The In-Time Aviation Safety Management System (IASMS) Concept of Operations (ConOps) envisions new capabilities to monitor, assess, and mitigate flight safety risks. Systems will be tailored to mission type, vehicle/equipage type, operational environment, and safety risk tolerance. Within an IASMS framework, several capabilities may be implemented spanning three operational phases (pre-flight, in-flight, and post-flight/off-line); consisting of lower level functions and information services which may reside on board the aircraft, on third-party server(s), and/or on ground/operator station(s). Each capability will be designed to produce and disseminate safety-relevant information; perform detection, diagnosis, and prediction of unsafe situations; and/or execute mitigation actions when hazardous events warrant such changes. This paper focuses on recent testing of airborne capabilities that demonstrate inflight aspects of the overarching concept for autonomous unmanned aircraft systems (UAS) operations in urban environments. A flight test architecture is described that applies run-time assurance principles (e.g., executes independent of the unassured autopilot), real-time risk assessment, and a technique to execute contingencies if necessary either automatically or via pilot intervention. Several tests using small UAS were conducted to verify the assured inflight risk mitigation capability. The paper draws significantly from a larger NASA technical report and recent prior conference papers, providing additional details. Data are analyzed for two representative flights to illustrate the performance for various sequential and simultaneous hazards used during testing. During each automated flight, several hazards are encountered at various points along the flight path. At each point, the hazard is mitigated by the system, with the vehicle then continuing to subsequent points. The paper concludes with lessons-learned regarding relevant aspects of the overarching IASMS concept and how it may be updated and further advanced in the future.
Incorporating unmanned aerial vehicles (UAVs) into the United States National Airspace System would demand enhanced airspace safety technologies for the safety of the UAVs, people, and property on the ground. One of the safety-critical factors to consider is the risk of a UAV deviating from its planned trajectory, which may result in loss of separation between other vehicles or obstacles or may cause early depletion of battery power. In this paper, we studied the effect of wind on UAV trajectory deviation by incorporating wind velocity as a drag component in a six-degrees-of-freedom trajectory simulation comprising a rotorcraft lumped-mass model. Both steady-state wind and wind turbulence effects were investigated. We validated our approach using real flight data from UAV experiments conducted at NASA Langley Research Center. The proposed approach would enable risk-informed decision making by timely mitigation of current and future collision events in an uncertain and dynamic environment.
View Video Presentation: https://doi.org/10.2514/6.2022-3458.vid Ongoing research at NASA is driven by a strategic plan defined by the Aeronautics Research Mission Directorate and a vision for future In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. In both visions, system safety awareness and provision are expanded through increased access to relevant data; integrated analysis and predictive capabilities; improved real-time detection and alerting of domain-specific hazards; decision support, and in some cases, automated risk mitigation strategies. One primary research focus is to develop means by which more timely (i.e., "in-time") actions may be taken to mitigate precursors, anomalies, or trends that are observed during operations. In this paper, we describe such means as a collection of Services, Functions, and Capabilities (SFCs) that are supported by an underlying information system. For example, an integrated risk assessment capability is envisioned that continuously monitors safety-related metrics and margins and recommends timely operational changes. Assessment functions and/or services can be based on data analytics and predictive models derived from heterogeneous data sets that span relevant indicator metrics and their time histories. Likewise, on-board functions can identify and reduce susceptibility to precursor conditions that have led (and can lead) to aircraft loss-of-control or out-of-control accidents. This paper summarizes development and testing of such an information system tailored to hazards anticipated for future highly autonomous flight missions near and over densely populated areas. Testing is accomplished via simulation and by using small, unmanned aircraft operating over a test range at NASA's Langley Research Center. Flight plans and test scenarios are defined to emulate several use-cases, including package delivery; reconnaissance; fire management; and urban air taxi vertiport operations. Two test phases are summarized with Phase 1 occurring in (2019-2020) and Phase 2 ongoing (2021-present). Results focus on SFC performance, technology readiness level assessment, and requirements discovery/validation. Companion papers are cited throughout for additional details on the recent testing.
An onboard risk management automation design is presented based on run-time assurance principles, as well as the concept for In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. The automation is designed to operate independently of the autopilot and perform real-time risk assessment spanning multiple classes of hazards, predict constraint violations, and track autopilot states. In the event of elevated risk conditions or predicted constraint violations, the automation will select from a set of available contingencies and trigger autopilot mode changes if necessary to mitigate risk exposure. The onboard automation also informs the remote operator/pilot of what the independent monitor is observing and any contingency decisions or actions that may arise during flight. Details of an implementation of this design and results of verification and validation activities, as required to meet stringent NASA software and system assurance standards, are also presented. This includes simulation and flight testing using small unmanned aircraft systems.
This report describes two extended visual line of sight (EVLOS) methods developed and utilized during two flight campaigns over the campus of NASA Langley Research Center (LaRC): a chase vehicle method and a radio controlled (RC) pilot handoff method. These campaigns were performed to (a) evaluate small unmanned aerial system (sUAS) flight beyond the visual line of sight (BVLOS) of the ground control station operator and (b) test technologies under development to enable a transition from EVLOS to BVLOS operations. While an autonomous waypoint-based operational approach enabled minimal pilot intervention in both methods, range containment was enforced (a) manually via continual pilot visual monitoring and (b) autonomously via on-board contingency landing autonomy triggerable at the boundary of stay-in geofences. In the thirty-nine flights which utilized the chase vehicle, the pilot followed the sUAS flying a 1.2 km path at 40m altitude over urban streets. In the fifteen flights which utilized pilot handoff, a pilot at one end of a 1.5 km path initiated the flight at 120m altitude over buildings and trees, and at the midway point of the path transferred radio control to a pilot at the other end. In comparison, the chase vehicle method requires less ground crew and simpler avionics, while the pilot handoff method avoids schedule risk arising from street traffic congestion but better replicates actual direct routing for BVLOS flights. Collision risk with another aircraft was introduced in both campaigns and mitigated with the same manual and autonomous methods. Results from these campaigns serve as a basis for planned BVLOS operations at NASA LaRC.
This paper addresses the problem of building trust in the online prediction of a eUAV’s remaining available flying time powered by lithium-ion polymer batteries. A series of ground tests are described that make use of an electric unmanned aerial vehicle (eUAV) to verify the performance of remaining flying time predictions. The algorithm verification procedure described is implemented on a fully functional vehicle that is restrained to a platform for repeated run-to-functional-failure (charge depletion) experiments. The vehicle under test is commanded to follow a predefined propeller RPM profile in order to create battery demand profiles similar to those expected during flight. The eUAV is repeatedly operated until the charge stored in powertrain batteries falls below a specified limit threshold. The time at which the limit threshold on battery charge is crossed is then used to measure the accuracy of the remaining flying time prediction. In our earlier work battery aging was not included. In this work we take into account aging of the batteries where the parameters were updated to make predictions. Accuracy requirements are considered for an alarm that warns operators when remaining flying time is estimated to fall below the specified limit threshold.
NASA's UAS Traffic Management (UTM) concept proposes a federated, service-based traffic management system for small UAS operating at altitudes below 400 feet. Under this concept, private entities operate UTM Service Suppliers (USS) and are responsible for approval, coordination, and deconfliction of flight plans submitted by mission operators. Due to unforeseen factors, any number of off-nominal conditions could force a participating vehicle to stray from the approved flight plan and become non-conforming. NASA Langley Research Center (LaRC) conducted a series of flight tests referred to as Pathfinder 1 to demonstrate the use of onboard autonomy-enabling technologies in scenarios where a non-conforming UAS flies through the assigned airspace of another vehicle while trying to reach an emergency landing site. Two test vehicles were equipped with an onboard autonomy software developed at NASA LaRC referred to as ICAROUS (Independent Configurable Architecture for Reliable Operation of Unmanned Systems). ICAROUS's autonomous sense and avoid (SAA) and geofence conformance capabilities were tested and demonstrated in the Pathfinder 1 flight tests. In these flight tests, the two aircraft initially follow flight plans that have been previously approved by a USS and determined to be conflict-free. During the flight, a scripted emergency scenario is triggered, requiring one vehicle to make an emergency landing using an onboard application named Safe2Ditch to select the best landing site. A straight-line path to the landing site would cause the UAS to become non-conforming and cross directly through the airspace of the other UAS, creating an elevated risk of collision. Two methods of autonomous onboard conflict resolution were tested to resolve this scenario and prevent collision. In the first method, the non-conforming vehicle flew directly to the landing site, passing through the airspace of the conforming vehicle. The conforming vehicle used ICAROUS's SAA capability to autonomously deviate from its flight plan to maintain a well-clear distance of 500 feet then returned to the flight plan once the conflict had passed. In the second resolution method, a keep-out geofence was placed 500 feet around the flight plan of the conforming vehicle. The non-conforming vehicle used ICAROUS to plan a route to the landing site that respected the geofence and thus maintained a safe separation from the airspace of the conforming vehicle. This paper also reports on the use of FLARM (Flight Alarm), a vehicle-to-vehicle position communication technology that transmits on 915 MHz, to provide traffic vehicle position data for onboard SAA.
This paper reports the flight test results of an on-demand, distributed, consensus based merging algorithm for autonomous multi-agent coordination used to regulate flow of air traffic through a common intersection or merge fix in a given airspace. Distributed merging is enabled by vehicle-to-vehicle (V2V) communication technology, a distributed consensus algorithm and a scheduling algorithm to coordinate the arrival times of the vehicles approaching a merge fix. The proposed algorithm is integrated into the ICAROUS (Independent Configurable Architecture for Reliable Operations of Unmanned Systems) software suite and was used to demonstrate the merging capability in a flight test campaign. The objectives of these flight tests were to validate the distributed consensus-based merging algorithm and to evaluate the requirements and associated challenges in ensuring the successful application of the algorithm in a real-world setting. Details of the flight test setup, hardware used, impediments to the achievement of the outlined objectives, flight test results and lessons learned are documented in this paper.
As aviation adopts new and increasingly complex operational paradigms, vehicle types, and technologies to broaden airspace capability and efficiency, maintaining a safe system will require recognition and timely mitigation of new safety issues as they emerge and before significant consequences occur. A shift toward a more predictive risk mitigation capability becomes critical to meet this challenge. In-time safety assurance comprises monitoring, assessment, and mitigation functions that proactively reduce risk in complex operational environments where the interplay of hazards may not be known (and therefore not accounted for) during design. These functions can also help to understand and predict emergent effects caused by the increased use of automation or autonomous functions that may exhibit unexpected non-deterministic behaviors. The envisioned monitoring and assessment functions can look for precursors, anomalies, and trends (PATs) by applying model-based and data-driven methods. Outputs would then drive downstream mitigation(s) if needed to reduce risk. These mitigations may be accomplished using traditional design revision processes or via operational (and sometimes automated) mechanisms. The latter refers to the ‘in-time’ aspect of the system concept. This report comprises architecture and information requirements and considerations toward enabling such a capability within the domain of low altitude highly autonomous urban flight operations. This domain may span, for example, public-use surveillance missions flown by small unmanned aircraft (e.g., infrastructure inspection, facility management, emergency response, law enforcement, and/or security) to transportation missions flown by larger aircraft that may carry passengers or deliver products. Caveat: Any stated requirements in this report should be considered initial requirements that are intended to drive research and development (R&D). These initial requirements are likely to evolve based on R&D findings, refinement of operational concepts, industry advances, and new industry or regulatory policies or standards related to safety assurance.
This paper addresses the problem of building trust in the online prediction of a battery powered aircraft’s remaining flying time. A series of flight tests is described that make use of a small electric powered unmanned aerial vehicle (eUAV) to verify the performance of the remaining flying time prediction algorithm. The estimate of remaining flying time is used to activate an alarm when the predicted remaining time is two minutes. This notifies the pilot to transition to the landing phase of the flight. A second alarm is activated when the battery charge falls below a specified limit threshold. This threshold is the point at which the battery energy reserve would no longer safely support two repeated aborted landing attempts. During the test series, the motor system is operated with the same predefined timed airspeed profile for each test. To test the robustness of the prediction, half of the tests were performed with, and half were performed without, a simulated powertrain fault. The pilot remotely engages a resistor bank at a specified time during the test flight to simulate a partial powertrain fault. The flying time prediction system is agnostic of the pilot’s activation of the fault and must adapt to the vehicle’s state. The time at which the limit threshold on battery charge is reached is then used to measure the accuracy of the remaining flying time predictions. Accuracy requirements for the alarms are considered and the results discussed.
This paper addresses the problem of building trust in online predictions of a battery powered aircraft’s remaining available flying time. A set of ground tests is described that make use of a small unmanned aerial vehicle to verify the performance of remaining flying time predictions. The algorithm verification procedure described here uses a fully functional vehicle that is restrained to a platform for repeated run-to-functional-failure experiments. The vehicle under test is commanded to follow a predefined propeller RPM profile in order to create battery demand profiles similar to those expected in flight. The fully integrated aircraft is repeatedly operated until the charge stored in powertrain batteries falls below a specified lower-limit. The time at which the lower- limit on battery charge is crossed is then used to measure the accuracy of remaining flying time predictions. Accuracy requirements are considered in this paper for an alarm that warns operators when remaining flying time is estimated to fall below a specified threshold.