Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Isolation”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 433 records · Page 24

Galileo spacecraft power management and distribution system

The Galileo PMAD (power management and distribution system) is described, and the design drivers that established the final as-built hardware are discussed. The spacecraft is powered by two general-purpose heat-source-radioisotope thermoelectric generators. Power bus regulation is provided by a shunt regulator. Galileo PMAD distributes a 570-W beginning of mission (BOM) power source to a user complement of some 137 load elements. Extensive use of pyrotechnics requires two pyro switching subassemblies. They initiate 148 squibs which operate the 47 pyro devices on the spacecraft. Detection and correction of faults in the Galileo PMAD is an autonomous feature dictated by requirements for long life and reliability in the absence of ground-based support. Volatile computer memories in the spacecraft command and data system and attitude control system require a continuous source of backup power during all anticipated power bus fault scenarios. Power for the Jupiter Probe is conditioned, isolated, and controlled by a Probe interface subassembly. Flight performance of the spacecraft and the PMAD has been successful to date, with no major anomalies.

Detwiler, R. C.↗

Lower Level Repair Can Easily Fail Due to High Complexity

The International Space Station (ISS) uses Orbital Replacement Units (ORU’s) to repair failures on orbit. Using ORU’s reduces the crew time required to repair failures, but several copies of each ORU must be stored on ISS to ensure system availability. A typical ORU contains many components and has significant mass, but each ORU can repair only a single component failure. A full set of the ORU internal components could repair many different failures. Lower level assembly or component repair should reduce total spares mass. Successful electronics repair experiments were conducted on ISS. However, implementing component level repair would require a significant effort. The systems must be designed so they can be repaired during a mission, considering component layout and accessibility. The repair procedures must be developed and repair facilities, tools, and diagnostic and test instruments provided. Tracing a fault to a component is much more difficult than isolating it to an ORU. Replacing a component is much more difficult than replacing an ORU. Some problems with lower level repair are discussed. The mass savings of lower level repair will not save as much launch cost as before since launch cost has recently been reduced by an order of magnitude. Most system failures are not component failures that can be fixed by replacing a component but are due to system level problems. Repair and maintenance should be planned as part of an overall maintainability design. The risk that a lower level repair will fail is considerably greater than when using ORUs. With modern high reliability packaged systems, failure diagnosis and repair has become a lost art. However, diagnosis and repair data from the 1960’s show that increasing complexity often causes much longer diagnosis and repair times and may prevent successful repair. Increasing complexity by using lower level repair directly increases system cost, failure rate, crew time for repair, and the risk of an unrepairable system failure.

Harry W Jones↗

Flight test results of failure detection and isolation algorithms for a redundant strapdown inertial measurement unit

Flight test results for two sensor fault-tolerant algorithms developed for a redundant strapdown inertial measurement unit are presented. The inertial measurement unit (IMU) consists of four two-degrees-of-freedom gyros and accelerometers mounted on the faces of a semi-octahedron. Fault tolerance is provided by edge vector test and generalized likelihood test algorithms, each of which can provide dual fail-operational capability for the IMU. To detect the wide range of failure magnitudes in inertial sensors, which provide flight crucial information for flight control and navigation, failure detection and isolation are developed in terms of a multi level structure. Threshold compensation techniques, developed to enhance the sensitivity of the failure detection process to navigation level failures, are presented. Four flight tests were conducted in a commercial transport-type environment to compare and determine the performance of the failure detection and isolation methods. Dual flight processors enabled concurrent tests for the algorithms. Failure signals such as hard-over, null, or bias shift, were added to the sensor outputs as simple or multiple failures during the flights. Both algorithms provided timely detection and isolation of flight control level failures. The generalized likelihood test algorithm provided more timely detection of low-level sensor failures, but it produced one false isolation. Both algorithms demonstrated the capability to provide dual fail-operational performance for the skewed array of inertial sensors.

Morrell, F. R.↗

Fault Tree Based Diagnosis with Optimal Test Sequencing for Field Service Engineers

When field service engineers go to customer sites to service equipment, they want to diagnose and repair failures quickly and cost effectively. Symptoms exhibited by failed equipment frequently suggest several possible causes which require different approaches to diagnosis. This can lead the engineer to follow several fruitless paths in the diagnostic process before they find the actual failure. To assist in this situation, we have developed the Fault Tree Diagnosis and Optimal Test Sequence (FTDOTS) software system that performs automated diagnosis and ranks diagnostic hypotheses based on failure probability and the time or cost required to isolate and repair each failure. FTDOTS first finds a set of possible failures that explain exhibited symptoms by using a fault tree reliability model as a diagnostic knowledge to rank the hypothesized failures based on how likely they are and how long it would take or how much it would cost to isolate and repair them. This ordering suggests an optimal sequence for the field service engineer to investigate the hypothesized failures in order to minimize the time or cost required to accomplish the repair task. Previously, field service personnel would arrive at the customer site and choose which components to investigate based on past experience and service manuals. Using FTDOTS running on a portable computer, they can now enter a set of symptoms and get a list of possible failures ordered in an optimal test sequence to help them in their decisions. If facilities are available, the field engineer can connect the portable computer to the malfunctioning device for automated data gathering. FTDOTS is currently being applied to field service of medical test equipment. The techniques are flexible enough to use for many different types of devices. If a fault tree model of the equipment and information about component failure probabilities and isolation times or costs are available, a diagnostic knowledge base for that device can be developed easily.

Iverson, David L.↗

Model-based reasoning for power system management using KATE and the SSM/PMAD

The overall goal of this research effort has been the development of a software system which automates tasks related to monitoring and controlling electrical power distribution in spacecraft electrical power systems. The resulting software system is called the Intelligent Power Controller (IPC). The specific tasks performed by the IPC include continuous monitoring of the flow of power from a source to a set of loads, fast detection of anomalous behavior indicating a fault to one of the components of the distribution systems, generation of diagnosis (explanation) of anomalous behavior, isolation of faulty object from remainder of system, and maintenance of flow of power to critical loads and systems (e.g. life-support) despite fault conditions being present (recovery). The IPC system has evolved out of KATE (Knowledge-based Autonomous Test Engineer), developed at NASA-KSC. KATE consists of a set of software tools for developing and applying structure and behavior models to monitoring, diagnostic, and control applications.

Morris, Robert A.↗

Power system monitoring and source control of the Space Station Freedom DC power system testbed

Unlike a terrestrial electric utility which can purchase power from a neighboring utility, the Space Station Freedom (SSF) has strictly limited energy resources; as a result, source control, system monitoring, system protection, and load management are essential to the safe and efficient operation of the SSF Electric Power System (EPS). These functions are being evaluated in the DC Power Management and Distribution (PMAD) Testbed which NASA LeRC has developed at the Power System Facility (PSF) located in Cleveland, Ohio. The testbed is an ideal platform to develop, integrate, and verify power system monitoring and control algorithms. State Estimation (SE) is a monitoring tool used extensively in terrestrial electric utilities to ensure safe power system operation. It uses redundant system information to calculate the actual state of the EPS, to isolate faulty sensors, to determine source operating points, to verify faults detected by subsidiary controllers, and to identify high impedance faults. Source control and monitoring safeguard the power generation and storage subsystems and ensure that the power system operates within safe limits while satisfying user demands with minimal interruptions. System monitoring functions, in coordination with hardware implemented schemes, provide for a complete fault protection system. The objective of this paper is to overview the development and integration of the state estimator and the source control algorithms.

Kimnach, Greg L.↗

Power system monitoring and source control of the Space Station Freedom dc-power system testbed

Unlike a terrestrial electric utility which can purchase power from a neighboring utility, the Space Station Freedom (SSF) has strictly limited energy resources; as a result, source control, system monitoring, system protection, and load management are essential to the safe and efficient operation of the SSF Electric Power System (EPS). These functions are being evaluated in the dc Power Management and Distribution (PMAD) Testbed which NASA LeRC has developed at the Power System Facility (PSF) located in Cleveland, Ohio. The testbed is an ideal platform to develop, integrate, and verify power system monitoring and control algorithms. State Estimation (SE) is a monitoring tool used extensively in terrestrial electric utilities to ensure safe power system operation. It uses redundant system information to calculate the actual state of the EPS, to isolate faulty sensors, to determine source operating points, to verify faults detected by subsidiary controllers, and to identify high impedance faults. Source control and monitoring safeguard the power generation and storage subsystems and ensure that the power system operates within safe limits while satisfying user demands with minimal interruptions. System monitoring functions, in coordination with hardware implemented schemes, provide for a complete fault protection system. The objective of this paper is to overview the development and integration of the state estimator and the source control algorithms.

Kimnach, Greg L.↗

Advanced Power Regulator Developed for Spacecraft

The majority of new satellites generate electrical power using photovoltaic solar arrays and store energy in batteries for use during eclipse periods. Careful regulation of battery charging during insolation can greatly increase the expected lifetime of the satellite. The battery charge regulator is usually custom designed for each satellite and its specific mission. Economic competition in the small satellite market requires battery charge regulators that are lightweight, efficient, inexpensive, and modular enough to be used in a wide variety of satellites. A new battery charge regulator topology has been developed at the NASA Lewis Research Center to address these needs. The new regulator topology uses industry-standard dc-dc converters and a unique interconnection to provide size, weight, efficiency, fault tolerance, and modularity benefits over existing systems. A transformer-isolated buck converter is connected such that the high input line is connected in series with the output. This "bypass connection" biases the converter's output onto the solar array voltage. Because of this biasing, the converter only processes the fraction of power necessary to charge the battery above the solar array voltage. Likewise, the same converter hookup can be used to regulate the battery output to the spacecraft power bus with similar fractional power processing. The advantages of this scheme are: 1) Because only a fraction of the power is processed through the dc-dc converter, the single- stage conversion efficiency is 94 to 98 percent; 2) Costly, high-efficiency dc-dc converters are not necessary for high end-to-end system efficiency; 3) The system is highly fault tolerant because the bypass connection will still deliver power if the dc-dc converter fails; and 4) The converters can easily be connected in parallel, allowing higher power systems to be built from a common building block. This new technology will be spaceflight tested in the Photovoltaic Regulator Kit Experiment (PRKE) on TRW's Small Spacecraft Technology Initiative (SSTI) satellite scheduled for launch in 1996. This experiment uses commercial dc-dc converters (28 to 15 Vdc) and additional control circuitry to regulate current to a battery load. The 60-W, 87- percent efficiency converters can control 180 W of power at an efficiency of 94 percent in the new configuration. The power density of the Photovoltaic Regulator Kit Experiment is about 200 W/kg.

Source record↗

Extension and strain in Northern Tharsis

The northern areas of Tharsis, south of Alba Patera, are remarkable in that they are dominated by extensive, generally north trending graben. Some graben are small isolated features whereas others are complex overlapping features in which individual fault pairs are impossible to separate. This pattern indicates an east-west extensional stress regime, consistent with stress models for Tharsis. To estimate the regional east-west extension and strain, graben along a profile at 35 N latitude, between longitudes 135 and 93 degs were studied. This profile was chosen because the graben have a northerly trend, the structures are relatively simple, the profile is anchored to ancient Noachian age crust, and high resolution images are available. The western end of the profile begins at Acheron Fossae and ends in the east at the southwestern part of Tempe Fossae. Plains units cut by the graben include Hesperian and Amazonian age members of the Alba Patera and Ceraunius Fossae Formations.

Plescia, J. B.↗

System Modeling and Diagnostics for Liquefying-Fuel Hybrid Rockets

A Hybrid Combustion Facility (HCF) was recently built at NASA Ames Research Center to study the combustion properties of a new fuel formulation that burns approximately three times faster than conventional hybrid fuels. Researchers at Ames working in the area of Integrated Vehicle Health Management recognized a good opportunity to apply IVHM techniques to a candidate technology for next generation launch systems. Five tools were selected to examine various IVHM techniques for the HCF. Three of the tools, TEAMS (Testability Engineering and Maintenance System), L2 (Livingstone2), and RODON, are model-based reasoning (or diagnostic) systems. Two other tools in this study, ICS (Interval Constraint Simulator) and IMS (Inductive Monitoring System) do not attempt to isolate the cause of the failure but may be used for fault detection. Models of varying scope and completeness were created, both qualitative and quantitative. In each of the models, the structure and behavior of the physical system are captured. In the qualitative models, the temporal aspects of the system behavior and the abstraction of sensor data are handled outside of the model and require the development of additional code. In the quantitative model, less extensive processing code is also necessary. Examples of fault diagnoses are given.

Poll, Scott↗

Advanced Power Regulator Developed for Spacecraft

The majority of new satellites generate electrical power using photovoltaic solar arrays and store energy in batteries for use during eclipse periods. Careful regulation of battery charging during insolation can greatly increase the expected lifetime of the satellite. The battery charge regulator is usually custom designed for each satellite and its specific mission. Economic competition in the small satellite market requires battery charge regulators that are lightweight, efficient, inexpensive, and modular enough to be used in a wide variety of satellites. A new battery charge regulator topology has been developed at the NASA Lewis Research Center to address these needs. The new regulator topology uses industry-standard dc-dc converters and a unique interconnection to provide size, weight, efficiency, fault tolerance, and modularity benefits over existing systems. A transformer-isolated buck converter is connected such that the high input line is connected in series with the output. This "bypass connection" biases the converter's output onto the solar array voltage. Because of this biasing, the converter only processes the fraction of power necessary to charge the battery above the solar array voltage. Likewise, the same converter hookup can be used to regulate the battery output to the spacecraft power bus with similar fractional power processing.

Source record↗

Thermal Management and Power Packaging for Spacecraft of the Next Millennium

Power Distribution; Cabling, fault protection and switches to turn power on/off to spacecraft loads; Isolate loads from bus noise and regulate power to load against disturbances from the load and the bus; Protect the power distribution system from load failures.

X2000 Thermal management Power Packaging Next Mill↗

Modeling and Diagnostic Software for Liquefying-Fuel Rockets

A report presents a study of five modeling and diagnostic computer programs considered for use in an integrated vehicle health management (IVHM) system during testing of liquefying-fuel hybrid rocket engines in the Hybrid Combustion Facility (HCF) at NASA Ames Research Center. Three of the programs -- TEAMS, L2, and RODON -- are model-based reasoning (or diagnostic) programs. The other two programs -- ICS and IMS -- do not attempt to isolate the causes of failures but can be used for detecting faults. In the study, qualitative models (in TEAMS and L2) and quantitative models (in RODON) having varying scope and completeness were created. Each of the models captured the structure and behavior of the HCF as a physical system. It was noted that in the cases of the qualitative models, the temporal aspects of the behavior of the HCF and the abstraction of sensor data are handled outside of the models, and it is necessary to develop additional code for this purpose. A need for additional code was also noted in the case of the quantitative model, though the amount of development effort needed was found to be less than that for the qualitative models.

Poll, Scott↗

Flight test results of the Strapdown hexad Inertial Reference Unit (SIRU). Volume 1: Flight test summary

Flight test results of the strapdown inertial reference unit (SIRU) navigation system are presented. The fault-tolerant SIRU navigation system features a redundant inertial sensor unit and dual computers. System software provides for detection and isolation of inertial sensor failures and continued operation in the event of failures. Flight test results include assessments of the system's navigational performance and fault tolerance.

Hruby, R. J.↗

Flight test results of the strapdown hexad inertial reference unit (SIRU). Volume 2: Test report

Results of flight tests of the Strapdown Inertial Reference Unit (SIRU) navigation system are presented. The fault tolerant SIRU navigation system features a redundant inertial sensor unit and dual computers. System software provides for detection and isolation of inertial sensor failures and continued operation in the event of failures. Flight test results include assessments of the system's navigational performance and fault tolerance. Performance shortcomings are analyzed.

Hruby, R. J.↗

Flight test results of the Strapdown hexad Inertial Reference Unit (SIRU). Volume 3: Appendices A-G

Results of flight tests of the Strapdown Inertial Reference Unit (SIRU) navigation system are presented. The fault tolerant SIRU navigation system features a redundant inertial sensor unit and dual computers. System software provides for detection and isolation of inertial sensor failures and continued operation in the event of failures. Flight test results include assessments of the system's navigational performance and fault tolerance. Selected facets of the flight tests are also described in detail and include some of the following: (1) flight test plans and ground track plots; (2) navigation residual plots; (3) effects of approximations in navigation algorithms; (4) vibration spectrum of the CV-340 aircraft; and (5) modification of the statistical FDICR algorithm parameters for the flight environment.

Hruby, R. J.↗

Some methods of estimating a coverage parameter

To demonstrate the high reliability of fault-tolerant computing systems, experimental testing can be performed by injecting faults into their hardware and observing the times needed to detect and isolate failed components and reconfigure the good components. Coverage, a parameter measuring continued system success, is the probability that recovery occurs before other, perhaps catastrophic, component failures occur. Methods of estimating coverage are given for the case of randomly selecting a subset of the pins or chips for testing. Pin-level samples of times to recovery are treated by the Type I censoring model often used in life testing.

Lee, L. D.↗

Tectonics of the Outer Planet Satellites

Tectonic features on the satellites of the outer planets range from the familiar, such as clearly recognizable graben on many satellites, to the bizarre, such as the ubiquitous double ridges on Europa, the twisting sets of ridges on Triton, or the isolated giant mountains rising from Io's surface. All of the large and middle-sized outer planet satellites except Io are dominated by water ice near their surfaces. Though ice is a brittle material at the cold temperatures found in the outer solar system, the amount of energy it takes to bring it close to its melting point is lower than for a rocky body. Therefore, some unique features of icy satellite tectonics may be influenced by a near-surface ductile layer beneath the brittle surface material, and several of the icy satellites may possess subsurface oceans. Sources of stress to drive tectonism are commonly dominated by the tides that deform these satellites as they orbit their primary giant planets. On several satellites, the observed tectonic features may be the result of changes in their tidal figures, or motions of their solid surfaces with respect to their tidal figures. Other driving mechanisms for tectonics include volume changes due to ice or water phase changes in the interior, thermoelastic stress, deformation of the surface above rising diapirs of warm ice, and motion of subsurface material toward large impact basins as they fill in and relax. Most satellites exhibit evidence for extensional deformation, and some exhibit strike-slip faulting, whereas contractional tectonism appears to be rare. Io s surface is unique, exhibiting huge isolated mountains that may be blocks of crust tilting and foundering into the rapidly emptying interior as the surface is constantly buried by deposits from hyperactive volcanoes. Of the satellites, diminutive Enceladus is spectacularly active; its south polar terrain is a site of young tectonism, copious heat flow, and tall plumes venting into space. Europa's surface is pervasively tectonized, covered with a diverse array of exotic and incompletely understood tectonic features. The paucity of impact craters on Europa suggests that its tectonic activity is ongoing. Geysers on Triton show that some degree of current activity, while tectonic features that cross sparsely cratered terrain indicate that it may also be tectonically active. Ganymede and Miranda both exhibit ancient terrains that have been pulled apart by normal faulting. On Ganymede these faults form a global network, while they are confined to regional provinces on Miranda. Ariel, Dione, Tethys, Rhea, and Titania all have systems of normal faults cutting across their surfaces, though the rifting is less pronounced than it is on Ganymede and Miranda. Iapetus exhibits a giant equatorial ridge that has defied simple explanation. The rest of the large and middle-sized satellites show very little evidence for tectonic features on their surfaces, though the exploration of Titan's surface has just begun.

McKinnon, W. B.↗