Systems and methods for controlling the motion of spacecraft in a multi-body celestial system
A controller system for spacecraft motion control determines control-invariant sets and abort laws offline to manage uncertainties, ensuring safe operation and avoiding unauthorized entry into a keep-away zone, addressing thruster failures and unmodeled phenomena.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-25
- Publication Date
- 2026-04-10
AI Technical Summary
Existing spacecraft rendezvous and motion control systems face challenges in maintaining safety during normal and abnormal operations, particularly in avoiding unauthorized entry into a keep-away zone due to thruster failures, measurement noise, and unmodeled phenomena, which can lead to collisions or unauthorized access.
A controller system that determines control-invariant sets and corresponding abort control laws offline to manage spacecraft motion, using probabilistic methods to account for unbounded uncertainty, ensuring the spacecraft remains within safe operational boundaries and avoids the keep-away zone even in abnormal conditions.
The system effectively maintains spacecraft safety by reducing computational load and latency in responding to abnormalities, ensuring controlled motion and preventing unauthorized entry into the keep-away zone with a given safety likelihood, despite unbounded probabilistic uncertainty.
Smart Images

Figure 0007843686000031 
Figure 0007843686000032 
Figure 0007843686000033
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to the control of the movement of spacecraft, and more particularly, to a system and method for controlling the movement of a spacecraft in a multi-object celestial system while avoiding unauthorized entry into a keep-away zone during normal and abnormal operations of the spacecraft.
Background Art
[0002] Spacecraft rendezvous is a set of orbital operations in which, during its execution, two spacecraft, namely a chaser spacecraft and a target or space station, arrive at the same orbit and approach each other at a close distance (e.g., within visual contact). Spacecraft rendezvous requires precise alignment of the orbital velocities and position vectors of the two spacecraft, enabling them to maintain a constant distance through orbital station-keeping. Spacecraft rendezvous may be followed by docking or berthing, i.e., physically contacting the spacecraft with each other and forming a link between the spacecraft, or it may not. Furthermore, the same spacecraft rendezvous may be used for the "landing" of a spacecraft on a natural object in the presence of a weak gravitational field, such as landing on an asteroid or one of the moons of Mars. The landing of a spacecraft on a natural object may also be the same as matching the orbital velocity and may be followed by a "descent" that shares similarities with docking.
[0003] However, spacecraft rendezvous with a target is a difficult task. An important criterion for spacecraft rendezvous is maintaining safety, i.e., the ability to avoid a collision between the chaser spacecraft and the target in the event of a partial thruster failure. In the event of a partial thruster failure, the chaser spacecraft may deviate from its nominal approach near the target. When the chaser spacecraft deviates significantly from its nominal approach near the target and its current orbit is not passively safe, a predefined active collision avoidance maneuver (CAM) is initiated. However, depending on the approach trajectory and the extent of the partial thruster failure, CAM may not always be possible.
[0004] Furthermore, for spacecraft motion planning, mathematical models are used to predict the trajectory as a specific sequence of thrusters is applied to the Chaser spacecraft over time. However, in reality, the true spacecraft motion may deviate from the trajectory predicted by the mathematical model. Such deviations can occur for a variety of reasons, including operational mismatch, measurement noise, and unmodeled phenomena. Operational mismatch results from poor thruster tuning and limitations of the hardware installed on the Chaser spacecraft. Measurement noise can result from the sensing limits of sensors, which provide inaccurate information about the state of the Chaser spacecraft, including its position and velocity. Also, for the computational and interpretability of the mathematical model, it is common practice to exclude complex phenomena that may have a slight impact on the trajectory.
[0005] Therefore, improved methods are needed to control the operation of the Chaser spacecraft for safe rendezvous in the event of malfunction, operational mismatch, measurement noise, and other uncertainties. [Overview of the Initiative]
[0006] The objective of some embodiments is to provide systems and methods for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft. As used herein, normal operation includes moving toward a target within a keepaway zone, and abnormal operation includes one or a combination of failure to receive permission to enter a keepaway zone and / or failure of at least one component of the spacecraft. This problem arises from the requirements of spacecraft motion and rendezvous of multiple spacecraft forming a multi-body celestial system in order to ensure greater safety in space collaboration. For that purpose, the objective of one embodiment is, upon detecting abnormal operation, to control the motion of the spacecraft toward a keepaway zone such that the likelihood of moving the spacecraft toward a keepaway zone while avoiding it is high.
[0007] Some embodiments are based on the recognition that there exists a spacecraft state close to the keepaway zone that could inevitably lead the spacecraft into the keepaway zone, even if access permission is denied for any reason, including a complete or partial failure of the spacecraft's propulsion. As used herein, the state of the spacecraft includes the position of the spacecraft and at least one or a combination of the spacecraft's velocity and acceleration. Furthermore, internal and external forces acting on the spacecraft during its motion, such as inertia and gravity, can change the state of the spacecraft to a particular state that could lead the spacecraft into the keepaway zone, despite any efforts the spacecraft may make.
[0008] Some embodiments are based on the recognition that this problem can be addressed by using a set of control-invariant values of the spacecraft's state in which it should be. As used herein, the control-invariant set is determined such that, when the spacecraft's state is within the control-invariant set, there exist control commands generated by control laws that maintain the spacecraft's state within the control-invariant set despite internal and external forces acting on the spacecraft. Thus, when the spacecraft is within the control-invariant set, there exist control laws within specified control limits that prevent the spacecraft from entering the keepaway zone.
[0009] Since control invariants depend on control limits, some embodiments determine multiple control invariants that form a union of multiple control invariants of values for the spacecraft's state. The union of multiple control invariants may partially enclose the keepaway zone. In some other embodiments, the union of multiple control invariants may completely enclose the keepaway zone. Furthermore, to control the spacecraft's motion in the event of abnormal operation, each control invariant is determined such that there exists an abnormal control law that safely aborts the spacecraft's motion, taking into account the operating limits associated with the abnormality.
[0010] Some embodiments are based on the recognition that calculating the control invariant set online, i.e., during real-time control of the spacecraft, is computationally expensive. To mitigate this problem, the control invariant set and the corresponding abort control laws are determined offline, i.e., in advance. Specifically, the abort control laws are determined jointly and interdependently with respect to the corresponding control invariant set in order to generate abort control commands. The control invariant set and the corresponding abort laws determined offline may be stored in the controller used to control the motion of the spacecraft.
[0011] To this end, during online control of a spacecraft experiencing abnormal operation, the controller receives the spacecraft's current state. Furthermore, the processor selects a set of control invariants that includes the spacecraft's current state. The controller then executes an abort control law corresponding to the selected set of control invariants. Thus, in different states where abnormal operation is detected, the controller may use different predetermined abort control laws, thereby reducing the computational load and the latency of the response when abnormal operation is detected.
[0012] Some embodiments are based on the recognition that the motion of a spacecraft is affected by unbounded probabilistic uncertainty. Unbounded probabilistic uncertainty includes a probabilistic distribution of process noise. Process noise can impose operational mismatches and / or unmodeled dynamics of the spacecraft's motion. In addition to process noise, unbounded probabilistic uncertainty may include a probabilistic distribution of measurement noise in the estimation of the spacecraft's state. Since the motion of a spacecraft is affected by unbounded probabilistic uncertainty, it is necessary to take this uncertainty into account and avoid unauthorized entry of the spacecraft into the keepaway zone with a given safety likelihood.
[0013] Some embodiments are based on the understanding that it is possible to control the motion of a spacecraft with a given safety likelihood. For example, different methods for implementing motion under unbounded probabilistic uncertainty include opportunity constraints, particle filtering, scenario optimization, and probabilistic tube methods. To this end, one might assume that it is possible to control the motion of a spacecraft with a given safety likelihood within a union of multiple sets of control invariants. However, such an assumption is based on the concept that each set of control invariants is determined deterministically, i.e., without unbounded probabilistic uncertainty. However, such an assumption can be inaccurate because if there is some uncertainty in the motion of the spacecraft during online control of the spacecraft, the same or similar uncertainty exists in the computation of the control invariants.
[0014] To this end, some embodiments are based on the understanding that, in order to guarantee control invariance under unbounded probabilistic uncertainty, each set of control invariants should internally approximate the values of the spacecraft's state. Furthermore, such a guarantee should be accompanied by a likelihood of unbounded probabilistic uncertainty that is greater than a given safety likelihood. This is because the final probabilistic guarantee of motion control is a function of the product of the likelihood of control invariance under unbounded probabilistic uncertainty and the likelihood of motion satisfying the constraints derived from the set of control invariants. Due to unbounded probabilistic uncertainty, all of these likelihoods are less than 1 and therefore must be considered together to guarantee a given safety likelihood.
[0015] Therefore, each control invariant set internally approximates the value of the spacecraft's state to guarantee control invariance in the state where the first likelihood of unbounded probabilistic uncertainty is greater than a given safety likelihood. The control laws are constructed to generate control commands that maintain the spacecraft's state within the union of control invariant sets with a second likelihood, the second likelihood being chosen such that the product of the first likelihood and the second likelihood is greater than or equal to a given safety likelihood.
[0016] Several embodiments use various techniques to compute a set of control invariants for the dynamics of a spacecraft under unbounded probabilistic uncertainty. For example, one embodiment uses a probabilistically reachable set to determine the set of control invariants. This embodiment is advantageous when the set of control invariants to stay within is convex, but may be suboptimal when the uncertainty has a probability density with thick tails. When the uncertainty has a probability density with thick tails, the estimated range of uncertainty for computing the set of control invariants becomes larger, leading to a significant decrease in the amount of the set of control invariants computed. Since the set of control invariants restricts the states allowed for normal operation, it is desirable to have a large set of control invariants. With respect to the problem in question, the uncertainty is Gaussian uncertainty, and therefore has thin tails.
[0017] Additionally or alternatively, the controlled invariant set can be computed by leveraging the robust uncontrolled invariant set. The robust uncontrolled invariant set determines the set of states that can maintain safety despite bounded, unprobabilistic uncertainty. Various computational algorithms can be used to compute the robust uncontrolled invariant set. However, these algorithms are not directly applicable to problems involving the presence of unbounded, probabilistic uncertainty, such as probabilistic distributions of process and / or measurement noise. This is because the computational algorithms are applicable to problems involving the presence of bounded, deterministic uncertainty.
[0018] To mitigate this problem, unbounded probabilistic uncertainty is transformed into a finite deterministic uncertainty with a predefined likelihood that specifies a range of values over the unbounded probabilistic uncertainty. For this purpose, a robust uncontrolled invariant set can be computed using a computational algorithm. Furthermore, a controlled invariant set can be determined based on the computed robust uncontrolled invariant set.
[0019] Accordingly, one embodiment discloses a controller for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, where normal operation includes moving toward the keepaway zone, and abnormal operation includes one or a combination of failure to receive permission to enter the keepaway zone and failure of at least one component of the spacecraft. The controller comprises at least one processor and a memory storing instructions, which, when executed by at least one processor, cause the controller to execute nominal control laws that, during normal operation of the spacecraft, are constrained to maintain the state of the spacecraft within a union of multiple control invariant sets of spacecraft state values that partially or completely enclose a keepaway zone, where the state of the spacecraft includes the position of the spacecraft and at least one or a combination of the velocity and acceleration of the spacecraft, each of the multiple control invariant sets being constrained to maintain the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft when the state of the spacecraft is within the control invariant set. It is determined that there exist control commands generated by nominal control laws, and the instructions are further determined, when executed by at least one processor, to cause the controller, upon detecting abnormal behavior of the spacecraft, to execute abort control laws associated with a set of control invariants containing the current state of the spacecraft, and at least several different abort control laws are associated with at least several different sets of control invariants, and the abort control laws are determined jointly and interdependently to generate abort control commands for the corresponding sets of control invariants, which move the spacecraft while avoiding the keepaway zone for any state within the corresponding sets of control invariants.
[0020] Accordingly, another embodiment discloses a tracking method for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, where normal operation includes moving toward a keepaway zone, and abnormal operation includes one or a combination of failure to receive permission to enter a keepaway zone and failure of at least one component of the spacecraft. The method includes, during normal operation of the spacecraft, executing a nominal control law that is constrained to maintain the state of the spacecraft within a union of multiple control invariant sets of spacecraft state values that partially or completely enclose a keepaway zone, where the state of the spacecraft includes the position of the spacecraft and at least one or a combination of the spacecraft's velocity and acceleration. Each of the multiple control invariant sets is determined such that there exists a control command generated by the nominal control law that maintains the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft when the state of the spacecraft is within the control invariant set. The method further includes detecting abnormal behavior of the spacecraft and executing abort control laws associated with a set of control invariants containing the current state of the spacecraft, wherein at least several different abort control laws are associated with at least several different sets of control invariants, and the abort control laws are determined jointly and interdependently to generate abort control commands for the corresponding sets of control invariants that move the spacecraft while avoiding the keepaway zone for any state within the corresponding sets of control invariants.
[0021] Accordingly, yet another embodiment discloses a non-temporary computer-readable storage medium embodying a processor-executable program for performing a method for controlling the motion of a spacecraft in a multi-body celestial system, while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, wherein normal operation includes moving toward a keepaway zone, and abnormal operation includes one or a combination of failing to receive permission to enter a keepaway zone and failure of at least one component of the spacecraft. The method comprises, during normal operation of the spacecraft, executing nominal control laws constrained to maintaining the state of the spacecraft within a union of multiple sets of control invariants of spacecraft state values that partially or completely enclose a keepaway zone, wherein the state of the spacecraft includes the position of the spacecraft and at least one or a combination of the spacecraft's velocity and acceleration, and each of the multiple sets of control invariants is determined such that there exists a control command generated by a nominal control law that maintains the state of the spacecraft within the set of control invariants despite internal and external forces acting on the spacecraft when the state of the spacecraft is within the set of control invariants, and the method further comprises, upon detection of abnormal operation of the spacecraft, executing abort control laws associated with a set of control invariants containing the current state of the spacecraft, wherein at least several different abort control laws are associated with at least several different sets of control invariants, and the abort control laws are determined jointly and interdependently to generate abort control commands for the corresponding sets of control invariants that move the spacecraft while avoiding the keepaway zone for any state within the corresponding sets of control invariants.
[0022] The embodiments disclosed herein will be further described with reference to the attached drawings. The drawings shown are not necessarily to scale and, instead, are generally intended to illustrate the principles of the embodiments of this disclosure. [Brief explanation of the drawing]
[0023] [Figure 1A] This invention illustrates the motion of a spacecraft in a multi-body celestial system according to one embodiment of this disclosure. [Figure 1B] A block diagram of a controller for controlling the movement of a spacecraft during normal and abnormal operations of the spacecraft according to an embodiment of the present disclosure is shown. [Figure 1C] A union of a plurality of control invariant sets of values of the state of a spacecraft according to an embodiment of the present disclosure is shown. [Figure 2] A block diagram of a spacecraft including a controller and other components according to an embodiment of the present disclosure is shown. [Figure 3A] A keep-away set and its complement according to an embodiment of the present disclosure are shown. [Figure 3B] A probabilistic reachable set according to an embodiment of the present disclosure is shown. [Figure 3C] An inner approximation of a probabilistic reachable set according to an embodiment of the present disclosure is shown. [Figure 4] An example of a two-dimensional projection of a control invariant set and a control invariant subset according to an embodiment of the present disclosure is shown. [Figure 5] A schematic diagram for determining a control invariant set by utilizing a robust controlled invariant set according to an embodiment of the present disclosure is shown. [Figure 6A] A flowchart of a method for calculating an inner approximation of a probabilistic reachable set based on a robust controlled invariant set according to an embodiment of the present disclosure is shown. [Figure 6B] A complement of a keep-away set decomposed as a union of convex sets according to an embodiment of the present disclosure is shown. [Figure 6C] Convex half-spaces that jointly define the complement of a keep-away set according to an embodiment of the present disclosure are shown collectively. [Figure 6D] Convex half-spaces that jointly define the complement of a keep-away set according to an embodiment of the present disclosure are shown collectively. [Figure 6E] Convex half-spaces that jointly define the complement of a keep-away set according to an embodiment of the present disclosure are shown collectively. [Figure 6F] Convex half-spaces that jointly define the complement of a keep-away set according to an embodiment of the present disclosure are shown collectively. [Figure 7A] A block diagram is shown for reformulating an opportunity constraint according to one embodiment of the present disclosure, which requires that future nominal orbital states remain outside the keepaway set. [Figure 7B] A block diagram is shown for reformulating an opportunity constraint, according to one embodiment of the present disclosure, which requires that future measurements of a spacecraft remain within a control-invariant set. [Figure 8] This diagram shows a block diagram of a method for controlling the motion of a spacecraft while avoiding unauthorized entry into the keepaway zone during normal and abnormal operation of the spacecraft. [Figure 9] This is a schematic diagram showing some of the components used to implement the method and system disclosed herein. [Figure 10] This is a schematic diagram illustrating, by non-limiting examples, a computing device for implementing the method and system of this disclosure. [Modes for carrying out the invention]
[0024] Detailed explanation In the following description, for illustrative purposes and to facilitate a full understanding of the disclosure, numerous specific details are provided. However, it will be apparent to those skilled in the art that the disclosure may be implemented without these specific details. In other examples, the apparatus and methods are shown only in block diagram form to avoid obscuring the disclosure.
[0025] Where used herein and in the claims, the words “for example,” “as an example,” “etc.,” and the verbs “equip,” “have,” “include,” and their other verb forms should each be interpreted as open-ended when used with a list of one or more components or other items, meaning that the list should not be considered to exclude any other additional components or items. The word “based on” means based at least in part. Furthermore, it should be understood that the expressions and terms used herein are for illustrative purposes only and should not be considered limiting. Any headings used within this description are for convenience only and have no legal or limiting effect.
[0026] Figure 1A shows the motion of a spacecraft 101 in a multi-body celestial system according to one embodiment of the present disclosure. The spacecraft 101 may be configured to rendezvous with a target 103 by following an orbit 105. The target 103 may be a spacecraft, a celestial body, the International Space Station, or orbital debris. For illustrative purposes, target 103 is shown as the International Space Station. A keepaway zone 107 exists around target 103. The keepaway zone 107 refers to an area that the spacecraft 101 must not enter without permission. Additionally or alternatively, the keepaway zone 107 corresponds to a keepaway set, which is a collection of conditions including spacecraft position and velocity that the spacecraft 101 must keep outside of it.
[0027] The objective of some embodiments is to control the motion of the spacecraft 101 while avoiding unauthorized entry into the keepaway zone 107 during normal and abnormal operation of the spacecraft 101. As used herein, normal operation includes the spacecraft 101 moving toward the keepaway zone 107. Abnormal operation includes failure to receive permission to enter the keepaway zone 107 and failure of at least one component of the spacecraft 101, such as a thruster, or a combination thereof.
[0028] To achieve such control objectives, some embodiments provide controllers for controlling the motion of the spacecraft 101 during normal and abnormal operation of the spacecraft 101.
[0029] Figure 1B shows a block diagram of a controller 109 for controlling the motion of the spacecraft 101 during normal and abnormal operation, according to one embodiment of the present disclosure. The controller 109 includes a processor 111 and memory 113. The processor 111 may be a single-core processor, a multi-core processor, a computing cluster, or any number of other configurations. The memory 113 may include random-access memory (RAM), read-only memory (ROM), flash memory, or any other suitable memory system. Furthermore, in some embodiments, the memory 113 may be implemented using a hard drive, an optical drive, a thumb drive, an array of drives, or any combination thereof.
[0030] Some embodiments are based on the recognition that, even if access permission is denied, there are states of the spacecraft 101 near the keepaway zone 107 that could inevitably lead the spacecraft 101 into the keepaway zone 107, making it difficult to achieve the aforementioned control objective (i.e., controlling the motion of the spacecraft 101 while avoiding unauthorized entry into the keepaway zone 107 during normal and abnormal operation of the spacecraft 101). Access permission may be denied for any reason, including a total or partial failure of the spacecraft 101's propulsion. As used herein, the state of the spacecraft 101 includes the position of the spacecraft 101 and at least one or a combination of the spacecraft 101's velocity and acceleration. In addition, internal and external forces acting on the spacecraft 101 during its motion, such as inertia and gravity, may change the state of the spacecraft 101 to a specific state that could lead the spacecraft 101 into the keepaway zone 107, regardless of any efforts the spacecraft 101 may make.
[0031] Some embodiments are based on the understanding that this problem can be addressed by computing the union of multiple control-invariant sets of state values for spacecraft 101, within which the state of spacecraft 101 should be maintained.
[0032] Figure 1C shows the union of several control invariant sets of state values for the spacecraft 101 according to one embodiment of the present disclosure. Control invariant sets 115, 117, 119, and 121 form the union of several control invariant sets. In some embodiments, the union of several control invariant sets may partially enclose the keepaway zone 107. In some other embodiments, the union of several control invariant sets may completely enclose the keepaway zone 107 so as to allow the spacecraft 101 to approach the target 103. Each control invariant set is determined such that, when the state of the spacecraft 101 is within a certain control invariant set (e.g., control invariant set 121), there exists a control command generated by a nominal control law that maintains the state of the spacecraft 101 within that control invariant set (control invariant set 121) despite internal and external forces acting on the spacecraft 101.
[0033] Therefore, during normal operation of the spacecraft 101, when the state of the spacecraft 101 is within the range of any of the control invariant sets 115, 117, 119, and 121, the state of the spacecraft 101 is controlled so that the spacecraft 101 remains within the range of any of the control invariant sets 115, 117, 119, and 121 and does not enter the keepaway zone 107.
[0034] Furthermore, in order to control the motion of the spacecraft 101 in the event of abnormal operation, each control invariant set is determined such that there exists an abort control law that generates an abort control command. The abort control command safely aborts the motion of the spacecraft 101 while avoiding the keepaway zone 107. For example, if the state of the spacecraft is within control invariant set 121 and there is a thruster failure (abnormal operation), the abort law corresponding to control invariant set 121 generates an abort control command that safely aborts the motion of the spacecraft 101 while avoiding the keepaway zone 107.
[0035] Some embodiments are based on the recognition that calculating the control invariant sets 115, 117, 119, and 121 online, i.e., during real-time control of the spacecraft 101, is computationally expensive. To mitigate this problem, the control invariant sets 115, 117, 119, and 121 and their corresponding abort control laws are determined offline, i.e., in advance. Specifically, the abort control laws are determined collaboratively and interdependently to generate abort control commands for the corresponding control invariant sets. The control invariant sets and their corresponding abort laws determined offline may be stored in the memory 113 of the controller 109.
[0036] To this end, during online control of the spacecraft 101 while it is malfunctioning, the processor 111 receives the current state of the spacecraft 101. Furthermore, the processor 111 selects a set of control invariants that includes the current state of the spacecraft 101. The processor 111 executes an abort control law corresponding to the selected set of control invariants. Therefore, in different states where malfunction is detected, the controller 109 may use different predetermined abort control laws, thereby reducing the computational load and the latency of the response when malfunction is detected.
[0037] According to one embodiment, the controller 109 may be embedded in the spacecraft 101. Figure 2 shows a block diagram of the spacecraft 101 including the controller 109 and other components according to one embodiment of the present disclosure. The spacecraft 101 includes the controller 109, a set of thrusters 201, a set of sensors 203, and a circuit 205. The processor 111 may submit a sequence of control commands, i.e., control commands and abort control commands, generated by nominal control laws and abort control laws, to the set of thrusters 201. The set of thrusters 201 is configured to change the state of the spacecraft 101 according to the sequence of control commands generated by nominal control laws and abort control laws. According to one embodiment, the set of thrusters 201 includes eight thrusters, each thruster mounted in a manner aligned with the center of mass of the spacecraft 101, so that the thrusters generate forces that change the position of the spacecraft 101 without generating torque that rotates the spacecraft 101.
[0038] The sensor set 203 is configured to generate measurements indicating the state of the spacecraft 101. These measurements indicating the state of the spacecraft 101 are submitted to the processor 111. In one embodiment, the sensor set 203 may include a velocity sensor configured to generate measurements indicating the velocity of the spacecraft 101 and an accelerometer configured to generate measurements indicating the acceleration of the spacecraft 101. The circuit 205 is configured to detect abnormal operation of the spacecraft 101. In one embodiment, the circuit 205 may detect abnormal operation based on the off state of the thruster set 201. For example, one or more thrusters in the thruster set 201 may be turned off due to a failure in the spacecraft 101. Based on the off state of one or more thrusters, the circuit 205 detects abnormal operation and communicates it to the processor 111.
[0039] Some embodiments are based on the understanding that the motion of spacecraft 101 is affected by unbounded probabilistic uncertainty. Unbounded probabilistic uncertainty includes a probabilistic distribution of process noise. Process noise may define operational mismatch and / or unmodeled dynamics of the motion of spacecraft 101. In addition to process noise, unbounded probabilistic uncertainty may include a probabilistic distribution of measurement noise in the estimation of the spacecraft's state. Since the motion of spacecraft 101 is affected by unbounded probabilistic uncertainty, it is necessary to take this unbounded probabilistic uncertainty into account and prevent spacecraft 101 from illegally entering the keepaway zone 107 with a given safety likelihood.
[0040] Some embodiments are based on the understanding that it is possible to control the motion of spacecraft 101 with a given safety likelihood. For example, different methods for implementing motion under unbounded probabilistic uncertainty include opportunity constraints, particle filtering, scenario optimization, and probabilistic tube methods. To this end, it may be assumed that the motion of spacecraft 101 can be controlled with a given safety likelihood within the union of multiple control invariant sets. However, such assumption is based on the concept that each control invariant set is determined deterministically, i.e., without unbounded probabilistic uncertainty. However, such assumption can be inaccurate because if there is some uncertainty in the motion of spacecraft 101 during online control of spacecraft 101, the same or similar uncertainty exists in the calculation of the control invariant sets.
[0041] To this end, some embodiments are based on the understanding that, in order to guarantee control invariance under unbounded probabilistic uncertainty, each set of control invariants should internally approximate the state values of spacecraft 101. Furthermore, such a guarantee should be accompanied by a likelihood of unbounded probabilistic uncertainty that is greater than a given safety likelihood. This is because the final probabilistic guarantee of motion control is a function of the product of the likelihood of control invariance under unbounded probabilistic uncertainty and the likelihood of motion satisfying the constraints derived from the set of control invariants. Due to unbounded probabilistic uncertainty, all of these likelihoods are less than 1 and therefore must be considered together to guarantee a given safety likelihood.
[0042] Therefore, each control invariant set internally approximates the state of spacecraft 101 to guarantee control invariance in the state where the first likelihood of unbounded probabilistic uncertainty is greater than a predetermined safety likelihood. The nominal control law is constructed to generate control commands that maintain the state of spacecraft 101 with a second likelihood within the union of control invariant sets, the second likelihood being selected such that the product of the first likelihood and the second likelihood is greater than or equal to a predetermined safety likelihood.
[0043] The control problem described above can be expressed mathematically as follows:
[0044]
number
[0045]
number
[0046]
number
[0047]
number
[0048]
number
[0049]
number
[0050] In one embodiment, the nominal control law steers the spacecraft 101 to target 103 in the keepaway set, while ensuring that the spacecraft 101 remains within the control-invariant set and that all necessary state and input constraints are satisfied by the nominal control law. An example of such a control law solves the following optimization problem at each time step.
[0051]
number
[0052]
number
[0053] Constraint (1b) results in a collection of linear equality constraints describing the expansion of the mean and covariance matrices of the spacecraft's states and measurements. Some embodiments are based on the recognition that, due to the linearity of the spacecraft's dynamics and the Gaussian nature of the operational and measurement uncertainties, the future states and measurements of spacecraft 101 can be described as Gaussian random vectors, along with an explicit description of their mean and covariance.
[0054]
number
[0055]
number
[0056]
number
[0057]
number
[0058]
number
[0059]
number
[0060] Several embodiments employ various techniques to compute the set of control invariants for the dynamics of spacecraft 101 under unbounded probabilistic uncertainty (i.e., Gaussian uncertainty). For example, one embodiment uses a probabilistically reachable set to determine the set of control invariants. This embodiment is advantageous when the set of control invariants to remain within is convex, but may be suboptimal when the uncertainty has a probability density with thick tails. When the uncertainty has a probability density with thick tails, the estimated range of uncertainty for the computation of the set of control invariants is larger, leading to a significant decrease in the amount of the calculated set of control invariants. Since the set of control invariants restricts the states allowed for normal operation, it is desirable to have a large set of control invariants. With respect to the problem in question, the uncertainty is Gaussian uncertainty, and therefore has thin tails.
[0061] Each probabilistically reachable set used to determine the control-invariant set internally approximates the values of the spacecraft 101's states to guarantee control invariance. In one embodiment, the internal approximation of the probabilistically reachable set is obtained as the union of probabilistically reachable sets defined for each convex component of the complement of the keepout set. The internal approximation of the probabilistically reachable set is described below with reference to Figures 3A, 3B, and 3C.
[0062] Figure 3A shows a keepaway set 301 and its complement 303 according to an embodiment of the present disclosure.
[0063] Figure 3B shows a probabilistically reachable set 305 according to one embodiment of the present disclosure. The probabilistically reachable set 305 includes all states in which the controller 109 can safely keep the spacecraft 101 (i.e., keep the spacecraft 101 outside the keepaway set 301) up to a specified likelihood, despite unbounded probabilistic uncertainty. For the initial state 307, orbits 311, 313, and 315 may be probabilistic future state orbits. For the initial state 309, orbits 317, 319, and 321 may be probabilistic future state orbits. Orbits 311, 313, and 321 are not safe because the spacecraft 101 must remain outside the keepaway set 301, but orbits 315, 317, and 319 are safe. In other words, the controller 109 can keep spacecraft 101 safe starting from initial state 309 with a likelihood of 2 / 3, and can keep spacecraft 101 safe starting from initial state 307 with a likelihood of 1 / 3. As a result, set 305 (shown by the horizontal pattern filling) is a probabilistically reachable set corresponding to a safety likelihood of 2 / 3. Therefore, the probabilistically reachable set 305 includes initial state 309 but does not include initial state 307.
[0064] Figure 3C shows an internal approximation of a probabilistically reachable set according to one embodiment of the present disclosure. Set 323 (shown by vertical pattern filling) is an internal approximation of the probabilistically reachable set 305 (shown by horizontal pattern filling). Every state in set 323 is also in probabilistically reachable set 305. From Figure 3C, it can be seen that neither set 323 nor probabilistically reachable set 305 covers the entire complement of keepaway set 301 (shown in gray without pattern filling).
[0065] According to one embodiment, the internal approximation of a probabilistically reachable set may correspond to a control-invariant subset. For any state of spacecraft 101 within the control-invariant subset, there exists a control command that maintains the state of spacecraft 101 within the control-invariant subset for known or acceptable future states of the nominal orbit. An exemplary control-invariant subset is described below with reference to Figure 4.
[0066] Figure 4 shows an example of a two-dimensional projection 400 of a control invariant set 403 corresponding to a constraint set 401 according to one embodiment of the present disclosure. In one embodiment, the constraint set 401 may be a multidimensional polytope determined by a hyperplane represented by linear inequalities along multiple dimensions corresponding to constraints on the motion of the spacecraft 101. The constraint set 401 may encode safe states of the spacecraft 101. For any state of the spacecraft 101 in the control invariant subset 403, there exists a control command that maintains the state of the spacecraft 101 within the control invariant subset 403 for known or acceptable future states of the nominal orbit. For example, for any state of the spacecraft 101, such as state 415, within the control invariant subset 403 and among all possible control inputs 417-423 that the controller 109 can execute, there exists at least one control command 423 that maintains the state of the spacecraft 101 within the control invariant subset 403. On the other hand, state 405 may be achievable for a single iteration, but all control commands 407-413 that controller 109 is allowed to take during the next iteration may take the state of spacecraft 101 outside the constraint set 401.
[0067] Some embodiments are based on the understanding that a controlled invariant set can be computed by utilizing a robust uncontrolled invariant set. The robust uncontrolled invariant set determines the set of states that can maintain safety despite bounded, non-probabilistic uncertainty.
[0068] Figure 5 shows a schematic diagram of determining a controllable invariant set by utilizing a robust uncontrollable invariant set according to one embodiment of the present disclosure. Various computational algorithms can be used to compute the robust uncontrollable invariant set. However, these algorithms are not directly applicable to problems involving the presence of unbounded probabilistic uncertainty, including the probabilistic distribution of process and / or measurement noise. This is because the computational algorithms are applicable to problems involving bounded deterministic uncertainty.
[0069]
number
[0070] Figure 6A shows a block diagram of a method 600 for calculating an internal approximation of a probabilistically reachable set based on a robust, controllable, invariant set, according to one embodiment of the present disclosure. In block 601, the method 600 includes decomposing the complement of a keepaway set (e.g., the complement 303 of the keepaway set 301, as shown in Figure 3A) as a union of convex sets.
[0071] Figure 6B shows the complement of the keepaway set 301, which has been decomposed as a union of convex sets, according to one embodiment of the present disclosure. The convex sets 607-621 form a union of convex sets. Specifically, the keepaway set 301 is a polytope, and the complement of the keepaway set 301 can be represented as a union of halfspaces. Each of these halfspaces is convex.
[0072] Figures 6C to 6F collectively show the convex halfspaces that together define the complement of the keepaway set 301. Sets 623, 627, 631, and 635 are copies of the keepaway set 301. Set 625 contains sets 607, 609, and 611, and set 629 contains sets 611, 613, and 615. Set 633 contains sets 615, 617, and 619, and set 637 contains sets 619, 621, and 607. The convex sets 607 to 621 are called the keepaway complement components.
[0073]
number
[0074]
number
[0075] In block 605, method 600 further includes the step of computing the union of robust controlled invariant sets to obtain one probabilistically reachable internal approximation for the complement of the keepaway set, for each exponent i. The internal approximation guarantees control invariance with a first likelihood of unbounded probabilistic uncertainty over a horizon of M time steps. In other words, in the case of abnormal behavior, there exists an abort control law that can steer spacecraft 101 away from the keepaway set with a first likelihood over M time steps into the future.
[0076] In one embodiment, the robust control invariant set and the corresponding abort control law are determined jointly and interdependently using a single computation of the robust control invariant set. The computation of the robust control invariant set automatically generates, for each state, a set of control actions that maintain spacecraft 101 within the robust control invariant set. The set of control actions is characterized by spacecraft dynamics, control constraints, and the robust control set. Thus, the abort control law involves selecting a control action from the set of control actions at each time step.
[0077]
number
[0078]
number
[0079] Furthermore, the nominal control law applied during normal operation steers the spacecraft 101 to target 103 in the keepaway set, while ensuring that the spacecraft 101 remains within the control-invariant set and that all necessary state and input constraints are satisfied by the nominal control law. An example of such a nominal control law solves the optimization problem given by equation (1). In one embodiment, the nominal control law is designed using a model predictive controller (MPC). The MPC is based on iterative finite horizon optimization of a model of the dynamics of the spacecraft 101, a set of objectives for the motion of the spacecraft 101, and constraints on the spacecraft propulsion system and motion. The MPC can predict future events to take appropriate control actions. According to an embodiment, the MPC may estimate a sequence of control steps over the predicted horizon acting on the spacecraft 101 under the influence of internal and external forces.
[0080]
number
[0081] Some embodiments are based on the recognition that implementing opportunity constraints (1c) and (1d) can be cumbersome. Therefore, some embodiments aim to provide conservative but manageable implementations of opportunity constraints (1c) and (1d). Some embodiments are based on the recognition that, in order to conservatively implement opportunity constraints (1c) and (1d), opportunity constraints (1c) and (1d) can be reformatted as a collection of mixed integer linear constraints that conservatively implement opportunity constraints (1c) and (1d). In some embodiments, opportunity constraints (1c) and (1d) can be reformatted as a collection of mixed integer linear constraints based on Boolean inequalities, quantile reformatting, and disjunctive programming. The reformattings of opportunity constraints (1c) and (1d) are described below with reference to Figures 7A and 7B, respectively.
[0082]
number
[0083] In block 703, a probabilistic joint chance constraint is obtained by encoding the desired behavior. The probabilistic joint chance constraint may be given as follows:
[0084]
number
[0085] Stochastic coupling opportunity constraints limit the probability of undesirable behavior to a small probability. In block 705, the individual opportunity constraints for arbitrary choices are obtained by utilizing simple probability theory and the quantile reformulation of Gaussian opportunity constraints. The individual opportunity constraints for arbitrary choices may also be given as follows:
[0086]
number
[0087] In block 707, mixed-integer linear constraints are obtained based on constraint reinforcement and tangent programming. The mixed-integer linear constraints may be given as follows:
[0088]
number
[0089]
number
[0090] Figure 7B shows a block diagram for reformulating the opportunity constraint (1d) according to one embodiment of the present disclosure, which requires that future measurements of spacecraft 101 remain within a controllable invariant set. In block 709, the desired behavior of future measurements of spacecraft 101 to remain within a controllable invariant set is given as a deterministic inequality constraint for all t, as follows:
[0091]
number
[0092] In block 711, a probabilistic coupling opportunity constraint is obtained by encoding the desired behavior. The probabilistic coupling opportunity constraint may be given as follows:
[0093]
number
[0094] In Block 713, individual opportunity constraints for arbitrary choices can be obtained by utilizing simple probability theory and the quantile reformulation of Gaussian opportunity constraints. These individual opportunity constraints may also be given as follows:
[0095]
number
[0096] In block 715, the mixed-integer linear constraints are obtained based on constraint strengthening and tangent programming. The mixed-integer linear constraints may be given as follows:
[0097]
number
[0098]
number
[0099] The use of mixed-integer linear constraints (4) and (5) in optimization problem (1) gives optimization problem (1) a mixed-integer program due to the presence of binary variables. In the case of a real-time implementation, the feasible values for the binary variables may be pre-assigned to obtain a convex quadratic program.
[0100] Figure 8 shows a block diagram of method 800 for controlling the motion of spacecraft 101 while avoiding unauthorized entry into the keepaway zone 107 during normal and abnormal operation of spacecraft 101.
[0101] In block 801, method 800 includes receiving the current state of spacecraft 101. In block 803, method 800 includes selecting a control-invariant set containing the current state of spacecraft 101.
[0102] In block 805, the method includes determining whether an abnormal operation has been detected. If an abnormal operation is detected, in block 807, the method 800 includes executing an abort control law associated with a selected set of control invariants. The abort control law generates an abort control command that moves the spacecraft 101 while avoiding the keepaway zone 107.
[0103] If no abnormal operation is detected, in block 809, method 800 includes executing nominal control laws. The nominal control laws generate control commands that maintain the state of the spacecraft 101 within a set of control invariants, despite internal and external forces acting on the spacecraft 101.
[0104] Figure 9 is a schematic diagram showing some components used to implement the methods and systems of this disclosure. For example, the computer 900 may be adapted to control the motion of a spacecraft 101 in a multi-body celestial system while avoiding unauthorized entry into the keepaway zone 107 during normal and abnormal operation of the spacecraft 101. The CPU or processor 901 may be connected to a memory 905, an input / output device 907, and a communication interface 909 via a bus system 903. A storage device 911, a control interface 913, a display interface 915, and an external interface 917 may also be connected to the bus system 903.
[0105] The external interface 917 can be connected to the extended memory 919, vehicle parameters 921 (i.e., spacecraft specifications, thruster specifications, size, weight, etc.), initial orbit data 923 (i.e., parameters including time, date, altitude, inclination, eccentricity, etc.), target orbit data 925, and other orbit data 927 (i.e., unique orbit data). The bus system 903 can also connect to the control interface 929, the output interface 931, the receiver 933, and the transmitter 935. Furthermore, the bus system 903 can connect the GPS receiver module 937 to the GPS 939. The computer 900 includes an orbit maintenance module 941. The orbit maintenance module 941 may output thruster commands 943. The orbit maintenance module 941 includes a transition orbit generation unit 945, a feedback gain module 947, a feedback controller 949, and a thruster command generation unit 951.
[0106] The computer 900 may be a server or a desktop, laptop, mobile or other computer device or system having one or more processors 901. The processor 901 may be a central processing unit adapted to access code in the form of a transition path generation unit 945 within the memory 905 or storage device 911 (or within extended memory 919) of the computer 900. Depending on the aspects relating to the systems and methods of this disclosure, external storage devices may be contemplated, as further required depending on the specific design of the intended hardware and purpose implementation. For example, the computer 900 may be used to implement steps of the systems and methods in which the memory 905 and / or storage device 911 can store data.
[0107] The data stored in memory 905 may include executable module data, vehicle data, and historical spatial data. For example, vehicle data may include the specifications, dimensions, weight, and performance data under varying conditions, including gravity, as well as other perturbations, i.e., the complex motion of a mass body subject to forces other than the gravitational pull of a single other mass body in space.
[0108] Furthermore, vehicle data may include data relating to aspects of vehicle dynamics associated with one or more of the following multivariables: (1) anomalous orbital characteristics of a celestial body, i.e., natural objects located outside the Earth's atmosphere, such as the Moon, Sun, asteroids, planets, or stars; (2) anomalous orbital motion of a celestial body; (3) anomalous near-orbits of a celestial body around another celestial body; and (4) other known perturbations. Spatial data may include data relating to celestial bodies, past missions to celestial bodies, and any other data relating to space, spacecraft, and the planning of orbital designs for other celestial bodies in space. For example, spatial data may include data about a celestial body's moon, such as characteristics of the celestial body that can be taken into consideration when developing orbital designs from an initial celestial body orbit to a similar target celestial body orbit.
[0109] The processor 901 of computer 900 may consist of two or more processors, depending on the specific application. For example, some steps may require a separate processor to ensure a specific processing time or processing speed associated with the systems and methods of this disclosure. The receiver 933 or input interface may receive spatial data, which may be the most recent spatial data acquired from either the Earth Mission Control Center or a sensor associated with the spacecraft, or any other location, after stored historical spatial data stored in memory 905. The receiver 933 and transmitter 935 may provide a radio location for receiving data and transmitting it, for example, to the Earth Mission Control Center or any other destination. A GPS receiver module 937 connected to GPS 939 may be used in aspects related to navigation. Computer 900 may further include external devices, control interfaces, displays, sensors, machines, etc., intended for use in relation to the systems and methods of this disclosure.
[0110] Figure 10 is a schematic diagram illustrating, by non-limiting examples, a computing device for carrying out the method and system of the present disclosure. The computing device 1000 may include a power supply 1001, a processor 1003, memory 1005, and storage device 1007, all connected to bus 1009. Furthermore, a high-speed interface 1011, a low-speed interface 1013, a high-speed expansion port 1015, and a low-speed connection port 1017 may be connected to bus 1009. In addition, a low-speed expansion port 1019 is connected to bus 1009. Furthermore, an input interface 1021 may be connected to an external receiver 1023 and an output interface 1025 via bus 1009. Receiver 1027 may be connected to an external transmitter 1029 and a transmitter 1031 via bus 1009. Also, an external memory 1033, an external sensor 1035, a machine 1037, and an environment 1039 may be connected to bus 1009. Furthermore, one or more external input / output devices 1041 can be connected to bus 1009. A network interface controller (NIC) 1043 can be adapted to connect to network 1045 via bus 1009, and data or other data can be rendered on, among other things, third-party display devices, third-party imaging devices, and / or third-party printing devices outside of the computing device 1000.
[0111] Memory 1005 can store instructions executable by computing device 1000, historical data, and any data available by the methods and systems of this disclosure. Memory 1005 may include random access memory (RAM), read-only memory (ROM), flash memory, or any other suitable memory system. Memory 1005 may be a volatile memory unit and / or a non-volatile memory unit. Memory 1005 may also be another form of computer-readable medium, such as a magnetic disk or an optical disk.
[0112] The storage device 1007 may be adapted to store supplemental data and / or software modules used by the computing device 1000. For example, the storage device 1007 may store historical data and other related data as described above in relation to this disclosure. In addition, or alternatively, the storage device 1007 may store historical data such as the data referred to above in relation to this disclosure. The storage device 1007 may include a hard drive, an optical drive, a thumb drive, an array of drives, or any combination thereof. Furthermore, the storage device 1007 may include an array of devices including computer-readable media such as floppy disk devices, hard disk devices, optical disk devices, or tape devices, flash memory or other similar solid memory devices, or devices in a storage area network or other configuration. Instructions may be stored on the information carrier. When an instruction is executed by one or more processing units (e.g., processor 1003), it performs one or more methods, such as those described above.
[0113] The computing device 1000 may optionally be linked via bus 1009 to a display interface or user interface (HMI) 1047 adapted to connect the computing device 1000 to a display device 1049 and a keyboard 1051, the display device 1049 may include, among other things, a computer monitor, a camera, a television, a projector, or a mobile device. In some realizations, the computing device 1000 may also include a printer interface for connecting to a printing device, the printing device may include, among other things, a liquid inkjet printer, a solid ink printer, a large-scale commercial printer, a thermal printer, a UV printer, or a dye sublimation printer.
[0114] The high-speed interface 1011 manages bandwidth-intensive operations for the computing device 1000, and the low-speed interface 1013 manages less bandwidth-intensive operations. Such function assignments are merely examples. In some implementations, the high-speed interface 1011 may be coupled to memory 1005, a user interface (HMI) 1047, a keyboard 1051 and a display 1049 (e.g., via a graphics processor or accelerator), and a high-speed expansion port 1015 that can accept various expansion cards via bus 1009. In some implementations, the low-speed interface 1013 is coupled to storage device 1007 and the low-speed expansion port 1017 via bus 1009. The low-speed expansion port 1017, which may include various communication ports (e.g., USB, Bluetooth®, Ethernet®, Wireless Ethernet®), may be coupled to one or more input / output devices 1041. The computing device 1000 may be connected to a server 1053 and a rack server 1055. The computing device 1000 may be implemented in several different forms. For example, the computing device 1000 may be implemented as part of a rack server 1055.
[0115] The following description provides only exemplary embodiments and is not intended to limit the scope, applicability, or configuration of the disclosure. Rather, the following description of exemplary embodiments provides a practicable description for realizing one or more exemplary embodiments. The intent is to describe various modifications that may be made to the function and configuration of the elements without departing from the spirit and scope of the subject matter disclosed as described in the claims.
[0116] The following description provides specific details for a complete understanding of the embodiments. However, it will be understood by those skilled in the art that embodiments may be carried out without these specific details. For example, systems, processes, and other elements in the disclosed subject matter may be shown as components in the form of block diagrams so as not to obscure the embodiments with unnecessary details. In other examples, well-known processes, structures, and techniques may be shown without unnecessary details to avoid obscuring the embodiments. Furthermore, similar reference numbers and names in different drawings refer to similar elements.
[0117] Furthermore, individual embodiments may be described as processes shown as flowcharts, flow diagrams, data flow diagrams, structural diagrams, or block diagrams. While flowcharts can describe operations as sequential processes, many operations can be performed in parallel or simultaneously. In addition, the order of operations may be rearranged. A process may terminate when its operations are complete, but it may have additional steps that are not discussed or included in the diagrams. Moreover, not all operations in any particular process described may occur in all embodiments. A process may correspond to a method, function, procedure, subroutine, subprogram, etc. When a process corresponds to a function, the termination of the function may correspond to the function's return to the calling function or the main function.
[0118] Furthermore, embodiments of the disclosed subject matter may be implemented at least partially manually or automatically. Manual or automatic implementations may be performed, or at least assisted, through the use of a machine, hardware, software, firmware, middleware, microcode, hardware description language, or any combination thereof. When implemented in software, firmware, middleware, or microcode, program code or code segments for performing the required tasks may be stored in a machine-readable medium. The required tasks may be performed by a processor.
[0119] The various methods or processes outlined herein may be coded as software executable on one or more processors using any one of various operating systems or platforms. In addition, such software may be written using any of several preferred programming languages and / or programming or scripting tools, and may be compiled as executable machine language code or intermediate code that runs on a framework or virtual machine. Typically, the functionality of program modules may be combined or distributed as desired in various embodiments.
[0120] Embodiments of this disclosure may be embodied as an example provided. The actions performed as part of the method may be ordered in any preferred manner. Thus, embodiments may be constructed in which the actions are performed in a different order than exemplary, which may include performing several actions simultaneously that are shown as sequential actions in the exemplary embodiments.
[0121] While this disclosure has been described with reference to certain preferred embodiments, it should be understood that various other adaptations and modifications can be made within the spirit and scope of this disclosure. Therefore, it is the claims aspect to encompass all variations and modifications that fall within the true spirit and scope of this disclosure. [Explanation of Symbols]
[0122] 101 Spacecraft, 103 Target, 105 Orbit, 107 Keepaway Zone, 109 Controller, 111 Processor, 113 Memory.
Claims
1. A controller for controlling the motion of a spacecraft in a multi-body celestial system, while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation of the spacecraft, wherein normal operation includes moving toward a target in the keepaway zone, and abnormal operation includes one or a combination of failure to receive permission to enter the keepaway zone and failure of at least one component of the spacecraft, wherein the controller comprises at least one processor and a memory storing instructions, and when an instruction is executed by the at least one processor, the controller, During the normal operation of the spacecraft, a nominal control law is executed to maintain the state of the spacecraft within a union of multiple control invariant sets of state values of the spacecraft that partially or completely enclose the keepaway zone, wherein the state of the spacecraft includes the position of the spacecraft and at least one or a combination of the velocity and acceleration of the spacecraft, and each of the multiple control invariant sets is determined to execute a control command generated by the nominal control law that maintains the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft when the state of the spacecraft is within the control invariant set, wherein the nominal control law solves an optimization problem at each time step that minimizes the sum of the squared distances of the spacecraft over time to the keepaway zone and the amount of energy consumed by an open-loop control sequence that is subject to linear equality constraints describing the state of the spacecraft and the expansion of the mean and covariance matrix of the measurements, and the instruction, when executed by the at least one processor, further to the controller, Upon detecting the abnormal operation of the spacecraft, an abort control law associated with a set of control invariants including the current state of the spacecraft is executed, and at least several different abort control laws are associated with at least several different sets of control invariants, and the abort control laws are jointly and interdependently determined to execute abort control commands for the corresponding sets of control invariants, causing the spacecraft to move while avoiding the keepaway zone for any state within the corresponding sets of control invariants. The aforementioned abort control command is determined offline in advance and stored in memory by the controller.
2. A spacecraft for travel in a multi-body celestial system, The controller according to claim 1, A set of thrusters configured to change the state of a spacecraft according to a sequence of control commands generated by the aforementioned nominal control law and the aforementioned abort control law, A set of sensors configured to generate measurements indicating the state of the spacecraft, A spacecraft comprising a circuit configured to detect the abnormal operation of the spacecraft.
3. The controller according to claim 1, wherein the motion of the spacecraft is subject to unbounded probabilistic uncertainty, while the unauthorized entry of the spacecraft into the keepaway zone is avoided with a predetermined safety likelihood, each of the control invariant sets internally approximates the value of the state of the spacecraft to guarantee control invariance such that the first likelihood of the unbounded probabilistic uncertainty is greater than the predetermined safety likelihood, and the nominal control law is configured to generate control commands that maintain the state of the spacecraft with a second likelihood within the union of the plurality of control invariant sets, the second likelihood being selected such that the product of the first likelihood and the second likelihood is greater than or equal to the predetermined safety likelihood.
4. The controller according to claim 3, wherein each of the control invariant sets is a probabilistically reachable set determined by the first likelihood of the unbounded probabilistic uncertainty that can occur.
5. The controller according to claim 3, wherein each of the control invariant sets is a robust control invariant set determined with respect to the nominal control law together with bounded unprobabilistic uncertainty corresponding to the first likelihood on the unbounded probabilistic uncertainty.
6. The controller according to claim 5, wherein the nominal control law is a model predictive control (MPC) using a model of the dynamics of the spacecraft with the unbounded probabilistic uncertainty, and the nominal control law, together with other constraints including one or a combination of operating constraints, ensures that the spacecraft remains within the robust controlled invariant set with a second likelihood, and the nominal orbit approaches the keepaway set without entering the keepaway set.
7. The controller according to claim 6, wherein the stochastic distribution of process noise specifies one or a combination of the operational mismatch of the spacecraft thrusters and the unmodeled dynamics of the spacecraft's motion.
8. The controller according to claim 6, wherein the unbounded probabilistic uncertainty includes a probabilistic distribution of measurement noise for estimating the state of the spacecraft, and the MPC estimates a sequence of control steps over a predictive horizon acting on the spacecraft, such that the state has bounded measurement noise having a range of values, the range of values being restricted to have a likelihood for the probabilistic distribution of the measurement noise greater than the first likelihood.
9. The controller according to claim 8, wherein the state of the spacecraft is determined by a stochastic filter that is subject to the measurement noise.
10. The controller according to claim 9, wherein the stochastic filter includes one or a combination of a Kalman filter and a particle filter.
11. The controller according to claim 3, wherein the constraints on maintaining the state of the spacecraft within the union of the plurality of control invariant sets require their satisfaction with the second likelihood.
12. The controller according to claim 11, wherein the aforementioned constraints include opportunity constraints.
13. The controller according to claim 11, wherein the constraints include one or a combination of opportunity constraints requiring the state of the spacecraft to be outside the keepaway zone, operational constraints, and opportunity constraints requiring the measurement of the spacecraft to be within the plurality of control invariant sets.
14. A method for controlling the motion of a spacecraft in a multi-body celestial system while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation, wherein the normal operation includes moving toward the keepaway zone, and the abnormal operation includes one or a combination of failing to receive permission to enter the keepaway zone and / or failure of at least one component of the spacecraft, and the method is During the normal operation of the spacecraft, the method includes executing a nominal control law that maintains the state of the spacecraft within a union of multiple control invariant sets of state values of the spacecraft that partially or completely enclose the keepaway zone, wherein the state of the spacecraft includes the position of the spacecraft and at least one or a combination of the velocity and acceleration of the spacecraft, and each of the multiple control invariant sets is determined to execute a control command generated by the nominal control law that maintains the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft, while the state of the spacecraft is within the control invariant set, wherein the nominal control law solves an optimization problem at each time step that minimizes the sum of the squared distances of the spacecraft over time to the keepaway zone and the amount of energy consumed by an open-loop control sequence that is subject to linear equality constraints describing the state of the spacecraft and the expansion of the mean and covariance matrix of the measured values of the spacecraft, and the method further, Upon detecting the abnormal operation of the spacecraft, the following actions are taken: an abort control law associated with a set of control invariants including the current state of the spacecraft is executed, wherein at least several different abort control laws are associated with at least several different sets of control invariants, and the abort control laws are determined jointly and interdependently to execute abort control commands for the corresponding sets of control invariants, causing the spacecraft to move while avoiding the keepaway zone for any state within the corresponding sets of control invariants. The abort control command is determined offline in advance and stored in memory.
15. The method according to claim 14, wherein the motion of the spacecraft is subject to unbounded probabilistic uncertainty, while the unauthorized entry of the spacecraft into the keepaway zone is avoided with a predetermined safety likelihood, each of the control invariant sets internally approximates the value of the state of the spacecraft to guarantee control invariance such that the first likelihood of the unbounded probabilistic uncertainty is greater than the predetermined safety likelihood, the nominal control law is configured to generate a control command that maintains the state of the spacecraft with a second likelihood in the union of the plurality of control invariant sets, the second likelihood is selected such that the product of the first likelihood and the second likelihood is greater than or equal to the predetermined safety likelihood.
16. The method according to claim 15, wherein each of the control invariant sets is a probabilistically reachable set determined by the first likelihood of the unbounded probabilistic uncertainty for possible abnormal behavior.
17. The method according to claim 15, wherein each of the control invariant sets is a robust control invariant set determined with respect to the nominal control law together with the bounded unprobabilistic uncertainty corresponding to the first likelihood on the unbounded probabilistic uncertainty.
18. The method according to claim 16, wherein the unbounded probabilistic uncertainty includes a probabilistic distribution of process noise.
19. A non-temporary computer-readable storage medium embodying a processor-executable program for performing a method for controlling the motion of a spacecraft in a multi-body celestial system, while avoiding unauthorized entry into a keepaway zone during normal and abnormal operation, wherein the normal operation includes moving toward the keepaway zone, and the abnormal operation includes one or a combination of failing to receive permission to enter the keepaway zone and failure of at least one component of the spacecraft, and the method is During the normal operation of the spacecraft, the method includes executing a nominal control law that maintains the state of the spacecraft within a union of multiple control invariant sets of state values of the spacecraft that partially or completely enclose the keepaway zone, wherein the state of the spacecraft includes the position of the spacecraft and at least one or a combination of the velocity and acceleration of the spacecraft, and each of the multiple control invariant sets is determined to execute a control command generated by the nominal control law that maintains the state of the spacecraft within the control invariant set despite internal and external forces acting on the spacecraft, while the state of the spacecraft is within the control invariant set, wherein the nominal control law solves an optimization problem at each time step that minimizes the sum of the squared distances of the spacecraft over time to the keepaway zone and the amount of energy consumed by an open-loop control sequence that is subject to linear equality constraints describing the state of the spacecraft and the expansion of the mean and covariance matrix of the measured values of the spacecraft, and the method further, Upon detecting the abnormal operation of the spacecraft, the following actions are taken: an abort control law associated with a set of control invariants including the current state of the spacecraft is executed, wherein at least several different abort control laws are associated with at least several different sets of control invariants, and the abort control laws are determined jointly and interdependently to execute abort control commands for the corresponding sets of control invariants, causing the spacecraft to move while avoiding the keepaway zone for any state within the corresponding sets of control invariants. The abort control command is a non-temporary computer-readable storage medium that is determined offline in advance and stored in memory.
Citation Information
Patent Citations
Automatic collision avoiding device
JP1997286400A
Original position method and system for autonomous failure detection, isolation, repair
JP1998329799A
Abort-safe vehicle rendezvous in the event of partial control failure.
JP2023526875A
JPP7233609B