Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Protection Design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Aerospace technology development of three types of solid state remote power controllers for 120VDC with current ratings of five, and thirty amperes, one type having current limiting

The first generation of remote power controllers (RPC) developed included: a 5-ampere design (Type 1), capable of limiting maximum overload current to 15 amperes for .1 sec; and 5-ampere noncurrent (Type 2) and 30-ampere noncurrent (Type 3) limiting designs, both with selectable instant trip levels for high-current overload. Each design provides overcurrent protection through an inverse I squared T trip-out function with an automatic reset option and demonstrates step-applied fault capability with a 4000-ampere surge, fast-risetime (low-inductance) power source. They also meet MIL - STD - 461A specification for electromagnetic interference. The second generation RPCs traded off specification compliance for reduction in cost and complexity for the Type 1 and 2 designs and give comparable or improved performance in most areas. The noncurrent limiting RPC proved to be a more economical and feasible method of overload protection for certain load types.

Baker, D. E.↗

High-power converters for space applications

Phase 1 was a concept definition effort to extend space-type dc/dc converter technology to the megawatt level with a weight of less than 0.1 kg/kW (220 lb./MW). Two system designs were evaluated in Phase 1. Each design operates from a 5 kV stacked fuel cell source and provides a voltage step-up to 100 kV at 10 A for charging capacitors (100 pps at a duty cycle of 17 min on, 17 min off). Both designs use an MCT-based, full-bridge inverter, gaseous hydrogen cooling, and crowbar fault protection. The GE-CRD system uses an advanced high-voltage transformer/rectifier filter is series with a resonant tank circuit, driven by an inverter operating at 20 to 50 kHz. Output voltage is controlled through frequency and phase shift control. Fast transient response and stability is ensured via optimal control. Super-resonant operation employing MCTs provides the advantages of lossless snubbing, no turn-on switching loss, use of medium-speed diodes, and intrinsic current limiting under load-fault conditions. Estimated weight of the GE-CRD system is 88 kg (1.5 cu ft.). Efficiency of 94.4 percent and total system loss is 55.711 kW operating at 1 MW load power. The Maxwell system is based on a resonance transformer approach using a cascade of five LC resonant sections at 100 kHz. The 5 kV bus is converted to a square wave, stepped-up to a 100 kV sine wave by the LC sections, rectified, and filtered. Output voltage is controlled with a special series regulator circuit. Estimated weight of the Maxwell system is 83.8 kg (4.0 cu ft.). Efficiency is 87.2 percent and total system loss is 146.411 kW operating at 1 MW load power.

Park, J. N.↗

Description of the SSF PMAD DC testbed control system data acquisition function

The NASA LeRC in Cleveland, Ohio has completed the development and integration of a Power Management and Distribution (PMAD) DC Testbed. This testbed is a reduced scale representation of the end to end, sources to loads, Space Station Freedom Electrical Power System (SSF EPS). This unique facility is being used to demonstrate DC power generation and distribution, power management and control, and system operation techniques considered to be prime candidates for the Space Station Freedom. A key capability of the testbed is its ability to be configured to address system level issues in support of critical SSF program design milestones. Electrical power system control and operation issues like source control, source regulation, system fault protection, end-to-end system stability, health monitoring, resource allocation, and resource management are being evaluated in the testbed. The SSF EPS control functional allocation between on-board computers and ground based systems is evolving. Initially, ground based systems will perform the bulk of power system control and operation. The EPS control system is required to continuously monitor and determine the current state of the power system. The DC Testbed Control System consists of standard controllers arranged in a hierarchical and distributed architecture. These controllers provide all the monitoring and control functions for the DC Testbed Electrical Power System. Higher level controllers include the Power Management Controller, Load Management Controller, Operator Interface System, and a network of computer systems that perform some of the SSF Ground based Control Center Operation. The lower level controllers include Main Bus Switch Controllers and Photovoltaic Controllers. Power system status information is periodically provided to the higher level controllers to perform system control and operation. The data acquisition function of the control system is distributed among the various levels of the hierarchy. Data requirements are dictated by the control system algorithms being implemented at each level. A functional description of the various levels of the testbed control system architecture, the data acquisition function, and the status of its implementationis presented.

Baez, Anastacio N.↗

Searching for Grid-Forming Technologies That Do Not Impact Protection Systems: A promising technology

The design of legacy-line protection elements has been guided by the behavior of synchronous machines during faults. Because of the significant field-winding inductance and rotating mass, the magnitude, angular frequency, and phase angle of the back-electromotive force (EMF) voltage waveforms of synchronous machines remain practically constant for several hundreds of milliseconds after a fault occurs. Furthermore this has facilitated the engineering of the memory-polarization technique in mho distance elements, which has been effective for machine-dominant power grids. However, this assumption is no longer held for inverter-based resources (IBRs) because of the lack of field winding and moment of inertia in power electronics devices. Notably, the negative-sequence directional overcurrent protection and the quadrilateral distance elements have been impacted by early IBRs with grid-following (GFL) controls because they did not inject negative-sequence currents during asymmetrical faults.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Single-chip microcontrollers for switchgear control

A switchgear controller utilizing a microcontroller is described. The primary goal was to mimic the functions and performance of the generic controller board with a microcontroller board which will cause the power automation system to consume less power. The code for the microcontroller implementation on a development board has been developed, and the signal conditioning for the signals to the microcontroller has been designed and tested. The implementation of this decision system for data gathering, command control, fault detection, and circuit protection, when compared to other implementations, provides more functions and better response while reducing weight, volume, and power consumption.

Watson, Karan↗

Modifying real convolutional codes for protecting digital filtering systems

A novel method is proposed for protecting digital filters from temporary and permanent failures that are not easily detected by conventional fault-tolerant computer design principles, on the basis of the error-detecting properties of real convolutional codes. Erroneous behavior is detected by externally comparing the calculated and regenerated parity samples. Great simplifications are obtainable by modifying the code structure to yield simplified parity channels with finite impulse response structures. A matrix equation involving the original parity values of the code and the polynomial of the digital filter's transfer function is formed, and row manipulations separate this equation into a set of homogeneous equations constraining the modifying scaling coefficients and another set which defines the code parity values' implementation.

Redinbo, G. R.↗

Autonomous failure detection and correction on Landsat-4

An integrated hardware/software fault tolerant system for an earth oriented, computer controlled spacecraft is described. The design philosophy as well as the rationale behind the chosen fault tolerant system is outlined. In-flight performance of the system is included for several different instances where the Failure Detection and Correction system acted autonomously to protect the spacecraft. This system exceeded the expectations of the designers by demonstrating the capability to provide a measure of safety to the spacecraft for inadvertent and undesirable ground commands as well as satisfying its primary function of monitoring the flight hardware and software for failures.

Welch, R. V.↗

Hybrid routing technique for a fault-tolerant, integrated information network

The evolutionary growth of the space station and the diverse activities onboard are expected to require a hierarchy of integrated, local area networks capable of supporting data, voice, and video communications. In addition, fault-tolerant network operation is necessary to protect communications between critical systems attached to the net and to relieve the valuable human resources onboard the space station of time-critical data system repair tasks. A key issue for the design of the fault-tolerant, integrated network is the development of a robust routing algorithm which dynamically selects the optimum communication paths through the net. A routing technique is described that adapts to topological changes in the network to support fault-tolerant operation and system evolvability.

Meredith, B. D.↗

Hard Fault Protection for a Silicon Carbide-Based Aerospace Motor Drive

Due to increasingly high DC link voltages and further advancements in the current density of silicon carbide (SiC) MOSFETs, it has become evident that conventional IGBT protection methods are not sufficient to protect these devices from overcurrent during low-inductance fault events. The use of an air core Rogowski coil topology was explored to see if it could mitigate these hard fault events. The design of this circuit resulted in safe shutdown of a low impedance phase-tophase fault, tested up to DC link voltages of 1 kV.

High Voltage↗

Impact of Inverter-Based Resources on Grid Protection: A Review of Negative-Sequence Current Generation

The increasing integration of inverter-based resources (IBRs) in power grids poses challenges to traditional protection systems, primarily due to their different fault current signatures compared to conventional synchronous generators. Unlike synchronous generators whose fault response is dictated by their physical design, IBRs exhibit a wide range of fault characteristics due to manufacturer-specific control algorithms and settings. This dependence on proprietary control schemes makes modeling IBR behavior during faults significantly more complex, especially considering the rapid evolution of inverter technology and the diverse control strategies employed. While much research has focused on the positive-sequence current injections of IBRs during symmetrical faults, the understanding of negative-sequence current generation during non-symmetrical faults remains limited. This report provides an overview of current research on IBRs' negative-sequence current generation during unbalanced faults and its impact on protection schemes based on negative-sequence components. It covers both type III wind turbines and full-size converter-based IBRs. Additionally, this report reviews strategies for grid-forming controlled inverters to generate negative-sequence current during unbalanced faults, in addition to grid-following controlled ones.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Design of a power management and distribution system for a thermionic-diode powered spacecraft

The Electrical Systems Development Branch of the Power Technology Division at the NASA Lewis Research Center in Cleveland, Ohio is designing a Power Management and Distribution (PMAD) System for the Air Force's Integrated Solar Upper Stage (ISUS) Engine Ground Test Demonstration (EGD). The ISUS program uses solar-thermal propulsion to perform orbit transfers from Low Earth Orbit (LEO) to Geosynchronous Orbit (GEO) and from LEO to Molnya. The ISUS uses the same energy conversion receiver to perform the LEO to High Earth Orbit (HEO) transfer and to generate on-orbit electric power for the payloads. On-orbit power generation is accomplished via two solar concentrators heating a dual-cavity graphite-core which has Thermionic Diodes (TMD's) encircling each cavity. The graphite core and concentrators together are called the Receiver and Concentrator (RAC). The TDM-emitters reach peak temperatures of approximately 2200K, and the TID-collectors are run at approximately 1000K. Because of the high Specific Impulse (I(sup sp)) of solar thermal propulsion relative to chemical propulsion, and because a common bus is used for communications, GN&C, power, etc., a substantial increase in payload weight is possible. This potentially allows for a stepdown in the required launch vehicle size or class for similar payload weight using conventional chemical propulsion and a separate spacecraft bus. The ISUS power system is to provide 1000W(sub e) at 28+/-6V(sub dc) to the payload/spacecraft from a maximum TID generation capability of 1070W(sub e) at 2200K. Producing power with this quality, protecting the spacecraft from electrical faults and accommodating operational constraints of the TID's are the responsibilities of the PMAD system. The design strategy and system options examined along with the proposed designs for the Flight and EGD configurations are discussed herein.

Kimnach, Greg L.↗

GN and C Fault Protection Fundamentals

This is a companion presentation for a paper by the same name for the same conference. The objective of this paper is to shed some light on the fundamentals of fault tolerant design for GN&C. The common heritage of ideas behind both faulted and normal operation is explored, as is the increasingly indistinct line between these realms in complex missions. Techniques in common practice are then evaluated in this light to suggest a better direction for future efforts.

fault protection↗

Technical Reference Suite Addressing Challenges of Providing Assurance for Fault Management Architectural Design

Research into complexities of software systems Fault Management (FM) and how architectural design decisions affect safety, preservation of assets, and maintenance of desired system functionality has coalesced into a technical reference (TR) suite that advances the provision of safety and mission assurance. The NASA Independent Verification and Validation (IV&V) Program, with Software Assurance Research Program support, extracted FM architectures across the IV&V portfolio to evaluate robustness, assess visibility for validation and test, and define software assurance methods applied to the architectures and designs. This investigation spanned IV&V projects with seven different primary developers, a wide range of sizes and complexities, and encompassed Deep Space Robotic, Human Spaceflight, and Earth Orbiter mission FM architectures. The initiative continues with an expansion of the TR suite to include Launch Vehicles, adding the benefit of investigating differences intrinsic to model-based FM architectures and insight into complexities of FM within an Agile software development environment, in order to improve awareness of how nontraditional processes affect FM architectural design and system health management. The identification of particular FM architectures, visibility, and associated IV&V techniques provides a TR suite that enables greater assurance that critical software systems will adequately protect against faults and respond to adverse conditions. Additionally, the role FM has with regard to strengthened security requirements, with potential to advance overall asset protection of flight software systems, is being addressed with the development of an adverse conditions database encompassing flight software vulnerabilities. Capitalizing on the established framework, this TR suite provides assurance capability for a variety of FM architectures and varied development approaches. Research results are being disseminated across NASA, other agencies, and the software community. This paper discusses the findings and TR suite informing the FM domain in best practices for FM architectural design, visibility observations, and methods employed for IV&V and mission assurance.

Fitz, Rhonda↗

Enhancing operational safety: The NSTX-U Shorted Turn Protection (STP) system

The NSTX-U Shorted Turn Protection (STP) system is a vital safety feature designed to protect the tokamak’s coils during operations. It employs a Kalman filter-based algorithm to monitor coil currents and detect faults in real-time. If an anomaly is detected, the system swiftly terminates the tokamak pulse to prevent damage. Developed with Matlab and Simulink, the STP system has been validated through real-time simulations, ensuring its effectiveness for the upcoming upgrades of the NSTX-U facility. In conclusion, this article presents the theory for implementation of the STP algorithm and the results from simulation and real-time implementation.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Power electronic applications for Space Station Freedom

NASA plans to orbit a permanently manned space station in the late 1990s, which requires development and assembly of a photovoltaic (PV) power source system to supply up to 75 kW of electrical power average during the orbital period. The electrical power requirements are to be met by a combination of PV source, storage, and control elements for the sun and eclipse periods. The authors discuss the application of power electronics and controls to manage the generation, storage, and distribution of power to meet the station loads, as well as the computer models used for analysis and simulation of the PV power system. The requirements for power source integrated controls to adjust storage charge power during the insolation period current limiting, breaker interrupt current values, and the electrical fault protection approach are defined. Based on these requirements, operating concepts have been defined which then become drivers for specific system and element design.

Pickrell, Roy L.↗

ATTNChecker: Highly-Optimized Fault Tolerant Attention for Large Language Model Training

Large Language Models (LLMs) have demonstrated remarkable performance in various natural language processing tasks. However, the training of these models is computationally intensive and susceptible to faults, particularly in the attention mechanism, which is a critical component of transformer-based LLMs. In this paper, we investigate the impact of faults on LLM training, focusing on INF, NaN, and near-INF values in the computation results with systematic fault injection experiments. We observe the propagation patterns of these errors, which can trigger non-trainable states in the model and disrupt training, forcing the procedure to load from checkpoints. To mitigate the impact of these faults, we propose ATTNChecker, the first Algorithm-Based Fault Tolerance (ABFT) technique tailored for the attention mechanism in LLMs. ATTNChecker is designed based on fault propagation patterns of LLM and incorporates performance optimization to adapt to both system reliability and model vulnerability while providing lightweight protection for fast LLM training. Evaluations on four LLMs show that ATTNChecker on average incurs on average 7% overhead on training while detecting and correcting all extreme errors. Compared with the state-of-the-art checkpoint/restore approach, ATTNChecker reduces recovery overhead by up to 49×.

Liang, Yuhang [University of Alabama - Birmingham]↗

Autonomous power subsystem design for an Outer Planet Spacecraft.

This paper describes the overall design of the Thermoelectric Outer Planet Spacecraft (TOPS) power subsystem. It discusses the implementation of spacecraft requirements into a fault-tolerant design in which an on-board self-test and repair computer is utilized to provide autonomous operation. Development of a protected bus concept is discussed whereby electrical power supplied to essential spacecraft loads is maintained in the event of major on-board power blackouts. Particular attention is given to describing the interfaces and operation of the power subsystem with the spacecraft control computer subsystem. Autonomous power management operations are discussed where the on-board computer adjusts the spacecraft load demand to provide maximum utilization of source power for a given mission mode.

Andrews, R. E.↗

The 30-cm ion thruster power processor

A power processor unit for powering and controlling the 30 cm Mercury Electron-Bombardment Ion Thruster was designed, fabricated, and tested. The unit uses a unique and highly efficient transistor bridge inverter power stage in its implementation. The system operated from a 200 to 400 V dc input power bus, provides 12 independently controllable and closely regulated dc power outputs, and has an overall power conditioning capacity of 3.5 kW. Protective circuitry was incorporated as an integral part of the design to assure failure-free operation during transient and steady-state load faults. The implemented unit demonstrated an electrical efficiency between 91.5 and 91.9 at its nominal rated load over the 200 to 400 V dc input bus range.

Herron, B. G.↗