Engineering PapersSearch

SEARCH · Engineering Papers

Results for “operations”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Investigating the impact of a multi-module operation environment on the task performance time of human operators – An explanatory study

The worldwide demand for Small Modular Reactors (SMRs) has surged in recent years due to their enhanced safety and versatility in supporting diverse industrial sectors. A unique feature of SMR operation is that a single human operator is responsible for managing multiple modules. Therefore, securing a sufficient amount of human performance data pertaining to this new environment is essential for the safe operation of SMRs. In this explanatory study, a series of experiments were conducted using the NuScale simulator, a representative SMR design, with student operators. A total of 12 student operators were assigned two types of off-normal events and asked to cope with them using paper-based procedures. Subsequently, their task performance times were compared with those of student operators responsible for a single unit based on the Task Complexity (TACOM) measure. Results indicate that the performance of student operators under the experimental conditions of this study degraded by a factor of 2 to 3, depending on the characteristics of the off-normal events.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS

Integrated operation scenarios: Chapter 6 of the special issue: on the path to tokamak burning plasma operation

Here we report the progress of the development and optimization of operational scenarios for ITER and beyond, focusing upon baseline, hybrid, and steady-state scenarios since 2007. This includes advancements made by the integrated operation scenarios (IOS) topical group of the international tokamak physical activity as well as contributions from the broader tokamak community. The key area of research involves developing IOSs that encompass tokamak physics, operation, and technology by utilizing integrated modeling and control strategies. This requires leveraging available actuators to simultaneously control plasma position and shape, MHD activities that could lead to disruptions, transport, plasma-wall interaction and power exhaust, fuel cycle, fusion burn, and tritium breeding. The control extends from the plasma initiation phase, through the current ramp-up, flattop, start and end of the fusion burn, and current ramp-down, to the plasma termination phase. A review of the currently developed scenarios and modeling is provided in terms of (i) optimizing plasma initiation in ITER, (ii) preparing for the low activation phase to fully commission all tokamak systems and establish and validate physics and scenario conditions in preparation for deuterim-tritium (DT) operation, (iii) developing and preparing baseline and hybrid scenarios to demonstrate the feasibility of achieving these regimes within device constraints, (iv) exploring steady-state scenarios to meet ITER’s steady-state goals, (v) evaluating and preparing actuators for ITER, (vi) developing integrated control solutions using shared actuators. The most notable achievements include; (i) the development of ITER demonstration discharges by matching various dimensionless parameters, (ii) the development of scenarios in an ITER-like tungsten environment and DT operation, and (iii) the development of scenarios in superconducting tokamaks, enabling long-pulse operations with similar coil constraints to ITER. Along with these significant achievements, outstanding issues and recommendations for further research and development are provided. Importantly, this study goes beyond simply updating the ITER Physics Basis; it carries profound implications for the broader field of burning plasma research, offering valuable insights and guidance for the next generation of fusion experiments and devices.

ITER

Voltage cycling as a dynamic operation mode for high temperature electrolysis solid oxide cells

Solid Oxide Electrolysis Cells (SOECs) have emerged as a promising technology for the efficient production of H2 via high-temperature electrolysis. However, power input from dynamic energy sources remains a significant challenge for their long-term stability. It is important to analyze the tolerance of cells under dynamic operation conditions. This study focuses on evaluating the impact of voltage cycling on the performance and durability of electrode-supported SOECs. We explore the operational limits and degradation mechanisms of SOECs subjected to various voltage conditions and find that the cells have high tolerance for dynamic voltage. Voltage cycling between 1.3 V and 1.5 V for 9000 cycles does not damage the cell. Conversely, cycling to higher voltages (≥1.7 V) results in accelerated degradation. Advanced characterization is used to screen for various degradation modes post operation. Within the oxygen electrode, XRD and STEM EDS find compositional and phase evolution in all voltage cycled samples including increased decomposition of the air electrode resulting in cation migration. Microstructural analysis of the fuel electrode from nano-CT data shows minimal change throughout the sample set and no evidence of Ni migration, indicating the fuel electrode is stable and not impacted by cycling to higher voltages within the timeframe studied.

Zhu, Zhikuan

Operational Evolution of FTS3: A DevOps Driven Approach to Elastic Operations

The File Transfer Service (FTS3) is a distributed data movement service developed at CERN and widely used to transfer data across the Worldwide LHC Computing Grid (WLCG). At Fermilab, FTS3 supports data transfers for multiple experiments, including Intensity Frontier experiments such as DUNE, enabling reliable data movement between WebDAV endpoints in Europe and the Americas.​ At CHEP 2021, we reported on the initial containerized deployment of FTS3 on OKD, the community Kubernetes distribution of Red Hat OpenShift. In this work, we present the subsequent evolution of this deployment, focusing on new operational capabilities introduced to improve scalability, robustness, and long-term maintainability.​ We describe the adoption of more secure and reproducible container build workflows, the integration of DevOps-driven operational practices, and enhancements in monitoring and automation. A key new result is the introduction of horizontal scaling and elastic resource management, allowing FTS3 components to dynamically adapt to workload variations while maintaining service reliability. We also discuss improvements in fault tolerance and operational procedures derived from production experience.​ Finally, we summarize lessons learned from operating FTS3 as a Kubernetes-native service and outline how these developments have improved the resilience and efficiency of data movement operations at Fermilab.

Munoz Flores, Victor Leopoldo [Fermilab]

Novel Organosulfur-Based Electrolytes for Safe Operation of High Voltage Li-ion Batteries over a Wide Operating Temperature

This project addresses the failure of conventional electrolytes and enables high-voltage operation of lithium-ion batteries (LIBs) by developing a novel organosulfur-based electrolyte system. To achieve this goal, we first designed and synthesized new organosulfur solvents that functionalized with strong electron-withdrawing groups such as fluoroalkyl and cyano substituents. Through regio-specific molecular engineering, supported by theoretical calculations, we lowered the highest occupied molecular orbital (HOMO) energy levels of these molecules to increase their anodic stability for high-voltage operation. We then optimized the formulation of the organosulfur-based electrolyte with additives, co-solvents and salts tailored to the newly synthesized solvent molecules. In parallel, we utilized advanced spectroscopic techniques—including in situ FTIR, EIS, and DEMS—to thoroughly elucidate the mechanisms of interaction between the electrolyte and electrode materials. Finally, we evaluated 2 Ah pouch cells under both normal and extreme conditions. Pouch cells with the newly developed electrolyte system demonstrated >90% capacity retention after 500 cycles under 4.5 V operating voltage, >80% capacity retention after 1000 cycles in coin cell level. In addition, the cells exhibited high safety and reliable operation capability over a wide temperature range from −30 °C to +45 °C.

25 ENERGY STORAGE

The JPL Telerobot Operator Control Station: Operational Experiences

The Operator Control Station of the JPL/NASA Telerobot Demonstration System provides an efficient man-machine interface for the performance of telerobot tasks. Its hardware and software have been designed with high flexibility. It provides a feedback-rich interactive environment in which the Operator performs teleoperation tasks, robotic tasks, and telerobotic tasks with ease. The to-date operational experiences of this system, particularly related to the Object Designate Process and the Voice Input/Output Process are discussed.

Edwin P Kan

Influence of Operating Conditions on Ethanol Passive Prechamber Cold-start Operation

Cold-start operation in spark ignition engines is characterized by many drawbacks such as poor fuel vaporization, substantial wall film formation, and weak ignition which can result in unstable combustion and high concentrations of carbon monoxide (CO), nitrogen oxides (NOx), and unburnt hydrocarbons (UHC) prior to catalyst light-off. These challenges are particularly important for ethanol as the fuel’s high latent heat of vaporization and low vapor pressure can hinder reliable ignition during cold-start. In this context, passive prechamber ignition systems offer a viable pathway to improve ignitability by producing hot turbulent jets that can promote combustion in the main chamber. In this study, the influence of operating conditions on jet formation and combustion characteristics in an ethanol-fueled passive prechamber spark ignition engine is investigated. Two intake pressures (40 kPa and 60 kPa) and two engine speeds (450 and 600 rpm) are studied to represent various stages of the cold-start ramp-up. Results indicate that lower intake pressures lead to delayed and asymmetric turbulent jet formation, and lower peak heat release rates. Lower engine speeds, on the other hand, produced higher peak heat release and faster combustion due to greater residence time in the engine. This greater residence time also increases the likelihood of autoignition in the main chamber, potentially promoting quicker heat release for lower engine speeds. These results provide insight into the role of operating conditions on cold-start ramp-up of passive prechamber engines.

Banagiri, Shrikar [ORNL] (ORCID:0000000239745099)

Heterogeneous Mixtures of Dictionary Functions to Approximate Subspace Invariance in Koopman Operators: Why Deep Koopman Operators Work

Abstract Koopman operators model nonlinear dynamics as a linear dynamic system acting on a nonlinear function as the state. This nonstandard state is often called a Koopman observable and is usually approximated numerically by a superposition of functions drawn from a dictionary . In a widely used algorithm, extended dynamic mode decomposition (EDMD), the dictionary functions are drawn from a fixed class of functions. Deep learning combined with EDMD has been used to learn novel dictionary functions in an algorithm called deep dynamic mode decomposition (deepDMD). The learned representation both (1) accurately models and (2) scales well with the dimension of the original nonlinear system. In this paper, we analyze the learned dictionaries from deepDMD and explore the theoretical basis for their strong performance. We explore State-Inclusive Logistic Lifting (SILL) dictionary functions to approximate Koopman observables. Error analysis of these dictionary functions show they satisfy a property of subspace approximation, which we define as uniform finite approximate closure. Typically, a Koopman dictionary’s nonlinear functions are homogeneous. In this paper, we discover that structured mixing of heterogeneous dictionary functions drawn from different classes of nonlinear functions achieve the same accuracy and dimensional scaling as the deep-learning-based deepDMD algorithm Yeung et al. ( In: 2019 American Control Conference (ACC), 2019). We specifically show this by building a heterogeneous dictionary comprised of SILL functions and conjunctive radial basis functions (RBFs). This mixed dictionary achieves similar accuracy and dimensional scaling to deepDMD with an order of magnitude reduction in parameters, while maintaining geometric interpretability. These results strengthen the viability of dictionary-based Koopman models to solving high-dimensional nonlinear learning problems.

Johnson, Charles A.

Flexible Operation of Microgrids Through Operator-Configurable Microgrid Controllers

Microgrids are becoming critical assets in power distribution systems. This is partly due to the resiliency and reliability challenges faced by power distribution systems in the last decade and partly due to the increased integration of distributed energy resource assets, such as solar photovoltaic. This increased need for microgrids has created a multitude of needs for microgrid controllers. Most microgrid controllers in the past decade have been uniquely programmed or custom programmed to meet the needs of a specific microgrid. Currently, IEEE standards aim to integrate the needs and capabilities of microgrid controllers under a unified umbrella. But the standards do not recommend necessary or appropriate software development practices for microgrid controllers. In addition, the programmable nature and maintenance of controllers are also key characteristics that fall outside the coverage of the standards. In this paper, we present the best software practices that utility engineers and microgrid operators should consider in the microgrid software platform. This paper can be used as an information document for developing documentation of controller requirements and assessing microgrid controller requirements.

Banshee microgrid

Hazard and Operability Analysis for Operating, Refueling, and Maintenance of Fuel Cell Electric Buses

​​Since hydrogen vehicles can be implemented in heavy-duty transportation applications such as buses, it is important to understand safety hazards and risks of hydrogen fuel cell electric bus (FCEB) and refueling technology. We conducted a hazard and operability analysis for FCEB operation/driving, refueling, and maintenance/inspection. We identified failure modes and consequences and defined a qualitative risk metric as the product of the likelihood of a failure and the severity of the worst-ca

08 HYDROGEN

Testing of operating envelope to support DF LAW operations

The primary objective of the present work was to investigate the potential impact of likely process variations on the nominal glass composition for LAW AP-107 waste that is determined by the LAW glass correlation (AP107WDFL). This was accomplished by evaluating glass and feed variations at crucible scale and DM100 melter tests.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Implementation and Demonstration of the Digital Twin Certification System Remote Operations Framework

Microreactors are one promising advanced-reactor concept being pursued by the nuclear industry. They are distinguished by a relatively low power output of 20 MWth or less. These microreactors are intended for deployment in applications where conventional small-capacity power solutions, such as diesel generators, are either economically unfeasible or logistically challenging. Such applications include providing electric power and/or heat for remote communities, mining sites, defense installations, and humanitarian and disaster-relief missions. An important feature for the successful deployment of microreactors is their capability to be operated remotely. This capability can significantly reduce staffing costs by eliminating the need for licensed operators to be physically present at each reactor site. Instead, operators can be centralized in a single remote operations center placed in an economically advantageous location, thereby optimizing resources by consolidating expertise and enhancing operational efficiency. However, the implementation of a remote operation system for nuclear reactors raises new concerns regarding the security, reliability, and resilience of such a system. One way in which remote operations can be supported in a manner that maintains system security, reliability, and resilience is through the use of digital twins in a novel framework designed to verify and validate sensor data and commands communicated between the remote operations center and reactor. This framework, known as the Digital Twin Certification System (DTCS), has previously been proposed as an operations architecture that can bring security and resiliency levels of remote nuclear-reactor operations to a level acceptable for commercial deployment. This paper moves the proposed DTCS architecture from concept to reality by presenting the implementation and testing of the system. The rationale and implementation of the DTCS using tools such as DeepLynx and Apache Airflow, is covered in-depth. This is followed by a demonstration of the DTCS by applying the implemented system architecture to the Single Primary Heat Extraction and Removal Emulator, a small-scale non-nuclear test bed that emulates thermal behavior of a microreactor. The demonstration includes both normal and abnormal operating scenarios to highlight how the DTCS can increase the security, reliability, and resilience of a remote operations system.

22 - GENERAL STUDIES OF NUCLEAR REACTORS

A Comparison of Pre‐Construction and Operational Wake Loss Estimates for Land‐Based Wind Plants

The overall bias between pre‐construction energy yield assessment (EYA) estimates of wind plant energy production and the achieved operational production is improving in the wind industry, but uncertainty remains high for individual wind plants. Wake effects within wind plants are one of the largest sources of energy loss considered in the EYA process, and previous work shows wake loss estimates to be a major source of disagreement among wind energy consultants who perform EYAs. To better understand the accuracy of wake loss predictions, we compare overall operational wake loss estimates based on supervisory control and data acquisition data to pre‐construction estimates provided by six wind energy consultants for five land‐based wind plants in North America. By augmenting existing approaches for quantifying operational wake losses, we estimate wake losses during the period of record for which operational data are available as well as the expected long‐term wake losses, based on historical reanalysis weather data, to which the EYA estimates are compared. To account for power variations at different turbine locations caused by terrain‐induced wind resource heterogeneity, we correct the operational wake loss estimates using predicted freestream wind speed variations from the Wind Systems Engineering Reynolds‐averaged Navier–Stokes (RANS) tool. We identify long‐term corrected operational wake losses between 1.9% and 6.4% for the five plants, with a mean loss of 4%. For the project deemed most acceptable for operational wake loss assessment, which is located in the simplest terrain and isolated from neighboring plants, the mean EYA wake loss estimate is within 0.7 percentage points of the operational value of 6.4%. For most of the remaining plants, results suggest that wake losses are generally overpredicted by 2.6–6.3 percentage points. However, operational wake losses may be underestimated for many of these projects because of spatial wind resource variations not captured by the RANS model, external wake effects that are unaccounted for in the estimation process, and wind plant blockage effects. To better understand factors that contribute to the observed wake losses, we investigate operational wake losses as a function of wind direction and wind speed. As expected, wake losses are generally concentrated near wind directions that are aligned with rows of closely spaced turbines and at below‐rated wind speeds; however, for some projects, the energy produced by the wind plant exceeds the estimated potential energy of the plant without wake interactions for certain wind directions and wind speeds, suggesting inaccurate assumptions in the wake loss estimation method for those plants. Lastly, we compare predicted and operational wake losses for individual wind turbines, finding that even when overall wake losses are predicted accurately, large uncertainty exists at the turbine level.

17 WIND ENERGY

Cyber Conservative Operations

In an era of increasingly sophisticated and pervasive cyber threats, robust cyber resilience strategies are more critical than ever. This paper introduces the concept of Cyber Conservative Operations, a proactive approach designed to assist critical infrastructure owners and operators in managing risk and maintaining resilience in the face of imminent, yet not occurring, cyber events. By leveraging the principles of Cyber-Informed Engineering (CIE) and the energy sector’s practice of conservative operations, Cyber Conservative Operations offer a framework for planning and executing coordinated active defense and resilience-oriented actions ahead of cyber events. This approach aims to minimize the consequences of digitally-enabled hazards and ensure swift recovery from anticipated cyber threats. Cyber Conservative Operations enhance the ability of owners and operators to execute pre-planned defense and resilience actions, thereby reducing the impact of digitally-enabled hazards. These operations are crucial for addressing impacts that cannot be precisely quantified or forecasted and for preparing organizations for rapid recovery from imminent digital threats. The paper begins with a discussion of conservative operations as applied to the bulk power system (BPS), a current mechanism allowing BPS entities to enact defensive operating plans to mitigate impending grid unreliability. Building on this model, we present a concept for implementing cyber conservative operations at asset owner facilities. The paper concludes with two case studies of cyber conservative operations drawn from high-profile cyber events, illustrating the practical application and benefits of this proactive approach.

42 - ENGINEERING

Human Supervision of Autonomous Vehicle Fleet Operations and Associated Passenger Communications: Preprint

Advances in automated vehicle (AV) technology and expanded operations are rapidly emerging with Automated Mobility District (AMD) deployments in global cities. NLR's AMD research addresses critical elements of human supervision of AV fleet operations and associated passenger communications for vehicles in which no driver or safety attendant is present. Although sufficiently advanced AVs no longer have direct oversight by a driver, fleet management remains staffed with operations personnel at the operations command and control (OCC) facility. This paper examines the functionality of the OCC, drawing comparisons of how automated train control and automated people mover OCCs operate. Within an AMD, the OCC manages various vehicle types, sizes, and operational modes, including on-demand and fixed route service, to facilitate a 'network of networks' for transport within a metropolitan area. The OCC serves as oversight for multiple AV fleets assisting AVs via remote operation of vehicles, communication, and dispatching personnel to resolve problems. The OCC also coordinates system operation, geographically staging vehicles, and managing weather, police, and emergency events. Informed by traffic management center (TMC) strategies using highly integrated software and communications, OCCs facilitate seamless information flows. OCC personnel remotely assist passengers and oversee multi-party operation to ensure safety and security. Although social norms mitigate large-capacity unattended vehicle operations, social interaction in multi-party automated small vehicles has little precedent. This poses a new frontier for society and requires research to effectively understand and manage. Future research will monitor OCC implementations, passenger interfaces, and deployment scaling of initial AMD systems.

33 ADVANCED PROPULSION SYSTEMS

General Purpose Data-Driven Monitoring for Space Operations

As modern space propulsion and exploration systems improve in capability and efficiency, their designs are becoming increasingly sophisticated and complex. Determining the health state of these systems, using traditional parameter limit checking, model-based, or rule-based methods, is becoming more difficult as the number of sensors and component interactions grow. Data-driven monitoring techniques have been developed to address these issues by analyzing system operations data to automatically characterize normal system behavior. System health can be monitored by comparing real-time operating data with these nominal characterizations, providing detection of anomalous data signatures indicative of system faults or failures. Data-driven techniques have a number of advantages over other methods for monitoring complex space vehicles. Unlike model-based systems, the developer does not need to understand or encode the internal operation of the system. The knowledge required to monitor the system is automatically derived from archived data from system operation. Unlike rule-based systems, data-driven systems do not require system analysts to define nominal relationships among sensors. Analysts can and often do determine these relationships for a system with few sensors; it is more difficult to analytically determine the nominal relationship among a large number of sensors. Data-driven techniques are not limited to low-dimensional spaces and work as effectively with dozens of parameters as they do with a few. Knowledge bases formed by data-driven techniques are also easy to update. As the operating envelope of the monitored system is expanded, data-driven techniques can be quickly retrained to incorporate the new behavior into the knowledge base. The expertise and time-consuming process of updating a model or rule base to maintain consistency with the new operation is not required. The Inductive Monitoring System (IMS) is a data-driven system health monitoring software tool that has been successfully applied to several aerospace applications. IMS uses a data mining technique called clustering to analyze archived system data and characterize normal interactions between parameters. This characterization, or model, of nominal operation is stored in a knowledge base that can be used for real-time system monitoring or analysis of archived events. System data is compared with the nominal IMS model to produce a measure of how well current system behavior matches the normal behavior defined by the training data. Significant deviations from the nominal system model can provide alerts to system malfunctions or precursors of significant failures. The scope of IMS based data-driven monitoring applications continues to expand with current development activities. Successful IMS deployment in the International Space Station (ISS) flight control room to monitor ISS attitude control systems has led to applications in other ISS flight control disciplines, such as thermal control. It has also generated interest in data-driven monitoring capability for Constellation, NASA's program to replace the Space Shuttle with new launch vehicles and spacecraft capable of returning astronauts to the moon, and then on to Mars. Several projects are currently underway to evaluate and mature the IMS technology and complementary tools for use in the Constellation program. These include an experiment on board the Air Force TacSat-3 satellite, and ground systems monitoring for NASA's Ares I-X and Ares I launch vehicles. The TacSat-3 Vehicle System Management (TVSM) project is a software experiment to integrate fault and anomaly detection algorithms and diagnosis tools with executive and adaptive planning functions contained in the flight software on-board the Air Force Research Laboratory TacSat-3 satellite. The TVSM software package will be uploaded after launch to monitor spacecraft subsystems such as power and guidance, navigation, and control (GN&C). It will analyze data in real-time to demonstrate detection of faults and unusual conditions, diagnose problems, and react to threats to spacecraft health and mission goals. The experiment will demonstrate the feasibility and effectiveness of integrated system health management (ISHM) technologies with both ground and on-board experiments. Initially, the TVSM software will run open loop, providing system health information and recommendations to ground operators, without automatically performing fault-mitigating corrective actions. After the end of the satellite's mission, closed loop tests combining TVSM monitoring and diagnosis with reactive capabilities by the flight software will be performed. In addition to monitoring for long periods of actual operation, the experiment will include fault injection into TacSat-3 data as well as commanded operations to test and evaluate automatic ISHM monitoring and recovery under controlled conditions.

Satellites