Thermal management and method for spacecraft system

WO2026163149A1PCT designated stage Publication Date: 2026-08-06QUANTUM SPACE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
QUANTUM SPACE LLC
Filing Date
2026-01-30
Publication Date
2026-08-06

Smart Images

  • Figure IB2026050906_06082026_PF_FP_ABST
    Figure IB2026050906_06082026_PF_FP_ABST
Patent Text Reader

Abstract

A spacecraft thermal management system is disclosed for controlling waste heat generated by spacecraft subsystems, including propulsion electronics, pumps, controllers, and related components. The system uses thermal transport elements to conduct waste heat from heat-generating components thermally tolerant structures having substantial thermal mass. The thermally tolerant structures operate as a transient thermal sink during propulsion events to limit peak component temperatures and reduce reliance on oversized radiators or active cooling hardware. The thermal management system further includes multilayer insulation to minimize environmental heat exchange and one or more radiative surfaces configured to reject accumulated heat to space. In certain embodiments, electrical heaters controlled by redundant thermostats and / or software to maintain components above minimum allowable temperatures during cold conditions. The disclosed thermal architecture supports both ground testing and on-orbit operation without reconfiguration and provides a low-mass, reliable solution for managing concentrated and transient spacecraft heat loads.
Need to check novelty before this filing date? Find Prior Art

Description

Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669THERMAL MANAGEMENT AND METHOD FOR SPACECRAFT SYSTEM CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims benefit of priority of U. S. Provisional Patent Application No. 63 / 751,459, entitled “PROPULSION SYSTEM AND TANK, THERMAL MANAGEMENT AND CONTROLLER FOR PROPULSION SYSTEM,” filed January 30, 2025. The entire contents and disclosures of this patent application is incorporated herein by reference in their entirety.BACKGROUNDField of the Invention

[0002] The present disclosure relates generally to thermal management systems for spacecraft, and more particularly to integrated thermal control architectures and methods for managing waste heat generated by spacecraft subsystems, including, for examples, propulsion, power electronics, avionics, RF communications, attitude control subsystem, payloads, and externally mounted modules, under both ground-test and on-orbit operating conditions.Background of the Invention

[0003] Spacecraft thermal control systems (TCS) are generally designed to maintain spacecraft subsystems within allowable operational temperature limits across a wide range of environmental conditions, including eclipse, sun-pointing attitudes, and transient operational events. Conventional spacecraft TCS implementations typically rely on a combination of (i) radiators configured to reject waste heat to space, (ii) insulators used to minimize environmental heat losses and gains, and (iii) electrical heaters used to maintain components above minimum allowable temperatures during cold conditions.

[0004] In many spacecraft architectures, the thermal design is further complicated by the presence of subsystems mounted externally to the primary structure, such as rendezvous / proximity operations (RPO) modules and communications modules, which may be thermally isolated from the primary structure and therefore require localized thermal control implementations that nonetheless must remain compatible with the overall spacecraft thermal design philosophy.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0005] While these conventional approaches are generally effective for steady-state heat loads, they can become increasingly challenged when a spacecraft includes subsystems that generate high transient power dissipation, particularly during mission phases involving propulsion system operation. In such cases, the propulsion subsystem may generate significant waste heat, including from propulsion electronics and high-power components mounted on a propulsion deck.

[0006] In parallel, pump-fed propulsion architectures and their associated power electronics can introduce additional thermal design constraints because electrically driven pumps and controllers may create concentrated heat sources that must be accommodated without exceeding component maximum temperature limits or imposing excessive mass, volume, or power penalties on the spacecraft.

[0007] A common response to elevated or transient heat loads is to increase radiator area, increase conductive coupling to radiative surfaces, or increase heater / thermal hardware margins. However, such measures can materially impact spacecraft mass, packaging, and integration complexity, and may be inefficient where heat loads are intermittent rather than continuous. Moreover, thermal control architectures that over-rely on radiative rejection can be constrained by spacecraft attitudes and solar exposure. Radiator performance may also be influenced by coating selection intended to balance thermal performance with resistance to environmental degradation, further complicating design tradeoffs.

[0008] Thermal control system complexity can also increase due to reliability-driven redundancy requirements. For example, heater circuits may be implemented as redundant circuits controlled by mechanical thermostats, including thermostat configurations intended to reduce the risk of over-temperature conditions in the event of a single-point thermostat failure.

[0009] Similarly, MLI implementations may vary' across spacecraft zones (e.g., primary / structure, harnessing, propellant lines, and high-temperature areas), with differing layer counts and materials selected to address distinct thermal environments and integration constraints.

[0010] These considerations become especially acute for spacecraft in which it is desirable to manage a substantial propulsion-associated heat load without incurring disproportionate radiator sizing, thermal hardware mass, or heater power draw. In particular, spacecraft propulsion subsystems may benefit from thermal architectures that can redistribute or buffer transient waste heat using thermally tolerant structures having substantial thermal mass. For example, propellant tanks (particularly tanks formed of conductive materials) can present anAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669attractive heat sink for absorbing propulsion-generated waste heat during propulsion operations, provided the heat can be transported efficiently from heat-generating components to the tank and managed in a manner compatible with both flight and ground test configurations. Other targets for waste heat may include the remainder of spacecraft bus subsystems. Similarly, waste heat from selected spacecraft subsystems can be rejected from them into propellant, which can then in turn, transport waste heat to warm the propellant(s).

[0011] Accordingly, there remains a need for improved spacecraft thermal management architectures and methods that can accommodate concentrated and transient subsystem heat loads, particularly those associated with propulsion operation, while maintaining subsystem temperatures within allowable limits, reducing heater power consumption, minimizing radiator oversizing, and supporting practical integration and testability.SUMMARY

[0012] According to first broad aspect, the present disclosure provides a thermal management system for a spacecraft, comprising: one or more heat-generating components of the spacecraft that dissipate heat during a propulsion event; one or more components of the spacecraft having heat capacity to absorb waste heat from propulsion system operations; one or more thermal transport elements thermally coupled to the one or more components of the spacecraft having heat capacity to absorb waste heat; and thermal insulation disposed about at least a portion of the spacecraft, wherein the thermal management system is configured to transfer waste heat generated by the one or more heat-generating components to the one or more components of the spacecraft having heat capacity to absorb waste heat during propulsion operation to maintain spacecraft components within allowable operating temperature limits.

[0013] According to a second broad aspect, the present disclosure provides a method of managing thermal energy in a spacecraft, comprising: generating waste heat from one or more components of the spacecraft that have heat dissipation during a propulsion event; transporting the waste heat from one or more propulsion components to another one or more components of the spacecraft having heat capacity to absorb waste heat from propulsion system operations using one or more thermal transport elements; and thermally insulating the spacecraft to reduce environmental heat exchange during the propulsion event.

[0014] According to a third broad aspect, the present disclosure provides a spacecraft system, comprising: one or more heat-generating components of the spacecraft system thatAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669dissipate heat during a propulsion event; a thermal management subsystem including thermal transport elements coupling the one or more heat-generating components to one or more components of the spacecraft system having heat capacity to absorb waste heat from propulsion system operations; and a spacecraft controller configured to monitor temperature telemetry and coordinate heater operation, wherein the thermal management subsystem absorbs propulsion-generated waste heat in the one or more components of the spacecraft system having heat capacity to absorb waste heat while the spacecraft controller maintains system temperatures within predetermined limits.

[0015] According to a fourth broad aspect, the present disclosure provides a non-transitory computer-readable medium storing instructions that, when executed by a spacecraft controller, cause the controller to: monitor temperature data from one or more components of a spacecraft that have heat dissipation during a propulsion event; coordinate operation of electrical heaters based on the monitored temperature data; and manage spacecraft thermal conditions in cooperation with a thermal management architecture that transfers propulsion-generated waste heat to one or more components of the spacecraft having heat capacity to absorb waste heat from a propulsion system operation.BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings, which are incorporated herein and constitute part of this specification, illustrate exemplary embodiments of the invention, and, together with the general description given above and the detailed description given below, serve to explain the features of the invention.

[0017] FIG. I illustrates a propulsion block diagram according to one embodiment of the present disclosure.

[0018] FIG. 2 illustrates a thermal block diagram according to one embodiment of the present disclosure.

[0019] FIG. 3 illustrates thermal analysis results according to one embodiment of the present disclosure.

[0020] FIG. 4 illustrates a flowchart for a built-in test according to one embodiment of the present disclosure.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0021] FIG. 5 illustrates a flowchart for a boot-strap sequence according to one embodiment of the present disclosure.

[0022] FIG. 6 illustrates a flowchart for a shut-down sequence according to one embodiment of the present disclosure.

[0023] FIG. 7 illustrates an electrical block diagram of the distributed propulsion system according to one embodiment of the present disclosure.

[0024] FIG. 8 illustrates a finite element analysis result for an exemplary tank assembly according to one embodiment of the present disclosure.

[0025] FIG. 9 illustrates a side view of an exemplary tank assembly according to one embodiment of the present disclosure.

[0026] FIG. 10 illustrates multiple components of custom weld tooling according to one embodiment of the present disclosure.

[0027] FIG. 11 illustrates a flowchart for a hibernation sequence according to one embodiment of the present disclosure.

[0028] FIG. 12 graphically illustrates mission simulation ODY ECI position, cOBC test values vs. SOLIS truth values according to one embodiment of the present disclosure.

[0029] FIG. 13 graphically illustrates mission simulation ODY ECI velocity, cOBC test values vs. SOUS truth values according to one embodiment of the present disclosure.

[0030] FIG. 14 is an overview of the electrical connections within an exemplary? propulsion system according to one embodiment of the present disclosure.

[0031] FIG. 15 illustrates the physical connections between the flight and ground avionics systems according to one embodiment of the present disclosure.

[0032] FIG. 16 provides an overview of the cOBC / MAX connections according to one embodiment of the present disclosure.

[0033] FIG. 17 illustrates a propulsion controller block diagram according to one embodiment of the present disclosure.

[0034] FIG. 18 illustrates flight and ground software connections according to one embodiment of the present disclosure.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0035] FIG. 19 represents pressure data recorded from propulsion FlatSat telemetry according to one embodiment of the present disclosure.

[0036] FIG. 20 illustrates a diagram of an exemplary propulsion FlatSat fluid system according to one embodiment of the present disclosure.

[0037] FIG. 21 graphically illustrates pump speed and outlet pressure vs time according to one embodiment of the present disclosure.

[0038] FIG. 22 graphically illustrates measured pump speed (filtered) vs time according to one embodiment of the present disclosure.

[0039] FIG. 23 graphically illustrates measured pump speed rampup according to one embodiment of the present disclosure.

[0040] FIG. 24 graphically illustrates pump speed command dropouts according to one embodiment of the present disclosure.

[0041] FIG. 25 graphically illustrates a pump speed telem sample rate histogram (left) and a pump speed telem filtered sample rate histogram (right) according to one embodiment of the present disclosure.

[0042] FIG. 26 illustrates a nested feedback loops from a pump motor driver to a propulsion controller according to one embodiment of the present disclosure.DETAILED DESCRIPTION OF THE INVENTIONDefinitions

[0043] Where the definition of terms departs from the commonly used meaning of the term, applicant intends to utilize the definitions provided below, unless specifically indicated.

[0044] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of any subject matter claimed. In this application, the use of the singular includes the plural unless specifically stated otherwise. It must be noted that, as used in the specification and the appended claims, the singular forms “a,” “an” and “the” include plural referents unless the context clearly dictates otherwise. In this application, the use of “or” means “and / or” unless stated otherwise. Furthermore, use of the term “including” as well as other forms, such as “include”, “includes,” and “included,” is not limiting.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0045] For purposes of the present disclosure, the term “comprising”, the term “having”, the term “including,” and variations of these words are intended to be open-ended and mean that there may be additional elements other than the listed elements.

[0046] For purposes of the present disclosure, directional terms such as “top,” “bottom,” “upper,” “lower,” “above,” “below,” “left,” “right,” “horizontal,” “vertical,” “up,” “down,” etc,, are used merely for convenience in describing the various embodiments of the present disclosure. The embodiments of the present disclosure may be oriented in various ways. For example, the diagrams, apparatuses, etc., shown in the drawing figures may be flipped over, rotated by 90° in any direction, reversed, etc.

[0047] For purposes of the present disclosure, a value or property is “based” on a particular value, property, the satisfaction of a condition, or other factor, if that value is derived by performing a mathematical calculation or logical decision using that value, property or other factor.

[0048] For purposes of the present disclosure, it should be noted that to provide a more concise description, some of the quantitative expressions given herein are not qualified with the term “about.” It. is understood that whether the term “about” is used explicitly or not, every quantity given herein is meant to refer to the actual given value, and it is also meant to refer to the approximation to such given value that would reasonably be inferred based on the ordinary skill in the art, including approximations due to the experimental and / or measurement conditions for such given value.

[0049] For purposes of the present disclosure, the term “ANSI / AIAA S-080A-2018 (Reaffirmed 2024)” refers to a key American Institute of Aeronautics and Astronautics (AIAA) standard that sets baseline requirements for the design, fabrication, testing, and operation of metallic pressure vessels and pressurized components used in space systems, like spacecraft and launch vehicles. It covers everything from tanks and lines to cryostats and batteries, ensuring safety and reliability for storing liquids and gases in space.

[0050] For purposes of the present disclosure, the term “bootstrapping” refers to starting a system from nothing, most commonly the process of powering on a computer and loading the operating system (OS) using small, initial programs in firmware (BIOS / UEFI) that find and load the bootloader, which then loads the OS kernel. It may also refer to making software (like a compiler) available on a new platform by using an existing version to compile itself for theAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669new target, or a web framework (like Bootstrap) that provides pre-built components for faster development.

[0051] For purposes of the present disclosure, the term “closed-loop control” refers to a control architecture in which one or more control signals are generated based at least in part on feedback information representative of one or more measured operating parameters or output states of a controlled subsystem. In a closed-loop control configuration, sensed feedback data is compared to a desired reference value or command setpoint, and the resulting error signal is used to dynamically adjust actuation commands in order to regulate system performance, maintain stability, and compensate for disturbances, component variations, or changing operating conditions. As used herein with respect to propulsion electronics and spacecraft control systems, closed-loop control may refer to a control architecture in which propulsion control commands are generated based on feedback signals representative of one or more measured operating parameters of a propulsion subsystem or vehicle state. Such measured parameters may include, by way of non-limiting example, pump outlet pressure, propellant flow rate, chamber pressure, motor speed, valve position, thrust level, attitude rate, or vehicle orientation. In a closed-loop configuration, the measured feedback is compared to one or more commanded setpoints or reference profiles, and corresponding error signals are processed by propulsion electronics to dynamically adjust pump drive signals, valve actuation, thruster firing commands, or gimbal positioning in order to regulate propellant delivery, control thrust magnitude and direction, stabilize vehicle attitude, and compensate for disturbances, component tolerances, propellant property variations, and time-varying mission conditions.

[0052] For purposes of the present disclosure, the term “computer” refers to any type of computer or other device that implements software including an individual computer such as a personal computer, laptop computer, tablet computer, mainframe computer, mini -computer, etc. A computer also refers to electronic devices such as an electronic scientific instrument such as a spectrometer, a smartphone, an eBook reader, a cell phone, a television, a handheld electronic game console, a videogame console, a compressed audio or video player such as an MP3 player, a Blu-ray player, a DVD player, etc. In addition, the term “computer” refers to any type of network of computers, such as a network of computers in a business, a computer bank, the Cloud, the Internet, etc. Various processes of the present disclosure may be carried out using a computer. Various functions of the present disclosure may be performed by one or more computers.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0053] For the purposes of the present disclosure, the term “computer hardware” and the term “hardware” refer to the digital circuitry and physical devices of a computer system, as opposed to computer software, which is stored on a hardware device such as a hard disk. Most computer hardware is not seen by normal users, because it is embedded within a variety of every day systems, such as in automobiles, microwave ovens, electrocardiograph machines, compact disc players, and video games, among many others. A typical personal computer consists of a case or chassis in a tower shape (desktop) and the following parts: motherboard, CPU, RAM, firmware, internal buses (PIC, PCI-E, USB, HyperTran sport, CSI, AGP, VLB), external bus controllers (parallel port, serial port, USB, Firewire, SCSI. PS / 2, ISA, EISA, MCA), power supply, case control with cooling fan, storage controllers (CD-ROM, DVD, DVD-ROM, DVD Writer, DVD RAM Drive, Blu-ray, BD-ROM, BD Writer, floppy disk, USB Flash, tape drives, SATA, SAS), video controller, sound card, network controllers (modem, NIC), and peripherals, including mice, keyboards, pointing devices, gaming devices, scanner, webcam, audio devices, printers, monitors, etc.

[0054] For the purposes of the present disclosure, the term “computer network” refers to a group of interconnected computers. Networks may be classified according to a wide variety of characteristics. The most common types of computer networks in order of scale include: Personal Area Network (PAN), Local Area Network (LAN), Campus Area Network (CAN), Metropolitan Area Network (MAN), Wide Area Network (WAN), Global Area Network (GAN), Internetwork (intranet, extranet, Internet), and various types of wireless networks. All networks are made up of basic hardware building blocks to interconnect network nodes, such as Network Interface Cards (NICs), Bridges, Hubs, Switches, and Routers. In addition, some method of connecting these building blocks is required, usually in the form of galvanic cable (most commonly category 5 cable). Less common are microwave links (as in IEEE 802.11) or optical cable (“optical fiber”).

[0055] For the purposes of the present disclosure, the term “computer software” and the term “software” refers to one or more computer programs, procedures and documentation that perform some tasks on a computer system. The term includes application software such as word processors which perform productive tasks for users, system software such as operating systems, which interface with hardware to provide the necessary services for application software, and middleware which controls and co-ordinates distributed systems. Software may include websites, programs, video games, etc. that are coded by programming languages likeAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669C, C++, Java, etc. Computer software is usually regarded as anything but hardware, meaning the “hard” are the parts that are tangible (able to hold) while the “soft” part is the intangible objects inside the computer. Computer software is so called to distinguish it from computer hardware, which encompasses the physical interconnections and devices required to store and execute (or run) the software. At the lowest level, software consists of a machine language specific to an individual processor. A machine language consists of groups of binary values signifying processor instructions which change the state of the computer from its preceding state.

[0056] For the purposes of the present disclosure, the term “computer system” refers to any type of computer system that, implements software including an individual computer such as a personal computer, mainframe computer, mini-computer, etc. In addition, computer system refers to any type of network of computers, such as a network of computers in a business, the Internet, personal data assistant (PDA), devices such as a cell phone, a television, a videogame console, a compressed audio or video player such as an MP3 player, a DVD player, a microwave oven, etc. A personal computer is one type of computer system that typically includes the following components: a case or chassis in a tower shape (desktop) and the following parts: motherboard, CPU, RAM, firmware, internal buses (PIC, PCI-E, USB, HyperTransport, CSI, AGP, VLB), external bus controllers (parallel port, serial port, USB, Firewire, SCSI. PS / 2, ISA, EISA, MCA), power supply, case control with cooling fan, storage controllers (CD-ROM,, DVD, DVD-ROM,, DVD Writer, DVD RAM Drive, Blu-ray, BD- ROM, BD Writer, floppy disk, USB Flash, tape drives, SATA, SAS), video controller, sound card, network controllers (modem, NIC), and peripherals, including mice, keyboards, pointing devices, gaming devices, scanner, webcam, audio devices, printers, monitors, etc.

[0057] For the purposes of the present disclosure, the term “data” means the reinterpretable representation of information in a formalized manner suitable for communication, interpretation, or processing. Although one type of common type data is a computer file, data may also be streaming data, a web service, etc. The term “data” is used to refer to one or more pieces of data.

[0058] For the purposes of the present disclosure, the term “database” or “data record” refers to a structured collection of records or data that is stored in a computer system. The structure is achieved by organizing the data according to a database model. The model in most common use today is the relational model. Other models such as the hierarchical model andAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669the network model use a more explicit representation of relationships (see below for explanation of the various database models). A computer database relies upon software to organize the storage of data. This software is known as a database management system (DBMS). Database management systems are categorized according to the database model that they support. The model tends to determine the query’ languages that are available to access the database. A great deal of the internal engineering of a DBMS, however, is independent of the data model, and is concerned with managing factors such as performance, concurrency, integrity, and recovery from hardware failures. In these areas there are large differences between products.

[0059] For the purposes of the present disclosure, the term “database management system (DBMS)” represents computer software designed for the purpose of managing databases based on a variety of data models. A DBMS is a set of software programs that controls the organization, storage, management, and retrieval of data in a database. DBMS are categorized according to their data structures or types. It is a set of prewritten programs that are used to store, update and retrieve a Database.

[0060] For the purposes of the present disclosure, the term “data storage medium” or “data storage device” refers to any medium or media on which a data may be stored for use by a computer system. Examples of data storage media include floppy disks, ZipTMdisks, CD-ROM, CD-R, CD-RW, DVD, DVD-R, memory sticks, flash memory, hard disks, solid state disks, optical disks, etc. Two or more data storage media acting similarly to a single data storage medium may be referred to as a “data storage medium” for the purposes of the present disclosure. A data storage medium may be part of a computer.

[0061] For purposes of the present disclosure, the term “dynamic loading” refers to any force that changes over time, varying in magnitude, direction, or both, unlike a static load which is constant and stationary, and it's crucial for designing structures, machines, and components that move.

[0062] For purposes of the present disclosure, the term “envelope expansion test” refers to an initial phase of flight testing, for example, focusing on expanding an aircraft’s flight envelope, which refers to the range of flight conditions within which the aircraft may safely operate.

[0063] For purposes of the present disclosure, the term “feed pressure” refers to the pressure of a propellant at the entrance of a thruster at its inlet.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0064] For purposes of the present disclosure, the term “finite element method” (FEM) refers to a method for numerically solving differential equations arising in engineering and mathematical modeling. Typical problem areas of interest may include the traditional fields of structural analysis, heat transfer, fluid flow, mass transport, and electromagnetic potential. Computers may be used to perform the calculations required. With high-speed supercomputers, better solutions can be achieved and are often required to solve the largest and most complex problems. FEM is a general numerical method for solving partial differential equations in two-or three-space variables (i.e., some boundary value problems). To solve a problem, FEM subdivides a large system into smaller, simpler parts called finite elements. This is achieved by a particular space discretization in the space dimensions, which is implemented by the construction of a mesh of the object: the numerical domain for the solution that has a finite number of points. FEM formulation of a boundary' value problem finally results in a system of algebraic equations. The method approximates the unknown function over the domain. The simple equations that model these finite elements are then assembled into a larger system of equations that models the entire problem. FEM then approximates a solution by minimizing an associated error function via the calculus of variations. Studying or analyzing a phenomenon with FEM is often referred to as finite element analysis (FEA).

[0065] For purposes of the present disclosure, the term “flight weld geometries” refers to a weld joint configuration, interface profile, and resulting cross-sectional weld shape that is specifically engineered, qualified, and certified for use in flight hardware. Such geometries are selected to satisfy structural load requirements, pressure containment performance, fatigue resistance, thermal cycling tolerance, and nondestructive inspection criteria associated with aerospace operating environments. Flight weld geometries may include, without limitation, full-penetration butt joints, lap joints, stepped interfaces, scarf joints, reinforced crown or root profiles, and multi-pass or tool-path-controlled solid-state weld formations. As used herein, flight weld geometries may refer to a weld joint profile and interface configuration formed in a flight-rated component using a solid-state or fusion welding process, including friction stir welding, wherein the geometry is configured to produce a defect-free weld nugget, controlled heat-affected zone, and mechanically robust joint capable of withstanding pressurization, cryogenic operation, launch loads, and orbital thermal cycling.

[0066] For purposes of the present disclosure, the term “friction stir welding” (FSW) refers to a solid-state joining process that uses mechanical stirring action to plastically deformAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669materials, create minimal heat, and join materials without melting them. It’s a continuous operation that can join a variety of materials, including, for example, aluminum, copper, titanium, and stainless steel. In some disclosed embodiments, FSW uses a non-consumable tool to join two facing workpieces without melting the work piece material. Heat is generated by friction between the rotating tool and the workpiece material, which leads to a softened region near the FSW tool. While the tool is traversed along the joint line, it mechanically intermixes the two pieces of metal, and forges the hot and softened metal by the mechanical pressure, which is applied by the tool, much like joining clay, or dough. It may be used on wrought or extruded aluminum and particularly for structures which need very high weld strength to produce welds often stronger than the base material(s). FSW is capable of joining aluminum alloys, copper alloys, titanium alloys, mild steel, stainless steel and magnesium alloys. In addition, joining of dissimilar metals, such as aluminum to magnesium alloys, has been recently achieved by FSW. In some disclosed embodiments, friction stir welding is performed with a rotating cylindrical tool which has a profiled pin (also known as a probe) having a diameter smaller than the diameter of its shoulder. During welding the tool is fed into a butt joint between two clamped workpieces, until the probe pierces into the workpiece and its shoulder touches the surface of the workpieces. The probe may be slightly shorter than the weld depth required, with the tool shoulder riding atop the work surface. After a short dwell time, the tool is moved forward along the joint line at the pre-set welding speed. Frictional heat is generated between the wear-resistant tool and the work pieces. This heat, along with that generated by the mechanical mixing process and the adiabatic heat within the material, cause the stirred materials to soften without melting. As the tool is moved forward, a special profile on the probe forces plasticized material from the leading face to the rear, where the high forces assist in a forged consolidation of the weld. This process of the tool traversing along the weld line in a plasticized tubular shaft of metal results in severe solid-state deformation involving dynamic recrystallization of the base material. The solid-state nature of the FSW process, combined with its unusual tool shape and asymmetric speed profile, results in a highly characteristic micro- structure. The solid-state nature of FSW leads to several advantages over fusion welding methods, as problems associated with cooling from the liquid phase are avoided. Issues such as porosity, solute redistribution, solidification cracking and liquation cracking do not arise during FSW. In general, in accordance with disclosed embodiments, FSW has been found to produce a low concentration of defects and is very tolerant to variations in parameters and materials.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0067] For purposes of the present disclosure, the term “friction stir welds” (FSW) refers to welds produced by friction stir welding (FSW).

[0068] For purposes of the present disclosure, the term “hardware and / or software” refers to functions that may be performed by digital software, digital hardware, or a combination of both digital hardware and digital software. Various features of the present disclosure may be performed by hardware and / or software.

[0069] For purposes of the present disclosure, the term “internal burst pressure” refers to the maximum internal pressure a pipe, vessel, or component can withstand before it ruptures, cracks, or permanently fails, leading to a leak or catastrophic breach, determined by material strength, wall thickness, diameter, and temperature. It's a critical safety limit, significantly higher than normal working pressure, ensuring a safe buffer against sudden pressure spikes and allowing for safe operation in demanding industrial, chemical, or hydraulic systems.

[0070] For the purposes of the present disclosure, the term “Internet” is a global system of interconnected computer networks that interchange data by packet switching using the standardized Internet Protocol Suite (TCP / IP). It is a “network of networks” that consists of millions of private and public, academic, business, and government networks of local to global scope that are linked by copper wires, fiber-optic cables, wireless connections, and other technologies. The Internet carries various information resources and services, such as electronic mail, online chat, file transfer and file sharing, online gaming, and the inter-linked hypertext documents and other resources of the World Wide Web (WWW).

[0071] For the purposes of the present disclosure, the term “Internet protocol (IP)” refers to a protocol used for communicating data across a packet-switched internetwork using the Internet Protocol Suite (TCP / IP). IP is the primary protocol in the Internet Layer of the Internet Protocol Suite and has the task of delivering datagrams (packets) from the source host to the destination host solely based on its address. For this purpose the Internet Protocol defines addressing methods and structures for datagram encapsulation. The first major version of addressing structure, now referred to as Internet Protocol Version 4 (Ipv4) is still the dominant protocol of the Internet, although the successor, Internet Protocol Version 6 (Ipv6) is actively deployed world-wide. In one embodiment, an EGI-SOA of the present disclosure may be specifically designed to seamlessly implement both of these protocols.

[0072] For the purposes of the present disclosure, the term “intranet” refers to a set of networks, using the Internet Protocol and IP-based tools such as web browsers and file transferAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669applications that are under the control of a single administrative entity. That administrative entity closes the intranet to all but specific, authorized users. Most commonly, an intranet is the internal network of an organization. A large intranet will typically have at least one web server to provide users with organizational information. Intranets may or may not have connections to the Internet. If connected to the Internet, the intranet is normally protected from being accessed from the Internet without proper authorization. The Internet is not considered to be a part of the intranet.

[0073] For the purposes of the present disclosure, the term “local area network (LAN)” refers to a network covering a small geographic area, like a home, office, or building. Current LANs are most likely to be based on Ethernet technology. The cables to the servers are typically on Cat 5e enhanced cable, which will support IEEE 802.3 at 1 Gbit / s. A wireless LAN may exist using a different IEEE protocol, 802.11b, 802.11g or possibly 802.11n. The defining characteristics of LANs, in contrast to WANs (wide area networks), include their higher data transfer rates, smaller geographic range, and lack of a need for leased telecommunication lines. Current Ethernet or other IEEE 802.3 LAN technologies operate at speeds up to 10 Gbit / s.

[0074] For purposes of the present disclosure, the term “machine-readable medium” refers to any tangible or non-transitory medium that is capable of storing, encoding or carrying instructions for execution by the machine and that cause the machine to perform any one or more of the methodologies of the present disclosure, or that is capable of storing, encoding or carrying data structures utilized by or associated with such instructions. The term “machine- readable medium” includes, but is limited to, solid-state memories, and optical and magnetic media. Specific examples of machine-readable media include non-volatile memory, including by way of example, semiconductor memory devices, e.g., EPROM, EEPROM, and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto¬ optical disks; and CD-ROM and DVD-ROM disks. The term “machine-readable medium” may include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) that store the one or more instructions or data structures.

[0075] For purposes of the present disclosure, the term “maximum pressure” refers to the highest pressure a system, device, or material can safely withstand or is designed to handle, varying by context from Maximum Allowable Working Pressure (MAWP) in vessels to peak systolic pressure in the body, representing the upper limit before failure, damage, or health risk.Attorney Docket No.: 118717-25169WO01 / Custonier No.: 110669It’s crucial for safety and design, often set by standards or manufacturers, and differs from normal operating pressures.

[0076] For the purposes of the present disclosure, the term “MEMS” refers to Micro- Electro-Mechanical Systems. MEMS, is a technology that in its most general form may be defined as miniaturized mechanical and electro-mechanical elements (i.e., devices and structures) that are made using the techniques of microfabrication. The critical physical dimensions of MEMS devices can vary from well below one micron on the lower end of the dimensional spectrum, all the way to several millimeters. Likewise, the types of MEMS devices can vary from relatively simple structures having no moving elements, to extremely complex electromechanical systems with multiple moving elements under the control of integrated microelectronics. A main criterion of MEMS may include that there are at least some elements having some sort of mechanical functionality whether or not these elements can move. The term used to define MEMS varies in different parts of the world. In the United States they are predominantly called MEMS, while in some other parts of the world they are called “Microsystems Technology” or “micromachined devices.” While the functional elements of MEMS are miniaturized structures, sensors, actuators, and microelectronics, most notable elements may include microsensors and microactuators. Microsensors and microactuators may be appropriately categorized as “transducers,” which are defined as devices that convert energy from one form to another. In the case of microsensors, the device typically converts a measured mechanical signal into an electrical signal.

[0077] For purposes of the present disclosure, the term “non-axisymmetric” refers to an object lacking rotational symmetry; instead of looking the same when spun around an axis (like a perfect cylinder or sphere), its shape or properties change as it rotates, often exhibiting unevenness, lumps, or distinct patterns in different, direction. Exemplary embodiments may include a lopsided ball versus a perfect one, or a spinning top with a flat side wherein the flat side makes it non-axisymmetric.

[0078] For purposes of the present disclosure, the term “non -transient, storage medium” refers to a storage medium that is non-transitory, tangible and computer readable. Non-transient storage medium may refer generally to any durable medium known in the art upon which data can be stored and later retrieved by data processing circuitry operably coupled with the medium. A non-transitory, tangible, computer-readable storage medium may be capable of storing data, instructions, or information for use by, or in connection with, one or moreAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669processors or data-processing circuits. A non-transient storage medium permits the stored data to be accessed and retrieved at a later time and expressly excludes transitory forms of signal transmission, including propagating electromagnetic signals per se. A non-limiting non¬ exclusive list of exemplary non-transitory data storage media may include magnetic data storage media (e.g., hard disc, data tape, etc.), solid state semiconductor data storage media (e.g., SDRAM, flash memory, ROM, etc.), and optical data storage media (e.g., compact optical disc, DVD, etc.).

[0079] For purposes of the present disclosure, the term “ON-pulsing and OFF-pulsing” refers to control strategies used to manage a spacecraft’s velocity and attitude (orientation) during maneuvers.

[0080] For purposes of the present disclosure, the term “ON-pulsing” refers to firing thrusters that are normally inactive in short, discrete bursts. It may be used for attitude control or small orbital corrections. Thrusters may be commanded to turn " ON" for a fixed duration to generate a specific impulse bit and then return to an " OFF" state. Applications may be employed in satellite formation flying or for precise pointing in deep-space missions.

[0081] For purposes of the present disclosure, the term “OFF-pulsing” refers to turning off thrusters that are already firing continuously (to change a spacecraft’ s velocity). It may be used to generate control torques (rotation) while the main propulsion system is performing a primary burn. By momentarily cutting power or fuel to a specific subset of thrusters, the system creates an imbalance in thrust, allowing the spacecraft to rotate without needing a separate set of dedicated control thrusters. This method allows a single propulsion system to handle both velocity changes and attitude maintenance simultaneously.

[0082] For purposes of the present disclosure, the term “open-loop control” refers to a control architecture in which one or more control signals are generated and applied to a controlled subsystem based on predetermined commands, schedules, or operating parameters without reliance on real-time feedback of an output state or performance variable of the controlled subsystem for corrective adjustment. In an open-loop control configuration, the commanded actuation is executed independently of measured system response, such that the control action is not dynamically modified based on sensed output conditions. In an exemplary configuration of the disclosed open-loop control system, the controller issues control signals according to a predefined model, schedule, or command profile, and the system output is not measured or compared against a reference value for corrective action. As a result, the systemAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669does not automatically compensate for disturbances, component variations, or changes in operating conditions. In propulsion systems, open-loop control may be used, for example, to command pump speeds, valve positions, or thruster firing durations based on pre-calculated operating profiles. For example, a thruster may be fired for a predetermined duration at a specified pump speed without monitoring chamber pressure or thrust output. While this approach simplifies system design and reduces sensor dependency, it assumes stable and predictable system behavior.

[0083] For purposes of the present disclosure, the term “pressure transducer” refers to a sensing device configured to measure a fluid pressure associated with a propulsion subsystem and to generate a corresponding electrical output signal representative of the measured pressure for use by propulsion electronics and control circuitry. In exemplary embodiments, the pressure transducer may be coupled to a pump outlet, propellant feed line, tank volume, regulator interface, or thruster inlet to provide real-time pressure feedback for closed-loop pump control, thrust regulation, flow balancing, and system health monitoring. The pressure transducer may¬ employ any suitable sensing technology, including, by way of non-limiting example, piezoresistive, capacitive, strain-gauge, or microelectromechanical system (MEMS)-based sensing elements, and may be configured to operate over pressure and temperature ranges compatible with spaceflight environments. The term “pressure transducer” is intended to encompass flight-qualified sensors, redundant sensor assemblies, and integrated sensing modules capable of providing calibrated, temperature-compensated, and radiation-tolerant pressure measurements suitable for use in spacecraft propulsion applications.

[0084] For purposes of the present disclosure, the term “pressurant” refers to a gas (or sometimes a vapor) used to increase pressure within a system, typically to force a liquid out of a tank, maintain a liquid's state, or control fluid flow in pipelines, common in rocketry (e.g., like helium or self-generated gas) and industrial systems. It may be regarded as a working fluid that applies force, acting like a piston to move other fluids, ensuring they stay liquid or move where needed.

[0085] For purposes of the present disclosure, the term “pressurant tank” refers to a high- pressure storage vessel used in liquid propulsion systems, e.g., in spacecraft and satellites, to hold inert gas (the “pressurant”) for the purpose of expelling propellants.

[0086] For purposes of the present disclosure, the term “processor” refers to a device that performs the basic operations in a computer. A microprocessor is one example of a processorAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0087] For purposes of the present disclosure, the term “propellant” refers to any substance that produces thrust or force when expelled, enabling vehicles like rockets to move, or driving products out of aerosol devices, functioning as either a fuel / oxidizer mix (rockets), a compressed gas, or a liquefied gas to create pressure, with key types including solid (e.g., for boosters), liquid (e.g., liquid hydrogen / oxygen), and aerosol (e.g., nitrogen, propane) propellants. It works by expelling mass backward (relying on Newton’s Third Law for propulsion) to propel an object forward, whether through combustion (e.g., rockets) or pressure release (aerosols).

[0088] For purposes of the present disclosure, the term “psig” (PSIG) refers to pounds per square inch gauge, and may be regarded as a unit used to measure pressure relative to atmospheric pressure. Thus, PSIG measures gauge pressure, which uses atmospheric pressure as its reference point. This is the pressure above or below the local atmospheric pressure.

[0089] For the purposes of the present disclosure, the term “random-access memory (RAM)” refers to a type of computer data storage. Today it takes the form of integrated circuits that, allow the stored data to be accessed in any order, i.e. at random. The word random thus refers to the fact that any piece of data can be returned in a constant time, regardless of its physical location and whether or not it is related to the previous piece of data. This contrasts with storage mechanisms such as tapes, magnetic discs and optical discs, which rely on the physical movement of the recording medium or a reading head. In these devices, the movement takes longer than the data transfer, and the retrieval time varies depending on the physical location of the next item. The word RANI is mostly associated with volatile types of memory (such as DRAM memory modules), where the information is lost after the power is switched off. However, many other types of memory are RAM as well, including most types of ROM and a kind of flash memory called NOR-Flash.

[0090] For the purposes of the present disclosure, the term “read-only memory (ROM)” refers to a class of storage media used in computers and other electronic devices. Because data stored in ROM cannot be modified (at least not very quickly or easily), it is mainly used to distribute firmware (software that is very closely tied to specific hardware, and unlikely to require frequent updates). In its strictest sense, ROM refers only to mask ROM (the oldest type of solid state ROM), which is fabricated with the desired data permanently stored in it, and thus can never be modified. However, more modem types such as EPROM and flash EEPROM can be erased and re-programmed multiple times; they are still described as “read-only memory'”Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669because the reprogramming process is generally infrequent, comparatively slow, and often does not permit random access writes to individual memory locations.

[0091] For the purposes of the present disclosure, the term “real-time processing” refers to a processing system designed to handle workloads whose state is constantly changing. Real¬ time processing means that a transaction is processed fast enough for the result to come back and be acted on as transaction events are generated. In the context of a database, real-time databases are databases that are capable of yielding reliable responses in real-time.

[0092] For the purposes of the present disclosure, the term “rocket engine assembly” (REA) refers to a fully integrated propulsion unit designed to generate thrust by expelling high- velocity exhaust gases. The rocket engine assembly encompasses not merely the thrustproducing engine hardware, but the coordinated integration of all mechanical, fluidic, structural, and control subsystems required for autonomous operation. The rocket engine assembly may include a combustion chamber, one or more propellant injectors, a convergent–divergent nozzle, a propellant delivery system, and associated control and actuation systems, all supported within a dedicated structural framework that mechanically interfaces with the launch vehicle. Unlike air-breathing engines, the assembly may be self-contained, carrying both fuel and oxidizer to enable operation in the vacuum of space. During operation, fuel and oxidizer may be metered from onboard propellant tanks through feed lines and, where applicable, pumps or pressure-fed regulators. These propellants may be introduced into the combustion chamber via the injector, which is configured to promote efficient atomization, mixing, and stable combustion. Combustion within the chamber produces high-temperature, high-pressure gases that are directed through the nozzle. The nozzle’s convergent- div ergent geometry converts thermal and pressure energy into directed kinetic energy, accelerating the exhaust to supersonic velocities and thereby producing thrust in accordance with conservation of momentum. Control systems associated with the engine assembly may regulate propellant flow rates, chamber pressure, ignition sequencing, and, in many embodiments, thrust vectoring through movable nozzles or secondary flow-control mechanisms. These systems may include valves, actuators, sensors, and electronic controllers that collectively enable precise thrust modulation and vehicle steering. The engine mount and supporting structure maintain alignment of the propulsion axis, transmit loads from the engine to the rocket airframe, and ensure structural integrity under the extreme thermal and mechanical stresses encountered during launch and flight. The rocket engine assembly represents a complete, self-containedAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669propulsion section in which plumbing, electrical interfaces, structural mounts, and control hardware are combined into a single functional unit. Once assembled and qualified, this propulsion unit can be horizontally or vertically integrated with the remainder of a rocket stage. In essence, the rocket engine assembly embodies the end-to-end construction of a standalone propulsion system capable of reliably producing thrust in space by ejecting mass at high velocity. In certain embodiments, the disclosed rocket engine assembly (REA) may be configured to self-contain one or more propellants; however, in some practical implementations, the REA is supported by a separate, but fluidly coupled, propellant feed system that is configured to store propellant(s) and to regulate, meter, and distribute the propellant(s) to one or more REAs. Such feed systems may include, for example, tanks, pumps, valves, regulators, and associated control electronics to enable controlled delivery of propellant under commanded operating conditions. Certain disclosed storable chemical propellant rocket engine assemblies (REAs) utilize a single propellant and are therefore commonly referred to as monopropellant thrusters. In such embodiments, the propellant is directed through a catalyst bed disposed within the thruster, wherein the catalyst promotes rapid exothermic decomposition of the liquid propellant into high-temperature, high-pressure gaseous reaction products. The resulting gases are subsequently expanded and expelled through a nozzle at high velocity to generate thrust. Bipropellant thrusters may be configured to receive and mix two reactive propellants, which in certain embodiments may be hypergolic propellant pairs that ignite upon contact. Upon mixing, such as within a combustion chamber, the propellants undergo a rapid exothermic reaction that generates high-temperature, high-pressure gaseous combustion products, which are subsequently expanded and expelled through a nozzle to produce thrust.

[0093] For the purposes of the present disclosure, the term “solid-state electronics” refers to those circuits or devices built entirely from solid materials and in which the electrons, or other charge carriers, are confined entirely within the solid material. The term is often used to contrast with the earlier technologies of vacuum and gas-discharge tube devices and it is also conventional to exclude electro-mechanical devices (relays, switches, hard drives and other devices with moving parts) from the term solid state. While solid-state can include crystalline, polycrystalline and amorphous solids and refer to electrical conductors, insulators and semiconductors, the building material is most often a crystalline semiconductor. Common solid-state devices include transistors, microprocessor chips, and RAM. A specialized type of RAM called flash RAM is used in flash drives and more recently, solid state drives to replaceAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669mechanically rotating magnetic disc hard drives. More recently, the integrated circuit (IC), the light-emitting diode (LED), and the liquid-crystal display (LCD) have evolved as further examples of solid-state devices. In a solid-state component, the current is confined to solid elements and compounds engineered specifically to switch and amplify it.

[0094] For the purposes of the present disclosure, the term “solid state sensor” refers to sensor built entirely from a solid-phase material such that the electrons or other charge carriers produced in response to the measured quantity stay entirely with the solid volume of the detector, as opposed to gas-discharge or electro-mechanical sensors. Pure solid-state sensors have no mobile parts and are distinct from electro-mechanical transducers or actuators in which mechanical motion is created proportional to the measured quantity.

[0095] For purposes of the present disclosure, the term “storage medium” refers to any form of storage that may be used to store bits of information. Examples of storage media include both volatile and non-volatile memories such as MRRAM, MRRAM, ERAM, flash memory, RFID tags, floppy disks, Zip™ disks, CD-ROM, CD-R, CD-RW, DVD, DVD-R, flash memory', hard disks, optical disks, etc. Two or more storage media acting similarly to a single data storage medium may be referred to as a “storage medium” for the purposes of the present disclosure. A storage medium may be part of a computer.

[0096] For purposes of the present disclosure, the term “spacecraft” refers to a vehicle or device engineered to operate beyond Earth's atmosphere, either with or without a crew, in a controlled flight pattern. Disclosed embodiments may use rockets to cany astronauts, cargo, or instruments to their destination, or be the destination itself.

[0097] For purposes of the present disclosure, the term “spacecraft bus” refers to the core structure and support system of a spacecraft, providing essential “life support” functions like power, thermal control, navigation, communication, and data processing, allowing the mission¬ specific payload (e.g., cameras or telescopes) to operate in space. Embodiments may include the infrastructure that carries the entirety of the spacecraft, acting as the main body and framework for all the components, from propulsion to structural support, enabling the scientific mission.

[0098] For purposes of the present disclosure, the term “spinforming” (metal spinning) refers to a manufacturing process that shapes flat metal discs or tubes into axially symmetric parts (e.g., cones, hemispheres, cylinders) by rotating them at high speeds on a lathe andAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669pressing them against a rotating mold (mandrel) with tools, creating hollow, round components without removing material, often for cost-effective, low-to-medium volume production.

[0099] For purposes of the present disclosure, the term “specific impulse” (Isp) refers to a key measure of rocket engine efficiency, showing how much thrust is generated per unit of propellant consumed over time, often expressed in seconds (s) by normalizing exhaust velocity by Earth's gravity, meaning a higher Isp indicates more efficient fuel use for longer thrust, similar to better gas mileage for a car. It's calculated as thrust divided by propellant weight flow rate, and higher Isp allows a rocket to achieve greater velocity changes with less fuel. Thus, in terms of efficiency, Isp may quantify how effectively a rocket converts propellant into thrust

[0100] For purposes of the present disclosure, the term “telemetry / ” refers to the the process of recording and transmitting the readings of an instrument.

[0101] For the purposes of the present disclosure, the term “time” refers to a component of a measuring system used to sequence events, to compare the durations of events and the intervals between them, and to quantify the motions of objects. Time is considered one of the few fundamental quantities and is used to define quantities such as velocity. An operational definition of time, wherein one says that observing a certain number of repetitions of one or another standard cyclical event (such as the passage of a free-swinging pendulum) constitutes one standard unit such as the second, has a high utility value in the conduct of both advanced experiments and everyday affairs of life. Temporal measurement has occupied scientists and technologists, and was a prime motivation in navigation and astronomy. Periodic events and periodic motion have long served as standards for units of time. Examples include the apparent motion of the sun across the sky, the phases of the moon, the swing of a pendulum, and the beat of a heart. Currently, the international unit of time, the second, is defined in terms of radiation emitted by cesium atoms.

[0102] For the purposes of the present disclosure, the term “timestamp” refers to a sequence of characters, denoting the date and / or time at which a certain event occurred. This data is usually presented in a consistent format, allowing for easy comparison of two different records and tracking progress over time; the practice of recording timestamps in a consistent manner along with the actual data is called timestamping. Timestamps are typically used for logging events, in which case each event in a log is marked with a timestamp. In file systems, timestampAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669may mean the stored date / time of creation or modification of a file. The International Organization for Standardization (ISO) has defined ISO 8601 which standardizes timestamps.

[0103] For purposes of the present disclosure, the term “thruster” refers to a small rocket engine on a spacecraft, used to make alterations in its flight path or altitude.

[0104] For purposes of the present disclosure, the term “transducer” refers to a device or component configured to convert a physical quantity or condition into a corresponding electrical signal, or to convert an electrical signal into a corresponding physical output. In exemplary' embodiments, a transducer may be configured to sense one or more operational parameters including, by way of non-limiting example, pressure, temperature, flow rate, force, position, acceleration, or voltage, and to generate an output signal representative of the sensed parameter for use by control electronics, monitoring systems, or data acquisition circuitry. In other embodiments, a transducer may be configured to receive an electrical control signal and produce a corresponding mechanical, thermal, or fluidic response. The term “transducer” is intended to encompass sensors, actuators, and hybrid sensing-actuation devices, whether implemented as discrete components or integrated within a multi-functional assembly.

[0105] For the purposes of the present disclosure, the term “visual display device” or “visual display apparatus” includes any type of visual display device or apparatus such as a CRT monitor, LCD screen, LEDs, a projected display, a printer for printing out an image such as a picture and / or text, etc. A visual display device may be a part of another device such as a computer monitor, television, projector, telephone, cell phone, smartphone, laptop computer, tablet computer, handheld music and / or video player, personal data assistant (PDA), handheld game player, head mounted display, a heads-up display (HUD), a global positioning system (GPS) receiver, automotive navigation system, dashboard, watch, microwave oven, electronic organ, automatic teller machine (ATM) etc.Description

[0106] While the invention is susceptible to various modifications and alternative forms, specific embodiment thereof has been shown by way of example in the drawings and will be described in detail below. It should be understood, however that it. is not intended to limit the invention to the particular forms disclosed, but on the contrary, the invention is to cover all modifications, equivalents, and alternatives falling within the spirit and the scope of the invention.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0107] In certain embodiments, the disclosed spacecraft thermal control system (TCS) employs a predominantly passive, low-risk architecture, with the primary design differentiation residing in the manner in which propulsion-generated heat loads are managed. Waste heat generated by spacecraft components is rejected to space using one or more radiators mounted to the spacecraft structure and / or directly to heat-generating components. With the exception of designated radiative surfaces, substantially the entire spacecraft is covered with multilayer insulation (MLI) to minimize unwanted environmental heat gains and losses.

[0108] Electrical heaters are provided to maintain spacecraft components above predetermined minimum allowable operating temperatures during cold conditions. In some embodiments, all heater circuits are implemented with redundancy and are controlled by paired mechanical thermostats. The thermostats may be electrically wired in series such that an over¬ temperature condition is prevented in the event that a single thermostat fails in a closed state.

[0109] Subsystems mounted externally to the spacecraft primary structure, including rendezvous and proximity operations (RPO) modules, communications modules, and cold-gas or chemical control subsystems, are thermally isolated from the primary structure. Each such subsystem may incorporate an independent thermal design and control implementation, while employing the same fundamental design principles, materials, and hardware types used throughout the spacecraft thermal control system.

[0110] During propulsion operation, the propulsion subsystem may generate substantial transient and steady-state heat loads, particularly during operation of high-power thrusters such as LE144 thrusters. In disclosed embodiments, this heat load is managed by leveraging the substantial thermal mass of the propellant and the metallic construction of the propellant tank. Waste heat generated by propulsion components mounted on a propulsion deck is intentionally transported to the propellant tank, which functions as a controlled thermal sink.

[0111] Thermal transport from propulsion components to the propellant tank is accomplished using a network of constant conductance heat pipes (CCHPs). The CCHP network is configured to provide reliable, passive and in some cases active heat transport during both flight operation and ground testing, including thermal -vacuum and thermal balance testing, without reconfiguration.

[0112] Radiator surface coatings are selected based on both thermal performance and resistance to degradation in the space environment. Depending on expected solar exposure andAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669orbital orientation, radiator surfaces may employ coatings including Z93 white paint, optical solar reflectors (OSRs), or silver Teflon (AgTef), each having significant flight heritage.

[0113] Multiple MLI configurations may be employed across the spacecraft to accommodate differing thermal environments. In some embodiments, the majority of the spacecraft exterior and instrument modules are covered with MLI blankets comprising approximately twelve inner layers and an outer layer of metallized fabric such as Stamet. Smaller components, including propellant lines and harnesses, may utilize MLI blankets comprising fewer inner layers and an outer layer of Stamet or Kapton, depending on whether the insulation is located internally or externally. High-temperature regions may employ specialized MLI blankets comprising alternating layers of stainless steel foil and Kapton, with a stainless steel outer layer. MLI fabrication may utilize heritage materials and fabrication techniques.

[0114] Heater circuits may employ mechanical thermostats supplied by commercially available vendors such as Honeywell or Sensata / Klixon. Heater elements may include Kapton / foil or Kapton / wire-wound heaters produced by vendors such as Minco or Tayco Engineering. In some embodiments, thermostats and heaters are selected to comply with applicable NASA thermal hardware specifications, including NASA S-311-641 and NASA S- 311-G-079.

[0115] In disclosed embodiments, the constant conductance heat pipes comprise commercially available extruded heat pipe assemblies. Thermal design and analysis may be performed assuming, by way of example, extruded aluminum heat pipes having a nominal outer diameter of approximately one-half inch and charged with ammonia as the working fluid. Such CCHPs have extensive flight heritage and a technology readiness level (TRL) of 9. In alternative embodiments, copper-water heat pipes may be employed, depending on operating temperature ranges and system requirements. In further embodiments, diode heat pipes or variable conductance heat pipes may be utilized to provide directional or adaptive thermal transport capability. The heat pipes may be procured from established vendors, including Advance Cooling Technologies or Northrop Grumman.

[0116] Advantageously, substantially all components used in the disclosed thermal control system may be selected from hardware with demonstrated spaceflight heritage and high technology readiness levels, thereby reducing development risk while enabling effective management of concentrated and transient spacecraft heat loads.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0117] Spacecraft propulsion systems have historically relied on pressure-fed architectures, in which one or more propellants are stored in high-pressure tanks and delivered to thrusters using a stored pressurant gas, such as helium. In such systems, the propellant tank itself must withstand the full operating pressure required to deliver propellant to the thrusters, resulting in tanks that are structurally heavy, geometrically constrained, and costly to manufacture. Thrust modulation and vehicle attitude control in these systems are typically achieved by valve pulsing, in which thruster valves are repeatedly opened and closed to approximate desired thrust levels or steering moments.

[0118] Because the feed pressure in conventional pressure-fed systems is largely fixed by tank and regulator design, such systems generally lack the ability to continuously vary propellant inlet pressure at the thruster. As a result, thrusters often operate away from optimal steady-state conditions, leading to reduced specific impulse and inefficient propellant utilization. Frequent on-off pulsing further exacerbates inefficiencies and introduces transient thermal and mechanical stresses into propulsion components.

[0119] The foregoing limitations of pressure-fed tank designs have motivated the development of pump-fed propulsion architectures, in which electrically driven pumps generate the propellant feed pressure delivered to the thrusters. By decoupling thruster inlet pressure from tank storage pressure, pump-fed systems allow propellant tanks to operate at substantially lower pressures than those required in conventional pressure-fed architectures.

[0120] Lower tank operating pressures relax structural requirements on the tank, enabling reduced wall thickness, broader material selection, and greater freedom in tank geometry. In particular, tanks may be designed to conform to available spacecraft volumes rather than being constrained to pressure-optimized shapes. This conformability improves volumetric efficiency and allows a greater fraction of the spacecraft envelope to be utilized for propellant storage, payload, or other subsystems.

[0121] Pump-fed architectures also reduce or eliminate the need for dedicated pressurant vessels and associated hardware, thereby simplifying system design and reducing mass and integration complexity. Moreover, because feed pressure is actively generated and controlled by the pumps, propulsion performance can be dynamically adjusted without relying on fixed tank pressure or inefficient valve pulsing techniques.

[0122] However, the adoption of pump-fed propulsion introduces new technical challenges, including the need for coordinated control of multiple pumps, precise regulation of propellantAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669flow and pressure, and management of waste heat generated by pump operation. These challenges, and the systems and methods for addressing them, are the subject of the present disclosure.

[0123] In particular, the disclosed pump-fed systems may employ multiple electrically driven pumps, potentially operating simultaneously to supply different propellants and multiple thrusters. Coordinated operation of such pumps requires precise control of pump speed, timing, and synchronization in order to maintain desired mixture ratios, inlet pressures, and thrust levels across the propulsion system. Moreover, pump-fed architectures enable rapid and continuous modulation of propellant flow, which demands control logic capable of high-frequency adjustments while maintaining system stability and efficiency.

[0124] Existing spacecraft propulsion controllers were generally designed around pressure- fed assumptions and discrete valve actuation schemes. Such controllers are poorly suited for managing dynamically throttled pumps, especially where thrust vector control is achieved by continuously varying pump output rather than by valve pulsing. In addition, electrically driven pumps and their associated power electronics generate significant waste heat during operation. Absent coordinated control strategies, such heat can degrade controller reliability, reduce pump lifetime, or necessitate oversized thermal rejection hardware.

[0125] Accordingly, disclosed embodiments address the need for an integrated propulsion controller specifically adapted for pump-fed spacecraft propulsion systems. The disclosed controller is capable of managing multiple pumps in concert, dynamically controlling propellant feed pressure and flow rate to one or more thrusters, enabling efficient steady-state operation, and supporting fine-grained thrust and attitude control without reliance on inefficient valve pulsing. Disclosed embodiments also provide controller architectures that cooperate with propulsion system thermal management strategies, including the intentional redistribution of pump-generated waste heat to other spacecraft components, such as propellant tanks or onboard electronics.

[0126] The present disclosure addresses these needs by providing improved controller architectures, control methods, and system integrations tailored to pump-fed spacecraft propulsion systems,

[0127] FIG. 1 illustrates a propulsion block diagram according to one embodiment of the present disclosure. The propulsion system 100 includes separate storage volumes 102, 104 for fuel (102) and oxidizer (104). In bipropellant operating modes, each bipropellant rocket engineAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669assembly (REA) is supplied with propellant from the respective tanks 102, 104 by two motor- driven pumps, one associated with the fuel and one associated with the oxidizer. The propulsion system electronics 106 are configured to close a control loop between pump outlet pressure and pump rotational speed, thereby regulating propellant delivery to the REA.

[0128] Propulsion system 100 may further include one or more monopropellant thrusters 120, 122, and 124. In such embodiments, the monopropellant thrusters 120, 122, and 124 may be supplied by a single operating pump (such as hydrazine pump 116), which may optionally be provided with a redundant backup pump 138. Thus, in one disclosed embodiment, a configuration exists wherein pump 138 is parallel to pump 116 that is telemetered by pressure transducer 118 and feeds monopropellant thrusters 120, 122 and 124. Accordingly, in exemplary configurations, propulsion system 100 may implement one or more electrically driven pump assemblies that include redundant pump units for each pump required in a single¬ string architecture, thereby enhancing system reliability and fault tolerance.

[0129] Operation of the monopropellant pump is likewise controlled by the propulsion system electronics 106 based on feedback from one or more pressure sensors to regulate outlet pressure and flow.

[0130] Oxidizer pumps 108, 126 provide pressurized flow of oxidizer to the bipropellant thruster(s) 114, 132. The pump to thruster ratio can be 1:1, or the pair of Ox / Fu pumps can feed multiple thrusters. If the pair of Ox / Fu pumps feeds a single thruster and there is a multiplicity of the Ox / Fu pumps + thrusters, then the feed pressure can be varied among the thrusters to provide differential thrust control to the spacecraft for steering or to accommodate center-of-mass imbalances or shifts in the space vehicle throughout the mission lifetime.

[0131] Fuel pumps 110 and 128 may be configured to deliver pressurized fuel flow to the bipropellant thrusters. As described above, multiple implementation configurations may be employed, including embodiments in which the pumps are independently controllable to enable differential throttling for flow balancing, thrust modulation, and system optimization.

[0132] Pressure transducers 112, 118, 130, 134, and 136 are configured to measure pump outlet pressure and provide real-time feedback signals to pump control loops executed by the propulsion electronics. The pressure feedback may be used to regulate pump speed, maintain target feed pressures, compensate for transient operating conditions, and support closed-loop control of propellant delivery to the thrusters.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0133] Bipropellant thrusters 114 and 132 are configured to receive oxidizer and fuel supplied by corresponding pump assemblies. In embodiments in which individual thrusters are fed by dedicated oxidizer / fuel pump pairs, each thruster may be independently throttled by adjusting associated pump operating parameters. Such independent control enables selective modulation of thrust level, specific impulse (Isp), and other performance characteristics in accordance with commanded operating setpoints and mission requirements.

[0134] Hydrazine pump 116 is configured to supply pressurized propellant to a monopropellant thruster circuit. In various embodiments, a single monopropellant thruster or a plurality of monopropellant thrusters may be supplied by one or more hydrazine pumps. Multiple pumps may be implemented, for example, to provide system redundancy, enable operation of multiple thrusters within fault-isolated feed circuits, or establish one-to-one pump- to-thruster configurations that support independent throttling and differential thrust control.

[0135] Monopropellant thrusters 120, 122, and 124 are configured to generate thrust using a monopropellant feed circuit. In the illustrated embodiment, multiple thrusters are supplied within a common feed circuit; however, alternative configurations are contemplated, including those described with respect to hydrazine pump 116, such as individually fed thruster circuits, fault-isolated architectures, and one-to-one pump-to-thruster arrangements and additional embodiments, as described below.

[0136] The propulsion system electronics 106 thus provide coordinated control of pump operation across both bipropellant and monopropellant modes, including pressure regulation, pump speed control, and fault management.

[0137] Propulsion system 100 may be implemented in a variety of configurations. In some embodiments, propulsion system 100 may include only monopropellant thrusters, only bipropellant thrusters, only dual-mode thrusters, or any combination thereof. The number and type of rocket engine assemblies (REAs) of each type may be selected based on mission requirements and may be increased or decreased without departing from the scope of the disclosure.

[0138] In various embodiments, one or more REAs may be supplied by a single pump or a set of pumps. Alternatively, a single REA may be supplied by a single pump, a paired set of pumps associated with different propellants (e.g., fuel and oxidizer), or redundant pump pairs. Thrust control of the REAs may be achieved using pump speed modulation, one or more flow¬ control valves, or a combination of both. In addition, multiple groups or blocks of REAs mayAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669each be supplied by one or more pumps arranged in single, paired, or parallel configurations. Parallel pump configurations may also be implemented to provide N: 1 redundancy, in which a single pump is required for nominal operation and a plurality of additional pumps are provided as redundant units. In such embodiments, one or more standby pumps may be selectively activated, for example, in the event of a primary pump failure, performance degradation, or maintenance condition, thereby enhancing system reliability, availability, and fault tolerance.

[0139] Isolation valves, filters, pressure transducers, temperature sensors, and other propulsion system components may be positioned at various locations throughout the propulsion system in numerous configurations and permutations. The propulsion system may further be supplied from a single propellant tank or from multiple propellant tanks. The propellant tanks may be loaded using onboard pumps or via one or more service valves located at different positions within the system.

[0140] Each propellant type may be stored in one or more dedicated tanks, or multiple propellants may be stored in tanks having a common bulkhead, depending on system architecture and mission constraints.

[0141] A functional overview of the disclosed thermal management architecture 200 is illustrated in thermal block diagram FIG. 2. Components of the propulsion system 100 that generate waste heat are conductively and thermally coupled to a propulsion subsystem structure that incorporates one or more heat spreaders 202. Heat spreaders 202 are configured to distribute waste heat among heat-generating and heat-tolerant components, including the propellant pumps 204, pump motor controllers 206, and the propulsion controller 208. Additional propulsion subsystem components, such as sensors used to monitor propulsion system health, flow control devices, and filters, may also be mounted to and thermally accommodated by the propulsion subsystem structure. In certain embodiments, pumped fluid from the propulsion system may be routed through one or more heat exchangers thermally- coupled to other spacecraft subsystems or equipment in order to absorb waste heat generated thereby and transport the recovered thermal energy to one or more propellant tanks. Such configurations enable redistribution of waste heat for thermal conditioning of propellant storage volumes and may reduce reliance on dedicated thermal control hardware while improving overall system thermal efficiency.

[0142] One or more additional heat spreaders 202 may be configured to transport waste heat from the propulsion subsystem structure to one or more propellant tanks, thereby maintainingAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669tank and propellant temperatures above predetermined minimum operating thresholds. In alternative embodiments, pumped propellant may be routed through one or more heat exchangers thermally coupled to the propellant tank(s) to transfer waste heat generated by pumps, propulsion controllers, or other propulsion-related components into the propellant storage volume. Such configurations enable active redistribution of waste heat for propellant thermal conditioning and system-level thermal management. The propellant tank or tanks are covered with multi-layer insulation (MLI) blankets 210 to reduce heat loss through radiative transfer. Similarly, the propulsion subsystem structure that supports propulsion components may be at least partially covered with MLI to minimize radiative heat exchange with cold space and with other spacecraft subsystems.

[0143] Thrusters may be thermally isolated from the remainder of the spacecraft structure to limit undesired conductive heat transfer and to reduce thermal coupling between propulsion components and adjacent subsystems. Propellant feed lines may likewise be both conductively isolated, for example through the use of thermally insulative stand-offs or low-conductivity mounting interfaces, and radiatively isolated using multi-layer insulation (MLI) blankets. In addition, the propellant feed lines may incorporate electrically resistive heating elements configured to maintain propellant temperature within a predetermined operating range.

[0144] In various embodiments, operation of such heaters may be controlled by mechanical thermostats, by the propulsion controller, or by the spacecraft avionics and electrical power subsystems, which may implement closed-loop temperature regulation by processing feedback signals from temperature sensors, for example, using flight software. In further embodiments, heater operation may be governed in addition to, or alternatively, by software-based control algorithms, including, by way of non-limiting example, bang-bang control schemes or variable¬ output control schemes such as proportional control or pulse-width modulation (PWM), using measured temperature data as feedback within a heater control loop.

[0145] Reaction engine assemblies 212 may be thermally isolated from the rest of the propulsion system 100. Propulsion system 100 may employ a variety of thermal transport and heat rejection mechanisms to manage waste heat generated by propulsion system components. In some embodiments, propulsion system 100 may include a pumped thermal fluid loop that circulates a working fluid other than the propellant to transport waste heat to one or more propellant tanks, supporting structures and / or other components of the spacecraft.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0146] In certain embodiments, propellant may be actively circulated between waste heat¬ generating propulsion components and one or more propellant tanks to transfer thermal energy to the tank structure and the propellant contained therein. Alternatively or additionally, propulsion system 100 may incorporate passive and active thermal transport devices, such as heat pipes, to conduct waste heat from propulsion components to the propellant and and / or associated tank assemblies. In exemplary implementations, such heat pipes may include constant-conductance heat pipes or variable-conductance heat pipes. In other embodiments, thermal energy transfer may be accomplished using indirect heat exchange architectures, such as a heat exchanger coupling a pumped propellant flow to a separate thermal control loop employing a different working fluid. In further embodiments, loop heat pipes may be utilized to provide capillary-driven heat transport over extended distances and across varying thermal gradients and operating environments.

[0147] Non-fluidic thermal conduction mechanisms may also be employed. For example, propulsion system 100 may utilize metallic heat straps, pyrolytic graphite elements, or other high-conductivity materials to conduct waste heat to the tank(s), structure, or other designated thermal sinks.

[0148] In some embodiments, waste heat may be rejected directly to cold space through radiative surfaces rather than being transferred to the propellant or tank(s). In further embodiments, the propulsion system may incorporate phase change material (PCM) systems, including open or closed PCM configurations or variable emittance radiators, to temporarily absorb waste heat during transient propulsion events.

[0149] These thermal management approaches may be used individually or in combination to achieve desired thermal performance under varying mission and operational conditions.

[0150] During a transient propulsive maneuver, waste heat generated by propulsion system components including, for examples, the propellant, pumps, pump motor controllers, and propulsion controller, is transferred to one or more propellant tanks, the propellant(s) contained therein, and supporting structures thermally coupled to the tank(s). The disclosed thermal management system is configured to absorb and distribute this heat such that all propulsion- related components, including the propellant(s) and / or other spacecraft components, remain below their respective maximum allowable operating temperatures at the conclusion of the maneuver, with margin. Thus, waste heat generated by pumps or propulsion electronics isAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669thermally coupled to at least one propellant tank, propellant volume, or other spacecraft components that may benefit from thermal power input.

[0151] Accordingly, in certain disclosed embodiments, heat transfer components configured to distribute thermal energy among multiple propulsion or spacecraft components, or to transfer heat from one or more components to another component or group of components, may also include heat pipes, thermally conductive straps or plates, and actively pumped thermal control loops. Additional thermal management configurations may include selectively conductive devices, such as variable conductance heat pipes and thermal switches, as well as variable-emittance elements, including radiative louvers, for adaptive heat rejection, or other emissivity control device. In further embodiments, phase change materials may be employed to temporarily absorb thermal energy and subsequently release the stored heat at a controlled rate, thereby moderating transient thermal loads and improving overall thermal stability.

[0152] Preliminary thermal analyses were performed to evaluate the propulsion system’s capability to transport and absorb propulsion-related waste heat over the duration of representative operational scenarios. The analysis demonstrates that all equipment list items, including the propellant(s), remain within their specified operating temperature limits following a representative 34-minute delta- V maneuver. The analysis assumed conservative component power dissipation values, including current best estimates with added margin, and further assumed a worst-case thermal orientation in which the multi-layer insulation (MLI)–blanketed thruster and propulsion equipment, support structure is exposed to direct solar illumination during the maneuver.

[0153] In certain embodiments, a non-transitory computer-readable medium may store executable instructions that, when executed by processing circuitry of a spacecraft thermal management controller, cause the thermal management system to monitor, regulate, and coordinate thermal conditions associated with propulsion system operation. During a propulsion event, the thermal management controller may obtain temperature data from a plurality of spacecraft components that experience heat generation or heat dissipation, including but not limited to propulsion system components, pumps, thrusters, valves, power electronics, propulsion controllers, structural mounting interfaces, and adjacent spacecraft subsystems. The acquired temperature data may be received from distributed temperature sensors, embedded thermal sensors, or integrated subsystem telemetry interfaces.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0154] The executable instructions may further cause the thermal management controller to analyze the monitored temperature data and to coordinate operation of one or more electrical heaters based on measured thermal conditions. In certain implementations, the thermal management controller may selectively activate, modulate, or deactivate heaters associated with propulsion components, propellant tanks, feed lines, catalyst beds, injectors, or other thermally sensitive elements in order to maintain such components within predetermined operating temperature ranges. Heater coordination may be performed using open-loop control strategies based on predefined operating profiles or closed-loop control strategies using temperature feedback to dynamically adjust heater power levels.

[0155] In further embodiments, the thermal management controller may be configured to manage spacecraft thermal conditions in cooperation with a thermal management architecture configured to redistribute propulsion-generated waste heat. Such thermal management architecture may include, by way of non-limiting example, heat exchangers, heat pipes, thermal straps, conductive structural interfaces, pumped fluid loops, phase-change devices, or integrated tank heat absorption structures. The thermal management controller may direct or regulate the transfer of waste heat from propulsion system components to one or more spacecraft components having thermal mass or heat capacity sufficient to absorb and buffer the waste heat, including propellant tanks, structural elements, radiators, or dedicated thermal storage components. In this manner, propulsion-generated thermal energy may be repurposed to maintain other spacecraft subsystems within allowable temperature limits while reducing reliance on active cooling hardware.

[0156] The executable instructions stored on the non -transitory computer-readable medium may further cause the thermal management controller to generate display data representative of thermal operating conditions and control states. The display data may include temperature values, heater activation status, waste-heat transfer pathways, thermal load distribution, and system health indicators. The thermal management controller may transmit the display data to a display device located onboard the spacecraft, within a ground support system, or at a remote mission operations center. The displayed information may be updated in real time during propulsion events or at predetermined refresh intervals to support operator situational awareness, thermal performance monitoring, and post-event analysis.

[0157] In certain embodiments, the thermal management controller may further enable user interaction with the displayed thermal data, including selection of monitored components,Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669adjustment of thermal control parameters, visualization of historical temperature trends stored in non-volatile memory, and identification of anomalous thermal conditions. Such functionality may facilitate coordinated propulsion and thermal management operations, system diagnostics, and long-term performance optimization of the spacecraft thermal control system.

[0158] FIG. 3 illustrates thermal analysis results according to one embodiment of the present disclosure. The thermal analysis was performed using Thermal Desktop and indicates substantial thermal margin between predicted component temperatures and their respective maximum operating limits, thereby confirming the robustness of the propulsion system thermal management approach under transient maneuver conditions. Analysis results are specific to a specific thermal design implementation.

[0159] Flowchart for BIT

[0160] The flowchart provided in FIG. 4 illustrates an exemplary process flow 400 for a propulsion system built-in test (BIT). In the illustrated embodiment, the BIT process begins by verifying responsiveness and operational status of propulsion system sensors, pump motor controllers, and gimbal controllers. Upon successful verification, the BIT process proceeds to evaluate pump responsiveness, thruster valve actuation, and operation of one or more isolation valves configured to selectively isolate the propellant tank(s) from other propulsion system components.

[0161] The BIT process thus enables automated verification of proper operation of active propulsion system components prior to propulsion system activation, thereby supporting fault detection, system readiness assessment, and safe execution of subsequent propulsion operations. The spacecraft flight software could issue discrete commands to the propulsion controller to execute the BIT. There are many permutations on the order of operations for the BIT.

[0162] Flowchart for boot-strapping

[0163] In some embodiments, the disclosed propulsion system is configured to automatically execute a start-up and boot-strap sequence. FIG. 5 illustrates a flowchart for boot-strap sequence 500 according to one embodiment of the present disclosure. The sequence may include performing a built-in test (BIT), initiating operation of one or more attitude control system (ACS) propellant pumps, and increasing propellant feed pressure to a predeterminedAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669level. The sequence tn ay further include initiating operation of one or more delta- V fuel pumps and operating one or more delta- V rocket engine assemblies (REAs) in a monopropellant mode.

[0164] Following stabilization of monopropellant operation, the sequence may include starting and increasing the outlet pressure of a delta- V oxidizer pump, opening oxidizer valves associated with the delta- V REAs, and controlling operation of the delta- V fuel and oxidizer pumps to achieve a desired thrust level of the delta- V REAs. Upon completion of the boot¬ strap sequence, the disclosed propulsion system may transmit telemetry indicating successful completion of the automated start-up process. There are many permutations of a bootstrap procedure that could be tailored to a specific propulsion system equipment list.

[0165] Flowchart for Shutdown procedure

[0166] In some embodiments, the propulsion system is configured to automatically execute a shut-down sequence. FIG. 6 illustrates a flowchart for a shut-down sequence 600 according to one embodiment of the present disclosure. The sequence may include commanding all pumps to ramp their rotational speeds to zero revolutions per minute (RPM) and verifying that, the commanded zero-speed condition has been achieved and gimbals may be re-homed. Upon successful verification, the sequence may further include closing all thruster valves and transmitting telemetry indicating successful completion of the shut-down procedure.

[0167] If one or more pumps fail to reach the commanded zero-speed condition within a predetermined time or tolerance, the propulsion system may transmit telemetry indicating an unsuccessful shut-down condition. In response to such telemetry, the spacecraft may remove electrical power from one or more pump controllers to place the propulsion system in a safe state. There are many permutations of a shutdown procedure that could be tailored to a specific propulsion system equipment list.

[0168] Electrical block diagram of distributed propulsion system

[0169] FIG. 7 illustrates an electrical block diagram 700 of the distributed propulsion system 702 according to one embodiment of the present disclosure. The disclosed propulsion system command and telemetry' (CMD / TLM) interfaces are centralized within the propulsion controller 704, which includes redundant CMD / TLM interfaces to a spacecraft Command and Data Handling (C& DH) flight computer (FC) 706. Electrical power for the propulsion system is supplied via the spacecraft Electrical Power Subsystem (EPS) 708.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0170] Propulsion controller 704 is configured to abstract and manage interfaces for substantially all active propulsion system components, with the possible exception of certain heater elements. In this role, propulsion controller 704 aggregates telemetry’ data from propulsion system components and distributes command signals, thereby providing consolidated CMD / TLM data streams between propulsion controller 704 and FC 706.

[0171] Propulsion controller 704 directly controls operation of rocket engine assembly (REA) valves and isolation valves 710 via dedicated valve driver circuitry integrated within propulsion controller 704. Propulsion controller 704 further provides power conditioning for, and directly interfaces with, sensors 712 used to monitor propulsion system performance and health, and digitizes sensor outputs for use in control and telemetry functions.

[0172] In addition, propulsion controller 704 is configured to control operation of pump motor controllers 714 and to establish one or more closed-loop feedback control paths between propulsion system sensors 712 and the pump motor controllers 714 to regulate propellant, delivery and overall system performance, including via actuation of pump motors 716. In the illustrated embodiment, each pump motor controller 714 is powered directly and independently by electrical power system (EPS) 708. Propulsion controller 704 may further be configured to control gimbal actuation and to process position feedback signals from associated position transducers to enable closed-loop thrust vector control and attitude regulation.

[0173] Thermal control for the propulsion system may be provided by, or coordinated with, the spacecraft thermal control subsystem, which is configured to maintain propulsion system components within their respective allowable operating temperature ranges. In certain embodiments, the propulsion controller may be configured to control one or more heating elements, including thermostatically regulated heaters, software-controlled heaters, or combinations thereof, to provide active thermal management of propulsion components in accordance with commanded operating modes and mission requirements. In further embodiments, thermal control functionality may be implemented directly within the propulsion system itself, wherein waste heat generated by propulsion components, including pumps and propulsion control electronics, is actively transported to one or more propellant tanks and, by extension, to the contained propellant. Such configurations enable mitigation of component overheating while simultaneously providing beneficial thermal conditioning of propellant storage volumes.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0174] In some embodiments, each pump motor controller may additionally operate valve driver circuitry for one or more corresponding rocket engine assemblies (REAs), and one or more motor controllers may be integrated within a propulsion controller. Pump motors may include redundant windings to provide fault tolerance. In such embodiments, the propulsion controller may include a switch matrix configured to selectively map individual motor windings to available motor drivers, thereby enabling reconfiguration in the event of a fault.

[0175] In various embodiments, the pump motor controllers may be configured to directly implement one or more closed-loop feedback control paths between propulsion system sensors and associated pump motors and / or gimbal actuators. The propulsion controller may further be configured to selectively enable or disable electrical power delivery to one or more pump motor controllers, for example, in order to manage operating modes, support fault isolation, and coordinate propulsion subsystem operation.

[0176] In alternative architectures, the propulsion controller may be replaced or supplemented by a plurality of distributed control units, each dedicated to a respective thruster or pump. Such distributed units may interface directly with a spacecraft flight computer (FC), either via a shared communication bus or through individual communication links.

[0177] The propulsion controller may also control operation of catalyst bed heaters, injector heaters, or other propulsion-related heaters. In some embodiments, the propulsion controller orchestrates propulsion system thermal management by powering, conditioning, and telemetering temperature sensors, distributing power to thermostatically controlled heaters, and / or closing feedback control loops between heaters switched within the propulsion controller and associated temperature sensors.

[0178] Pump operation may be conducted in open-loop mode or based on one or more lookup tables that define pump operating parameters across a range of operating conditions, including variations occurring over the operational lifetime of the propulsion system. In further embodiments, the propulsion system may incorporate data generated external to the propulsion system to close feedback control loops or otherwise influence propulsion system operation.

[0179] Spacecraft systems, particularly chemical propulsion systems, have traditionally employed pressure-fed architectures, in which one or more propellants are stored in high- pressure tanks and delivered to thrusters by means of a dedicated pressurant gas, such as helium. In such systems, the propellant tank is required to withstand substantial internal pressures throughout the entire mission lifecycle, including during ground handling, launch siteAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669preparation, ascent, and on-orbit operation. As a consequence, tank structural design has historically been driven primarily by pressure containment requirements rather than by considerations of mass efficiency or spacecraft integration.

[0180] To meet these pressure demands, conventional spacecraft propellant tanks are commonly fabricated from high-strength materials, including titanium alloys or composite overwrapped pressure vessels (COPVs). These tanks are typically configured with non- conformal geometries, such as spherical or cylindrical shapes, which are well suited for resisting internal pressure but are poorly optimized for efficient use of available spacecraft volume. In addition, the manufacture of such tanks is often costly and time-intensive, requiring specialized materials, complex fabrication processes, and long lead times associated with qualified aerospace suppliers. The resulting tanks therefore tend to be mass-inefficient, consuming a disproportionate share of the spacecraft’s mass budget relative to the amount of usable propellant they contain.

[0181] These limitations are increasingly problematic for modern spacecraft platforms, where payload capacity, maneuverability, and overall mission economics are highly sensitive to subsystem mass and volume. Moreover, high-pressure propellant tanks introduce added complexity and operational risk during launch site activities, where large quantities of energetic propellants are handled in close proximity to personnel. Such conditions necessitate extensive qualification testing, conservative safety margins, and rigorous certification procedures, further increasing cost and development timelines.

[0182] Additionally, conventional high-pressure propellant tanks inherently tie tank structural design to thruster feed pressure requirements, forcing designers to oversize and over¬ engineer tanks for pressure containment rather than functional integration. This coupling results in tanks that are heavier, more expensive, and less adaptable to nontraditional spacecraft geometries.

[0183] Furthermore, traditional tank designs are poorly suited for advanced propulsion architectures that seek to optimize system efficiency, thermal behavior, and packaging flexibility. In particular, known tank solutions do not adequately address the opportunity to leverage lower-pressure storage to enable alternative materials, welding techniques, and structural configurations while still meeting propulsion system demands.

[0184] Efforts to improve conventional pressure-fed tank designs have generally focused on incremental enhancements, such as the use of alternative materials or localized structuralAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669reinforcement. While these approaches may provide modest improvements, they do not fundamentally address the underlying tradeoffs between high pressure tolerance, low mass, manufacturability, and efficient integration with increasingly compact spacecraft buses. As a result, existing tank technologies remain constrained by design paradigms that prioritize pressure containment at the expense of system-level efficiency.

[0185] Accordingly, there remains a need for a spacecraft propellant tank that departs from conventional high-pressure design approaches and instead operates at substantially lower internal pressures, while still meeting safety and qualification requirements. Such a tank preferably enables conformal geometries that maximize propellant volume within the available spacecraft envelope, reduce overall mass, cost, and manufacturing lead time, and remain compatible with modern propulsion architectures without compromising maneuvering capability or system performance.

[0186] In view of the foregoing, there is a clear need for an improved spacecraft propell ant tank that departs from conventional high-pressure paradigms and enables lightweight, low- pressure, conformal storage of propellants, while maintaining structural integrity, safety, and compatibility with spacecraft propulsion systems. The present disclosure addresses these and other deficiencies of the prior art.

[0187] The present disclosure relates to propellant tank systems employing conformal, multi-wall geometries fabricated using friction stir welding (FSW) of machined aluminum plate components. The disclosed tanks provide high propellant mass fraction, low operating pressure capability, and reduced production cost by eliminating the need for traditional tank manufacturing methods such as spinforming or large-billet machining, A progressive build-test-analyze development approach validates structural integrity, including subscale burst-test units that replicate flight weld geometries. Burst testing demonstrates that the tank design exceeds predicted structural margins, enabling mass reduction and scalable production. Additionally, reaction force data collected from the disclosed subscale weld process is used to design appropriate tooling for generation of the disclosed full-scale tank assembly.

[0188] A conformal multi-wall propellant tank is provided having an inner and an outer wall formed from machined plate components joined using friction stir welding. The welded structure includes longitudinal weld seams configured to withstand burst pressures significantly greater than nominal operating pressures. Subscale tanks replicating these weld geometries are constructed and validated using an automated burst-test system employingAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669nitrogen pressurization, liquid fill masses, flow-restriction orifices, fail-safe solenoid valves, a data-acquisition subsystem, and a programmable controller. The controller executes predetermined pressure-gate sequences and captures synchronized pressure data and high-speed imagery to identify rupture initiation sites and validate structural models. The test data enables refinement of weld geometry, mass-reduction strategies, and full-scale tank development.101891 Friction stir welding (FSW) enables joining of machined plate structures with minimal distortion, consistent weld penetration, and high joint strength. However, traditional tank geometries and T-joint weld configurations introduce stress distributions that cannot be reliably predicted using classical shell analysis. Because weld microstructure, penetration depth, and geometric imperfections can significantly affect burst behavior, subscale testing is required to establish weld knockdown factors and validate finite-element structural models.

[0190] Accordingly, the present disclosure also relates to propellant storage systems for spacecraft and, more specifically, to conformal multi-wall propellant tanks fabricated using friction stir welding of machined aluminum plate structures. The disclosure also relates to automated structural validation systems configured to perform controlled hydro-pneumatic burst testing.

[0191] Burst-test programs typically require specialized hydro-pneumatic facilities. To support rapid, iterative tank development, an automated pressure-test system is disclosed using solenoid valves, a precision pressure regulator, data-acquisition electronics, and programmable control software. Subscale tanks are subjected to controlled internal pressurization while pressure-time data, valve states, and high-speed imagery are recorded. Rupture locations are correlated with stress predictions, weld micrographs, and finite-element models.

[0192] The present disclosure is directed to a spacecraft propellant tank configured to store one or more chemical propellants at substantially lower internal pressures than those required by conventional pressure-fed propulsion systems. By decoupling propellant storage pressure from thruster feed pressure requirements, the disclosed tank enables a combination of structural, geometric, and manufacturing advantages that are not achievable with traditional high-pressure tank designs.

[0193] In one aspect, the propellant tank is configured for operation at internal pressures that are significantly below' those associated with pressure-fed architectures that rely on pressurant gases such as helium. Because the tank is not required to maintain high internalAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669pressure to deliver propellant to downstream propulsion components, the structural requirements imposed on the tank walls, seams, and joints are correspondingly reduced. This allows the tank to be fabricated from lighter, more readily manufacturable materials, including aluminum or aluminum alloys, rather than higher-cost and higher-strength materials such as titanium or composite overwrapped pressure vessels.

[0194] The reduced pressure environment further enables the tank to be formed in non- traditional, conformal geometries that are tailored to the available volume within a spacecraft bus. Unlike spherical or cylindrical pressure vessels that are optimized primarily for uniform stress distribution under high pressure, the disclosed tank may be shaped to conform to surrounding spacecraft structures, panels, or internal cavities. In this manner, the tank maximizes usable propellant volume within a given spacecraft envelope, thereby improving volumetric efficiency and overall system packaging without increasing spacecraft size. Hence, a primary design of the disclosed tank is not necessarily to handle prescribed pressures, but rather to maximize the amount of fuel that can be supplied and carried by a spacecraft. Thus, the benefits of the present disclosure include an ability to generate a lower pressure tank allowing it to be conformal. Furthermore, due to the lower pressure requirement, the disclosed embodiment will not hinder the ability to maneuver, because the disclosed pumps provide the pressure necessary in the absence of a conventional pressure and tank design.

[0195] In certain embodiments, the tank includes one or more welded seams, joints, or interfaces configured to provide structural integrity sufficient for low-pressure operation while meeting applicable safety and qualification requirements for ground handling, launch site operations, and flight. Because the tank is designed for lower internal pressures, welding techniques and joint configurations may be selected to balance strength, manufacturability, and cost, rather than being driven exclusively by extreme pressure containment considerations. This facilitates faster manufacturing schedules and reduces reliance on specialized fabrication processes traditionally associated with high-pressure aerospace tanks.

[0196] The disclosed tank design also provides advantages in terms of mass efficiency and cost reduction. Lower pressure requirements permit thinner wall sections and reduced reinforcement, resulting in a tank that occupies a smaller fraction of the spacecraft mass budget relative to the amount of propellant stored. Additionally, the ability to use widely available materials and simplified manufacturing processes reduces both direct production costs and long lead times, which are common limitations of conventional propellant tank procurement.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0197] In some implementations, the disclosed tank is configured to interface with a propulsion system in which propellant delivery pressure is generated downstream of the tank, such as by one or more pumps or other pressure-generating devices. In such configurations, the tank functions primarily as a storage vessel rather than as a pressure vessel, allowing internal pressure to remain relatively low during operation. However, the invention is not limited to any particular propulsion architecture, and the tank may be employed in a variety of spacecraft systems that benefit from low-pressure, lightweight, and conformal propellant storage.

[0198] The tank may further be configured to participate in thermal management of the spacecraft, including acting as a thermal mass or heat sink. Because propellant tanks typically contain a substantial mass of fluid, the disclosed tank may be arranged to receive, distribute, or moderate thermal energy within the spacecraft, thereby assisting in maintaining propellant and surrounding components within desired temperature ranges. Such thermal interaction may be achieved through conductive coupling, fluid circulation, or other heat transfer mechanisms, without requiring the tank to serve as a high-pressure containment vessel.

[0199] Advantageously, the disclosed tank design addresses safety considerations associated with the storage of energetic propellants. Lower internal pressures reduce the stored energy within the tank, thereby mitigating risks during ground handling and launch site operations. The tank may be qualified through structural testing, including over-pressurization or burst testing, to demonstrate appropriate safety margins relative to its intended operating pressure, while still benefiting from reduced structural demands compared to conventional high-pressure tanks.

[0200] Accordingly, the invention provides a spacecraft propellant tank that departs from traditional high-pressure design paradigms and instead enables low-pressure operation, conformal integration, reduced mass, reduced cost, and improved manufacturability, while remaining compatible with modern spacecraft propulsion and operational requirements.

[0201] The disclosed propellant tank system includes a conformal multi -wall structure defining inner and outer volumes configured for use in pump-fed spacecraft propulsion systems. Turning to FIG. 8, an exemplary tank assembly 800 is illustrated in which it is analyzed against multiple loadcases, including maximum expected operating pressure and launch loading. FIG. 9 illustrates a side view of tank assembly 800 having weld seam 902 disposed along an outer surface 904 thereof. The disclosed conformal multi-wall propellant tank may include an inner wall and outer wall joined by friction stir welded seams includingAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669longitudinal weld seams and T-joint welds. Longitudinal weld seams extend along the interface between machined plate segments, and T-joints connect orthogonal wall panels. Endcaps are attached using additional weld seams, and bolt rings provide attachment for interfaces and fill ports. The tank assembly 800 may be formed by machining aluminum plate components, positioning them in specialized tooling assemblies, and performing controlled FSW operations to produce consistent weld penetration depths and joint profiles. Thus, the tank structure is manufactured from machined aluminum plate sections joined by friction stir welding (FSW), forming longitudinal weld seams and T-joints with geometry corresponding to anticipated flight hardware.

[0202] The disclosed propellant tank may incorporate a conformal multi-wall structure consisting of machined aluminum plate sections joined by friction stir welding. The geometry allows propellant volumes to be integrated efficiently within the spacecraft structure, and the friction stir welded joints provide high structural continuity while reducing manufacturing cost and complexity. The longitudinal weld seams and T-joints are configured to reproduce the expected weld geometry of full-scale tanks, thereby allowing subscale validation of structural performance.

[0203] FSW provides high weld quality and repeatable penetration depth due to the solid-state joining process. As part of the disclosed tank design and manufacturing process, custom tooling may be created and employed to enable these welds to occur in a controlled, repeatable manner. FIG. 10 illustrates multiple pieces of weld tooling which have been proven out during a build of the disclosed tanks. The same jigs (in some cases with minor part swaps to match tank sizing) are used on all talk design phases. This tooling was created in such a way that adapting between tank diameters and lengths can be accomplished by simple part swaps. Thus, for each stage in the progressive design cycle and for the Ranger full-scale tank, the same core weld tooling technology is utilized.

[0204] Weld geometry includes a nugget zone at the center of the tool path and a heat-affected zone surrounding the weld. Weld seam profiles are confirmed using micrographs. Machined tank panels are secured in fixturing tooling assemblies including clamping fixtures, cylindrical rotational fixtures (1044), and guide rails. These tooling structures ensure alignment of the weld path and support plate geometry during joining operations.

[0205] Subscale tanks are fabricated using the same weld parameters, material thicknesses, and geometric features as flight designs. Prior to testing, weld coupons and sectioned jointsAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669are inspected through etching and microscopy, and the tanks undergo leak-check procedures. Following verification, the tanks are integrated into an automated burst-test apparatus.

[0206] The automated burst-test system may include a nitrogen gas source, a regulator, flow-restriction orifices, solenoid valves arranged to pressurize or vent individual tank volumes, and a data-acquisition system configured to log pressure, valve state, and timing information at high rates. A programmable controller executes sequential pressure gates that incrementally increase pressure within the inner or outer volume, depending on test configuration. Deionized water is added to the tank volumes in measured masses to achieve controlled ullage volumes and to maintain the stored energy within prescribed limits. High-speed video cameras positioned around the tank record structural behavior during pressurization.

[0207] During testing, the controller increases pressure until rupture occurs. In one representative test, the inner tank volume withstood more than nine hundred pounds per square inch before rupture initiated at the longitudinal weld seam, followed shortly by the outer wall. Post-test inspection and refined finite-element analysis confirm that the longitudinal weld region — not the T-joint — constitutes the critical location for burst initiation. These results support mass-reduction strategies and confirm that the tank architecture provides ample structural margin relative to operating pressures.

[0208] To validate the structural performance of the tank architecture, subscale tanks are constructed that generally maintain the same weld thicknesses, penetration depths, and material properties as flight designs. These subscale units are subjected to controlled hydro-pneumatic burst testing using a custom-built automated test apparatus featuring computer-controlled solenoid valves, pressure regulators, and synchronized high-rate data acquisition. Thus, in some disclosed embodiments, subscale versions of the tank are constructed and tested using a burst-validation system that includes a nitrogen supply, pressure regulator, flow restriction pressurization and vent solenoids, a burst test stand, and a data acquisition module. A test controller executes sequential pressure-gate steps, providing command traces while pressure transducers measure real-time structural response. High-speed video cameras document weld deformation and rupture onset.

[0209] During testing, the inner and outer tank volumes are filled with deionized water to precise mass targets, ensuring appropriate ullage and safe stored-energy conditions. SequentialAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669pressurization gates are executed, with high-speed video positioned around the tank and pressure instrumentation capturing structural behavior up to rupture.102101 A finite-element structural model including inner wall elements, outer wall elements, weld mesh regions, and symmetry boundaries correlates with weld micrographs showing nugget zones and heat-affected zones. Test results confirm that rupture typically initiates at longitudinal weld seams, enabling refinement of tank geometries and weld parameters.

[0211] A first disclosed test demonstrates that both inner and outer chambers withstand significant internal pressure without bursting. A second disclosed test, pressurizing only the inner chamber, produces a controlled rupture at approximately 942 psig, initiating at the longitudinal weld seam. Post-test inspection and refined finite element analysis correlate failure to predicted stress regions, confirming the conservative strength of T-welds previously believed to be critical.

[0212] These results demonstrate that the tank structure provides significantly greater pressure capacity than required for flight, supporting design optimizations including weight reduction and weld-geometry refinement. The subscale test program establishes validated analytical models for subsequent full-scale tank manufacturing.

[0213] A variety of low-pressure propellant tank configurations may be employed. Such configurations may include separate fuel and oxidizer tanks; multiple fuel tanks and multiple oxidizer tanks; multiple fuel tanks with a single oxidizer tank; multiple oxidizer tanks with a single fuel tank; one or more fuel tanks without an oxidizer tank; or one or more tanks incorporating a common bulkhead that separates fuel and oxidizer volumes. Other combinations and permutations of low-pressure tank architectures may also be used without departing from the scope of the disclosure.

[0214] This application is not directed to, and does not rely upon, any particular implementation details of specific low-pressure propulsion tanks, and the propulsion system described herein may be used in conjunction with a wide range of low-pressure tank designs.

[0215] In some embodiments, the disclosed propulsion system is configured to execute an automated hibernation sequence for bipropellant rocket engine assemblies (REAs) and associated propellant feed systems. FIG. 11 illustrates a flowchart for a hibernation sequence 1100 according to one embodiment of the present disclosure. The purpose of hibernation sequence 1100 is to reduce electrical power consumption associated with heaters of theAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669propulsion system. By evacuating residual propellant from the delta- V bipropellant REAs and their feed lines, the propellant lines may be maintained at a reduced temperature, thereby lowering heater power requirements during extended periods of inactivity.

[0216] In an exemplary embodiment, hibernation sequence 1100 begins 1102 by closing an oxidizer supply isolation valve 1104 to isolate the oxidizer tank from the remainder of the propulsion system. One or more bipropellant REA oxidizer valves are then opened 1106 to vent residual oxidizer contained within the oxidizer pump(s) and associated feed lines to space. After venting is complete, the oxidizer valves of the bipropellant REAs are closed 1108.

[0217] Hibernation sequence 1100 may then include closing a bipropellant fuel tank isolation valve 1110, followed by opening one or more bipropellant REA fuel valves 1112 to vent residual fuel contained within the fuel pump(s) and associated feed lines, or decomposition products thereof, to space. Upon completion of fuel venting, all bipropellant REA fuel valves are closed 1114.

[0218] In certain disclosed embodiments, venting residual propellant enables propellant feed lines and other propulsion system components that are no longer wetted by propellant to be maintained at a reduced temperature. This thermal condition may be advantageous for minimizing parasitic heat loads, limiting component outgassing or degradation, and supporting controlled thermal management of the propulsion subsystem following propellant depletion or system shutdown.

[0219] Following completion of hibernation sequence 1100, the propulsion controller transmits telemetry indicating successful execution of the hibernation procedure 1116.

[0220] In some embodiments, a hibernation sequence may be omitted, for example, when mission duration is relatively short or when the bipropellant propulsion system is expected to be operated frequently. The order and composition of hibernation operations may vary depending on the particular fuel and oxidizer employed, the configuration of the propulsion system, and the specific rocket engine assemblies (REAs) used. Accordingly, numerous variations and permutations of the operational sequence may be implemented without departing from the scope of the disclosure.

[0221] Having described the many embodiments of the present disclosure in detail, it will be apparent that modifications and variations are possible without departing from the scope of the invention defined in the appended claims. Furthermore, it should be appreciated that allAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669examples in the present disclosure, while illustrating many embodiments of the invention, are provided as non-limiting examples and are, therefore, not to be taken as limiting the various aspects so illustrated.EXAMPLESExample 1

[0222] Summary

[0223] The purpose of this test was to demonstrate an end-to-end simulation of a critical orbital maneuver utilizing the prototype Ranger system. The scope of this test covers major hardware / software / infrastructure systems including: a mission simulation of a trans lunar injection (TLI) burn using Ranger Main Engines (RME) as developed in STK SOLIS, MAX flight software running with ODySSy on an engineering model of a Ranger flight computer (cOBC), a development Quantum Propulsion Controller (QPC) based on a set of Arduino microcontrollers, a propulsion FlatSat to simulate the Ranger propulsion system, and ground software sending commands and receiving / storing telemetry. The objective was to utilize these systems together to run the mission sim in an ops-like environment and visualize the test data in real time to represent how the burn may happen in flight.

[0224] Each subsystem had an initial list of goals to accomplish from the test. After running the mission simulation, all major goals were accomplished with areas for future work. The mission simulation sequence ran as expected, with GNC commands being formed and sent to the QPC based on simulated data from ODySSy. The vehicle ephemeris data generated by ODySS Y matched the simulated data from SOLIS showing the burn was executed as expected. The QPC received all commands from the cOBC, actuated the pumps and valves on the propulsion system with minor hiccups, formed telemetry packets with pump speeds and pressure readings, and sent these back to the flight computer at the desired rate. This telemetry data, as w'ell as telemetry from the other systems in flight software was streamed without error to ground software and ingested into a database for storage and visualization of the test data. The entire system also operated electrically and mechanically as expected.

[0225] For future work, running a mission sim that leverages both RMEs as well as ACS thrusters would fully make use of the Propulsion FlatSat and demonstrate more capability of GNC. The QPC needs additional work due to a timing issue with the SPI connection between the Arduino Giga and Arduino Unos, which caused incorrect telemetry data and misdirectedAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669pump commands This can be attributed to the limitations of using Arduino as the initial development unit for the QPC. The shutdown procedure needs to be revised as well to avoid large pressures in the propulsion system upon conclusion of the simulation. For the propulsion FlatSat, using components and interfaces that more accurately reflect flight-like systems would improve system performance and reliability. Overall, this first end-to-end mission simulation with hardware in the loop provided valuable technical progress on Ranger and confirmed the suitability of all the system components.

[0226] Introduction

[0227] The development of the Ranger propulsion system includes a multi-disciplinary engineering team that is testing all portions of the end-to-end system, from mission simulation to ground systems. This provides proof of concept for several aspects of Ranger systems, such as the propulsion system, as well as establishing a discipline testing infrastructure including documentation for utilizing flight and ground software and data flow from flight software to database and visualization tools.

[0228] The scope of this test demonstrated the capability of major components such as:

[0229] • The capability of SOLIS to correctly simulate a burn and provide usable configuration settings (configs) to MAX Flight Software (MAX FSW).

[0230] • The capability of MAX FSW and ODySSy to utilize configs and sequence files provided by SOLIS to accurately simulate a burn modelled in SOLIS and provide telemetry data demonstrating that the burn was accurately simulated.

[0231] • The capability of MAX FSW to interface with and command the development propulsion system and provide telemetry' accurately reflecting its state and behavior.

[0232] • The capability of the electrical systems to safely operate in a lab setting, power all of the hardware without harm to the systems or the operator, and to meet all power requirements of the hardware in question.

[0233] • The capability of the development propulsion system to receive commands from FSW and execute that behavior correctly as well as provide accurate data reflecting the state of the system and valves.

[0234] • The capability of MAX GDS to command FSW, receive telemetry from the system, and push telemetry to data visualization tools.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0235] • The capability of database and data visualization tools (InfluxDB / Grafana) to display test data in real time and provide useful visualizations, as well as store data for later analysis.

[0236] This test was the first attempt to exercise all these capabilities in conjunction with demonstrating the end-to-end operation of the prototype Ranger system. This test establishes the ability of the chosen hardware, software, and infrastructure systems to execute the desired behavior at the desired performance and identifies any issues required for future tests. The success of this test shows that the selected hardware and software can perform at the expected level for Ranger at this stage.

[0237] The following sections of this disclosure are split by subject area. Each subject area includes a description of the goals, the setup, and the results. Issues and results for each area are shown with supporting figures and data.

[0238] Mission

[0239] Goals

[0240] • Run a MAX ODySSy sim on the cOBC EM with QPC in-the-loop.

[0241] * Extract and record telemetry consistent with expected SOLIS simulation results.

[0242] Setup

[0243] -For block diagram, see Ground Software / Operations-

[0244] The mission simulation sequence was developed in STK SOLIS using the latest Quantum-developed Ranger SOLIS build. The simulation was constructed such that Ranger is initialized 5 minutes prior to a TLI burn at Earth perigee which will set up a Lunar flyby five days later. The vehicle is initialized in an orientation near the inertial burn attitude, and reaction wheels are commanded to slew the vehicle the rest of the way. At the burn start epoch, the RMEs are commanded to fire for 248.6 seconds, or until the vehicle has accumulated 40.6 m / sec of Delta- V. During the burn, the LE-144s are throttled down from maximum to control attitude about the X and Y axes. Minimal disturbance is experienced about the Z axis. After the burn, the vehicle propagates for an additional five minutes (or until the test operator shuts off the simulation).

[0245] Once the necessary GNC commands were written into the SOLIS FlightJAS sequence file to perform the above scenario, the SOLIS -generated MAX configuration filesAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669and FlightJAS sequence file were pushed to Gitlab, where they were then retrieved by the FSW lead (Eileen Liu) for integration onto the cOBC, and the Test Conductor / Operations lead (Alex Petit) for inclusion into the test-level FlightJAS sequence file.

[0246] Results

[0247] During the mission simulation, the lead FSW engineer confirmed that the ODySSy simulation was running as expected and that GNC commands to actuate the LE-144 thrusters were being received and interpreted by the QPC, which in turn actuated the corresponding valves and pumps on the hardware FlatSat. After the simulation run, ODY propagated vehicle ephemeris data was extracted and plotted against the “truth” data from SOLIS, visualized below. The expectation, given the same simulation sequence is running in the SOLIS instance of MAX as is executed in the test setup on the cOBC, is that the position and velocity states during the simulation will match exactly. As seen in the images below, the test vehicle position and velocity data (dotted lines) exactly match the truth data from SOLIS (solid lines), indicating that the test vehicle performed the burn as expected. This was further verified through ODySSy propulsion system telemetry, showing LE-144 thrust beginning at the expected sim-time epoch, burning for 248.6 seconds, and shutting off at a sim-time epoch.

[0248] Avionics / EIectrical Systems

[0249] Goals

[0250] The avionics and electrical system are composed of two distinct segments: the avionics FlatSat and the QPC electronics. These two systems are supported by various pieces of GSE such as power supplies and lab computers. The intention is for these systems to reflect a “flight-like” configuration as much as possible to provide ground operators an interface to the system as they would experience it during an actual mission scenario. In practice, the goals of the avionics and electrical systems are to provide power and control over the propulsion FlatSat with as little human intervention as possible. 24V power is provided to the propulsion FlatSat to support expected mission cases of current dissipation, 400mA per active valve and up to 12.5 A per motor when running at their maximum capability. Pump motors are controlled by individual Arduino Unos which provide the PWM signal needed to command a desired spin rate RPM. The Arduinos also ingest pressure transducer analog telemetry. All the individual Arduinos are connected on a common data bus over which telemetry flows to a main controller Arduino. This main Arduino is responsible for accepting commands from the avionics FlatSat, commanding pump speed, actuating valves, and reporting back all pressure and motor speedAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669telemetry to the avionics FlatSat. The targeted rate for telemetry reporting from the propulsion FlatSat to the avionics FlatSat is 5Hz, which is commensurate with the expected hardware limitations of the Arduinos.

[0251] The avionics FlatSat is based on a form, fit, and function engineering model of the Beyond Gravity cOBC. The cOBC is powered directly through its flight interface at the nominally expected 28V bus voltage and is expected to fall within its nominal current draw of 700mA. To interface with the ground operators, the cOBC’s debug port is accessed through the provided Debug Adapter Board (DAB) and connected to an unmanaged ethernet switch. This ethernet switch also interfaces to a lab PC and the Quantum network through which the ground operators interact with the cOBC. Using one of the flight data connectors, the cOBC communicates with the propulsion FlatSat over an RS485 interface, which reflects what will be used in future iterations of the QPC.

[0252] Setup

[0253] FIG. 14 show's a summary' of the electrical connections within the propulsion system. It show's how various components, including pumps, valves, controllers, and sensors, are powered and connected. The system includes several 24V power supplies, analog and digital signal interfaces, and control links like SPI and RS485. The QPC is the main controller for the pumps and valves, while also communicating with the cOBC in the Avionics FlatSat. A lab PC is also connected to the QPC for debug, though this w'as not needed during the test.

[0254] FIG. 15 illustrates the physical connections between the flight and ground avionics systems. It depicts how key components, such as the Lab PC, power supply, and Prop Flatsat, are interconnected via Ethernet, RS485, and USB. The power control unit receives a 28V supply, distributing power to critical components like the onboard computer (cOBC) and propulsion systems, while Ethernet links enable communication between the Lab PC, network switch, and other subsystems. This setup ensures coordinated operation and communication between ground and flight systems.

[0255] Results

[0256] The hardware in the loop mission simulation was able to run successfully through the full chain from ground operator and MOC through individual pump controllers and valve switches. Some system imperfections and anomalies were present in the run-for-record test and can be observed in some of the data analysis provided by other disciplines. These are reflectiveAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669of the hardware limitations inherent to the Arduinos used for the Propulsion Controller. The primary' communication interface between the main Arduino Giga and the distributed Arduino Unos is SPI, typically used to communicate over short copper traces between PCB level components such as FPGAs and. ADCs. This was chosen because of the immediate availability and support on the Arduinos and the speed at which software development could continue. To improve system performance and reliability, the hardware that is more reflective of flight like systems using interfaces such as CAN or RS485 would need to be integrated into the propulsion FlatSat.

[0257] Ground Software / Operations

[0258] Goals

[0259] • MAX GDS runs commands / sequences during simulation to execute critical events.

[0260] sTelemetry is visualized in Grafana in real-time during the simulation, at Grafana’ s native rate.

[0261] * Backorbit telemetry (recorded telemetry stored onboard that can be downlinked after the fact) is downloaded providing higher rate data than the live telemetry stream.

[0262] Setup

[0263] FIG. 16 provides an overview of the cOBC / MAX connections. It illustrates how the onboard computer (cOBC) runs the MAX flight software, which handles mission simulations including GNC and propulsive maneuvers. Commands are sent from the cOBC to the Prop Flatsat to control valves and pumps. Additionally, mission data is collected via InfluxDB and visualized in Grafana, while the MAX GDS interfaces with the system to provide ground data services. Ranger’s configuration and flight sequence information are managed through SOLIS, ensuring version control and accurate mission execution.

[0264] Results

[0265] • MAX GDS was successfully used to command the FlatSat to run the simulation.

[0266] • Telemetry' was visualized in Grafana in real-time during the simulation.

[0267] * Backorbit telemetry was not downlinked during this test run, but capability was tested and proven at a different time.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0268] • To retroactively deal with bad telemetry from SPI interface (See Flight Software results), filtering could be applied to the data to remove aberrant values.

[0269] sThe ideal resolution to the bad telemetry and commanding caused by the SPI interface would be the hardware upgrade path detailed in the Avionics / EPS section. If the situation was such that a hardware upgrade was not an option (such as in flight), then ops would work with flight software to develop a satisfactory workaround to the problem.

[0270] Flight Software

[0271] Goals

[0272] * Prop controller receives commands and sends telemetry correctly.

[0273] * Prop system runs pumps at desired speeds and reads pressures and speeds accurately.

[0274] • FSW converts GNC outputs into commands to the prop system correctly.

[0275] * FSW sends commands and produces telemetry from prop sy stem in real time.

[0276] sTelemetry is consistent with expected SOLIS simulation results.

[0277] sAll software runs without errors beyond pre-declared / expected errors.

[0278] Setup

[0279] FIG. 17 illustrates the propulsion system setup with the QPC and pump controllers interfacing with the cOBC EM and FlatSat through UART. A lab computer was hooked up to the QPC through a USB connection for debug purposes as well as recording telemetry data. This was not used during the test.

[0280] FIG. 18 illustrates flight and ground software connections according to one embodiment of the present disclosure. The operator accesses the lab computer via a remote desktop session. The lab computer is aliased to qs-lab04.quantumspace.us and is a Windows computer physically located next to the propulsion hardware. The lab computer qs-lab04 is also physically connected to the hardware through the wall The cOBC EM has the IP address 172,18.100.115, but in this test is typically only accessed through a direct serial connection to the lab computer. The lab computer qs-lab04 also contains the interface which is used to power the cOBC. The operator accesses MAX GDS via the virtual machine addressed at qs-Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669maxOl. quantum space, us. The virtual machine qs-max01 is an Ubuntu / Linux machine which is used to host MAX GDS and associated services (InfluxDB / Grafana).

[0281] Assumptions

[0282] Expected errors are:

[0283] I. Upon MAX boot, the terminal will print an error that the DSW did not initialize properly. This is expected and only occurs because the remote TTR side did not initialize, which is not being used at the moment.

[0284] 2. Sometimes and only if the QPC debug messages are disabled, some interface errors are printed by the QPC driver indicating malformed messages. This is expected and will be resolved.

[0285] 3. The SPI interface between the Arduino Giga and Arduino Unos sometimes delivers incorrect, messages, which can set a pump to an undesired voltage, or produce an incorrect telemetry' point.

[0286] 4. ODySSy sets all thrusters to full thrust at sim startup, so the QPC will throw an error since it starts in safe mode. This also causes two of four RMEs to not receive any more voltage commands.

[0287] Results

[0288] All expected, flight software behavior was observed in the test run. When the TLIBum raw sequence was run, the burn sequence began at the correct spacecraft clock time and FSW began commanding the prop system at that. time. Actuation of all RMEs was observed, which was all commanded from FSW due to the execution of the sequence. FSW reported all telemetry as expected which reflected the state of the prop hardware and the expected GNC behavior according to the simulation state. The GNC / position telemetry data matching the SOLIS sim was verified by the SME (Collin Deans). The analysis showing this successful result is shown in FIG. 12 and FIG. 13. A backorbit dump of telemetry was not completed. No errors occurred other than expected errors which are recorded in the Assumptions section.

[0289] The QPC had a few' minor problems during the test run. Occasionally an aberrant data point would come through the telemetry for a pressure reading or pump speed reading. This was expected and likely due to mistiming of SPI transmissions between the QPC and theAttorney Docket No.: 118717-25169WO01 / Customer No.: 1106699 pump controllers. This SPI issue also caused a few pump controllers to receive a command to set the pump to 0V mid-run. These behaviors can be seen in FIG. 19, showing the resulting pressures from the pumps dropping speed for a short period. Other than the SPI issues, the prop system ran smoothly. All 8 delta- V pumps were ran, and telemetry was streamed at 5Hz to the cOBC EM. The QPC transitioned through nominal ready mode to the bootstrap sequence to delta- V mode and shutdown back to nominal ready mode without error.102901 Mechanical / Propulsion Systems

[0291] Goals

[0292] 1. Demonstrate simultaneous command and actuation of propulsion system sensors and effectors including four RME stand-in assemblies (BLDC-driven gear pumps and NC solenoid valves), ACS circuit (single BLDC-driven gear pump and ACS thruster stand-ins) and feed system pressure transducers and solenoid valves.

[0293] 2. Demonstrate system pressure ramp-up ‘bootstrapping’ process for RME fuel and oxidizer segments.

[0294] 3. Demonstrate (coarse, open-loop) rpm synchronization across RME pump sets (operating point output pressures between 300-400 psi ).

[0295] 4. Record pump performance telemetry to inform an initial LUT / cal for closed- loop control.

[0296] 5. All pumps track commands (within reaction time of the pump, -100ms).

[0297] Setup

[0298] FIG. 20 illustrates a diagram of an exemplary propulsion FlatSat fluid system according to one embodiment of the present disclosure. The fluid system of the Block 1 propulsion FlatSat contained representative components for 4 Ranger Main Engines, an ACS circuit, and a fluid feed system. Each Ranger Main Engine subassembly comprised a pair of COTS BLDC-driven gear pumps (one for fuel, one for oxidizer), series-redundant solenoid valves, and pump output pressure transducers and gauges. The ACS thruster circuit (of one pump and 12 representative thrusters) and four additional pressure transducers, though inactive for this mission sim, did return data and were electrically and fluidically attached to the system.

[0299] AssumptionsAttorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0300] • Pump PP-F009 was not used in this test, so the speed value does not reflect its actual state.

[0301] sThe pressure transducers are not per-unit calibrated or at runtime, so each transducer carries its own offset, and true absolute pressures were not measured.

[0302] * Some pump-to-pump speed variability when commanded by the same voltage would occur.

[0303] • Occasional pressure transducer spikes and pump Ov commands (see flight software assumptions)

[0304] sPumps PP-F005, PP-M006, PP-F007 and PP-M008 did not receive portions of the command sequence.

[0305] * Each RME subassembly suffered flow restrictions and increased pressure drops, with hard water deposits and hard water corrosion likely to blame. FIG. 21 graphically illustrates pump speed and outlet pressure vs time according to one embodiment of the present disclosure.

[0306] FIG. 21 graphically illustrates pump speed and outlet pressure vs time according to one embodiment of the present disclosure. FIG. 22 graphically illustrates measured pump speed (filtered) vs time according to one embodiment of the present disclosure. In FIG. 22, the pump speed is the pump speed returned by Arduino Unos of Dev Propulsion Controller during mission sim script. NOTE: post-processing filters eliminating most aberrant samples are applied.

[0307] After multiple run-throughs to develop control algorithms, transducer calibrations and fluid system procedures, the run for Mission Sim 1 showed all RME and ACS pumps were commanded and reacted as expected, and fluid system sensors were read & telemetry recorded (MECH-PROP objective 1 above). ‘As expected’ behavior in this case includes zero rpm commanded ACS pump speed and that the 8 RME pumps were simultaneously commanded to full thrust (see flight software section). However, despite pressure data to show that the ACS circuit did not become pressurized, and no noise, vibration or other indication of ACS pump spin were observed in person at any time during the test, telemetry' shows the ACS pump measured speed to be approximately 2500rpm the entire time the Dev Propulsion Controller is powered on.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0308] A typical bum would incorporate a deliberate and carefully timed sequence to segment and fluid circuit up to operating pressures. The disclosed prototype sequence would normally first start with the ACS pump spinning up to pressurize the ACS circuit prior to engine ignition (for pose or settling maneuvers, for instance). However, in the case of this mission script, the fluid system bootstrapping sequence only included the fuel and oxidizer pumps from each RME subassembly for simplicity. The intended timings for this test are as follows (where T-0 is the start of the mission sequence & Delta- V maneuver):

[0309] • T+2.5 - all RME pumps commanded to 4V (3300rpm expected pump speed, open loop).

[0310] • T+2.25 - all thruster valves commanded open.

[0311] • T-0 - Mission sim start. Dev Propulsion Controller begins accepting commands from the flight computer.

[0312] However, due to variability in the time required for each pump controller (Arduino Uno) to boot up, and because the flight computer only sends fresh pump speed commands to alter pump speed, some pumps did not receive portions of this command sequence and did spin up to full speed. Namely, PP-F005, PP-M006, PP-F007 and PP-M008 did not spin up past the first commanded 3000rpm of the bootstrapping process as shown in FIG. 23. In FIG. 23, measured pump speed is the measured pump speed showing bootstrapping and handover. NOTE: Line discontinuities are due to post-test filtering of the data.

[0313] Additionally, over the course of the test campaign, a test abort capability was added and initially demonstrated. This abort mode removes power from the pump motors, while keeping telemetry and local data logging in place, allowing for onsite hardware issues or concerns related to the pumps to be immediately mitigated. Future work here may incorporate a power-off safe state, wherein all fluid valves (including propellant source isolation valves) could be deenergized and result in a known-safe state with a single emergency stop device, and would include the replacement of all manual hand-actuated valves with electrically actuated valves such that no fluid control device could remain in an unknown or unsafe state in the event of an abort (either commanded or manually triggered via e-stop).

[0314] During preparation for the run-for-record, each RME subassembly suffered growing flow restrictions and increased pressure drop that was ultimately resolved by removing return filters downstream of each set of firing valves and removing check valve cores on pumps PP-Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669M002 and PP-F007. In future, the system may be cleaned and demineralized, and only run with deionized water, as hard water deposits and hard water corrosion were to blame for the complete blockage of these filters.

[0315] Some bugs persist within the Dev Propulsion Controller, including intermittent 0V speed commands delivered mid-burn due to SPI issues between the Arduino Uno pump controllers and the Arduino Giga primary microcontroller (plotted in FIG. 24 wherein pump speed dips from inadvertent 0V / Orpm commands between elements of the Dev Propulsion Controller Conclusions and Recommendations). Similar issues caused pressure spikes (errant pressure samples) where either noise on the bus or other microcontroller conflicts caused single-sample readings to exceed 2500psig. Additionally, visible chatter and unsteady pressure showed on the manual gauges downstream of the pumps but was rapid enough to be aliased and not recorded in telemetry'.

[0316] This first end-to-end mission sirn test has given the engineering team valuable insight as to how? each subsystem comes together on Ranger, from operations to hardware and software. The technical progress made through this test also helped confirm the feasibility and suitability of each component as part of a bigger system. All the main objectives for this test were successfully met, with some areas for future work.

[0317] Further work is required to fully meet MECH-PROP objectives 2, 3 and 4. The pressure bootstrapping process was not fully leveraged in this test, as the ACS thrusters and fluid circuit were left idle (MECH-PROP obj. 2).

[0318] Future work to improve the fidelity of the data returned from the fluid system should include higher rate data acquisition (on the order of several hundred Hz sample rate), and tighter timing of sensor sampling (end-to-end propulsion sensor sample rate had a standard deviation of 54Hz, and a standard deviation of 0.78Hz after outlier filtering - population distributions shown in FIG, 25 (showing Dev Propulsion Controller sample rate histograms).

[0319] Depending on specific flight software development goals, it may also be beneficial to adopt a "black-box data recorder’ approach to tests, where the FSW and flight computer are free to record and manipulate a subset of all sensor data from the onboard system, but a separate GSE added to capture all sensor data and bus traffic (e.g capturing mod-demod issues across SPI and UART or SPI dropouts) as a full diagnostic capture of the system under test. This would also allow' for sample rate to be independently set (significantly higher) from onboard processor and bus bandwidth.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0320] Though the Dev Propulsion Controller followed its canned command sequence for pressure build (referred to as a ‘bootstrapping’ sequence), limitations in ODySSy sim behavior resulted in these commands being only partially received - namely that the flight software only sends asynchronous thrust commands to the QPC to indicate a change in thrust. Since the thrust was statically set for the duration of this sim, after the first set of thrust commands were sent (and rejected by the Dev Prop Controller as it was still bootstrapping), no further updates were sent. This shows that incorporating exact commands and command structures in the saved test data remains an area of future improvement for ground tests, as well as bootstrapping-to-main- computer handover as an area of future demonstration.

[0321] Pump acceleration (ramp up, ramp down) control along with speed control is also likely necessary, as the system shutdown sequence used in this test was abrupt. The current shutdown sequence simultaneously commands all pumps to 0V (Orpm) and all thruster valves closed, leading to extremely high (600 – 1000psi) pressure spikes in the trapped volume downstream of the pump outlets and upstream of the thruster valves as the pumps spin down against dead-headed valves. Instead, commanding each fluid component in upstream-downstream sequence to shut down or deactivate would be a first-pass improvement. Pump acceleration (i.e. rate of change of rpm speed), over the course of more than a pair of commands (a series of speeds between full rpm and zero rpm on the order of 250ms), will benefit pump and valve life, and likely be necessary in flight to ensure proper start conditions for repeat burns.

[0322] In addition, despite commanding the same voltage be sent to each pump, the measured pump speed achieved an average dispersion of 10.1 rpm over a deviation of + 103.76 / -263.89 rpm for the pumps successfully receiving commands from the flight computer over the duration of the test (PP-[F001, M002, F003, M004, M008]). FIG. 26 illustrates a nested feedback loops from a pump motor driver to a propulsion controller according to one embodiment of the present disclosure. The test goals acknowledged that only a coarse rpm synchronization could be achieved with an open-loop setup, and this will likely be resolved with per-pump calibration and mapping of inlet pressure vs rpm vs outlet pressure, and ultimately pump output pressure closed-loop control in the next iteration of QPC.

[0323] All documents, patents, journal articles and other materials cited in the present application are incorporated herein by reference.Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669

[0324] While the present disclosure has been disclosed with references to certain embodiments, numerous modification, alterations, and changes to the described embodiments are possible without departing from the sphere and scope of the present disclosure, as defined in the appended claims. Accordingly, it is intended that the present disclosure not be limited to the described embodiments, but that it has the full scope defined by the language of the following claims, and equivalents thereof.

Claims

Attorney Docket No.: 118717-25169WO01 / Customer No.: 110669WHAT IS CLAIMED IS:

1. A thermal management system for a spacecraft, comprising:one or more heat-generating components of the spacecraft that dissipate heat during a propulsion event;one or more components of the spacecraft having heat capacity to absorb waste heat from propulsion system operations;one or more thermal transport elements thermally coupled to the one or more components of the spacecraft having heat capacity to absorb waste heat; and thermal insulation disposed about at least a portion of the spacecraft,wherein the thermal management system is configured to transfer waste heat generated by the one or more heat-generating components to the one or more components of the spacecraft having heat capacity to absorb waste heat during propulsion operation to maintain spacecraft components within allowable operating temperature limits.

2. The thermal management system of claim 1, wherein the one or more thermal transport elements comprise one or more constant conductance heat pipes.

3. The thermal management system of claim 2, wherein the constant conductance heat pipes comprise extruded aluminum heat pipes, copper-water heat pipes, diode heat pipes and / or variable conductance heat pipes.

4. The thermal management system of claim 1, wherein the one or more thermal transport elements comprise conductive heat spreaders integrated into the spacecraft.

5. The thermal management system of claim 1, wherein a component of the spacecraft having thermal capacity to absorb w'aste heat from the propulsion system is configured to function as a transient thermal sink during propulsion maneuvers.

6. The thermal management system of claim 1, wherein the thermal insulation comprises multi-layer insulation (MLI) blankets disposed over portions of the spacecraft exterior.Attorney Docket No.: 118717-25169WO01 / Customer No.: 1106697. The thermal management system of claim 6, wherein different regions of the spacecraft employ different MLI constructions based on operating temperature and environmental exposure.

8. The thermal management system of claim 1, further comprising at least one radiator thermally coupled to the spacecraft structure and configured to reject heat to space.

9. The thermal management system of claim 8, wherein the radiator includes a coating selected from Z93 white paint, optical solar reflectors, silver Teflon (AgTef), phase change materials.

10. The thermal management system of claim 1, further comprising one or more electrical heaters controlled by redundant mechanical thermostats or software controlled heaters.

11. The thermal management system of claim 10, wherein the thermostats are wired in series to prevent over-temperature conditions in the event of a thermostat failure.

12. The thermal management system of claim 1, further comprising one or more software controlled electrical heaters.

13. The thermal management system of claim 12, wherein the one or more software controlled electrical heaters employ one or more temperature sensors and a computer algorithm using temperature sensor data as feedback in a heater control loop.

14. The thermal management system of claim 1, wherein one or more propulsion feed lines are thermally isolated from the spacecraft structure and insulated using multilayer insulation.

15. The thermal management system of claim 1, wherein the thermal management system is configured to operate during both ground testing and on-orbit operation without reconfiguration of the thermal transport elements that are not actively pumped.

16. The thermal management system of claim 15, wherein the thermal transport elements are not actively pumped.Attorney Docket No.: 118717-25169WO01 / Customer No.: 11066917. The thermal management system of claim 1, wherein the one or more heat¬ generating components of the spacecraft includes a propellant pump, a pump motor controller, a propulsion controller, propulsion electronics, or propulsion subsystem components.

18. The thermal management system of claim 17, wherein the propulsion subsystem components include sensors used to monitor propulsion system health, flow control devices, or filters.

19. The thermal management system of claim 1, wherein the one or more heat¬ generating components of the spacecraft includes a propellant tank, a propellant volume, spacecraft support structures, or other spacecraft components benefiting from thermal power input.

20. The thermal management system of claim 1, wherein pumped fluid is routed through one or more heat exchangers thermally coupled to the one or more heat¬ generating components of the spacecraft to absorb waste heat.

21. The thermal management system of claim 1, further comprising a variable¬ emittance element for adaptive heat rejection.

22. The thermal management, system of claim 21, wherein the variable-emittance element comprises a radiative louver or other emissivity control device.

23. A method of managing thermal energy in a spacecraft, comprising:generating waste heat from one or more components of the spacecraft that have heat dissipation during a propulsion event;transporting the waste heat from one or more propulsion components to another one or more components of the spacecraft having heat capacity to absorb waste heat from propulsion system operations using one or more thermal transport elements, andthermally insulating the spacecraft to reduce environmental heat exchange during the propulsion event.Attorney Docket No.: 118717-25169WO01 / Customer No.: 11066924. The method of claim 23, wherein transporting the waste heat comprises transporting heat using constant conductance heat pipes or other transport devices not requiring an actively pumped working fluid.

25. The method of claim 23, further comprising rejecting a portion of the absorbed heat to space through one or more radiators after completion of the propulsion event.

26. The method of claim 23, further comprising controlling electrical heaters using redundant mechanical thermostats or via software control to maintain components above minimum allowable temperatures.

27. The method of claim 23, wherein the method is performed during thermal-vacuum ground testing and during on-orbit operation without modification to the thermal transport architecture.

28. A spacecraft system, comprising:one or more heat-generating components of the spacecraft system that dissipate heat during a propulsion event;a thermal management subsystem including thermal transport elements coupling the one or more heat-generating components to one or more components of the spacecraft system having heat capacity to absorb waste heat from propulsion system operations; anda spacecraft controller configured to monitor temperature telemetry and coordinate heater operation,wherein the thermal management subsystem absorbs propulsion-generated waste heat in the one or more components of the spacecraft system having heat capacity to absorb waste heat while the spacecraft controller maintains system temperatures within predetermined limits.

29. The spacecraft system of claim 28, wherein the controller is further configured to transmit thermal telemetry to a spacecraft flight computer.

30. The spacecraft system of claim 28, wherein heater activation is inhibited during propulsion events to prioritize heat absorption by the one or more components of the spacecraft system having heat capacity to absorb waste heat.Attorney Docket No.: 118717-25169WO01 / Customer No.: 11066931. The spacecraft system of claim 28, wherein the thermal management subsystem includes thermal transport elements that are not actively pumped configured to permit thermal transport during both flight and ground testing.

32. The spacecraft system of claim 31, wherein the thermal transport elements are not actively pumped.

33. A non-transitory computer-readable medium storing instructions that, when executed by a spacecraft controller, cause the controller to:monitor temperature data from one or more components of a spacecraft that have heat dissipation during a propulsion event;coordinate operation of electrical heaters based on the monitored temperature data; and manage spacecraft thermal conditions in cooperation with a thermal management architecture that transfers propulsion-generated waste heat to one or more components of the spacecraft having heat capacity to absorb waste heat from a propulsion system operation.