Search NASA⌕ Search

SEARCH · Search NASA

Results for “reliability requirements”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Redundancy: How Many Unreliable Spares are Needed for High Reliability and Confidence?

This paper investigates the number of redundant units needed to achieve high reliability with high confidence. The approach is developed for the case when the system failure rate is too high for a single unit to provide the required reliability over the mission duration. To achieve high reliability, N redundant units can be used, one operating unit and N – 1 spares. If the unit failure rate is f, the mission length is L, and f * L is small (not the case assumed here), the unit failure probability over the mission duration is F1 = f * L << 1. In this case, the probability that all N units will fail is Ffail = F1 N , and the needed redundancy N = LN(F)/LN(F1). For the case of large f * L assumed here, F1 = f * L > 1, and F1 is the expected number of failures during the mission. (When F1 = f * L << 1, F1 is the probability that a unit will fail during the mission. When F1 = f * L > 1, F1 is the expected number of failures during the mission.) The needed redundancy, N, to achieve the required N redundant unit reliability, FN, can be computed using the cumulative Poisson distribution with mean equal to F1. The number of spares, N - 1, is increased until the probability - that the total number of failures will be less than N -1 - is equal to the required reliability. The confidence that this reliability can be achieved can be computed using the cumulative Poisson distribution or the chi-square distribution. Since the measured unit failure rate, f, has some probabilistic uncertainty, the actual failure rate will be randomly higher or lower. This means that the reliability of the N redundant systems will be overestimated about half the time. Adding more redundant units increases the confidence that the required reliability will be achieved. For a fixed number of redundant units, the expected reliability and confidence can be traded off, since lower reliability goals will be achieved with higher confidence. Both the desired reliability and confidence can be specified as initial requirements and the needed number of redundant units estimated using the measured failure rate.

Redundancy↗

Design verification of SIFT

A SIFT reliable aircraft control computer system, designed to meet the ultrahigh reliability required for safety critical flight control applications by use of processor replications and voting, was constructed for SRI, and delivered to NASA Langley for evaluation in the AIRLAB. To increase confidence in the reliability projections for SIFT, produced by a Markov reliability model, SRI constructed a formal specification, defining the meaning of reliability in the context of flight control. A further series of specifications defined, in increasing detail, the design of SIFT down to pre- and post-conditions on Pascal code procedures. Mechanically checked mathematical proofs were constructed to demonstrate that the more detailed design specifications for SIFT do indeed imply the formal reliability requirement. An additional specification defined some of the assumptions made about SIFT by the Markov model, and further proofs were constructed to show that these assumptions, as expressed by that specification, did indeed follow from the more detailed design specifications for SIFT. This report provides an outline of the methodology used for this hierarchical specification and proof, and describes the various specifications and proofs performed.

Moser, Louise↗

A study of low cost approaches to scientific experiment implementation for shuttle launched and serviced automated spacecraft

Cost reductions that can be obtained in experiment instrumentation by the use of standardized electronics and by the relaxation of instrument reliability requirements are studied. The feasibility of using standardized equipment for experiment instrumentation is assessed and a system design approach that most effectively incorporates standardized equipment is developed. The level and form of modularization that is appropriate for the standardized equipment is determined. Mission assurance aspects of instrument development are examined to determine the cost reductions that might be derived from the relaxation of reliability requirements and to formulate a systematic approach to the optimization of mission assurance cost reductions. The results of the analyses are applied to a representative model HEAO payload in order to provide a concrete example of the cost reductions that can be achieved by a standardized approach to the instrument electronics.

Source record↗

SEASAT economic assessment. Volume 10: The SATIL 2 program (a program for the evaluation of the costs of an operational SEASAT system as a function of operational requirements and reliability

The SATIL 2 computer program was developed to assist with the programmatic evaluation of alternative approaches to establishing and maintaining a specified mix of operational sensors on spacecraft in an operational SEASAT system. The program computes the probability distributions of events (i.e., number of launch attempts, number of spacecraft purchased, etc.), annual recurring cost, and present value of recurring cost. This is accomplished for the specific task of placing a desired mix of sensors in orbit in an optimal fashion in order to satisfy a specified sensor demand function. Flow charts are shown, and printouts of the programs are given.

Source record↗

A distributed microprocessor system for spacecraft control and data handling

The specific requirements for spacecraft computing systems are considered. These requirements are partly related to the constraints of limited resources of power, weight, and volume. Another important factor is the requirement of extremely high reliability. These reliability requirements have led to introduction of automated redundancy techniques on board the spacecraft. The various redundant computers check each other and provide recovery procedures when a computer is found to have failed. Past and future capabilities are considered along with distributed processing requirements. System considerations are discussed, taking into account suboptimum computer throughput, sensitivity to software modifications, hierarchic timing, I/O granularity, restricted communications, synchronous functions, hierarchic control, and concurrent error detection. A description is presented of the Unified Data System (UDS), which consists of a set of standard microcomputers connected by several buses. Attention is also given to synchronization and timing, the executive control structure, the programming language, and the executive program.

Rennels, D. A.↗

Learning reliable manipulation strategies without initial physical models

A description is given of a robot, possessing limited sensory and effectory capabilities but no initial model of the effects of its actions on the world, that acquires such a model through exploration, practice, and observation. By acquiring an increasingly correct model of its actions, it generates increasingly successful plans to achieve its goals. In an apparently nondeterministic world, achieving reliability requires the identification of reliable actions and a preference for using such actions. Furthermore, by selecting its training actions carefully, the robot can significantly improve its learning rate.

Christiansen, Alan D.↗

Roller Locking Brake

Roller locking brake is normally braking rotary mechanism allowing free rotation when electromagnet in mechanism energized. Well suited to robots and other machinery which automatic braking upon removal of electrical power required. More compact and reliable. Requires little electrical power to maintain free rotation and exhibits minimal buildup of heat.

Vranish, John M.↗

Implementing Software Safety in the NASA Environment

Until recently, NASA did not consider allowing computers total control of flight systems. Human operators, via hardware, have constituted the ultimate safety control. In an attempt to reduce costs, NASA has come to rely more and more heavily on computers and software to control space missions. (For example. software is now planned to control most of the operational functions of the International Space Station.) Thus the need for systematic software safety programs has become crucial for mission success. Concurrent engineering principles dictate that safety should be designed into software up front, not tested into the software after the fact. 'Cost of Quality' studies have statistics and metrics to prove the value of building quality and safety into the development cycle. Unfortunately, most software engineers are not familiar with designing for safety, and most safety engineers are not software experts. Software written to specifications which have not been safety analyzed is a major source of computer related accidents. Safer software is achieved step by step throughout the system and software life cycle. It is a process that includes requirements definition, hazard analyses, formal software inspections, safety analyses, testing, and maintenance. The greatest emphasis is placed on clearly and completely defining system and software requirements, including safety and reliability requirements. Unfortunately, development and review of requirements are the weakest link in the process. While some of the more academic methods, e.g. mathematical models, may help bring about safer software, this paper proposes the use of currently approved software methodologies, and sound software and assurance practices to show how, to a large degree, safety can be designed into software from the start. NASA's approach today is to first conduct a preliminary system hazard analysis (PHA) during the concept and planning phase of a project. This determines the overall hazard potential of the system to be built. Shortly thereafter, as the system requirements are being defined, the second iteration of hazard analyses takes place, the systems hazard analysis (SHA). During the systems requirements phase, decisions are made as to what functions of the system will be the responsibility of software. This is the most critical time to affect the safety of the software. From this point, software safety analyses as well as software engineering practices are the main focus for assuring safe software. While many of the steps proposed in this paper seem like just sound engineering practices, they are the best technical and most cost effective means to assure safe software within a safe system.

Wetherholt, Martha S.↗

Reliability Impacts in Life Support Architecture and Technology Selection

Equivalent System Mass (ESM) and reliability estimates were performed for different life support architectures based primarily on International Space Station (ISS) technologies. The analysis was applied to a hypothetical 1-year deep-space mission. High-level fault trees were initially developed relating loss of life support functionality to the Loss of Crew (LOC) top event. System reliability was then expressed as the complement (nonoccurrence) this event and was increased through the addition of redundancy and spares, which added to the ESM. The reliability analysis assumed constant failure rates and used current projected values of the Mean Time Between Failures (MTBF) from an ISS database where available. Results were obtained showing the dependence of ESM on system reliability for each architecture. Although the analysis employed numerous simplifications and many of the input parameters are considered to have high uncertainty, the results strongly suggest that achieving necessary reliabilities for deep-space missions will add substantially to the life support system mass. As a point of reference, the reliability for a single-string architecture using the most regenerative combination of ISS technologies without unscheduled replacement spares was estimated to be less than 1%. The results also demonstrate how adding technologies in a serial manner to increase system closure forces the reliability of other life support technologies to increase in order to meet the system reliability requirement. This increase in reliability results in increased mass for multiple technologies through the need for additional spares. Alternative parallel architecture approaches and approaches with the potential to do more with less are discussed. The tall poles in life support ESM are also reexamined in light of estimated reliability impacts.

Lange, Kevin E.↗

Formal methods for achieving reliable software

Requirements for reliable avionic systems are discussed in terms of the effectiveness of programming methodology. The need for methods to cope with the complexity of critical real-time systems is emphasized. Some general concepts about formal methods are presented and an example is given of the SRI hierarchical development methodology taken from the executive system of the SIFT fault tolerant computer. Formal methods with alternatives are compared and the prospects for introducing formal methods into practice are considered.

Goldberg, J.↗

NASA Reference Motor Designs for Electric Vertical Takeoff and Landing Vehicles

Electric and hybrid electric vertical takeoff and landing vehicles require high performance and high reliability electric motor drivetrains. Failure analysis of NASA’s Revolutionary Vertical Lift Technologies’ reference vehicles pointed to current electric motor drivetrain reliability being below what is needed to meet the expected stringent reliability requirements for Urban Air Mobility vehicles. In this paper, design studies are carried out for UAM vehicle electric motors to produce reference designs. The primary intent of these reference motor designs is to provide guidance for UAM motor reliability model development and technology advancement. They additionally provide high fidelity motor sizing information for vehicle designers and references for different technologies or motor topologies to be traded against.

Electric Motor Urban Air Mobility↗

NASA Reference Motor Designs for Electric Vertical Takeoff and Landing Vehicles

Electric and hybrid electric vertical takeoff and landing vehicles require high performance and high reliability electric motor drivetrains. Failure analysis of NASA’s Revolutionary Vertical Lift Technologies’ reference vehicles pointed to current electric motor drivetrain reliability being below what is needed to meet the expected stringent reliability requirements for Urban Air Mobility vehicles [1]. In this paper, design studies are carried out for UAM vehicle electric motors to produce reference designs. The primary intent of these reference motor designs is to provide guidance for UAM motor reliability model development and technology advancement. They additionally provide high fidelity motor sizing information for vehicle designers and references for different technologies or motor topologies to be traded against.

Thomas Tallerico↗

Future challenges in V/STOL flight propulsion control integration

A survey of propulsion control requirements forming part of an advanced V/STOL control requirements study has to date determined, among other findings: (1) that the dependence of V/STOL flying qualities on propulsive lift makes it necessary to identify propulsion control requirements early in a development program; (2) that V/STOL controls of the future should relieve the pilot of control functions and elevate him to the position of a flight operations manager, with substantial gains in capability and/or safety; and (3) that research is required to define the V/STOL control system reliability requirements and specific component reliability allocations. An interactive, integrated design process for the realization of these objectives is also described.

Roth, S. P.↗

Modular Stirling Radioisotope Generator

High efficiency radioisotope power generators will play an important role in future NASA space exploration missions. Stirling Radioisotope Generators (SRG) have been identified as a candidate generator technology capable of providing mission designers with an efficient, high specific power electrical generator. SRGs high conversion efficiency has the potential to extend the limited Pu-238 supply when compared with current Radioisotope Thermoelectric Generators (RTG). Due to budgetary constraints, the Advanced Stirling Radioisotope Generator (ASRG) was canceled in the fall of 2013. Over the past year a joint study by NASA and DOE called the Nuclear Power Assessment Study (NPAS) recommended that Stirling technologies continue to be explored. During the mission studies of the NPAS, spare SRGs were sometimes required to meet mission power system reliability requirements. This led to an additional mass penalty and increased isotope consumption levied on certain SRG-based missions. In an attempt to remove the spare power system, a new generator architecture is considered which could increase the reliability of a Stirling generator and provide a more fault-tolerant power system. This new generator called the Modular Stirling Radioisotope Generator (MSRG) employs multiple parallel Stirling convertor/controller strings, all of which share the heat from the General Purpose Heat Source (GPHS) modules. For this design, generators utilizing one to eight GPHS modules were analyzed, which provide about 50 to 450 watts DC to the spacecraft, respectively. Four Stirling convertors are arranged around each GPHS module resulting in from 4 to 32 Stirling/controller strings. The convertors are balanced either individually or in pairs, and are radiatively coupled to the GPHS modules. Heat is rejected through the housing/radiator which is similar in construction to the ASRG. Mass and power analysis for these systems indicate that specific power may be slightly lower than the ASRG and similar to the MMRTG. However, the reliability should be significantly increased compared to ASRG.

Stirling Cycle↗

Modular Stirling Radioisotope Generator

High-efficiency radioisotope power generators will play an important role in future NASA space exploration missions. Stirling Radioisotope Generators (SRGs) have been identified as a candidate generator technology capable of providing mission designers with an efficient, high-specific-power electrical generator. SRGs high conversion efficiency has the potential to extend the limited Pu-238 supply when compared with current Radioisotope Thermoelectric Generators (RTGs). Due to budgetary constraints, the Advanced Stirling Radioisotope Generator (ASRG) was canceled in the fall of 2013. Over the past year a joint study by NASA and the Department of Energy (DOE) called the Nuclear Power Assessment Study (NPAS) recommended that Stirling technologies continue to be explored. During the mission studies of the NPAS, spare SRGs were sometimes required to meet mission power system reliability requirements. This led to an additional mass penalty and increased isotope consumption levied on certain SRG-based missions. In an attempt to remove the spare power system, a new generator architecture is considered, which could increase the reliability of a Stirling generator and provide a more fault-tolerant power system. This new generator called the Modular Stirling Radioisotope Generator (MSRG) employs multiple parallel Stirling convertor/controller strings, all of which share the heat from the General Purpose Heat Source (GPHS) modules. For this design, generators utilizing one to eight GPHS modules were analyzed, which provided about 50 to 450 W of direct current (DC) to the spacecraft, respectively. Four Stirling convertors are arranged around each GPHS module resulting in from 4 to 32 Stirling/controller strings. The convertors are balanced either individually or in pairs, and are radiatively coupled to the GPHS modules. Heat is rejected through the housing/radiator, which is similar in construction to the ASRG. Mass and power analysis for these systems indicate that specific power may be slightly lower than the ASRG and similar to the Multi-Mission Radioisotope Thermoelectric Generator (MMRTG). However, the reliability should be significantly increased compared to ASRG.

Modules↗

Narrowband Propagation Statistics of Aeronautical Mobile-Ground Links in the L- and C-Bands

To provide for the safe integration of unmanned aircraft systems (UAS) into the National Airspace System (NAS), command and control (C2) links must be highly reliable. Hence, protected aviation spectrum is required to support such links for UAS that are integrated into controlled non-segregated airspace. For air-ground (i.e., non-satellite) links, protected aviation spectrum to support C2 links is available in the 960-1164 MHz (L) and 5030-5091 MHz (C) bands. The performance of any C2 system is critically dependent upon the characteristics of the air-ground (AG) channel. Therefore, as part of its UAS Integration in the NAS (UAS in the NAS) project, the U.S. National Aeronautics and Space Administration (NASA) performed a series of air-ground propagation flight tests to collect AG channel data for model development and analysis of potential C2 communications links capable of providing the required reliability. NASA's Glenn Research Center (GRC) conducted an extensive air-ground channel propagation measurement campaign (at altitude) for frequencies in the 960-977 MHz and 5030-5091 MHz ranges, for seven different terrain environments. The measurements were conducted in 2013, and produced the largest set of AG channel data ever gathered to date. This data was subsequently processed to develop models for the AG channel. The statistics collected enabled the derivation of channel model parameters for both narrowband and wideband channels. In order to make the propagation data widely available, the resulting narrowband statistics were processed and submitted to the International Telecommunications Union - Radiocommunication Sector (ITU-R) Study Group 3 Data Banks. Formats for data tables were developed, and tables of the aggregate narrowband propagation statistics for the seven ground site terrain environments were prepared, submitted to, and approved by, the ITU-R Study Group 3. This paper provides brief background on the measurement campaign, collection and processing of data, and development of the narrowband data tables. It further provides examples of the data and its use.

radiofrequency spectrum↗

Narrowband Propagation Statistics of Aeronautical Mobile-Ground Links in the L- and C-Bands

To provide for the safe integration of unmanned aircraft systems (UAS) into the National Airspace System (NAS), command and control (C2) links must be highly reliable. Hence, protected aviation spectrum is required to support such links for UAS that are integrated into controlled non-segregated airspace. For air-ground (i.e., non-satellite) links, protected aviation spectrum to support C2 links is available in the 960-1164 MHz (L) and 5030-5091 MHz (C) bands. The performance of any C2 system is critically dependent upon the characteristics of the air-ground (AG) channel. Therefore, as part of its UAS Integration in the NAS (UAS in the NAS) project, the U.S. National Aeronautics and Space Administration (NASA) performed a series of air-ground propagation flight tests to collect AG channel data for model development and analysis of potential C2 communications links capable of providing the required reliability. NASA's Glenn Research Center (GRC) conducted an extensive air-ground channel propagation measurement campaign (at altitude) for frequencies in the 960-977 MHz and 5030-5091 MHz ranges, for seven different terrain environments. The measurements were conducted in 2013, and produced the largest set of AG channel data ever gathered to date. This data was subsequently processed to develop models for the AG channel. The statistics collected enabled the derivation of channel model parameters for both narrowband and wideband channels. In order to make the propagation data widely available, the resulting narrowband statistics were processed and submitted to the International Telecommunications Union Radiocommunication Sector (ITU-R) Study Group 3 Data Banks. Formats for data tables were developed, and tables of the aggregate narrowband propagation statistics for the seven ground site terrain environments were prepared, submitted to, and approved by, the ITU-R Study Group 3. This paper provides brief background on the measurement campaign, collection and processing of data, and development of the narrowband data tables. It further provides examples of the data and its use.

aircraft communications↗

Voyager design study. volume vi- program plans

Voyager spacecraft design - landing module sterilization effects and requirements, long term space soak effects, high reliability requirements, and entry and operation on Mars

STERILIZATION↗