This paper provides an approach to capture state-based behavior of elements, that is, the specification of their state evolution in time, and the interactions amongst them. Elements can be components (e.g., sensors, actuators) or environments, and are characterized by state variables that vary with time. The behaviors of these elements, as well as interactions among them are represented through constraints on state variables. This paper discusses the concepts and relationships introduced in this behavior ontology, and the modeling patterns associated with it. Two example cases are provided to illustrate their usage, as well as to demonstrate the flexibility and scalability of the behavior ontology: a simple flashlight electrical model and a more complex spacecraft model involving instruments, power and data behaviors. Finally, an implementation in a SysML profile is provided.
This software implements a real-time access protocol that is intended to make all connected users aware of the presence of other connected users, and which of them is currently of the system. Here, in control means that a single user is authorized and enabled to issue instructions to the system. The software The software also implements a goal scheduling mechanism that can detect situations where plans for the operation of a target system proposed by different users overlap and interact conflicting ways. In such situations, the system can either simply report the conflict (rejecting one goal or the entire plan), or reschedule the goals a way that does not conflict. The access mechanism (and associated protocol) is unique. Other access mechanisms are generally intended to authenticate users, or exclude unauthorized access. This software does neither, and would likely depend on having some other mechanism to support those requirements.
The Mission Data System provides a framework for modeling complex systems in terms of system behaviors and goals that express intent. Complex activity plans can be represented as goal networks that express the coordination of goals on different state variables of the system. Real-time projection extends the ability of this system to verify plan achievability (all goals can be satisfied over the entire plan) into the execution domain so that the system is able to continuously re-verify a plan as it is executed, and as the states of the system change in response to goals and the environment. Previous versions were able to detect and respond to goal violations when they actually occur during execution. This new capability enables the prediction of future goal failures; specifically, goals that were previously found to be achievable but are no longer achievable due to unanticipated faults or environmental conditions. Early detection of such situations enables operators or an autonomous fault response capability to deal with the problem at a point that maximizes the available options. For example, this system has been applied to the problem of managing battery energy on a lunar rover as it is used to explore the Moon. Astronauts drive the rover to waypoints and conduct science observations according to a plan that is scheduled and verified to be achievable with the energy resources available. As the astronauts execute this plan, the system uses this new capability to continuously re-verify the plan as energy is consumed to ensure that the battery will never be depleted below safe levels across the entire plan.
The increasingly ambitious requirements levied on JPL's space science missions, and the development pace of such missions, challenge our current engineering practices. 12All the engineering disciplines face this growth in complexity to some degree, but the challenges are greatest in systems engineering where numerous competing interests must be reconciled and where complex system-level interactions must be identified and managed. Undesired system-level interactions are increasingly a major risk factor that cannot be reliably exposed by testing, and natural-language single-viewpoint specifications are inadequate to capture and expose system level interactions and characteristics. Systems engineering practices must improve to meet these challenges, and the most promising approach today is the movement toward a more integrated and model-centric approach to mission conception, design, implementation and operations. This approach elevates engineering models to a principal role in systems engineering, gradually replacing traditional document-centric engineering practices.
Large telescopes are characterized by a high level of distribution of control-related tasks and will feature diverse data flow patterns and large ranges of sampling frequencies; there will often be no single, fixed serverclient relationship between the control tasks. The architecture is also challenged by the task of integrating heterogeneous subsystems which will be delivered by multiple different contractors. Due to the high number of distributed components, the control system needs to effectively detect errors and faults, impede their propagation, and accurately mitigate them in the shortest time possible, enabling the service to be restored. The presented Data-Driven Architecture is based on a decentralized approach with an end-to-end integration of disparate, independently-developed software components. These components employ a high-performance standardsbased communication middle-ware infrastructure, based on the Data Distribution Service. A set of rules and principles, based on JPL's State Analysis method and architecture, are use to constrain component-tocomponent interactions, where the Control System and System Under Control are clearly separated. State Analysis provides a model-based process for capturing system and software requirements and design, greatly reducing the gap between the requirements on software specified by systems engineers and the implementation by software engineers. The method and architecture has been field tested at the Very Large Telescope, where it has been integrated into an operational system.
The ight software on virtually every mission currently managed by JPL has several major aws that make it vulnerable to potentially fatal software defects. Many of these problems can be addressed by recently developed partitioned operating systems (OS). JPL has avoided adopting a partitioned operating system on its ight missions, primarily because doing so would require signi cant changes in ight software design, and the risks associated with changes of that magnitude cannot be accepted by an active ight project. The choice of a partitioned OS can have a dramatic e ect on the overall system and software architecture, allowing for realization of bene ts far beyond the concerns typically associated with the choice of OS. Speci cally, we believe that a partitioned operating system, when coupled with an appropriate architecture, can provide a strong infrastructure for developing systems for which reusability, modi ability, testability, and reliability are essential qualities. By adopting a partitioned OS, projects can gain bene ts throughout the entire development lifecycle, from requirements and design, all the way to implementation, testing, and operations.
** †† ‡‡ Long duration human-robotic missions to the Moon and beyond will require increased use of automation beyond current Space Shuttle and International Space Station practice. This paper explores the application of a model- and state-based goal-oriented control architecture to solving the problem of coordinating activities between humans and robots to improve the reliability and safety of these interactions. A goal-oriented control system continuously enforces constraints on states of the system to achieve not only control goals, but also to enforce passive constraints, such as safety constraints, on those activities.
In black-box testing, the system being tested is typically characterized as a number of inputs, where each input can take one of a number of values. Thus each test is a vector of input settings, and the set of possible tests is an N dimensional space, where N is the number of inputs. For example, an instance of a simulation of a crew exploration vehicle's (CEV) launch pad abort scenario can have 76 floating-point inputs. Unfortunately, for such a large number of inputs only a small percentage of the test space can be actually tested. This paper characterizes levels of partial test space coverage and presents Testgen, a tool for generating a suite of tests that guarantees a level of test space coverage, which a user can adapt to take advantage of knowledge of system internals. This ability to adapt coverage makes Testgen a gray-box testing tool.
*In 2007 the NASA Office of Chief Engineer commissioned a multi-center study to bring forth technical and managerial strategies to address risks from growth in size and complexity of flight software in NASA’s space missions. The motivation for the study grew from problems attributed to flight software in a variety of missions—in both pre-launch and post-launch activities—and concerns that such problems were growing with the expanding role of flight software. The study was tasked to examine the growth in flight software size and complexity, recommend ways to reduce and better manage complexity, and identify methods of testing complex logic. This report examines complexity throughout the engineering lifecycle—from requirements definition through design, development, verification, and operations—and presents sixteen findings and associated recommendations.
In robotic space missions the purpose of any operat ions paradigm is to achieve specific objectives while protecting the health of the space vehicle(s). Unfortunately, in the dominant paradigm of command sequencing, the representation of such objectives, health constraints and other dependencies is left behind in the ground -based activity planning process and never carried into uplinked products where it can s upport context-specific status monitoring, resource allocation, fault protection, and general automation on the spacecraft. In contrast, in the paradigm of goal-based operations, operational objectives are everpresent, from the beginning of activity planning al l the way to execution on a space vehicle. This paper examines the change in operations perspective from command sequencing to goal-based operations, with particular emphasis on the uplinked product—termed a goal network —and the design of goal elaborators needed to generate it.
As the challenges of space missions have grown over time, we have seen a steady trend toward greater automation, with a growing portion assumed by the spacecraft. This trend is accelerating rapidly, spurred by mounting complexity in mission objectives and the systems required to achieve them. In fact, the advent of truly self‐directed space robots is not just an imminent possibility, but an economic necessity, if we are to continue our progress into space. What is clear now, however, is that spacecraft system complexity is reaching a threshold where customary methods of control are no longer affordable or sufficiently reliable. At the heart of this problem are conventional approaches to systems and software engineering. Divide‐and‐conquer strategies based on subsystem‐level functional decomposition fail to scale in the tangled web of interactions typically encountered in complex spacecraft designs, where subsystems are inevitably very tightly coupled through their need to share limited resources and perform robustly in uncertain environments. A straightforward extrapolation of past methods has neither the conceptual reach nor the analytical depth to address the challenges associated with future space exploration objectives. Furthermore, there is a fundamental gap between the requirements on software specified by systems engineers and the implementation of these requirements by software engineers. Software engineers must perform the translation of requirements into software code, hoping to accurately capture the systems engineer's understanding of the system behavior, which is not always specified explicitly or completely. This gap opens up the possibility for misinterpretation by the software engineer of the systems engineer's intent, potentially leading to software errors. Similar problems can arise during operations. These challenges have motivated the development of the Mission Data System (MDS), a unified software architecture for distributed, automated flight, ground, and test systems, and a novel systems engineering methodology, called State Analysis. State Analysis addresses these challenges by asserting the following basic principles. a principal engineer in the Systems and Software division at JPL. He has been a member of the technical staff at JPL since 1975, gaining extensive experience in spacecraft attitude control and computer systems, test and flight operations, and automation and autonomy ‐ particularly in the area of spacecraft fault protection. His flight mission adventures include systems engineering for Voyager and
This objectives of this slide presentation are to: (1) Share JPL experiences by describing the evolution of fault protection during its history in deep space exploration, (2) Examine issues of fault protection scope and implementation that affect missions today, and (3) Discuss solutions for the problems of today and tomorrow.
NASA is currently evaluating the benefits of transitioning to a highly reconfigurable network of arrayed dish antennas to support an increasing number of deep space missions. The next-generation Deep Space Network (NG-DSN), as currently conceptualized, would require extensive automation to reduce operations cost and handle the increased complexity associated with monitoring and controlling the larger number of antennas. This paper presents a prototype operations architecture for the proposed NG-DSN that is fundamentally based on three concepts: physical state variables of the system to be controlled, expressions of operational intent for those state variables (“goals”), and models describing the behavior of these state variables and their interactions. These concepts shape the software design of an automated control system, the model-based systems engineering analysis that feeds this design, and the human operator interface to the control system. This control system provides for automation of capabilities such as resource allocation and fault recovery (both localized and system-wide). This paper describes the development and demonstration of the control system on prototype antenna array hardware at the Jet Propulsion Laboratory.
This slide presentation shows several case studies for fault protection. The cases involve a discovery-class mission to excavate material from a comet, rendezvous with two asteroids and develop a prototype system for a next-generation Deep Space Network consisting of ndca large array of small antennas.
Time-based command sequencing is the traditional paradigm for control of spacecraft and rovers in NASA's robotic missions, but this paradigm has been increasingly strained to accommodate today's missions. Goal-based control is a new paradigm that supports time-driven and event-driven operation in a more natural way and permits a melding of sequencing and fault protection into a single control paradigm. This paper describes one approach to goal-based control as an architectural pattern in terms of purpose, motivation, structure, applicability, and consequences. This paper is intended to help flight and ground software engineers understand the new paradigm and how it compares to time-based sequencing.