Search NASA⌕ Search

SEARCH · Search NASA

Results for “REDUNDANT SYSTEM”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Simulation and simulator development of a separate surface attitude command control system for light aircraft

A detailed description is presented of the simulation philosophy and process used in the development of a Separate Surface Attitude Command control system (SSAC) for a Beech Model 99 Airliner. The intent of this system is to provide complete three axes stability augmentation at low cost and without the need for system redundancy. The system, although aimed at the general aviation market, also has applications to certain military airplanes as well as to miniature submarines.

Roskam, J.↗

Space Shuttle Solid Rocket Motor Program - Lessons learned

An evaluation is given of the most important lessons learned concerning the Space Shuttle's Solid Rocket Motors with respect to flight safety, reuse requirements, system reliability, structural integrity, and hardware damage due to reentry, water impact, and retrieval. Within the major categories of flight safety, performance, and reuse/cost, priorities are identified for implementation of envisioned improvements; schedule and cost considerations are noted to have been substantially downgraded in favor of flight safety. The consequences of the primacy of flight safety are discussed in the areas of primary systems design, redundant systems, manufacturing and assembly processing, and launch constraints.

Mccool, A. A.↗

Space Shuttle GN and C Development History and Evolution

Completion of the final Space Shuttle flight marks the end of a significant era in Human Spaceflight. Developed in the 1970 s, first launched in 1981, the Space Shuttle embodies many significant engineering achievements. One of these is the development and operation of the first extensive fly-by-wire human space transportation Guidance, Navigation and Control (GN&C) System. Development of the Space Shuttle GN&C represented first time inclusions of modern techniques for electronics, software, algorithms, systems and management in a complex system. Numerous technical design trades and lessons learned continue to drive current vehicle development. For example, the Space Shuttle GN&C system incorporated redundant systems, complex algorithms and flight software rigorously verified through integrated vehicle simulations and avionics integration testing techniques. Over the past thirty years, the Shuttle GN&C continued to go through a series of upgrades to improve safety, performance and to enable the complex flight operations required for assembly of the international space station. Upgrades to the GN&C ranged from the addition of nose wheel steering to modifications that extend capabilities to control of the large flexible configurations while being docked to the Space Station. This paper provides a history of the development and evolution of the Space Shuttle GN&C system. Emphasis is placed on key architecture decisions, design trades and the lessons learned for future complex space transportation system developments. Finally, some of the interesting flight operations experience is provided to inform future developers of flight experiences.

Zimpfer, Douglas↗

AFTI/F-16 flight test results and lessons

The AFTI/F-16 flight test program is summarized, and several design issues of general interest are addressed. A brief description is given of the test vehicle, its flight control modes, and the flight envelopes in which testing was performed. Flight test results are summarized by addressing benefits experienced in flight control task-tailoring, handling qualities in mission tasks, aircraft structure considerations, digital flight control system performance, and human factors. Finally, several design issues relevant to future fighter aircraft are examined, including degraded flight control, system complexity, simplex information in redundant systems, and single failure propagation in redundant systems.

Ishmael, S. D.↗

Requirement analysis of an intelligent, redundant, actuation system

The reliability and fault tolerance requirements of integrated, critical, digital fly-by-wire control systems for advanced military and civil aircraft requires redundant, reconfigurable implementations of the actuation system. An effective way for controlling the actuators and implementing the required fault detection and reconfiguration strategies is by means of dedicated microprocessors. This paper describes a laboratory implementation of a flexible intelligent redundant actuation system capable of demonstrating the concept and analyzing a variety of configurations and technical issues.

De Feo, P.↗

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures↗

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures↗

Effectiveness of Redundant Communications Systems in Maintaining Operational Control of Small Unmanned Aircraft

As a part of NASA’s Unmanned Aircraft System (UAS) Traffic Management (UTM) research, a test was performed to evaluate the effectiveness of the redundant Command and Control (C2) communications system for maintaining operational control of small UAS in the airspace over a rural area. In the test, operators set up a primary and a secondary UAS C2 communications system, sent a maneuver command to an Unmanned Aircraft (UA) with and without a functioning primary system, then verified the execution of the sent command to confirm the operator control. Operators reported that the tested redundancy configurations were effective in maintaining operational control in the test airspace over rural locations. Since the next phase of UTM research focuses on operations in an urban area where an increased level of Radio Frequency (RF) activities occur compared to a rural area, four recommendations are provided to sustain the effectiveness of redundancy in urban operations. First, the operator should not include C2 systems that use the industrial, scientific, and medical (ISM) radio bands in redundancy configurations. Second, the operator should verify the RF characteristics of the intended operation area and examine the area’s radio noise floor. Third, the operator should monitor the availability, quality, and reliability of communications services used by a redundant system. Fourth, the small UAS community should adopt a standard set of contingency steps to handle the loss of C2 communications so that such events are managed in a consistent manner across the airspace. The insights from the test will be used to accommodate the FAA’s UAS integration effort.

Jung, Jaewoo↗

Common Cause Failure Modeling

Common Cause Failures (CCFs) are a known and documented phenomenon that defeats system redundancy. CCFS are a set of dependent type of failures that can be caused by: system environments; manufacturing; transportation; storage; maintenance; and assembly, as examples. Since there are many factors that contribute to CCFs, the effects can be reduced, but they are difficult to eliminate entirely. Furthermore, failure databases sometimes fail to differentiate between independent and CCF (dependent) failure and data is limited, especially for launch vehicles. The Probabilistic Risk Assessment (PRA) of NASA's Safety and Mission Assurance Directorate at Marshall Space Flight Center (MFSC) is using generic data from the Nuclear Regulatory Commission's database of common cause failures at nuclear power plants to estimate CCF due to the lack of a more appropriate data source. There remains uncertainty in the actual magnitude of the common cause risk estimates for different systems at this stage of the design. Given the limited data about launch vehicle CCF and that launch vehicles are a highly redundant system by design, it is important to make design decisions to account for a range of values for independent and CCFs. When investigating the design of the one-out-of-two component redundant system for launch vehicles, a response surface was constructed to represent the impact of the independent failure rate versus a common cause beta factor effect on a system's failure probability. This presentation will define a CCF and review estimation calculations. It gives a summary of reduction methodologies and a review of examples of historical CCFs. Finally, it presents the response surface and discusses the results of the different CCFs on the reliability of a one-out-of-two system.

Hark, Frank↗

Common Cause Failure Modeling

Common Cause Failures (CCFs) are a known and documented phenomenon that defeats system redundancy. CCFS are a set of dependent type of failures that can be caused by: system environments; manufacturing; transportation; storage; maintenance; and assembly, as examples. Since there are many factors that contribute to CCFs, the effects can be reduced, but they are difficult to eliminate entirely. Furthermore, failure databases sometimes fail to differentiate between independent and CCF (dependent) failure and data is limited, especially for launch vehicles. The Probabilistic Risk Assessment (PRA) of NASA's Safety and Mission Assurance Directorate at Marshal Space Flight Center (MFSC) is using generic data from the Nuclear Regulatory Commission's database of common cause failures at nuclear power plants to estimate CCF due to the lack of a more appropriate data source. There remains uncertainty in the actual magnitude of the common cause risk estimates for different systems at this stage of the design. Given the limited data about launch vehicle CCF and that launch vehicles are a highly redundant system by design, it is important to make design decisions to account for a range of values for independent and CCFs. When investigating the design of the one-out-of-two component redundant system for launch vehicles, a response surface was constructed to represent the impact of the independent failure rate versus a common cause beta factor effect on a system's failure probability. This presentation will define a CCF and review estimation calculations. It gives a summary of reduction methodologies and a review of examples of historical CCFs. Finally, it presents the response surface and discusses the results of the different CCFs on the reliability of a one-out-of-two system.

Hark, Frank↗

Logic redundancy improves digital system reliability

Redundant-channel system automatically corrects any single error in a set of three binary signal channels. This system is especially applicable to digital computers where data is transmitted in parallel channels.

Source record↗

An evaluation plan of bus architectures and protocols using the NASA Ames intelligent redundant actuation system

Means for evaluating data bus architectures and protocols for highly integrated flight control system applications are needed. Described are the criteria and plans to do this by using the NASA/Ames Intelligent Redundant Actuation System (IRAS) experimental set-up. Candidate bus architectures differ from one another in terms of: topology, access control, message transfer schemes, message characteristics, initialization. data flow control, transmission rates, fault tolerance, and time synchronization. The evaluation criteria are developed relative to these features. A preliminary, analytical evaluation of four candidate busses (MIL-STD-1553B, DATAC, Ethernet, and HSIS) is described. A bus must be exercised in a real-time environment to evaluate its dynamic characteristics. A plan for real-time evaluation of these four busses using a combination of hardware and simulation techniques is presented.

Defeo, P.↗

Gyro and accelerometer failure detection and identification in redundant sensor systems

Algorithms for failure detection and identification for redundant noncolinear arrays of single degree of freedom gyros and accelerometers are described. These algorithms are optimum in the sense that detection occurs as soon as it is no longer possible to account for the instrument outputs as the outputs of good instruments operating within their noise tolerances, and identification occurs as soon as it is true that only a particular instrument failure could account for the actual instrument outputs within the noise tolerance of good instruments. An estimation algorithm is described which minimizes the maximum possible estimation error magnitude for the given set of instrument outputs. Monte Carlo simulation results are presented for the application of the algorithms to an inertial reference unit consisting of six gyros and six accelerometers in two alternate configurations.

Potter, J. E.↗

Gyro and accelerometer failure detection and identification in redundant sensor systems.

An algorithm for failure detection and identification for redundant non-orthogonal arrays of single degree of freedom gyros and accelerometers is described which is optimum in the sense that detection occurs as soon as it is no longer possible to account for the instrument outputs as the outputs of good instruments operating within their noise tolerances, and identification occurs as soon as it is true that only a particular instrument failure could account for the actual instrument outputs within the noise tolerance of good instruments. An estimation algorithm is described which minimizes the maximum possible error magnitude for the given set of instrument outputs. Monte Carlo simulation results are presented for the application of the algorithms to an inertial reference unit consisting of six gyros and six accelerometers in two alternate configurations.

Potter, J. E.↗