Search NASA⌕ Search

SEARCH · Search NASA

Results for “SYSTEM FAILURE”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Can Cell to Cell Thermal Runaway Propagation be Prevented in a Li-ion Battery Module?

Increasing cell spacing decreased adjacent cell damage center dotElectrically connected adjacent cells drained more than physically adjacent cells center dotRadiant barrier prevents propagation when fully installed between BP cells center dotBP cells vent rapidly and expel contents at 100% SOC -Slower vent with flame/smoke at 50% -Thermal runaway event typically occurs at 160 degC center dotLG cells vent but do not expel contents -Thermal runaway event typically occurs at 200 degC center dotSKC LFP modules did not propagate; fuses on negative terminal of cell may provide a benefit in reducing cell to cell damage propagation. New requirement in NASA-Battery Safety Requirements document: JSC 20793 Rev C 5.1.5.1 Requirements - Thermal Runaway Propagation a. For battery designs greater than a 80-Wh energy employing high specific energy cells (greater than 80 watt-hours/kg, for example, lithium-ion chemistries) with catastrophic failure modes, the battery shall be evaluated to ascertain the severity of a worst-case single-cell thermal runaway event and the propensity of the design to demonstrate cell-to-cell propagation in the intended application and environment. NASA has traditionally addressed the threat of thermal runaway incidents in its battery deployments through comprehensive prevention protocols. This prevention-centered approach has included extensive screening for manufacturing defects, as well as robust battery management controls that prevent abuse-induced runaway even in the face of multiple system failures. This focused strategy has made the likelihood of occurrence of such an event highly improbable. b. The evaluation shall include all necessary analysis and test to quantify the severity (consequence) of the event in the intended application and environment as well as to identify design modifications to the battery or the system that could appreciably reduce that severity. In addition to prevention protocols, programs developing battery designs with catastrophic failure modes should take the steps necessary to assess the severity of a possible thermal runaway event. Programs should assess whether there are reasonable design changes that could appreciably affect the severity of the outcome. Evaluation should include environmental effects to surrounding hardware (i.e., temperature, pressure, shock), contamination effects due to any expelled contaminates, and venting propulsive effects when venting overboard.

Jeevarajan, Judith↗

Douglas flight deck design philosophy

The systems experience gained from 17 years of DC-10 operation was used during the design of the MD-11 to automate system operation and reduce crew workload. All functions, from preflight to shutdown at the termination of flight, require little input from the crew. The MD-11 aircraft systems are monitored for proper operation by the Aircraft Systems Controllers (ASC). In most cases, system reconfiguration as a result of a malfunction is automated. Manual input is required for irreversible actions such as engine shutdown, fuel dump, fire agent discharge, or Integrated Drive Generator (IDG) disconnect. During normal operations, when the cockpit is configured for flight, all annunciators on the overhead panel will be extinguished. This Dark Cockpit immediately confirms to the crew that the panels are correctly configured and that no abnormalities are present. Primary systems annunciations are shown in text on the Alert Area of the Engine and Alert Display (EAD). This eliminates the need to scan the overhead. The MD-11 aircraft systems can be manually controlled from the overhead area of the cockpit. The center portion of the overhead panel is composed of the primary aircraft systems panels, which include FUEL, AIR, Electrical (ELEC) and Hydraulic (HYD) systems, which are easily accessible from both flight crew positions. Each Aircraft Systems Controller (ASC) has two automatic channels and a manual mode. All rectangular lights are annunciators. All square lights are combined switches and annunciators called switch/lights. Red switch/lights on the overhead (Level 3 alerts) are for conditions requiring immediate crew action. Amber (Level 2 or Level 1 alerts) indicates a fault or switch out of position requiring awareness or crew interaction. Overhead switches used in normal operating conditions will illuminate blue when in use (Level 0 alerts) such as WING ANTI-ICE - ON. An overhead switch/light with BLACK LETTERING on an amber or red background indicates a system failure and that crew interaction is required. A switch/light with blue or amber lettering and a BLACK BACKGROUND indicates a switch out of normal position and that crew action is necessary only if the system is in manual operation.

Oldale, Paul↗

A graphical language for reliability model generation

A graphical interface capability of the hybrid automated reliability predictor (HARP) is described. The graphics-oriented (GO) module provides the user with a graphical language for modeling system failure modes through the selection of various fault tree gates, including sequence dependency gates, or by a Markov chain. With this graphical input language, a fault tree becomes a convenient notation for describing a system. In accounting for any sequence dependencies, HARP converts the fault-tree notation to a complex stochastic process that is reduced to a Markov chain which it can then solve for system reliability. The graphics capability is available for use on an IBM-compatible PC, a Sun, and a VAX workstation. The GO module is written in the C programming language and uses the Graphical Kernel System (GKS) standard for graphics implementation. The PC, VAX, and Sun versions of the HARP GO module are currently in beta-testing.

Howell, Sandra V.↗

Development of an extravehicular activity self rescue technique for Space Station

A design study was conducted to delineate potential failure modes and to evaluate various solutions to the many risks to which an astronaut is exposed while performing EVA activities. Among these are suit depressurization as a result of micrometeoroid impact and portable life system failure. There is also a risk of prolonged separation from the vehicle should a tether break or a manned maneuvering unit run out of fuel. In order to simplify contingency operations and to prepare for the situation when no other means are available, a self-rescue capability must be determined. Rescue options are detailed and a number of possible approaches and solutions are presented.

Brody, Adam↗

The Spacecraft Materials Selector: An Artificial Intelligence System for Preliminary Design Trade Studies, Materials Assessments, and Estimates of Environments Present

Institutions need ways to retain valuable information even as experienced individuals leave an organization. Modern electronic systems have enough capacity to retain large quantities of information that can mitigate the loss of experience. Performance information for long-term space applications is relatively scarce and specific information (typically held by a few individuals within a single project) is often rather narrowly distributed. Spacecraft operate under severe conditions and the consequences of hardware and/or system failures, in terms of cost, loss of information, and time required to replace the loss, are extreme. These risk factors place a premium on appropriate choice of materials and components for space applications. An expert system is a very cost-effective method for sharing valuable and scarce information about spacecraft performance. Boeing has an artificial intelligence software package, called the Boeing Expert System Tool (BEST), to construct and operate knowledge bases to selectively recall and distribute information about specific subjects. A specific knowledge base to evaluate the on-orbit performance of selected materials on spacecraft has been developed under contract to the NASA SEE program. The performance capabilities of the Spacecraft Materials Selector (SMS) knowledge base are described. The knowledge base is a backward-chaining, rule-based system. The user answers a sequence of questions, and the expert system provides estimates of optical and mechanical performance of selected materials under specific environmental conditions. The initial operating capability of the system will include data for Kapton, silverized Teflon, selected paints, silicone-based materials, and certain metals. For situations where a mission profile (launch date, orbital parameters, mission duration, spacecraft orientation) is not precisely defined, the knowledge base still attempts to provide qualitative observations about materials performance and likely exposures. Prior to the NASA contract, a knowledge base, the Spacecraft Environments Assistant (SEA,) was initially developed by Boeing to estimate the environmental factors important for a specific spacecraft mission profile. The NASA SEE program has funded specific enhancements to the capability of this knowledge base. The SEA qualitatively identifies over 25 environmental factors that may influence the performance of a spacecraft during its operational lifetime. For cases where sufficiently detailed answers are provided to questions asked by the knowledge base, atomic oxygen fluence levels, proton and/or electron fluence and dose levels, and solar exposure hours are calculated. The SMS knowledge base incorporates the previously developed SEA knowledge base. A case history for previous flight experiment will be shown as an example, and capabilities and limitations of the system will be discussed.

Pippin, H. G.↗

Risk Analysis of On-Orbit Spacecraft Refueling Concepts

On-orbit refueling of spacecraft has been proposed as an alternative to the exclusive use of Heavy-lift Launch Vehicles to enable human exploration beyond Low Earth Orbit (LEO). In these scenarios, beyond LEO spacecraft are launched dry (without propellant) or partially dry into orbit, using smaller or fewer element launch vehicles. Propellant is then launched into LEO on separate launch vehicles and transferred to the spacecraft. Refueling concepts are potentially attractive because they reduce the maximum individual payload that must be placed in Earth orbit. However, these types of approaches add significant complexity to mission operations and introduce more uncertainty and opportunities for failure to the mission. In order to evaluate these complex scenarios, the authors developed a Monte Carlo based discrete-event model that simulates the operational risks involved with such strategies, including launch processing delays, transportation system failures, and onorbit element lifetimes. This paper describes the methodology used to simulate the mission risks for refueling concepts, the strategies that were evaluated, and the results of the investigation. The results of the investigation show that scenarios that employ refueling concepts will likely have to include long launch and assembly timelines, as well as the use of spare tanker launch vehicles, in order to achieve high levels of mission success through Trans Lunar Injection.

Cirillo, William M.↗

The analysis of the pilot's cognitive and decision processes

Articles are presented on pilot performance in zero-visibility precision approach, failure detection by pilots during automatic landing, experiments in pilot decision-making during simulated low visibility approaches, a multinomial maximum likelihood program, and a random search algorithm for laboratory computers. Other topics discussed include detection of system failures in multi-axis tasks and changes in pilot workload during an instrument landing.

Curry, R. E.↗

Graphical workstation capability for reliability modeling

In addition to computational capabilities, software tools for estimating the reliability of fault-tolerant digital computer systems must also provide a means of interfacing with the user. Described here is the new graphical interface capability of the hybrid automated reliability predictor (HARP), a software package that implements advanced reliability modeling techniques. The graphics oriented (GO) module provides the user with a graphical language for modeling system failure modes through the selection of various fault-tree gates, including sequence-dependency gates, or by a Markov chain. By using this graphical input language, a fault tree becomes a convenient notation for describing a system. In accounting for any sequence dependencies, HARP converts the fault-tree notation to a complex stochastic process that is reduced to a Markov chain, which it can then solve for system reliability. The graphics capability is available for use on an IBM-compatible PC, a Sun, and a VAX workstation. The GO module is written in the C programming language and uses the graphical kernal system (GKS) standard for graphics implementation. The PC, VAX, and Sun versions of the HARP GO module are currently in beta-testing stages.

Bavuso, Salvatore J.↗

An Investigation of Nonlinear Controller for Propulsion Controlled Aircraft

Aircraft control systems are usually very reliable because of redundancy and multiple control surfaces. However, there are rare occasions when potentially disastrous flight control system failures do occur. At such times, the use of appropriate modulation of engine thrust to stabilize the aircraft may be the only chance of survival for the people aboard. In several cases where complete loss of control systems has occurred in multi-engine aircraft, pilots used the propulsion system to regain limited control of the aircraft with various degrees of success. In order to evaluate the feasibility of using only engine thrust modulation for emergency backup flight control, the NASA Dryden Flight Research Center has been conducting a series of analytical studies and flight tests on several different types of aircraft in a propulsion controlled aircraft (PCA) program. Simulation studies have included B-720, B-727, MD-11, C-402, C-17, F-18, and F-15, and flight tests have included B-747, B-777, MD-11, T-39, Lear 24, F-18, F-15, T-38, and PA-30. One objective was to determine the degree of control available with manual manipulation (open-loop) of the engine throttles. Flight tests and simulations soon showed that a closed loop controller could improve the chances of making a safe runway landing. The major work to date has concentrated on three aircraft (F-15, F-18, and the MD-11). Successful landings using PCA controllers were performed on the F-15 and MD-11 without the use of control surfaces. During the course of the research, some unique challenges have been identified. Compared to the conventional flight control surfaces, the engines are slow and have limited control effectiveness. Hence the ability of the system to promptly respond to aerodynamic changes is limited. Consequently, many nonlinear effects, which are easily accommodated by a conventional flight control system, become significant issues in the design of an effective controller when the engines are used as the only control effectors. A number of nonlinear behaviors observed during PCA flight tests, which are not meant to be exhaustive, are reviewed in the next section.

Lu, Ping↗

Outbrief - Long Life Rocket Engine Panel

This white paper is an overview of the JANNAF Long Life Rocket Engine (LLRE) Panel results from the last several years of activity. The LLRE Panel has met over the last several years in order to develop an approach for the development of long life rocket engines. Membership for this panel was drawn from a diverse set of the groups currently working on rocket engines (Le. government labs, both large and small companies and university members). The LLRE Panel was formed in order to determine the best way to enable the design of rocket engine systems that have life capability greater than 500 cycles while meeting or exceeding current performance levels (Specific Impulse and Thrust/Weight) with a 1/1,OOO,OOO likelihood of vehicle loss due to rocket system failure. After several meetings and much independent work the panel reached a consensus opinion that the primary issues preventing LLRE are a lack of: physics based life prediction, combined loads prediction, understanding of material microphysics, cost effective system level testing. and the inclusion of fabrication process effects into physics based models. With the expected level of funding devoted to LLRE development, the panel recommended that fundamental research efforts focused on these five areas be emphasized.

Quinn, Jason Eugene↗

Predicting System Accidents with Model Analysis During Hybrid Simulation

Standard discrete event simulation is commonly used to identify system bottlenecks and starving and blocking conditions in resources and services. The CONFIG hybrid discrete/continuous simulation tool can simulate such conditions in combination with inputs external to the simulation. This provides a means for evaluating the vulnerability to system accidents of a system's design, operating procedures, and control software. System accidents are brought about by complex unexpected interactions among multiple system failures , faulty or misleading sensor data, and inappropriate responses of human operators or software. The flows of resource and product materials play a central role in the hazardous situations that may arise in fluid transport and processing systems. We describe the capabilities of CONFIG for simulation-time linear circuit analysis of fluid flows in the context of model-based hazard analysis. We focus on how CONFIG simulates the static stresses in systems of flow. Unlike other flow-related properties, static stresses (or static potentials) cannot be represented by a set of state equations. The distribution of static stresses is dependent on the specific history of operations performed on a system. We discuss the use of this type of information in hazard analysis of system designs.

Malin, Jane T.↗

High Speed Mobility Through On-Demand Aviation

Game changing advances come about by the introduction of new technologies at a time when societal needs create the opportunity for new market solutions. A unique opportunity exists for NASA to bring about such a mobility revolution in General Aviation, extendable to other aviation markets, to maintain leadership in aviation by the United States. This report outlines the research carried out so far under NASA's leadership towards developing a new mobility choice, called Zip Aviation1,2,3. The feasibility, technology and system gaps that need to be addressed, and pathways for successful implementation have been investigated to guide future investment. The past decade indicates exciting trends in transportation technologies, which are quickly evolving. Automobiles are embracing automation to ease driver tasks as well as to completely control the vehicle with added safety (Figure 1). Electric propulsion is providing zero tail-pipe emission vehicles with dramatically lower energy and maintenance costs. These technologies have not yet been applied to aviation, yet offer compelling potential benefits across all aviation markets, and in particular to General Aviation (GA) as an early adopter market. The benefits of such an adoption are applicable in the following areas: 􀁸 Safety: The GA market experiences accident rates that are substantially higher than automobiles or commercial airlines, with 7.5 fatal accidents per 100 million vehicle miles compared to 1.3 for automobiles and.068 for airlines. Approximately 80% of these accidents are caused by some form of pilot error, with another 13% caused by single point propulsion system failure. 􀁸 Emissions: Environmental constraints are pushing for the elimination of 100Low Lead (LL) fuel used in most GA aircraft, with aviation fuel the #1 source of lead emissions into the environment. Aircraft also have no emission control systems (i.e. no catalytic converters etc.), so they are gross hydrocarbon polluters compared to automobiles. 􀁸 Community Noise: Hub and smaller GA airports are facing increasing noise restrictions, and while commercial airliners have dramatically decreased their community noise footprint over the past 30 years, GA aircraft noise has essentially remained same, and moreover, is located in closer proximity to neighborhoods and businesses. 􀁸 Operating Costs: GA operating costs have risen dramatically due to average fuel costs of over $6 per gallon, which has constrained the market over the past decade and resulted in more than 50% lower sales and 35% less yearly operations. Infusion of autonomy and electric propulsion technologies can accomplish not only a transformation of the GA market, but also provide a technology enablement bridge for both larger aircraft and the emerging civil Unmanned Aerial Systems (UAS) markets. The NASA Advanced General Aviation Transport Experiments (AGATE) project successfully used a similar approach to enable the introduction of primary composite structures and flat panel displays in the 1990s, establishing both the technology and certification standardization to permit quick adoption through partnerships with industry, academia, and the Federal Aviation Administration (FAA). Regional and airliner markets are experiencing constant pressure to achieve decreasing levels of community emissions and noise, while lowering operating costs and improving safety. But to what degree can these new technology frontiers impact aircraft safety, the environment, operations, cost, and performance? Are the benefits transformational enough to fundamentally alter aircraft competiveness and productivity to permit much greater aviation use for high speed and On-Demand Mobility (ODM)? These questions were asked in a Zip aviation system study named after the Zip Car, an emerging car-sharing business model. Zip Aviation investigates the potential to enable new emergent markets for aviation that offer "more flexibility than the existing transportation solutions." These studies indicate that autonomy and electric propulsion technology infusions offer a unique opportunity to provide breakthrough capabilities for new high speed, on-demand travel alternatives that can leapfrog the need for future expensive ground-based infrastructure investment. At the same time, such investments offer a method of laying the foundation for these technologies to be incubated for commercial aviation at lower cost, and with lower initial certification thresholds due to the relatively poor capabilities of GA aircraft to permit early adoption and private market capitalization by rapid technology accelerations, as depicted in Figure 2.

Moore, Mark D.↗

Validation methods for flight crucial systems

Research to develop techniques that can aid in determining the reliability and performance of digital electronic fault-tolerant systems, that have probability of catastrophic system failure on the order of 10 to the -9th at 10 hours, is reviewed. The computer-aided reliability estimation program (CARE III) provides general-purpose reliability analysis and a design tool for fault-tolerant systems; large reduction of state size; and a fault-handling model based on probabilistic description of detection, isolation, and recovery mechanisms. The application of design proof techniques as part of the design and development of the software implemented fault-tolerance computer is mentioned. Emulation techniques and experimental procedures are verified using specimens of fault-tolerant computers and the capabilities of the validation research laboratory, AIRLAB.

Holt, H. M.↗

Extended behavioral decomposition for estimating ultrahigh reliability

Limitations of some analytic techniques in approximating the reliability of life-critical electronic systems are discussed, and a framework for the specification of recovery and fault-handling submodels is suggested. The framework makes full use of the instantaneous jump theorem by viewing the collection of interfering, premature exits from any fault handling and recovery submodel as defining a new, competing process submodel. This approach allows a greater flexibility in submodel representation, since submodels may contain arbitrary entrance arcs, exit arcs, and competing, interfering transitions with arbitrary destinations. Since the effects of near-coincident faults need not be represented as system failure events, the reliability estimates produced need not be unduly conservative. Comparisons on small models, where exact results can be computed, show substantial improvement in accuracy over earlier techniques. Implementation of the technique in an X-windows-based system, XHARP, is described.

Geist, Robert↗

Automatically Finding the Control Variables for Complex System Behavior

Testing large-scale systems is expensive in terms of both time and money. Running simulations early in the process is a proven method of finding the design faults likely to lead to critical system failures, but determining the exact cause of those errors is still time-consuming and requires access to a limited number of domain experts. It is desirable to find an automated method that explores the large number of combinations and is able to isolate likely fault points. Treatment learning is a subset of minimal contrast-set learning that, rather than classifying data into distinct categories, focuses on finding the unique factors that lead to a particular classification. That is, they find the smallest change to the data that causes the largest change in the class distribution. These treatments, when imposed, are able to identify the factors most likely to cause a mission-critical failure. The goal of this research is to comparatively assess treatment learning against state-of-the-art numerical optimization techniques. To achieve this, this paper benchmarks the TAR3 and TAR4.1 treatment learners against optimization techniques across three complex systems, including two projects from the Robust Software Engineering (RSE) group within the National Aeronautics and Space Administration (NASA) Ames Research Center. The results clearly show that treatment learning is both faster and more accurate than traditional optimization methods.

Gay, Gregory↗

In-Time Non-Participant Casualty Risk Assessment to Support Onboard Decision Making for Autonomous Unmanned Aircraft

Numerous operational paradigms, technologies, and missions are emerging as newcomers to the National Airspace System (NAS) develop small Unmanned Aircraft Systems (sUAS), personal air vehicles and other Urban Air Mobility (UAM) concepts. As the list of applications expands, maintaining the safety of the current airspace system remains one of the core concerns preventing widespread commercial implementation of these concepts. Further, the risks associated with unmanned aircraft operations themselves have to be recognized and mitigated in a timely manner. Safety-critical risks include, but are not limited to, flight outside of approved airspace, unsafe proximity to people or property, critical system failures, loss-of control, and cyber-security related risks. Instead of reacting to accidents, a set of predictive and data-driven risk monitoring, assessment, and mitigation capabilities are envisioned to help capture and eliminate hazards as these systems become operational. NASA’s System-wide Safety project is performing R&D on such a safety assurance concept. As part of this concept, this paper describes an architecture that continuously monitors a diverse set of onboard and ground-based sources to estimate and predict non-participant casualty risk during flight. Timely identification of the changing nature of this risk can inform decision making processes to mitigate current and impending situations.

Ancel, Ersin↗

Design, analysis, and control of large transport aircraft utilizing engine thrust as a backup system for the primary flight controls

A review of accidents that involved the loss of hydraulic flight control systems serves as an introduction to this project. In each of the accidents--involving transport aircraft such as the DC-10, the C-5A, the L-1011, and the Boeing 747--the flight crew attempted to control the aircraft by means of thrust control. Although these incidents had tragic endings, in the absence of control power due to primary control system failure, control power generated by selective application of engine thrust has proven to be a viable alternative. NASA Dryden has demonstrated the feasibility of controlling an aircraft during level flight, approach, and landing conditions using an augmented throttles-only control system. This system has been successfully flown in the flight test simulator for the B-720 passenger transport and the F-15 air superiority fighter and in actual flight tests for the F-15 aircraft. The Douglas Aircraft Company is developing a similar system for the MD-11 aircraft. The project's ultimate goal is to provide data for the development of thrust control systems for mega-transports (600+ passengers).

Gerren, Donna S.↗

An Automaton Rover Enabling Long Duration In-Situ Science in Extreme Environments

The Automaton Rover for Extreme Environments (AREE) is a NASA Innovative Advanced Concept (NIAC) funded study focused on enabling long duration science on Venus by replacing vulnerable electronics with an entirely mechanical design. By utilizing high temperature alloys, the rover would survive on the surface of Venus for weeks if not months. The rover concept harvests wind energy using a turbine and stores it in a constant force spring. The mobility system would be guided by a mechanical computer and logic system, programed to carry out the mission. It would collect basic science data such as wind speed, temperature, and seismic events. Communicating the data back to Earth is the most challenging aspect of the system design with multiple options being explored in a trade: a simple electronic high temperature transponder, a retroreflector target or inscribing phonograph style records to be launched via a balloon to a high altitude drone capable of transmitting the data back to Earth. AREE is not only a new exciting in-situ rover concept, but also a paradigm shift to conducting in-situ science in extreme environments. Traditional extreme environment vehicles collect as many diverse data points as possible in the short period of time before system failure. AREE breaks that trend by exploring what can be done with only a few basic scientific measurements, but recorded over long periods of time. In addition to Venus, the concept can be useful in other extreme environments in the solar system including Mercury, Jupiter's radiation belts, the interiors of gas giants, the mantle of the Earth and volcanoes throughout the solar system.

Parness, Aaron↗