Search NASA⌕ Search

SEARCH · Search NASA

Results for “Systems Engineering, Failure Prevention”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Failures and anomalies attributed to spacecraft charging

The effects of spacecraft charging can be very detrimental to electronic systems utilized in space missions. Assuring that subsystems and systems are protected against charging is an important engineering function necessary to assure mission success. Spacecraft charging is expected to have a significant role in future space activities and programs. Objectives of this reference publication are to present a brief overview of spacecraft charging, to acquaint the reader with charging history, including illustrative cases of charging anomalies, and to introduce current spacecraft charging prevention activities of the Electromagnetics and Environments Branch, Marshall Space Flight Center (MSFC), National Aeronautics and Space Administration (NASA).

Leach, R. D.↗

Fire safety practices in the Shuttle and the Space Station Freedom

The Shuttle reinforces its policy of fire-preventive measures with onboard smoke detectors and Halon 1301 fire extinguishers. The forthcoming Space Station Freedom will have expanded fire protection with photoelectric smoke detectors, radiation flame detectors, and both fixed and portable carbon dioxide fire extinguishers. Many design and operational issues remain to be resolved for Freedom. In particular, the fire-suppression designs must consider the problems of gas leakage in toxic concentrations, alternative systems for single-failure redundancy, and commonality with the corresponding systems of the Freedom international partners. While physical and engineering requirements remain the primary driving forces for spacecraft fire-safety technology, there are, nevertheless, needs and opportunities for the application of microgravity combustion knowledge to improve and optimize the fire-protective systems.

Friedman, Robert↗

PROBABALISTIC RISK ANALYSIS AND THERMAL MARGIN PROCESS FOR AN INFLATABLE AEROSHELL

Atmospheric entry vehicle thermal protection systems (TPS) are margined due to the uncertainties that exist in entry aeroheating environments and the thermal response of the materials and structures. Traditional approaches typically over-margin TPS and offer very little insight into the risk of over-temperature during flight. A probabilistic margin process can be used to apply thermal margin to an aeroshell based on a rigorously calculated risk of failure. This probabilistic margin process allows engineers to make informed aeroshell design, entry-trajectory modifications, and risk trades while preventing excessive margin from being applied. This methodology can also be applied to other TPS applications, hot structures, and other engineering disciplines.

Steven A Tobin↗

Physics-Guided Deep Learning for Complex System Health Management and Decision Making

The landscape of complex engineered systems is rapidly evolving, from smart manufacturing facilities to next-generation transportation vehicles. As these systems become increasingly sophisticated and interconnected, the need for advanced health management systems grows ever more critical. These systems must go beyond simple monitoring, actively predicting potential failures before they occur. This paradigm shift from fixed maintenance schedules to condition-based predictions is key to optimizing system performance, enhancing safety, and paving the way for autonomous decision-making across various industries. Whether in industrial processes, energy systems, or advanced transportation, the ability to anticipate and prevent failures is becoming a cornerstone of operational excellence. To accurately predict the future health of any complex system, knowledge of its current health state and future operational conditions is essential. Recent advancements in data-driven algorithms have generated growing interest in artificial intelligence for industrial applications. However, the limitations of pure data-driven methods, particularly in industries where data acquisition is costly and limited, have become apparent. This has led to a focus on blending physics with data-driven algorithms, mitigating the drawbacks of both approaches while emphasizing their respective advantages. This research proposes a novel framework for integrating physics-based performance models with deep learning algorithms for the prognostics of complex safety-critical systems. In this approach, physics-based models serve as a blueprint, capturing fundamental system behaviors, while deep learning algorithms, leveraging real-world sensor data, fill in gaps and identify subtle patterns indicative of potential problems. This hybrid methodology, utilizing techniques such as Physics-Informed Neural Networks (PINNs), offers a powerful solution for predicting system health. By fusing domain knowledge with data-driven insights, this approach promises more accurate, adaptable, and reliable models for health prediction. The resulting framework is versatile, applicable across various sectors including aerospace, manufacturing, and energy systems, ultimately contributing to safer, more efficient operations in our increasingly complex technological landscape.

Diagnostics↗

Dual output variable pitch turbofan actuation system

An improved actuating mechanism was provided for a gas turbine engine incorporating fan blades of the variable pitch variety, the actuator adapted to rotate the individual fan blades within apertures in an associated fan disc. The actuator included means such as a pair of synchronizing ring gears, one on each side of the blade shanks, and adapted to engage pinions disposed thereon. Means were provided to impart rotation to the ring gears in opposite directions to effect rotation of the blade shanks in response to a predetermined input signal. In the event of system failure, a run-away actuator was prevented by an improved braking device which arrests the mechanism.

Griswold, R. H., Jr.↗

Software analysis handbook: Software complexity analysis and software reliability estimation and prediction

This handbook documents the three software analysis processes the Space Station Software Analysis team uses to assess space station software, including their backgrounds, theories, tools, and analysis procedures. Potential applications of these analysis results are also presented. The first section describes how software complexity analysis provides quantitative information on code, such as code structure and risk areas, throughout the software life cycle. Software complexity analysis allows an analyst to understand the software structure, identify critical software components, assess risk areas within a software system, identify testing deficiencies, and recommend program improvements. Performing this type of analysis during the early design phases of software development can positively affect the process, and may prevent later, much larger, difficulties. The second section describes how software reliability estimation and prediction analysis, or software reliability, provides a quantitative means to measure the probability of failure-free operation of a computer program, and describes the two tools used by JSC to determine failure rates and design tradeoffs between reliability, costs, performance, and schedule.

Computer systems design↗

Pattern Recognition for a Flight Dynamics Monte Carlo Simulation

The design, analysis, and verification and validation of a spacecraft relies heavily on Monte Carlo simulations. Modern computational techniques are able to generate large amounts of Monte Carlo data but flight dynamics engineers lack the time and resources to analyze it all. The growing amounts of data combined with the diminished available time of engineers motivates the need to automate the analysis process. Pattern recognition algorithms are an innovative way of analyzing flight dynamics data efficiently. They can search large data sets for specific patterns and highlight critical variables so analysts can focus their analysis efforts. This work combines a few tractable pattern recognition algorithms with basic flight dynamics concepts to build a practical analysis tool for Monte Carlo simulations. Current results show that this tool can quickly and automatically identify individual design parameters, and most importantly, specific combinations of parameters that should be avoided in order to prevent specific system failures. The current version uses a kernel density estimation algorithm and a sequential feature selection algorithm combined with a k-nearest neighbor classifier to find and rank important design parameters. This provides an increased level of confidence in the analysis and saves a significant amount of time.

Restrepo, Carolina↗

Integration issues of a plasma contactor Power Electronics Unit

A hollow cathode-based plasma contactor is baselined on International Space Station Alpha (ISSA) for spacecraft charge control. The plasma contactor system consists of a hollow cathode assembly (HCA), a power electronics unit (PEU), and an expellant management unit (EMU). The plasma contactor has recently been required to operate in a cyclic mode to conserve xenon expellant and extend system life. Originally, a DC cathode heater converter was baselined for a continuous operation mode because only a few ignitions of the hollow cathode were expected. However, for cyclic operation, a DC heater supply can potentially result in hollow cathode heater component failure due to the DC electrostatic field. This can prevent the heater from attaining the proper cathode tip temperature for reliable ignition of the hollow cathode. To mitigate this problem, an AC cathode heater supply was therefore designed, fabricated, and installed into a modified PEU. The PEU was tested using resistive loads and then integrated with an engineering model hollow cathode to demonstrate stable steady-state operation. Integration issues such as the effect of line and load impedance on the output of the AC cathode heater supply and the characterization of the temperature profile of the heater under AC excitation were investigated.

Pinero, Luis R.↗

A Multilayered Thin Film Insulator for Harsh Environments

The status of work to develop a reliable high temperature dielectric thin film for use with thin film sensors is presented. The use of thin films to electrically insulate thin film sensors on engine components minimizes the intrusiveness of the sensor and allows a more accurate measurement of the environment. A variety of insulating films were investigated for preventing electrical shorting caused by insulator failure between the sensor and the component. By alternating layers of sputtered high temperature ceramics, a sequence of insulating layers was devised that prevents pinholes from forming completely through the insulator and maintains high electrical resistivity at high temperatures. The major technical challenge remaining is to optimize the fabrication of the insulator with respect to composition to achieve a reliable high temperature insulating film. Data from the testing of various potentially insulating thin film systems is presented and their application to thin film sensors is also discussed.

Wrbanek, John D.↗

Improved Joining of Metal Components to Composite Structures

Systems requirements for complex spacecraft drive design requirements that lead to structures, components, and/or enclosures of a multi-material and multifunctional design. The varying physical properties of aluminum, tungsten, Invar, or other high-grade aerospace metals when utilized in conjunction with lightweight composites multiply system level solutions. These multi-material designs are largely dependent upon effective joining techAn improved method of joining metal components to matrix/fiber composite material structures has been invented. The method is particularly applicable to equipping such thin-wall polymer-matrix composite (PMC) structures as tanks with flanges, ceramic matrix composite (CMC) liners for high heat engine nozzles, and other metallic-to-composite attachments. The method is oriented toward new architectures and distributing mechanical loads as widely as possible in the vicinities of attachment locations to prevent excessive concentrations of stresses that could give rise to delaminations, debonds, leaks, and other failures. The method in its most basic form can be summarized as follows: A metal component is to be joined to a designated attachment area on a composite-material structure. In preparation for joining, the metal component is fabricated to include multiple studs projecting from the aforementioned face. Also in preparation for joining, holes just wide enough to accept the studs are molded into, drilled, or otherwise formed in the corresponding locations in the designated attachment area of the uncured ("wet') composite structure. The metal component is brought together with the uncured composite structure so that the studs become firmly seated in the holes, thereby causing the composite material to become intertwined with the metal component in the joining area. Alternately, it is proposed to utilize other mechanical attachment schemes whereby the uncured composite and metallic parts are joined with "z-direction" fasteners. The resulting "wet" assembly is then subjected to the composite-curing heat treatment, becoming a unitary structure. It should be noted that this new art will require different techniques for CMC s versus PMC's, but the final architecture and companion curing philosophy is the same. For instance, a chemical vapor infiltration (CVI) fabrication technique may require special integration of the pre-form and

Semmes, Edmund↗

The International Space Station (ISS) Solar Alpha Rotary Joint (SARJ): Materials & Processes (M&P) Lessons Learned for a Large, Rotating Spacecraft Mechanism

The International Space Station (ISS) utilizes two large rotating mechanisms, the solar alpha rotary joints (SARJs), as part of the solar arrays' alignment system for more efficient power generation. Each SARJ is a 10.3m circumference, nitrided 15-5PH steel race ring of triangular cross-section, with 12 sets of trundle bearing assemblies transferring load across the rolling joint. The SARJ mechanism rotates continuously and slowly - once every orbit, or every 90 minutes. In 2007, the starboard SARJ suffered a lubrication failure, resulting in severe damage (spalling) to one of the race ring surfaces. Extensive effort was conducted to prevent the port SARJ from suffering the same failure, and fortunately that effort was ultimately successful in also recovering the functionality of the starboard SARJ. The M&P engineering function was key in determining the cause of failure and the means for mechanism recovery. From a M&P lessons-learned perspective, observations are made concerning the original SARJ design parameters (boundary conditions), the perceived need for nitriding the race ring, the test conditions employed during qualification, the environmental controls used for the hardware preflight, and the lubrication robustness necessary for complex kinematic mechanisms expecting high-reliability and long-life.

Golden, Johnny L.↗

Postflight Evaluation of Atlas-Centaur AC-5 (Launched 2 March 1965)

The Atlas-Centaur AC-5 vehicle was launched from ETR Complex 36A on March 2., 1965 at 8:25.04 a.m. EST. Within about 1 second after launch the thrust of the Atlas booster engine decayed rapidly; the vehicle settled back on the launch pad and was quickly destroyed by fire and explosion. Considerable damage was sustained by the launch complex and its associated equipment. Loss of booster engine thrust was due to fuel depletion at the turbopump inlets, which is attributed to closure of the fuel prevalve or the staging valve. To preclude the recurrence of either of these fuel valving malfunctions, the following corrective action has been taken: The remote control actuator has been replaced by manual operation of the Atlas fuel prevalve; the internal passage dimensions in the staging valve have been increased to lessen the hydraulic load on the valve poppet. In addition to the Atlas fuel system malfunction, a failure in the power control circuitry of the Centaur guidance computer resulted in partial removal of power at umbilical ejection. To prevent such a guidance system failure on future flights some redundant circuitry has been eliminated and more rigorous checkout procedures have been adopted. No further anomalies were discovered in the telemetered data prior to the Atlas booster thrust decay. A prime objective of the AC-5 flight was to place a dynamic model of the Surveyor spacecraft in a simulated lunar transfer trajectory. An important facet of this problem is the demonstration of a launch-on-time capability in accordance with the proper Earth-moon relation. The window opening time was established at 8:25 a.m. EST; thus the actual launch occurred within 4 seconds of the planned time.

Source record↗

Space Shuttle Main Engine Liquid Air Insulation Redesign Lessons Learned

The Space Shuttle Main Engine Liquid Air Insulation redesign was required to prevent the reoccurance of the STS-111 High Pressure Speed Sensor In-Flight Anomaly. The STS-111 In-Flight Anomaly Failure Investigation Team's initial redesign of the High Pressure Fuel Turbopump Pump End Ball Bearing Liquid Air Insulation failed the certification test by producing Liquid Air. The certification test failure indicated not only the High Pressure Fuel Turbopump Liquid Air Insulation, but all other Space Shuttle Main Engine Liquid Air Insulation. This paper will document the original Space Shuttle Main Engine Liquid Air STS-111 In-Flight Anomaly investigation, the heritage Space Shuttle Main Engine Insulation certification testing faults, the techniques and instrumentation used to accurately test the Liquid Air Insulation systems on the Stennis Space Center SSME test stand, the analysis techniques used to identify the Liquid Air Insulation problem areas and the analytical verification of the redesign before entering certification testing, Trade study down selected to three potential design solutions, the results of the development testing which down selected the final Liquid Air Redesign are also documented within this paper.

Darrell Gaddy↗

Collaboration of the NASA Glenn Research Center and Rolls-Royce Developed Thin Film Multilayered Dielectrics for Harsh Environments

The use of thin films to electrically insulate thin film sensors on engine components minimizes the intrusiveness of the sensors and allows a more accurate measurement of the environment. A variety of insulating films were investigated for preventing electrical shorting caused by insulator failure between the sensor and the component. By alternating layers of sputtered high-temperature ceramics, a sequence of insulating layers was devised that (1) prevents pinholes from forming completely through the insulator and (2) maintains high electrical resistivity at high temperatures. The total thickness is only a fraction of that needed for conventional insulating techniques. The Sensors and Electronics Technology Branch of the NASA Glenn Research Center has an in-house effort to develop thin film sensors for surface measurement in propulsion system research. Thin film sensors do not require special machining of the components on which they are mounted, and they are considerably thinner (less than 10 mm thick) than wire or foil sensors. The thin film sensors are thus much less disturbing to the operating environment and have a minimal impact on the physical characteristics of the supporting component. To further this research, NASA Glenn and Rolls-Royce (Derby, UK), with assistance from the Ohio Aerospace Institute (OAI) and the Akima Corporation, pursued a joint investigation using multilayered thin film dielectrics as a reliable insulator in harsh environments. The use of a multilayered scheme is thought to be promising for the fabrication of electrically insulating thin films. A major cause of conduction in thin film dielectrics is the presence of defects, such as pinholes, that propagate through the film to the underlying substrate surface. By alternating the insulating material, each new growth pattern would deviate from the previous one, eliminating direct pathways for conduction to the substrate. The film depositions and testing were conducted in the Instrument Research Laboratory at Glenn. The multilayered insulator test samples were made from alumina and stainless steel shims that were first covered with a sputtered underlayer of either yttria-stabilized zirconia or chromium carbide, and then overcoated with a sputtered top layer of alumina. An example of a test sample is shown in the following photograph. Each multilayered insulator sample was 5 mm thick, at least an order of magnitude thinner than conventional insulators. The insulating properties of the samples were tested in a high-temperature air oven to determine their suitability. The multilayer insulators tested showed a stabilized film at temperatures in excess of 800 C (1472 F). The underlying materials in these multilayers allow thermal expansion stresses produced during the heating to be graded. The chromium carbide-alumina multilayer had the best adhesion at high temperatures, presumably from the induced chemical bonding between the substrate and the chromium carbide underlayer. However, the zirconia-alumina multilayer proved to have slightly better insulating properties when adhering. The application of the zirconia-alumina insulator has been demonstrated on a nickel-alloy fan blade, as shown. The insulators using thin film sensors still need to be tested in a relevant high-temperature combustion environment.

Wrbanek, John D.↗

Human Performance Contributions to Safety in Commercial Aviation

Every day in aviation, pilots, air traffic controllers, and other front-line personnel perform countless correct judgments and actions in a variety of operational environments. These judgments and actions are often the difference between an accident and a non-event. Ironically, data on these behaviors are rarely collected or analyzed. Data-driven decisions about safety management and design of safety-critical systems are limited by the available data, which influence how decision makers characterize problems and identify solutions. Large volumes of data are collected on the failures and errors that result in infrequent incidents and accidents, but in the absence of data on behaviors that result in routine successful outcomes, safety management and system design decisions are based on a small sample of nonrepresentative safety data. This assessment aimed to find and document “safety successes” made possible by human operators. With many Aeronautics Research Mission Directorate (ARMD) Programs and Projects focusing on increased automation and autonomy and decreased human involvement, failure to fully consider the human contributions to successful system performance in civil aviation represents a significant risk — a risk that has not been recognized to date. Without understanding how humans contribute to safety, any estimate of predicted safety of autonomous capabilities is incomplete and inherently suspect. Furthermore, understanding the ways in which humans contribute to safety can promote strategic interactions among safety technologies, functions, procedures and the people using them. Without this understanding, the full benefits of an integrated, optimized human/technology or autonomous system will not be realized. Historically, safety has been consistently defined in terms of the occurrence of accidents or recognized risks (i.e., in terms of things that go wrong). These adverse outcomes are explained by identifying their causes, and safety is restored by eliminating or mitigating these causes. An alternative to this approach is to focus on what goes right and identify how to replicate that process. Focusing on the rare cases of failures attributed to “human error” provides little information about why human performance routinely prevents adverse events. Hollnagel has proposed that things go right because people continuously adjust their work to match their operating conditions. These adjustments become increasingly important as systems continue to grow in complexity. Thus, the definition of safety should reflect not only “avoiding things that go wrong” but “ensuring that things go right.” The basis for safety management requires developing an understanding of everyday activities. However, few mechanisms to monitor everyday work exist in the aviation domain, which limits opportunities to learn how designs function in reality. This concept of safety thinking and safety management is reflected in the emerging field of resilience engineering. According to Hollnagel, a system is resilient if it can sustain required operations under expected and unexpected conditions by adjusting its functioning prior to, during, or following changes, disturbances, and opportunities. To explore “positive” behaviors that contribute to resilient performance in commercial aviation, the assessment team examined a range of existing sources of data about pilot and air traffic control (ATC) tower controller performance, including subjective interviews with domain experts and objective aircraft flight data records. These data were used to identify strategies that support resilient performance, methods for exploring and refining those strategies in existing data, and proposed methods for capturing and analyzing new data.

Null, Cynthia H.↗

Solar thermal energy receiver

A plurality of heat pipes in a shell receive concentrated solar energy and transfer the energy to a heat activated system. To provide for even distribution of the energy despite uneven impingement of solar energy on the heat pipes, absence of solar energy at times, or failure of one or more of the heat pipes, energy storage means are disposed on the heat pipes which extend through a heat pipe thermal coupling means into the heat activated device. To enhance energy transfer to the heat activated device, the heat pipe coupling cavity means may be provided with extensions into the device. For use with a Stirling engine having passages for working gas, heat transfer members may be positioned to contact the gas and the heat pipes. The shell may be divided into sections by transverse walls. To prevent cavity working fluid from collecting in the extensions, a porous body is positioned in the cavity.

Baker, Karl W.↗

High-speed civil transport flight- and propulsion-control technological issues

Technology advances required in the flight and propulsion control system disciplines to develop a high speed civil transport (HSCT) are identified. The mission and requirements of the transport and major flight and propulsion control technology issues are discussed. Each issue is ranked and, for each issue, a plan for technology readiness is given. Certain features are unique and dominate control system design. These features include the high temperature environment, large flexible aircraft, control-configured empennage, minimizing control margins, and high availability and excellent maintainability. The failure to resolve most high-priority issues can prevent the transport from achieving its goals. The flow-time for hardware may require stimulus, since market forces may be insufficient to ensure timely production. Flight and propulsion control technology will contribute to takeoff gross weight reduction. Similar technology advances are necessary also to ensure flight safety for the transport. The certification basis of the HSCT must be negotiated between airplane manufacturers and government regulators. Efficient, quality design of the transport will require an integrated set of design tools that support the entire engineering design team.

Ray, J. K.↗

Emerging technologies for V&V of ISHM software for space exploration

Systems1,2 required to exhibit high operational reliability often rely on some form of fault protection to recognize and respond to faults, preventing faults' escalation to catastrophic failures. Integrated System Health Management (ISHM) extends the functionality of fault protection to both scale to more complex systems (and systems of systems), and to maintain capability rather than just avert catastrophe. Forms of ISHM have been utilized to good effect in the maintenance phase of systems' total lifecycles (often referred to as 'condition-based mainte-nance'), but less so in a 'fault protection' role during actual operations. One of the impediments to such use lies in the challenges of verification, validation and certification of ISHM systems themselves. This paper makes the case that state-of-the-practice V&V and certification techniques will not suffice for emerging forms of ISHM systems; however, a number of maturing software engineering assurance technologies show particular promise for addressing these ISHM V&V challenges.

fault detection, isolation, and recovery↗