Search NASASearch

SEARCH · Search NASA

Results for “SYSTEM FAILURE”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

System for Anomaly and Failure Detection (SAFD) system development

The System for Anomaly and Failure Detection (SAFD) algorithm was developed as an improvement over the current redline system used in the Space Shuttle Main Engine Controller (SSMEC). Simulation tests and execution against previous hot fire tests demonstrated that the SAFD algorithm can detect engine failures as much as tens of seconds before the redline system recognized the failure. Although the current algorithm only operates during steady state conditions (engine not throttling), work is underway to expand the algorithm to work during transient conditions. This task assignment originally specified developing a platform for executing the algorithm during hot fire tests at Technology Test Bed (TTB) and installing the SAFD algorithm on that platform. Two units were built and installed in the Hardware Simulation Lab and at the TTB in December 1991. Since that time, the task primarily entailed improvement and maintenance of the systems, additional testing to prove the feasibility of the algorithm, and support of hot fire testing. This document addresses the work done since the last report of June 1992. The work on the System for Anomaly and Failure Detection during this period included improving the platform and the algorithm, testing the algorithm against previous test data and in the Hardware Simulation Lab, installing other algorithms on the system, providing support for operations at the Technology Test Bed, and providing routine maintenance.

Oreilly, D.

An adaptive tracking observer for failure-detection systems

The design problem of adaptive observers applied to linear, constant and variable parameters, multi-input, multi-output systems, is considered. It is shown that, in order to keep the observer's (or Kalman filter) false-alarm rate (FAR) under a certain specified value, it is necessary to have an acceptable proper matching between the observer (or KF) model and the system parameters. An adaptive observer algorithm is introduced in order to maintain desired system-observer model matching, despite initial mismatching and/or system parameter variations. Only a properly designed adaptive observer is able to detect abrupt changes in the system (actuator, sensor failures, etc.) with adequate reliability and FAR. Conditions for convergence for the adaptive process were obtained, leading to a simple adaptive law (algorithm) with the possibility of an a priori choice of fixed adaptive gains. Simulation results show good tracking performance with small observer output errors and accurate and fast parameter identification, in both deterministic and stochastic cases.

Sidar, M.

Airworthiness Qualification Criteria for Rotorcraft with External Sling Loads

This report presents the results of a study to develop airworthiness requirements for rotorcraft with external sling loads. The report starts with a review of the various phenomena that limit external sling load operations. Specifically discussed are the rotorcraft-load aeroservoelastic stability, load-on handling qualities, effects of automatic flight control system failure, load suspension system failure, and load stability at speed. Based on past experience and treatment of these phenomena, criteria are proposed to form a package for airworthiness qualification. The desired end objective is a set of operational flight envelopes for the rotorcraft with intended loads that can be provided to the user to guide operations in the field. The specific criteria proposed are parts of ADS-33E-PRF; MIL-F-9490D, and MIL-STD-913A all applied in the context of external sling loads. The study was performed for the Directorate of Engineering, U.S. Army Aviation and Missile Command (AMCOM), as part of the contract monitored by the Aerothermodynamics Directorate, U.S. Army AMCOM.

Key, David L.

System for Anomaly and Failure Detection (SAFD) system development

This task specified developing the hardware and software necessary to implement the System for Anomaly and Failure Detection (SAFD) algorithm, developed under Technology Test Bed (TTB) Task 21, on the TTB engine stand. This effort involved building two units; one unit to be installed in the Block II Space Shuttle Main Engine (SSME) Hardware Simulation Lab (HSL) at Marshall Space Flight Center (MSFC), and one unit to be installed at the TTB engine stand. Rocketdyne personnel from the HSL performed the task. The SAFD algorithm was developed as an improvement over the current redline system used in the Space Shuttle Main Engine Controller (SSMEC). Simulation tests and execution against previous hot fire tests demonstrated that the SAFD algorithm can detect engine failure as much as tens of seconds before the redline system recognized the failure. Although the current algorithm only operates during steady state conditions (engine not throttling), work is underway to expand the algorithm to work during transient condition.

Oreilly, D.

A Comprehensive Reliability Methodology for Assessing Risk of Reusing Failed Hardware Without Corrective Actions with and Without Redundancy

This paper deals with the development of a reliability methodology to assess the consequences of using hardware, without failure analysis or corrective action, that has previously demonstrated that it did not perform per specification. The subject of this paper arose from the need to provide a detailed probabilistic analysis to calculate the change in probability of failures with respect to the base or non-failed hardware. The methodology used for the analysis is primarily based on principles of Monte Carlo simulation. The random variables in the analysis are: Maximum Time of Operation (MTO) and operation Time of each Unit (OTU) The failure of a unit is considered to happen if (OTU) is less than MTO for the Normal Operational Period (NOP) in which this unit is used. NOP as a whole uses a total of 4 units. Two cases are considered. in the first specialized scenario, the failure of any operation or system failure is considered to happen if any of the units used during the NOP fail. in the second specialized scenario, the failure of any operation or system failure is considered to happen only if any two of the units used during the MOP fail together. The probability of failure of the units and the system as a whole is determined for 3 kinds of systems - Perfect System, Imperfect System 1 and Imperfect System 2. in a Perfect System, the operation time of the failed unit is the same as that of the MTO. In an Imperfect System 1, the operation time of the failed unit is assumed as 1 percent of the MTO. In an Imperfect System 2, the operation time of the failed unit is assumed as zero. in addition, simulated operation time of failed units is assumed as 10 percent of the corresponding units before zero value. Monte Carlo simulation analysis is used for this study. Necessary software has been developed as part of this study to perform the reliability calculations. The results of the analysis showed that the predicted change in failure probability (P(sub F)) for the previously failed units is as high as 49 percent above the baseline (perfect system) for the worst case. The predicted change in system P(sub F) for the previously failed units is as high as 36% for single unit failure without any redundancy. For redundant systems, with dual unit failure, the predicted change in P(sub F) for the previously failed units is as high as 16%. These results will help management to make decisions regarding the consequences of using previously failed units without adequate failure analysis or corrective action.

Putcha, Chandra S.

An intelligent control system for failure detection and controller reconfiguration

We present an architecture of an intelligent restructurable control system to automatically detect failure of system components, assess its impact on system performance and safety, and reconfigure the controller for performance recovery. Fault detection is based on neural network associative memories and pattern classifiers, and is implemented using a multilayer feedforward network. Details of the fault detection network along with simulation results on health monitoring of a dc motor have been presented. Conceptual developments for fault assessment using an expert system and controller reconfiguration using a neural network are outlined.

Biswas, Saroj K.

Electrified Aircraft Propulsion Systems: Potential Failure Modes and Failure Mitigation Strategies

Electrified aircraft propulsion (EAP) systems hold great potential for the reduction of aircraft fuel burn, emissions, and noise. Currently, NASA and other organizations are actively working to identify and mature technologies necessary to bring EAP designs to reality. A requirement for the development of any civil aircraft and its systems is to ensure that potential hazards in the design are identified and appropriately mitigated to ensure that the system is safe. During aircraft development, a system safety assessment that consists of a functional hazard assessment is conducted to identify all potential failure conditions of each function, and classify those failures according to the severity of their effects on the aircraft or its occupants. The more severe a function's failure condition classification, the greater the development assurance level required for the function to ensure that the probability of the hazard is acceptably low. Today, aircraft engines and their control systems receive type certificate approval as a stand-alone system to signify their airworthiness. However, the complex coupling and distributed nature of EAP designs are expected to place added challenges on the certification of these systems. This presentation will provide an initial high-level review of the potential failure modes and hazards posed by a generic EAP system along with potential mitigation strategies for those failures. The EAP system is assumed to be a hybrid design consisting of gas turbine engines, mechanical drives, electric machines, power electronics and distribution systems, energy storage devices, and motor driven propulsors. The functionality provided by each of these EAP subsystems will be discussed along with the potential failure modes they may encounter. This will include a discussion of coupled failure effects, where a fault in one EAP subsystem effects the operation of other subsystems in the architecture. Next, potential failure mitigation strategies are discussed including both software-based and hardware-based mitigation strategies. The presentation will conclude with an example evaluation of the potential failure modes and mitigation strategies for a concept EAP system proposed by NASA.

Simon, Donald L.

Lunar Base Life Support Failures

Dynamic simulation of the lunar outpost habitat life support was undertaken to investigate the impact of life support failures and to investigate responses. Some preparatory static analysis for the Lunar Outpost life support model, an earlier version of the model, and an investigation into the impact of Extravehicular Activity (EVA) were reported previously. (Jones, 2008-01-2184, 2008-01-2017) The earlier model was modified to include possible resupply delays, power failures, recycling system failures, and atmosphere and other material storage failures. Most failures impact the lunar outpost water balance and can be mitigated by reducing water usage. Food solids, nitrogen can be obtained only by resupply from Earth. The most time urgent failure is a lass of carbon dioxide removal capability. Life support failures might be survivable if effective operational solutions are provided in the system design.

Jones, Harry W.

High Reliability at Minimum Cost

This paper investigates the minimum cost of improving the reliability of complex technical systems. The two major methods to improve reliability are redesigning the system for higher reliability or providing redundant components to replace failed elements. The costs of redesign for reliability or adding redundancy are estimated. The most cost-effective combination for high reliability can be identified. The cost of increasing the intrinsic reliability of a system can be modeled as cost proportional to 1/(system failure rate) a , where the exponent “a” measures the difficulty of increasing reliability. The “a” exponent can vary from 0.25 to about 2.5. Operational reliability can also be increased by using redundant systems. The failure rate for N parallel redundant units is (system failure rate) N . The cost of redundancy is N times the system cost. The total redundant system cost is proportional to N/(system failure rate) a . The cost of redundancy increases as N gets larger, but larger N allows a higher system failure rate, which reduces the system design cost. There is a certain N, a certain level of redundancy, that has the minimum cost to achieve the required overall redundant system failure rate. The minimum cost for the redundant system is achieved at the optimum level of redundancy. The N for minimum cost is equal to -a ln (redundant system failure rate). The minimum cost of the N redundant systems is proportional to N * (original system failure rate) a . The optimum redesigned individual system failure rate is proportional to exp (-1/a), so the greater the difficulty, the higher the optimum individual system failure rate. Increasing the intrinsic reliability of a system encounters diminishing returns and at some point it becomes more cost-effective to add redundancy. The difficulty of increasing intrinsic system reliability determines the optimum design for high reliability at minimum cost.

reliability

High Reliability at Minimum Cost

This paper investigates the minimum cost of improving the reliability of complex technical systems. The two major methods to improve reliability are redesigning the system for higher reliability or providing redundant components to replace failed elements. The costs of redesign for reliability or adding redundancy are estimated. The most cost-effective combination for high reliability can be identified. The cost of increasing the intrinsic reliability of a system can be modeled as cost proportional to 1/(system failure rate) a , where the exponent “a” measures the difficulty of increasing reliability. The “a” exponent can vary from 0.25 to about 2.5. Operational reliability can also be increased by using redundant systems. The failure rate for N parallel redundant units is (system failure rate) N . The cost of redundancy is N times the system cost. The total redundant system cost is proportional to N/(system failure rate) a . The cost of redundancy increases as N gets larger, but larger N allows a higher system failure rate, which reduces the system design cost. There is a certain N, a certain level of redundancy, that has the minimum cost to achieve the required overall redundant system failure rate. The minimum cost for the redundant system is achieved at the optimum level of redundancy. The N for minimum cost is equal to -a ln (redundant system failure rate). The minimum cost of the N redundant systems is proportional to N * (original system failure rate) a . The optimum redesigned individual system failure rate is proportional to exp (-1/a), so the greater the difficulty, the higher the optimum individual system failure rate. Increasing the intrinsic reliability of a system encounters diminishing returns and at some point it becomes more cost-effective to add redundancy. The difficulty of increasing intrinsic system reliability determines the optimum design for high reliability at minimum cost.

reliability

Failure detection system design methodology

The design of a failure detection and identification system consists of designing a robust residual generation process and a high performance decision making process. The design of these two processes are examined separately. Residual generation is based on analytical redundancy. Redundancy relations that are insensitive to modelling errors and noise effects are important for designing robust residual generation processes. The characterization of the concept of analytical redundancy in terms of a generalized parity space provides a framework in which a systematic approach to the determination of robust redundancy relations are developed. The Bayesian approach is adopted for the design of high performance decision processes. The FDI decision problem is formulated as a Bayes sequential decision problem. Since the optimal decision rule is incomputable, a methodology for designing suboptimal rules is proposed. A numerical algorithm is developed to facilitate the design and performance evaluation of suboptimal rules.

Chow, E. Y.

Environmental Control System Development

Since before the first men landed on the moon, human beings have aspired to reach farther into space, to discover and answer the great mysteries that exist beyond imagination. To reach where no one has gone before. To able to see all the wonderful things that can be found in space and that only satellites have revealed to us during all this time. Considering the last trip to the moon, mankind has been evolving and improving their technology to reach destinations whose distances had been impossible to transit. To reach that goal, the National Aeronautics and Space Administration (NASA) has designed and developed the largest and most powerful rocket ever created by the human race, the Space Launch System - better known as the SLS. To be able to send this large rocket to space, Kennedy Space Center (KSC) is doing upgrades to their existing facilities and equipment. At Launch Pad 39B, they are setting up a new Environmental Control System (ECS) developed to supply the rocket with the correct gases and mixtures that will be needed for the rocket to launch. The ECS is similar to an air conditioning unit. The main functionality of it is to supply the SLS with the correct gas mixture for it to launch. Also the ECS has been required to reduce or eliminate the possibility of a complete system failure. The system is part of the Ground Support Equipment (GSE) for the SLS that will be going to the Moon and Mars.

Flores Arroyo, Elvin A.

A review of wiring system safety in space power systems

Wiring system failures have resulted from arc propagation in the wiring harnesses of current aerospace vehicles. These failures occur when the insulation becomes conductive upon the initiation of an arc. In some cases, the conductive path of the carbon arc track displays a high enough resistance such that the current is limited, and therefore may be difficult to detect using conventional circuit protection. Often, such wiring failures are not simply the result of insulation failure, but are due to a combination of wiring system factors. Inadequate circuit protection, unforgiving system designs, and careless maintenance procedures can contribute to a wiring system failure. This paper approaches the problem with respect to the overall wiring system, in order to determine what steps can be taken to improve the reliability, maintainability, and safety of space power systems. Power system technologies, system designs, and maintenance procedures which have led to past wiring system failures will be discussed. New technologies, design processes, and management techniques which may lead to improved wiring system safety will be introduced.

Stavnes, Mark W.

Failure detection system risk reduction assessment

A process includes determining a probability of a failure mode of a system being analyzed reaching a failure limit as a function of time to failure limit, determining a probability of a mitigation of the failure mode as a function of a time to failure limit, and quantifying a risk reduction based on the probability of the failure mode reaching the failure limit and the probability of the mitigation.

Aguilar, Robert B.

Test Results for the Automated Rendezvous and Capture System

The Automated Rendezvous and Capture (AR&C) system was designed and tested at NASA's Marshall Space Flight Center (MSFC) to demonstrate technologies and mission strategies for automated rendezvous and docking of spacecraft in Earth orbit, The system incorporates some of the latest innovations in Global Positioning, System space navigation, laser sensor technologies and automated mission sequencing algorithms. The system's initial design and integration was completed in 1998 and has undergone testing at MSFC. This paper describes the major components of the AR&C system and presents results from the official system tests performed in MSFC's Flight Robotics Laboratory with digital simulations and hardware in the loop tests. The results show that the AR&C system can safely and reliably perform automated rendezvous and docking missions in the absence of system failures with 100 percent success. When system failures are included, the system uses its automated collision avoidance maneuver logic to recover in a safe manner. The primary objective of the AR&C project is to prove that by designing a safe and robust automated system, mission operations cost can be reduced by decreasing the personnel required for mission design, preflight planning and training required for crewed rendezvous and docking missions.

Cruzen, Craig