In the field of rocketry, range safety may be assured by a system which is intended to protect people and assets on both the rocket range and downrange in cases when a launch vehicle might endanger them. For a rocket deemed to be off course, range safety may be implemented by something as simple as commanding the rocket to shut-down the propulsion system or by something as sophisticated as an independent Flight Termination System (FTS) that has redundant transceivers in the launch vehicle that can receive a command to self-destruct then set off charges in the launch vehicle to combust the rocket propellants at altitude. Not all national space programs utilize flight termination systems on launch vehicles.
In the United States, Range safety is usually the responsibility of a Range Safety Officer (RSO) affiliated with either the civilian space program led by NASA or the military space program led by the Department of Defense, through its subordinate unit the Air Force Space Command. At NASA, the range safety goal is for the general public to be as safe during range operations as they are in their normal day-to-day activities.
RSOs are also present in the hobby of model rocketry. In this case, they are usually responsible for ensuring a rocket is built correctly, using a safe engine/recovery device, and launched correctly.[not verified in body]
Some launch systems use flight termination for range safety. In these systems the RSO can remotely command the vehicle to self-destruct to prevent the vehicle from traveling outside prescribed safety zone. This allows as-yet unconsumed propellants to combust at altitude, rather than upon the vehicle reaching the ground.
Space vehicles for sub-orbital and orbital flights from the Eastern and Western Test Ranges were destroyed if they endangered populated areas by crossing pre-determined destruct lines encompassing the safe flight launch corridor. To assist the RSO in making a flight termination decision, he had many indicators showing the condition of the space vehicle in flight. These included booster chamber pressures, vertical plane charts (later supplanted by computer-generated destruct lines), and height and speed indicators. Supporting the RSO for this information were a supporting team of RSO's reporting from profile and horizontal parallel wires used at lift-off (before radar could capture the vehicle) and telemetry indicators. After initial lift-off, flight information is captured with X and C-band radars, and S-Band telemetry receivers from vehicle-borne transmitters. At the Eastern Test Range, S and C-Band antennas were located in the Bahamas and as far as the island of Antigua, after which the space vehicle finished its propulsion stages or is in orbit. Two switches were used, ARM and DESTRUCT. The ARM switch shut down propulsion for liquid propelled vehicles, and the DESTRUCT ignited the primacord surrounding the fuel tanks. In the case of manned flight, the vehicle would be allowed to fly to apogee before the DESTRUCT was transmitted. This would allow the astronauts the maximum amount of time for their self-ejection. During the early days of space flight (Minute Man, Polaris, Poseidon, Atlas Agenas, Thor Deltas, etc.) there were a number of destruct actions, including the Orbiting Astronomical Observatory (OAS) aboard an Atlas Agena. A less destructive type of range safety system allows the RSO to remotely command the vehicle to shut down its propulsive rocket engines. The thrust termination concept was proposed for the Titan III-M launch vehicle which would have been used in the Manned Orbiting Laboratory program.
Rockets are usually launched into a space above the launch range called the launch corridor. If rocket engines fail while the rocket flies inside the corridor, the rocket falls in an uninhabited area. Engine failure outside the launch corridor may cause the rocket to fall on people or property. Therefore if the rocket is about to exit the launch corridor, the RSO will terminate powered flight to ensure that no debris falls outside the launch corridor. This involves sending coded messages (typically sequences of audio tones, kept secret before launch) to special redundant UHF receivers in the various stages or components of the launch vehicle. On receipt of an 'arm' command, liquid-fueled rocket engines are shut down. A separate 'fire' command detonates explosives, typically linear shaped charges, to cut the propellant tanks open and disperse their contents.
Solid-fuel rockets cannot be shut down, but cutting them open terminates thrust even though the propellant will continue to burn.
Reliability is a high priority in range safety systems, with extensive emphasis on redundancy and pre-launch testing. Range safety transmitters operate continuously at very high power levels to ensure a substantial link margin. The signal levels seen by the range safety receivers are checked before launch and monitored throughout flight to ensure adequate margins. When the launch vehicle is no longer a threat, the range safety system is typically safed (shut down) to prevent inadvertent activation. The S-IVB stage of the Saturn 1B and Saturn V rockets did this with a command to the range safety system to remove its own power.
|This section requires expansion. (March 2014)|
Range safety concerns are addressed in a variety of ways by the various countries involved with launch vehicle and guided missile technology.
Eastern and Western Ranges
For launches from the Eastern Range, which includes Kennedy Space Center and Cape Canaveral Air Force Station, the Mission Flight Control Officer (MFCO) is responsible for ensuring public safety from the vehicle during its flight up to orbital insertion, or, in the event that the launch is of a ballistic type, until all pieces have fallen safely to Earth. Despite a common misconception, the MFCO is not part of the Safety Office but, rather is part of the Operations group of the Range Squadron of the 45th Space Wing of the Air Force, and who is considered a direct representative of the Wing Commander. The MFCO is guided in making destruct decisions by as many as three different types of computer display graphics, generated by the Flight Analysis section of Range Safety. One of the primary displays for most vehicles is a vacuum impact point display in which drag, vehicle turns, wind, and explosion parameters are built into the corresponding graphics. Another includes a vertical plane display with the vehicle’s trajectory projected onto two planes. For the Space Shuttle, the primary display a MFCO used is a continuous real time footprint, a moving closed simple curve indicating where most of the debris would fall if the MFCO were to destroy the Shuttle at that moment. This real time footprint was developed in response to the Space Shuttle Challenger disaster in 1986 when stray solid rocket boosters unexpectedly broke off from the destroyed core vehicle and began traveling uprange, toward land.
Range safety at the Western Range (Vandenberg Air Force Base in California) is controlled using a somewhat similar set of graphics and display system. However, the Western Range MFCOs fall under the Safety Team during launches, and they are the focal point for all safety related activities during a launch.
Range safety in US manned spaceflight
Even for U.S. manned space missions, the RSO has authority to order the remote destruction of the launch vehicle if it shows signs of being out of control during launch, and if it crosses pre-set abort limits designed to protect populated areas from harm. The U.S. space shuttle orbiter did not have destruct devices, but the solid rocket boosters (SRBs) and external tank both did.
After the Space Shuttle Challenger broke up in flight, the RSO ordered the uncontrolled, free-flying SRBs destroyed before they could pose a threat.
Despite the fact that the RSO continues work after Kennedy Space Center hands over control to Mission Control at Johnson Space Center, he or she is not considered to be a flight controller. The RSO works at the Range Operations Control Center at Cape Canaveral Air Force Station, and the job of the RSO ends when the missile or vehicle moves out of range and is no longer a threat to any sea or land area (after completing First Stage Ascent).
Autonomous flight termination
Commercial spaceflight firm SpaceX has been developing an autonomous flight termination system, one where the computer control system on the vehicle itself makes the determination to terminate an off-nominal flight without any human-in-the-loop monitoring with manual implementation of a flight termination command. This system has been included in the prototype development vehicle SpaceX uses to test its reusable rocket technology development program.
In the event, the autonomous system was first tested in August 2014 on the F9R Dev1 prototype booster when the test vehicle had a flight anomaly in a test flight and the vehicle control system issued a command to terminate, and the vehicle self-destructed in the air over the designated test area near McGregor, Texas.
- "NASA Range Safety Overview". NASA.
- "s Shuttle Lifts Off, NASA Will Man Destruct Switch—Just in Case". Popular Mechanics.
- RSO report
- "Report of the PRESIDENTIAL COMMISSION on the Space Shuttle Challenger Accident - Chapter IX: Other Safety Considerations". NASA.
- Saturn V Launch Vehicle Flight Evaluation Report AS-502 Apollo 6 Mission. NASA George C. Marshall Space Center. June 25, 1968.
- "SpaceX makes late call to delay ASIASAT-6 launch". nasaspaceflight.com. 2014-08-26. Retrieved 2014-08-27. "the demise of the F-9R Dev-1 ... provided what is understood to be a first, specifically the first U.S. autonomous Range Safety event, as the test vehicle capably ended her own life – despite not using the more extensive version of the Flight Termination System (FTS) that Falcon 9 v1.1′s can utilize during launches out of Cape Canaveral and Vandenberg Air Force Base."
- "45th Space Wing/Patrick Air Force Base Launch Site Safety Assessment" (PDF). June 8, 2002.
- This article includes an explanation of the Space Shuttle's Range Safety System