Engineering PapersSearch

SEARCH · Engineering Papers

Results for “communication failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Autonomy Architectures for a Constellation of Spacecraft

Until the past few years, missions typically involved fairly large expensive spacecraft. Such missions have primarily favored using older proven technologies over more recently developed ones, and humans controlled spacecraft by manually generating detailed command sequences with low-level tools and then transmitting the sequences for subsequent execution on a spacecraft controller. This approach toward controlling a spacecraft has worked spectacularly on previous missions, but it has limitations deriving from communications restrictions - scheduling time to communicate with a particular spacecraft involves competing with other projects due to the limited number of deep space network antennae. This implies that a spacecraft can spend a long time just waiting whenever a command sequence fails. This is one reason why the New Millennium program has an objective to migrate parts of mission control tasks onboard a spacecraft to reduce wait time by making spacecraft more robust. The migrated software is called a "remote agent" and has 4 components: a mission manager to generate the high level goals, a planner/scheduler to turn goals into activities while reasoning about future expected situations, an executive/diagnostics engine to initiate and maintain activities while interpreting sensed events by reasoning about past and present situations, and a conventional real-time subsystem to interface with the spacecraft to implement an activity's primitive actions. In addition to needing remote planning and execution for isolated spacecraft, a trend toward multiple-spacecraft missions points to the need for remote distributed planning and execution. The past few years have seen missions with growing numbers of probes. Pathfinder has its rover (Sojourner), Cassini has its lander (Huygens), and the New Millenium Deep Space 3 (DS3) proposal involves a constellation of 3 spacecraft for interferometric mapping. This trend is expected to continue to progressively larger fleets. For example, one mission proposed to succeed DS3 would have 18 spacecraft flying in formation in order to detect earth-sized planets orbiting other stars. A proposed magnetospheric constellation would involve 5 to 500 spacecraft in Earth orbit to measure global phenomena within the magnetosphere. This work describes and compares three autonomy architectures for a system that continuously plans to control a fleet of spacecraft using collective mission goals instead of goals or command sequences for each spacecraft. A fleet of self-commanding spacecraft would autonomously coordinate itself to satisfy high level science and engineering goals in a changing partially-understood environment making feasible the operation of tens or even a hundred spacecraft (such as for interferometry or plasma physics missions). The easiest way to adapt autonomous spacecraft research to controlling constellations involves treating the constellation as a single spacecraft. Here one spacecraft directly controls the others as if they were connected. The controlling "master" spacecraft performs all autonomy reasoning, and the slaves only have real-time subsystems to execute the master's commands and transmit local telemetry/observations. The executive/diagnostics module starts actions and the master's real-time subsystem controls the action either locally or remotely through a slave. While the master/slave approach benefits from conceptual simplicity, it relies on an assumption that the master spacecraft's executive can continuously monitor the slaves' real-time subsystems, and this relies on high-bandwidth highly-reliable communications. Since unintended results occur fairly rarely, one way to relax the bandwidth requirements involves only monitoring unexpected events in spacecraft. Unfortunately, this disables the ability to monitor for unexpected events between spacecraft and leads to a host of coordination problems among the slaves. Also, failures in the communications system can result in losing slaves. The other two architectures improve robustness while reducing communications by progressively distributing more of the other three remote agent components across the constellation. In a teamwork architecture, all spacecraft have executives and real-time subsystems - only the leader has the planner/scheduler and mission manager. Finally, distributing all remote agent components leads to a peer-to-peer approach toward constellation control.

Barrett, Anthony

Fault-Tolerant Local-Area Network

Local-area network (LAN) for computers prevents single-point failure from interrupting communication between nodes of network. Includes two complete cables, LAN 1 and LAN 2. Microprocessor-based slave switches link cables to network-node devices as work stations, print servers, and file servers. Slave switches respond to commands from master switch, connecting nodes to two cable networks or disconnecting them so they are completely isolated. System monitor and control computer (SMC) acts as gateway, allowing nodes on either cable to communicate with each other and ensuring that LAN 1 and LAN 2 are fully used when functioning properly. Network monitors and controls itself, automatically routes traffic for efficient use of resources, and isolates and corrects its own faults, with potential dramatic reduction in time out of service.

Morales, Sergio

Roadside-based communication system and method

A roadside-based communication system providing backup communication between emergency mobile units and emergency command centers. In the event of failure of a primary communication, the mobile units transmit wireless messages to nearby roadside controllers that may take the form of intersection controllers. The intersection controllers receive the wireless messages, convert the messages into standard digital streams, and transmit the digital streams along a citywide network to a destination intersection or command center.

Bachelder, Aaron D.

Repairing a communications satellite on orbit

A review of past failures indicates that module exchange can satisfy most repair requirements of communications satellites. Emphasis is placed on the design of a serviceable communications satellites with 20 modules, on the development of an on-orbit servicer designed to remove failed modules from a body-stabilized spacecraft and to replace them with good modules, and on servicing operations. Benefits of servicing or repair include increased satellite availability, increased reliability, decreased life cycle costs, replacement of worn-out items, installation of updated equipment, and correction of design failures. The use of servicing instead of replacement could result in cost savings in excess of 40 percent. Significant savings are possible when the lifetime of a program is long relative to the satellite lifetime.

Gordon, G. D.

Failure detection and recovery in the assembly/contingency subsystem

The Assembly/Contingency Subsystem (ACS) is the primary communications link on board the Space Station. Any failure in a component of this system or in the external devices through which it communicates with ground-based systems will isolate the Station. The ACS software design includes a failure management capability (ACFM) that provides protocols for failure detection, isolation, and recovery (FDIR). The the ACFM design requirements as outlined in the current ACS software requirements specification document are reviewed. The activities carried out in this review include: (1) an informal, but thorough, end-to-end failure mode and effects analysis of the proposed software architecture for the ACFM; and (2) a prototype of the ACFM software, implemented as a C program under the UNIX operating system. The purpose of this review is to evaluate the FDIR protocols specified in the ACS design and the specifications themselves in light of their use in implementing the ACFM. The basis of failure detection in the ACFM is the loss of signal between the ground and the Station, which (under the appropriate circumstances) will initiate recovery to restore communications. This recovery involves the reconfiguration of the ACS to either a backup set of components or to a degraded communications mode. The initiation of recovery depends largely on the criticality of the failure mode, which is defined by tables in the ACFM and can be modified to provide a measure of flexibility in recovery procedures.

Gantenbein, Rex E.

Reliability Analysis of Complex NASA Systems with Model-Based Engineering

The emergence of model-based engineering, with Model- Based Systems Engineering (MBSE) leading the way, is transforming design and analysis methodologies. The recognized benefits to systems development include moving from document-centric information systems and document-centric project communication to a model-centric environment in which control of design changes in the life cycles is facilitated. In addition, a “single source of truth” about the system, that is up-to-date in all respects of the design, becomes the authoritative source of data and information about the system. This promotes consistency and efficiency in regard to integration of the system elements as the design emerges and thereby may further optimize the design. Therefore Reliability Engineers (REs) supporting NASA missions must be integrated into model-based engineering to ensure the outputs of their analyses are relevant and value-needed to the design, development, and operational processes for failure risks assessment and communication.

FMEA/FMECA

Reliability Analysis of Complex NASA Systems with Model Based Engineering

The emergence of model-based engineering, with Model- Based Systems Engineering (MBSE) leading the way, is transforming design and analysis methodologies. The recognized benefits to systems development include moving from document-centric information systems and document-centric project communication to a model-centric environment in which control of design changes in the life cycles is facilitated. In addition, a “single source of truth” about the system, that is up-to-date in all respects of the design, becomes the authoritative source of data and information about the system. This promotes consistency and efficiency in regard to integration of the system elements as the design emerges and thereby may further optimize the design. Therefore Reliability Engineers (REs) supporting NASA missions must be integrated into model-based engineering to ensure the outputs of their analyses are relevant and value-needed to the design, development, and operational processes for failure risks assessment and communication.

Reliability prediction

A user assessment of servicing at geostationary orbit

Orbital servicing assessed from the viewpoint of a commercial user of communications satellites at geostationary orbit. The need for servicing is emphasized by looking at the history of failures and defects occurring in communications satellites. The methods used in servicing were evaluated in terms of the needs of a communications satellite user. A system that utilizes servicing was studied, and some benefits in addition to cost savings were identified. Most of the assumptions and conclusions apply to earth observation satellites at geostationary orbit.

Gordon, G. D.

Model-Based SMA Initiative Phase 1 Report: Reliability Tips Excerpt

The emergence of model-based engineering, with Model- Based Systems Engineering (MBSE) leading the way, is transforming design and analysis methodologies. [7] The recognized benefits to systems development include moving from document-centric information systems and document-centric project communication to a model-centric environment in which control of design changes in the life cycles is facilitated. In addition, a “single source of truth” about the system, that is up-to-date in all respects of the design, becomes the authoritative source of data and information about the system. This promotes consistency and efficiency in regard to integration of the system elements as the design emerges and thereby may further optimize the designs. Therefore Reliability Engineers (REs) supporting NASA missions must be integrated into model-based engineering, using these recommended modeling techniques, to ensure the outputs of their analyses are relevant and value-needed to the design, development, and operational processes for failure risk assessment and communication.

Nancy J. Lindsey

International Space Station (ISS) Payload Autonomous Operations Past, Present and Future

Draper Laboratorys Timeliner is a scripting and automation system that runs onboard computers in the International Space Station (ISS). Timeliner is fully integrated with ISS and can be used to automate ISS operations tasks. Some of the most challenging aspects of operating a payload in low earth orbit are communication delays, ground equipment failures, and human errors. How does a Payload Developer (PD) know their equipment is operating nominally and collecting science in the most efficient way possible or even powered at any given time? During a ground Loss of Signal (LOS) data outage, PDs have no insight into their experiments state, and benefit greatly from Timeliner scripts executing on ISS to perform telemetry monitoring and commanding operations. This paper will discuss current software designs, and new operational uses for Timeliner. Existing Timeliner capabilities discussed will include: autonomous EXPRESS Rack activation and deactivation; autonomous science data downlinks; Minus Eighty Degree Freezer (MELFI) Dewar autonomous safing; JAXA and ESA module autonomous payload facility safing; as well as many others. New operational concepts discussed will include allowing Timeliner on the payload computer to issue core commands (Thermal, Power, Fire Detection), creation of new ground tools that will monitor the current status of Payload Racks as well as all the messaging from autonomous scripts executing, decreasing approval time for Timeliner bundles, and opening up the Payload MDM Enhanced Processor Integrated Communications Card (EPIC) interface. The EPIC interface could provide a new crew interface for PL Timeliner execution. The new interface could operate on either a Payload Computer System (PCS) or a Station Support Computer (SSC) that is plugged into either the Payload LAN or the Operations LAN which will make communicating to the PL MDM more flexible and greatly increase band width for communication.

Space Mission Automation

Ku-band signal design study

Analytical tools, methods and techniques for assessing the design and performance of the space shuttle orbiter data processing system (DPS) are provided. The computer data processing network is evaluated in the key areas of queueing behavior synchronization and network reliability. The structure of the data processing network is described as well as the system operation principles and the network configuration. The characteristics of the computer systems are indicated. System reliability measures are defined and studied. System and network invulnerability measures are computed. Communication path and network failure analysis techniques are included.

Rubin, I.

Attitude and articulation control for CRAF/Cassini

The Comet Rendezvous/Asteroid Flyby (CRAF) and Cassini planetary missions provide exciting pointing and control challenges. The mission and science objectives, and an attitude and articulation control concept designed to meet these challenges, are described. CRAF/Cassini mission characteristics which drive pointing and control include: close range flybys of asteroids and icy satellites; Huygens probe guidance and communication; Saturn orbit insertion; comet rendezvous and orbit insertion; closed loop target tracking from a comet orbit perturbed by gas and dust pressure; fine spacecraft pointing for Titan radar mapping and Earth communications; requirements for autonomous failure detection; isolation; recovery; and 13.5 year lifetime. The philosophy and approach chosen to meet these challenges and the overall control architecture are addressed, including operational and autonomous safe modes. Critical functions are highlighted, such as charge coupled device imaging of stars and extended bodies which provide references for inertial and target referenced pointing respectively. Tradeoffs and rationale for the selection and location of sensors and actuators are reviewed.

Bell, C. E.

Proximity operations considerations affecting spacecraft design

Proximity operations can be defined as the maneuvering of two or more spacecraft within 1 nautical mile range, with relative velocity less than 10 feet per second. The passive vehicle is nontranslating and should provide for maintenance of the desired approach attitude. It must accommodate the active (translating) vehicle induced structural loads and performance characteristics (mating hardware tolerances), and support sensor compatibility (transponder, visual targets, etc.). The active vehicle must provide adequate sensor systems (relative state information, field-of-view, redundancy), flight control hardware (thruster sizing, minimal cross-coupling, performance margins, redundancy) and software (reconfigurable, attitude/rate modes, translation and rotation fine control authority) characteristic, and adequate non-propulsive consumables such as power. Operational concerns must be considered. These include the following: (1) the desired approach trajectory and relative orientation; (2) the active vehicle thruster plume effects (forces, torques, contamination) on the passive vehicle; and (3) procedures for contingencies such as loss of communications, sensor or propulsion failures, and target vehicle loss of control.

Staas, Steven K.

Understanding Crew Decision-Making in the Presence of Complexity: A Flight Simulation Experiment

Crew decision making and response have long been leading causal and contributing factors associated with aircraft accidents. Further, it is anticipated that future aircraft and operational environments will increase exposure to risks related to these factors if proactive steps are not taken to account for ever-increasing complexity. A flight simulation study was designed to collect data to help in understanding how complexity can, or may, be manifest. More specifically, an experimental apparatus was constructed that allowed for manipulation of information complexity and uncertainty, while also manipulating operational complexity and uncertainty. Through these manipulations, and the aid of experienced airline pilots, several issues have been discovered, related most prominently to the influence of information content, quality, and management. Flight crews were immersed in an environment that included new operational complexities suggested for the future air transportation system as well as new technological complexities (e.g. electronic flight bags, expanded data link services, synthetic and enhanced vision systems, and interval management automation). In addition, a set of off-nominal situations were emulated. These included, for example, adverse weather conditions, traffic deviations, equipment failures, poor data quality, communication errors, and unexpected clearances, or changes to flight plans. Each situation was based on one or more reference events from past accidents or incidents, or on a similar case that had been used in previous developmental tests or studies. Over the course of the study, 10 twopilot airline crews participated, completing over 230 flights. Each flight consisted of an approach beginning at 10,000 ft. Based on the recorded data and pilot and research observations, preliminary results are presented regarding decision-making issues in the presence of the operational and technological complexities encountered during the flights.

Young, Steven D.

Survivable Failure Data Recorders for Spacecraft

A spacecraft may be unable to communicate critical data associated with a serious or catastrophic failure. A brief report proposes a system, somewhat like a commercial aircraft "black box," for retrieving these data. A microspacecraft attached to the prime spacecraft would continually store recent critical data from that spacecraft. If either spacecraft detected certain serious conditions of the prime spacecraft, the microspacecraft would separate from the prime spacecraft and independently transmit the stored data to Earth. Supplemental data, acquired from sensors onboard the microspacecraft, could be added to this transmission. For example, the orientation and angular rates of the prime spacecraft immediately before separation as well as pictures taken of the prime spacecraft after separation could be included. Functional enhancements over aircraft black boxes include the separation from the prime vehicle (which gains independence from the fate of that vehicle), wireless transmission of data (making physical black box recovery unnecessary), and the optional acquisition of supplemental sensor data.

Carraway, John

Operational characteristics of the dispersed sensor processor mesh

The dispersed sensor processing mesh (DSPM) is part of an experimental system used to pursue a proof of concept for an advanced fault-tolerant communication strategy. The DSPM experiments incorporate sensors and effectors into an ultra-reliable nodal network in which a central bus controller performs algorithms to grow and maintain the network. The experiments demonstrate that DSPM is an achievable communication network that can sustain failures and continue to function properly. The results of the experiment give insights into the unique characteristics of the DSPM network and the network's capacity to limit physical damage propagation, limit damaged-data propagation, and to survive cyclic communication paths. This paper describes the concept, mechanization, and performance of the DSPM system in a real-time flight-critical environment.

Abbott, L. W.

The Raid distributed database system

Raid, a robust and adaptable distributed database system for transaction processing (TP), is described. Raid is a message-passing system, with server processes on each site to manage concurrent processing, consistent replicated copies during site failures, and atomic distributed commitment. A high-level layered communications package provides a clean location-independent interface between servers. The latest design of the package delivers messages via shared memory in a configuration with several servers linked into a single process. Raid provides the infrastructure to investigate various methods for supporting reliable distributed TP. Measurements on TP and server CPU time are presented, along with data from experiments on communications software, consistent replicated copy control during site failures, and concurrent distributed checkpointing. A software tool for evaluating the implementation of TP algorithms in an operating-system kernel is proposed.

Bhargava, Bharat

7.3 Communications and Navigation

This presentation gives an overview of the networks NASA currently uses to support space communications and navigation, and the requirements for supporting future deep space missions, including manned lunar and Mars missions. The presentation addresses the Space Network, Deep Space Network, and Ground Network, why new support systems are needed, and the potential for catastrophic failure of aging antennas. Space communications and navigation are considered during Aerocapture, Entry, Descent and Landing (AEDL) only in order to precisely position, track and interact with the spacecraft at its destination (moon, Mars and Earth return) arrival. The presentation recommends a combined optical/radio frequency strategy for deep space communications.

Manning, Rob