Search NASASearch

SEARCH · Search NASA

Results for “Redundant Designs”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

In Space Nuclear Power as an Enabling Technology for Deep Space Exploration

Deep Space Exploration missions, both for scientific and Human Exploration and Development (HEDS), appear to be as weight limited today as they would have been 35 years ago. Right behind the weight constraints is the nearly equally important mission limitation of cost. Launch vehicles, upper stages and in-space propulsion systems also cost about the same today with the same efficiency as they have had for many years (excluding impact of inflation). Both these dual mission constraints combine to force either very expensive, mega systems missions or very light weight, but high risk/low margin planetary spacecraft designs, such as the recent unsuccessful attempts for an extremely low cost mission to Mars during the 1998-99 opportunity (i.e., Mars Climate Orbiter and the Mars Polar Lander). When one considers spacecraft missions to the outer heliopause or even the outer planets, the enormous weight and cost constraints will impose even more daunting concerns for mission cost, risk and the ability to establish adequate mission margins for success. This paper will discuss the benefits of using a safe in-space nuclear reactor as the basis for providing both sufficient electric power and high performance space propulsion that will greatly reduce mission risk and significantly increase weight (IMLEO) and cost margins. Weight and cost margins are increased by enabling much higher payload fractions and redundant design features for a given launch vehicle (higher payload fraction of IMLEO). The paper will also discuss and summarize the recent advances in nuclear reactor technology and safety of modern reactor designs and operating practice and experience, as well as advances in reactor coupled power generation and high performance nuclear thermal and electric propulsion technologies. It will be shown that these nuclear power and propulsion technologies are major enabling capabilities for higher reliability, higher margin and lower cost deep space missions design to reliably reach the outer planets for scientific exploration.

Sackheim, Robert L.

Application of fully stressed design procedures to redundant and non-isotropic structures

An evaluation is presented of fully stressed design procedures for sizing highly redundant structures including structures made of composite materials. The evaluation is carried out by sizing three structures: a simple box beam of either composite or metal construction; a low aspect ratio titanium wing; and a titanium arrow wing for a conceptual supersonic cruise aircraft. All three structures are sized by ordinary fully-stressed design (FSD) and thermal fully stressed design (TFSD) for combined mechanical and thermal loads. Where possible, designs are checked by applying rigorous mathematical programming techniques to the structures. It is found that FSD and TFSD produce optimum designs for the metal box beam, but produce highly non-optimum designs for the composite box beam. Results from the delta wing and arrow wing indicate that FSD and TFSD exhibits slow convergence for highly redundant metal structures. Further, TFSD exhibits slow oscillatory convergence behavior for the arrow wing for very high temperatures. In all cases where FSD and TFSD perform poorly either in obtaining nonoptimum designs or in converging slowly, the assumptions on which the algorithms are based are grossly violated. The use of scaling, however, is found to be very effective in obtaining fast convergence and efficiently produces safe designs even for those cases when FSD and TFSD alone are ineffective.

Adelman, H. M.

SIRU development. Volume 1: System development

A complete description of the development and initial evaluation of the Strapdown Inertial Reference Unit (SIRU) system is reported. System development documents the system mechanization with the analytic formulation for fault detection and isolation processing structure; the hardware redundancy design and the individual modularity features; the computational structure and facilities; and the initial subsystem evaluation results.

Gilmore, J. P.

Command decoder unit

The design and testing of laboratory hardware (a command decoder unit) used in evaluating space shuttle instrumentation, data processing, and ground check-out operations is described. The hardware was a modification of another similar instrumentation system. A data bus coupler was designed and tested to interface the equipment to a central bus controller (computer). A serial digital data transfer mechanism was also designed. Redundant power supplies and overhead modules were provided to minimize the probability of a single component failure causing a catastrophic failure. The command decoder unit is packaged in a modular configuration to allow maximum user flexibility in configuring a system. Test procedures and special test equipment for use in testing the hardware are described. Results indicate that the unit will allow NASA to evaluate future software systems for use in space shuttles. The units were delivered to NASA and appear to be adequately performing their intended function. Engineering sketches and photographs of the command decoder unit are included.

Source record

SIFT - Design and analysis of a fault-tolerant computer for aircraft control

SIFT (Software Implemented Fault Tolerance) is an ultrareliable computer for critical aircraft control applications that achieves fault tolerance by the replication of tasks among processing units. The main processing units are off-the-shelf minicomputers, with standard microcomputers serving as the interface to the I/O system. Fault isolation is achieved by using a specially designed redundant bus system to interconnect the processing units. Error detection and analysis and system reconfiguration are performed by software. Iterative tasks are redundantly executed, and the results of each iteration are voted upon before being used. Thus, any single failure in a processing unit or bus can be tolerated with triplication of tasks, and subsequent failures can be tolerated after reconfiguration. Independent execution by separate processors means that the processors need only be loosely synchronized, and a novel fault-tolerant synchronization method is described.

Wensley, J. H.

Space Shuttle Solid Rocket Motor Program - Lessons learned

An evaluation is given of the most important lessons learned concerning the Space Shuttle's Solid Rocket Motors with respect to flight safety, reuse requirements, system reliability, structural integrity, and hardware damage due to reentry, water impact, and retrieval. Within the major categories of flight safety, performance, and reuse/cost, priorities are identified for implementation of envisioned improvements; schedule and cost considerations are noted to have been substantially downgraded in favor of flight safety. The consequences of the primacy of flight safety are discussed in the areas of primary systems design, redundant systems, manufacturing and assembly processing, and launch constraints.

Mccool, A. A.

Optimal selection of space transportation fleet to meet multi-mission space program needs

A space program that spans several decades will be comprised of a collection of missions such as low earth orbital space station, a polar platform, geosynchronous space station, lunar base, Mars astronaut mission, and Mars base. The optimal selection of a fleet of several recoverable and expendable launch vehicles, upper stages, and interplanetary spacecraft necessary to logistically establish and support these space missions can be examined by means of a linear integer programming optimization model. Such a selection must be made because the economies of scale which comes from producing large quantities of a few standard vehicle types, rather than many, will be needed to provide learning curve effects to reduce the overall cost of space transportation if these future missions are to be affordable. Optimization model inputs come from data and from vehicle designs. Each launch vehicle currently in existence has a launch history, giving rise to statistical estimates of launch reliability. For future, not-yet-developed launch vehicles, theoretical reliabilities corresponding to the maturity of the launch vehicles' technology and the degree of design redundancy must be estimated. Also, each such launch vehicle has a certain historical or estimated development cost, tooling cost, and a variable cost. The cost of a launch used in this paper includes the variable cost plus an amortized portion of the fixed and development costs. The integer linear programming model will have several constraint equations based on assumptions of mission mass requirements, volume requirements, and number of astronauts needed. The model will minimize launch vehicle logistic support cost and will select the most desirable launch vehicle fleet.

Morgenthaler, George W.

Flight Hydrogen Sensor for use in the ISS Oxygen Generation Assembly

This paper provides a description of the hydrogen sensor Orbital Replacement Unit (ORU) used on the Oxygen Generation Assembly (OGA), to be operated on the International Space Station (ISS). The hydrogen sensor ORU is being provided by Makel Engineering, Inc. (MEI) to monitor the oxygen outlet for the presence of hydrogen. The hydrogen sensor ORU is a triple redundant design where each sensor converts raw measurements to actual hydrogen partial pressure that is reported to the OGA system controller. The signal outputs are utilized for system shutdown in the event that the hydrogen concentration in the oxygen outlet line exceeds the specified shutdown limit. Improvements have been made to the Micro-Electro-Mechanical Systems (MEMS) based sensing element, screening, and calibration process to meet OGA operating requirements. Two flight hydrogen sensor ORUs have successfully completed the acceptance test phase. This paper also describes the sensor s performance during acceptance testing, additional tests planned to extend the operational performance calibration cycle, and integration with the OGA system.

MSadoques, George, Jr.

The Iodine Satellite (iSat) Propellant Feed System - Design and Demonstration

CUBESATS are relatively new spacecraft platforms that are typically deployed from a launch vehicle as a secondary payload, providing low-cost access to space for a wide range of end-users. These satellites are comprised of building blocks having dimensions of 10x10x10 cm3 and a mass of 1.33 kg (a 1-U size). While providing low-cost access to space, a major operational limitation is the lack of a propulsion system that can fit within a CubeSat and is capable of executing high Delta V maneuvers. This makes it difficult to use CubeSats on missions requiring certain types of maneuvers (i.e. formation flying, spacecraft rendezvous). Work has been performed investigating the use of iodine as a propellant for Hall-effect thrusters (HETs) that could subsequently be used to provide a high specific impulse path to CubeSat propulsion. One of the systems under development to support such a technology is the propellant feed system, which must be capable of storing solid iodine propellant, applying heat to sublime the stored solid into the vapor phase, and then control the flow of low-pressure gaseous iodine to both the thruster and cathode. In a test conducted in 2016, a first-generation iodine propellant feed system was integrated with a cathode and Hall thruster. While this test had to be terminated, the feed system in this first test was able to support both cathode and integrated cathode and thruster operation prior to the termination of the test. In the present paper, we describe work performed since that initial integrated test. The effort uses lessons learned from the previous integrated test, retiring risk associated with the iodine propellant feed system, answering open design-space questions, and demonstrating iodine flow control in an integrated system. The work is undertaken at both the component level and then at the integrated subsystem level to systematically improve the feed system design, improving the hardware fidelity so the appearance and operation of the system are as flight-like as possible. At the component level, the work focuses on the propellant tank, the feed system tubing, the valves used to control the flow to the cathode and thruster, and the heaters that maintain the temperature of the flowpaths and keep iodine from redepositing and clogging the system. Work on the propellant reservoir focuses on fabricating a tank that matches the geometry of the flight design, which allows for the identification of flight tank fabrication issues that may arise and permits thermal testing of a tank possessing the same size and thermal mass as the flight design, which can be used to anchor thermal modeling of the component. This is critical for finalizing the tank heater power requirements that feed into the heater design. All metallic materials in the feed system are hastelloy or Inconel, as these materials are resistant to chemical attack by the highly-reactive iodine vapor. The tubing in the iodine feed system must possess ports to permit a neutral gas purge of the system that clear impurities after iodine is loaded into the propellant tank. A procedure is discussed whereby these ports are crimped and sealed after the purge process is completed so as to not re-expose the iodine system to air. The valves are a critical component for control of the flow to the thruster and the cathode. Significant effort has gone into upgrading the materials of the valves to make them more resistant to chemical attack and into developing an understanding of the use of these valves during the startup and operation of the cathode and thruster. The heaters that line the entire feed system are designed to draw minimal power from the power processing unit (PPU) while still having the capacity to maintain all the feed system components at the temperatures required to discourage iodine deposition inside components downstream of the propellant tank exit. The heaters possess two separate resistive traces, giving the design redundancy should a failure occur in the primary heater circuit of one of the heater zones. The task of operating a feed system in conjunction with a thruster and cathode is undertaken in a series of sub-steps. The system is first assembled and operated on xenon gas, using the valves for cathode startup and thruster control based on measurement of the discharge current. After startup and control on xenon are demonstrated, the thruster will be transitioned to iodine operation, demonstrating thruster startup and feed system control while using a xenon-fed cathode. Finally, the last step is to integrate an iodine-compatible cathode with the system, demonstrate autonomous cathode start-up with open-loop control and thruster start-up with closed-loop control for multiple cycles.

Polzin, Kurt A.

Short Circuiting the Controller – Missteps in Maintenance and Inspection of Process and Wiring in STS-93

The primary objective of the Space Transportation System mission 93 (STS-93) was to deploy the Chandra X-Ray Observatory. Chandra, the world's most powerful X-Ray telescope, allowed scientists from around the world to study some of the most distant and dynamic objects in the universe. Stripped of nearly 7,000 pounds of its own gear to make room for the payload, the orbiter assigned to this mission was Space Shuttle Columbia. Prior to STS-93, Columbia had flown 25 flights and was NASA's oldest and heaviest orbiter. On July 23, 1999, after two prior launch scrubs, Eileen Collins and her crew of four launched from Kennedy Space Center. About five seconds after launch, Mission Control at Johnson Space Center detected a voltage drop on one of Columbia's electrical buses. As a result of this power fluctuation, a primary and back-up Main Engine controller dropped offline. Given design redundancy, the two remaining controllers supported all three engines. If there had been any other AC bus issues, one engine of the three on the Orbiter would have shut down. The redundant set of digital computer units in each engine controller saved Columbia and her crew from a very risky contingency abort. Post-flight inspection revealed soot on a screw head and a hole in an adjacent Kapton insulated wire. The single strand of polyimide wire was located nearly half-way down the payload bay. The Shuttle Independent Assessment Team (SIAT) reported that the wire had rubbed and chaffed against a burred screw head. The burr was later determined to be the result of overtightening of the screw by a technician during a maintenance refurbishment. Alone, the burr may not have been problematic, but later, during another ground processing event, possibly years after, someone inadvertently stepped on the wiring harness. With the pressure and motion of unintended contact, some of the Kapton insulation rubbed off against the burred screw head. The SIAT suspected the wire damage was pre-existing and was caused 4 or 5 years prior to the flight. Finally, the intense vibrations during the launch sequence allowed contact between the exposed conductor and exposed metal area on the burred screw head, resulting in the arcing and shorting of the wire. Due to the quick turnaround times of Space Shuttle Orbiters, wiring issues caused from multiple maintenance events were often overlooked. Additionally, failing to incorporate thorough and early inclusion of human systems integration (HSI) applications as a crucial part of the decision process can result in these types of misshaps. In order to reduce human error associated with integrated manufacturing, maintenance, refurbishment and flight preparations, wire inspection criteria should be refined and standardized, visual inspection processes should be quantified, and technicians should be certified by specially trained instructors. This case, among many others, unveils why human error management and development of safety metrics is a vital piece in the development of complex systems, and why it should be supported aggressively and implemented program wide.

Human Systems Integration

Performance Evaluation of a Vapor-compression-cycle Based Heat Pump System for a Lunar Habitat under the Impact of Dust Deposits on the Coupled Radiators

Space exploration gains new momentum. A near goal is set by NASA to return humans to the Moon andestablish a sustainable presence on the lunar surface for more repeatable and affordable expeditions.The lunar dust is one of the dangerous environment hazard causing serious problems for explorationactivities. In this paper, in order to study the impact of lunar dust on the performance of a thermalmanagement system for a lunar habitat, a dynamical model of an active thermal control system that iscomprised of a vapor-compression cycle heat pump and a radiator loop is developed. A heat pump to liftthe heat rejection temperature is required due to high lunar daytime surface temperature. Parametricstudies on radiator size, percentage of dust coverage on the radiator, and lunar habitat location arecarried out. The results show that lunar deposits can significantly increase the power consumption ofthe thermal management system. A dust covered radiator panel results in net heat input to the heattransfer fluid during the period of strong solar irradiance, causing deteriorated performance of theradiator loop. The lunar dust contamination problem raises the requirement of redundancy design of asystem for fault tolerance. A synergetic design of a thermal management system, a power generationsystem and robotic maintenance system is proposed to achieve maximal mass cut for a whole lunarhabitat system.

Chunjian Pan

Analytical redundancy and the design of robust failure detection systems

The Failure Detection and Identification (FDI) process is viewed as consisting of two stages: residual generation and decision making. It is argued that a robust FDI system can be achieved by designing a robust residual generation process. Analytical redundancy, the basis for residual generation, is characterized in terms of a parity space. Using the concept of parity relations, residuals can be generated in a number of ways and the design of a robust residual generation process can be formulated as a minimax optimization problem. An example is included to illustrate this design methodology. Previously announcedd in STAR as N83-20653

Chow, E. Y.

Handbook: Design of automated redundancy verification

The use of the handbook is discussed and the design progress is reviewed. A description of the problem is presented, and examples are given to illustrate the necessity for redundancy verification, along with the types of situations to which it is typically applied. Reusable space vehicles, such as the space shuttle, are recognized as being significant in the development of the automated redundancy verification problem.

Ford, F. A.

Use of residual redundancy in the design of joint source/channel coders

A technique for providing error protection without the additional overhead required for channel coding is developed, starting from the premise that, during source coder design, for the sake of simplicity or due to imperfect knowledge, assumptions have to be made about the source which are often incorrect. This results in residual redundancy at the output of the source coder. The residual redundancy can then be used to provide error protection in much the same way as the insertion of redundancy in convolutional coding provides error protection. To show the validity of this approach, it is applied to image coding using differential pulse code modulation (DPCM). Substantial performance gains are obtained, in terms of both objective and subjective measures.

Sayood, Khalid

Preliminary design of the redundant software experiment

The goal of the present experiment is to characterize the fault distributions of highly reliable software replicates, constructed using techniques and environments which are similar to those used in comtemporary industrial software facilities. The fault distributions and their effect on the reliability of fault tolerant configurations of the software will be determined through extensive life testing of the replicates against carefully constructed randomly generated test data. Each detected error will be carefully analyzed to provide insight in to their nature and cause. A direct objective is to develop techniques for reducing the intensity of coincident errors, thus increasing the reliability gain which can be achieved with fault tolerance. Data on the reliability gains realized, and the cost of the fault tolerant configurations can be used to design a companion experiment to determine the cost effectiveness of the fault tolerant strategy. Finally, the data and analysis produced by this experiment will be valuable to the software engineering community as a whole because it will provide a useful insight into the nature and cause of hard to find, subtle faults which escape standard software engineering validation techniques and thus persist far into the software life cycle.

Campbell, Roy

The design of an automated verification of redundant systems

Handbook describes design processes, presents design considerations and techniques, gives tutorial material on implementation and methodology, shows design aids, illustrates use of design aids and application samples, and identifies general practices to be adhered to or avoided.

Ford, F. A.

Study of techniques for redundancy verification without disrupting systems, phases 1-3

The problem of verifying the operational integrity of redundant equipment and the impact of a requirement for verification on such equipment are considered. Redundant circuits are examined and the characteristics which determine adaptability to verification are identified. Mutually exclusive and exhaustive categories for verification approaches are established. The range of applicability of these techniques is defined in terms of signal characteristics and redundancy features. Verification approaches are discussed and a methodology for the design of redundancy verification is developed. A case study is presented which involves the design of a verification system for a hypothetical communications system. Design criteria for redundant equipment are presented. Recommendations for the development of technological areas pertinent to the goal of increased verification capabilities are given.

Source record

AFTI/F-111 MAW flight control system and redundancy management description

The wing on the NASA F-111 transonic aircraft technology (TACT) airplane was modified to provide flexible leading and trailing edge flaps; this modified wing is known as the mission adaptive wing (MAW). A dual digital primary fly-by-wire flight control system was developed with analog backup reversion for redundancy. This report discusses the functions, design, and redundancy management of the flight control system for these flaps.

Larson, Richard R.