Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Contingency planning”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Contingency plans for the ISEE-3 libration-point mission

During the planning stage of the International Sun-Earth Explorer-3 (ISEE-3) mission, a recovery strategy was developed in case the Delta rocket underperformed during the launch phase. If a large underburn had occurred, the ISEE-3 spacecraft would have been allowed to complete one revolution of its highly elliptical earth orbit. The recovery plan called for a maneuver near perigee to increase the energy of the off-nominal orbit; a relatively small second maneuver would then insert the spacecraft into a new transfer trajectory toward the desired halo orbit target, and a third maneuver would place the spacecraft in the halo orbit. Results of the study showed that a large range of underburns could be corrected for a total nominal velocity deviation cost within the ISEE-3 fuel budget.

Dunham, D. W.↗

Guidelines for contingency planning NASA (National Aeronautics and Space Administration) ADP security risk reduction decision studies

Guidance is presented to NASA Computer Security Officials for determining the acceptability or unacceptability of ADP security risks based on the technical, operational and economic feasibility of potential safeguards. The risk management process is reviewed as a specialized application of the systems approach to problem solving and information systems analysis and design. Reporting the results of the risk reduction analysis to management is considered. Report formats for the risk reduction study are provided.

Tompkins, F. G.↗

Managing Variability: A Cognitive Ethnography of the Work of Airline Dispatchers

Airline dispatchers' workflow is often described in broad terms like 'flight planning' and 'flight following'. Such high-level descriptions fail to recognize the number and complexity of tasks involved in these activities. An ethnographic study was conducted at three US airlines to understand the cognitive workload involved in flight planning. Fuel planning was identified as one of five key flight planning tasks. Fuel planning was conducted concurrently with other planning and monitoring tasks which often led to interruptions. Planning fuel was dynamic, with recalculations required whenever other factors varied (e.g., payload, route, alternates). This rework increased workload and opportunities for error while reducing efficiency. Four main factors contributed variability to fuel planning: contingency planning, load planning, pilots, and station operations. Strategies for managing variability included pattern identification, use of buffers, rounding up, and leveraging software tools. Software design often added to workload by forcing dispatchers to attend to low level tasks.

dispatcher↗

Adaptive Planning: Understanding Organizational Workload to Capability/ Capacity through Modeling and Simulation

In August 2003, the Secretary of Defense (SECDEF) established the Adaptive Planning (AP) initiative [1] with an objective of reducing the time necessary to develop and revise Combatant Commander (COCOM) contingency plans and increase SECDEF plan visibility. In addition to reducing the traditional plan development timeline from twenty-four months to less than twelve months (with a goal of six months)[2], AP increased plan visibility to Department of Defense (DoD) leadership through In-Progress Reviews (IPRs). The IPR process, as well as the increased number of campaign and contingency plans COCOMs had to develop, increased the workload while the number of planners remained fixed. Several efforts from collaborative planning tools to streamlined processes were initiated to compensate for the increased workload enabling COCOMS to better meet shorter planning timelines. This paper examines the Joint Strategic Capabilities Plan (JSCP) directed contingency planning and staffing requirements assigned to a combatant commander staff through the lens of modeling and simulation. The dynamics of developing a COCOM plan are captured with an ExtendSim [3] simulation. The resulting analysis provides a quantifiable means by which to measure a combatant commander staffs workload associated with development and staffing JSCP [4] directed contingency plans with COCOM capability/capacity. Modeling and simulation bring significant opportunities in measuring the sensitivity of key variables in the assessment of workload to capability/capacity analysis. Gaining an understanding of the relationship between plan complexity, number of plans, planning processes, and number of planners with time required for plan development provides valuable information to DoD leadership. Through modeling and simulation AP leadership can gain greater insight in making key decisions on knowing where to best allocate scarce resources in an effort to meet DoD planning objectives.

Hase, Chris↗

Cassini's Grand Finale: A Mission Planning Retrospective

On September 15, 2017, Cassini plunged deep into Saturn, down to where the atmosphere was sufficiently dense to destroy the spacecraft, making it part of Saturn forever. In the five months leading up to its destruction, Cassini flew between Saturn and its rings 22 times, collecting data from the never before-explored region of the Kronian system. These orbits, the Grand Finale of Cassini, were the culmination of years of planning by the Cassini flight team. This paper looks back upon the mission planning effort in particular, comparing the baseline operational scenarios and contingency plans to the as flown Grand Finale. The bulk of the Grand Finale mission planning effort was focused on the environmental hazards present in the region between Saturn and its rings: the dust and the atmosphere. Dust hazard and atmospheric transit contingency plans were in place to help ensure spacecraft health and maximize science data return. The dust hazard plan gave the operations team the option to turn the spacecraft to a safe attitude during ring-plane crossings had the dust environment proved more threatening than anticipated. The atmospheric transit plan would have made use of an orbital trim maneuver in order to raise or lower periapsis depending on the density of the atmosphere. The proximal environment did have its surprises, though they were good surprises. The dust was significantly less hazardous than predicted. So much so that elements of the contingency plan were leveraged in order to remove a dust hazard protection from the baseline plan, rather than add one to it. While the atmosphere was substantially denser than predicted, it was not dense enough to warrant a periapsis-raise maneuver and actually meant that better in-situ data was gathered. Ultimately, from a mission planning perspective, the Grand Finale went better than expected.

Sturm II, Erick J.↗

A case study of a system engineered for control by humans

Alternatives to the traditional concepts for real time health and safety operations were examined. The pitfalls of the conventional contingency planning for health and safety are highlighted. The Solar Maximum Mission (SMM) contingency planning and operations provides the evolution from the conventional people intensive health and safety operation, toward a night watchman mode of operations. The SMM spacecraft health and safety operations were budget constrained to the point that one operator was responsible for the health and safety of the entire spacecraft one week after launch. The spacecraft was a protoflight with brand new subsystem configurations, software and procedures. To manage the risks associated with this one man SMM health and safety operation, the real time contingency planning and operations centered around unambiguously identifying a system level problem, and reactively safing components susceptible to unrecoverable damage. The methodology applied to both analyzing and implementing this approach of SMM is shown.

Rothenberg, J.↗

Expected Utility Distributions for Flexible, Contingent Execution

This paper presents a method for using expected utility distributions in the execution of flexible, contingent plans. A utility distribution maps the possible start times of an action to the expected utility of the plan suffix starting with that action. The contingent plan encodes a tree of possible courses of action and includes flexible temporal constraints and resource constraints. When execution reaches a branch point, the eligible option with the highest expected utility at that point in time is selected. The utility distributions make this selection sensitive to the runtime context, yet still efficient. Our approach uses predictions of action duration uncertainty as well as expectations of resource usage and availability to determine when an action can execute and with what probability. Execution windows and probabilities inevitably change as execution proceeds, but such changes do not invalidate the cached utility distributions, thus, dynamic updating of utility information is minimized.

Bresina, John L.↗

Launching and Deploying the James Webb Space Telescope

On December 25, 2021, at 12:20 UTC, the James Webb Space Telescope lifted off and onward to its destination in orbit at the second Lagrange point. With more than two decades in development, and an international collaboration between NASA, CSA, and ESA, Webb is one of the most anticipated science missions ever launched. After a dramatic and flawless launch, Webb's toughest and riskiest days lie ahead. Unprecedented in its complexity and ambition, over the next two weeks Webb would undergo the most complex on-orbit deployment sequence ever attempted, with any single deployment anomaly carrying the risk of full mission failure. An exquisite design, years of ground testing, a exhaustively trained and rehearsed operations and engineering team, and an unprecedented level of contingency planning, all resulted in a fully and successfully deployed Webb observatory, on its way to L2, and nominally cooling to its cryogenic temperatures. Although Webb still had many more months of commissioning left, there was a collective sigh of relief heard round the world. This incredible achievement was not by chance but was years in the making. We go behind the scenes of Webb's first month on orbit, starting with the unique and challenging launch itself, the time criticality of its mid-course corrections, and a summary of nearly 14 days to undergo nearly 50 major deployments. We discuss what went better than planned and how years of robust and detailed contingency planning were prepared for unanticipated events and on-orbit spacecraft behavior. And finally, we provide a brief overview of the entire commissioning process which successfully completed on July 10th, 2022.

Keith A Parrish↗

Virtualization - A Key Cost Saver in NASA Multi-Mission Ground System Architecture

With science team budgets being slashed, and a lack of adequate facilities for science payload teams to operate their instruments, there is a strong need for innovative new ground systems that are able to provide necessary levels of capability processing power, system availability and redundancy while maintaining a small footprint in terms of physical space, power utilization and cooling.The ground system architecture being presented is based off of heritage from several other projects currently in development or operations at Goddard, but was designed and built specifically to meet the needs of the Science and Planetary Operations Control Center (SPOCC) as a low-cost payload command, control, planning and analysis operations center. However, this SPOCC architecture was designed to be generic enough to be re-used partially or in whole by other labs and missions (since its inception that has already happened in several cases!)The SPOCC architecture leverages a highly available VMware-based virtualization cluster with shared SAS Direct-Attached Storage (DAS) to provide an extremely high-performing, low-power-utilization and small-footprint compute environment that provides Virtual Machine resources shared among the various tenant missions in the SPOCC. The storage is also expandable, allowing future missions to chain up to 7 additional 2U chassis of storage at an extremely competitive cost if they require additional archive or virtual machine storage space.The software architecture provides a fully-redundant GMSEC-based message bus architecture based on the ActiveMQ middleware to track all health and safety status within the SPOCC ground system. All virtual machines utilize the GMSEC system agents to report system host health over the GMSEC bus, and spacecraft payload health is monitored using the Hammers Integrated Test and Operations System (ITOS) Galaxy Telemetry and Command (TC) system, which performs near-real-time limit checking and data processing on the downlinked data stream and injects messages into the GMSEC bus that are monitored to automatically page the on-call operator or Systems Administrator (SA) when an off-nominal condition is detected. This architecture, like the LTSP thin clients, are shared across all tenant missions.Other required IT security controls are implemented at the ground system level, including physical access controls, logical system-level authentication authorization management, auditing and reporting, network management and a NIST 800-53 FISMA-Moderate IT Security plan Risk Assessment Contingency Plan, helping multiple missions share the cost of compliance with agency-mandated directives.The SPOCC architecture provides science payload control centers and backup mission operations centers with a cost-effective, standardized approach to virtualizing and monitoring resources that were traditionally multiple racks full of physical machines. The increased agility in deploying new virtual systems and thin client workstations can provide significant savings in personnel costs for maintaining the ground system. The cost savings in procurement, power, rack footprint and cooling as well as the shared multi-mission design greatly reduces upfront cost for missions moving into the facility. Overall, the authors hope that this architecture will become a model for how future NASA operations centers are constructed!

Ground System Architecture↗

Dawn Spacecraft Performance at Ceres: Results of Hybrid Control for Ceres Mapping

Dawn is a low-thrust interplanetary spacecraft currently orbiting the dwarf planet Ceres, to better understand the early creation of the solar system. Launched in September 2007, Dawn arrived at Vesta in July 2011. After a 16-month successful science campaign at Vesta, Dawn departed for Ceres, arriving in early 2015. The Dawn spacecraft uses both reaction wheel assemblies (RWA) and a reaction control system (RCS) to provide 3-axis attitude control for the spacecraft. Reaction wheels were designed to be the primary system for attitude control, however two wheels have shown high friction anomalies and have been removed from service. The project has implemented a hybrid control algorithm using two reaction wheels and RCS thrusters. This hybrid control capability enabled Dawn to achieve very high science return, while significantly conserving remaining hydrazine propellant. With only two remaining healthy RWA’s, hybrid control became part of the baseline plan for Ceres science operations. The Dawn team developed specific operational approaches in which sequences were developed with careful consideration of science versus resource trades. Commanding and sequence planning also incorporated contingency planning, in the event that another reaction wheel may fail. Despite the differences in operational approach between Vesta and Ceres, both campaigns achieved very rich scientific data return. This paper highlights Dawn’s recent flight experience with hybrid attitude control during Ceres orbit operations. The discussion includes the approaches utilized by the Dawn team to address unique operational challenges presented by the hybrid approach, and reviews spacecraft performance under hybrid control in low orbit at Ceres. Additionally, methods used to optimize hydrazine use and thereby extend the science campaign will be presented. Finally, a preliminary assessment of an orbit transfer with two reaction wheels, during extended mission operations, is discussed.

Smith, Brett A.↗

Validation of Fault-Tolerant Plans for Europa Clipper

The Europa Clipper mission will explore that icy moon in a series of brief flybys through the Jovian radiation belts. A single event upset in the spacecraft flight computer during these critical scientific periods could jeopardize the success of the mission. Rather than safing and awaiting operator intervention, the Clipper mission envisions limited onboard autonomy that can restore spacecraft state sufficiently to resume the encounter observation plan as rapidly as possible. The contingency plan is contained in an Activity Restart Timeline (ART) that is transmitted in parallel with the nominal plan, which must be co-validated jointly against all spacecraft state and resource constraints amid unpredictable fault timing. A prototype validation tool was built that leverages declarative spacecraft models and automated search techniques to find such potential inconsistencies in the unified contingent mission plan. Early validation results within motivating scenarios are presented.

Ferguson, Eric↗

Deep Learning-Based Negotiation Strategy Selection for Cooperative Conflict Resolution in Urban Air Mobility

This paper presents a collaborative conflict resolution technique using deep neural network-based intelligent search of the solution space. This approach offers a rapid convergence to a mutually acceptable solution for real-time conflict resolution, suitable for urban air mobility operations. Furthermore, the presented technique allows operational flexibility to the urban air mobility agents where these agents can collaboratively devise the solution via integrative negotiation, based on their local utility functions, as long as such a solution does not violate the global safety thresholds. The presented machine-to-machine negotiation method is built on our prior work on holistic assessment of the airspace and potential conflict detection implemented at-the-edge, onboard the unmanned aircraft systems. This paper extends the prior work to augment decision-making at-the-edge, thereby, promising a true distributed control architecture for urban air mobility. In this approach, each agent (a) builds a potential in-flight conflict map, (b) identifies the conflicting agents, (c) dynamically prepares a list of alternatives based on its current utility functions, (d) negotiates with the conflicting agents to pick one of these alternatives, and (e) implements the negotiated alternative to mutually resolve the conflict. Note that such an approach does not require a contingency plan to be made pre-flight, as the conflict resolution strategies are decided and negotiated in real time based on the present state of the agent. The contingency plan, if available, can serve as an input to the real-time conflict resolution strategy formulation, and also can be used as a fallback plan in case the negotiation fails and the impacted agents need to switch to a rule-based/supervisory resolution mode from the discussed distributed resolution mode. The presented collaborative negotiation-based conflict resolution technique incorporates a time-dependent reward function to catalyze collaborative resolution by incentivizing the agents with local and global rewards beneficial to their business operations.

Advanced Air Mobility↗

IMPACT 1.0—Task Impairment: A Novel Approach for Assessing Impairment during Exploration-Class Missions

Exploration-class and International Space Station (ISS) missions have significantly different levels of associated medical risk for crewmembers. The Integrated Medical Model (IMM), the probabilistic risk assessment tool used for ISS medical trade-space analyses, uses a Functional Impairment (FI) metric to determine quality time lost should a crewmember be afflicted with a medical condition. While IMM-based FI has been successful for ISS operations, it has limitations when applied to exploration-class missions. As the National Aeronautics and Space Administration (NASA) looks ahead to Gateway, Artemis, and Martian missions, a novel, dynamic, and mission-appropriate impairment paradigm is necessary for accurate contingency planning. This paradigm, Task Impairment (TI), fulfills that need by utilizing mission-specific tasks. TI will allow future capability for a loss of mission metric, previously not available with IMM. TI serves as a replacement metric for FI within IMPACT, the next-generation trade-space analysis tool suite created to replace the IMM. IMPACT significantly increases the fidelity of probabilistic risk assessment for exploration-class missions. The Human Exploration of Mars Preliminary List of Crew Tasks (MTL, a source of 1100+ exploration-class mission-specific tasks for crewmembers) was used to calculate TI. Using the Task List, 18 individual Human System Categories were identified as being required to perform each task (e.g., Cardiopulmonary, Cognitive, etc.). Each of the 1200+ tasks were mapped to the Human System categories listed in the Task List. The total number of tasks in each category were tallied to determine how many tasks required each Human System. Lastly, each of the 120 medical conditions from the IMPACT condition list were mapped to the Human System categories to complete the TI calculation. NASA subject matter experts across five medical specialties established consensus for the mapping of each condition. The resulting total tasks impaired by each condition were used to calculate discrete TI values. This process was repeated for each of the four severity/resource utilization variants of each condition, and for each of the three phases of clinical care. Through this process, discrete TI values were calculated for each of the 120 IMPACT medical conditions and their variants. The Task Impairment metric provides higher fidelity, dynamic utility, and quicker analysis of medical impairment compared to the previous Functional Impairment metric used for the Integrated Medical Model. TI will be used for higher fidelity medical impairment analysis and contingency planning during Lunar, Martian, and other long-term exploration-class missions.

William L Fernandez↗

Antarctic Exploration Parallels for Future Human Planetary Exploration: A Workshop Report

Four Antarctic explorers were invited to a workshop at Johnson Space Center (JSC) to provide expert assessments of NASA's current understanding of future human exploration missions beyond low Earth orbit. These explorers had been on relatively sophisticated, extensive Antarctic expeditions with sparse or nonexistent support infrastructure in the period following World War II through the end of the International Geophysical Year. Their experience was similar to that predicted for early Mars or other planetary exploration missions. For example: one Antarctic a expedition lasted two years with only one planned resupply mission and contingency plans for no resupply missions should sea ice prevent a ship from reaching them; several traverses across Antarctica measured more than 1000 total miles, required several months to complete, and were made without maps (because they did not exist) and with only a few aerial photos of the route; and the crews of six to 15 were often international in composition. At JSC, the explorers were given tours of development, training, and scientific facilities, as well as documentation at operational scenarios for future planetary exploration. This report records their observations about these facilities and plans in answers to a series of questions provided to them before the workshop.

Hoffman, Stephen J.↗

OSIRIS-REx Off-Nominal Re-entry Breakup Analysis

The Origins, Spectral Interpretation, Resource Identification, Security, Regolith Explorer (OSIRIS-REx) is a NASA asteroid sampling mission that launched on September 8, 2016. Its objectives are to study the asteroid Bennu for up to 505 days and obtain at least 60 grams of pristine regolith. The sample return to Earth is planned for September 2023. For contingency planning and risk assessment of a potential off-nominal Earth-return trajectory, a re-entry breakup analysis was performed to determine the response of the spacecraft to the environment and predict the breakup sequence and timeline, debris survival, and debris impact conditions. The failure scenario assumed a failure to separate between the bus and the sample return capsule (SRC), resulting in the combined bus+SRC configuration for the re-entry vehicle. Furthermore, consistent overburns or underburns were considered to produce three sets of initial conditions for the analysis consisting of nominal, steep, and shallow entry flight path angles. The results were compared to the breakup analysis performed for a similar vehicle, the Stardust spacecraft, which returned samples from the comet Wild 2 in 2006. This paper describes the OSIRIS-REx spacecraft and presents the results of the re-entry breakup analysis.

reentry breakup analysis↗