System and method for controlling motion of spacecraft in multi-object celestial system

JP2023086671A5Active Publication Date: 2025-07-30MITSUBISHI ELECTRIC CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022170258
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-12-30
Filing Date
2022-10-25
Publication Date
2025-07-30
Estimated Expiration
2042-10-25

AI Technical Summary

Technical Problem

Existing spacecraft rendezvous and landing technologies face challenges in maintaining safety and precision due to partial thruster failures, actuation mismatches, measurement noise, and unmodeled phenomena, leading to potential unauthorized entry into keep-away zones during normal and abnormal operations in multi-body systems.

Method used

A controller system that computes and stores off-line control-invariant sets and corresponding abort control laws to maintain spacecraft within safe operational boundaries, using probabilistic reachable sets and robust controlled invariant sets to handle unbounded stochastic uncertainties, ensuring safe motion control with predetermined safety likelihoods.

Benefits of technology

The system effectively prevents unauthorized entry into keep-away zones by reducing computational load and latency, ensuring safe spacecraft motion under various uncertainties and failures, enhancing safety and precision in multi-body systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide a system and method for controlling a motion of a spacecraft in a multi-object celestial system while avoiding an unauthorized entry into a keep-away region during a normal operation and an abnormal operation of the spacecraft.SOLUTION: The method includes executing, during the normal operation of the spacecraft, a nominal control law subject to constraints on maintaining a state of the spacecraft within a union of a plurality of control invariant sets of values of the state of the spacecraft. The state of the spacecraft includes a location of the spacecraft, and at least one or a combination of a velocity and an acceleration of the spacecraft. The method further includes executing, upon detecting the abnormal operation of the spacecraft, an abort control law associated with the control invariant set including a current state of the spacecraft.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates generally to controlling the motion of a spacecraft, and more particularly to systems and methods for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into keep-away regions during normal and abnormal spacecraft operation. [Background technology]

[0002] A spacecraft rendezvous is a set of orbital maneuvers during which two spacecraft, a chaser spacecraft and a target or space station, arrive in the same orbit and approach close together (e.g., within visual contact). A spacecraft rendezvous requires precise matching of the orbital velocity and position vectors of the two spacecraft, allowing them to remain at a consistent distance throughout orbital stationkeeping. A spacecraft rendezvous may or may not be followed by docking or berthing, a procedure that physically brings the spacecraft into contact and forms a link between them. Furthermore, the same spacecraft rendezvous may be used for spacecraft "landing" on natural objects in the presence of weak gravitational fields, such as landing on an asteroid or one of Mars' moons. Spacecraft landing on natural objects may also involve orbital velocity matching, followed by a "descent," which shares similarities with docking.

[0003] However, spacecraft rendezvous with the target is a difficult task. An important criterion for spacecraft rendezvous is maintaining safety, i.e., the ability to avoid a collision between the chaser spacecraft and the target in the event of a partial thruster failure. In the event of a partial thruster failure, the chaser spacecraft may deviate from its nominal approach near the target. When the chaser spacecraft significantly deviates from its nominal approach near the target and its current trajectory is not passively safe, a predetermined active collision avoidance maneuver (CAM) is initiated. However, depending on the approach trajectory and the severity of the partial thruster failure, CAM may not always be possible.

[0004] Furthermore, for spacecraft motion planning, mathematical models are used to predict the trajectory when a specific sequence of thrusters is applied to a chaser spacecraft over time. However, in reality, the true spacecraft motion may deviate from the trajectory predicted by the mathematical model. Such deviations can occur for various reasons, including actuation mismatch, measurement noise, and unmodeled phenomena. Actuation mismatch results from thruster misalignment and limitations of the hardware onboard the chaser spacecraft. Measurement noise can result from sensor sensitivity limitations, which results in inaccurate information about the state of the chaser spacecraft, including its position and velocity. Furthermore, for the sake of computational and interpretable mathematical models, it is common to exclude complex phenomena that may have a subtle effect on the trajectory.

[0005] Therefore, there is a need for an improved method of controlling chaser spacecraft operation for safe rendezvous in the event of malfunctions and in the presence of operational mismatches, measurement noise, and other uncertainties. Summary of the Invention

[0006] An objective of some embodiments is to provide a system and method for controlling spacecraft motion in a multi-body celestial system while avoiding unauthorized entry into a keepaway region during normal and abnormal spacecraft operation. As used herein, normal operation includes moving toward a target within a keepaway zone, and abnormal operation includes one or a combination of failing to receive permission to enter the keepaway zone and a failure of at least one component of the spacecraft. This problem stems from the requirement for spacecraft motion and rendezvous of multiple spacecraft forming a multi-body celestial system to ensure greater safety in space collaboration. To that end, an objective of one embodiment is to control spacecraft motion toward a keepaway region upon detection of abnormal operation, such that there is a high likelihood of moving the spacecraft while avoiding the keepaway zone.

[0007] Some embodiments are based on the recognition that even if entry clearance is denied for any reason, including a complete or partial failure of the spacecraft's propulsion, there are spacecraft conditions near the keep-away zone that may inevitably lead the spacecraft to the keep-away zone. As used herein, a spacecraft condition includes a spacecraft's position and at least one or a combination of the spacecraft's velocity and acceleration. Furthermore, internal and external forces acting on the spacecraft during its motion, such as inertia and gravity, may change the spacecraft's condition to a particular condition that may lead the spacecraft to the keep-away zone, despite any efforts the spacecraft may make.

[0008] Some embodiments are based on the recognition that this problem can be addressed by using a control invariant set of values ​​for the spacecraft state within which the spacecraft should be. As used herein, a control invariant set is determined such that when the spacecraft state is within the control invariant set, there are control commands generated by control laws that will keep the spacecraft state within the control invariant set despite internal and external forces acting on the spacecraft. Thus, when the spacecraft is within the control invariant set, there are control laws within specified control limits such that the spacecraft does not enter the keep-away zone.

[0009] Because control invariant sets depend on control limits, some embodiments determine multiple control invariant sets that form a union of multiple control invariant sets of spacecraft state values. The union of the multiple control invariant sets may partially enclose the keepaway zone. In some other embodiments, the union of the multiple control invariant sets may completely enclose the keepaway zone. Furthermore, to control spacecraft motion in the event of abnormal operation, each control invariant set is determined such that an abnormal control law exists that takes into account operating limits associated with the abnormality and that safely aborts spacecraft motion.

[0010] Some embodiments are based on the recognition that computing control invariant sets online, i.e., during real-time control of a spacecraft, is computationally expensive. To alleviate this problem, control invariant sets and corresponding abort control laws are determined offline, i.e., in advance. Specifically, abort control laws are determined jointly and interdependently with respect to corresponding control invariant sets to generate abort control commands. The offline-determined control invariant sets and corresponding abort laws may be stored in a controller used to control the motion of the spacecraft.

[0011] To that end, during online control of a spacecraft during abnormal operation, the controller receives a current state of the spacecraft. Further, the processor selects a control invariant set that includes the current state of the spacecraft. Further, the controller executes an abort control law corresponding to the selected control invariant set. Thus, in different states where abnormal operation is detected, the controller may use different predetermined abort control laws, thereby reducing computational load and reducing latency of response when abnormal operation is detected.

[0012] Some embodiments are based on the recognition that spacecraft motion is subject to unbounded stochastic uncertainty. The unbounded stochastic uncertainty includes a probabilistic distribution of process noise. The process noise may define operating mismatches and / or unmodeled dynamics of the spacecraft motion. In addition to the process noise, the unbounded stochastic uncertainty may include a probabilistic distribution of measurement noise of spacecraft state estimates. Because spacecraft motion is subject to unbounded stochastic uncertainty, there is a need to avoid unauthorized entry of a spacecraft into a keepaway zone with a given safety likelihood, taking into account the unbounded stochastic uncertainty.

[0013] Some embodiments are based on the understanding that it is possible to control the motion of a spacecraft with a predetermined safe likelihood. For example, different methods for implementing motion under unbounded stochastic uncertainty include chance constraints, particle filtering, scenario optimization, and stochastic tube methods. To this end, it may be assumed that the motion of a spacecraft can be controlled with a predetermined safe likelihood within the union of multiple control invariant sets. However, such an assumption is based on the concept that each control invariant set is determined deterministically, i.e., without unbounded stochastic uncertainty. However, such an assumption may be inaccurate if there is some uncertainty in the motion of the spacecraft during online control of the spacecraft, because the same or similar uncertainty exists during the calculation of the control invariant sets.

[0014] To that end, some embodiments recognize that to guarantee control invariance under unbounded stochastic uncertainty, each control invariant set should internally approximate the value of the spacecraft state. Furthermore, such guarantees should be accompanied by a likelihood of unbounded stochastic uncertainty that is greater than a predetermined safety likelihood. This is because the final probabilistic guarantee of motion control is a function of the product of the likelihood of control invariance under unbounded stochastic uncertainty and the likelihood of motion satisfying constraints derived from the control invariant sets. For unbounded stochastic uncertainty, all of these likelihoods are less than 1 and therefore need to be considered together to guarantee a predetermined safety likelihood.

[0015] Thus, each control invariant set internally approximates values ​​of the spacecraft state to ensure control invariance under conditions where a first likelihood of unbounded stochastic uncertainty is greater than a predetermined safety likelihood. The control law is configured to generate control commands that maintain the spacecraft state within a union of the control invariant sets with a second likelihood, the second likelihood being selected such that the product of the first likelihood and the second likelihood is greater than or equal to the predetermined safety likelihood.

[0016] Some embodiments use various techniques to calculate control invariant sets for spacecraft dynamics under unbounded stochastic uncertainty. For example, one embodiment uses a probabilistic reachable set to determine the control invariant set. This embodiment is advantageous when the control invariant set to stay within is convex, but may be suboptimal when the uncertainty has a heavy-tailed probability density. When the uncertainty has a heavy-tailed probability density, the estimated uncertainty range for the calculation of the control invariant set becomes larger, leading to a significant reduction in the amount of calculated control invariant sets. Since the control invariant set limits the states that are acceptable for normal operation, it is desirable to have a large control invariant set. For the problem of interest, the uncertainty is Gaussian and therefore thin-tailed.

[0017] Additionally or alternatively, the control invariant set can be computed by utilizing a robust controlled invariant set. The robust controlled invariant set determines a set of states that can maintain safety despite bounded, non-probabilistic uncertainty. Various computational algorithms can be used to compute the robust controlled invariant set. However, these algorithms are not directly applicable to problems with unbounded probabilistic uncertainty, including probabilistic distributions of process and / or measurement noise. This is because the computational algorithms are applicable to problems with bounded, deterministic uncertainty.

[0018] To alleviate this problem, the unbounded probabilistic uncertainty is transformed into a bounded deterministic uncertainty with a predefined likelihood that specifies a range of values ​​over the unbounded probabilistic uncertainty. To this end, a computational algorithm can be used to compute a robust controlled invariant set. Furthermore, a controlled invariant set can be determined based on the computed robust controlled invariant set.

[0019] Accordingly, one embodiment discloses a controller for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keep-away zone during normal and abnormal operation of the spacecraft, where normal operation includes moving toward the keep-away zone and abnormal operation includes one or a combination of failing to receive permission to enter the keep-away zone and a failure of at least one component of the spacecraft. The controller comprises at least one processor and a memory having stored thereon instructions that, when executed by the at least one processor, cause the controller to execute a nominal control law subject to a constraint to maintaining a state of the spacecraft within a union of a plurality of control invariant sets of values ​​of the spacecraft state that partially or completely enclose the keep-away zone during normal operation of the spacecraft, the spacecraft state including a position of the spacecraft and at least one or a combination of velocity and acceleration of the spacecraft, each of the plurality of control invariant sets being constrained to maintain the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft when the state of the spacecraft is within the control invariant set. The instructions, when executed by the at least one processor, further cause the controller, upon detecting abnormal operation of the spacecraft, to execute an abort control law associated with a control invariant set that includes a current state of the spacecraft, wherein at least some different abort control laws are associated with the at least some different control invariant sets, and the abort control laws are jointly and interdependently determined to generate, for a corresponding control invariant set, an abort control command that moves the spacecraft while avoiding the keepaway zone for any state within the corresponding control invariant set.

[0020]

[0009] Accordingly, another embodiment discloses a tracking method for controlling spacecraft motion in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, where normal operation includes moving toward the keepaway zone and abnormal operation includes one or a combination of failing to receive permission to enter the keepaway zone and a failure of at least one component of the spacecraft. The method includes, during normal operation of the spacecraft, executing a nominal control law subject to constraints to maintaining a state of the spacecraft within a union of a plurality of control invariant sets of values ​​of the spacecraft state that partially or completely enclose the keepaway zone, the spacecraft state including spacecraft position and at least one or a combination of spacecraft velocity and acceleration. Each of the plurality of control invariant sets is determined such that, when the spacecraft state is within the control invariant set, there are control commands generated by the nominal control law that maintain the spacecraft state within the control invariant set despite internal and external forces acting on the spacecraft. The method further includes, upon detecting abnormal operation of the spacecraft, executing an abort control law associated with a control invariant set that includes a current state of the spacecraft, wherein at least some different abort control laws are associated with at least some different control invariant sets, and the abort control laws are jointly and interdependently determined for a corresponding control invariant set to generate abort control commands that move the spacecraft while avoiding the keepaway zone for any state within the corresponding control invariant set.

[0021] Accordingly, yet another embodiment discloses a non-transitory computer-readable storage medium having embodied thereon a program executable by a processor to perform a method for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, wherein normal operation includes moving toward the keepaway zone and wherein abnormal operation includes one or a combination of failing to receive permission to enter the keepaway zone and a failure of at least one component of the spacecraft. The method includes, during normal operation of the spacecraft, executing a nominal control law constrained to maintain a spacecraft state within a union of a plurality of control invariant sets of values ​​of the spacecraft state that partially or completely enclose a keepaway zone, the spacecraft state including a position of the spacecraft and at least one or a combination of velocity and acceleration of the spacecraft, each of the plurality of control invariant sets being determined such that when the spacecraft state is within the control invariant set, there is a control command generated by the nominal control law that maintains the spacecraft state within the control invariant set despite internal and external forces acting on the spacecraft, the method further includes, upon detecting abnormal operation of the spacecraft, executing an abort control law associated with the control invariant set that includes the current state of the spacecraft, at least some different abort control laws are associated with the at least some different control invariant sets, the abort control laws being jointly and interdependently determined to generate, for a corresponding control invariant set, an abort control command that moves the spacecraft while avoiding the keepaway zone for any state within the corresponding control invariant set.

[0022] The presently disclosed embodiments are further described with reference to the accompanying drawings, in which: The drawings shown are not necessarily to scale, emphasis instead generally being placed upon illustrating the principles of embodiments of the present disclosure. [Brief explanation of the drawings]

[0023] [Figure 1A] 1 illustrates the motion of a spacecraft in a multi-body celestial body system, according to one embodiment of the present disclosure. [Figure 1B] FIG. 1 illustrates a block diagram of a controller for controlling spacecraft motion during normal and abnormal spacecraft operation, according to one embodiment of the present disclosure. [Figure 1C] 1 illustrates a union of multiple control invariant sets of values ​​for a spacecraft state, according to one embodiment of the present disclosure. [Figure 2] FIG. 1 illustrates a block diagram of a spacecraft including a controller and other components, according to one embodiment of the present disclosure. [Figure 3A] 1 illustrates a keepaway set and its complement, according to one embodiment of the present disclosure. [Figure 3B] 1 illustrates a probabilistic reachable set according to an embodiment of the present disclosure. [Figure 3C] 1 illustrates an inner approximation of a probabilistic reachable set according to an embodiment of the present disclosure. [Figure 4] 1 illustrates an example of a two-dimensional projection of a control invariant set and a control invariant subset, according to an embodiment of the present disclosure. [Figure 5] FIG. 1 shows a schematic diagram for determining a controlled invariant set by leveraging robust controlled invariant sets according to one embodiment of the present disclosure. [Figure 6A] 1 illustrates a flow diagram of a method for computing an inner approximation of a probabilistic reachable set based on a robust controlled invariant set, according to one embodiment of the present disclosure. [Figure 6B] 10 illustrates the complement of a keepaway set decomposed as a union of convex sets, according to one embodiment of the present disclosure. [Figure 6C] 10A-10C collectively illustrate convex half-spaces that together define the complement of a keep-away set, according to one embodiment of the present disclosure. [Figure 6D] 10A-10C collectively illustrate convex half-spaces that together define the complement of a keep-away set, according to one embodiment of the present disclosure. [Figure 6E] 10A-10C collectively illustrate convex half-spaces that together define the complement of a keep-away set, according to one embodiment of the present disclosure. [Figure 6F] 10A-10C collectively illustrate convex half-spaces that together define the complement of a keep-away set, according to one embodiment of the present disclosure. [Figure 7A] FIG. 1 illustrates a block diagram for a reformulation of a chance constraint that requires future nominal orbit states to remain outside a keepaway set, according to one embodiment of the present disclosure. [Figure 7B] FIG. 1 illustrates a block diagram for a reformulation of a chance constraint requiring future measurements of a spacecraft to remain within a control invariant set, according to one embodiment of the present disclosure. [Figure 8] 1 illustrates a block diagram of a method for controlling spacecraft motion while avoiding unauthorized entry into keep-away zones during normal and abnormal spacecraft operation. [Figure 9] FIG. 1 is a schematic diagram illustrating some of the components used to implement the methods and systems of the present disclosure. [Figure 10] FIG. 1 is a schematic diagram illustrating, by way of non-limiting example, a computing device for implementing the disclosed methods and systems. DETAILED DESCRIPTION OF THE INVENTION

[0024] Detailed Description In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. However, it will be apparent to those skilled in the art that the present disclosure may be practiced without these specific details. In other instances, devices and methods are shown only in block diagram form in order to avoid obscuring the present disclosure.

[0025] As used in this specification and claims, the words "for example," "for example," "e.g.," "e.g.," and the verbs "comprise," "have," "include," and other verb forms thereof, when used in conjunction with a list of one or more components or other items, should each be construed as open-ended, meaning that the list should not be viewed as excluding other additional components or items. The phrase "based on" means based at least in part on. Furthermore, it should be understood that the phraseology and terminology used herein are for purposes of description and should not be considered limiting. Any headings used within this description are for convenience only and have no legal or restrictive effect.

[0026] 1A illustrates the motion of a spacecraft 101 in a multi-body celestial system, according to one embodiment of the present disclosure. The spacecraft 101 may be configured to rendezvous with a target 103 by following an orbit 105. The target 103 may be a spacecraft, a celestial body, the International Space Station, or orbital debris. For purposes of illustration, the target 103 is shown as the International Space Station. Around the target 103 is a keepaway zone 107. The keepaway zone 107 refers to an area into which the spacecraft 101 must not enter without authorization. Additionally or alternatively, the keepaway zone 107 corresponds to a keepaway set, which is a collection of states including spacecraft position and velocity outside of which the spacecraft 101 must remain.

[0027] An objective of some embodiments is to control the movement of spacecraft 101 while avoiding unauthorized entry into keepaway zone 107 during normal and abnormal operation of spacecraft 101. As used herein, normal operation includes spacecraft 101 moving toward keepaway zone 107. Abnormal operation includes one or a combination of the following: failure to receive permission to enter keepaway zone 107; and failure of at least one component of spacecraft 101, e.g., a thruster.

[0028] To achieve such control objectives, some embodiments provide a controller for controlling the motion of spacecraft 101 during normal and abnormal operation of spacecraft 101.

[0029] 1B illustrates a block diagram of a controller 109 for controlling the motion of a spacecraft 101 during normal and abnormal operation of the spacecraft 101, according to one embodiment of the present disclosure. The controller 109 includes a processor 111 and a memory 113. The processor 111 may be a single-core processor, a multi-core processor, a computing cluster, or any number of other configurations. The memory 113 may include random access memory (RAM), read-only memory (ROM), flash memory, or any other suitable memory system. Additionally, in some embodiments, the memory 113 may be implemented using a hard drive, an optical drive, a thumb drive, an array of drives, or any combination thereof.

[0030] Some embodiments recognize that achieving the aforementioned control objective (i.e., controlling the motion of the spacecraft 101 while avoiding unauthorized entry into the keepaway zone 107 during normal and abnormal operation of the spacecraft 101) is difficult because there are conditions of the spacecraft 101 near the keepaway zone 107 that may unavoidably lead the spacecraft 101 into the keepaway zone 107 even if entry clearance is denied. Entry clearance may be denied based on any reason, including total or partial failure of the spacecraft 101's propulsion. As used herein, the state of the spacecraft 101 includes the position of the spacecraft 101 and at least one or a combination of the velocity and acceleration of the spacecraft 101. Additionally, internal and external forces acting on spacecraft 101 during its motion, such as inertia and gravity, may change the state of spacecraft 101 into certain conditions that may lead spacecraft 101 into keepaway zone 107, despite any efforts spacecraft 101 may make.

[0031] Some embodiments are based on the recognition that this problem can be addressed by computing the union of multiple control invariant sets of values ​​of the state of spacecraft 101 within which the state of spacecraft 101 should be maintained.

[0032] 1C illustrates a union of multiple control invariant sets of values ​​for the states of spacecraft 101, according to one embodiment of the present disclosure. Control invariant sets 115, 117, 119, and 121 form the union of the multiple control invariant sets. In some embodiments, the union of the multiple control invariant sets may partially enclose keepaway zone 107. In some other embodiments, the union of the multiple control invariant sets may completely enclose keepaway zone 107, allowing spacecraft 101 to approach target 103. Each control invariant set is determined such that when the state of spacecraft 101 is within a control invariant set (e.g., control invariant set 121), there are control commands generated by a nominal control law that maintain the state of spacecraft 101 within that control invariant set (control invariant set 121) despite internal and external forces acting on spacecraft 101.

[0033] Thus, during normal operation of spacecraft 101, when the state of spacecraft 101 is within any of control invariant sets 115, 117, 119, and 121, the state of spacecraft 101 is controlled so that spacecraft 101 remains within any of control invariant sets 115, 117, 119, and 121 and does not enter keepaway zone 107.

[0034] Furthermore, to control the motion of spacecraft 101 in the event of abnormal operation, each control invariant set is determined such that there exists an abort control law that generates an abort control command that safely aborts the motion of spacecraft 101 while avoiding keepaway zone 107. For example, if the state of the spacecraft is within control invariant set 121 and there is a thruster failure (abnormal operation), then the abort law corresponding to control invariant set 121 generates an abort control command that safely aborts the motion of spacecraft 101 while avoiding keepaway zone 107.

[0035] Some embodiments recognize that computing control invariant sets 115, 117, 119, and 121 online, i.e., during real-time control of spacecraft 101, is computationally expensive. To alleviate this problem, control invariant sets 115, 117, 119, and 121 and corresponding abort control laws are determined offline, i.e., in advance. Specifically, the abort control laws are determined jointly and interdependently to generate abort control commands for the corresponding control invariant sets. The offline-determined control invariant sets and corresponding abort laws may be stored in memory 113 of controller 109.

[0036] To that end, during online control of spacecraft 101 during abnormal operation, processor 111 receives the current state of spacecraft 101. Further, processor 111 selects a control invariant set that includes the current state of spacecraft 101. Processor 111 executes the abort control law corresponding to the selected control invariant set. Thus, in different states where abnormal operation is detected, controller 109 may use different predetermined abort control laws, thereby reducing computational load and reducing latency of reaction when abnormal operation is detected.

[0037] According to an embodiment, the controller 109 may be embedded in the spacecraft 101. FIG. 2 shows a block diagram of the spacecraft 101 including the controller 109 and other components according to one embodiment of the present disclosure. The spacecraft 101 includes the controller 109, a set of thrusters 201, a set of sensors 203, and circuitry 205. The processor 111 may submit a sequence of control commands, i.e., control commands and abort control commands, generated by the nominal and abort control laws to the set of thrusters 201. The set of thrusters 201 is configured to change the state of the spacecraft 101 according to the sequence of control commands generated by the nominal and abort control laws. According to one embodiment, the set of thrusters 201 includes eight thrusters, each mounted in a manner aligned with the center of mass of the spacecraft 101, so that the thrusters generate forces that change the position of the spacecraft 101 without generating torques that rotate the spacecraft 101.

[0038] Set of sensors 203 is configured to generate measurements indicative of a state of spacecraft 101. The measurements indicative of the state of spacecraft 101 are submitted to processor 111. In one embodiment, set of sensors 203 may include a velocity sensor configured to generate a measurement indicative of a velocity of spacecraft 101 and an acceleration sensor configured to generate a measurement indicative of an acceleration of spacecraft 101. Circuit 205 is configured to detect abnormal operation of spacecraft 101. In one embodiment, circuit 205 may detect abnormal operation based on an off state of set of thrusters 201. For example, a fault in spacecraft 101 may cause one or more thrusters in set of thrusters 201 to be in an off state. Based on the off state of one or more thrusters, circuit 205 detects the abnormal operation and communicates it to processor 111.

[0039] Some embodiments are based on the recognition that the motion of the spacecraft 101 is subject to unbounded stochastic uncertainty. The unbounded stochastic uncertainty includes a probabilistic distribution of process noise. The process noise may define actuation mismatches and / or unmodeled dynamics of the motion of the spacecraft 101. In addition to the process noise, the unbounded stochastic uncertainty may include a probabilistic distribution of measurement noise of the spacecraft state estimate. Because the motion of the spacecraft 101 is subject to unbounded stochastic uncertainty, the unbounded stochastic uncertainty must be taken into account to prevent the spacecraft 101 from illegally entering the keep-away zone 107 with a given safety likelihood.

[0040] Some embodiments are based on the understanding that it is possible to control the motion of the spacecraft 101 with a predetermined safe likelihood. For example, different methods for implementing motion under unbounded stochastic uncertainty include chance constraints, particle filtering, scenario optimization, and stochastic tube methods. To that end, it may be assumed that the motion of the spacecraft 101 can be controlled with a predetermined safe likelihood within the union of multiple control invariant sets. However, such an assumption is based on the concept that each control invariant set is determined deterministically, i.e., without unbounded stochastic uncertainty. However, such an assumption may be inaccurate because if there is any uncertainty in the motion of the spacecraft 101 during online control of the spacecraft 101, the same or similar uncertainty exists during the calculation of the control invariant sets.

[0041] To that end, some embodiments recognize that to guarantee control invariance under unbounded stochastic uncertainty, each control invariant set should internally approximate the values ​​of the states of the spacecraft 101. Furthermore, such guarantees should be accompanied by a likelihood of unbounded stochastic uncertainty that is greater than a predetermined safety likelihood. This is because the final probabilistic guarantee of motion control is a function of the product of the likelihood of control invariance under unbounded stochastic uncertainty and the likelihood of motion satisfying constraints derived from the control invariant sets. For unbounded stochastic uncertainty, all of these likelihoods are less than 1 and therefore need to be considered together to guarantee a predetermined safety likelihood.

[0042] Thus, each control invariant set internally approximates the value of the state of the spacecraft 101 to ensure control invariance under conditions where a first likelihood of unbounded stochastic uncertainty is greater than a predetermined safety likelihood. The nominal control law is configured to generate control commands that maintain the state of the spacecraft 101 within a union of the control invariant sets with a second likelihood, where the second likelihood is selected such that the product of the first likelihood and the second likelihood is greater than or equal to the predetermined safety likelihood.

[0043] The above control problem can be mathematically expressed as follows:

[0044]

number

[0045]

number

[0046]

number

[0047]

number

[0048]

number

[0049]

number

[0050] According to one embodiment, the nominal control law steers the spacecraft 101 to the target 103 in the keep-away set while ensuring that the spacecraft 101 remains within the control invariant set and all necessary state and input constraints are satisfied by the nominal control law. An example of such a control law solves the following optimization problem at each time step:

[0051]

number

[0052]

number

[0053] Constraint (1b) results in a collection of linear equality constraints that describe the evolution of the mean and covariance matrices of the spacecraft states and measurements. Some embodiments are based on the recognition that due to the linearity of spacecraft dynamics and the Gaussian nature of actuation and measurement uncertainties, the future states and measurements of the spacecraft 101 can be described as Gaussian random vectors, with an explicit description of their means and covariances.

[0054]

number

[0055]

number

[0056]

number

[0057]

number

[0058]

number

[0059]

number

[0060] Some embodiments use various techniques to compute control invariant sets for the dynamics of the spacecraft 101 under unbounded stochastic uncertainty (i.e., Gaussian uncertainty). For example, one embodiment uses a probabilistic reachable set to determine the control invariant set. This embodiment is advantageous when the control invariant set to stay within is convex, but may be suboptimal when the uncertainty has a heavy-tailed probability density. When the uncertainty has a heavy-tailed probability density, the estimated uncertainty range for the computation of the control invariant set becomes larger, leading to a significant reduction in the amount of computed control invariant sets. Since the control invariant set limits the states that are acceptable for normal operation, it is desirable to have a large control invariant set. For the problem of interest, the uncertainty is Gaussian and therefore thin-tailed.

[0061] Each probabilistic reachable set used to determine the control invariant set internally approximates the values ​​of the states of the spacecraft 101 to ensure control invariance. In one embodiment, the internal approximation of the probabilistic reachable set is obtained as the union of the probabilistic reachable sets defined for each convex component of the complement of the keepout set. The internal approximation of the probabilistic reachable set is described below with reference to Figures 3A, 3B, and 3C.

[0062] FIG. 3A illustrates a keepaway set 301 and its complement 303, according to an embodiment of the present disclosure.

[0063] 3B illustrates a probabilistic reachable set 305 according to one embodiment of the present disclosure. The probabilistic reachable set 305 includes all states in which the controller 109 can safely maintain the spacecraft 101 (i.e., maintain the spacecraft 101 outside the keepaway set 301) to a specified likelihood despite unbounded probabilistic uncertainty. For the initial state 307, trajectories 311, 313, and 315 may be probabilistic future-state trajectories. For the initial state 309, trajectories 317, 319, and 321 may be probabilistic future-state trajectories. Because the spacecraft 101 must remain outside the keepaway set 301, trajectories 311, 313, and 321 are unsafe, but trajectories 315, 317, and 319 are safe. That is, controller 109 can keep spacecraft 101 safe starting from initial state 309 with a 2 / 3 likelihood, and can keep spacecraft 101 safe starting from initial state 307 with a 1 / 3 likelihood. As a result, set 305 (shown with a horizontal pattern fill) is the probabilistically reachable set corresponding to a 2 / 3 likelihood of safety. Thus, probabilistically reachable set 305 includes initial state 309, but not initial state 307.

[0064] 3C illustrates an inner approximation of the probabilistically reachable set according to an embodiment of the present disclosure. Set 323 (shown with vertical pattern fill) is an inner approximation of probabilistically reachable set 305 (shown with horizontal pattern fill). Any state in set 323 is also in probabilistically reachable set 305. It may be seen from FIG. 3C that neither set 323 nor probabilistically reachable set 305 cover the entire complement of keepaway set 301 (shown with no pattern fill and in gray).

[0065] According to an embodiment, an inner approximation of the probabilistic reachable set may correspond to a control-invariant subset. For any state of spacecraft 101 within the control-invariant subset, there exist control commands that maintain the state of spacecraft 101 within the control-invariant subset for known or allowable future states of the nominal orbit. An exemplary control-invariant subset is described below with reference to FIG. 4.

[0066] FIG. 4 illustrates an example two-dimensional projection 400 of a control invariant set 403 corresponding to a constraint set 401, according to one embodiment of the present disclosure. In one embodiment, constraint set 401 may be a multidimensional polytope determined by a hyperplane expressed by linear inequalities along multiple dimensions corresponding to constraints on the motion of spacecraft 101. Constraint set 401 may encode states of spacecraft 101 that are safe. For any state of spacecraft 101 within control invariant subset 403, there exists a control command that maintains the state of spacecraft 101 within control invariant subset 403 for known or acceptable future states of the nominal trajectory. For example, for any state of spacecraft 101, such as state 415 within control invariant subset 403 and within all possible control inputs 417-423 that controller 109 can execute, there exists at least one control command 423 that maintains the state of spacecraft 101 within control invariant subset 403. On the other hand, state 405 may be feasible for one iteration, but all control commands 407-413 that controller 109 is allowed to take during the next iteration may take the state of spacecraft 101 outside of constraint set 401.

[0067] Some embodiments are based on the recognition that a controlled invariant set can be computed by leveraging a robust controlled invariant set, which determines a set of states that can remain safe despite bounded, non-probabilistic uncertainty.

[0068] 5 shows a schematic diagram 500 for determining a controlled invariant set by utilizing a robust controlled invariant set, according to one embodiment of the present disclosure. Various computational algorithms can be used to compute a robust controlled invariant set. However, these algorithms are not directly applicable to problems involving the presence of unbounded probabilistic uncertainty 402, including probabilistic distributions of process and / or measurement noise. This is because the computational algorithms are applicable to problems involving the presence of bounded deterministic uncertainty.

[0069]

number

[0070] 6A illustrates a block diagram of a method 600 for computing an inner approximation of a probabilistic reachable set based on a robust controlled invariant set, according to one embodiment of the present disclosure. At block 601, the method 600 includes decomposing the complement of a keepaway set (e.g., complement 303 of keepaway set 301 as shown in FIG. 3A) as a union of convex sets.

[0071] 6B illustrates the complement of keepaway set 301 decomposed as a union of convex sets, according to one embodiment of the present disclosure. Convex sets 607-621 form a union of convex sets. Specifically, keepaway set 301 is a polytope, and the complement of keepaway set 301 can be expressed as a union of half-spaces. Each such half-space is convex.

[0072] Figures 6C-6F collectively show convex half-spaces that together define the complement of keepaway set 301. Sets 623, 627, 631, and 635 are copies of keepaway set 301. Set 625 contains sets 607, 609, and 611, and set 629 contains sets 611, 613, and 615. Set 633 contains sets 615, 617, and 619, and set 637 contains sets 619, 621, and 607. Sets 607-621, which are convex, are called keepaway complement components.

[0073]

number

[0074]

number

[0075] At block 605, the method 600 further includes computing a union of the robust controlled invariant sets to obtain an inner approximation of the probabilistic reachable set to the complement of the keepaway set, one for each index i. The inner approximation guarantees control invariance with a first likelihood of unbounded probabilistic uncertainty over a horizon of M time steps. In other words, there exists an abort control law that can steer the spacecraft 101 away from the keepaway set with a first likelihood for M time steps into the future in the event of abnormal operation.

[0076] In one embodiment, the robust control invariant set and the corresponding abort control law are jointly and interdependently determined using a single computation of the robust control invariant set. The computation of the robust control invariant set automatically generates, for each state, a set of control actions that maintains the spacecraft 101 within the robust control invariant set. The set of control actions is characterized by the spacecraft dynamics, the control constraints, and the robust control set. Thus, the abort control law will select a control action from the set of control actions at each time step.

[0077]

number

[0078]

number

[0079] Furthermore, the nominal control law applied during normal operation steers the spacecraft 101 to the target 103 in the keep-away set while ensuring that the spacecraft 101 remains within the control invariant set and that all required state and input constraints are satisfied by the nominal control law. An example of such a nominal control law solves the optimization problem given by equation (1). In one embodiment, the nominal control law is designed using a model predictive controller (MPC). The MPC is based on iterative finite-horizon optimization of a model of the spacecraft 101 dynamics, a set of spacecraft 101 motion objectives, and constraints on the spacecraft propulsion system and motion. The MPC can predict future events to take appropriate control actions. According to an embodiment, the MPC may estimate a sequence of control steps over a prediction horizon that will act on the spacecraft 101 under the influence of internal and external forces.

[0080]

number

[0081] Some embodiments recognize that enforcing the chance constraints (1c) and (1d) can be intractable. To that end, some embodiments aim to provide a conservative yet tractable implementation of the chance constraints (1c) and (1d). Some embodiments recognize that to conservatively enforce the chance constraints (1c) and (1d), the chance constraints (1c) and (1d) can be reformulated as a collection of mixed-integer linear constraints that conservatively enforce the chance constraints (1c) and (1d). In one embodiment, the chance constraints (1c) and (1d) can be reformulated as a collection of mixed-integer linear constraints based on Boolean inequalities, quantile reformulation, and disjunctive programming. Reformulations of the chance constraints (1c) and (1d) are described below with reference to FIGS. 7A and 7B, respectively.

[0082]

number

[0083] In block 703, a probabilistic joint chance constraint is obtained by encoding the desired behavior. The probabilistic joint chance constraint may be given as follows:

[0084]

number

[0085] Probabilistic joint chance constraints limit the probability of undesirable behavior with a small probability. In block 705, optional individual chance constraints are obtained by utilizing simple probability theory and a quantile reformulation of Gaussian chance constraints. The optional individual chance constraints may be given as follows:

[0086]

number

[0087] In block 707, the mixed integer linear constraints are obtained based on constraint enforcement and disjunctive programming. The mixed integer linear constraints may be given as follows:

[0088]

number

[0089]

number

[0090] 7B shows a block diagram for reformulating the chance constraint (1d) to require future measurements of spacecraft 101 to remain within the control invariant set, according to one embodiment of the present disclosure. In block 709, the desired behavior of future measurements of spacecraft 101 to remain within the control invariant set is given as a deterministic inequality constraint for all t, as follows:

[0091]

number

[0092] In block 711, the probabilistic joint chance constraints are obtained by encoding the desired behavior. The probabilistic joint chance constraints may be given as follows:

[0093]

number

[0094] In block 713, optional individual chance constraints are obtained by utilizing simple probability theory and quantile reformulation of Gaussian chance constraints. The optional individual chance constraints may be given as follows:

[0095]

number

[0096] In block 715, the mixed integer linear constraints are obtained based on constraint enforcement and disjunctive programming. The mixed integer linear constraints may be given as follows:

[0097]

number

[0098]

number

[0099] The use of mixed-integer linear constraints (4) and (5) in the optimization problem (1) presents the optimization problem (1) as a mixed-integer program due to the presence of binary variables. For real-time implementations, feasible values ​​for the binary variables may be pre-assigned to obtain a convex quadratic program.

[0100] FIG. 8 illustrates a block diagram of a method 800 for controlling the motion of a spacecraft 101 while avoiding unauthorized entry into a keep-away zone 107 during normal and abnormal operation of the spacecraft 101.

[0101] At block 801, method 800 includes receiving a current state of spacecraft 101. At block 803, method 800 includes selecting a control invariant set that includes the current state of spacecraft 101.

[0102] At block 805, the method includes determining whether abnormal operation is detected. If abnormal operation is detected, at block 807, the method 800 includes executing an abort control law associated with the selected control invariant set. The abort control law generates an abort control command that moves the spacecraft 101 while avoiding the keepaway zone 107.

[0103] If no abnormal operation is detected, then in block 809, method 800 includes executing a nominal control law. The nominal control law generates control commands that maintain the state of spacecraft 101 within the control invariant set despite internal and external forces acting on spacecraft 101.

[0104] 9 is a schematic diagram illustrating some of the components used to implement the methods and systems of the present disclosure. For example, a computer 900 may be adapted to control the motion of a spacecraft 101 in a multi-body celestial system while avoiding unauthorized entry into a keep-away zone 107 during normal and abnormal operation of the spacecraft 101. A CPU or processor 901 may be connected to a memory 905, input / output devices 907, and a communication interface 909 via a bus system 903. Also connected to the bus system 903 may be a storage device 911, a control interface 913, a display interface 915, and an external interface 917.

[0105] The external interface 917 can be connected to an expansion memory 919, vehicle parameters 921 (i.e., spacecraft specifications, thruster specifications, size, weight, etc.), initial orbit data 923 (i.e., parameters including time, date, altitude, inclination, eccentricity, etc.), target orbit data 925, and other orbit data 927 (i.e., specific orbit data). The bus system 903 can also connect a control interface 929, an output interface 931, a receiver 933, and a transmitter 935. Furthermore, the bus system 903 can connect a GPS receiver module 937 to a GPS 939. The computer 900 includes an orbit keeping module 941. The orbit keeping module 941 may output thruster commands 943. The orbit keeping module 941 includes a transfer orbit generator 945, a feedback gain module 947, a feedback controller 949, and a thruster command generator 951.

[0106] The computer 900 can be a server or desktop, laptop, mobile, or other computing device or system having one or more processors 901. The processor 901 may be a central processing unit adapted to access code in the form of a transition trajectory generator 945 in the memory 905 or storage device 911 (or in expansion memory 919) of the computer 900. In accordance with aspects related to the systems and methods of the present disclosure, external storage devices are contemplated as further needed depending on the specific design and aspects of the intended hardware and implementation. For example, the computer 900 can be used to implement the steps of the systems and methods in which the memory 905 and / or storage device 911 can store data.

[0107] The data stored in memory 905 can include executable modules, vehicle data, and historical space data. For example, vehicle data can include spacecraft specifications, dimensions, weight, performance data under varied conditions including gravity, and other perturbations, i.e., the complex motion of a mass subject to forces other than the gravitational attraction of a single other mass in space.

[0108] Additionally, vehicle data can include data related to aspects of vehicle dynamics associated with multiple variables, i.e., one or more of: (1) anomalous orbital characteristics of a celestial body, i.e., a natural object located outside the Earth's atmosphere, such as the Moon, the Sun, an asteroid, a planet, or a star; (2) anomalous orbital motion of a celestial body; (3) a near-anomalous orbit of a celestial body around another celestial body; and (4) other known perturbations. Spatial data can include data related to celestial systems, past missions to celestial bodies, and any other data related to planning space, spacecraft, and orbital designs for other celestial bodies in space. For example, spatial data can include data related to the moon of a celestial body, such as the properties of the celestial body that can be considered when developing an orbital design from an initial celestial body orbit to a similar target celestial body orbit.

[0109] The processor 901 of the computer 900 may include two or more processors depending on the particular application. For example, some steps may require separate processors to ensure a particular processing time or processing speed associated with the systems and methods of the present disclosure. The receiver 933 or input interface can receive spatial data, which may be stored historical spatial data stored in the memory 905, or current spatial data obtained from either an Earth mission control center, a sensor associated with the spacecraft, or some other location. The receiver 933 and transmitter 935 can receive data and provide a radio location for transmission, for example, to an Earth mission control center or some other destination. A GPS receiver module 937 connected to a GPS 939 can be used for navigation-related aspects. The computer 900 may further include external devices, control interfaces, displays, sensors, machines, etc., contemplated for use in connection with the systems and methods of the present disclosure.

[0110] 10 is a schematic diagram illustrating, by way of non-limiting example, a computing device for implementing the methods and systems of the present disclosure. The computing device 1000 may include a power supply 1001, a processor 1003, a memory 1005, and a storage device 1007, all connected to a bus 1009. Further, a high-speed interface 1011, a low-speed interface 1013, a high-speed expansion port 1015, and a low-speed connection port 1017 may be connected to the bus 1009. Additionally, a low-speed expansion port 1019 may be connected to the bus 1009. Furthermore, an input interface 1021 may be connected to an external receiver 1023 and an output interface 1025 via the bus 1009. The receiver 1027 may be connected to an external transmitter 1029 and a transmitter 1031 via the bus 1009. Also connected to the bus 1009 may be an external memory 1033, an external sensor 1035, a machine 1037, and an environment 1039. Additionally, one or more external input / output devices 1041 may be connected to bus 1009. A network interface controller (NIC) 1043 may be adapted to connect to a network 1045 through bus 1009, allowing data or other data to be rendered on, among other things, a third-party display device, a third-party imaging device, and / or a third-party printing device external to computing device 1000.

[0111] The memory 1005 may store instructions executable by the computing device 1000, historical data, and any data that may be utilized by the methods and systems of the present disclosure. The memory 1005 may include random access memory (RAM), read-only memory (ROM), flash memory, or any other suitable memory system. The memory 1005 may be a volatile memory unit and / or a non-volatile memory unit. The memory 1005 may also be another form of computer-readable medium, such as a magnetic disk or an optical disk.

[0112] The storage device 1007 may be adapted to store supplemental data and / or software modules used by the computing device 1000. For example, the storage device 1007 may store historical data and other relevant data, as described above with respect to this disclosure. Additionally or alternatively, the storage device 1007 may store historical data, such as the data referred to above with respect to this disclosure. The storage device 1007 may include a hard drive, an optical drive, a thumb drive, an array of drives, or any combination thereof. Furthermore, the storage device 1007 may include an array of devices, including computer-readable media such as a floppy disk device, a hard disk device, an optical disk device, or a tape device, a flash memory or other similar solid-state memory device, or a device in a storage area network or other configuration. The instructions may be stored on an information carrier. When executed by one or more processing units (e.g., the processor 1003), the instructions perform one or more methods, such as those described above.

[0113] Computing device 1000 may be linked via bus 1009 to an optional display interface or user interface (HMI) 1047 adapted to connect computing device 1000 to a display device 1049 and keyboard 1051, which may include, among other things, a computer monitor, a camera, a television, a projector, or a mobile device. In some implementations, computing device 1000 may include a printer interface for connecting to a printing device, which may include, among other things, a liquid inkjet printer, a solid ink printer, a large-scale commercial printer, a thermal printer, a UV printer, or a dye sublimation printer.

[0114] The high-speed interface 1011 manages bandwidth-intensive operations for the computing device 1000, and the low-speed interface 1013 manages less bandwidth-intensive operations. This allocation of functionality is merely an example. In some implementations, the high-speed interface 1011 may be coupled to memory 1005, a user interface (HMI) 1047, a keyboard 1051 and a display 1049 (e.g., via a graphics processor or accelerator), and a high-speed expansion port 1015 that may accept various expansion cards via a bus 1009. In one implementation, the low-speed interface 1013 is coupled to storage device 1007 and a low-speed expansion port 1017 via a bus 1009. The low-speed expansion port 1017, which may include various communication ports (e.g., USB, Bluetooth, Ethernet, wireless Ethernet), may be coupled to one or more input / output devices 1041. The computing device 1000 may be connected to a server 1053 and a rack server 1055. The computing device 1000 may be implemented in a number of different forms. For example, the computing device 1000 may be implemented as part of a rack server 1055.

[0115] The following description provides exemplary embodiments only and is not intended to limit the scope, applicability, or configuration of the present disclosure. Rather, the following description of exemplary embodiments provides those skilled in the art with an enabling description for implementing one or more exemplary embodiments. Contemplated are various changes that may be made in the function and arrangement of elements without departing from the spirit and scope of the disclosed subject matter as set forth in the claims.

[0116] In the following description, specific details are given for a thorough understanding of the embodiments. However, it will be understood by those skilled in the art that the embodiments may be practiced without these specific details. For example, systems, processes, and other elements in the disclosed subject matter may be shown as components in block diagram form so as not to obscure the embodiments in unnecessary detail. In other instances, well-known processes, structures, and techniques may be shown without unnecessary detail to avoid obscuring the embodiments. Furthermore, like reference numbers and names in the various drawings indicate like elements.

[0117] Also, particular embodiments may be described as a process that is depicted as a flowchart, a flow diagram, a data flow diagram, a structure diagram, or a block diagram. While a flowchart may describe operations as a sequential process, many of the operations can be performed in parallel or simultaneously. Additionally, the order of operations may be rearranged. A process may terminate when its operations are completed, or may have additional steps not discussed or included in the diagram. Moreover, not all operations in any particularly described process may occur in all embodiments. A process may correspond to a method, a function, a procedure, a subroutine, a subprogram, etc. When a process corresponds to a function, the end of the function may correspond to a return of the function to the calling function or the main function.

[0118] Furthermore, embodiments of the disclosed subject matter may be implemented, at least in part, either manually or automatically. The manual or automatic implementation may be performed, or at least assisted, through the use of a machine, hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware, or microcode, the program code or code segments to perform the necessary tasks may be stored on a machine-readable medium. The necessary tasks may be performed by a processor.

[0119] The various methods or processes outlined herein may be coded as software executable on one or more processors using any one of a variety of operating systems or platforms. Additionally, such software may be written using any of a number of suitable programming languages ​​and / or programming or scripting tools, and may be compiled as executable machine language code or intermediate code that runs on a framework or virtual machine. Typically, the functionality of the program modules may be combined or distributed as desired in various embodiments.

[0120] The embodiments of the present disclosure may be embodied as a method, of which an example is provided. The acts performed as part of the method may be ordered in any suitable manner. Thus, embodiments may be constructed in which acts are performed in a different order than illustrated, including simultaneously performing some acts shown as sequential acts in the exemplary embodiment.

[0121] Although the present disclosure has been described with reference to certain preferred embodiments, it is to be understood that various other adaptations and modifications can be made within the spirit and scope of the disclosure. It is therefore the object of the appended claims to cover all such variations and modifications as come within the true spirit and scope of the disclosure. [Explanation of symbols]

[0122] 101 spacecraft, 103 target, 105 orbit, 107 keepaway zone, 109 controller, 111 processor, 113 memory.

Claims

1. 1. A controller for controlling motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, wherein the normal operation includes moving toward a target in the keepaway zone and the abnormal operation includes one or a combination of a failure to receive permission to enter the keepaway zone and a failure of at least one component of the spacecraft, the controller comprising at least one processor and a memory storing instructions, the instructions, when executed by the at least one processor, causing the controller to: and executing a nominal control law constrained to maintain a state of the spacecraft within a union of a plurality of control invariant sets of values of the state of the spacecraft that partially or completely enclose the keepaway zone during the normal operation of the spacecraft, the state of the spacecraft including a position of the spacecraft and at least one or a combination of a velocity and an acceleration of the spacecraft, each of the plurality of control invariant sets being determined such that when the state of the spacecraft is within a control invariant set, there are control commands generated by the nominal control law that maintain the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft, the nominal control law solving at each time step an optimization problem that minimizes a sum of squared distances of the spacecraft relative to the keepaway zone over time and an amount of energy consumed by an open-loop control sequence subject to linear equality constraints that describe the evolution of mean and covariance matrices of the spacecraft states and measurements. The instructions, when executed by the at least one processor, further cause the controller to: and wherein upon detecting the abnormal operation of the spacecraft, the controllers execute an abort control law associated with a control invariant set that includes a current state of the spacecraft, at least some different abort control laws are associated with at least some different control invariant sets, the abort control laws being jointly and interdependently determined for a corresponding control invariant set to generate an abort control command that moves the spacecraft while avoiding the keepaway zone for any state within the corresponding control invariant set.

2. 1. A spacecraft for travel in a multi-body celestial system, comprising: The controller of claim 1; a set of thrusters configured to alter a spacecraft state according to a sequence of control commands generated by the nominal control law and the abort control law; a set of sensors configured to generate measurements indicative of the state of the spacecraft; and circuitry configured to detect said abnormal operation of said spacecraft.

3. 2. The controller of claim 1, wherein the controller is configured to avoid the unauthorized entry of the spacecraft into the keepaway zone with a predetermined safety likelihood while the motion of the spacecraft is subject to unbounded stochastic uncertainty, each of the control invariant sets internally approximating the value of the state of the spacecraft to ensure control invariance with a first likelihood of the unbounded stochastic uncertainty greater than the predetermined safety likelihood, and the nominal control law is configured to generate control commands that maintain the state of the spacecraft within the union of the plurality of control invariant sets with a second likelihood, the second likelihood selected such that a product of the first likelihood and the second likelihood is greater than or equal to the predetermined safety likelihood.

4. The controller of claim 3 , wherein each of the control invariant sets is a probabilistic reachable set determined for possible abnormal operations defined by the first likelihood of the unbounded probabilistic uncertainty.

5. 4. The controller of claim 3, wherein each of the control invariant sets is a robust control invariant set determined for the nominal control law with bounded non-probabilistic uncertainties corresponding to the first likelihood over the unbounded stochastic uncertainties.

6. 6. The controller of claim 5, wherein the nominal control law is a model predictive control (MPC) using a model of the spacecraft dynamics with the unbounded stochastic uncertainty, and the nominal control law, together with other constraints including one or a combination of actuation constraints, ensures the spacecraft stays within the robust controlled invariant set with a second likelihood, and a nominal trajectory approaches the keepaway set without entering the keepaway set.

7. 7. The controller of claim 6, wherein the stochastic distribution of process noise specifies one or a combination of spacecraft thruster actuation mismatch and unmodeled dynamics of the motion of the spacecraft.

8. 7. The controller of claim 6, wherein the unbounded stochastic uncertainty includes a probabilistic distribution of measurement noise of the estimate of the state of the spacecraft, and the MPC estimates a sequence of control steps over a prediction horizon to act on the spacecraft with the state having bounded measurement noise having a range of values, the range of values being constrained to have a likelihood for the probabilistic distribution of the measurement noise that is greater than the first likelihood.

9. The controller of claim 8 , wherein the state of the spacecraft is determined by a stochastic filter subject to the measurement noise.

10. The controller of claim 9 , wherein the probabilistic filter comprises one or a combination of a Kalman filter and a particle filter.

11. The controller of claim 3 , wherein the constraints that maintain the state of the spacecraft within the union of the plurality of control invariant sets require their satisfaction with the second likelihood.

12. The controller of claim 11 , wherein the constraints include chance constraints.

13. 12. The controller of claim 11, wherein the constraints include one or a combination of chance constraints requiring the states of the spacecraft to be outside the keepaway zone, actuation constraints, and chance constraints requiring measurements of the spacecraft to be within the plurality of control invariant sets.

14. 1. A method for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keep-away zone during normal and abnormal operation of the spacecraft, wherein the normal operation includes moving toward the keep-away zone and the abnormal operation includes one or a combination of a failure to receive permission to enter the keep-away zone and a failure of at least one component of the spacecraft, the method comprising: and executing a nominal control law that is constrained to maintain a state of the spacecraft within a union of a plurality of control invariant sets of values of the state of the spacecraft that partially or completely enclose the keepaway zone during the normal operation of the spacecraft, the state of the spacecraft including a position of the spacecraft and at least one or a combination of a velocity and an acceleration of the spacecraft, each of the plurality of control invariant sets being determined such that when the state of the spacecraft is within a control invariant set, there are control commands generated by the nominal control law that maintain the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft, the nominal control law solving an optimization problem at each time step that minimizes a sum of squared distances of the spacecraft relative to the keepaway zone over time and an amount of energy consumed by an open-loop control sequence subject to linear equality constraints that describe the evolution of mean and covariance matrices of the state and measurements of the spacecraft, the method further comprising: Upon detecting the abnormal operation of the spacecraft, executing an abort control law associated with a control invariant set that includes a current state of the spacecraft, wherein at least some different abort control laws are associated with at least some different control invariant sets, and the abort control laws, for corresponding control invariant sets, execute abort control laws that move the spacecraft while avoiding the keepaway zone for any state within the corresponding control invariant sets. The method is jointly and interdependently determined to generate a control command.

15. 15. The method of claim 14, further comprising avoiding the unauthorized entry of the spacecraft into the keepaway zone with a predetermined safety likelihood while the motion of the spacecraft is subject to unbounded stochastic uncertainty, wherein each of the control invariant sets internally approximates the value of the state of the spacecraft to ensure control invariance with a first likelihood of the unbounded stochastic uncertainty greater than the predetermined safety likelihood, and wherein the nominal control law is configured to generate control commands that maintain the state of the spacecraft within the union of the plurality of control invariant sets with a second likelihood, wherein the second likelihood is selected such that a product of the first likelihood and the second likelihood is greater than or equal to the predetermined safety likelihood.

16. 16. The method of claim 15, wherein each of the control invariant sets is a probabilistic reachable set determined by the first likelihood of the unbounded probabilistic uncertainty about possible abnormal behavior.

17. 16. The method of claim 15, wherein each of the control invariant sets is a robust control invariant set determined for the nominal control law with bounded non-probabilistic uncertainties corresponding to the first likelihood over the unbounded stochastic uncertainties.

18. The method of claim 16 , wherein the unbounded probabilistic uncertainty comprises a probabilistic distribution of process noise.

19. 1. A non-transitory computer-readable storage medium having embodied thereon a program executable by a processor to perform a method for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, wherein the normal operation includes moving toward the keepaway zone and the abnormal operation includes one or a combination of a failure to receive permission to enter the keepaway zone and a failure of at least one component of the spacecraft, the method comprising: and executing a nominal control law that is constrained to maintain a state of the spacecraft within a union of a plurality of control invariant sets of values of the state of the spacecraft that partially or completely enclose the keepaway zone during the normal operation of the spacecraft, the state of the spacecraft including a position of the spacecraft and at least one or a combination of a velocity and an acceleration of the spacecraft, each of the plurality of control invariant sets being determined such that when the state of the spacecraft is within a control invariant set, there are control commands generated by the nominal control law that maintain the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft, the nominal control law solving an optimization problem at each time step that minimizes a sum of squared distances of the spacecraft relative to the keepaway zone over time and an amount of energy consumed by an open-loop control sequence subject to linear equality constraints that describe the evolution of mean and covariance matrices of the state and measurements of the spacecraft, the method further comprising: and upon detecting the abnormal operation of the spacecraft, executing an abort control law associated with a control invariant set that includes a current state of the spacecraft, at least some different abort control laws associated with at least some different control invariant sets, the abort control laws jointly and interdependently determined for a corresponding control invariant set to generate an abort control command that moves the spacecraft while avoiding the keepaway zone for any state within the corresponding control invariant set.