivities resulting from different 'mission mode' assumptions, and quantifies potential schedule and cost benefits resulting from this modular moon/Mars NTR vehicle approach.

Borowski, S.↗

Climate Scenarios for the NASA / USAID SERVIR Project: Challenges for Multiple Planning Horizons

SERVIR, an acronym meaning "to serve" in Spanish, is a joint venture between NASA and the U.S. Agency for International Development (USAID) which provides satellite-based Earth observation data, modeling, and science applications to help developing nations in Central America, East Africa and the Himalayas improve environmental decision making. Anticipating climate variability / climate change impacts has now become an important component of the SERVIR efforts to build capacity in these regions. Uncertainty in hydrometeorological components of climate variations and exposure to extreme events across scales from weather to climate are of particular concern. We report here on work to construct scenarios or outlooks that are being developed as input drivers for decision support systems (DSSs) in a variety of settings. These DSSs are being developed jointly by a broad array NASA Applied Science Team (AST) Investigations and user communities in the three SERVIR Hub Regions, Central America, East Africa and the Himalayas. Issues span hydrologic / water resources modeling, agricultural productivity, and forest carbon reserves. The scenarios needed for these efforts encompass seasonal forecasts, interannual outlooks, and likely decadal / multi-decadal trends. Providing these scenarios across the different AST efforts enables some level of integration in considering regional responses to climate events. We will discuss a number of challenges in developing this continuum of scenarios including the identification and "mining" of predictability, addressing multiple continental regions, issues of downscaling global model integrations to regional / local applications (i.e. hydrologic and crop modeling). We compare / contrast the role of the U.S. National Multi- Model Experiment initiative in seasonal forecasts and the CMIP-5 climate model experiments in supporting these efforts. Examples of these scenarios, their use, and an assessment of their utility as well as limitations will be presented.

Robertson, Franklin R.↗

Molnets: An Artificial Chemistry Based on Neural Networks

The fundamental problem in the evolution of matter is to understand how structure-function relationships are formed and increase in complexity from the molecular level all the way to a genetic system. We have created a system where structure-function relationships arise naturally and without the need of ad hoc function assignments to given structures. The idea was inspired by neural networks, where the structure of the net embodies specific computational properties. In this system networks interact with other networks to create connections between the inputs of one net and the outputs of another. The newly created net then recomputes its own synaptic weights, based on anti-hebbian rules. As a result some connections may be cut, and multiple nets can emerge as products of a 'reaction'. The idea is to study emergent reaction behaviors, based on simple rules that constitute a pseudophysics of the system. These simple rules are parameterized to produce behaviors that emulate chemical reactions. We find that these simple rules show a gradual increase in the size and complexity of molecules. We have been building a virtual artificial chemistry laboratory for discovering interesting reactions and for testing further ideas on the evolution of primitive molecules. Some of these ideas include the potential effect of membranes and selective diffusion according to molecular size.

Colombano, Silvano↗

Exploration Systems Development (ESD) Approach to Enterprise Risk Management

The National Aeronautics and Space Administration (NASA) Exploration Systems Development (ESD) Division has implemented an innovative approach to Enterprise Risk Management under a unique governance structure and streamlined integration model. ESD's mission is to design and build the capability to extend human existence to deep space. The Enterprise consists of three Programs: Space Launch System (SLS), Orion, and Ground Systems Development and Operations (GSDO). The SLS is a rocket and launch system that will be capable of powering humans, habitats, and support systems to deep space. Orion will be the first spacecraft in history capable of taking humans to multiple destinations within deep space. GSDO is modernizing Kennedy's spaceport to launch spacecraft built and designed by both NASA and private industry. ESD's approach to Enterprise Risk Management is commensurate with affordability and a streamlined management philosophy. ESD Enterprise Risk Management leverages off of the primary mechanisms for integration within the Enterprise. The Enterprise integration approach emphasizes delegation of authority to manage and execute the majority of cross-program activities and products to the individual Programs, while maintaining the overall responsibility for all cross-program activities at the Division. The intent of the ESD Enterprise Risk Management approach is to improve risk communication, to avoid replication and/or contradictory strategies, and to minimize overhead process burden. This is accomplished by the facilitation and integration of risk information within ESD. The ESD Division risks, Orion risks, SLS risks, and GSDO risks are owned and managed by the applicable Program. When the Programs have shared risks with multiple consequences, they are jointly owned and managed. When a risk is associated with the integrated system that involves more than one Program in condition, consequence, or mitigation plan, it is considered an Exploration Systems Integration (ESI) Risk. An ESI risk may require visibility and risk handling by multiple organizations. The Integrated Risk Working Group (IRWG) is a small team of Risk experts that are responsible for collaborating and communicating best practices. In addition, the forum facilitates proper integration of risks across the Enterprise. The IRWG uses a Continuous Risk Management approach for facilitating the identification, analysis, planning, tracking, and controlling of ESI Risks. The ESD Division, Programs, and Integrated Task Teams identify ESI Risks. The IRWG maintains a set of metrics for understanding Enterprise Risk process and the overall Risk Posture. The team is also actively involved in the modeling of risk for Enterprise Performance Management. With the Enterprise being constrained in Schedule and Budget, and with significant technical complexity, the appropriate use of Risk Management techniques is crucial to the success of the Enterprise. The IRWG achieves this through the modified approach, providing a forum for collaboration on risks that cross boundaries between the separate entities.

Bauder, Stephen P.↗

Design and Development of a Sub-Zero Fluid System for Demonstration of Orion's Phase Change Material Heat Exchangers on ISS

NASA's Orion Multipurpose Crew Vehicle's Exploration Mission 2 is expected to loiter in Lunar orbit for a relatively long period of time. In low Lunar orbit (LLO) the thermal environment is cyclic - extremely cold in the eclipse and relatively hot near the subsolar point. Phase change material heat exchangers (PCM HXs) are the best option for long term missions in these environments. A PCM HX allows a vehicle to store excess waste energy by thawing a phase change material such as n-pentadecane wax. During portions of the orbit that are extremely cold, the excess energy is rejected, resolidifying the wax. Due to the inherent risk of compromising the heat exchanger during multiple freeze and thaw cycles, a unique payload was designed for the International Space Station to test and demonstration the functions of a PCM HX. The payload incorporates the use of a pumped fluid system and a thermoelectric heat exchanger to promote the freezing and thawing of the PCM HX. This paper shall review the design and development undertaken to build such a system.

Sheth, Rubik B.↗

Harmonization of global land use change and management for the period 850–2100 (LUH2) for CMIP6

Human land use activities have resulted in large changes to the biogeochemical and biophysical properties of the Earth's surface, with consequences for climate and other ecosystem services. In the future, land use activities are likely to expand and/or intensify further to meet growing demands for food, fiber, and energy. As part of the World Climate Research Program Coupled Model Intercomparison Project (CMIP6), the international community has developed the next generation of advanced Earth system models (ESMs) to estimate the combined effects of human activities (e.g., land use and fossil fuel emissions) on the carbon–climate system. A new set of historical data based on the History of the Global Environment database (HYDE), and multiple alternative scenarios of the future (2015–2100) from Integrated Assessment Model (IAM) teams, is required as input for these models. With most ESM simulations for CMIP6 now completed, it is important to document the land use patterns used by those simulations. Here we present results from the Land-Use Harmonization 2 (LUH2) project, which smoothly connects updated historical reconstructions of land use with eight new future projections in the format required for ESMs. The harmonization strategy estimates the fractional land use patterns, underlying land use transitions, key agricultural management information, and resulting secondary lands annually, while minimizing the differences between the end of the historical reconstruction and IAM initial conditions and preserving changes depicted by the IAMs in the future. The new approach builds on a similar effort from CMIP5 and is now provided at higher resolution (0.25°×0.25°) over a longer time domain (850–2100, with extensions to 2300) with more detail (including multiple crop and pasture types and associated management practices) using more input datasets (including Landsat remote sensing data) and updated algorithms (wood harvest and shifting cultivation); it is assessed via a new diagnostic package. The new LUH2 products contain > 50 times the information content of the datasets used in CMIP5 and are designed to enable new and improved estimates of the combined effects of land use on the global carbon–climate system.

land use land cover change↗

X-57 Flight Systems Integration Path

The foundation for a safe and successful flight test of the National Aeronautics and Space Administration (NASA) X-57 Maxwell all-electric experimental airplane, or any X-Plane, is comprehensive system testing on the ground. This test campaign includes verification and validation (V&V) that the integrated system operates as designed and expected, as well as understanding how the system reacts and responds to failures that can occur during flight by performing failure modes and effects testing (FMET). The aircraft should be in the final flight configuration for these test activities because any modifications, even those that appear insignificant, could affect test outcomes. Although the plan was to perform V&V and FMET testing once the airplane was in the flight configuration, due to multiple component redesigns, concurrent software development, and other problems with on-aircraft testing, the X-57 Maxwell never made it into a full-flight configuration. As a result, a build-up approach was followed to test software and hardware as they became ready in order to continue making progress wherever possible. Using this approach revealed problems with the hardware and software faster than waiting for a full-flight configuration, allowing solutions to be found more quickly and in parallel with other project tasks. Other than unloaded motor testing in a lab setting, the only other test setup was on the airplane itself. On-aircraft testing was preferrable in order to test things as close to a flight configuration as possible but was time consuming due to the requirements for testing on the airplane. To overcome some of the on-aircraft barriers, off-aircraft test configurations, such as the Systems Integration Laboratory (SIL) and hardware-in-the-loop (HIL) setups, were used, but each of these setups had limitations to be considered. As a result, solutions found in the SIL or HIL configurations did not always work as expected on the airplane, resulting in an iterative process between on- and off-aircraft testing to find the final solution. Having a dedicated test platform such as an iron bird that closely represents the aircraft - without flight hardware - would have been the most effective off-aircraft test setup, which could have allowed the project to save time and money and potentially reach flight. This paper will highlight the V&V and FMET considerations and testing prerequisites, the build-up approaches to both software and system testing, the benefits and drawbacks to different test configurations, as well as battery testing and operations.

Kassidy M. Mclaughlin↗

X-57 Flight Systems Integration Path

The foundation for a safe and successful flight test of the National Aeronautics and Space Administration (NASA) X-57 Maxwell all-electric experimental airplane, or any X-Plane, is comprehensive system testing on the ground. This test campaign includes verification and validation (V&V) that the integrated system operates as designed and expected, as well as understanding how the system reacts and responds to failures that can occur during flight by performing failure modes and effects testing (FMET). The aircraft should be in the final flight configuration for these test activities because any modifications, even those that appear insignificant, could affect test outcomes. Although the plan was to perform V&V and FMET testing once the airplane was in the flight configuration, due to multiple component redesigns, concurrent software development, and other problems with on-aircraft testing, the X-57 Maxwell never made it into a full-flight configuration. As a result, a build-up approach was followed to test software and hardware as they became ready in order to continue making progress wherever possible. Using this approach revealed problems with the hardware and software faster than waiting for a full-flight configuration, allowing solutions to be found more quickly and in parallel with other project tasks. Other than unloaded motor testing in a lab setting, the only other test setup was on the airplane itself. On-aircraft testing was preferrable in order to test things as close to a flight configuration as possible but was time consuming due to the requirements for testing on the airplane. To overcome some of the on-aircraft barriers, off-aircraft test configurations, such as the Systems Integration Laboratory (SIL) and hardware-in-the-loop (HIL) setups, were used, but each of these setups had limitations to be considered. As a result, solutions found in the SIL or HIL configurations did not always work as expected on the airplane, resulting in an iterative process between on- and off-aircraft testing to find the final solution. Having a dedicated test platform such as an iron bird that closely represents the aircraft - without flight hardware - would have been the most effective off-aircraft test setup, which could have allowed the project to save time and money and potentially reach flight. This paper will highlight the V&V and FMET considerations and testing prerequisites, the build-up approaches to both software and system testing, the benefits and drawbacks to different test configurations, as well as battery testing and operations.

Kassidy McLaughlin↗

Preliminary Application of Formal Verification to An Autonomy Architecture for Unmanned Aircraft

There is a desire to design autonomous systems in such a way that capabilities can be easily added or re- combined to produce new behaviors while preserving their safety properties. ICAROUS, a prototype software architecture for building safety-centric autonomous unmanned aircraft applications, is designed to support this type of extensibility and re-configurability. In ICAROUS, core capabilities are implemented as individual soft- ware services, so that enabling access to new capabilities simply requires adding new services. To make use of these capabilities, ICAROUS includes a specialized service that provides a general framework for config- uring the relative priorities, conditions, and rules that govern how different modules should be engaged and disengaged during flight. The inherent complexity of coordinating multiple modules under changing conditions makes it difficult to determine whether a particular configuration could have erroneous behaviors in certain circumstances. A robust set of integration tests can help discover errors, but testing can only realistically cover a relatively small proportion of total system behaviors. Developing good tests and interpreting the results to pinpoint the cause of errors when they arise can also be very time-consuming. To supplement testing, formal methods can be used to model and analyze complex systems, achieving better coverage and simplifying the process of finding, understanding, and fixing errors. To demonstrate these benefits, this paper explores the ap- plication of formal methods to ICAROUS. In particular, the Spin model checker is used to specify requirements for and model portions of the system, then verify whether the model satisfies the requirements and find and fix errors when it does not.

Formal Methods↗

Information Systems Technology for NASA Earth Systems Digital Twins (ESDT)

The term “Digital Twin” was first used in 2002 for product lifecycle management. Since then, Digital Twin concepts have been proposed in various domains until very recently for Earth Science. For NASA’s Advanced Information Systems Technology (AIST) Program, an Earth System Digital Twin (ESDT) is defined as composed of three components: 1. A Digital Replica, i.e., an integrated picture of the past and current states of Earth systems 2. Forecasting capabilities, providing an integrated picture of how Earth systems will evolve in the future from the current state 3. Impact Assessment capabilities, providing an integrated picture of how Earth systems could evolve under different hypothetical what-if scenarios. Developing such a vision will require technologies related to: integrating continuous observations from various disparate sources; developing frameworks that builds on inter-connected models; improving the speed and accuracy of integrated prediction, analysis and visualization capabilities (e.g., by using machine learning); and utilizing causality and uncertainty quantification to improve our understanding of the evolution of Earth Science systems as a function of their interactions with other Earth and human systems. In addition, AIST is also investigating interoperability standards to federate multiple Digital Twins, as well as computational resources required by those systems.

Earth Science Remote Sensing; Information Systems↗

Harnessing the Digital Transformation for Development of Electrified Aircraft Propulsion Control Systems

Hybrid electric aircraft propulsion is an emerging technology that presents a variety of potential benefits along with technical integration challenges. Developing these new propulsion architectures with their complex control systems, and ultimately proving their benefit, is a multistep process. This process includes concept development and analysis, dynamic simulation, hardware-in-the-loop testing, full-scale testing, and so on. This effort is being revolutionized and indeed enabled by new digital tools that support increasing the technology readiness level throughout the maturation process. As part of this Digital Transformation, NASA has developed a suite of publicly available digital tools that facilitate the path from concept to implementation. This paper describes the NASA-developed tools and puts them in the context of control system development for hybrid electric aircraft propulsion. The three MATLAB®-based software packages are the Toolbox for the Modeling and Analysis of Thermodynamic Systems (T-MATS), the Electrical Modeling and Thermal Analysis Toolbox (EMTAT), and the Thermal Systems Analysis Toolbox (TSAT). These tools are interactive, complementary, and compatible with each other. T-MATS is a modular thermodynamic modeling framework designed for creating custom component level models of jet engines. EMTAT is a modeling framework used to simulate a variety of power electronic devices, using both physics-based and power flow calculations. TSAT is a framework for modeling and analysis of dynamic heat transfer. These packages all consist of graphical, drag-and-drop, parameterizable building blocks representing various components of the system to be modeled, e.g., compressors, turbines, motors, energy storage devices, etc. They are designed to enable the user to model and simulate the end-to-end dynamic operation of a hybrid electric gas turbine engine powertrain at the timescale of the turbomachinery, capturing mechanical, electrical, and thermal interactions. This paper demonstrates through multiple examples how these tools have been used successfully in a variety of applications, including several of the early stages of hybrid electric gas turbine engine propulsion system development, from the initial system modeling to real-time interactive pilot-in-the-loop simulation to physical hardware-in-the-loop testing, each step bringing the technology closer to fruition.

hybrid electric propulsion↗

Evaluating Liftoff Debris for NASA’s Space Launch System (SLS) Prior to the Artemis I Launch

The SLS Artemis I launch vehicle is the first of several planned Artemis launch vehicles, with a number of design differences from earlier NASA missions that incur liftoff debris risk to the mission. As a test vehicle, the Artemis I hardware also endured environments and tests not planned for future missions, which led to several additional factors contributing to an evolving liftoff debris risk to the SLS vehicle. This paper will summarize these risk factors and address the processes used to evaluate and communicate the risks to support a successful Artemis I launch. It will discuss how the evolving risks that were quantified and evaluated by a Cross-Program team of debris Subject Matter Experts to mitigate liftoff debris hazards and communicate updated risk to the SLS vehicle. This process was performed through the inaugural use of an SLS debris day-of-launch (DOL) standard operating procedure that will be used for subsequent Artemis missions. This paper addresses the risk of liftoff debris, debris released by the vehicle or from the launch pad during liftoff through vehicle tower clear. Expected liftoff debris is well understood from previous NASA programs’ experience and from tests of materials, processes and functions that are known to release liftoff debris. These expected sources were assessed and cleared well ahead of launch day. However, given the ever-changing schedules and environments, processes were in place to evaluate any additional potential liftoff debris risks identified during launch countdown. Although many of the Artemis vehicle hardware components are similar to those on the NASA Shuttle Program, there are important differences in the architecture of the Artemis I vehicle which require new assessments of liftoff debris risk for the Artemis missions. The more favorable Artemis crew module location and surfaces are far less vulnerable to debris impacts; however, the longer vehicle can result in higher liftoff debris impact energies to those components on the aft end of the vehicle. Additionally, the positional change of the RS-25 liquid engines to nearer the Booster nozzle exit plane along with the change in Booster throat plug design is a disadvantage to the overall liftoff debris risk which resulted in additional test and analysis efforts for evaluating the integrated vehicle debris risk. In spite of the comprehensive tests and analyses of Artemis I expected liftoff debris, a number of additional tests/processes were completed prior to the Artemis I mission that were required to support a complete understanding of a new launch vehicle, but increased the risk of releasing liftoff debris. The hardware endured several additional cryogenic loading cycles, including the Green Run tests at Stennis Space Center, Wet Dress Rehearsals at Kennedy Space Center, and multiple launch attempts. Each of these cycles induced stresses in the thermal protection system (TPS) materials, increasing the risk of damage to and release of the TPS. Additionally, induced and weather environmental factors that could increase the likelihood of debris release were significant. Vibrations and stresses in the TPS were induced by a required roll-back to the Vehicle Assembly Building before Hurricane Ian to protect the vehicle from damage by high winds. Wind damage and potential internal stresses to several outer mold line materials on the integrated SLS vehicle and mobile launcher were caused by weathering Hurricane Nicole at Pad 39B the week before launch. A thorough imagery scan of the vehicle was performed after each event and the damage observed was repaired, removed, or assessed and the risk to the mission evaluated. Mitigation of debris risk can occur by tests and analyses to show debris impacted components as damage tolerant, by new/improved processes for prevention of debris availability, or redesign. Risk mitigation processes for Artemis I-specific liftoff debris events and the development and use of the SLS debris day of launch (DOL) procedures that will be used for subsequent Artemis missions will be described.

Space Launch System↗

Core Body Temperature Predictions Using Metabolic Energy Expenditure and Heart Rate During Simulated Extravehicular Activity

Long duration spaceflight missions will require crew to become more autonomous in conducting extravehicular activities (EVA) without direct communication with Mission Control for biomedical support. To enable such autonomy, we are developing a Crew State and Risk Model (CSRM) as a collection of key physiology domains that drive EVA crew capabilities and workloads. One model component of CSRM is human thermal regulation. In this paper, customized development of a baseline model to predict core body temperature is presented using physiology inputs of heart rate and metabolic rate. The model development dataset included a baseline study where participants (n=6, equal male and female) performed a 5-hour EVA in a two-part session while wearing a hybrid space suit simulator (HS3). The first session included an end-to-end EVA traversing 1500 meters to a geology site and traversing back to a habitat conducting geology, payload relocation, and maintenance operations every 500 meters. The second session included standalone tasks of a 2000-meter traverse followed by geology tasks. Thermal measures of core body temperature, local skin temperature, liquid cooling garment temperature, heart rate, and metabolic rate were collected through the test duration. Multiple regression was used to build a linear equation to predict core body temperature from inputs of heart rate and metabolic rate. Heat storage was calculated via predicted core body temperature plus LCG and skin temperatures. The model was tested against a dataset from a pressurized suited test (n=6, equal male and female) in the NASA Active Response Gravity Offload System (ARGOS) conducting similar end-to-end EVA and standalone tasks. Predicted error of the model against the raw test cases was 0.2±0.15 °C. The baseline prediction of core body temperature using heart rates and metabolic rates allows for simple real-time tracking from data collected in-flight to monitor crew consumables and thermal flight limits during EVA.

Bradley Hoffmann↗

Evaluating Liftoff Debris for NASA’s Space Launch System (SLS) Prior to the Artemis I Launch

The SLS Artemis I launch vehicle is the first of several planned Artemis launch vehicles, with a number of design differences from earlier NASA missions that incur liftoff debris risk to the mission. As a test vehicle, the Artemis I hardware also endured environments and tests not planned for future missions, which led to several additional factors contributing to an evolving liftoff debris risk to the SLS vehicle. This paper will summarize these risk factors and address the processes used to evaluate and communicate the risks to support a successful Artemis I launch. It will discuss how the evolving risks that were quantified and evaluated by a Cross-Program team of debris Subject Matter Experts to mitigate liftoff debris hazards and communicate updated risk to the SLS vehicle. This process was performed through the inaugural use of an SLS debris day-of-launch (DOL) standard operating procedure that will be used for subsequent Artemis missions. This paper addresses the risk of liftoff debris, debris released by the vehicle or from the launch pad during liftoff through vehicle tower clear. Expected liftoff debris is well understood from previous NASA programs’ experience and from tests of materials, processes and functions that are known to release liftoff debris. These expected sources were assessed and cleared well ahead of launch day. However, given the ever-changing schedules and environments, processes were in place to evaluate any additional potential liftoff debris risks identified during launch countdown. Although many of the Artemis vehicle hardware components are similar to those on the NASA Shuttle Program, there are important differences in the architecture of the Artemis I vehicle which require new assessments of liftoff debris risk for the Artemis missions. The more favorable Artemis crew module location and surfaces are far less vulnerable to debris impacts; however, the longer vehicle can result in higher liftoff debris impact energies to those components on the aft end of the vehicle. Additionally, the positional change of the RS-25 liquid engines to nearer the Booster nozzle exit plane along with the change in Booster throat plug design is a disadvantage to the overall liftoff debris risk which resulted in additional test and analysis efforts for evaluating the integrated vehicle debris risk. In spite of the comprehensive tests and analyses of Artemis I expected liftoff debris, a number of additional tests/processes were completed prior to the Artemis I mission that were required to support a complete understanding of a new launch vehicle, but increased the risk of releasing liftoff debris. The hardware endured several additional cryogenic loading cycles, including the Green Run tests at Stennis Space Center, Wet Dress Rehearsals at Kennedy Space Center, and multiple launch attempts. Each of these cycles induced stresses in the thermal protection system (TPS) materials, increasing the risk of damage to and release of the TPS. Additionally, induced and weather environmental factors that could increase the likelihood of debris release were significant. Vibrations and stresses in the TPS were induced by a required roll-back to the Vehicle Assembly Building before Hurricane Ian to protect the vehicle from damage by high winds. Wind damage and potential internal stresses to several outer mold line materials on the integrated SLS vehicle and mobile launcher were caused by weathering Hurricane Nicole at Pad 39B the week before launch. A thorough imagery scan of the vehicle was performed after each event and the damage observed was repaired, removed, or assessed and the risk to the mission evaluated. Mitigation of debris risk can occur by tests and analyses to show debris impacted components as damage tolerant, by new/improved processes for prevention of debris availability, or redesign. Risk mitigation processes for Artemis I-specific liftoff debris events and the development and use of the SLS debris day of launch (DOL) procedures that will be used for subsequent Artemis missions will be described.

Space Launch System↗

Preliminary Application of Formal Verification to An Autonomy Architecture for Unmanned Aircraft

There is a desire to design autonomous systems in such a way that capabilities can be easily added or re-combined to produce new behaviors while preserving their safety properties. ICAROUS, a prototype software architecture for building safety-centric autonomous unmanned aircraft applications, is designed to support this type of extensibility and re-configurability. In ICAROUS, core capabilities are implemented as individual soft- ware services, so that enabling access to new capabilities simply requires adding new services. To make use of these capabilities, ICAROUS includes a specialized service that provides a general framework for config- uring the relative priorities, conditions, and rules that govern how different modules should be engaged and disengaged during flight. The inherent complexity of coordinating multiple modules under changing conditions makes it difficult to determine whether a particular configuration could have erroneous behaviors in certain circumstances. A robust set of integration tests can help discover errors, but testing can only realistically cover a relatively small proportion of total system behaviors. Developing good tests and interpreting the results to pinpoint the cause of errors when they arise can also be very time-consuming. To supplement testing, formal methods can be used to model and analyze complex systems, achieving better coverage and simplifying the process of finding, understanding, and fixing errors. To demonstrate these benefits, this paper explores the ap- plication of formal methods to ICAROUS. In particular, the Spin model checker is used to specify requirements for and model portions of the system, then verify whether the model satisfies the requirements and find and fix errors when it does not.

Formal Methods↗

Integration of domain and resource-based reasoning for real-time control in dynamic environments

A real-time software controller that successfully integrates domain-based and resource-based control reasoning to perform task execution in a dynamically changing environment is described. The design of the controller is based on the concept of partitioning the process to be controlled into a set of tasks, each of which achieves some process goal. It is assumed that, in general, there are multiple ways (tasks) to achieve a goal. The controller dynamically determines current goals and their current criticality, choosing and scheduling tasks to achieve those goals in the time available. It incorporates rule-based goal reasoning, a TMS-based criticality propagation mechanism, and a real-time scheduler. The controller has been used to build a knowledge-based situation assessment system that formed a major component of a real-time, distributed, cooperative problem solving system built under DARPA contract. It is also being employed in other applications now in progress.

Morgan, Keith↗

The Consolidated Planning and Scheduling System for Space Transportation and Space Station operations - Successful development experience

In 1992, NASA made the decision to evolve a Consolidated Planning System (CPS) by adding the Space Transportation System (STS) requirements to the Space Station Freedom (SSF) planning software. This paper describes this evolutionary process, which began with a series of six-month design-build-test cycles, using a domain-independent architecture and a set of developmental tools known as the Advanced Scheduling Environment. It is shown that, during these tests, the CPS could be used at multiple organizational levels of planning and for integrating schedules from geographically distributed (including international) planning environments. The potential for using the CPS for other planning and scheduling tasks in the SSF program is being currently examined.

Hornstein, Rhoda S.↗

Overview of NASA's Earth Science Data Systems

For over the last 15 years, NASA's Earth Science Enterprise (ESE) has devoted a tremendous effort to design and build the Earth Observing System (EOS) Data and Information System (EOSDIS) to acquire, process, archive and distribute the data of the EOS series of satellites and other ESE missions and field programs. The development of EOSDIS began with an early prototype to support NASA data from heritage missions and progressed through a formal development process to today's system that supports the data from multiple missions including Landsat 7, Terra, Aqua, SORCE and ICESat. The system is deployed at multiple Distributed Active Archive Centers (DAACs) and its current holdings are approximately 4.5 petabytes. The current set of unique users requesting EOS data and information products exceeds 2 million. While EOSDIS has been the centerpiece of NASA's Earth Science Data Systems, other initiatives have augmented the services of EOSDIS and have impacted its evolution and the future directions of data systems within the ESE. ESDIS had an active prototyping effort and has continued to be involved in the activities of the Earth Science Technology Office (ESTO). In response to concerns from the science community that EOSDIS was too large and monolithic, the ESE initiated the Earth Science Information Partners (ESP) Federation Experiment that funded a series of projects to develop specialized products and services to support Earth science research and applications. Last year, the enterprise made 41 awards to successful proposals to the Research, Education and Applications Solutions Network (REASON) Cooperative Agreement Notice to continue and extend the ESP activity. The ESE has also sponsored a formulation activity called the Strategy for the Evolution of ESE Data Systems (SEEDS) to develop approaches and decision support processes for the management of the collection of data system and service providers of the enterprise. Throughout the development of its earth science data systems, NASA has had an active collaboration with a number of interagency and international partners. One of the mechanisms that has been extremely helpful in initiating and promoting this collaboration has been NASA's participation in the Committee on Earth Observation Satellites (CEOS) and its Working Group on Information Systems and Services (WGISS). The CEOS members, working together, have implemented an International Directory Network that enables users to locate collections of earth science data held by the international community and an International Catalog System to search and order specific data products. CEOS WGISS has also promoted the international interest in the Open GIS Consortium s specifications that further advance the access and use of geospatial data and the interoperation of GTS components. These are just a few highlights of the benefits that member agencies gain from CEOS participation.

McDonald, Kenneth↗