In an effort to effectively develop more complex spacecraft fault management (FM) systems new technologies are sought to enable rapid diagnostic model generation and validation, and provide tools to perform FM analyses Model-based Systems Engineering approaches to FM system development are uniquely suited to be combined with model-based tools currently utilized in the design of other parts of flight systems. Combined tools utilizing information from a common system model can reduce design inconsistencies and gaps in analyses. Tighter integration of FM with other system-level and subsystem-level hardware/software development activities allows crucial redundancy and sensor placement trades to be performed earlier and throughout the mission lifecycle. Our work has been towards the integration of a model-based fault management tool suite called MONSID®, with JPL’s Computer Aided Engineering for Systems ARchitecture (CAESAR ) platform as a way to improve FM system modeling and analysis. MONSID relies on application-specific models of the system being monitored. MONSID models consist of interconnected elements representing system hardware and measurement/command input points, called the topology. Model topology design is currently a manual process and often relies heavily on paper documentation such as hardware/software specs, engineering drawings, and interface control documents. CAESAR is a semantically- driven toolchain for model-based system engineering. At the core is a system model expressed in the Ontological Modeling Language (OML). It is intended to support semantic modeling, consistency validation, and continuous integration. A goal of the combined toolset is to automate FM model development by directly extracting models from CAESAR and then analyzing them in MONSID. Analyses currently available in MONSID include model topology inspection and validation and fault isolation capability based on sensor placement. While we have focused on two specific tools, the integration approaches can be leveraged by other semantically driven model-centric platforms and tools. This paper describes the evolution of our integration approaches as we evaluated different insertion points in the CAESAR toolchain with respect to MONSID model requirements. The MONSID-CAESAR tool is demonstrated on a simplified example of a spacecraft heat reclamation system. Results of the generated MONSID model are discussed, including levels of automation achieved and information surfaced to the users about the extracted model topology.
Model-Based System Engineering (MBSE) employs models and formal languages to support development of complex (systems-of-) systems. NASA Jet Propulsion Laboratory (JPL) sees MBSE as a key approach to managing the complexity of system development. However, balancing agility and rigor in MBSE has been reported as a challenging task not yet addressed by modeling tools and frameworks. This is because existing MBSE approaches may enable agility but compromise rigor, or enhance rigor but impede agility. We discuss the challenges of balancing agility and rigor in MBSE across seven systems engineering architectural functions defined by the JPL Integrated Model-Centric Engineering (IMCE) initiative. We demonstrate how openCAESAR, an open-source MBSE methodology and framework created at JPL, can strike a balance between agility and rigor through a case study of the Kepler16b project and discussion of lessons learned from past projects.
Recent collaborations between JPL's Integrated Model Centric Engineering (IMCE) initiative and the Europa Clipper project have produced six distinct applications of MBSE. Most of these collaborations have been successful, and all have been valuable learning experiences. Here we describe all of the applications including technical approach, benefits, challenges, and lessons learned.
In this paper we describe a system called the Computer Aided Engineering for Spacecraft System Architectures Tool Suite, or CAESAR for short, a platform for enabling model-based system engineering (MBSE). CAESAR recognizes that engineers are already likely to use models, but they typically keep the models private, only interpreting model information into documents or presentations that become project baseline. MBSE needs to enable more automated sharing of information directly between models to ensure model consistency, improve the rigor of engineering process, and ultimately, reduce the effort needed to get a clear answer to engineering questions. We explain the features of CAESAR, and describe how these features were leveraged in a case study where CAESAR was used to develop a model-based process for spacecraft electrical interface design and harness specification for the Europa Clipper flight project.
In 2015 NASA chartered a partnership between the Jet Propulsion Laboratory (JPL) and the Johns Hopkins Applied Physics Laboratory (APL) to begin planning a mission to study the Jovian moon Europa. The project has adopted a Model-Based Systems Engineering (MBSE) approach to its architecting process since its early formulation, developing certain modeling practices and tools as needed, with the expectation that this process would result in a more consistent and verifiable architecture than with a more traditional document-based approach. A sound architecture is essential to provide the rationale for requirements on the system design, and to define the trade space of acceptable design points within which technical and programmatic concerns as well as project objectives can be addressed. This paper provides an overview of the framework used by the Europa project to describe the mission architecture and discusses how a system model was instrumental in providing a singlesource-of-truth for this description. Several key modeling patterns to represent the architecture are presented, along with audit methods to ensure the consistency and the correctness of the model. Finally, the benefits and challenges of using a model-based approach to generate traditional requirements documents and other gate products are assessed.
This paper provides an approach to capture state-based behavior of elements, that is, the specification of their state evolution in time, and the interactions amongst them. Elements can be components (e.g., sensors, actuators) or environments, and are characterized by state variables that vary with time. The behaviors of these elements, as well as interactions among them are represented through constraints on state variables. This paper discusses the concepts and relationships introduced in this behavior ontology, and the modeling patterns associated with it. Two example cases are provided to illustrate their usage, as well as to demonstrate the flexibility and scalability of the behavior ontology: a simple flashlight electrical model and a more complex spacecraft model involving instruments, power and data behaviors. Finally, an implementation in a SysML profile is provided.
State Analysis is a methodology developed over the last decade for architecting, designing and documenting complex control systems. Although it was originally conceived for designing robotic spacecraft, recent applications include the design of control systems for large ground-based telescopes. The European Southern Observatory (ESO) began a project to design the European Extremely Large Telescope (E-ELT), which will require coordinated control of over a thousand articulated mirror segments. The designers are using State Analysis as a methodology and the Systems Modeling Language (SysML) as a modeling and documentation language in this task. To effectively apply the State Analysis methodology in this context it became necessary to provide ontological definitions of the concepts and relations in State Analysis and greater flexibility through a mapping of State Analysis into a practical extension of SysML. The ontology provides the formal basis for verifying compliance with State Analysis semantics including architectural constraints. The SysML extension provides the practical basis for applying the State Analysis methodology with SysML tools. This paper will discuss the method used to develop these formalisms (the ontology), the formalisms themselves, the mapping to SysML and approach to using these formalisms to specify a control system and enforce architectural constraints in a SysML model.
The Mission Data System provides a framework for modeling complex systems in terms of system behaviors and goals that express intent. Complex activity plans can be represented as goal networks that express the coordination of goals on different state variables of the system. Real-time projection extends the ability of this system to verify plan achievability (all goals can be satisfied over the entire plan) into the execution domain so that the system is able to continuously re-verify a plan as it is executed, and as the states of the system change in response to goals and the environment. Previous versions were able to detect and respond to goal violations when they actually occur during execution. This new capability enables the prediction of future goal failures; specifically, goals that were previously found to be achievable but are no longer achievable due to unanticipated faults or environmental conditions. Early detection of such situations enables operators or an autonomous fault response capability to deal with the problem at a point that maximizes the available options. For example, this system has been applied to the problem of managing battery energy on a lunar rover as it is used to explore the Moon. Astronauts drive the rover to waypoints and conduct science observations according to a plan that is scheduled and verified to be achievable with the energy resources available. As the astronauts execute this plan, the system uses this new capability to continuously re-verify the plan as energy is consumed to ensure that the battery will never be depleted below safe levels across the entire plan.
By leveraging the existing Model‐Based Systems Engineering (MBSE) infrastructure at JPL and adding a modest investment, the Europa Mission Concept Study made striking advances in mission concept capture and analysis. This effort has reaffirmed the importance of architecting and successfully harnessed the synergistic relationship of system modeling to mission architecting. It clearly demonstrated that MBSE can provide greater agility than traditional systems engineering methods. This paper will describe the successful application of MBSE in the dynamic environment of early mission formulation, the significant results produced and lessons learned in the process.
Safe human exploration in space missions requires careful management of limited resources such as breathable air and stored electrical energy. Daily activities for astronauts must be carefully planned with respect to such resources, and usage must be monitored as activities proceed to ensure that they can be completed while maintaining safe resource margins. Such planning and monitoring can be complex because they depend on models of resource usage, the activities being planned, and uncertainties. This paper describes a system - and the technology behind it - for energy management of the NASA-Johnson Space Center's Multi-Mission Space Exploration Vehicles (SEV), that provides, in an onboard advisory mode, situational awareness to astronauts and real-time guidance to mission operators. This new capability was evaluated during this year's Desert RATS (Research and Technology Studies) planetary exploration analog test in Arizona. This software aided ground operators and crew members in modifying the day's activities based on the real-time execution of the plan and on energy data received from the rovers.
** †† ‡‡ Long duration human-robotic missions to the Moon and beyond will require increased use of automation beyond current Space Shuttle and International Space Station practice. This paper explores the application of a model- and state-based goal-oriented control architecture to solving the problem of coordinating activities between humans and robots to improve the reliability and safety of these interactions. A goal-oriented control system continuously enforces constraints on states of the system to achieve not only control goals, but also to enforce passive constraints, such as safety constraints, on those activities.
This paper describes a domain-specific language prototype developed for the NASA Constellation launch control system project. A key element of the launch control system architecture, the domain-specific language prototype is a specialized monitor and control language composed of constructs for specifying and programming test, checkout, and launch processing applications for flight and ground systems. The principal objectives of the prototyping activity were to perform a proof-of-concept of an approach to ultimately lower the lifecycle costs of application software for the launch control system, and to explore mitigations for a number of development risks perceived by the project. The language has been implemented as a library that extends the dynamically-typed Python scripting language, and validated in a demonstration of capability required for Constellation. A study of the statically typed Scala programming language as an alternative domain-specific language implementation language is also presented.
Time-based command sequencing is the traditional paradigm for control of spacecraft and rovers in NASA's robotic missions, but this paradigm has been increasingly strained to accommodate today's missions. Goal-based control is a new paradigm that supports time-driven and event-driven operation in a more natural way and permits a melding of sequencing and fault protection into a single control paradigm. This paper describes one approach to goal-based control as an architectural pattern in terms of purpose, motivation, structure, applicability, and consequences. This paper is intended to help flight and ground software engineers understand the new paradigm and how it compares to time-based sequencing.
The dynamic cast operation allows flexibility in the design and use of data management facilities in object- oriented programs. Dynamic cast has an important role in the implementation of the data management services (DMS) of the mission data system project (MDS), the jet propulsion laboratory's experimental work for providing a state-based and goal-oriented unified architecture for testing and development of mission software. DMS is responsible for the storage and transport of control and scientific data in a remote autonomous spacecraft. Like similar operators in other languages, the C++ dynamic cast operator does not provide the timing guarantees needed for hard real-time embedded systems. In a recent study, Gibbs and Stroustrup (G&S) devised a dynamic cast implementation strategy that guarantees fast constant-time performance. This paper presents the definition and application of a co-simulation framework to formally verify and evaluate the G&S fast dynamic casting scheme and its applicability in the mission data system DMS application. We describe the systematic process of model-based simulation and analysis that has lead to performance improvement of the G&S algorithm's heuristics by about a factor of 2.