Search NASA⌕ Search

SEARCH · Search NASA

Results for “fail operational”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Current CFD Practices in Launch Vehicle Applications

The quest for sustained space exploration will require the development of advanced launch vehicles, and efficient and reliable operating systems. Development of launch vehicles via test-fail-fix approach is very expensive and time consuming. For decision making, modeling and simulation (M&S) has played increasingly important roles in many aspects of launch vehicle development. It is therefore essential to develop and maintain most advanced M&S capability. More specifically computational fluid dynamics (CFD) has been providing critical data for developing launch vehicles complementing expensive testing. During the past three decades CFD capability has increased remarkably along with advances in computer hardware and computing technology. However, most of the fundamental CFD capability in launch vehicle applications is derived from the past advances. Specific gaps in the solution procedures are being filled primarily through "piggy backed" efforts.on various projects while solving today's problems. Therefore, some of the advanced capabilities are not readily available for various new tasks, and mission-support problems are often analyzed using ad hoc approaches. The current report is intended to present our view on state-of-the-art (SOA) in CFD and its shortcomings in support of space transport vehicle development. Best practices in solving current issues will be discussed using examples from ascending launch vehicles. Some of the pacing will be discussed in conjunction with these examples.

Kwak, Dochan↗

ISS Charging Hazards and Low Earth Orbit Space Weather Effects

Current collection by high voltage solar arrays on the International Space Station (ISS) drives the vehicle to negative floating potentials in the low Earth orbit daytime plasma environment. Pre-flight predictions of ISS floating potentials Phi greater than |-100 V| suggested a risk for degradation of dielectric thermal control coatings on surfaces in the U.S. sector due to arcing and an electrical shock hazard to astronauts during extravehicular activity (EVA). However, hazard studies conducted by the ISS program have demonstrated that the thermal control material degradation risk is effectively mitigated during the lifetime of the ISS vehicle by a sufficiently large ion collection area present on the vehicle to balance current collection by the solar arrays. To date, crew risk during EVA has been mitigated by operating one of two plasma contactors during EVA to control the vehicle potential within Phi less than or equal to |-40 V| with a backup process requiring reorientation of the solar arrays into a configuration which places the current collection surfaces into wake. This operation minimizes current collection by the solar arrays should the plasma contactors fail. This paper presents an analysis of F-region electron density and temperature variations at low and midlatitudes generated by space weather events to determine what range of conditions represent charging threats to ISS. We first use historical ionospheric plasma measurements from spacecraft operating at altitudes relevant to the 51.6 degree inclination ISS orbit to provide an extensive database of F-region plasma conditions over a variety of solar cycle conditions. Then, the statistical results from the historical data are compared to more recent in-situ measurements from the Floating Potential Measurement Unit (FPMU) operating on ISS in a campaign mode since its installation in August, 2006.

Minow, Joseph↗

Evaluation of Technologies to Prevent Precipitation During Water Recovery from Urine

The International Space Station (ISS) Urine Processor Assembly (UPA) experienced a hardware failure in the Distillation Assembly (DA) in October 2010. Initially the UPA was operated to recover 85% of the water from urine through distillation, concentrating the contaminants in the remaining urine. The DA failed due to precipitation of calcium sulfate (gypsum) which caused a loss of UPA function. The ISS UPA operations have been modified to only recover 70% of the water minimizing gypsum precipitation risk but substantially increasing water resupply needs. This paper describes the feasibility assessment of several technologies (ion exchange, chelating agents, threshold inhibitors, and Lorentz devices) to prevent gypsum precipitation. The feasibility assessment includes the development of assessment methods, chemical modeling, bench top testing, and validation testing in a flight-like ground UPA unit. Ion exchange technology has been successfully demonstrated and has been recommended for further development. The incorporation of the selected technology will enable water recovery to be increased from 70% back to the original 85% and improve the ISS water balance.

Broyan, James L., Jr.↗

A CLIPS prototype for autonomous power system control

The model of the system assumes a constant power source and loads (experiments) whose power demands exceed the supply. Experiments are described by their name, power consumption, time for a complete run, present status and the state of the load. The power consumption of each load is set at a constant level but can be dynamically modified by the operator. The status specifies if the experiment is running, paused, completed or failed. The state compensates for the lack of actual feedback sensor data, by signifying the stability of the load. Experiments are scheduled to keep as many running as possible with the current system limitations. A graphics oriented user interface is embedded into the rule-based system to enable an operator to easily experiment with the system.

Vezina, James M.↗

Improving the prediction of daily reservoir releases over the CONUS using conditioned LSTM

Reservoirs play a vital role in regulating streamflow timing and variability for hydroelectricity, flood control, water supply, irrigation, and recreation. Despite their importance, many reservoirs lack comprehensive operational guidelines, making their management complex due to conflicting operational objectives. Hence traditional policy-based reservoir models often fail to capture real-world conditions accurately and they depend on perfect streamflow predictions, which are not always available. In contrast, data-driven models like Long Short-Term Memory (LSTM) networks offer a robust alternative. This study introduces an approach that integrates reservoir characteristics—such as main use, climate, and maximum capacity—into the LSTM model to enhance reservoir release predictions. Using data from nearly 200 reservoirs in the contiguous United States (CONUS), our conditioned LSTM model (LSTM_cond) was compared with both the vanila LSTM and a traditional policy-based approach. Furthermore, our results show that while both LSTM_cond and LSTM perfoms better than the policy-based approach, LSTM_cond consistently outperforms LSTM for hydroelectric, water supply, irrigation, and recreation reservoirs. The KGE median values for LSTM_cond for out-sample reservoirs are 0.764, 0.565, 0.821, and 0.779, respectively, for the aforementioned reservoir types, which are consistently higher that the corresponding KGE values of 0.737, 0.413, 0.775, and 0.713 of LSTM, demonstrating its advantages in improving generalizability.

CONUS↗

The Standard Autonomous File Server, a Customized, Off-the-Shelf Success Story

The Standard Autonomous File Server (SAFS), which includes both off-the-shelf hardware and software, uses an improved automated file transfer process to provide a quicker, more reliable, prioritized file distribution for customers of near real-time data without interfering with the assets involved in the acquisition and processing of the data. It operates as a stand-alone solution, monitoring itself, and providing an automated fail-over process to enhance reliability. This paper will describe the unique problems and lessons learned both during the COTS selection and integration into SAFS, and the system's first year of operation in support of NASA's satellite ground network. COTS was the key factor in allowing the two-person development team to deploy systems in less than a year, meeting the required launch schedule. The SAFS system his been so successful, it is becoming a NASA standard resource, leading to its nomination for NASA's Software or the Year Award in 1999.

Semancik, Susan K.↗

We Can't Count on Repairing All Failures Going to Mars

Reliability analysis often assumes that a complex system can be kept operating indefinitely with scheduled maintenance and emergency repair using a stock of spare parts, as long as the spare parts are not depleted. This assumption seems justified for well-tested, widely used, long operational systems with a multigenerational history of failure, redesign, and reliability growth. It seems doubtful that newer, relatively untried, high technology space systems can always be repaired. We cannot assume space systems will have a low rate of random failures that can all be repaired with a few identical spares. New untried systems usually have a high initial failure rate, called infant mortality, due to errors in requirements, design, parts, materials, and operations planning. These problems can cause groups of related failures called Common Cause Failures (CCFs). The practical definition of a CCF is any failure mode that cannot be cured using identical redundant systems or spare parts. Systems with CCFs may fail repeatedly for the same reason. Can a life support system be kept operating on the way to Mars using only redundant systems and spare parts? The failure history of International Space Station (ISS) life support systems suggests that CCFs are likely to occur and will probably require design changes rather than being reparable with spare parts.

Mars↗

The Voyager 2 scan platform anomaly

The two Voyager spacecraft were launched in the summer of 1977, flew past Jupiter in 1979, and reached Saturn in 1980 and 1981. The Voyager Attitude and Articulation Control Subsystem (AACS) controls the positioning of a scan platform on which scientific instruments are mounted. On August 26, 1981, it was discovered that the azimuth axis of the scan platform of Voyager 2 had not completed the commanded slew. The profile of the failed slew command resembled a similar scan failure on Voyager 1 on February 23, 1979. In that case, contamination of the output gear mesh in the azimuth actuator was identified as the most probable cause of the failure. The problem was solved by cycling the azimuth actuator until the contaminant broke down and smooth operation was restored. A similar treatment applied to the Voyager 2 problem failed. Details of the Voyager 2 anomaly investigation are discussed.

Marchetto, C. A.↗

Foil Bearing Starting Considerations and Requirements for Rotorcraft Engine Applications

Foil gas bearings under development for rotorcraft-sized, hot core engine applications have been susceptible to damage from the slow acceleration and rates typically encountered during the pre-ignition stage in conventional engines. Recent laboratory failures have been assumed to be directly linked to operating foil bearings below their lift-off speed while following conventional startup procedures for the engines. In each instance, the continuous sliding contact between the foils and shaft was believed to thermally overload the bearing and cause the engines to fail. These failures highlight the need to characterize required acceleration rates and minimum operating speeds for these applications. In this report, startup experiments were conducted with a large, rotorcraft engine sized foil bearing under moderate load and acceleration rates to identify the proper start procedures needed to avoid bearing failure. The results showed that a bearing under a 39.4 kPa static load can withstand a modest acceleration rate of 500 rpm/s and excessive loitering below the bearing lift-off speed provided an adequate solid lubricant is present.

Radil, Kevin C.↗

Relationship of area postrema to three putative measures of motion sickness

Although the rat has an incomplete emetic reflex, several species-specific responses to motion were proposed as measures of 'motion sickness' in rats. The purpose was to determine the dependence of these responses on one of several neural structures known to be essential to motion-induced vomiting in species with a complete emetic reflex. The Area Postrema (AP) was shown to play an important role in the production of motion sickness in vomiting species. The effects of thermo-cautery ablations of the AP on three different responses supposedly reflecting motion sickness in the rat were compared: conditioned taste aversion (CTA); drinking suppression; and fecal boli. Efficacy of the ablations was determined by subjecting ablated, sham-operated, and unoperated control animals to a CTA test which is known to require a functional AP. Animals with AP ablations failed to form CTA when 0.15 M LiCl was paired with a 10 percent sucrose solution, while sham-operated control subjects conditioned as well as the unoperated control subjects. The extent of the ablations was evaluated histologically at the end of the experiment. To determine the effects of the ablations on the measures of motion sickness, all animals were subjected to rotation for 30 min or 90 min on a platform displaced 20 deg from earth horizontal. Results indicate that ablation of AP in the rat has no effect on the formation of CTA to a 4 percent solution of cider paired with motion, on the suppression of drinking immediately after exposure to motion, or on the frequency of fecal boli during exposure to motion. This failure of AP ablations to eliminate the effects of motion on any of these responses discourages their use as equivalents of motion-induced vomiting. The appropriateness of other suggested measures, e.g., pica, remains untested but the dependence of such measures on stimulation more severe than commonly used in motion sickness research and the absence of a demonstration of their dependence on neural structures essential to motion sickness in vomiting species, suggest caution in the use of such responses. Further, until more is known about the neural structures underlying these putative measures, the rat will remain a questionable subject in which to study motion sickness.

R Sutton↗

Fail-Safe Logic Design Strategies Within Modern FPGA Architectures

Fail-safe computing refers to computing systems that revert to a non-operational safe state when a fault occurs. In this paper, we investigate a circuit level technique as mitigation for single event upsets (SEUs) and fault injection attacks on field programmable gate arrays (FPGAs), and analyze the effectiveness of the technique as a fail-safe monitor for an encryption algorithm. The propagation of fault effects through FPGA primitives including lookup tables (LUTs) and programmable interconnect points (PIPs) is assessed within an FPGA architecture created using an open source tool, and validated using fault injection experiments on an FPGA. The analysis reveals additional vulnerabilities exist within reconfigurable architectures over those in equivalent fail-safe application specific integrated circuit (ASIC), thus requiring a more elaborate network of redundant circuits and checking logic. The configuration memory bits (CMBs), which configure routing and designate logic functions within the LUTs of the FPGA, add complexity to fail-safe design strategies by introducing additional fault conditions and fault propagation paths. A resource-efficient fail-safe circuit design technique called DEsign for Fail-safe in reCONfigurable systems (DEFCON) is proposed. The benefits and limitations associated with DEFCON are described in the context of fault injection experiments carried out as simulations and in FPGA hardware.

Bhakta, Priya A. [Univ. of New Mexico, Albuquerque↗

Critical insights into the steam electrolysis electrode in protonic ceramic cells for hydrogen production

Intermediate-temperature protonic ceramic electrolysis cells (PCECs), which combine the benefits of both lower- and higher-temperature electrolysis, are among the most efficient technologies for the production of green hydrogen. To ensure economic competitiveness and broad adoption, ongoing innovations in cell materials are essential to improve durability and reduce costs. The water oxidation half-reaction at the anode is a key area for improvement as it is a major contributor to performance degradation and efficiency loss in PCECs. Current anode designs, which are largely derived from solid oxide electrolysis cells, fail to address the specific requirements for PCECs under realistic operating conditions. Here, this Perspective highlights the unique challenges faced by PCEC anodes, focusing on the impact of high steam concentrations and the critical role of proton-coupled electron-transfer mechanisms—factors that are absent in solid oxide electrolysis cells. Furthermore, we explore design principles for advancing anodes tailored for PCECs, offering guidance for future research and development in this promising field.

Electrocatalysis↗

Speed in Information Processing with a Computer Driven Visual Display in a Real-time Digital Simulation

Information transfer between the operator and computer-generated display systems is an area where the human factors engineer discovers little useful design data relating human performance to system effectiveness. This study utilized a computer-driven, cathode-ray-tube graphic display to quantify human response speed in a sequential information processing task. The performance criteria was response time to sixteen cell elements of a square matrix display. A stimulus signal instruction specified selected cell locations by both row and column identification. An equal probable number code, from one to four, was assigned at random to the sixteen cells of the matrix and correspondingly required one of four, matched keyed-response alternatives. The display format corresponded to a sequence of diagnostic system maintenance events, that enable the operator to verify prime system status, engage backup redundancy for failed subsystem components, and exercise alternate decision-making judgements. The experimental task bypassed the skilled decision-making element and computer processing time, in order to determine a lower bound on the basic response speed for given stimulus/response hardware arrangement.

Kyle, R. G.↗

A fault-tolerant clock

Computers must operate correctly even though one or more of components have failed. Electronic clock has been designed to be insensitive to occurrence of faults; it is substantial advance over any known clock.

Daley, W. P.↗

LANDSAT-1 and LANDSAT-2 flight evaluation report

The LANDSAT-1 spacecraft was launched from the Western Test Range on 23 July 1972, at 18:08:06.508Z. The launch and orbital injection phase of the space flight was nominal and deployment of the spacecraft followed predictions. Orbital operations of the spacecraft and payload subsystems were satisfactory through Orbit 147, after which an internal short circuit disabled one of the Wideband Video Tape Recorders (WBVTR-2). Operations resumed until Orbit 196, when the Return Beam Vidicon failed to respond when commanded off. The RBV was commanded off via alternate commands. LANDSAT-1 continued to perform its imaging mission with the Multispectral Scanner and the remaining Wideband Video Tape Recorder providing image data.

Source record↗

Situation management in the Link Monitor and Control Operator Assistant (LMCOA)

This paper describes a knowledge-based system called the Situation Manager that was developed for the Link Monitor and Control Operator Assistant (LMCOA) at the Jet Propulsion Laboratory. This system was developed in response to a number of deficiencies that were identified in an earlier version of the LMCOA: the need to close the control loop between sending a directive and knowing when its execution is complete (versus just closing the communications loop), the need to recognize an anomaly and alert the operator when a directive is rejected or a link device fails, and the need to suggest ways to work around an anomaly, provided that it is recognizable. In response to these needs, the Situation Manager has been designed to provide the LMCOA with three basic capabilities: situation assessment, anomaly diagnosis, and recovery from commonly occurring problems.

Hill, Randall W., Jr.↗