Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Error Resilience”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

50 records · Page 3

Identifying Outside Influences as Latent Factors to Risk in Human Performance

During the Acquisition Life Cycle for a program, there are several opportunities for the system in design to be adjusted in accordance with its changing landscape as it is being shaped by evolving policy and organizational culture. Human Systems Integration is integral to identifying these opportunities of change as there are a set number of activities that may account for altered operational states, human performance deviations, and overall component engagement if HSI is enacted early enough in the life cycle. Some changes that occur in the operational environment may not be accounted for since the organizational culture and practices are not currently a part of the HSI focus. Likewise, policy changes themselves from a top-to-bottom analysis may not have the appearance of effecting human performance until having gone through a trail-and-error period. Workarounds to adjust for unforeseen policy affects become the system's solution that usually includes changes in the training and education of the operators, maintainers, and support personnel. A system full of workarounds and off-normal practices, that cause operators to disregard the purpose of the design, coupled with the false notion that these activities are proven for successful system operation, is the very definition of “an accident waiting to happen”. Unforeseen changes in policies and practices that cause new and unusual activities to successfully and keep the system running, should be considered latent factors that may cause a potential mishap, and not part of the resilience that humans provide to the successful operation of the system. This presentation will explore how latent factors may find their way into system operations and how they can be identified and addressed.

Human Systems Integration↗

Modeling Global Indices for Estimating Non-Photosynthetic Vegetation Cover

Non-photosynthetic vegetation (NPV) includes plant litter, senesced leaves, and crop residues. NPV plays an essential role in terrestrial ecosystem processes, and is an important indicator of drought severity, ecosystem disturbance, agricultural resilience, and wildfire danger. Current moderate spatial resolution multispectral satellite systems (e.g., Landsat and Sentinel-2) have only a single band in the 2000–2500 nm shortwave infrared “SWIR2” range where non-pigment biochemical constituents of NPV, including cellulose and lignin, have important spectral absorption features. Thus, these current systems have suboptimal capabilities for characterizing NPV cover. This research used simulated spectral mixtures accounting for variability among NPV and soils to evaluate globally-appropriate hyperspectral and multispectral indices for estimation of fractional NPV cover. The Continuum Interpolated NPV Depth Index (CINDI), a weighted ratio index measuring lignocellulose absorption near 2100 nm, was found to produce the lowest error in estimating NPV cover. CINDI was less sensitive to variability in soil spectra and green vegetation cover than competing indices. While CINDI was sensitive to the relative water content of soil and NPV, this sensitivity allowed for correcting error in estimated NPV cover as water content increased. CINDI bands were less capable than Dual Absorption NPV Index (DANI) bands for maintaining continuity with the heritage Landsat SWIR2 band, but combining multiple CINDI bands demonstrated adequate continuity. Three SWIR2 bands with band centers at 2038, 2108, and 2211 nm can provide superior capabilities for future moderate resolution multispectral/superspectral systems targeting NPV monitoring, including the next generation Landsat mission (Landsat Next). These bands and the associated CINDI index provide potential for global NPV monitoring using a constellation of future superspectral sensors and imaging spectrometers, with applications including improving soil management, preventing land degradation, evaluating impacts of drought, mapping ecosystem disturbance, and assessing wildfire danger.

Index optimization↗

Human Performance Contributions to Safety in Commercial Aviation

Every day in aviation, pilots, air traffic controllers, and other front-line personnel perform countless correct judgments and actions in a variety of operational environments. These judgments and actions are often the difference between an accident and a non-event. Ironically, data on these behaviors are rarely collected or analyzed. Data-driven decisions about safety management and design of safety-critical systems are limited by the available data, which influence how decision makers characterize problems and identify solutions. Large volumes of data are collected on the failures and errors that result in infrequent incidents and accidents, but in the absence of data on behaviors that result in routine successful outcomes, safety management and system design decisions are based on a small sample of nonrepresentative safety data. This assessment aimed to find and document “safety successes” made possible by human operators. With many Aeronautics Research Mission Directorate (ARMD) Programs and Projects focusing on increased automation and autonomy and decreased human involvement, failure to fully consider the human contributions to successful system performance in civil aviation represents a significant risk — a risk that has not been recognized to date. Without understanding how humans contribute to safety, any estimate of predicted safety of autonomous capabilities is incomplete and inherently suspect. Furthermore, understanding the ways in which humans contribute to safety can promote strategic interactions among safety technologies, functions, procedures and the people using them. Without this understanding, the full benefits of an integrated, optimized human/technology or autonomous system will not be realized. Historically, safety has been consistently defined in terms of the occurrence of accidents or recognized risks (i.e., in terms of things that go wrong). These adverse outcomes are explained by identifying their causes, and safety is restored by eliminating or mitigating these causes. An alternative to this approach is to focus on what goes right and identify how to replicate that process. Focusing on the rare cases of failures attributed to “human error” provides little information about why human performance routinely prevents adverse events. Hollnagel has proposed that things go right because people continuously adjust their work to match their operating conditions. These adjustments become increasingly important as systems continue to grow in complexity. Thus, the definition of safety should reflect not only “avoiding things that go wrong” but “ensuring that things go right.” The basis for safety management requires developing an understanding of everyday activities. However, few mechanisms to monitor everyday work exist in the aviation domain, which limits opportunities to learn how designs function in reality. This concept of safety thinking and safety management is reflected in the emerging field of resilience engineering. According to Hollnagel, a system is resilient if it can sustain required operations under expected and unexpected conditions by adjusting its functioning prior to, during, or following changes, disturbances, and opportunities. To explore “positive” behaviors that contribute to resilient performance in commercial aviation, the assessment team examined a range of existing sources of data about pilot and air traffic control (ATC) tower controller performance, including subjective interviews with domain experts and objective aircraft flight data records. These data were used to identify strategies that support resilient performance, methods for exploring and refining those strategies in existing data, and proposed methods for capturing and analyzing new data.

Null, Cynthia H.↗

The Cognitive Challenges of Flying a Remotely Piloted Aircraft

A large variety of Remotely Piloted Aircraft (RPA) designs are currently in production or in development. These aircraft range from small electric quadcopters that are flown close to the ground within visual range of the operator, to larger systems capable of extended flight in airspace shared with conventional aircraft. Before RPA can operate routinely and safely in civilian airspace, we need to understand the unique human factors associated with these aircraft. The task of flying an RPA in civilian airspace involves challenges common to the operation of other highly-automated systems, but also introduces new considerations for pilot perception, decision-making, and action execution. RPA pilots participated in focus groups where they were asked to recall critical incidents that either presented a threat to safety, or highlighted a case where the pilot contributed to system resilience or mission success. Ninety incidents were gathered from focus-groups. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies. Some of these concerns have received significant attention in the literature, or are analogous to human factors of manned aircraft. The presentation will focus on issues that are poorly understood, and have not yet been the subject of extensive human factors study. Although many of the reported incidents were related to pilot error, the participants also provided examples of the positive contribution that humans make to the operation of highly-automated systems.

remote pilot station↗

Optimization of Second Fault Detection Thresholds to Maximize Mission Probability of Success

In order to support manned spaceflight safety requirements, the Space Launch System (SLS) has defined program-level requirements for key systems to ensure successful operation under single fault conditions. The SLS program has also levied requirements relating to the capability of the Inertial Navigation System to detect a second fault. This detection functionality is required in order to feed abort analysis and ensure crew safety. Increases in navigation state error due to sensor faults in a purely inertial system can drive the vehicle outside of its operational as-designed environmental and performance envelope. As this performance outside of first fault detections is defined and controlled at the vehicle level, it allows for the use of system level margins to increase probability of mission success on the operational edges of the design. A top-down approach is utilized to assess vehicle sensitivity to second sensor faults. A wide range of failure scenarios in terms of both fault magnitude and time is used for assessment. The approach also utilizes a schedule to change fault detection thresholds autonomously. These individual values are optimized along a nominal trajectory in order to maximize probability of mission success in terms of system-level insertion requirements while minimizing the probability of false positives. This paper will describe an approach integrating Genetic Algorithms and Monte Carlo analysis to tune the threshold parameters to maximize vehicle resilience to second fault events over an ascent mission profile. The analysis approach and performance assessment and verification will be presented to demonstrate the applicability of this approach to second fault detection optimization to maximize mission probability of success through taking advantage of existing margin.

Anzalone, Evan J.↗

Calculating and Mitigating the Risk of a Cut Glove to a Space Walking Astronaut

One of the high risk operations on the International Space Station (ISS) is conducting a space walk, or an Extra Vehicular Activity (EVA). Threats to the space walking crew include airlock failures, space suit failures, and strikes from micro ]meteoroids and orbital debris (MM/OD). There are risks of becoming untethered from the space station, being pinched between the robotic arm and a piece of equipment, tearing your suit on a sharp edge, and other human errors that can be catastrophic. For decades NASA identified and tried to control sharp edges on external structure and equipment by design; however a new and unexpected source of sharp edges has since become apparent. Until recently, one of the underappreciated environmental risks was damage to EVA gloves during a spacewalk. The ISS has some elements which have been flying in the environment of space for over 14 years. It has and continues to be bombarded with MM/OD strikes that have created small, sharp craters all over the structure, including the dedicated EVA handrails and surrounding structure. These craters are capable of cutting through several layers of the EVA gloves. Starting in 2006, five EVA crewmembers reported cuts in their gloves so large they rendered the gloves unusable and in some cases cut the spacewalk short for the safety of the crew. This new hazard took engineers and managers by surprise. NASA has set out to mitigate this risk to safety and operations by redesigning the spacesuit gloves to be more resilient and designing a clamp to isolate MM/OD strikes on handrails, and is considering the necessity of an additional tool to repair strikes on non ]handrail surfaces (such as a file). This paper will address how the ISS Risk Team quantified an estimate of the MM/OD damage to the ISS, and the resulting likelihood of sustaining a cut glove in order to measure the effectiveness of the solutions being investigated to mitigate this risk to the mission and crew.

Castillo, Theresa↗

Health Management and Prognostics for Electric Aircraft Powertrain

W and c Any air borne vehicle needs incorporating safety as key parameter of measure, and inclusion of autonomy raises the critical need for safety under autonomous operations. Management of faults and component degradation is key as complexity in autonomous operations grow over the period of time. Therefore, in addition to basic operational requirements, an autonomous electric vehicle should be able to make accurate estimates of its current system health and take the correct decisions to complete its mission successfully. Real-time safety and state-awareness tools are therefore essential for the vehicle to be able to reach its destination in a safe and successful manner. The need for safety assurance and health management capabilities is particularly relevant for aircraft electric propulsion systems, which are relatively new and with limited historical to learn. They are critical systems requiring high power density along with reliability, resilience, efficient management of weight, and operational costs. A model- based fault diagnosis and prognostics approach of complex critical systems can successfully accomplish the safety and state awareness goal for such electric propulsion systems, enabling autonomous decision making capability for safe and efficient operation. To identify critical components in the system a Qualitative Bayesian approach using FMECA is implemented. This requires the assessment of some quantities representing the state of the electric unmanned aerial systems (e-UAS), as well as look-ahead forecasts of such states during the entire flight, presented in form of safety metrics (SM). In-service data and performance data gathered from degraded components sup- ports diagnostic and prognostic methods for these systems, but this data can be difficult to obtain as weight and packaging restrictions reduce redundancy and instrumentation on-board the vehicle. Therefore, an model-based framework should be capable or operating with limited data. In addition to data scarcity, the variability of such complex critical systems re- quires the model-based framework to reason in the presence of uncertainty, such as sensor noise, and modeling imperfections. Quantification of errors and uncertainties in the measured states and quantities is therefore a fundamental step for a precise estimation of such SMs; un-modeled uncertainty may result in erroneous state assessment and un- reliable predictions of future states of e-UAVs. Typical, centralized model-based schemes suffer from inherent disadvantages such as computational complexity, single point of failure, and scalability issues, and therefore may fail in such a complex scenario. This paper presents a methodology for developing a system level diagnostics and prognostics approach using a Qualitative Bayesian FMECA approach along with a formal uncertainty management framework for an e-UAS. In this work we demonstrate the efficacy of the framework to predict effects of sub-system level degradation on vehicle operation incorporating uncertainty management to predict future behavior under different operating conditions.

Kulkarni, Chetan↗

Optimization of Second Fault Detection Thresholds to Maximize Mission POS

In order to support manned spaceflight safety requirements, the Space Launch System (SLS) has defined program-level requirements for key systems to ensure successful operation under single fault conditions. To accommodate this with regards to Navigation, the SLS utilizes an internally redundant Inertial Navigation System (INS) with built-in capability to detect, isolate, and recover from first failure conditions and still maintain adherence to performance requirements. The unit utilizes multiple hardware- and software-level techniques to enable detection, isolation, and recovery from these events in terms of its built-in Fault Detection, Isolation, and Recovery (FDIR) algorithms. Successful operation is defined in terms of sufficient navigation accuracy at insertion while operating under worst case single sensor outages (gyroscope and accelerometer faults at launch). In addition to first fault detection and recovery, the SLS program has also levied requirements relating to the capability of the INS to detect a second fault, tracking any unacceptable uncertainty in knowledge of the vehicle's state. This detection functionality is required in order to feed abort analysis and ensure crew safety. Increases in navigation state error and sensor faults can drive the vehicle outside of its operational as-designed environments and outside of its performance envelope causing loss of mission, or worse, loss of crew. The criteria for operation under second faults allows for a larger set of achievable missions in terms of potential fault conditions, due to the INS operating at the edge of its capability. As this performance is defined and controlled at the vehicle level, it allows for the use of system level margins to increase probability of mission success on the operational edges of the design space. Due to the implications of the vehicle response to abort conditions (such as a potentially failed INS), it is important to consider a wide range of failure scenarios in terms of both magnitude and time. As such, the Navigation team is taking advantage of the INS's capability to schedule and change fault detection thresholds in flight. These values are optimized along a nominal trajectory in order to maximize probability of mission success, and reducing the probability of false positives (defined as when the INS would report a second fault condition resulting in loss of mission, but the vehicle would still meet insertion requirements within system-level margins). This paper will describe an optimization approach using Genetic Algorithms to tune the threshold parameters to maximize vehicle resilience to second fault events as a function of potential fault magnitude and time of fault over an ascent mission profile. The analysis approach, and performance assessment of the results will be presented to demonstrate the applicability of this process to second fault detection to maximize mission probability of success.

Anzalone, Evan↗

Pilot Critical Incident Reports as a Means to Identify Human Factors of Remotely Piloted Aircraft

It has been estimated that aviation accidents are typically preceded by numerous minor incidents arising from the same causal factors that ultimately produced the accident. Accident databases provide in-depth information on a relatively small number of occurrences, however incident databases have the potential to provide insights into the human factors of Remotely Piloted Aircraft System (RPAS) operations based on a larger volume of less-detailed reports. Currently, there is a lack of incident data dealing with the human factors of unmanned aircraft systems. An exploratory study is being conducted to examine the feasibility of collecting voluntary critical incident reports from RPAS pilots. Twenty-three experienced RPAS pilots volunteered to participate in focus groups in which they described critical incidents from their own experience. Participants were asked to recall (1) incidents that revealed a system flaw, or (2) highlighted a case where the human operator contributed to system resilience or mission success. Participants were asked to only report incidents that could be included in a public document. During each focus group session, a note taker produced a de-identified written record of the incident narratives. At the end of the session, participants reviewed each written incident report, and made edits and corrections as necessary. The incidents were later analyzed to identify contributing factors, with a focus on design issues that either hindered or assisted the pilot during the events. A total of 90 incidents were reported. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies. Pilots participated willingly and enthusiastically in the study, and generally had little difficulty recalling critical incidents. The results suggest that pilot interviews can be a productive method of gathering information on incidents that might not otherwise be reported. Some of the issues described in the reports have received significant attention in the literature, or are analogous to human factors of manned aircraft. In other cases, incident reports involved human factors that are poorly understood, and have not yet been the subject of extensive study. Although many of the reported incidents were related to pilot error, the participants also provided examples of the positive contribution that humans make to the operation of highly-automated systems.

unmanned aircraft systems↗

Exploring Methods to Collect and Analyze Data on Human Contributions to Aviation Safety: A Panel Discussion

Focusing on undesired operator behaviors is pervasive in system design and safety management cultures in aviation. This focus limits the data that are collected, the questions that are asked during data analysis, and therefore our understanding of what operators do in everyday work. Human performance represents a significant source of aviation safety data that includes both desired and undesired actions. When safety is characterized only in terms of errors and failures, the vast majority of human impacts on system safety and performance are ignored. The outcomes of safety data analyses dictate what is learned from those data, which in turn informs safety policies and safety-related decision making. When learning opportunities are systematically restricted by focusing only on rare failure events, not only do we learn less (and less often), but we can draw misleading conclusions by relying on a non-representative sample of human performance data. Changes in how we define and think about safety can highlight new opportunities for collection and analysis of safety-relevant data. Developing an integrated safety picture to better inform safety-related decision making and policies depends upon identifying, collecting, and interpreting safety-producing behaviors in addition to safety-reducing behaviors. Opportunities and challenges in collecting and analyzing the largely unexploited data on desired, safety-producing operator behaviors are discussed.

Aviation Safety↗

Exploring Methods to Collect and Analyze Data on Human Contributions to Aviation Safety: A Panel Discussion

Focusing on undesired operator behaviors is pervasive in system design and safety management cultures in aviation. This focus limits the data that are collected, the questions that are asked during data analysis, and therefore our understanding of what operators do in everyday work. Human performance represents a significant source of aviation safety data that includes both desired and undesired actions. When safety is characterized only in terms of errors and failures, the vast majority of human impacts on system safety and performance are ignored. The outcomes of safety data analyses dictate what is learned from those data, which in turn informs safety policies and safety-related decision making. When learning opportunities are systematically restricted by focusing only on rare failure events, not only do we learn less (and less often), but we can draw misleading conclusions by relying on a non-representative sample of human performance data. Changes in how we define and think about safety can highlight new opportunities for collection and analysis of safety-relevant data. Developing an integrated safety picture to better inform safety-related decision making and policies depends upon identifying, collecting, and interpreting safety producing behaviors in addition to safety reducing behaviors. The panel will discuss opportunities and challenges in collecting and analyzing the largely unexploited data on desired, safety-producing operator behaviors.

aviation safety↗

Earth Independent Medical Operations (EIMO) Datascope: Challenges and Potential Solutions

Data flows and storage/retrieval capacity are severely constrained during missions in space and challenges will become even greater during exploration class missions. There is a need for an artificial intelligence (AI)-based clinical decision support system (CDSS) to monitor and analyze data to provide real-time consultative support for crew medical officer (CMO) decision-making. EIMO is defined as the gradual transition of medical care and decision making from terrestrial to space-based assets, enabling support of astronaut health and performance and reducing overall mission risk. While a hallmark of this paradigm shift from low-earth orbit is that on-board care will increasingly become the responsibility of the astronauts for primary management and decision making, terrestrial assets will continue to be paramount in pre-mission screening and planning, as well as prevention, health maintenance and long-term care contingencies. New capabilities and systems that enable progressively more robust and resilient systems and crews will be necessary to reduce risk and increase probability of deep space exploration mission success. An aspiration for EIMO is to develop AI-enhanced solutions for analysis of crew health & performance data and to facilitate clinical decision support for autonomous medical operations. A “system of systems” approach is envisioned whereby EIMO will deploy AI-supported natural language processing and machine learning (ML) techniques to utilize embedded reference databases and real-time data streams [input vectors] from multiple data sources. Constituent input vectors may include environmental controls, countermeasures data, behavioral data, physiologic wearables, point-of-care laboratory tests, personalized medical records, inventory trade space risk assessments, COTS medical databases, and ground support inputs. An ideal AI capability would possess trained fusion algorithms to cross reference input vectors with medical ‘knowledge’ [cultivated database] to stratify relevant data streams for predictive and actionable capabilities. In addition, EIMO will feature mobility, in that it can be accessed and can push/pull data within and between multiple vehicles/habitats. Large amounts and variable sources of data can be leveraged to diagnose, inform treatment strategies, and potentially predict medical events and performance decrements. Inclusion of advanced training tools using extended reality will enable increasingly autonomous medical care to aid a CMO when ground support is unavailable or time-delayed beyond required action window, e.g., emergent medical situations. EIMO CDSS would require very large datasets to train pre-flight and significant amounts of data are needed to support ML via in-flight CDSS operations. An additional challenge will be to find sufficient data to train a model relevant to astronaut demographics. The rapid, accelerating evolution of this field creates a propitious solution space to leverage multi-modal AI through public-private partnership(s). The status of multi-modal AI systems today would preclude their use for long duration missions as they remain unreliable and are subject to “digital hallucinations” and other errors that could pose operational risk. A federated labs structure is being considered to test and optimize data flow from the multiple input vectors leading to field testing in suitable ground/flight analogs. Critical to the success of an EIMO CDSS will be integration and interoperability and success will be defined by a system that can serve as an in-flight medical consult for the CMO providing critical support during medical contingencies. Benefits to terrestrial medicine may be significant as an outflow of the EIMO medical system, particularly for remote areas and communities lacking significant infrastructure, personnel and resources.

J Lemery↗

Earth Independent Medical Operations (EIMO) Datascope: Challenges and Potential Solutions

Data flows and storage/retrieval capacity are severely constrained during missions in space and challenges will become even greater during exploration class missions. There is a need for an artificial intelligence (AI)-based clinical decision support system (CDSS) to monitor and analyze data to provide real-time consultative support for crew medical officer (CMO) decision-making. EIMO is defined as the gradual transition of medical care and decision making from terrestrial to space-based assets, enabling support of astronaut health and performance and reducing overall mission risk. While a hallmark of this paradigm shift from low-earth orbit is that on-board care will increasingly become the responsibility of the astronauts for primary management and decision making, terrestrial assets will continue to be paramount in pre-mission screening and planning, as well as prevention, health maintenance and long-term care contingencies. New capabilities and systems that enable progressively more robust and resilient systems and crews will be necessary to reduce risk and increase probability of deep space exploration mission success. An aspiration for EIMO is to develop AI-enhanced solutions for analysis of crew health & performance data and to facilitate clinical decision support for autonomous medical operations. A “system of systems” approach is envisioned whereby EIMO will deploy AI-supported natural language processing and machine learning (ML) techniques to utilize embedded reference databases and real-time data streams [input vectors] from multiple data sources. Constituent input vectors may include environmental controls, countermeasures data, behavioral data, physiologic wearables, point-of-care laboratory tests, personalized medical records, inventory trade space risk assessments, COTS medical databases, and ground support inputs. An ideal AI capability would possess trained fusion algorithms to cross reference input vectors with medical ‘knowledge’ [cultivated database] to stratify relevant data streams for predictive and actionable capabilities. In addition, EIMO will feature mobility, in that it can be accessed and can push/pull data within and between multiple vehicles/habitats. Large amounts and variable sources of data can be leveraged to diagnose, inform treatment strategies, and potentially predict medical events and performance decrements. Inclusion of advanced training tools using extended reality will enable increasingly autonomous medical care to aid a CMO when ground support is unavailable or time-delayed beyond required action window, e.g., emergent medical situations. EIMO CDSS would require very large datasets to train pre-flight and significant amounts of data are needed to support ML via in-flight CDSS operations. An additional challenge will be to find sufficient data to train a model relevant to astronaut demographics. The rapid, accelerating evolution of this field creates a propitious solution space to leverage multi-modal AI through public-private partnership(s). The status of multi-modal AI systems today would preclude their use for long duration missions as they remain unreliable and are subject to “digital hallucinations” and other errors that could pose operational risk. A federated labs structure is being considered to test and optimize data flow from the multiple input vectors leading to field testing in suitable ground/flight analogs. Critical to the success of an EIMO CDSS will be integration and interoperability and success will be defined by a system that can serve as an in-flight medical consult for the CMO providing critical support during medical contingencies. Benefits to terrestrial medicine may be significant as an outflow of the EIMO medical system, particularly for remote areas and communities lacking significant infrastructure, personnel and resources.

Medical Operations↗

Investigating Low-Altitude Constellations of Ad-Hoc Lunar PNT System for Distributed Spacecraft Autonomy

In this study, we examine a low-altitude Lunar Position, Navigation, and Timing (LPNT) constellations and the localization performance of Centralized Extended Kalman Filter (CEKF) and Decentralized Extended Kalman Filter (DEKF) algorithms. The primary investigation involves a 100-node swarm operating at a 100 km altitude, in contrast to previous studies that examined a 21-node asset in a frozen-orbit at 5,500 km. The autonomous operation of large-scale swarm is based on two-way Inter-Satellite Link (ISL) measurements, which involve pseudoranges and relative velocities among swarm nodes. We perform a numerical assessment of the two filtering approaches, utilizing ‘fully sampled’ measurements from all available assets as well as ‘two ISL’ measurements where each spacecraft is restricted to only two antennas. This research includes an analysis of CEKF under 2-ISL constraints and evaluates the performance of DEKF in a 100-node swarm, which has not been explored in previous studies. In addition, we examine the impact of increasing the sampling frequency for DEKF, showing that the update cycle can be shortened from a 10-minute interval. A novel approach for ‘2-ISL limited’ DEKF will also be introduced, using a matching formulation that exhaustively enumerates all potential matches. This study provides valuable insights into large-scale distributed swarm operations, considering various filter configurations, sampling frequencies, matching strategies, and scalability of CEKF and DEKF for low-altitude LPNT applications. The Lunar PNT technology plays a key role in providing reliable and robust navigation services on the Moon's surface and the South pole, where the primary Lunar missions are planned. To support upcoming Lunar missions, including small satellites from NASA's Commercial Lunar Payload Services program, the Lunar PNT system must be adaptable to smaller platforms like CubeSats. Driven by the growing involvement of public and private exploration partnerships, the traditional low Earth orbit missions are shifting to beyond geosynchronous orbit [1]. These upcoming missions aim to foster a sustainable and innovative exploration program, in collaboration with commercial and international partners, to facilitate human expansion throughout the solar system and return new knowledge and opportunities to Earth [2]. As part of this trend, there are increasing efforts to utilize science missions in Lunar orbit to develop a non-dedicated and ad-hoc PNT network system. Two traditional approaches, the Deep Space Network (DSN) and the weak signal Global Positioning System (GPS), are established deep-space navigation technologies for missions beyond the geosynchronous orbit. Beginning in 1958, the DSN was developed to communicate with the Explorer 1 spacecraft based on the use of radiometric tracking in spacecraft navigation [3]. The DSN is capable of providing nearly unfettered coverage to spacecraft beyond low-Earth orbit (LEO), however, increased space mission volume has created concerns about future expectations of DSN usage for spacecraft navigation [4]. For cislunar mission applications, the position accuracy using DSN achieves 100 m (3σ) with at least three geometrically diverse ground stations when using radiometric tracking alone [5]. The DSN's dependence on Earth-based ground stations restricts its operational capabilities to periods of Earth visibility. This limitation, coupled with its poor localization performance, renders the DSN unsuitable for future lunar missions that demand continuous tracking and precise positioning. To satisfy the increasing requirements of DSN in Lunar applications, spacecrafts are also required to improve their onboard antenna power and efficiency of the transmission. However, there is an important aggregate cost trade between adding capabilities to every spacecraft and adding to a capacity on the ground that serves multiple spacecraft [6]. A weak GPS system can provide PNT service while the user spacecraft is bound to the Moon, leveraging a single, steerable high gain antenna with the relatively narrow beam which includes all the sources in its field of view [7]. However, the higher the altitude the receiver is above the GPS constellations, the poorer and the weaker are the relative geometry and the received signal powers, respectively, leading to a significant navigation accuracy reduction [8]. The transmitted power becomes weaker with increasing distance from the Earth as well as signals tracked from one of the side lobes of the GPS antenna pattern. As a results, the number of visible satellites and relative geometric condition of the GPS satellites at very high altitude drops dramatically and reduces the navigation solution accuracy. Therefore, the weak GPS system is also not an ideal way to provide PNT service to upcoming Lunar missions when considering its limited geometric condition and the recued navigation accuracy. Another navigation approach on the Moon is being developed, similar to the Global Navigation Satellite System (GNSS) on Earth, aiming to offer navigation service with continuous 24/7 coverage across the entire Lunar surface. For example, lunar communications relay and navigation systems (LCRNS) by NASA and Lunar navigation satellite systems (LNSS) by JAXA are designed to serve as dedicated Position, Navigation, and Timing (PNT) systems for the Moon. However, designing a dedicated LNSS and PNT service involves additional challenges, which are unique to the lunar environment, including limited payload capacity for the CubeSat platform, i.e., the size, weight, and power (SWaP) of the onboard clock, limited lunar ground monitoring stations, and limited financial investment as compared to the legacy Earth-GPS [9]. NASA’s focus on utilizing CubeSat platforms on the Moon leads to an alternative Lunar navigation platform that leverages the existing Lunar science and exploration assets. The small satellites used in Lunar missions can be used to create a low-cost, autonomous, ad-hoc, and on-demand mission-centric Lunar PNT swarm capable of providing PNT services to these low-cost lunar missions [10]. As upcoming Lunar missions will often operate at low-altitude about 30 km to 100 km for scientific observations and mapping purposes, the low-altitude orbital constellations could be employed to create an ad-hoc Lunar PNT system. However, several issues must be addressed, such as the instability of these orbits, which often require maintenance or are only suitable for short-duration missions, operating for fewer than 90 days. Additionally, at an altitude of 100 km, the satellites have a limited period during which they are above the horizon and capable of providing PNT service to users. The implementation of a non-dedicated, ad-hoc Lunar navigation constellation facilitates on-demand PNT services. A preliminary study of ad-hoc Lunar PNT system was conducted using 21 spacecraft in 5,5000 km altitude frozen orbits to test its feasibility and a basic performance of orbital asset localization among ad-hoc Lunar constellations in small satellites format [10]. These swarm assets are designed for autonomous localization with minimal Earth interaction, reducing dependency on bandwidth and ground resources. The design in [10] demonstrated the feasibility of a decentralized PNT approach, specifically employing a DEKF approach for state estimation, which helps minimize onboard operating costs. The DEKF method distributes computation across individual satellites, which lightens the computational load while maintaining accuracy in orbit ephemeris and clock offsets, similar to centralized systems [11]. In a follow-on study [12], each spacecraft was limited to 2 communications antennae, forcing the selection of measurements and scheduling spacecraft activities to perform the measurements. A matching algorithm is implemented to select the best measurements and schedule position estimation updates. The decentralized localization performance is also investigated with increasing levels of network degradation for swarm assets considering the impact of intermittent and permanent communication failure, to demonstrate the robustness and fidelity of the decentralized Lunar PNT service [13]. This study confirmed that the ad-hoc PNT constellations in frozen orbit are highly robust and resilient to communication failures. However, unlike frozen orbit swarm assets, the low-altitude satellites have a limited ground view at an altitude of 100 km, where the ad-hoc Lunar constellation consists of 98 low-altitude satellites, evenly distributed across seven circular polar orbital planes, alongside two satellites in a frozen orbit at an altitude of 5,500 km (Figure 1). Therefore, the number of satellites visible to ground users is significantly limited in low-altitude orbit constellations. As each visibility of a spacecraft remains intact for only a few ticks before it moves out of the field of view, the ground user encounters challenges in maintaining continuous navigation service, resulting in sparse availability and provision of Lunar PNT system. Consequently, service availability is primarily restricted to the Lunar South Pole region (Figure 2). Given these limitations and concerns, the localization performance of low-altitude swarm assets will be assessed in this study. We focus on the investigation of the localization performance of low-altitude swarm assets and ground users near the Lunar South Pole. The overall flow of the Lunar PNT simulation incorporates the DEKF approach of asset localization and the weighted least-squares approach in user localization (Figure 3). The autonomous Lunar PNT simulation is primarily implemented in MATLAB, where the DEKF based on the matching scheduler is implemented with Google’s OR-tools as a model builder and Gurobi optimization tool as a backend solver. The General Mission Analysis Tool (GMAT) is utilized to generate ephemeris data for swarm assets, and accounts for satellite orbital details, mass, and perturbations like solar radiation pressure and drag coefficients. Each ephemeris dataset is produced in the Moon International Celestial Reference Frame (ICRF) inertial coordinate system. For state estimation, the distributed swarm assets rely on two-way Inter-Satellite Link (ISL) measurements, which involve tracking pseudoranges and relative velocities between visible satellites and anchor nodes during each observation. Numerical evaluations of the decentralized localization process are conducted to demonstrate the feasibility of the low-altitude PNT system in providing reliable navigation services. The main approach involves using DEKF and CEKF to localize 100 satellites in low-altitude constellations, where the CEKF is implemented to serve as a baseline for comparing the performance of distributed algorithms. In both cases, we evaluate ‘fully sampled’ measurements from all available assets, and ‘two ISL’ measurements when spacecraft are constrained to have only two antennas. We test four estimation techniques: CEKF fully sampled, CEKF two ISL, DEKF fully sampled, and DEKF two ISL filters. As the DEKF update cycle is comprised of network setup, communication, and computations, a global broadcast network and 2-way ISL network setup will take from 4 to 6 minutes as maximum [12]. In this simulation, the DEKF update cycle is set to 10 minutes, including a 4-minute latency for obtaining and computing the actual measurement updates. We experiment an increased update cycle to demonstrate the feasibility and evaluate the impact on localization performance using various tuning values for measurement noise covariances (Figures 4 and 5). By comparing centralized and decentralized approaches using a matching algorithm, we analyze the influence of cross-correlation factors in the covariance matrix, assuming 100% reliability of all assets and measurements. The increased frequency and the adjustments of tuning parameters reveal distinct error patterns between the two scenarios. The localization accuracy of the swarm assets and ground users is assessed by taking the median error across 100 assets and one ground user (84.9°S, 137.5°E) over 7-day simulation period (Table 1). Since the user localization accuracy is significantly affected by the performance of the swarm assets, it is crucial to maintain high localization accuracy within the swarm. This study will continue to explore decentralized filtering for autonomous LPNT operations, with further investigation of an 'iterative' matching approach which enumerates every valid matching pair, planned for the following month.

Yeji Kim↗