Search NASA⌕ Search

SEARCH · Search NASA

Results for “Systems Engineering, Failure Prevention”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Contamination Control and Hardware Processing Solutions at Marshall Space Flight Center

The Contamination Control Team of Marshall Space Flight Center's Materials and Processes Laboratory supports many Programs/ Projects that design, manufacture, and test a wide range of hardware types that are sensitive to contamination and foreign object damage (FOD). Examples where contamination/FOD concerns arise include sensitive structural bondline failure, critical orifice blockage, seal leakage, and reactive fluid compatibility (liquid oxygen, hydrazine) as well as performance degradation of sensitive instruments or spacecraft surfaces such as optical elements and thermal control systems. During the design phase, determination of the sensitivity of a hardware system to different types or levels of contamination/FOD is essential. A contamination control and FOD control plan must then be developed and implemented through all phases of ground processing, and, sometimes, on-orbit use, recovery, and refurbishment. Implementation of proper controls prevents cost and schedule impacts due to hardware damage or rework and helps assure mission success. Current capabilities are being used to support recent and on-going activities for multiple Mission Directorates / Programs such as International Space Station (ISS), James Webb Space Telescope (JWST), Space Launch System (SLS) elements (tanks, engines, booster), etc. The team also advances Green Technology initiatives and addresses materials obsolescence issues for NASA and external customers, most notably in the area of solvent replacement (e.g. aqueous cleaners containing hexavalent chrome, ozone depleting chemicals (CFC s and HCFC's), suspect carcinogens). The team evaluates new surface cleanliness inspection and cleaning technologies (e.g. plasma cleaning), and maintains databases for processing support materials as well as outgassing and optical compatibility test results for spaceflight environments.

Burns, DeWitt H.↗

International Space Station (ISS) External Thermal Control System (ETCS) Loop A Pump Module (PM) Jettison Options Assessment

On December 11, 2013, the International Space Station (ISS) experienced a failure of the External Thermal Control System (ETCS) Loop A Pump Module (PM). To minimize the number of extravehicular activities (EVA) required to replace the PM, jettisoning the faulty pump was evaluated. The objective of this study was to independently evaluate the jettison options considered by the ISS Trajectory Operations Officer (TOPO) and to provide recommendations for safe jettison of the ETCS Loop A PM. The simulation selected to evaluate the TOPO options was the NASA Engineering and Safety Center's (NESC) version of Program to Optimize Simulated Trajectories II (POST2) developed to support another NESC assessment. The objective of the jettison analysis was twofold: (1) to independently verify TOPO posigrade and retrograde jettison results, and (2) to determine jettison guidelines based on additional sensitivity, trade study, and Monte Carlo (MC) analysis that would prevent PM recontact. Recontact in this study designates a propagated PM trajectory that comes within 500 m of the ISS propagated trajectory. An additional simulation using Systems Tool Kit (STK) was run for independent verification of the POST2 simulation results. Ultimately, the ISS Program removed the PM jettison option from consideration. However, prior to the Program decision, the retrograde jettison option remained part of the EVA contingency plan. The jettison analysis presented showed that, in addition to separation velocity/direction and the atmosphere conditions, the key variables in determining the time to recontact the ISS is highly dependent on the ballistic number (BN) difference between the object being jettisoned and the ISS.

Murri, Daniel G.↗

Aging Mechanisms and Control: Specialists' Meeting on Life Management Techniques for Aging Air Vehicles

The costs of maintaining ageing aircraft are draining the existing budgets. The Specialist Meeting provided guidance on strategies for the development and implementation of technologies and logistic management processes to reduce this economic burden. The emphasis was on military aircraft, but many of the principles could be applied to other defence systems. The papers covered the entire range of ageing problems including structural integrity, corrosion, avionics, mechanical subsystems, structures and wiring as well as the role of information management. Forty-two papers addressed the safety and economic implications such as fatigue cracking, corrosion, wear and material degradation. Key technologies were discussed, including non-destructive inspection, repair, modifications, prevention analysis, and health management. The shortcomings of current were highlighted and the investment required was identified. The need for research and development was clearly identified.

aging tests (materials)↗

An improved turbine disk design to increase reliability of aircraft jet engines

An analytical study was performed on a novel disk design to replace the existing high-pressure turbine, stage 1 disk on the CF6-50 turbofan engine. Preliminary studies were conducted on seven candidate disk design concepts. An integral multidisk design with bore entry of the turbine blade cooling air was selected as the improved disk design. This disk has the unique feature of being redundant such that if one portion of the disk would fail, the remaining portion would prevent the release of large disk fragments from the turbine system. Low cycle fatigue lives, initial defect propagation lives, burst speed, and the kinetic energies of probable disk fragment configurations were calculated, and comparisons were made with the existing disk, both in its current material, IN 718, and with the substitution of an advanced alloy, Rene 95. The design for redundancy approach which necessitated the addition of approximately 44.5 kg (98 lb) to the design disk substantially improved the life of the disk. The life to crack initiation was increased from 30,000 cycles to more than 100,000 cycles. The cycles to failure from initial defect propagation were increased from 380 cycles to 1564 cycles. Burst speed was increased from 126 percent overspeed to 149 percent overspeed. Additionally, the maximum fragment energies associated with a failure were decreased by an order of magnitude.

Barack, W. N.↗

Real-time sensor data validation

This report describes the status of an on-going effort to develop software capable of detecting sensor failures on rocket engines in real time. This software could be used in a rocket engine controller to prevent the erroneous shutdown of an engine due to sensor failures which would otherwise be interpreted as engine failures by the control software. The approach taken combines analytical redundancy with Bayesian belief networks to provide a solution which has well defined real-time characteristics and well-defined error rates. Analytical redundancy is a technique in which a sensor's value is predicted by using values from other sensors and known or empirically derived mathematical relations. A set of sensors and a set of relations among them form a network of cross-checks which can be used to periodically validate all of the sensors in the network. Bayesian belief networks provide a method of determining if each of the sensors in the network is valid, given the results of the cross-checks. This approach has been successfully demonstrated on the Technology Test Bed Engine at the NASA Marshall Space Flight Center. Current efforts are focused on extending the system to provide a validation capability for 100 sensors on the Space Shuttle Main Engine.

Bickmore, Timothy W.↗

Automation-induced monitoring inefficiency: role of display location

Operators can be poor monitors of automation if they are engaged concurrently in other tasks. However, in previous studies of this phenomenon the automated task was always presented in the periphery, away from the primary manual tasks that were centrally displayed. In this study we examined whether centrally locating an automated task would boost monitoring performance during a flight-simulation task consisting of system monitoring, tracking and fuel resource management sub-tasks. Twelve nonpilot subjects were required to perform the tracking and fuel management tasks manually while watching the automated system monitoring task for occasional failures. The automation reliability was constant at 87.5% for six subjects and variable (alternating between 87.5% and 56.25%) for the other six subjects. Each subject completed four 30 min sessions over a period of 2 days. In each automation reliability condition the automation routine was disabled for the last 20 min of the fourth session in order to simulate catastrophic automation failure (0 % reliability). Monitoring for automation failure was inefficient when automation reliability was constant but not when it varied over time, replicating previous results. Furthermore, there was no evidence of resource or speed accuracy trade-off between tasks. Thus, automation-induced failures of monitoring cannot be prevented by centrally locating the automated task.

Automation↗

Cleanroom Contamination Identification Method Development

During fabrication, assembly, and testing of spacecraft and flight hardware it is vital to avoid contaminants that can cause degradation and could result in significant failure. Yet, there is no existing contamination monitoring method that provides the identity of airborne particles in a cleanroom facility. Knowing the particle identities, would allow scientists and engineers to determine the source of the contaminants and prevent setbacks before they occur or cause damage. Current cleanliness monitoring methods include airborne particle counters (APCs), fallout filters, and visual inspections. Particle counts from APCs are the primary metric used to define a cleanroom class and hence its level of cleanliness, but do not provide identification nor can they differentiate between large and small sizes of particles. In addition, using fallout filters is not a proactive, timely, or representative approach to cleanroom contamination monitoring because these samples are only retrieved after 30 days and are placed away from spacecraft processing to avoid interference with operations. In contrast, the forced air sampling method can collect a sample within an hour at any location required and provide results in less than a day. This system uses a cassette and filter sample medium to capture airborne particles which are then taken to a scanning electron microscope with energy dispersive spectroscopy (SEM/EDS) to identify and size the captured particles. Development of forced air sampling into an established laboratory capability will allow for fast sampling and routine identification of unknown contamination sources within the cleanroom. The test method development required market research for an air sampling cassette that increases sample collection efficiency and a filter with low enough background contamination to allow differentiation between a blank (control) and the collected sample. It was determined that a conductive black cassette and a polycarbonate filter were the best options. Conductive black cassettes, in comparison to the standard styrene, are manufactured using polypropylene filled with carbon. This makes the cassette conductive and minimizes the tendency of particles to stick to the wall of the cassette due to electrostatic force. In previous trials a mixed cellulose ester (MCE) filter was used to capture the contaminants, however the rougher surface of the filter contributed to entrapment of the particles within the filter structure and made it harder to identify the particles. In comparison, track etched polycarbonate filters have random cylindrical pores and a smooth surface which contributes to uniform sample distribution on the surface of the filter. Future work includes: testing the system using control samples to determine the efficiency and suitability of the medium, performing sample collection in various environments to establish ideal operating parameters and analyzing contaminant particles using SEM/EDS and assistant characterization techniques. Once fully developed, employing the forced air sampling method will help to prevent damage to spacecraft, avoid schedule delays, and allow for mission success.

Hernandez Melendez, Jailyn M.↗

Monitoring Damage Accumulation in Ceramic Matrix Composites Using Electrical Resistivity

The electric resistance of woven SiC fiber reinforced SiC matrix composites were measured under tensile loading conditions. The results show that the electrical resistance is closely related to damage and that real-time information about the damage state can be obtained through monitoring of the resistance. Such self-sensing capability provides the possibility of on-board/in-situ damage detection and accurate life prediction for high-temperature ceramic matrix composites. Woven silicon carbide fiber-reinforced silicon carbide (SiC/SiC) ceramic matrix composites (CMC) possess unique properties such as high thermal conductivity, excellent creep resistance, improved toughness, and good environmental stability (oxidation resistance), making them particularly suitable for hot structure applications. In specific, CMCs could be applied to hot section components of gas turbines [1], aerojet engines [2], thermal protection systems [3], and hot control surfaces [4]. The benefits of implementing these materials include reduced cooling air requirements, lower weight, simpler component design, longer service life, and higher thrust [5]. It has been identified in NASA High Speed Research (HSR) program that the SiC/SiC CMC has the most promise for high temperature, high oxidation applications [6]. One of the critical issues in the successful application of CMCs is on-board or insitu assessment of the damage state and an accurate prediction of the remaining service life of a particular component. This is of great concern, since most CMC components envisioned for aerospace applications will be exposed to harsh environments and play a key role in the vehicle s safety. On-line health monitoring can enable prediction of remaining life; thus resulting in improved safety and reliability of structural components. Monitoring can also allow for appropriate corrections to be made in real time, therefore leading to the prevention of catastrophic failures. Most conventional nondestructive evaluation (NDE) techniques such as ultrasonic C-scan, x-ray, thermography, and eddy current are limited since they require structural components of complex geometry to be taken out of service for a substantial length of time for post-damage inspection and assessment. Furthermore, the typical NDE techniques are useful for identifying large interlaminar flaws, but insensitive to CMC materials flaws developed perpendicular to the surface under tensile creep conditions. There are techniques such as piezoelectric sensor [7,8], and optical fiber [9,10] that could be used for on-line health monitoring of CMC structures. However, these systems involve attaching an external sensor or putting special fibers in CMC composites, which would be problematic at high temperature applications.

Smith, Craig E.↗

Spinoff 2013

Topics covered include: Innovative Software Tools Measure Behavioral Alertness; Miniaturized, Portable Sensors Monitor Metabolic Health; Patient Simulators Train Emergency Caregivers; Solar Refrigerators Store Life-Saving Vaccines; Monitors Enable Medication Management in Patients' Homes; Handheld Diagnostic Device Delivers Quick Medical Readings; Experiments Result in Safer, Spin-Resistant Aircraft; Interfaces Visualize Data for Airline Safety, Efficiency; Data Mining Tools Make Flights Safer, More Efficient; NASA Standards Inform Comfortable Car Seats; Heat Shield Paves the Way for Commercial Space; Air Systems Provide Life Support to Miners; Coatings Preserve Metal, Stone, Tile, and Concrete; Robots Spur Software That Lends a Hand; Cloud-Based Data Sharing Connects Emergency Managers; Catalytic Converters Maintain Air Quality in Mines; NASA-Enhanced Water Bottles Filter Water on the Go; Brainwave Monitoring Software Improves Distracted Minds; Thermal Materials Protect Priceless, Personal Keepsakes; Home Air Purifiers Eradicate Harmful Pathogens; Thermal Materials Drive Professional Apparel Line; Radiant Barriers Save Energy in Buildings; Open Source Initiative Powers Real-Time Data Streams; Shuttle Engine Designs Revolutionize Solar Power; Procedure-Authoring Tool Improves Safety on Oil Rigs; Satellite Data Aid Monitoring of Nation's Forests; Mars Technologies Spawn Durable Wind Turbines; Programs Visualize Earth and Space for Interactive Education; Processor Units Reduce Satellite Construction Costs; Software Accelerates Computing Time for Complex Math; Simulation Tools Prevent Signal Interference on Spacecraft; Software Simplifies the Sharing of Numerical Models; Virtual Machine Language Controls Remote Devices; Micro-Accelerometers Monitor Equipment Health; Reactors Save Energy, Costs for Hydrogen Production; Cameras Monitor Spacecraft Integrity to Prevent Failures; Testing Devices Garner Data on Insulation Performance; Smart Sensors Gather Information for Machine Diagnostics; Oxygen Sensors Monitor Bioreactors and Ensure Health and Safety; Vision Algorithms Catch Defects in Screen Displays; and Deformable Mirrors Capture Exoplanet Data, Reflect Lasers.

Source record↗

Space Plasma Shown to Make Satellite Solar Arrays Fail

In 1997, scientists and engineers of the Photovoltaic and Space Environments Branch of the NASA Lewis Research Center, Maxwell Technologies, and Space Systems/Loral discovered a new failure mechanism for solar arrays on communications satellites in orbit. Sustained electrical arcs, initiated by the space plasma and powered by the solar arrays themselves, were found to have destroyed solar array substrates on some Space Systems/Loral satellites, leading to array failure. The mechanism was tested at Lewis, and mitigation strategies were developed to prevent such disastrous occurrences on-orbit in the future. Deep Space 1 is a solar-electric-powered space mission to a comet, launched on October 24, 1998. Early in 1998, scientists at Lewis and Ballistic Missile Defense Organization (BMDO) realized that some aspects of the Deep Space 1 solar arrays were nearly identical to those that had led to the failure of solar arrays on Space Systems/Loral satellites. They decided to modify the Deep Space 1 arrays to prevent catastrophic failure in space. The arrays were suitably modified and are now performing optimally in outer space. Finally, the Earth Observing System (EOS) AM1, scheduled for launch in mid-1999, is a NASA mission managed by the Goddard Space Flight Center. Realizing the importance of Lewis testing on the Loral arrays, EOS-AM1 management asked Lewis scientists to test their solar arrays to show that they would not fail in the same way. The first phase of plasma testing showed that sustained arcing would occur on the unmodified EOS-AM1 arrays, so the arrays were removed from the spacecraft and fixed. Now, Lewis scientists have finished plasma testing of the modified array configuration to ensure that EOS-AM1 will have no sustained arcing problems on-orbit.

Ferguson, Dale C.↗

C-Band Airport Surface Communications System Engineering-Initial High-Level Safety Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed C-band (5091- to 5150-MHz) airport surface communication system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents an initial high-level safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the C-band communication system after the profile is finalized and system rollout timing is determined. A security risk assessment has been performed by NASA as a parallel activity. While safety analysis is concerned with a prevention of accidental errors and failures, the security threat analysis focuses on deliberate attacks. Both processes identify the events that affect operation of the system; and from a safety perspective the security threats may present safety risks.

Zelkin, Natalie↗

Extending the Life of NASA’s Tracking and Data Relay Satellite (TDRS)-8: TDRS-8 Power Challenges And Planning for End of Mission

The United States National Aeronautics and Space Administration (NASA) Near Space Network’s Space Relay (SR) System provides communication relay services to a number of scientific and manned space missions with its Tracking and Data Relay Satellite (TDRS) constellation. NASA’s eighth Tracking and Data Relay Satellite (TDRS) has been experiencing a decline in the health of its power subsystem, and recent reliability analyses indicate that the end of its mission serving the Space Relay is imminent. Launched in 2000, TDRS-8 is the oldest TDRS built upon a Boeing 601 platform, and as such it is the first TDRS to experience these age-related failures. The most prevalent elements of the power subsystem to decline are the solar array circuitry and the Bus Voltage Limiters (BVLs), which prevent too much power from the solar arrays being transferred to the bus by shunting excess current. This means that while the loss of solar array circuits introduces concerns that the solar arrays will continue providing the spacecraft with enough current to remain power positive, the loss of BVLs introduces a concern that the bus may not be adequately protected from overvoltage events. Spacecraft engineers at the TDRS primary ground terminal, the White Sands Complex (WSC) in Las Cruces, New Mexico, and at NASA's Goddard Space Flight Center (GSFC) have also been working in collaboration with Boeing to develop innovative techniques to extend the serviceable life of TDRS-8.

tdrs↗

Flat H Redundant Frangible Joint Development

Orion and Commercial Crew Program (CCP) Partners have chosen to use frangible joints for certain separation events. The joints currently available are zero failure tolerant and will be used in mission safety applications. The goal is to further develop a NASA designed redundant frangible joint that will lower flight risk and increase reliability. FY16 testing revealed a successful design in subscale straight test specimens that gained efficiency and supports Orion load requirements. Approach / Innovation A design constraint is that the redundant joint must fit within the current Orion architecture, without the need for additional vehicle modification. This limitation required a design that changed the orientation of the expanding tube assemblies (XTAs), by rotating them 90deg from the standard joint configuration. The change is not trivial and affects the fracture mechanism and structural load paths. To address these changes, the design incorporates cantilevered arms on the break plate. The shock transmission and expansion of the XTA applies force to these arms and creates a prying motion to push the plate walls outward to the point of structural failure at the notched section. The 2014 test design revealed that parts could slip during functioning wasting valuable energy needed to separate the structure with only a single XTA functioning. Dual XTA functioning fully separated the assembly showing a discrepancy can be backed up with redundancy. Work on other fully redundant systems outside NASA is limited to a few patents that have not been subjected to functionality testing Design changes to prevent unwanted slippage (with ICA funding in 2015) showed success with a single XTA. The main goal for FY 2016 was to send the new Flat H RFJ to WSTF where single XTA test failures occurred back in 2014. The plan was to gain efficiency in this design by separating the Flat H RFJ with thicker ligaments with dimensions baselined in 2014. Other modifications included geometry changes to better disperse loads paths and to minimize air gaps. The design additionally added more structural strength to enhance the structural limits in static loads testing. The design also implemented a smoother load line through the assembly. Results / Knowledge Gained The new Flat H RFJ successfully fractured at WSTF with thicker ligaments and lower cord size. Where failure to separate occurred earlier, there is now excessive energy available for structural separation. The new challenge to provide some structural support to prevent secondary fracturing of the break plate remains to be completed. This future work is being funded by the JSC Engineering Directorate in 2017 to elevate the TRL on curved Flat H RFJs that configure with the Orion Service Panel Separation. Additional funding from JSC Engineering will provide new design testing to avoid secondary fracturing.

Brown, Chris↗

Start Up Application Concerns with Field Programmable Gate Arrays (FPGAs)

This note is being published to improve the visibility of this subject, as we continue to see problems surface in designs, as well as to add additional information to the previously published note for design engineers. The original application note focused on designing systems with no single point failures using Actel Field Programmable Gate Arrays (FPGAs) for critical applications. Included in that note were the basic principles of operation of the Actel FPGA and a discussion of potential single-point failures. The note also discussed the issue of startup transients for that class of device. It is unfortunate that we continue to see some design problems using these devices. This note will focus on the startup properties of certain electronic components, in general, and current Actel FPGAs, in particular. Devices that are "power-on friendly" are currently being developed by Actel, as a variant of the new SX series of FPGAs. In the ideal world, electronic components would behave much differently than they do in the real world, The chain, of course, starts with the power supply. Ideally, the voltage will immediately rise to a stable V(sub cc) level, of course, it does not. Aside from practical design considerations, inrush current limits of certain capacitors must be observed and the power supply's output may be intentionally slew rate limited to prevent a large current spike on the system power bus. In any event, power supply rise time may range from less than I msec to 100 msec or more.

Katz, Richard B.↗

Turbomachine Sealing and Secondary Flows: Review of Rotordynamics Issues in Inherently Unsteady Flow Systems With Small Clearances - Part 2

Today's computational methods enable the determination of forces in complex systems, but without field validation data, or feedback, there is a high risk of failure when the design envelope is challenged. The data of Childs and Bently and field data reported in NASA Conference Proceedings serve as sources of design information for the development of these computational codes. Over time all turbomachines degrade and instabilities often develop, requiring responsible, accurate, turbomachine diagnostics with proper decisions to prevent failures. Tam et al. (numerical) and Bently and Muszynska (analytical) models corroborate and implicate that destabilizing factors are related through increases in the fluid-force average circumferential velocity. The stability threshold can be controlled by external swirl and swirl brakes and increases in radial fluid film stiffness (e.g., hydrostatic and ambient pressures) to enhance rotor stability. Also cited are drum rotor self-excited oscillations, where the classic fix is to add a split or severed damper ring or cylindrical damper drum, and the Benkert-Wachter work that engendered swirl brake concepts. For a smooth-operating, reliable, long-lived machine, designers must pay very close attention to sealing dynamics and diagnostic methods. Correcting the seals enabled the space shuttle main engine high-pressure fuel turbopump (SSME HPFTP) to operate successfully.

Hendricks, R. C.↗

Preliminary Analysis of Aircraft Loss of Control Accidents: Worst Case Precursor Combinations and Temporal Sequencing

Aircraft loss of control (LOC) is a leading cause of fatal accidents across all transport airplane and operational classes, and can result from a wide spectrum of hazards, often occurring in combination. Technologies developed for LOC prevention and recovery must therefore be effective under a wide variety of conditions and uncertainties, including multiple hazards, and their validation must provide a means of assessing system effectiveness and coverage of these hazards. This requires the definition of a comprehensive set of LOC test scenarios based on accident and incident data as well as future risks. This paper defines a comprehensive set of accidents and incidents over a recent 15 year period, and presents preliminary analysis results to identify worst-case combinations of causal and contributing factors (i.e., accident precursors) and how they sequence in time. Such analyses can provide insight in developing effective solutions for LOC, and form the basis for developing test scenarios that can be used in evaluating them. Preliminary findings based on the results of this paper indicate that system failures or malfunctions, crew actions or inactions, vehicle impairment conditions, and vehicle upsets contributed the most to accidents and fatalities, followed by inclement weather or atmospheric disturbances and poor visibility. Follow-on research will include finalizing the analysis through a team consensus process, defining future risks, and developing a comprehensive set of test scenarios with correlation to the accidents, incidents, and future risks. Since enhanced engineering simulations are required for batch and piloted evaluations under realistic LOC precursor conditions, these test scenarios can also serve as a high-level requirement for defining the engineering simulation enhancements needed for generating them.

Belcastro, Christine M.↗

Micrometeoroid and Orbital Debris (MMOD) Testing, Ballistic Limit Definition and Risk Assessment of the Exploration Extravehicular Mobility Unit (xEMU)

A well-known hazard associated with exposure to the space environment is the risk of failure due to an impact from a micrometeoroid and orbital debris (MMOD) particle. As NASA prepares to return astronauts to the moon with the Artemis program, the next generation of spacesuit is in development to support future extravehicular activities (EVAs.) An MMOD impact to the spacesuit is of great concern as a large leak could prevent an astronaut from safely reaching an airlock in time resulting in a loss of life. The exploration extravehicular mobility unit (xEMU) must meet MMOD requirements for multiple environments including those in low earth orbit (LEO) as well as the meteoroid and secondary lunar regolith ejecta environments found on the lunar surface. The subject of this paper is an internal xEMU configuration design developed by NASA Johnson Space Center (JSC) personnel. The xEMU shares similarities with the legacy Extravehicular Mobility Unit (EMU) spacesuit that is currently used for ISS EVAs, however differences in the layup (e.g., materials, thicknesses, and layers) of the fabric environmental protection garment (EPG), portable life support system (xPLSS) and helmet required an extensive test program to determine ballistic performance. Over 100 hypervelocity impact (HVI) tests were performed by the NASA/JSC HVIT and White Sands Test Facility (WSTF) teams on the xEMU EPG, xPLSS and helmet to generate ballistic limit equations (BLEs) for MMOD impacts. Additionally, over 50 low speed tests (< 1km/s) were performed by the NASA/JSC HVIT and Southwest Research Institute (SwRI) teams on the xEMU EPG, xPLSS and helmet to generate BLEs for lunar ejecta impacts. Post testing, ballistic limit equations (BLEs) used to define the performance of the various regions on the xEMU spacesuit were developed from a generic set of BLEs. The HVI and low speed testing was performed to establish a physical basis for the equations with the coefficients and exponents of the generic BLEs adjusted to fit the test data. The xEMU BLEs were added to the NASA/JSC software application used for spacecraft MMOD risk assessments (BUMPER-3). A finite element model (FEM) of the xEMU spacesuit, which defines the size and shape of the spacesuit as well as the locations of the various shielding configurations, was created based on a solid model provided by the xEMU program office. Using the FEM file and added xEMU BLEs, BUMPER-3 assessments of the xEMU spacesuit for probability of no penetration (PNP) were performed. For the LEO assessment of a typical ISS EVA, the orbital debris and meteoroids environments were defined using the latest engineering models, ORDEM 3.2 and MEM-3 respectively. The lunar surface assessment again used the MEM-3 engineering model to define the meteoroid environment along with the current released lunar surface ejecta model, NASA SP-8013 (developed during the Apollo Program). The Space Team in the Natural Environments Branch at Marshall Space Flight Center (MSFC) will soon release the new Lunar Meteoroid Ejecta Engineering Model (LMEEM), at which time the xEMU lunar surface EVA will be reassessed. Assessment of the MMOD risk for an 8-hour, 2-person EVA in both LEO and on the lunar surface showed that the xEMU spacesuit meets the program technical requirement of 1 in 2500 failure odds. Similar to the legacy EMU spacesuit, the majority of the MMOD risk (96% of the LEO EVA risk and 99% of the lunar surface EVA risk) is concentrated in regions of xEMU that are comprised primarily of softgoods (arms, legs, and gloves) rather than the hardgoods (xPLSS, hard upper torso and helmet).

Micrometeoroid↗

Analysis of Launch Vehicle Liftoff Debris: Historical Perspective from Space Shuttle and Application to Artemis I

Human exploration-class launch vehicles are inherently prone to debris due to the extreme environments generated during pre-launch operations, liftoff, and flight. The use of cryogenic propellants often requires thermal protection system (TPS) coatings, typically foam, to maintain the propellant conditions in the tank and prevent an accumulation ice on the external surface of the vehicle. Some ice growth is to be expected at umbilical interfaces, vents, flanges, or brackets where it is difficult to apply TPS. This ice may come loose at any time due to wind on the launch pad, structural vibration and acoustics after rocket ignition, or aerodynamic forces during flight. This phenomena is especially apparent on vehicles with no TPS, such as the Saturn V rockets used in the Apollo Program, see Figure 1. During propellant tanking, the thermal contraction of the underlying substrate may generate cracks in the TPS (Figure 1). Chunks of TPS can release due to the expansion of ingested gas from cryopumping or from aerodynamic forces if the crack creates an offset surface. Most foams will also have a certain amount of “popcorning” where small pieces of foam will pop off during flight because of the differential between the static surface pressure and the pressure of the gas trapped in the foam cell structure. There are a number of other coating or closeout materials that may be shed from the vehicle and become debris. During pre-launch operations and liftoff, the vehicle may also be exposed to debris originating from the launch pad or ground support equipment. This debris is separate from foreign object debris, or FOD, which is not intended to be present and is strictly controlled through operations and maintenance procedures. In this case, debris is generated from hardware and materials that are necessary for launch and are subject to the intense vibration, acoustics, and direct plume impingement of the launch environment. Examples include ice from umbilicals, tape and tie wraps that protect cables, and rust or corrosion from the launch platform. While NASA has historically been aware of debris as a potential issue that could cause a failure resulting in loss of mission, loss of vehicle, or loss of crew, the likelihood and severity of that risk was not always well understood or given sufficient weight in program and flight decisions. After the Space Shuttle Columbia accident (STS-107), the investigation found that foam TPS debris shed from the external tank was the proximate cause of the damage to the orbiter wing. Six previous observations of debris released from the foam ramp that covered the bipod connecting the forward end of the orbiter to the external tank resulted in minor changes or were determined to be accepted flight risks. Two occurrences of bipod ramp foam loss were not identified until the STS-107 investigation. Despite the damage inflicted by these debris strikes, the Shuttle Program Requirements Control Board deemed the vehicle safe to fly. During the Return to Flight effort following the Columbia disaster, NASA Engineering developed a process for the assessment of debris transport, impact, and damage tolerance to support independent assessments of risk by NASA Safety and Mission Assurance (S&MA). Under this system, each element (vehicle or ground system) defines a catalog of all expected debris based on launch history, component testing, or analysis. Debris transport analysis (DTA) is conducted using the debris catalog characteristics and potential flow transport mechanisms (e.g., vehicle aerodynamics, gravity, wind, plume-driven). The predicted debris impact locations and velocities are provided to the hardware owners, who use available test data and analysis to determine whether each component can withstand the impacts. In cases where the element hardware may be severely damaged or fail, the options are to mitigate the debris source through some change in design or operation, or to work with S&MA to try to characterize the probability of the impact and damage for program risk acceptance. Because of the differences in debris characteristics and transport, the DTA has been divided between the Liftoff and Ascent regimes. The development and application of Liftoff DTA methodology from the Shuttle Program to the current Artemis Program is the subject of this paper. Liftoff DTA covers the time from the start of pre-launch operations at the launch pad, up until the vehicle clears the launch tower and there is no longer any interaction with ground systems. Debris transport during this period is broadly classified as either gravity, wind, and plume-entrained (GWPE) or plume driven (PD). GWPE debris is generally lower speed, travelling in a forward-to-aft direction. PD transport includes flow features from the rocket ignition transient, as well as plume impingement and recirculation that occur as the vehicle lifts off the launch platform. In these cases, the debris typically moves in an aft-to-forward direction at higher speeds. The applicable transport mechanisms must be considered for each piece of debris depending on the material, and release location and time. For example, rust or metallic debris from the tower could fall (GWPE) and impact the vehicle before landing on the launch platform deck where it could be also be transported by plume impingement (PD). However, falling ice (GWPE) from an umbilical is unlikely to survive impact with the vehicle or launch platform and be available for PD transport. Modeling of debris transport is accomplished using a set of DTA tools which simulate debris trajectories subject to a reference frame acceleration (i.e., gravity) and aerodynamic drag. Where the trajectory encounters a solid surface, the debris is allowed to rebound with a specified coefficient of restitution. The drag is calculated by interpolating the fluid state at each point in the debris trajectory from high-fidelity computational fluid dynamics (CFD) simulations of the launch vehicle and pad. The CFD data may either be static (steady state or time averaged), typically for GWPE transport, or dynamic (time-accurate) for PD flow features like the ignition transient. Examples of the CFD flow field solutions for the Space Launch System (SLS) rocket and launch pad are shown in Figure 2. Typical SLS debris trajectory predictions from DTA are illustrated in Figure 3. The final version of this paper will include a more detailed examination of the Liftoff DTA process developed during the Shuttle Program, and how it has been augmented and applied to the SLS rocket under the Artemis Program. Comparisons with debris observations from the Artemis I launch will demonstrate validation of the tools and methodology.

Debris↗