Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Reliability and Integrity Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Damage Detection Response Characteristics of Open Circuit Resonant (SansEC) Sensors

The capability to assess the current or future state of the health of an aircraft to improve safety, availability, and reliability while reducing maintenance costs has been a continuous goal for decades. Many companies, commercial entities, and academic institutions have become interested in Integrated Vehicle Health Management (IVHM) and a growing effort of research into "smart" vehicle sensing systems has emerged. Methods to detect damage to aircraft materials and structures have historically relied on visual inspection during pre-flight or post-flight operations by flight and ground crews. More quantitative non-destructive investigations with various instruments and sensors have traditionally been performed when the aircraft is out of operational service during major scheduled maintenance. Through the use of reliable sensors coupled with data monitoring, data mining, and data analysis techniques, the health state of a vehicle can be detected in-situ. NASA Langley Research Center (LaRC) is developing a composite aircraft skin damage detection method and system based on open circuit SansEC (Sans Electric Connection) sensor technology. Composite materials are increasingly used in modern aircraft for reducing weight, improving fuel efficiency, and enhancing the overall design, performance, and manufacturability of airborne vehicles. Materials such as fiberglass reinforced composites (FRC) and carbon-fiber-reinforced polymers (CFRP) are being used to great advantage in airframes, wings, engine nacelles, turbine blades, fairings, fuselage structures, empennage structures, control surfaces and aircraft skins. SansEC sensor technology is a new technical framework for designing, powering, and interrogating sensors to detect various types of damage in composite materials. The source cause of the in-service damage (lightning strike, impact damage, material fatigue, etc.) to the aircraft composite is not relevant. The sensor will detect damage independent of the cause. Damage in composite material is generally associated with a localized change in material permittivity and/or conductivity. These changes are sensed using SansEC. The unique electrical signatures (amplitude, frequency, bandwidth, and phase) are used for damage detection and diagnosis. An operational system and method would incorporate a SansEC sensor array on select areas of the aircraft exterior surfaces to form a "Smart skin" sensing surface. In this paper a new method and system for aircraft in-situ damage detection and diagnosis is presented. Experimental test results on seeded fault damage coupons and computational modeling simulation results are presented. NASA LaRC has demonstrated with individual sensors that SansEC sensors can be effectively used for in-situ composite damage detection of delamination, voids, fractures, and rips. Keywords: Damage Detection, Composites, Integrated Vehicle Health Monitoring (IVHM), Aviation Safety, SansEC Sensors

Dudley, Kenneth L.↗

Electrical, Electronic, and Electromechanical (EEE) parts management and control requirements for NASA space flight programs

This document establishes electrical, electronic, and electromechanical (EEE) parts management and control requirements for contractors providing and maintaining space flight and mission-essential or critical ground support equipment for NASA space flight programs. Although the text is worded 'the contractor shall,' the requirements are also to be used by NASA Headquarters and field installations for developing program/project parts management and control requirements for in-house and contracted efforts. This document places increased emphasis on parts programs to ensure that reliability and quality are considered through adequate consideration of the selection, control, and application of parts. It is the intent of this document to identify disciplines that can be implemented to obtain reliable parts which meet mission needs. The parts management and control requirements described in this document are to be selectively applied, based on equipment class and mission needs. Individual equipment needs should be evaluated to determine the extent to which each requirement should be implemented on a procurement. Utilization of this document does not preclude the usage of other documents. The entire process of developing and implementing requirements is referred to as 'tailoring' the program for a specific project. Some factors that should be considered in this tailoring process include program phase, equipment category and criticality, equipment complexity, and mission requirements. Parts management and control requirements advocated by this document directly support the concept of 'reliability by design' and are an integral part of system reliability and maintainability. Achieving the required availability and mission success objectives during operation depends on the attention given reliability and maintainability in the design phase. Consequently, it is intended that the requirements described in this document are consistent with those of NASA publications, 'Reliability Program Requirements for Aeronautical and Space System Contractors,' NHB 5300.4(1A-l); 'Maintainability Program Requirements for Space Systems,' NHB 5300.4(1E); and 'Quality Program Provisions for Aeronautical and Space System Contractors,' NHB 5300.4(1B).

Source record↗

Multiplexer/Demultiplexer Loading Tool (MDMLT)

The purpose of the MDMLT is to improve the reliability and speed of loading multiplexers/demultiplexers (MDMs) in the Software Development and Integration Laboratory (SDIL) by automating the configuration management (CM) of the loads in the MDMs, automating the loading procedure, and providing the capability to load multiple or all MDMs concurrently. This loading may be accomplished in parallel, or single MDMs (remote). The MDMLT is a Web-based tool that is capable of loading the entire International Space Station (ISS) MDM configuration in parallel. It is able to load Flight Equivalent Units (FEUs), enhanced, standard, and prototype MDMs as well as both EEPROM (Electrically Erasable Programmable Read-Only Memory) and SSMMU (Solid State Mass Memory Unit) (MASS Memory). This software has extensive configuration management to track loading history, and the performance improvement means of loading the entire ISS MDM configuration of 49 MDMs in approximately 30 minutes, as opposed to 36 hours, which is what it took previously utilizing the flight method of S-Band uplink. The laptop version recently added to the MDMLT suite allows remote lab loading with the CM of information entered into a common database when it is reconnected to the network. This allows the program to reconfigure the test rigs quickly between shifts, allowing the lab to support a variety of onboard configurations during a single day, based on upcoming or current missions. The MDMLT Computer Software Configuration Item (CSCI) supports a Web-based command and control interface to the user. An interface to the SDIL File Transfer Protocol (FTP) server is supported to import Integrated Flight Loads (IFLs) and Internal Product Release Notes (IPRNs) into the database. An interface to the Monitor and Control System (MCS) is supported to control the power state, and to enable or disable the debug port of the MDMs to be loaded. Two direct interfaces to the MDM are supported: a serial interface (debug port) to receive MDM memory dump data and the calculated checksum, and the Small Computer System Interface (SCSI) to transfer load files to MDMs with hard disks. File transfer from the MDM Loading Tool to EEPROM within the MDM is performed via the MILSTD- 1553 bus, making use of the Real- Time Input/Output Processors (RTIOP) when using the rig-based MDMLT, and via a bus box when using the laptop MDMLT. The bus box is a cost-effective alternative to PC-1553 cards for the laptop. It is noted that this system can be modified and adapted to any avionic laboratory for spacecraft computer loading, ship avionics, or aircraft avionics where multiple configurations and strong configuration management of software/firmware loads are required.

Brewer, Lenox Allen↗

Space shuttle program: Shuttle Avionics Integration Laboratory. Volume 7: Logistics management plan

The logistics management plan for the shuttle avionics integration laboratory defines the organization, disciplines, and methodology for managing and controlling logistics support. Those elements requiring management include maintainability and reliability, maintenance planning, support and test equipment, supply support, transportation and handling, technical data, facilities, personnel and training, funding, and management data.

Source record↗

A Fuel-Efficient Conflict Resolution Maneuver for Separation Assurance

Automated separation assurance algorithms are envisioned to play an integral role in accommodating the forecasted increase in demand of the National Airspace System. Developing a robust, reliable, air traffic management system involves safely increasing efficiency and throughput while considering the potential impact on users. This experiment seeks to evaluate the benefit of augmenting a conflict detection and resolution algorithm to consider a fuel efficient, Zero-Delay Direct-To maneuver, when resolving a given conflict based on either minimum fuel burn or minimum delay. A total of twelve conditions were tested in a fast-time simulation conducted in three airspace regions with mixed aircraft types and light weather. Results show that inclusion of this maneuver has no appreciable effect on the ability of the algorithm to safely detect and resolve conflicts. The results further suggest that enabling the Zero-Delay Direct-To maneuver significantly increases the cumulative fuel burn savings when choosing resolution based on minimum fuel burn while marginally increasing the average delay per resolution.

Bowe, Aisha Ruth↗

CEO Sites Mission Management System (SMMS)

Late in fiscal year 2011, the Crew Earth Observations (CEO) team was tasked to upgrade its science site database management tool, which at the time was integrated with the Automated Mission Planning System (AMPS) originally developed for Earth Observations mission planning in the 1980s. Although AMPS had been adapted and was reliably used by CEO for International Space Station (ISS) payload operations support, the database structure was dated, and the compiler required for modifications would not be supported in the Windows 7 64-bit operating system scheduled for implementation the following year. The Sites Mission Management System (SMMS) is now the tool used by CEO to manage a heritage Structured Query Language (SQL) database of more than 2,000 records for Earth science sites. SMMS is a carefully designed and crafted in-house software package with complete and detailed help files available for the user and meticulous internal documentation for future modifications. It was delivered in February 2012 for test and evaluation. Following acceptance, it was implemented for CEO mission operations support in April 2012. The database spans the period from the earliest systematic requests for astronaut photography during the shuttle era to current ISS mission support of the CEO science payload. Besides logging basic image information (site names, locations, broad application categories, and mission requests), the upgraded database management tool now tracks dates of creation, modification, and activation; imagery acquired in response to requests; the status and location of ancillary site information; and affiliations with studies, their sponsors, and collaborators. SMMS was designed to facilitate overall mission planning in terms of site selection and activation and provide the necessary site parameters for the Satellite Tool Kit (STK) Integrated Message Production List Editor (SIMPLE), which is used by CEO operations to perform daily ISS mission planning. The CEO team uses the SMMS for three general functions - database queries of content and status, individual site creation and updates, and mission planning. The CEO administrator of the science site database is able to create or modify the content of sites and activate or deactivate them based on the requirements of the sponsors. The administrator supports and implements ISS mission planning by assembling, reporting, and activating mission-specific site selections for management; deactivating sites as requirements are met; and creating new sites, such as International Charter sites for disasters, as circumstances warrant. In addition to the above CEO internal uses, when site planning for a specific ISS mission is complete and approved, the SMMS can produce and export those essential site database elements for the mission into XML format for use by onboard Earth-location systems, such as Worldmap. The design, development, and implementation of the SMMS resulted in a superior database management system for CEO science sites by focusing on the functions and applications of the database alone instead of integrating the database with the multipurpose configuration of the AMPS. Unlike the AMPS, it can function and be modified within the existing Windows 7 environment. The functions and applications of the SMMS were expanded to accommodate more database elements, report products, and a streamlined interface for data entry and review. A particularly elegant enhancement in data entry was the integration of the Google Earth application for the visual display and definition of site coordinates for site areas defined by multiple coordinates. Transfer between the SMMS and Google Earth is accomplished with a Keyhole Markup Language (KML) expression of geographic data (see figures 3 and 4). Site coordinates may be entered into the SMMS panel directly for display in Google Earth, or the coordinates may be defined on the Google Earth display as a mouse-controlled polygonal definition and transferred back into the SMMS as KML input. This significantly reduces the possibility of errors in coordinate entries and provides visualization of the scale of the site being defined. CEO now has a powerful tool for managing and defining sites on the Earth's surface for both targets of astronaut photography or other onboard remote sensing systems. It can also record and track results by sponsor, collaborator, or type of study.

Trenchard, Mike↗

Future challenges in V/STOL flight propulsion control integration

A survey of propulsion control requirements forming part of an advanced V/STOL control requirements study has to date determined, among other findings: (1) that the dependence of V/STOL flying qualities on propulsive lift makes it necessary to identify propulsion control requirements early in a development program; (2) that V/STOL controls of the future should relieve the pilot of control functions and elevate him to the position of a flight operations manager, with substantial gains in capability and/or safety; and (3) that research is required to define the V/STOL control system reliability requirements and specific component reliability allocations. An interactive, integrated design process for the realization of these objectives is also described.

Roth, S. P.↗

Prototype thin-film thermocouple/heat-flux sensor for a ceramic-insulated diesel engine

A platinum versus platinum-13 percent rhodium thin-film thermocouple/heat-flux sensor was devised and tested in the harsh, high-temperature environment of a ceramic-insulated, low-heat-rejection diesel engine. The sensor probe assembly was developed to provide experimental validation of heat transfer and thermal analysis methodologies applicable to the insulated diesel engine concept. The thin-film thermocouple configuration was chosen to approximate an uninterrupted chamber surface and provide a 1-D heat-flux path through the probe body. The engine test was conducted by Purdue University for Integral Technologies, Inc., under a DOE-funded contract managed by NASA Lewis Research Center. The thin-film sensor performed reliably during 6 to 10 hr of repeated engine runs at indicated mean surface temperatures up to 950 K. However, the sensor suffered partial loss of adhesion in the thin-film thermocouple junction area following maximum cyclic temperature excursions to greater than 1150 K.

Kim, Walter S.↗

Hybrid Power Management

An engineering discipline denoted as hybrid power management (HPM) has emerged from continuing efforts to increase energy efficiency and reliability of hybrid power systems. HPM is oriented toward integration of diverse electric energy-generating, energy-storing, and energy-consuming devices in optimal configurations for both terrestrial and outer-space applications. The basic concepts of HPM are potentially applicable at power levels ranging from nanowatts to megawatts. Potential applications include terrestrial power-generation, terrestrial transportation, biotechnology, and outer-space power systems. Instances of this discipline at prior stages of development were reported (though not explicitly labeled as HPM) in three prior NASA Tech Briefs articles: "Ultracapacitors Store Energy in a Hybrid Electric Vehicle"(LEW-16876), Vol. 24, No. 4 (April 2000), page 63; "Photovoltaic Power Station With Ultracapacitors for Storage" (LEW-17177), Vol. 27, No. 8 (August 2003), page 38; and "Flasher Powered by Photovoltaic Cells and Ultracapacitors" (LEW-17246), Vol. 24, No. 10 (October 2003), page 37. As the titles of the cited articles indicate, the use of ultracapacitors as energy-storage devices lies at the heart of HPM. An ultracapacitor is an electrochemical energy-storage device, but unlike in a conventional rechargeable electrochemical cell or battery, chemical reactions do not take place during operation. Instead, energy is stored electrostatically at an electrode/electrolyte interface. The capacitance per unit volume of an ultracapacitor is much greater than that of a conventional capacitor because its electrodes have much greater surface area per unit volume and the separation between the electrodes is much smaller. Power-control circuits for ultracapacitors can be simpler than those for batteries, for two reasons: (1) Because of the absence of chemical reactions, charge and discharge currents can be greater than those in batteries, limited only by the electrical resistances of conductors; and (2) whereas the charge level of a battery depends on voltage, temperature, age, and load condition, the charge level of an ultracapacitor, like that of a conventional capacitor, depends only on voltage.

Eichenberg, Dennis↗

Space station software reliability analysis based on failures observed during testing at the multisystem integration facility

Quality of software not only is vital to the successful operation of the space station, it is also an important factor in establishing testing requirements, time needed for software verification and integration as well as launching schedules for the space station. Defense of management decisions can be greatly strengthened by combining engineering judgments with statistical analysis. Unlike hardware, software has the characteristics of no wearout and costly redundancies, thus making traditional statistical analysis not suitable in evaluating reliability of software. A statistical model was developed to provide a representation of the number as well as types of failures occur during software testing and verification. From this model, quantitative measure of software reliability based on failure history during testing are derived. Criteria to terminate testing based on reliability objectives and methods to estimate the expected number of fixings required are also presented.

Tamayo, Tak Chai↗

The NASA IVHM Technology Experiment for X-37

The NASA IVHM (Integrated Vehicle Health Management) technology experiment for X-37 is presented. The goals and objectives of this program are: to reduce cost and increase reliability of space transportation; to demonstrate benefits of in-flight IVHM to the operation of a Reusable Launch Vehicle; to advance this IVHM technology to Technology Readiness Level approx. 7 within a flight environment; and to operate IVHM software on the Vehicle Management Computer. The following sections are included: Background (X-37 & Livingstone), Livingstone model example from DS-1, Experiment overview, X-37 IVHM scope, Stanley interface to livingstone model, Right ruddervator actuator, Motor state diagram, inferred nominal state, and X-37 informed maintenance experiment.

Source record↗

Emerging technologies for V&V of ISHM software for space exploration

Systems1,2 required to exhibit high operational reliability often rely on some form of fault protection to recognize and respond to faults, preventing faults' escalation to catastrophic failures. Integrated System Health Management (ISHM) extends the functionality of fault protection to both scale to more complex systems (and systems of systems), and to maintain capability rather than just avert catastrophe. Forms of ISHM have been utilized to good effect in the maintenance phase of systems' total lifecycles (often referred to as 'condition-based mainte-nance'), but less so in a 'fault protection' role during actual operations. One of the impediments to such use lies in the challenges of verification, validation and certification of ISHM systems themselves. This paper makes the case that state-of-the-practice V&V and certification techniques will not suffice for emerging forms of ISHM systems; however, a number of maturing software engineering assurance technologies show particular promise for addressing these ISHM V&V challenges.

fault detection, isolation, and recovery↗

Smart Sensor Demonstration Payload

Sensors are a critical element to any monitoring, control, and evaluation processes such as those needed to support ground based testing for rocket engine test. Sensor applications involve tens to thousands of sensors; their reliable performance is critical to achieving overall system goals. Many figures of merit are used to describe and evaluate sensor characteristics; for example, sensitivity and linearity. In addition, sensor selection must satisfy many trade-offs among system engineering (SE) requirements to best integrate sensors into complex systems [1]. These SE trades include the familiar constraints of power, signal conditioning, cabling, reliability, and mass, and now include considerations such as spectrum allocation and interference for wireless sensors. Our group at NASA s John C. Stennis Space Center (SSC) works in the broad area of integrated systems health management (ISHM). Core ISHM technologies include smart and intelligent sensors, anomaly detection, root cause analysis, prognosis, and interfaces to operators and other system elements [2]. Sensor technologies are the base fabric that feed data and health information to higher layers. Cost-effective operation of the complement of test stands benefits from technologies and methodologies that contribute to reductions in labor costs, improvements in efficiency, reductions in turn-around times, improved reliability, and other measures. ISHM is an active area of development at SSC because it offers the potential to achieve many of those operational goals [3-5].

Schmalzel, John↗

From Here to Autonomicity: Self-Managing Agents and the Biological Metaphors that Inspire Them

We seek inspiration for self-managing systems from (obviously, pre-existing) biological mechanisms. Autonomic Computing (AC), a self-managing systems initiative based on the biological metaphor of the autonomic nervous system, is increasingly gaining momentum as the way forward for integrating and designing reliable systems, while agent technologies have been identified as a key enabler for engineering autonomicity in systems. This paper looks at other biological metaphors such as reflex and healing, heart- beat monitors, pulse monitors and apoptosis for assisting in the realization of autonomicity.

Sterritt, Roy↗

A rose by any other name: Certification seen as process rather than content

Green (1990) believes that the two main factors safeguarding flying from human error are both related to certification and regulation. First is the increasingly proceduralized nature of flying whereby as much as possible is reduced to a rule-based activity. Second is the emphasis placed upon training and competency checking of aircrew in simulators and in the air, both generally and for all particular types of aircraft flown. This leaves, believes Green, other human factors that are relatively unaddressed as yet and which can give rise to human reliability problems. These include: hardware factors and especially pilot/co-pilot relationships; and system factors including fatigue and cost/safety trade-offs. He also, importantly, identifies problems with the integration of the 'electronic crew member' following increased automation. Human reliability failures with artificial intelligence and automation, due to over-reliance on the system fail-safe mechanisms, or to operator under- confidence in the integrity or self-regulating capacity of the system, or to out-of-loop effects, are widely accepted as being due to deficiencies in plant design, planning, management and maintenance more than to 'operator error' - Reason's (1990) latent error or organization pathogens argument. Reliability failures in complex systems are well enough documented to give cause for concern and at least promote a debate on the merits of a full certification program. The purpose of this short paper is to seek out and explore what is valuable in certification, at the least to show that the benefits outweigh the disadvantages and at best to identify positive outcomes perhaps not obtainable in other ways. On both sides of the debate on certification there is general agreement on the need for a better human factors perspective and effort in complex aviation systems design. What is at issue is how this is to be promoted. It is incumbent upon opponents of certification to say how else such promotion be enabled. This is an exploratory and philosophical review, not a focused and specific one, and it will draw upon much that is not firmly in the domain of complex aviation systems.

Wilson, John R.↗

Modeling in the State Flow Environment to Support Launch Vehicle Verification Testing for Mission and Fault Management Algorithms in the NASA Space Launch System

Analysis methods and testing processes are essential activities in the engineering development and verification of the National Aeronautics and Space Administration's (NASA) new Space Launch System (SLS). Central to mission success is reliable verification of the Mission and Fault Management (M&FM) algorithms for the SLS launch vehicle (LV) flight software. This is particularly difficult because M&FM algorithms integrate and operate LV subsystems, which consist of diverse forms of hardware and software themselves, with equally diverse integration from the engineering disciplines of LV subsystems. M&FM operation of SLS requires a changing mix of LV automation. During pre-launch the LV is primarily operated by the Kennedy Space Center (KSC) Ground Systems Development and Operations (GSDO) organization with some LV automation of time-critical functions, and much more autonomous LV operations during ascent that have crucial interactions with the Orion crew capsule, its astronauts, and with mission controllers at the Johnson Space Center. M&FM algorithms must perform all nominal mission commanding via the flight computer to control LV states from pre-launch through disposal and also address failure conditions by initiating autonomous or commanded aborts (crew capsule escape from the failing LV), redundancy management of failing subsystems and components, and safing actions to reduce or prevent threats to ground systems and crew. To address the criticality of the verification testing of these algorithms, the NASA M&FM team has utilized the State Flow environment6 (SFE) with its existing Vehicle Management End-to-End Testbed (VMET) platform which also hosts vendor-supplied physics-based LV subsystem models. The human-derived M&FM algorithms are designed and vetted in Integrated Development Teams composed of design and development disciplines such as Systems Engineering, Flight Software (FSW), Safety and Mission Assurance (S&MA) and major subsystems and vehicle elements such as Main Propulsion Systems (MPS), boosters, avionics, Guidance, Navigation, and Control (GN&C), Thrust Vector Control (TVC), liquid engines, and the astronaut crew office. Since the algorithms are realized using model-based engineering (MBE) methods from a hybrid of the Unified Modeling Language (UML) and Systems Modeling Language (SysML), SFE methods are a natural fit to provide an in depth analysis of the interactive behavior of these algorithms with the SLS LV subsystem models. For this, the M&FM algorithms and the SLS LV subsystem models are modeled using constructs provided by Matlab which also enables modeling of the accompanying interfaces providing greater flexibility for integrated testing and analysis, which helps forecast expected behavior in forward VMET integrated testing activities. In VMET, the M&FM algorithms are prototyped and implemented using the same C++ programming language and similar state machine architectural concepts used by the FSW group. Due to the interactive complexity of the algorithms, VMET testing thus far has verified all the individual M&FM subsystem algorithms with select subsystem vendor models but is steadily progressing to assessing the interactive behavior of these algorithms with LV subsystems, as represented by subsystem models. The novel SFE applications has proven to be useful for quick look analysis into early integrated system behavior and assessment of the M&FM algorithms with the modeled LV subsystems. This early MBE analysis generates vital insight into the integrated system behaviors, algorithm sensitivities, design issues, and has aided in the debugging of the M&FM algorithms well before full testing can begin in more expensive, higher fidelity but more arduous environments such as VMET, FSW testing, and the Systems Integration Lab7 (SIL). SFE has exhibited both expected and unexpected behaviors in nominal and off nominal test cases prior to full VMET testing. In many findings, these behavioral characteristics were used to correct the M&FM algorithms, enable better test coverage, and develop more effective test cases for each of the LV subsystems. This has improved the fidelity of testing and planning for the next generation of M&FM algorithms as the SLS program evolves from non-crewed to crewed flight, impacting subsystem configurations and the M&FM algorithms that control them. SFE analysis has improved robustness and reliability of the M&FM algorithms by revealing implementation errors and documentation inconsistencies. It is also improving planning efficiency for future VMET testing of the M&FM algorithms hosted in the LV flight computers, further reducing risk for the SLS launch infrastructure, the SLS LV, and most importantly the crew.

Trevino, Luis↗

NASA's Spaceliner Investment Area Technology Activities

NASA's has established long term goals for access-to-space. The third generation launch systems are to be fully reusable and operational around 2025. The goals for the third generation launch system are to significantly reduce cost and improve safety over current conditions. The Advanced Space Transportation Program Office (ASTP) at the NASA's Marshall Space Flight Center in Huntsville, AL has the agency lead to develop space transportation technologies. Within ASTP, under the Spaceliner Investment Area, third generation technologies are being pursued in the areas of propulsion, airframes, integrated vehicle health management (IVHM), avionics, power, operations, and range. The ASTP program will mature these technologies through both ground and flight system testing. The Spaceliner Investment Area plans to mature vehicle technologies to reduce the implementation risks for future commercially developed reusable launch vehicles (RLV). The plan is to substantially increase the design and operating margins of the third generation RLV (the Space Shuttle is the first generation) by incorporating advanced technologies in propulsion, materials, structures, thermal protection systems, avionics, and power. Advancements in design tools and better characterization of the operational environment will allow improvements in design margins. Improvements in operational efficiencies will be provided through use of advanced integrated health management, operations, and range technologies. The increase in margins will allow components to operate well below their design points resulting in improved component operating life, reliability, and safety which in turn reduces both maintenance and refurbishment costs. These technologies have the potential of enabling horizontal takeoff by reducing the takeoff weight and achieving the goal of airline-like operation. These factors in conjunction with increased flight rates from an expanding market will result in significant improvements in safety and reductions in operational costs of future vehicles. The paper describes current status, future plans and technologies that are being matured by the Spaceliner Investment Area under the Advanced Space Transportation Program Office.

Hueter, Uwe↗

A Vehicle Management End-to-End Testing and Analysis Platform for Validation of Mission and Fault Management Algorithms to Reduce Risk for NASAs Space Launch System

The engineering development of the National Aeronautics and Space Administration's (NASA) new Space Launch System (SLS) requires cross discipline teams with extensive knowledge of launch vehicle subsystems, information theory, and autonomous algorithms dealing with all operations from pre-launch through on orbit operations. The nominal and off-nominal characteristics of SLS's elements and subsystems must be understood and matched with the autonomous algorithm monitoring and mitigation capabilities for accurate control and response to abnormal conditions throughout all vehicle mission flight phases, including precipitating safing actions and crew aborts. This presents a large and complex systems engineering challenge, which is being addressed in part by focusing on the specific subsystems involved in the handling of off-nominal mission and fault tolerance with response management. Using traditional model-based system and software engineering design principles from the Unified Modeling Language (UML) and Systems Modeling Language (SysML), the Mission and Fault Management (M&FM) algorithms for the vehicle are crafted and vetted in Integrated Development Teams (IDTs) composed of multiple development disciplines such as Systems Engineering (SE), Flight Software (FSW), Safety and Mission Assurance (S&MA) and the major subsystems and vehicle elements such as Main Propulsion Systems (MPS), boosters, avionics, Guidance, Navigation, and Control (GNC), Thrust Vector Control (TVC), and liquid engines. These model-based algorithms and their development lifecycle from inception through FSW certification are an important focus of SLS's development effort to further ensure reliable detection and response to off-nominal vehicle states during all phases of vehicle operation from pre-launch through end of flight. To test and validate these M&FM algorithms a dedicated test-bed was developed for full Vehicle Management End-to-End Testing (VMET). For addressing fault management (FM) early in the development lifecycle for the SLS program, NASA formed the M&FM team as part of the Integrated Systems Health Management and Automation Branch under the Spacecraft Vehicle Systems Department at the Marshall Space Flight Center (MSFC). To support the development of the FM algorithms, the VMET developed by the M&FM team provides the ability to integrate the algorithms, perform test cases, and integrate vendor-supplied physics-based launch vehicle (LV) subsystem models. Additionally, the team has developed processes for implementing and validating the M&FM algorithms for concept validation and risk reduction. The flexibility of the VMET capabilities enables thorough testing of the M&FM algorithms by providing configurable suites of both nominal and off-nominal test cases to validate the developed algorithms utilizing actual subsystem models such as MPS, GNC, and others. One of the principal functions of VMET is to validate the M&FM algorithms and substantiate them with performance baselines for each of the target vehicle subsystems in an independent platform exterior to the flight software test and validation processes. In any software development process there is inherent risk in the interpretation and implementation of concepts from requirements and test cases into flight software compounded with potential human errors throughout the development and regression testing lifecycle. Risk reduction is addressed by the M&FM group but in particular by the Analysis Team working with other organizations such as S&MA, Structures and Environments, GNC, Orion, Crew Office, Flight Operations, and Ground Operations by assessing performance of the M&FM algorithms in terms of their ability to reduce Loss of Mission (LOM) and Loss of Crew (LOC) probabilities. In addition, through state machine and diagnostic modeling, analysis efforts investigate a broader suite of failure effects and associated detection and responses to be tested in VMET to ensure reliable failure detection, and confirm responses do not create additional risks or cause undesired states through interactive dynamic effects with other algorithms and systems. VMET further contributes to risk reduction by prototyping and exercising the M&FM algorithms early in their implementation and without any inherent hindrances such as meeting FSW processor scheduling constraints due to their target platform - the ARINC 6535-partitioned Operating System, resource limitations, and other factors related to integration with other subsystems not directly involved with M&FM such as telemetry packing and processing. The baseline plan for use of VMET encompasses testing the original M&FM algorithms coded in the same C++ language and state machine architectural concepts as that used by FSW. This enables the development of performance standards and test cases to characterize the M&FM algorithms and sets a benchmark from which to measure their effectiveness and performance in the exterior FSW development and test processes. This paper is outlined in a systematic fashion analogous to a lifecycle process flow for engineering development of algorithms into software and testing. Section I describes the NASA SLS M&FM context, presenting the current infrastructure, leading principles, methods, and participants. Section II defines the testing philosophy of the M&FM algorithms as related to VMET followed by section III, which presents the modeling methods of the algorithms to be tested and validated in VMET. Its details are then further presented in section IV followed by Section V presenting integration, test status, and state analysis. Finally, section VI addresses the summary and forward directions followed by the appendices presenting relevant information on terminology and documentation.

Trevino, Luis↗