Jump to content

Key Considerations When Developing Avionics for Safety-Critical Systems


Recommended Posts

  • Publishers
Posted

This article is from the 2024 Technical Update.

Multiple human spaceflight programs are underway at NASA including Orion, Space Launch System, Gateway, Human Landing System, and EVA and Lunar Surface Mobility programs. Achieving success in these programs requires NASA to collaborate with a variety of commercial partners, including both new spaceflight companies and robotic spaceflight companies pursuing crewed spaceflight for the first time. It is not always clear to these organizations how to show their systems are safe for human spaceflight. This is particularly true for avionics systems, which are responsible for performing some of a crewed spacecraft’s most critical functions. NASA recently published guidance describing how to show the design of an avionic system meets safety requirements for crewed missions.

Background
The avionics in a crewed spacecraft perform many safety critical functions, including controlling the position and attitude of the spacecraft, activating onboard abort systems, and firing pyrotechnics. The incorrect operation of any of these functions can be catastrophic, causing loss of the crew. NASA’s human rating requirements describe the need for “additional rigor and scrutiny” when designing safety-critical systems beyond that done
for uncrewed spacecraft [2]. Unfortunately, it is not always clear how to interpret this guidance and show an avionics architecture is sufficiently safe. To address this problem, NASA recently published NASA/TM−20240009366 [1]. It outlines best practices for designing safety-critical avionics, as well as describes key artifacts or evidence NASA needs to assess the safety of an avionics architecture.

Failure Hypothesis
One of the most important steps to designing an avionics architecture for crewed spacecraft is specification of the failure hypothesis (FH). In short, the FH summarizes any assumptions the designers make about the type, number, and persistence of component failures (e.g., of onboard computers, network switches). It divides the space of all possible failures into two parts – failures the system is designed to tolerate and failures it is not.

screenshot-2024-12-12-at-9-58-01 am.png?

One key part of the FH is a description of failure modes the system can tolerate – i.e., the behavior exhibited by a failed component. Failure modes are categorized using a failure model. A typical failure model for avionics splits failures into two broad categories:

  • Value failures, where data produced by a component is missing (i.e., an omissive failure) or incorrect (i.e., a transmissive failure).
  • Timing failures, where data is produced by a component at the wrong time.

Timing failures can be further divided into many sub-categories, including:

  • Inadvertent activation, where data is produced by a component without the necessary preconditions.
  • Out-of-order failures, where data is produced by a component in an incorrect sequence.
  • Marginal timing failures, where data is produced by a component slightly too early or late.

In addition to occurring when data is produced by a component, these failure modes can also occur when data enters a component. (e.g., a faulty component can corrupt a message it receives). Moreover, all failure modes can manifest in one of two ways:

  • Symmetrically, where all observers see the same faulty behavior.
  • Asymmetrically, where some observers see different faulty behavior.

Importantly, NASA’s human-rating process requires that each of these failure modes be mitigated if it can result in catastrophic effects [2]. Any exceptions must be explicitly documented and strongly justified. In addition to specifying the failure modes a system can tolerate, the FH must specify any limiting assumptions about the relative arrival times of permanent failures and radiation-induced upsets/ errors or the ability for ground operator to intervene to safe the system or take recovery actions. For more information on specifying a FH and other artifacts needed to evaluate the safety of an avionics architecture for human spaceflight, see the full report [1].

View the full article

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Similar Topics

    • By NASA
      Credit: NASA NASA has awarded ASCEND Aerospace & Technology of Cape Canaveral, Florida, the Contract for Organizing Spaceflight Mission Operations and Systems (COSMOS), to provide services at the agency’s Johnson Space Center in Houston.
      The COSMOS is a single award, indefinite-delivery/indefinite-quantity contract valued at $1.8 billion that begins its five-year base period no earlier than Dec. 1, with two option periods that could extend until 2034. The Aerodyne Company of Cape Canaveral, Florida, and Jacobs Technology Company of Tullahoma, Tennessee, are joint venture partners.
      Work performed under the contract will support NASA’s Flight Operation Directorate including the Orion and Space Launch System Programs, the International Space Station, Commercial Crew Program, and the Artemis campaign. Services include Mission Control Center systems, training systems, mockup environments, and training for astronauts, instructors, and flight controllers.
      For more information about NASA and agency programs, visit:
      https://www.nasa.gov
      -end-
      Tiernan Doyle
      Headquarters, Washington
      202-358-1600
      tiernan.doyle@nasa.gov
      Chelsey Ballarte
      Johnson Space Center, Houston
      281-483-5111
      chelsey.n.ballarte@nasa.gov
      Share
      Details
      Last Updated Aug 28, 2025 LocationNASA Headquarters Related Terms
      Johnson Space Center Artemis Commercial Crew International Space Station (ISS) ISS Research Johnson Flight Operations Space Launch System (SLS) View the full article
    • By Space Force
      Space Systems Command activated a new Systems Delta to support the BMC3I Program Executive Office portfolio. This activation synchronizes acquisition efforts for critical space system capabilities and works together with Mission Deltas to improve mission readiness.

      View the full article
    • By Space Force
      Space Systems Command and United Launch Alliance's launch teams successfully completed the inaugural launch of a Vulcan Centaur rocket, carrying the U.S. Space Force-106 mission into geosynchronous Earth orbit.

      View the full article
    • By Space Force
      Space Systems Command and United Launch Alliance's launch teams successfully completed the inaugural launch of a Vulcan Centaur rocket, carrying the U.S. Space Force-106 mission into geosynchronous Earth orbit.

      View the full article
    • By NASA
      Technicians have successfully installed two sunshields onto NASA’s Nancy Grace Roman Space Telescope’s inner segment. Along with the observatory’s Solar Array Sun Shield and Deployable Aperture Cover, the panels (together called the Lower Instrument Sun Shade), will play a critical role in keeping Roman’s instruments cool and stable as the mission explores the infrared universe.
      To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
      This video shows technicians installing two sunshields onto NASA's nearly complete Nancy Grace Roman Space Telescope on July 17. The large yet lightweight panels will block sunlight, keeping Roman’s instruments cool and stable as the mission explores the infrared universe.Credit: NASA/Sophia Roberts The team is on track to join Roman’s outer and inner assemblies this fall to complete the full observatory, which can then undergo further prelaunch testing.
      “This shield is like an extremely strong sunblock for Roman’s sensitive instruments, protecting them from heat and light from the Sun that would otherwise overwhelm our ability to detect faint signals from space,” said Matthew Stephens, an aerospace engineer at NASA’s Goddard Space Flight Center in Greenbelt, Maryland.
      The sunshade, which was designed and engineered at NASA Goddard, is essentially an extension of Roman’s solar panels, except without solar cells. Each sunshade flap is roughly the size of a garage door — about 7 by 7 feet (2.1 by 2.1 meters) — and 3 inches (7.6 centimeters) thick.
      “They’re basically giant aluminum sandwiches, with metal sheets as thin as a credit card on the top and bottom and the central portion made up of a honeycomb structure,” said Conrad Mason, an aerospace engineer at NASA Goddard.
      This design makes the panels lightweight yet stiff, and the material helps limit heat transfer from the side facing the Sun to the back—no small feat considering the front will be hot enough to boil water (up to 216 degrees Fahrenheit, or 102 degrees Celsius) while the back will be much colder than Antarctica’s harshest winter (minus 211 Fahrenheit, or minus 135 Celsius). A specialized polymer film blanket will wrap around each panel to temper the heat, with 17 layers on the Sun side and one on the shaded side.
      The sunshade will be stowed and gently deploy around an hour after launch.
      To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
      In this time-lapse video, technicians manually deploy the Lower Instrument Sun Shield for NASA's Nancy Grace Roman Space Telescope. The test helps verify the panels will operate as designed in space.NASA/Sophia Roberts “The deploying mechanisms have dampers that work like soft-close hinges for drawers or cabinets, so the panels won’t slam open and rattle the observatory,” Stephens said. “They each take about two minutes to move into their final positions. This is the very first system that Roman will deploy in space after the spacecraft separates from the launch vehicle.”
      Now completely assembled, Roman’s inner segment is slated to undergo a 70-day thermal vacuum test next. Engineers and scientists will test the full functionality of the spacecraft, telescope, and instruments under simulated space conditions. Following the test, the sunshade will be temporarily removed while the team joins Roman’s outer and inner assemblies, and then reattached to complete the observatory. The mission remains on track for launch no later than May 2027 with the team aiming for as early as fall 2026.
      Click here to virtually tour an interactive version of the telescope Download high-resolution video and images from NASA’s Scientific Visualization Studio
      The Nancy Grace Roman Space Telescope is managed at NASA’s Goddard Space Flight Center in Greenbelt, Maryland, with participation by NASA’s Jet Propulsion Laboratory in Southern California; Caltech/IPAC in Pasadena, California; the Space Telescope Science Institute in Baltimore; and a science team comprising scientists from various research institutions. The primary industrial partners are BAE Systems Inc. in Boulder, Colorado; L3Harris Technologies in Rochester, New York; and Teledyne Scientific & Imaging in Thousand Oaks, California.
      By Ashley Balzer
      NASA’s Goddard Space Flight Center, Greenbelt, Md.
      Share
      Details
      Last Updated Jul 31, 2025 EditorAshley BalzerContactAshley Balzerashley.m.balzer@nasa.govLocationGoddard Space Flight Center Related Terms
      Nancy Grace Roman Space Telescope Dark Energy Dark Matter Exoplanets Galaxies Goddard Space Flight Center Nebulae Sensing the Universe & Multimessenger Astronomy Stars The Universe Explore More
      7 min read One Survey by NASA’s Roman Could Unveil 100,000 Cosmic Explosions
      Article 2 weeks ago 3 min read NASA’s Roman Space Telescope Team Installs Observatory’s Solar Panels
      Article 3 weeks ago 6 min read NASA’s Roman Mission Shares Detailed Plans to Scour Skies
      Article 3 months ago View the full article
  • Check out these Videos

×
×
  • Create New...