Search NASASearch

SEARCH · Search NASA

Results for “Systems Engineering, Failure Prevention”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Success Path Method: Conformance with Safety Management Systems

All industrial facilities deal with safety hazards such as equipment failures, chemical and toxic releases, and fires and explosions just to name a few. A disciplined framework for managing the integrity of operating systems and processes that handle hazardous substances by applying good design principles, engineering, and operating practices is called process safety. The goal of such framewoks is to prevent the release of energy or material that could cause harm to people or damage to equipment and/or environment. Process safety covers all aspects of facility operation also including design, maintenance, and human and organizational factors that could possibly have effect on process safety. As it will be seen from the discussion below, process safety is just one of the pieces of the much bigger matter, a safety culture. Many industries have long recognized the importance of safety culture in their day-to-day operation. Although the definition of safety culture can slightly differ from organization to organization, in general, a safety culture is how things are done to demonstrate a commitment to safety by everyone involved. An organization acquires safety culture over time as the product of individual and group values, actions, and behaviors toward overall safety. It is important to note that safety culture should not be viewed as some static state that an organization wants to reach. It is more like a constantly evolving level of “how things are done when nobody is watching.” Safety culture is an inherent characteristic of an organization, it is always present, but the level can range on a continuum from undesirable to desirable or more commonly used, from negative to positive. An example for an undesirable, negative safety culture would be a company in which accidents resulting in harm (physical and/or emotional) of its employees, equipment or surrounding environment and community occur frequently. At the other end of the spectrum would be a company in which such accidents are rare or do not occur at all (desired or positive safety culture). Every company/industry exists somewhere within this spectrum.

42 ENGINEERING

Outbrief - Long Life Rocket Engine Panel

This white paper is an overview of the JANNAF Long Life Rocket Engine (LLRE) Panel results from the last several years of activity. The LLRE Panel has met over the last several years in order to develop an approach for the development of long life rocket engines. Membership for this panel was drawn from a diverse set of the groups currently working on rocket engines (Le. government labs, both large and small companies and university members). The LLRE Panel was formed in order to determine the best way to enable the design of rocket engine systems that have life capability greater than 500 cycles while meeting or exceeding current performance levels (Specific Impulse and Thrust/Weight) with a 1/1,OOO,OOO likelihood of vehicle loss due to rocket system failure. After several meetings and much independent work the panel reached a consensus opinion that the primary issues preventing LLRE are a lack of: physics based life prediction, combined loads prediction, understanding of material microphysics, cost effective system level testing. and the inclusion of fabrication process effects into physics based models. With the expected level of funding devoted to LLRE development, the panel recommended that fundamental research efforts focused on these five areas be emphasized.

Quinn, Jason Eugene

What Reliability Engineers Should Know about Space Radiation Effects

Space radiation in space systems present unique failure modes and considerations for reliability engineers. Radiation effects is not a one size fits all field. Threat conditions that must be addressed for a given mission depend on the mission orbital profile, the technologies of parts used in critical functions and on application considerations, such as supply voltages, temperature, duty cycle, and redundancy. In general, the threats that must be addressed are of two types-the cumulative degradation mechanisms of total ionizing dose (TID) and displacement damage (DD). and the prompt responses of components to ionizing particles (protons and heavy ions) falling under the heading of single-event effects. Generally degradation mechanisms behave like wear-out mechanisms on any active components in a system: Total Ionizing Dose (TID) and Displacement Damage: (1) TID affects all active devices over time. Devices can fail either because of parametric shifts that prevent the device from fulfilling its application or due to device failures where the device stops functioning altogether. Since this failure mode varies from part to part and lot to lot, lot qualification testing with sufficient statistics is vital. Displacement damage failures are caused by the displacement of semiconductor atoms from their lattice positions. As with TID, failures can be either parametric or catastrophic, although parametric degradation is more common for displacement damage. Lot testing is critical not just to assure proper device fi.mctionality throughout the mission. It can also suggest remediation strategies when a device fails. This paper will look at these effects on a variety of devices in a variety of applications. This paper will look at these effects on a variety of devices in a variety of applications. (2) On the NEAR mission a functional failure was traced to a PIN diode failure caused by TID induced high leakage currents. NEAR was able to recover from the failure by reversing the current of a nearby Thermal Electric Cooler (turning the TEC into a heater). The elevated temperature caused the PIN diode to anneal and the device to recover. It was by lot qualification testing that NEAR knew the diode would recover when annealed. This paper will look at these effects on a variety of devices in a variety of applications. Single Event Effects (SEE): (1) In contrast to TID and displacement damage, Single Event Effects (SEE) resemble random failures. SEE modes can range from changes in device logic (single-event upset, or SEU). temporary disturbances (single-event transient) to catastrophic effects such as the destructive SEE modes, single-event latchup (SEL). single-event gate rupture (SEGR) and single-event burnout (SEB) (2) The consequences of nondestructive SEE modes such as SEU and SET depend critically on their application--and may range from trivial nuisance errors to catastrophic loss of mission. It is critical not just to ensure that potentially susceptible devices are well characterized for their susceptibility, but also to work with design engineers to understand the implications of each error mode. -For destructive SEE, the predominant risk mitigation strategy is to avoid susceptible parts, or if that is not possible. to avoid conditions under which the part may be susceptible. Destructive SEE mechanisms are often not well understood, and testing is slow and expensive, making rate prediction very challenging. (3) Because the consequences of radiation failure and degradation modes depend so critically on the application as well as the component technology, it is essential that radiation, component. design and system engineers work togetherpreferably starting early in the program to ensure critical applications are addressed in time to optimize the probability of mission success.

DiBari, Rebecca

Wire Rope Failure on the Guppy Winch

On January 6, 2016 at El Paso, the Guppy winch motor was changed. After completion of the operational checks, the load bar was being reinstalled on the cargo pallet when the motor control FORWARD relay failed in the energized position. The pallet was pinned at all locations (each pin has a load capacity of 16,000 lbs.) while the winch was running. The wire rope snapped before aircraft power could be removed. After disassembly, the fractured wire rope was shipped to ES4 lab for further characterization of the wire rope portion of the failure. The system was being operated without a clear understanding of the system capability and function. The proximate cause was the failure of the K48 -Forward Winch Control Relay in the energized position, which allowed the motor to continuously run without command from the hand controller, and operation of the winch system with both controllers connected to the system. This prevented the emergency stop feature on the hand controller from functioning as designed. An electrical checkout engineering work instruction was completed and identified the failed relay and confirmed the emergency stop only paused the system when the STOP button on both connected hand controllers were depressed simultaneously. The winch system incorporates a torque limiting clutch. It is suspected that the clutch did not slip and the motor did not stall or overload the current limiter. Aircraft Engineering is looking at how to change the procedures to provide a checkout of the clutch and set to a slip torque limit appropriate to support operations.

Figert, John

A Predictive Safety Management System Software Package Based on the Continuous Hazard Tracking and Failure Prediction Methodology

The goal of this research was to integrate a previously validated and reliable safety model, called Continuous Hazard Tracking and Failure Prediction Methodology (CHTFPM), into a software application. This led to the development of a safety management information system (PSMIS). This means that the theory or principles of the CHTFPM were incorporated in a software package; hence, the PSMIS is referred to as CHTFPM management information system (CHTFPM MIS). The purpose of the PSMIS is to reduce the time and manpower required to perform predictive studies as well as to facilitate the handling of enormous quantities of information in this type of studies. The CHTFPM theory encompasses the philosophy of looking at the concept of safety engineering from a new perspective: from a proactive, than a reactive, viewpoint. That is, corrective measures are taken before a problem instead of after it happened. That is why the CHTFPM is a predictive safety because it foresees or anticipates accidents, system failures and unacceptable risks; therefore, corrective action can be taken in order to prevent all these unwanted issues. Consequently, safety and reliability of systems or processes can be further improved by taking proactive and timely corrective actions.

Quintana, Rolando

Current Status of Hybrid Bearing Damage Detection

Advances in material development and processing have led to the introduction of ceramic hybrid bearings for many applications. The introduction of silicon nitride hybrid bearings into the high pressure oxidizer turbopump, on the space shuttle main engine, led NASA to solve a highly persistent and troublesome bearing problem. Hybrid bearings consist of ceramic balls and steel races. The majority of hybrid bearings utilize Si3N4 balls. The aerospace industry is currently studying the use of hybrid bearings and naturally the failure modes of these bearings become an issue in light of the limited data available. In today s turbine engines and helicopter transmissions, the health of the bearings is detected by the properties of the debris found in the lubrication line when damage begins to occur. Current oil debris sensor technology relies on the magnetic properties of the debris to detect damage. Since the ceramic rolling elements of hybrid bearings have no metallic properties, a new sensing system must be developed to indicate the system health if ceramic components are to be safely implemented in aerospace applications. The ceramic oil debris sensor must be capable of detecting ceramic and metallic component damage with sufficient reliability and forewarning to prevent a catastrophic failure. The objective of this research is to provide a background summary on what is currently known about hybrid bearing failure modes and to report preliminary results on the detection of silicon nitride debris, in oil, using a commercial particle counter.

Dempsey, Paula J.

Goal-Function Tree Modeling for Systems Engineering and Fault Management

The draft NASA Fault Management (FM) Handbook (2012) states that Fault Management (FM) is a "part of systems engineering", and that it "demands a system-level perspective" (NASAHDBK- 1002, 7). What, exactly, is the relationship between systems engineering and FM? To NASA, systems engineering (SE) is "the art and science of developing an operable system capable of meeting requirements within often opposed constraints" (NASA/SP-2007-6105, 3). Systems engineering starts with the elucidation and development of requirements, which set the goals that the system is to achieve. To achieve these goals, the systems engineer typically defines functions, and the functions in turn are the basis for design trades to determine the best means to perform the functions. System Health Management (SHM), by contrast, defines "the capabilities of a system that preserve the system's ability to function as intended" (Johnson et al., 2011, 3). Fault Management, in turn, is the operational subset of SHM, which detects current or future failures, and takes operational measures to prevent or respond to these failures. Failure, in turn, is the "unacceptable performance of intended function." (Johnson 2011, 605) Thus the relationship of SE to FM is that SE defines the functions and the design to perform those functions to meet system goals and requirements, while FM detects the inability to perform those functions and takes action. SHM and FM are in essence "the dark side" of SE. For every function to be performed (SE), there is the possibility that it is not successfully performed (SHM); FM defines the means to operationally detect and respond to this lack of success. We can also describe this in terms of goals: for every goal to be achieved, there is the possibility that it is not achieved; FM defines the means to operationally detect and respond to this inability to achieve the goal. This brief description of relationships between SE, SHM, and FM provide hints to a modeling approach to provide formal connectivity between the nominal (SE), and off-nominal (SHM and FM) aspects of functions and designs. This paper describes a formal modeling approach to the initial phases of the development process that integrates the nominal and off-nominal perspectives in a model that unites SE goals and functions of with the failure to achieve goals and functions (SHM/FM). This methodology and corresponding model, known as a Goal-Function Tree (GFT), provides a means to represent, decompose, and elaborate system goals and functions in a rigorous manner that connects directly to design through use of state variables that translate natural language requirements and goals into logical-physical state language. The state variable-based approach also provides the means to directly connect FM to the design, by specifying the range in which state variables must be controlled to achieve goals, and conversely, the failures that exist if system behavior go out-of-range. This in turn allows for the systems engineers and SHM/FM engineers to determine which state variables to monitor, and what action(s) to take should the system fail to achieve that goal. In sum, the GFT representation provides a unified approach to early-phase SE and FM development. This representation and methodology has been successfully developed and implemented using Systems Modeling Language (SysML) on the NASA Space Launch System (SLS) Program. It enabled early design trade studies of failure detection coverage to ensure complete detection coverage of all crew-threatening failures. The representation maps directly both to FM algorithm designs, and to failure scenario definitions needed for design analysis and testing. The GFT representation provided the basis for mapping of abort triggers into scenarios, both needed for initial, and successful quantitative analyses of abort effectiveness (detection and response to crew-threatening events).

Patterson, Jonathan D.

Modeling in the State Flow Environment to Support Launch Vehicle Verification Testing for Mission and Fault Management Algorithms in the NASA Space Launch System

Analysis methods and testing processes are essential activities in the engineering development and verification of the National Aeronautics and Space Administration's (NASA) new Space Launch System (SLS). Central to mission success is reliable verification of the Mission and Fault Management (M&FM) algorithms for the SLS launch vehicle (LV) flight software. This is particularly difficult because M&FM algorithms integrate and operate LV subsystems, which consist of diverse forms of hardware and software themselves, with equally diverse integration from the engineering disciplines of LV subsystems. M&FM operation of SLS requires a changing mix of LV automation. During pre-launch the LV is primarily operated by the Kennedy Space Center (KSC) Ground Systems Development and Operations (GSDO) organization with some LV automation of time-critical functions, and much more autonomous LV operations during ascent that have crucial interactions with the Orion crew capsule, its astronauts, and with mission controllers at the Johnson Space Center. M&FM algorithms must perform all nominal mission commanding via the flight computer to control LV states from pre-launch through disposal and also address failure conditions by initiating autonomous or commanded aborts (crew capsule escape from the failing LV), redundancy management of failing subsystems and components, and safing actions to reduce or prevent threats to ground systems and crew. To address the criticality of the verification testing of these algorithms, the NASA M&FM team has utilized the State Flow environment6 (SFE) with its existing Vehicle Management End-to-End Testbed (VMET) platform which also hosts vendor-supplied physics-based LV subsystem models. The human-derived M&FM algorithms are designed and vetted in Integrated Development Teams composed of design and development disciplines such as Systems Engineering, Flight Software (FSW), Safety and Mission Assurance (S&MA) and major subsystems and vehicle elements such as Main Propulsion Systems (MPS), boosters, avionics, Guidance, Navigation, and Control (GN&C), Thrust Vector Control (TVC), liquid engines, and the astronaut crew office. Since the algorithms are realized using model-based engineering (MBE) methods from a hybrid of the Unified Modeling Language (UML) and Systems Modeling Language (SysML), SFE methods are a natural fit to provide an in depth analysis of the interactive behavior of these algorithms with the SLS LV subsystem models. For this, the M&FM algorithms and the SLS LV subsystem models are modeled using constructs provided by Matlab which also enables modeling of the accompanying interfaces providing greater flexibility for integrated testing and analysis, which helps forecast expected behavior in forward VMET integrated testing activities. In VMET, the M&FM algorithms are prototyped and implemented using the same C++ programming language and similar state machine architectural concepts used by the FSW group. Due to the interactive complexity of the algorithms, VMET testing thus far has verified all the individual M&FM subsystem algorithms with select subsystem vendor models but is steadily progressing to assessing the interactive behavior of these algorithms with LV subsystems, as represented by subsystem models. The novel SFE applications has proven to be useful for quick look analysis into early integrated system behavior and assessment of the M&FM algorithms with the modeled LV subsystems. This early MBE analysis generates vital insight into the integrated system behaviors, algorithm sensitivities, design issues, and has aided in the debugging of the M&FM algorithms well before full testing can begin in more expensive, higher fidelity but more arduous environments such as VMET, FSW testing, and the Systems Integration Lab7 (SIL). SFE has exhibited both expected and unexpected behaviors in nominal and off nominal test cases prior to full VMET testing. In many findings, these behavioral characteristics were used to correct the M&FM algorithms, enable better test coverage, and develop more effective test cases for each of the LV subsystems. This has improved the fidelity of testing and planning for the next generation of M&FM algorithms as the SLS program evolves from non-crewed to crewed flight, impacting subsystem configurations and the M&FM algorithms that control them. SFE analysis has improved robustness and reliability of the M&FM algorithms by revealing implementation errors and documentation inconsistencies. It is also improving planning efficiency for future VMET testing of the M&FM algorithms hosted in the LV flight computers, further reducing risk for the SLS launch infrastructure, the SLS LV, and most importantly the crew.

Trevino, Luis

Adaptation of NASA technology for the optimization of orthopedic knee implants

The NASA technology originally developed for the optimization of composite structures (engine blades) is adapted and applied to the optimization of orthopedic knee implants. A method is developed enabling the tailoring of the implant for optimal interaction with the environment of the tibia. The shape of the implant components are optimized, such that the stresses in the bone are favorably controlled to minimize bone degradation and prevent failures. A pilot tailoring system is developed and the feasibility of the concept is elevated. The optimization system is expected to provide the means for improving knee prosthesis and individual implant tailoring for each patient.

Saravanos, D. A.

JPL/NASA/IEEE Test Effectiveness Workshop

(none given)From OBJECTIVES: Specific objectives of the working group are to support the innovation, development, evaluation and implementation of test methods, metrics and tools based on failure engineering/physics and/or root cause evaluations. Data sources systems and tools shall be developed and implemented that: 1) provide improved preventions, controls, analyses and tests (PACT) & field failure data collection, 2) facilities data analysis, archiving, retrieval, failure physics and/or root cause evaluations and 3) enable new and existing technology suitability evaluations to be performed.

effectiveness concurrent engineering metrics test

Reinforcing Additives for Ice Adhesion Reduction Coatings

Adhesion of contaminants has been identified as a ubiquitous issue for aeronautic exterior surfaces. In-flight icing is particularly hazardous for all aircraft and can be experienced throughout the year under the appropriate environmental conditions. On larger vehicles, the accretion of ice could result in loss of lift, engine failure, and potentially loss of vehicle and life were it not for active deicing or anti-icing equipment. Smaller vehicles though cannot support the mass and mechanical complexity of active ice mitigating systems and thus must rely upon passive approaches or avoid icing conditions altogether. One approach that may be applicable to all aircraft is the use of coatings. Durability remains an issue and has prevented realization of coatings for leading edge contamination mitigation. In this work, epoxy coatings were generated as a passive approach for ice adhesion mitigation and methods to improve durability were evaluated. Highly cross-linked epoxy systems can be extremely rigid, which could have deleterious consequences regarding application as a leading edge coating. Incorporation of flexible species, such as poly(ethylene glycol) may improve coating toughness.8 Additionally, core-shell rubber (CSR) particles have been utilized to improve fracture toughness of epoxies.9 Both of these more established additives are investigated in this work. An emerging additive that is also evaluated here is holey graphene. This nanomaterial possesses many of the advantageous properties of graphene (excellent mechanical properties, thermal and electrical conductivity, large surface area, etc.) while also exhibiting behaviors associated with flexible, porous materials (i.e., compressibility, increased permeation, etc.). Holey graphene, HG, was synthesized by the oxidation of defect-rich sites on graphene sheets through controlled thermal expo-sure.10 It is envisioned that the porous nature of HG would allow resin penetration through the graphitic plane, resulting in better interfacial interaction and therefore better translation of the nanomaterial’s properties to the surrounding matrix.

Wohl, Christopher J

Fallible humans and vulnerable systems - Lessons learned from aviation

It is suggested that the problems being experienced in complex automatic systems are essentially due to the failure of information management and communication. The failure covers the entire spectrum: display devices and techniques, coding information so as to reduce human error, and information economy, i.e., resisting the temptation to bombard the operator with unlimited information simply because the system possesses the capability to do so. Since there has been great progress in hardware engineering, it is suggested that further attention is needed in the 'soft' side of systems. The approach should focus on (1) preventing human cognitive slips and (2) making the systems less vulnerable to such slips when they do occur. Most of the examples are taken from studies of cockpit automation.

Wiener, Earl L.

Plume spectrometry for liquid rocket engine health monitoring

An investigation of Space Shuttle Main Engine (SSME) testing failures identified optical events which appeared to be precursors of those failures. A program was therefore undertaken to detect plume trace phenomena characteristic of the engine and to design a monitoring system, responsive to excessive activity in the plume, capable of delivering a warning of an anomalous condition. By sensing the amount of extraneous material entrained in the plume and considering engine history, it may be possible to identify wearing of failing components in time for a safe shutdown and thus prevent a catastrophic event. To investigate the possibilities of safe shutdown and thus prevent a monitor to initiate the shutdown procedure, a large amount of plume data were taken from SSME firings using laboratory instrumentation. Those data were used to design a more specialized instrument dedicated to rocket plume diagnostics. The spectral wavelength range of the baseline data was about 220 nanometers (nm) to 15 micrometer with special attention given to visible and near UV. The data indicates that a satisfactory design will include a polychromator covering the range of 250 nM to 1000 nM, along with a continuous coverage spectrometer, each having a resolution of at least 5A degrees. The concurrent requirements for high resolution and broad coverage are normally at odds with one another in commercial instruments, therefore necessitating the development of special instrumentation. The design of a polychromator is reviewed herein, with a detailed discussion of the continuous coverage spectrometer delayed to a later forum. The program also requires the development of applications software providing detection, variable background discrimination, noise reduction, filtering, and decision making based on varying historical data.

Powers, William T.

Goal-Function Tree Modeling for Systems Engineering and Fault Management

The draft NASA Fault Management (FM) Handbook (2012) states that Fault Management (FM) is a "part of systems engineering", and that it "demands a system-level perspective" (NASAHDBK- 1002, 7). What, exactly, is the relationship between systems engineering and FM? To NASA, systems engineering (SE) is "the art and science of developing an operable system capable of meeting requirements within often opposed constraints" (NASA/SP-2007-6105, 3). Systems engineering starts with the elucidation and development of requirements, which set the goals that the system is to achieve. To achieve these goals, the systems engineer typically defines functions, and the functions in turn are the basis for design trades to determine the best means to perform the functions. System Health Management (SHM), by contrast, defines "the capabilities of a system that preserve the system's ability to function as intended" (Johnson et al., 2011, 3). Fault Management, in turn, is the operational subset of SHM, which detects current or future failures, and takes operational measures to prevent or respond to these failures. Failure, in turn, is the "unacceptable performance of intended function." (Johnson 2011, 605) Thus the relationship of SE to FM is that SE defines the functions and the design to perform those functions to meet system goals and requirements, while FM detects the inability to perform those functions and takes action. SHM and FM are in essence "the dark side" of SE. For every function to be performed (SE), there is the possibility that it is not successfully performed (SHM); FM defines the means to operationally detect and respond to this lack of success. We can also describe this in terms of goals: for every goal to be achieved, there is the possibility that it is not achieved; FM defines the means to operationally detect and respond to this inability to achieve the goal. This brief description of relationships between SE, SHM, and FM provide hints to a modeling approach to provide formal connectivity between the nominal (SE), and off-nominal (SHM and FM) aspects of functions and designs. This paper describes a formal modeling approach to the initial phases of the development process that integrates the nominal and off-nominal perspectives in a model that unites SE goals and functions of with the failure to achieve goals and functions (SHM/FM).

Johnson, Stephen B.

Dynamic Open-Rotor Composite Shield Impact Test Report

The Federal Aviation Administration (FAA) is working with the European Aviation Safety Agency to determine the certification base for proposed new engines that would not have a containment structure on large commercial aircraft. Equivalent safety to the current fleet is desired by the regulators, which means that loss of a single fan blade will not cause hazard to the aircraft. NASA Glenn and Naval Air Warfare Center (NAWC) China Lake collaborated with the FAA Aircraft Catastrophic Failure Prevention Program to design and test a shield that would protect the aircraft passengers and critical systems from a released blade that could impact the fuselage. This report documents the live-fire test from a full-scale rig at NAWC China Lake. NASA provided manpower and photogrammetry expertise to document the impact and damage to the shields. The test was successful: the blade was stopped from penetrating the shield, which validates the design analysis method and the parameters used in the analysis. Additional work is required to implement the shielding into the aircraft.

Shielding

Shape optimization of tibial prosthesis components

NASA technology and optimal design methodologies originally developed for the optimization of composite structures (engine blades) are adapted and applied to the optimization of orthopaedic knee implants. A method is developed enabling the shape tailoring of the tibial components of a total knee replacement implant for optimal interaction within the environment of the tibia. The shape of the implant components are optimized such that the stresses in the bone are favorably controlled to minimize bone degradation, to improve the mechanical integrity of the implant/interface/bone system, and to prevent failures of the implant components. A pilot tailoring system is developed and the feasibility of the concept is demonstrated and evaluated. The methodology and evolution of the existing aerospace technology from which this pilot optimization code was developed is also presented and discussed. Both symmetric and unsymmetric in-plane loading conditions are investigated. The results of the optimization process indicate a trend toward wider and tapered posts as well as thicker backing trays. Unique component geometries were obtained for the different load cases.

Saravanos, D. A.

Simulated 'On-Line' Wear Metal Analysis of Lubricating Oils by X-Ray Fluorescence Spectroscopy

The objective of this project was to assess the sensitivity of X-ray Fluorescence Spectroscopy (XFS) for quantitative evaluation of metal particle content in engine oil suspensions and the feasibility of real-time, dynamic wear metal analysis. The study was focused on iron as the majority wear metal component. Variable parameters were: particle size, particle concentration and oil velocity. A commercial XFS spectrometer equipped with interchangeable static/dynamic (flow cell) sample chambers was used. XFS spectra were recorded for solutions of Fe-organometallic standard and for a series of DTE oil suspensions of high purity spherical iron particles of 2g, 4g, and 8g diameter, at concentrations from 5 ppm to 5,000 ppm. Real contaminated oil samples from Langley Air Force Base aircraft engines and NASA Langley Research Center wind tunnels were also analyzed. The experimental data conform the reliability of XFS as the analytical method of choice for this project. Intrinsic inadequacies of the instrument for precise analytic work at low metal concentrations were identified as being related to the particular x-ray beam definition, system geometry, and flow-cell materials selection. This work supports a proposal for the design, construction and testing of a conceptually new, miniature XFS spectrometer with superior performance, dedicated to on-line, real-time monitoring of lubricating oils in operating engines. Innovative design solutions include focalization of the incident x-ray beam, non-metal sample chamber, and miniaturization of the overall assembly. The instrument would contribute to prevention of catastrophic engine failures. A proposal for two-year funding has been presented to NASA Langley Research Center Internal Operation Group (IOG) Management, to continue the effort begun by this summer's project.

Kelliher, Warren C.

Electrical Pressurization Concept for the Orion MPCV European Service Module Propulsion System

The paper presents the design of the pressurization system of the European Service Module (ESM) of the Orion Multi-Purpose Crew Vehicle (MPCV). Being part of the propulsion subsystem, an electrical pressurization concept is implemented to condition propellants according to the engine needs via a bang-bang regulation system. Separate pressurization for the oxidizer and the fuel tank permits mixture ratio adjustments and prevents vapor mixing of the two hypergolic propellants during nominal operation. In case of loss of pressurization capability of a single side, the system can be converted into a common pressurization system. The regulation concept is based on evaluation of a set of tank pressure sensors and according activation of regulation valves, based on a single-failure tolerant weighting of three pressure signals. While regulation is performed on ESM level, commanding of regulation parameters as well as failure detection, isolation and recovery is performed from within the Crew Module, developed by Lockheed Martin Space System Company. The overall design and development maturity presented is post Preliminary Design Review (PDR) and reflects the current status of the MPCV ESM pressurization system.

Helium