Search NASASearch

SEARCH · Search NASA

Results for “Redundant Designs”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Architecture of a faul-tolerant and verifiable outer planet flyby

Flyby missions to outer solar system objects require a very high confidence of since there are no second chances. The quantity, quality, and diversity of science measurements to be made in a matter of hours or days must justify the mission cost. Accordingly, the mission architecture must include a high degree of redundancy, large design margins, and an ability to correct or operate through anomalies while at the same time being deterministic enough for confidence in system verification and validation. In this paper we present a system architecture as part of a proposed mission to Triton, called “Trident”.

Mitchell, Karl L.

Preliminary study of a serial-parallel redundant manipulator

The manipulator design discussed here results from the examination of some of the reasons why redundancy is necessary in general purpose manipulation systems. A spherical joint design actuated in-parallel, having the many advantages of parallel actuation, is described. In addition, the benefits of using redundant actuators are discussed and illustrated in the design by the elimination of loci of singularities from the usable workspace with the addition of only one actuator. Finally, what is known by the authors about space robotics requirements is summarized and the relevance of the proposed design matched against these requirements. The design problems outlined here are viewed as much from the mechanical engineering aspect as from concerns arising from the control and the programming of manipulators.

Hayward, Vincent

Markov Chains For Testing Redundant Software

Preliminary design developed for validation experiment that addresses problems unique to assuring extremely high quality of multiple-version programs in process-control software. Approach takes into account inertia of controlled system in sense it takes more than one failure of control program to cause controlled system to fail. Verification procedure consists of two steps: experimentation (numerical simulation) and computation, with Markov model for each step.

White, Allan L.

VIPER project

The VIPER project has so far produced a formal specification of a 32 bit RISC microprocessor, an implementation of that chip in radiation-hard SOS technology, a partial proof of correctness of the implementation which is still being extended, and a large body of supporting software. The time has now come to consider what has been achieved and what directions should be pursued in the future. The most obvious lesson from the VIPER project was the time and effort needed to use formal methods properly. Most of the problems arose in the interfaces between different formalisms, e.g., between the (informal) English description and the HOL spec, between the block-level spec in HOL and the equivalent in ELLA needed by the low-level CAD tools. These interfaces need to be made rigorous or (better) eliminated. VIPER 1A (the latest chip) is designed to operate in pairs, to give protection against breakdowns in service as well as design faults. We have come to regard redundancy and formal design methods as complementary, the one to guard against normal component failures and the other to provide insurance against the risk of the common-cause failures which bedevil reliability predictions. Any future VIPER chips will certainly need improved performance to keep up with increasingly demanding applications. We have a prototype design (not yet specified formally) which includes 32 and 64 bit multiply, instruction pre-fetch, more efficient interface timing, and a new instruction to allow a quick response to peripheral requests. Work is under way to specify this device in MIRANDA, and then to refine the spec into a block-level design by top-down transformations. When the refinement is complete, a relatively simple proof checker should be able to demonstrate its correctness. This paper is presented in viewgraph form.

Kershaw, John

High-Speed Ring Bus

The high-speed ring bus at the Jet Propulsion Laboratory (JPL) allows for future growth trends in spacecraft seen with future scientific missions. This innovation constitutes an enhancement of the 1393 bus as documented in the Institute of Electrical and Electronics Engineers (IEEE) 1393-1999 standard for a spaceborne fiber-optic data bus. It allows for high-bandwidth and time synchronization of all nodes on the ring. The JPL ring bus allows for interconnection of active units with autonomous operation and increased fault handling at high bandwidths. It minimizes the flight software interface with an intelligent physical layer design that has few states to manage as well as simplified testability. The design will soon be documented in the AS-1393 standard (Serial Hi-Rel Ring Network for Aerospace Applications). The framework is designed for "Class A" spacecraft operation and provides redundant data paths. It is based on "fault containment regions" and "redundant functional regions (RFR)" and has a method for allocating cables that completely supports the redundancy in spacecraft design, allowing for a complete RFR to fail. This design reduces the mass of the bus by incorporating both the Control Unit and the Data Unit in the same hardware. The standard uses ATM (asynchronous transfer mode) packets, standardized by ITU-T, ANSI, ETSI, and the ATM Forum. The IEEE-1393 standard uses the UNI form of the packet and provides no protection for the data portion of the cell. The JPL design adds optional formatting to this data portion. This design extends fault protection beyond that of the interconnect. This includes adding protection to the data portion that is contained within the Bus Interface Units (BIUs) and by adding to the signal interface between the Data Host and the JPL 1393 Ring Bus. Data transfer on the ring bus does not involve a master or initiator. Following bus protocol, any BIU may transmit data on the ring whenever it has data received from its host. There is no centralized arbitration or bus granting. The JPL design provides for autonomous synchronization of the nodes on the ring bus. An address-synchronous latency adjust buffer (LAB) has been designed that cannot get out of synchronization and needs no external input. Also, a priority-driven cable selection behavior has been programmed into each unit on the ring bus. This makes the bus able to connect itself up, according to a maximum redundancy priority system, without the need for computer intervention at startup. Switching around a failed or switched-off unit is also autonomous. The JPL bus provides a map of all the active units for the host computer to read and use for fault management. With regard to timing, this enhanced bus recognizes coordinated timing on a spacecraft as critical and addresses this with a single source of absolute and relative time, which is broadcast to all units on the bus with synchronization maintained to the tens of nanoseconds. Each BIU consists of up to five programmable triggers, which may be programmed for synchronization of events within the spacecraft of instrument. All JPL-formatted data transmitted on the ring bus are automatically time-stamped.

Wysocky, Terry

Kinematically redundant robot manipulators

Research on control, design and programming of kinematically redundant robot manipulators (KRRM) is discussed. These are devices in which there are more joint space degrees of freedom than are required to achieve every position and orientation of the end-effector necessary for a given task in a given workspace. The technological developments described here deal with: kinematic programming techniques for automatically generating joint-space trajectories to execute prescribed tasks; control of redundant manipulators to optimize dynamic criteria (e.g., applications of forces and moments at the end-effector that optimally distribute the loading of actuators); and design of KRRMs to optimize functionality in congested work environments or to achieve other goals unattainable with non-redundant manipulators. Kinematic programming techniques are discussed, which show that some pseudo-inverse techniques that have been proposed for redundant manipulator control fail to achieve the goals of avoiding kinematic singularities and also generating closed joint-space paths corresponding to close paths of the end effector in the workspace. The extended Jacobian is proposed as an alternative to pseudo-inverse techniques.

Baillieul, J.

Design Optimization Study of Fault Tolerant and Redundant Motor Drivetrains for Urban Air Mobility Vehicles

Fully electric and hybrid electric aircraft will require extremely lightweight and reliable electric motor drivetrains to meet performance and safety goals. It is likely that to meet reliability targets some form of fault tolerance and/or redundancy will need to be used in the electric motor drivetrain. The use of either redundancy or fault tolerance will result in a reduction in drivetrain performance. In this paper, an example design study is carried out comparing redundant and fault tolerant drivetrains based on an example fault tolerant motor topology for a tilt rotor UAM application. Results show a minimal weight penalty for the incorporation of fault tolerance into drivetrains with the example motor explored here.

Thomas Francis Tallerico

Design Optimization Study of Fault Tolerant and Redundant Motor Drivetrains for Urban Air Mobility Vehicles

Fully electric and hybrid electric aircraft will require extremely lightweight and reliable electric motor drivetrains to meet performance and safety goals. It is likely that to meet reliability targets some form of fault tolerance and/or redundancy will need to be used in the electric motor drivetrain. The use of either redundancy or fault tolerance will result in a reduction in drivetrain performance. In this paper, an example design study is carried out comparing redundant and fault tolerant drivetrains based on an example fault tolerant motor topology for a tilt rotor UAM application. Results show a minimal weight penalty for the incorporation of fault tolerance into drivetrains with the example motor explored here.

Thomas Tallerico

Techniques for generating highly reliable redundant systems.

A simple heuristic algorithm for designing highly reliable modularly redundant computer systems under complexity constraints is presented. The technique, which produces near optimal solutions, is intuitively appealing and easy to apply. The algorithms performance is shown to compare very well with the optimal solution obtained via a computerized model for dynamic programming.

White, J. B.

Prototype data terminal: Multiplexer/demultiplexer

The design and operation of a quad redundant data terminal and a multiplexer/demultiplexer (MDU) design are described. The most unique feature is the design of the quad redundant data terminal. This is one of the few designs where the unit is fail/op, fail/op, fail/safe. Laboratory tests confirm that the unit will operate satisfactorily with the failure of three out of four channels. Although the design utilizes state-of-the-art technology. The waveform error checks, the voting techniques, and the parity bit checks are believed to be used in unique configurations. Correct word selection routines are also novel, if not unique. The MDU design, while not redundant, utilizes, the latest state-of-the-art advantages of light couplers and integrated circuit amplifiers.

Leck, D. E.

Design of a developmental dual fail operational redundant strapped down inertial measurement unit

An experimental redundant strap-down inertial measurement unit (RSDIMU) is being developed at NASA-Langley as a link to satisfy safety and reliability considerations in the integrated avionics concept. The unit consists of four two-degrees-of-freedom (TDOF) tuned-rotor gyros, and four TDOF pendulous accelerometers in a skewed and separable semi-octahedron array. The system will be used to examine failure detection and isolation techniques, redundancy management rules, and optimal threshold levels for various flight configurations. The major characteristics of the RSDIMU hardware and software design, and its use as a research tool are described.

Morrell, F. R.

Effectiveness of Redundant Communications Systems in Maintaining Operational Control of Small Unmanned Aircraft

NASA has been researching prototype technologies for an Unmanned Aircraft System (UAS) Traffic Management (UTM) system to facilitate enabling of safe and efficient civilian low-altitude airspace and UAS operations, in a series of Technical Capability Levels (TCL) activities that are increasingly complex. In TCL1, completed in 2015, visual line-of-sight operations such as agriculture, firefighting and infrastructure monitoring were addressed with a focus on geofencing and operations scheduling. Technologies and requirements needed for beyond visual line-of-sight (BVLOS) operations in sparsely populated areas were examined in TCL2 in 2016, and those for operations over moderately populated areas in TCL3 in 2017 and 2018. TCL4 will build on the earlier TCLs and focus on technologies and requirements for operations in higher-density urban areas for tasks such as news gathering, package delivery and for managing large-scale contingencies. This paper describes a communications test conducted in TCL3 and discusses insights gained from the test. In the test, operators were directed to equip UAS with redundant Command and Control (C2) communications systems, send a maneuver command to Unmanned Aircraft (UA) via the primary system, then verify execution of the sent command. This exercise was repeated with each redundant system. The test was designed to assess effectiveness of redundant C2 systems in maintaining operational control of UA. Several UAS were configured with varying arrangements to achieve redundancy, including two identical radio modems using the same frequency band, WiFi and Long-Term Evolution (LTE) cellular modems, etc. From the test, digital data such as time maneuver command sent, time maneuver verified, etc., were collected. Descriptions of methods to detect loss of C2 communications and contingency steps for such event were collected and assessed. The final paper will include a detailed analysis of the collected data leading to the following insights. First, effectiveness of redundant C2 systems depends on several factors, such as operational environment and communications service availability. For example, use of two identical point-to-point radio to connect operator and UA on the same frequency band can be effective in mitigating radio malfunction when operating in an environment where possibility of Radio Frequency (RF) interference is low, such as over open plains. However, the same arrangement may not be effective where high level of RF transmissions in broad spectrum ranges can be expected, such as over or near urban areas. For redundant systems that consist of external communications services, such as cellular and satellite communications network, redundancy is maintained only in the areas where more than one services are available. Therefore, UAS operators should have the means to plan for and monitor the performance of external communications services they are relying on to control UA. Second, communications performance needs, such as the minimum data transfer rate and the maximum tolerable latency, should be assessed to reflect the potential hazard that can come from loss of UA control. For example, UA operations over desolate area pose less hazard to people than operations over densely populated area and performance need for the former would be less than the latter.

Jung, Jaewoo

A Two-Wheel Observing Mode for the MAP Spacecraft

The Microwave Anisotropy Probe (MAP) is a follow-on to the Differential Microwave Radiometer (DMR) instrument on the Cosmic Background Explorer (COBE). Due to the MAP project's limited mass, power, and budget, a traditional reliability concept including fully redundant components was not feasible. The MAP design employs selective hardware redundancy, along with backup software modes and algorithms, to improve the odds of mission success. This paper describes the effort to develop a backup control mode, known as Observing II, that will allow the MAP science mission to continue in the event of a failure of one of its three reaction wheel assemblies. This backup science mode requires a change from MAP's nominal zero-momentum control system to a momentum-bias system. In this system, existing thruster-based control modes are used to establish a momentum bias about the sun line sufficient to spin the spacecraft up to the desired scan rate. Natural spacecraft dynamics exhibits spin and nutation similar to the nominal MAP science mode with different relative rotation rates, so the two reaction wheels are used to establish and maintain the desired nutation angle from the sun line. Detailed descriptions of the ObservingII control algorithm and simulation results will be presented, along with the operational considerations of performing the rest of MAP's necessary functions with only two wheels.

Starin, Scott R.

Restoring Redundancy to the MAP Propulsion System

The Microwave Anisotropy Probe (MAP) is a follow-on to the Differential Microwave Radiometer (DMR) instrument on the Cosmic Background Explorer (COBE). Due to the MAP project's limited mass, power, and financial resources, a traditional reliability concept including fully redundant components was not feasible. The MAP design employs selective hardware redundancy, along with backup software modes and algorithms, to improve the odds of mission success. In particular, MAP's propulsion system, which is used for orbit maneuvers and momentum management, uses eight thrusters positioned and oriented in such a way that its thruster-based attitude control modes can maintain three-axis attitude control in the event of the failure of any one thruster.

O'Donnell, James R., Jr.

Progressive Damage Analysis of Bonded Composite Joints

The present work is related to the development and application of progressive damage modeling techniques to bonded joint technology. The joint designs studied in this work include a conventional composite splice joint and a NASA-patented durable redundant joint. Both designs involve honeycomb sandwich structures with carbon/epoxy facesheets joined using adhesively bonded doublers.Progressive damage modeling allows for the prediction of the initiation and evolution of damage within a structure. For structures that include multiple material systems, such as the joint designs under consideration, the number of potential failure mechanisms that must be accounted for drastically increases the complexity of the analyses. Potential failure mechanisms include fiber fracture, intraply matrix cracking, delamination, core crushing, adhesive failure, and their interactions. The bonded joints were modeled using highly parametric, explicitly solved finite element models, with damage modeling implemented via custom user-written subroutines. Each ply was discretely meshed using three-dimensional solid elements. Layers of cohesive elements were included between each ply to account for the possibility of delaminations and were used to model the adhesive layers forming the joint. Good correlation with experimental results was achieved both in terms of load-displacement history and the predicted failure mechanism(s).

Leone, Frank A., Jr.

Progressive Damage Modeling of Durable Bonded Joint Technology

The development of durable bonded joint technology for assembling composite structures for launch vehicles is being pursued for the U.S. Space Launch System. The present work is related to the development and application of progressive damage modeling techniques to bonded joint technology applicable to a wide range of sandwich structures for a Heavy Lift Launch Vehicle. The joint designs studied in this work include a conventional composite splice joint and a NASA-patented Durable Redundant Joint. Both designs involve a honeycomb sandwich with carbon/epoxy facesheets joined with adhesively bonded doublers. Progressive damage modeling allows for the prediction of the initiation and evolution of damage. For structures that include multiple materials, the number of potential failure mechanisms that must be considered increases the complexity of the analyses. Potential failure mechanisms include fiber fracture, matrix cracking, delamination, core crushing, adhesive failure, and their interactions. The joints were modeled using Abaqus parametric finite element models, in which damage was modeled with user-written subroutines. Each ply was meshed discretely, and layers of cohesive elements were used to account for delaminations and to model the adhesive layers. Good correlation with experimental results was achieved both in terms of load-displacement history and predicted failure mechanisms.

Leone, Frank A.

Hybrid optimization of truss structures with strength and buckling constraints

An efficient scheme utilizing standard nonlinear programming methodology is presented for the optimal design of elastic, redundant structures with strength and buckling constraints. Numerical examples are given which demonstrate how this method, involving a constraint redefinition, can successfully overcome certain problems typical to such structures. The scheme is applied to the design of a cantilever truss with strength and buckling constraints, in which optimal nonuniform cross section columns are used for all elements critical in buckling. It is found that permitting node movement and adding redundancies can lower the weight of the structure for the prescribed design constraints. In addition, the node excursions in this configuration are shown to be relatively small.

Hajela, P.

Joint-space adaptive control of a redundant telerobot manipulator

The design of a joint-space adaptive control scheme for controlling the slave arm motion of a dual-arm telerobot system is presented. Each slave arm of the dual-arm system is a kinematically redundant manipulator with 7 DOF. The implementation of the derived control scheme does not require the computation of manipulator dynamics, which makes the control scheme sufficiently fast for real-time applications.

Nguyen, Charles C.