Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Management Space Projects”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 307 records · Page 17

Crew Launch Vehicle (CLV) Upper Stage Configuration Selection Process

The Crew Launch Vehicle (CLV), a key component of NASA's blueprint for the next generation of spacecraft to take humans back to the moon, is being designed and built by engineers at NASA s Marshall Space Flight Center (MSFC). The vehicle s design is based on the results of NASA's 2005 Exploration Systems Architecture Study (ESAS), which called for development of a crew-launch system to reduce the gap between Shuttle retirement and Crew Exploration Vehicle (CEV) Initial Operating Capability, identification of key technologies required to enable and significantly enhance these reference exploration systems, and a reprioritization of near- and far-term technology investments. The Upper Stage Element (USE) of the CLV is a clean-sheet approach that is being designed and developed in-house, with element management at MSFC. The USE concept is a self-supporting cylindrical structure, approximately 115' long and 216" in diameter, consisting of the following subsystems: Primary Structures (LOX Tank, LH2 Tank, Intertank, Thrust Structure, Spacecraft Payload Adaptor, Interstage, Forward and Aft Skirts), Secondary Structures (Systems Tunnel), Avionics and Software, Main Propulsion System, Reaction Control System, Thrust Vector Control, Auxiliary Power Unit, and Hydraulic Systems. The ESAS originally recommended a CEV to be launched atop a four-segment Space Shuttle Main Engine (SSME) CLV, utilizing an RS-25 engine-powered upper stage. However, Agency decisions to utilize fewer CLV development steps to lunar missions, reduce the overall risk for the lunar program, and provide a more balanced engine production rate requirement prompted engineers to switch to a five-segment design with a single Saturn-derived J-2X engine. This approach provides for single upper stage engine development for the CLV and an Earth Departure Stage, single Reusable Solid Rocket Booster (RSRB) development for the CLV and a Cargo Launch Vehicle, and single core SSME development. While the RSRB design has changed since the CLV Project's inception, the USE design has remained essentially a clean-sheet approach. Although a clean-sheet upper stage design inherently carries more risk than a modified design, it does offer many advantages: a design for increased reliability; built-in extensibility to allow for commonality/growth without major redesign; and incorporation of state-of-the-art materials, hardware, and design, fabrication, and test techniques and processes to facilitate a potentially better, more reliable system. Because consideration was given in the ESAS to both clean-sheet and modified USE designs, this paper will highlight the advantages and disadvantages of both approaches and provide a detailed discussion of trades/selections made that led to the final upper stage configuration.

Davis, Daniel J.↗

Intelligent fault management for the Space Station active thermal control system

The Thermal Advanced Automation Project (TAAP) approach and architecture is described for automating the Space Station Freedom (SSF) Active Thermal Control System (ATCS). The baseline functionally and advanced automation techniques for Fault Detection, Isolation, and Recovery (FDIR) will be compared and contrasted. Advanced automation techniques such as rule-based systems and model-based reasoning should be utilized to efficiently control, monitor, and diagnose this extremely complex physical system. TAAP is developing advanced FDIR software for use on the SSF thermal control system. The goal of TAAP is to join Knowledge-Based System (KBS) technology, using a combination of rules and model-based reasoning, with conventional monitoring and control software in order to maximize autonomy of the ATCS. TAAP's predecessor was NASA's Thermal Expert System (TEXSYS) project which was the first large real-time expert system to use both extensive rules and model-based reasoning to control and perform FDIR on a large, complex physical system. TEXSYS showed that a method is needed for safely and inexpensively testing all possible faults of the ATCS, particularly those potentially damaging to the hardware, in order to develop a fully capable FDIR system. TAAP therefore includes the development of a high-fidelity simulation of the thermal control system. The simulation provides realistic, dynamic ATCS behavior and fault insertion capability for software testing without hardware related risks or expense. In addition, thermal engineers will gain greater confidence in the KBS FDIR software than was possible prior to this kind of simulation testing. The TAAP KBS will initially be a ground-based extension of the baseline ATCS monitoring and control software and could be migrated on-board as additional computation resources are made available.

Hill, Tim↗

Large Payload Ground Transportation and Test Considerations

Many spacecraft concepts under consideration by the National Aeronautics and Space Administration’s (NASA’s) Evolvable Mars Campaign take advantage of a Space Launch System payload shroud that may be 8 to 10 meters in diameter. Large payloads can theoretically save cost by reducing the number of launches needed--but only if it is possible to build, test, and transport a large payload to the launch site in the first place. Analysis performed previously for the Altair project identified several transportation and test issues with an 8.973 meters diameter payload. Although the entire Constellation Program—including Altair—has since been canceled, these issues serve as important lessons learned for spacecraft designers and program managers considering large payloads for future programs. A transportation feasibility study found that, even broken up into an Ascent and Descent Module, the Altair spacecraft would not fit inside available aircraft. Ground transportation of such large payloads over extended distances is not generally permitted, so overland transportation alone would not be an option. Limited ground transportation to the nearest waterway may be possible, but water transportation could take as long as 67 days per production unit, depending on point of origin and acceptance test facility; transportation from the western United States would require transit through the Panama Canal to access the Kennedy Space Center launch site. Large payloads also pose acceptance test and ground processing challenges. Although propulsion, mechanical vibration, and reverberant acoustic test facilities at NASA’s Plum Brook Station have been designed to accommodate large spacecraft, special handling and test work-arounds may be necessary, which could increase cost, schedule, and technical risk. Once at the launch site, there are no facilities currently capable of accommodating the combination of large payload size and hazardous processing such as hypergolic fuels, pyrotechnic devices, and high pressure gasses. Ironically, the limiting factor to a national heavy lift strategy may not be the rocket technology needed to throw a heavy payload, but rather the terrestrial infrastructure—roads, bridges, airframes, and buildings—necessary to transport, acceptance test, and process large spacecraft. Failure to carefully consider where and how large spacecraft are manufactured, tested, and launched could result in unforeseen cost to modify existing (or develop new) infrastructure, or incur additional risk due to increased handling operations or eliminating key verifications. Although this paper focuses on the canceled Altair spacecraft as a case study, the issues identified here have wide applicability to other large payloads, including concepts under consideration for NASA’s Evolvable Mars Campaign.

Rucker, Michelle A.↗

Transition flight control room automation

The Workstation Prototype Laboratory is currently working on a number of projects which can have a direct impact on ground operations automation. These projects include: (1) The fuel cell monitoring system (FCMS), which will monitor and detect problems with the fuel cells on the shuttle. FCMS will use a combination of rules (forward/backward) and multithreaded procedures, which run concurrently with the rules, to implement the malfunction algorithms of the EGIL flight controllers. The combination of rule-based reasoning and procedural reasoning allows us to more easily map the malfunction algorithms into a real-time system implementation. (2) A graphical computation language (AGCOMPL) is an experimental prototype to determine the benefits and drawbacks of using a graphical language to design computations (algorithms) to work on shuttle or space station telemetry and trajectory data. (3) The design of a system will allow a model of an electrical system, including telemetry sensors, to be configured on the screen graphically using previously defined electrical icons. This electrical model would then be used to generate rules and procedures for detecting malfunctions in the electrical components of the model. (4) A generic message management (GMM) system is being designed for real-time applications as a message management system which sends advisory messages to a user. The primary purpose of GMM is to reduce the risk of overloading a user with information when multiple failures occur and to assist the developer in the devising an explanation facility. The emphasis of our work is to develop practical tools and techniques, including identification of appropriate software tools to support research, application, and tool building activities, while determining the feasibility of a given approach.

Welborn, Curtis Ray↗

Transition Flight Control Room Automation

The Workstation Prototype Laboratory is currently working on a number of projects which we feel can have a direct impact on ground operations automation. These projects include: The Fuel Cell Monitoring System (FCMS), which will monitor and detect problems with the fuel cells on the Shuttle. FCMS will use a combination of rules (forward/backward) and multi-threaded procedures which run concurrently with the rules, to implement the malfunction algorithms of the EGIL flight controllers. The combination of rule based reasoning and procedural reasoning allows us to more easily map the malfunction algorithms into a real-time system implementation. A graphical computation language (AGCOMPL). AGCOMPL is an experimental prototype to determine the benefits and drawbacks of using a graphical language to design computations (algorithms) to work on Shuttle or Space Station telemetry and trajectory data. The design of a system which will allow a model of an electrical system, including telemetry sensors, to be configured on the screen graphically using previously defined electrical icons. This electrical model would then be used to generate rules and procedures for detecting malfunctions in the electrical components of the model. A generic message management (GMM) system. GMM is being designed as a message management system for real-time applications which send advisory messages to a user. The primary purpose of GMM is to reduce the risk of overloading a user with information when multiple failures occurs and in assisting the developer in devising an explanation facility. The emphasis of our work is to develop practical tools and techniques, while determining the feasibility of a given approach, including identification of appropriate software tools to support research, application and tool building activities.

Welborn, Curtis Ray↗

Heuristic algorithms for design of integrated monitoring of geologic carbon storage sites

Designs for Risk Evaluation and Management (DREAM) is a tool developed under the National Risk Assessment Partnership (NRAP) to enhance geologic carbon storage safety and efficiency. Using potential leakage scenarios generated externally by the users preferred history-matching approach, DREAM constructs ideal combinations of sensor locations in the right place at the right time to detect as many leaks as possible, detect them as early as possible, and minimize cost. This user-friendly tool, developed in Java, features a window-based GUI for input and a 3D visualization tool for viewing the domain space and optimized monitoring plans. DREAM's latest version accommodates real-world usage by allowing for joint optimization of wellbore point sensor placements and surface geophysics survey geometries, and by using more efficient multi-objective optimization algorithms. We show an example where, these two improvements combined allow us to support containment assurance and go from detecting 80–90 % of the potential CO 2 leakage to +99.7 %, a step-change improvement that can make the deciding difference in whether a site is suitable for geologic carbon storage. Though developed for geologic carbon storage, this tool would be equally applicable in many surface or offshore environmental monitoring projects.

58 GEOSCIENCES↗

Atrial Arrhythmias in Astronauts - Summary of a NASA Summit

Background and Problem Definition: To evaluate NASA s current standards and practices related to atrial arrhythmias in astronauts, Space Medicine s Advanced Projects Section at the Johnson Space Center was tasked with organizing a summit to discuss the approach to atrial arrhythmias in the astronaut cohort. Since 1959, 11 cases of atrial fibrillation, atrial flutter, or supraventricular tachycardia have been recorded among active corps crewmembers. Most of the cases were paroxysmal, although a few were sustained. While most of the affected crewmembers were asymptomatic, those slated for long-duration space flight underwent radiofrequency ablation treatment to prevent further episodes of the arrhythmia. The summit was convened to solicit expert opinion on screening, diagnosis, and treatment options, to identify gaps in knowledge, and to propose relevant research initiatives. Summit Meeting Objectives: The Atrial Arrhythmia Summit brought together a panel of six cardiologists, including nationally and internationally renowned leaders in cardiac electrophysiology, exercise physiology, and space flight cardiovascular physiology. The primary objectives of the summit discussions were to evaluate cases of atrial arrhythmia in the astronaut population, to understand the factors that may predispose an individual to this condition, to understand NASA s current capabilities for screening, diagnosis, and treatment, to discuss the risks associated with treatment of crewmembers assigned to long-duration missions or extravehicular activities, and to discuss recommendations for prevention or management of future cases. Summary of Recommendations: The summit panel s recommendations were grouped into seven categories: Epidemiology, Screening, Standards and Selection, Treatment of Atrial Fibrillation Manifesting Preflight, Atrial Fibrillation during Flight, Prevention of Atrial Fibrillation, and Future Research

Barr, Yael R.↗

Auxiliary Propulsion Activities in Support of NASA's Exploration Initiative

The Space Launch Initiative (SLI) procurement mechanism NRA8-30 initiated the Auxiliary Propulsion System/Main Propulsion System (APS/MPS) Project in 2001 to address technology gaps and development risks for non-toxic and cryogenic propellants for auxiliary propulsion applications. These applications include reaction control and orbital maneuvering engines, and storage, pressure control, and transfer technologies associated with on-orbit maintenance of cryogens. The project has successfully evolved over several years in response to changing requirements for re-usable launch vehicle technologies, general launch technology improvements, and, most recently, exploration technologies. Lessons learned based on actual hardware performance have also played a part in the project evolution to focus now on those technologies deemed specifically relevant to the Exploration Initiative. Formal relevance reviews held in the spring of 2004 resulted in authority for continuation of the Auxiliary Propulsion Project through Fiscal Year 2005 (FY05), and provided for a direct reporting path to the Exploration Systems Mission Directorate. The tasks determined to be relevant under the project were: continuation of the development, fabrication, and delivery of three 870 lbf thrust prototype LOX/ethanol reaction control engines; the fabrication, assembly, engine integration and testing of the Auxiliary Propulsion Test Bed at White Sands Test Facility; and the completion of FY04 cryogenic fluid management component and subsystem development tasks (mass gauging, pressure control, and liquid acquisition elements). This paper presents an overview of those tasks, their scope, expectations, and results to-date as carried forward into the Exploration Initiative.

Best, Philip J.↗

An Effective Health and Medical Technical Authority

The NASA Governance model directed the formation of three Technical Authorities, Engineering; Safety and Mission Assurance; and Health and Medical, to ensure that risks are identified and adjudicated efficiently and transparently in concert with the spaceflight programs and projects. The Health and Medical Technical Authority (HMTA) has been implemented at the Johnson Space Center (JSC) and consists of the Chief Medical Office (CMO), the Deputy CMO, and HMTA Delegates. The JSC HMTA achieves the goals of risk identification and adjudication through the discharge of the appropriate technical expertise to human space flight programs and projects and the escalation of issues within program and technical authority boards. The JSC HMTA relies on subject matter experts (SMEs) in the Space Life Sciences Directorate at JSC as well as experts from other Centers to work crew health and performance issues at the technical level, develop requirements, oversee implementation and validation of requirements, and identify risks and non-compliances. Once a risk or potential noncompliance has been identified and reported to the programs or projects, the JSC HMTA begins to track it and closely monitor the program's or project's response. As a risk is developed or a non-compliance negotiated, positions from various levels of decision makers are sought at the program and project control boards. The HMTA may support a program or project position if it is satisfied with the decision making and vetting processes (ex. the subject matter expert voiced his/her concerns and all dissenting opinions were documented) and finds that the position both acknowledges the risk and cost of the mitigation and resolves the issue without changing NASA risk posture. The HMTA may disagree with a program or project position if the NASA risk posture has been elevated or obfuscated. If the HMTA does disagree with the program or project position, it will appeal to successively higher levels of authority so that risk acceptance and risk trades will be acknowledged and sanctioned at the highest appropriate level; this includes Program Managers, Mission Directorate Associate Administrators and the Agency Administrator.

Fogarty, Jennifer A.↗

Methodolgy For Evaluation Of Technology Impacts In Space Electric Power Systems

The Analysis and Management branch of the Power and Propulsion Office at NASA Glenn Research Center is responsible for performing complex analyses of the space power and In-Space propulsion products developed by GRC. This work quantifies the benefits of the advanced technologies to support on-going advocacy efforts. The Power and Propulsion Office is committed to understanding how the advancement in space technologies could benefit future NASA missions. They support many diverse projects and missions throughout NASA as well as industry and academia. The area of work that we are concentrating on is space technology investment strategies. Our goal is to develop a Monte-Carlo based tool to investigate technology impacts in space electric power systems. The framework is being developed at this stage, which will be used to set up a computer simulation of a space electric power system (EPS). The outcome is expected to be a probabilistic assessment of critical technologies and potential development issues. We are developing methods for integrating existing spreadsheet-based tools into the simulation tool. Also, work is being done on defining interface protocols to enable rapid integration of future tools. Monte Carlo-based simulation programs for statistical modeling of the EPS Model. I decided to learn and evaluate Palisade's @Risk and Risk Optimizer software, and utilize it's capabilities for the Electric Power System (EPS) model. I also looked at similar software packages (JMP, SPSS, Crystal Ball, VenSim, Analytica) available from other suppliers and evaluated them. The second task was to develop the framework for the tool, in which we had to define technology characteristics using weighing factors and probability distributions. Also we had to define the simulation space and add hard and soft constraints to the model. The third task is to incorporate (preliminary) cost factors into the model. A final task is developing a cross-platform solution of this framework.

Holda, Julie↗

Enhancing Human Health Using Space Imagery: Summary of Research

The International Space University (ISU) 2002 Summer Session was conducted in Pomona, California, June 29-August 30, 2002. Ninety-nine professionals and students from thirty-one countries attended the Summer Session. More than half of these students participated in the Student Research Design Project entitled, "HI-STAR: Health Improvements through Space Technologies and Resources." ISU's interdisciplinary Student Research Design Projects are intended to have great educational value for the participants and, at the same time, to result in a product that will be useful to the field. The HI-STAR project was a success on both counts. The mission of the ISU students' effort on HI-STAR was to develop and promote a global strategy to help combat malaria using space technology. Like the tiny yet powerful mosquito, HI-STAR is a small program that aspires to make a difference. Timely detection of malaria danger zones is essential to help health authorities and policy makers make decisions about how to manage limited resources for combating malaria. In 2001, the technical support network for prevention and control of malaria epidemics published a study called "Malaria Early Warning Systems: Concepts, Indicators and Partners." This study, funded by Roll Back Malaria, a World Health Organization initiative, offered a framework for a monitoring and early warning system. HI-STAR seeks to build on this proposal and enhance the space elements of the suggested framework. Malaria disease dynamics and distributions are related to environmental variables. From space, environmental conditions that support the growth of mosquito populations can be monitored, Malaria-specific information can be gathered from satellite-borne remote sensing instruments and ground-based sensors. This information can be integrated via geographic information systems (GIS) into a Malaria Information System (MIS) that can provide assessment analyses and risk maps as output. HI-STAR defines and suggests the development of an active MIS as a low-cost tool to help organizations plan their efforts to fight malaria.

Finarelli, Margaret G.↗

Developing Advanced Support Technologies for Planetary Exploration Missions

The United States Vision for Space Exploration calls for sending robots and humans to explore the Earth s moon, the planet Mars, and beyond. The National Aeronautics and Space Administration (NASA) is developing a set of design reference missions that will provide further detail to these plans. Lunar missions are expected to provide a stepping stone, through operational research and evaluation, in developing the knowledge base necessary to send crews on long duration missions to Mars and other distant destinations. The NASA Exploration Systems Directorate (ExSD), in its program of bioastronautics research, manages the development of technologies that maintain human life, health, and performance in space. Using a systems engineering process and risk management methods, ExSD s Human Support Systems (HSS) Program selects and performs research and technology development in several critical areas and transfers the results of its efforts to NASA exploration mission/systems development programs in the form of developed technologies and new knowledge about the capabilities and constraints of systems required to support human existence beyond Low Earth Orbit. HSS efforts include the areas of advanced environmental monitoring and control, extravehicular activity, food technologies, life support systems, space human factors engineering, and systems integration of all these elements. The HSS Program provides a structured set of deliverable products to meet the needs of exploration programs. these products reduce the gaps that exist in our knowledge of and capabilities for human support for long duration, remote space missions. They also reduce the performance gap between the efficiency of current space systems and the greater efficiency that must be achieved to make human planetary exploration missions economically and logistically feasible. In conducting this research and technology development program, it is necessary for HSS technologists and program managers to develop a common currency for decision making and the allocation of funding. A high level assessment is made of both the knowledge gaps and the system performance gaps across the program s technical project portfolio. This allows decision making that assures proper emphasis areas and provides a key measure of annual technological progress, as exploration mission plans continue to mature.

Berdich, Debra P.↗

Developing Advanced Human Support Technologies for Planetary Exploration Missions

The United States Vision for Space Exploration calls for sending robots and humans to explore the Earth's moon, the planet Mars, and beyond. The National Aeronautics and Space Administration (NASA) is developing a set of design reference missions that will provide further detail to these plans. Lunar missions are expected to provide a stepping stone, through operational research and evaluation, in developing the knowledge base necessary to send crews on long duration missions to Mars and other distant destinations. The NASA Exploration Systems Directorate (ExSD), in its program of bioastronautics research, manages the development of technologies that maintain human life, health, and performance in space. Using a system engineering process and risk management methods, ExSD's Human Support Systems (HSS) Program selects and performs research and technology development in several critical areas and transfers the results of its efforts to NASA exploration mission/systems development programs in the form of developed technologies and new knowledge about the capabilities and constraints of systems required to support human existence beyond Low Earth Orbit. HSS efforts include the areas of advanced environmental monitoring and control, extravehicular activity, food technologies, life support systems, space human factors engineering, and systems integration of all these elements. The HSS Program provides a structured set of deliverable products to meet the needs of exploration programs. These products reduce the gaps that exist in our knowledge of and capabilities for human support for long duration, remote space missions. They also reduce the performance gap between the efficiency of current space systems and the greater efficiency that must be achieved to make human planetary exploration missions economically and logistically feasible. In conducting this research and technology development program, it is necessary for HSS technologists and program managers to develop a common currency for decision making and the allocation of funding. A high level assessment is made of both the knowledge gaps and the system performance gaps across the program s technical project portfolio. This allows decision making that assures proper emphasis areas and provides a key measure of annual technological progress, as exploration mission plans continue to mature.

Berdich, Debra P.↗

Human Exploration Science Office (KX) Overview

The Human Exploration Science Office supports human spaceflight, conducts research, and develops technology in the areas of space orbital debris, hypervelocity impact technology, image science and analysis, remote sensing, imagery integration, and human and robotic exploration science. NASA's Orbital Debris Program Office (ODPO) resides in the Human Exploration Science Office. ODPO provides leadership in orbital debris research and the development of national and international space policy on orbital debris. The office is recognized internationally for its measurement and modeling of the debris environment. It takes the lead in developing technical consensus across U.S. agencies and other space agencies on debris mitigation measures to protect users of the orbital environment. The Hypervelocity Impact Technology (HVIT) project evaluates the risks to spacecraft posed by micrometeoroid and orbital debris (MMOD). HVIT facilities at JSC and White Sands Test Facility (WSTF) use light gas guns, diagnostic tools, and high-speed imagery to quantify the response of spacecraft materials to MMOD impacts. Impact tests, with debris environment data provided by ODPO, are used by HVIT to predict risks to NASA and commercial spacecraft. HVIT directly serves NASA crew safety with MMOD risk assessments for each crewed mission and research into advanced shielding design for future missions. The Image Science and Analysis Group (ISAG) supports the International Space Station (ISS) and commercial spaceflight through the design of imagery acquisition schemes (ground- and vehicle-based) and imagery analyses for vehicle performance assessments and mission anomaly resolution. ISAG assists the Multi-Purpose Crew Vehicle (MPCV) Program in the development of camera systems for the Orion spacecraft that will serve as data sources for flight test objectives that lead to crewed missions. The multi-center Imagery Integration Team is led by the Human Exploration Science Office and provides expertise in the application of engineering imagery to spaceflight. The team links NASA programs and private industry with imagery capabilities developed and honed through decades of human spaceflight, including imagery integration, imaging assets, imagery data management, and photogrammetric analysis. The team is currently supporting several NASA programs, including commercial demonstration missions. The Earth Science and Remote Sensing Team is responsible for integrating the scientific use of Earth-observation assets onboard the ISS, which consist of externally mounted sensors and crew photography capabilities. This team facilitates collaboration on remote sensing and participates in research with academic organizations and other Government agencies, not only in conjunction with ISS science, but also for planetary exploration and regional environmental/geological studies. Human exploration science focuses on science strategies for future human exploration missions to the Moon, Mars, asteroids, and beyond. This function provides communication and coordination between the science community and mission planners. ARES scientists support the operation of robotic missions (i.e., Mars Exploration Rovers and the Mars Science Laboratory), contribute to the interpretation of returned mission data, and translate robotic mission technologies and techniques to human spaceflight.

Calhoun, Tracy A.↗

Fault Management Architectures and the Challenges of Providing Software Assurance

Fault Management (FM) is focused on safety, the preservation of assets, and maintaining the desired functionality of the system. How FM is implemented varies among missions. Common to most missions is system complexity due to a need to establish a multi-dimensional structure across hardware, software and spacecraft operations. FM is necessary to identify and respond to system faults, mitigate technical risks and ensure operational continuity. Generally, FM architecture, implementation, and software assurance efforts increase with mission complexity. Because FM is a systems engineering discipline with a distributed implementation, providing efficient and effective verification and validation (V&V) is challenging. A breakout session at the 2012 NASA Independent Verification & Validation (IV&V) Annual Workshop titled "V&V of Fault Management: Challenges and Successes" exposed this issue in terms of V&V for a representative set of architectures. NASA's Software Assurance Research Program (SARP) has provided funds to NASA IV&V to extend the work performed at the Workshop session in partnership with NASA's Jet Propulsion Laboratory (JPL). NASA IV&V will extract FM architectures across the IV&V portfolio and evaluate the data set, assess visibility for validation and test, and define software assurance methods that could be applied to the various architectures and designs. This SARP initiative focuses efforts on FM architectures from critical and complex projects within NASA. The identification of particular FM architectures and associated V&V/IV&V techniques provides a data set that can enable improved assurance that a system will adequately detect and respond to adverse conditions. Ultimately, results from this activity will be incorporated into the NASA Fault Management Handbook providing dissemination across NASA, other agencies and the space community. This paper discusses the approach taken to perform the evaluations and preliminary findings from the research.

Fault Management↗

A Process for Producing Highly Wettable Aluminum 6061 Surfaces Compatible with Hydrazine

NASA's Global Precipitation Measurement (GPM) mission is an ongoing Goddard Space Flight Center (GSFC) project whose basic objective is to improve global precipitation measurements. The space-based portion of the mission architecture consists of a primary or core spacecraft and a constellation of NASA and contributed spacecrafts. The efforts described in this paper refer to the core spacecraft (hereafter referred to as simply GPM) which is to be fabricated at GSFC. It has been decided that the GPM spacecraft is to be a "design-for-demise-spacecraft." This requirement resulted in the need for a propellant tank that would also demise or ablate to an appropriate degree upon re-entry. Composite overwrapped aluminum lined propellant tanks with aluminum propellant management devices (PMD) were shown by analyses to demise and thus became the baseline configuration for GPM. As part of the GPM tank development effort, long term compatibility and wettability testing with hydrazine was performed on Al6061 and 2219 coupons fabricated and cleaned by conventional processes. Long term compatibility was confirmed. However, the wettability of the aluminum as measured by contact angle produced higher than desired angles (greater than 30 deg.) with excessive scatter. The availability of PMD materials exhibiting consistently low contact angles aids in the design of simple PMDs. Two efforts performed by Angeles Crest Engineering and funded by GSFC were undertaken to reduce the risk of using aluminum for the GPM PMD. The goal of the first effort was to develop a cleaning or treatment process to produce consistently low contact angles. The goal of the second effort was to prove via testing that the processed aluminum would retain compatibility with hydrazine and retain low contact angle after long term exposure to hydrazine. Both goals were achieved. This paper describes both efforts and the results achieved.

Moore, N. R.↗

Gateway Modeling and Simulation Plan

This plan institutes direction across the Gateway Program and the Element Projects to ensure that Cross Program M&S are produced in a manner that (1) generate the artifacts required for NASA-STD-7009 compliance, (2) ensures interoperability of M&S exchanged and integrated across the program and, (3) drives integrated development efforts to provide cross-domain integrated simulation of the Gateway elements, space environment, and operational scenarios. This direction is flowed down via contractual enforcement to prime contractors and includes both the GMS requirements specified in this plan and the NASASTD- 7009 derived requirements necessary for compliance. Grounding principles for management of Gateway Models and Simulations (M&S) are derived from the Columbia Accident Investigation Board (CAIB) report and the Diaz team report, “A Renewed Commitment to Excellence.” As an outcome of these reports, and in response to Action 4 of the Diaz team report, the NASA Standard for Models and Simulations, NASA-STD-7009 was developed. The standard establishes M&S requirements for development and use activities to ensure proper capture and communication of M&S pedigree and credibility information to Gateway program decision makers. Through the course of the Gateway program life cycle M&S will be heavily relied upon to conduct analysis, test products, support operations activities, enable informed decision making and ultimately to certify the Gateway with an acceptable level of risk to crew and mission. To reduce risk associated with M&S influenced decisions, this plan applies the NASA-STD-7009 requirements to produce the artifacts that support credibility assessments and ensure the information is communicated to program management.

NASA-STD-7009↗

Cybersecurity for Distance Relay Protection

This project is a DOE follow-up effort on the CREDC workshop held on September 13, 2018 in Cambridge, MA to discuss cybersecurity of distance relays, which considered the benefits, vulnerabilities and risk mitigations for the use of communication systems in power system protection. The objectives of this project are to define the taxonomy of relay protection and associated communications; define use cases describing approaches to reduce the cyber-attack surface on those protective relays; and evaluate the loss of operational functional capability from changes to communication coverage. Mitigating controls will also be evaluated to understand if there are other approaches to reduce attack surfaces while maintaining communications or partial communications. Distance relays are used to protect transmission lines of approximately 10 to 300 miles in length, by detecting short circuits (i.e., faults) on the lines and then tripping circuit breakers in the substation. Such protection systems are a subset of the power system and they incorporate sensing, logic and communication functions. Protection system exposure to cyberattack could be drastically limited by disconnecting relays from all vulnerable communication systems, but this may adversely impact overall power system performance in the absence of cyberattack. This project began with a use case analysis of protection systems with communications, as summarized in this report. It continued with modeling, testing and evaluation in a miniature power system (MPS), located in the Western Area Power Administration (WAPA) Electric Power Training Center (EPTC). The project also incorporated feedback from two industry meetings held in February and September 2019. The suggested next steps account for and complement the work already underway with DOE/CESER funding: 1. Study the performance of LCD and PC vs. PUTT, which is less reliant on communication system performance and GPS timing references. The PUTT scheme could prove to be more resilient to cyberattack or communications-related disruption. It could also be more tolerant of message re-routing with SDN/SDR communication systems. On the other hand, it will be more vulnerable to false tripping during dynamic events or to loss of the voltage signal. The optimum choice of scheme may depend on the specific power system and risk assessment. This study could provide a new template for evaluation based on business functions. 2. Research and develop new methods to detect and monitor distributed physical attacks, possibly using drones, video sensors, thermal sensors, machine learning and other advanced techniques. This will help mitigate the impact of cyberattack on the protection system, and will also help mitigate the impact of wild fires. 3. Implement a scalable PKI for use in electric utility protection systems. This will encourage widespread adoption of secure authentication methods that are already available, but not widely used at present. This will help secure engineering access to the relays. 4. Investigate the use of SDN in combination with SDR to achieve better cybersecurity and electromagnetic security of the network, incorporating path variability. This would help secure both engineering access and peer-to-peer GOOSE messaging. 5. Perform additional testing, with operator evaluation of “red button” scenarios, PUTT vs. LCD, relay mis-operations, and other cyberattacks in the EPTC. This is an important advantage of testing in the EPTC rather than by computer simulation or even hardware-in-the-loop simulation; the EPTC is already dedicated to managing the situational awareness, operator response times and other human impacts. One of the project objectives was to settle on a common nomenclature for this problem space. We have concluded that the OSI layer model, supplemented by ANSI device numbers and other IEEE standards, is already well-accepted by the industry. The IEEE PSRC knowledge base provides a great deal of public information

24 POWER TRANSMISSION AND DISTRIBUTION↗