Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Protection Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Subsystem testing of Galileo's attitude and articulation control fault protection

This paper discusses the fault protection tesing of the Attitude and Articulation Control Subsystem (AACS) of the Galileo spacecraft. The need for an autonomous fault protection system on an interplanetary spacecraft is discussed. Galileo requirements for the detection and response of specific hardware failures is discussed along with the fault protection software design and implementation. The test beds and test methods used for fault protection testing are described. The paper concludes with a presentation of the results of this testing with an emphasis on requirement and design changes that were made as a result of these tests.

Anderson, L. L.↗

High-Speed Ring Bus

The high-speed ring bus at the Jet Propulsion Laboratory (JPL) allows for future growth trends in spacecraft seen with future scientific missions. This innovation constitutes an enhancement of the 1393 bus as documented in the Institute of Electrical and Electronics Engineers (IEEE) 1393-1999 standard for a spaceborne fiber-optic data bus. It allows for high-bandwidth and time synchronization of all nodes on the ring. The JPL ring bus allows for interconnection of active units with autonomous operation and increased fault handling at high bandwidths. It minimizes the flight software interface with an intelligent physical layer design that has few states to manage as well as simplified testability. The design will soon be documented in the AS-1393 standard (Serial Hi-Rel Ring Network for Aerospace Applications). The framework is designed for "Class A" spacecraft operation and provides redundant data paths. It is based on "fault containment regions" and "redundant functional regions (RFR)" and has a method for allocating cables that completely supports the redundancy in spacecraft design, allowing for a complete RFR to fail. This design reduces the mass of the bus by incorporating both the Control Unit and the Data Unit in the same hardware. The standard uses ATM (asynchronous transfer mode) packets, standardized by ITU-T, ANSI, ETSI, and the ATM Forum. The IEEE-1393 standard uses the UNI form of the packet and provides no protection for the data portion of the cell. The JPL design adds optional formatting to this data portion. This design extends fault protection beyond that of the interconnect. This includes adding protection to the data portion that is contained within the Bus Interface Units (BIUs) and by adding to the signal interface between the Data Host and the JPL 1393 Ring Bus. Data transfer on the ring bus does not involve a master or initiator. Following bus protocol, any BIU may transmit data on the ring whenever it has data received from its host. There is no centralized arbitration or bus granting. The JPL design provides for autonomous synchronization of the nodes on the ring bus. An address-synchronous latency adjust buffer (LAB) has been designed that cannot get out of synchronization and needs no external input. Also, a priority-driven cable selection behavior has been programmed into each unit on the ring bus. This makes the bus able to connect itself up, according to a maximum redundancy priority system, without the need for computer intervention at startup. Switching around a failed or switched-off unit is also autonomous. The JPL bus provides a map of all the active units for the host computer to read and use for fault management. With regard to timing, this enhanced bus recognizes coordinated timing on a spacecraft as critical and addresses this with a single source of absolute and relative time, which is broadcast to all units on the bus with synchronization maintained to the tens of nanoseconds. Each BIU consists of up to five programmable triggers, which may be programmed for synchronization of events within the spacecraft of instrument. All JPL-formatted data transmitted on the ring bus are automatically time-stamped.

Wysocky, Terry↗

Space Station automated systems testing/verification and the Galileo Orbiter fault protection design/verification

Aspects of Space Station automated systems testing and verification are discussed, taking into account several program requirements. It is found that these requirements lead to a number of issues of uncertainties which require study and resolution during the Space Station definition phase. Most, if not all, of the considered uncertainties have implications for the overall testing and verification strategy adopted by the Space Station Program. A description is given of the Galileo Orbiter fault protection design/verification approach. Attention is given to a mission description, an Orbiter description, the design approach and process, the fault protection design verification approach/process, and problems of 'stress' testing.

Landano, M. R.↗

SORCE Daylight-Only Operations

The recent experience of the SORCE flight operations team offers an excellent example of innovative engineering using limited resources. The goal of this paper is to extend to the space operations community the lessons learned during this critical redesign in order to aid other missions facing equally daunting challenges. The end result is a mission extended well beyond its designed life continuing to return important data to the science community to extend the climate record.

Spacecraft Anomaly Recovery↗

NASA Tech Briefs, February 2006

Topics discussed include: Nearly Direct Measurement of Relative Permittivity; DCS-Neural-Network Program for Aircraft Control and Testing; Dielectric Heaters for Testing Spacecraft Nuclear Reactors; Using Doppler Shifts of GPS Signals To Measure Angular Speed; Monitoring Temperatures of Tires Using Luminescent Materials; Highly Efficient Multilayer Thermoelectric Devices; Very High-Speed Digital Video Capability for In-Flight Use; MMIC DHBT Common-Base Amplifier for 172 GHz; Modular, Microprocessor-Controlled Flash Lighting System; Generic Environment for Simulating Launch Operations; Modular Aero-Propulsion System Simulation; X-Windows Socket Widget Class; Infrastructure for Rapid Development of Java GUI Programs; Processing Raman Spectra of High-Pressure Hydrogen Flames; X-Windows Information Sharing Protocol Widget Class; Simulating Humans as Integral Parts of Spacecraft Missions; Analyzing Power Supply and Demand on the ISS; Polyimides From a-BPDA and Aromatic Diamines; Making Plant-Support Structures From Waste Plant Fiber; Large Deployable Reflectarray Antenna; Periodically Discharging, Gas-Coalescing Filter; Ion Milling On Steps for Fabrication of Nanowires; Neuro-Prosthetic Implants With Adjustable Electrode Arrays; Microfluidic Devices for Studying Biomolecular Interactions; Studying Functions of All Yeast Genes Simultaneously; Polarization Phase-Compensating Coats for Metallic Mirrors; Tunable-Bandwidth Filter System; Methodology for Designing Fault-Protection Software; and Ground-Based Localization of Mars Rovers.

Source record↗

Lessons Learned During the Transition of SORCE Science Operations to Daylight Only Operations

In July 2013, NASA's Solar Radiation and Climate Experiment experienced a battery anomaly which placed it into safemode halting all science observations. Initial attempts to recover the spacecraft to an operational configuration failed due to the reduced capacity of the battery. As the keystone mission for measuring total solar irradiance, and the cornerstone mission for measuring the solar spectral irradiance there was a strong motivation for developing a new operations concept that would allow SORCE to resume daily measurements of the Sun. The operations team faced many challenges over the next several months. For a five-day period in late 2013 the operations team was able resume science observations to cross-calibrate SORCE data with a new instrument launched in November 2013. After the cross-calibration campaign was completed a new operations concept was deployed which allowed SORCE to perform daylight only operations. In this mode of operations all non-essential components are powered off at each eclipse entry and then turned back on at sunrise. In March 2014 SORCE resumed making daily measurements of the Sun. This paper will review the events and lessons learned from the six-month recovery effort.

Spacecraft Anomaly↗

Design and Testing of a Hard-Fault Protection Circuit for a 1 kV SiC MOSFET Inverter

Due to increasingly high DC link voltages and further advancements in the current density of silicon carbide (SiC) MOSFETs, it has become evident that conventional IGBT protection methods are not sufficient to prevent exceeding the current rating of these devices during low-inductance fault events. This paper explores the use of an air core Rogowski coil topology to mitigate these hard fault events. The design of this circuit resulted in safe shutdown of a low impedance phase-to-phase fault in under one microsecond, tested up to DC link voltages of 1 kV. This paper details the theory, design, simulation, and successful test results of this method.

hard fault protection↗

MER Surface Phase; Blurring the Line Between Fault Protection and What is Supposed to Happen

An assessment on the limitations of communication with MER rovers and how such constraints drove the system design, flight software and fault protection architecture, blurring the line between traditional fault protection and expected nominal behavior, and requiring the most novel autonomous and semi-autonomous elements of the vehicle software including communication, surface mobility, attitude knowledge acquisition, fault protection, and the activity arbitration service.

surface operations↗

Space station common module network topology and hardware development

Conceptual space station common module power management and distribution (SSM/PMAD) network layouts and detailed network evaluations were developed. Individual pieces of hardware to be developed for the SSM/PMAD test bed were identified. A technology assessment was developed to identify pieces of equipment requiring development effort. Equipment lists were developed from the previously selected network schematics. Additionally, functional requirements for the network equipment as well as other requirements which affected the suitability of specific items for use on the Space Station Program were identified. Assembly requirements were derived based on the SSM/PMAD developed requirements and on the selected SSM/PMAD network concepts. Basic requirements and simplified design block diagrams are included. DC remote power controllers were successfully integrated into the DC Marshall Space Flight Center breadboard. Two DC remote power controller (RPC) boards experienced mechanical failure of UES 706 stud-mounted diodes during mechanical installation of the boards into the system. These broken diodes caused input to output shorting of the RPC's. The UES 706 diodes were replaced on these RPC's which eliminated the problem. The DC RPC's as existing in the present breadboard configuration do not provide ground fault protection because the RPC was designed to only switch the hot side current. If ground fault protection were to be implemented, it would be necessary to design the system so the RPC switched both the hot and the return sides of power.

Anderson, P.↗

Fault protection techniques in JPL Spacecraft

While every JPL spacecraft requires some unique mission specific fault protection, there are many requirements which are common to all spacecraft configurations. These consist of protecting command and data processing & attitude control computers, protection against communication loss with the spacecraft, ensuring that safe external and internal temperature levels are maintained, and recovery from power overloads. Additionally, most JPL spacecraft are equipped with a general-purpose 'Safe Mode' response algorithm which configures the spacecraft to a lower power state which is safe and predictable so that diagnosis of more complex faults can be addressed by the Operations Team. This paper details the generic application of fault protection techniques which are implemented into most JPL spacecraft designs.

fault protection↗

Protecting Against Faults in JPL Spacecraft

A paper discusses techniques for protecting against faults in spacecraft designed and operated by NASA s Jet Propulsion Laboratory (JPL). The paper addresses, more specifically, fault-protection requirements and techniques common to most JPL spacecraft (in contradistinction to unique, mission specific techniques), standard practices in the implementation of these techniques, and fault-protection software architectures. Common requirements include those to protect onboard command, data-processing, and control computers; protect against loss of Earth/spacecraft radio communication; maintain safe temperatures; and recover from power overloads. The paper describes fault-protection techniques as part of a fault-management strategy that also includes functional redundancy, redundant hardware, and autonomous monitoring of (1) the operational and health statuses of spacecraft components, (2) temperatures inside and outside the spacecraft, and (3) allocation of power. The strategy also provides for preprogrammed automated responses to anomalous conditions. In addition, the software running in almost every JPL spacecraft incorporates a general-purpose "Safe Mode" response algorithm that configures the spacecraft in a lower-power state that is safe and predictable, thereby facilitating diagnosis of more complex faults by a team of human experts on Earth.

Morgan, Paula↗

Automatic Fault Protection in the Voyager Spacecraft

Due to reliability requirements placed on the Voyager spacecraft system design and a mission resulting in long two-way, light time communication links, on-board automatic fault detection and correction capabilities are a significant feature of that spacecraft's design. Most of the protection to otherwise mission-catastrophic failures is implemented in the software of the voyager's central computer, while some resides in an attitude control-dedicated processor. This paper will present the role that automatic fault protection plans in achieving Voyager's overall reliability, its design evolution, and how its design was validated during system testing. In-flight experience will also be described, and from the lessons learned there-in, conclusions and recommendations will be drawn for the benefit of future designs.

Jones, C. P.↗

Attitude control fault protection - The Voyager experience

The length of the Voyager mission and the communication delay caused by the distances involved made fault protection a necessary part of the Voyager Attitude and Articulation Control Subsystem (AACS) design. An overview of the Voyager attitude control fault protection is given and flight experiences relating to fault protection are provided.

Litty, E. C.↗

Photovoltaic system grounding and fault protection

The grounding and fault protection aspects of large photovoltaic power systems are studied. Broadly, the overlapping functions of these two plant subsystems include providing for the safety of personnel and equipment. Grounding subsystem design is generaly governed by considerations of personnel safety and the limiting of hazardous voltages to which they are exposed during the occurrence of a fault or other misoperation of equipment. A ground system is designed to provide a safe path for fault currents. Metal portions of the modules, array structures, and array foundations are used as a part of the ground system, provided that they and their interconnection are designed to be suitably reliable over the life of the plant. Several alternative types of fault protection and detection equipment are designed into the source circuits and dc buses feeding the input terminals of the subfield power conditioner. This design process requires evaluation of plausible faults, equipment, and remedial actions planned to correct faults. The evaluation should also consider life cycle cost impacts.

Stolte, W. J.↗

SSME digital control design characteristics

To protect against a latent programming error (software fault) existing in an untried branch combination that would render the space shuttle out of control in a critical flight phase, the Backup Flight System (BFS) was chartered to provide a safety alternative. The BFS is designed to operate in critical flight phases (ascent and descent) by monitoring the activities of the space shuttle flight subsystems that are under control of the primary flight software (PFS) (e.g., navigation, crew interface, propulsion), then, upon manual command by the flightcrew, to assume control of the space shuttle and deliver it to a noncritical flight condition (safe orbit or touchdown). The problems associated with the selection of the PFS/BFS system architecture, the internal BFS architecture, the fault tolerant software mechanisms, and the long term BFS utility are discussed.

Mitchell, W. T.↗