Search NASASearch

SEARCH · Search NASA

Results for “failure cause”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

A scheme for fault tolerance in earth sensors

A system is presented that uses dual-redundant earth sensors to measure pitch and roll errors of a three-axis stabilized spacecraft, with provision for (1) autonomously detecting and identifying a faulty earth sensor, and (2) automatically selecting the outputs of the fault-free sensor for closed-loop attitude control, before failures cause major problems. A brief description is given of the system, and various failure modes of earth sensors and their effects are discussed. Novel techniques and algorithms for automatic fault detection, identification, and reconfiguration (FDIR) of dual-redundant earth sensors are developed. The algorithms are validated through computer simulations, and the results are presented. The proposed scheme can easily be implemented without much penalty on hardware, power consumption, and processing time.

Murugesan, S.

STS-51 pad abort. OV103-engine 2033 (ME-2) fuel flowmeter sensor open circuit

The STS-51 initial launch attempt of Discovery (OV-103) was terminated on KSC launch pad 39B on 12 Aug. 1993 at 9:12 AM E.S.T. due to a sensor redundancy failure in the liquid hydrogen system of ME-2 (Engine 2033). The event description and time line are summarized. Propellant loading was initiated on 12 Aug. 1993 at 12:00 AM EST. All space shuttle main engine (SSME) chill parameters and Launch Commit Criteria (LCC) were nominal. At engine start plus 1.34 seconds a Failure Identification (FID) was posted against Engine 2033 for exceeding the 1800 spin intra-channel (A1-A2) Fuel Flowrate sensor channel qualification limit. The engine was shut down at 1.50 seconds followed by Engines 2032 and 2030. All shut down sequences were nominal and the mission was safely aborted. SSME Avionics hardware and software performed nominally during the incident. A review of vehicle data table (VDT) data and controller software logic revealed no failure indications other than the single FID 111-101, Fuel Flowrate Intra-Channel Test Channel A disqualification. Software logic was executed according to requirements and there was no anomalous controller software operation. Immediately following the abort, a Rocketdyne/NASA failure investigation team was assembled. The team successfully isolated the failure cause to an open circuit in a Fuel Flowrate Sensor. This type of failure has occurred eight previous times in ground testing. The sensor had performed acceptably on three previous flights of the engine and SSME flight history shows 684 combined fuel flow rate sensor channel flights without failure. The disqualification of an Engine 2 (SSME No. 2033) Fuel Flowrate sensor channel was a result of an instrumentation failure and not engine performance. All other engine operations were nominal. This disqualification resulted in an engine shutdown and safe sequential shutdown of all three engines prior to ignition of the solid boosters.

Source record

VIPER project

The VIPER project has so far produced a formal specification of a 32 bit RISC microprocessor, an implementation of that chip in radiation-hard SOS technology, a partial proof of correctness of the implementation which is still being extended, and a large body of supporting software. The time has now come to consider what has been achieved and what directions should be pursued in the future. The most obvious lesson from the VIPER project was the time and effort needed to use formal methods properly. Most of the problems arose in the interfaces between different formalisms, e.g., between the (informal) English description and the HOL spec, between the block-level spec in HOL and the equivalent in ELLA needed by the low-level CAD tools. These interfaces need to be made rigorous or (better) eliminated. VIPER 1A (the latest chip) is designed to operate in pairs, to give protection against breakdowns in service as well as design faults. We have come to regard redundancy and formal design methods as complementary, the one to guard against normal component failures and the other to provide insurance against the risk of the common-cause failures which bedevil reliability predictions. Any future VIPER chips will certainly need improved performance to keep up with increasingly demanding applications. We have a prototype design (not yet specified formally) which includes 32 and 64 bit multiply, instruction pre-fetch, more efficient interface timing, and a new instruction to allow a quick response to peripheral requests. Work is under way to specify this device in MIRANDA, and then to refine the spec into a block-level design by top-down transformations. When the refinement is complete, a relatively simple proof checker should be able to demonstrate its correctness. This paper is presented in viewgraph form.

Kershaw, John

Representing Complex Systems as Graphs for Debugging and Predictive Maintenance-Preliminary Thoughts

Representing complex systems as graphs enables use of mathematical tools to identify faults or predict failures. Graph nodes correspond to individual modules or subsystems, and edges link coupled system parts. ‘Probes’ measure the node outputs, monitoring the system health for unexpected behavior. Assuming one cannot probe every point, within a system, the fault correlates to a region—not necessarily the specific location. Bayesian networks trained to understand fault patterns can accurately identify the source. The diagnostic tool described aides debugging by pinpointing system failure causes. For predictive maintenance, probe data develop probability distribution functions describing subsystem mean time to failure. Unit lifetime can be estimated through these probability distributions. Two approaches include using Bayesian classifiers to infer the system failure source and developing maintenance schedules by treating systems as collections of random variables. When failure behavior does not follow a closed form function, use of similarity models is proposed.

97 MATHEMATICS AND COMPUTING

A 13000-hour test of a mercury hollow cathode

A mercury-fed hollow cathode was tested for 12,979 hours in a bell jar at SERT 2 neutralizer operating conditions. The net electron current drawn to a collector was 0.25 ampere at average collector voltages between 21.8 and 36.7 volts. The mercury flow rate was varied from 5.6 to 30.8 equivalent milliamperes to give stable operation at the desired electrode voltages and currents. Variations with time in the neutralizer discharge characteristics were observed and hypothesized to be related to changes in the cathode orifice dimensions and the availability of electron emissive material. A facility failure caused abnormal test conditions for the last 876 hours and led to the cathode heater failure which concluded the test.

Rawlin, V. K.

Experimental investigation of the dependence of void nucleation and growth on initial microstructure in high-purity titanium under tension

An experimental investigation of failure mechanisms in relation to the initial microstructure in high-purity titanium samples is presented. The initial microstructure of the specimens was measured in 3D using diffraction-contrast tomography (DCT). Ex-situ X-ray computed tomography (XCT) was used to visualize voids in specimens at various levels of deformation attained by interrupted tensile testing. Electron backscatter diffraction (EBSD) mapping was used to characterize the deformed microstructures per specimen. The investigation showed that the location of failures was unrelated to the formation of the first voids, but rather the nucleation and growth of cracks were from heavily deformed surface regions. The areas surrounding the failure-causing cracks had the highest propensity for void development of any area in the specimen. This facilitated crack propagation through the specimen via “linking up”. The failure of the specimens by microvoid coalescence was bolstered by “dimpled” fracture surfaces. Paint composed of gallium embedded in rubber was used to track the displacement of points along the loading direction of the specimens, to relate the location of failure to the material's initial microstructure. However, the correlation proved difficult, due to complex microstructural evolution involving voids, grain fragmentations, and profuse twinning. Nevertheless, it was shown that necking occurred near the largest grain in the gauge section of the specimens. This is likely caused by the decrease in strength of larger grains, causing strain to concentrate in their vicinity. Here, a comprehensive picture of the failure processes in high-purity titanium under axial loading is presented and discussed in the paper.

36 MATERIALS SCIENCE

Design and testing of small composite specimens

The effect of specimen size on the buckling strains of laminates subjected to low velocity projectile impact was investigated. The fiber composite selected was T300/5208 graphite/epoxy system. The quasi-isotropic laminates tested had 16 and 32 plies. The results were compared with those of a 48-ply laminate. Specimens of three different lengths with length to width aspect ratios of 1, 1.5, and 2 were also studied. The results show that (1) the specimen length does not have any significant influence on the buckling strains at failure caused by the projectile impact, and (2) the influence of specimen thickness on the strains at failure would decrease as the velocity of the impacting projectile increases.

Sharma, A. V.

Ultrasonic Lamb Wave Inspection of Composite Defects

Composites have been extensively used in aerospace engineering due to their advantages of light weight, high strength, and engineering design flexibility. Manufacturing defects such as wrinkle and porosity can affect the performance of the composites and may lead to failure in the end, while damage such as delamination, fiber fraction, and matrix cracking can directly cause failure of the composites. In this paper, a Lamb wave based nonintrusive nondestructive evaluation system, which employs piezoelectric transducer for actuation and scanning laser Doppler vibrometer for wavefield sensing, is presented for typical composite defect and damage inspection and evaluation. Two composite panels with different geometry (flat or curved) and with various embedded defects (wrinkle and delamination) are inspected using the nonintrusive Lamb wave system. Both the wrinkles and delamination are detected from the wavefield and approximately quantified through wavefield imaging methods.

Wrinkles

Methodology for Physics and Engineering of Reliable Products

Physics of failure approaches have gained wide spread acceptance within the electronic reliability community. These methodologies involve identifying root cause failure mechanisms, developing associated models, and utilizing these models to inprove time to market, lower development and build costs and higher reliability. The methodology outlined herein sets forth a process, based on integration of both physics and engineering principles, for achieving the same goals.

failure analysis electronics reliability PACT (pre

Independent Orbiter Assessment (IOA): Analysis of the purge, vent and drain subsystem

The results of the Independent Orbiter Assessment (IOA) of the Failure Modes and Effects Analysis (FMEA) and Critical Items List (CIL) are presented. The IOA approach features a top-down analysis of the hardware to determine failure modes, criticality, and potential critical items. To preserve independence, this analysis was accomplished without reliance upon the results contained within the NASA FMEA/CIL documentation. This report documents the independent analysis results corresponding to the Orbiter PV and D (Purge, Vent and Drain) Subsystem hardware. The PV and D Subsystem controls the environment of unpressurized compartments and window cavities, senses hazardous gases, and purges Orbiter/ET Disconnect. The subsystem is divided into six systems: Purge System (controls the environment of unpressurized structural compartments); Vent System (controls the pressure of unpressurized compartments); Drain System (removes water from unpressurized compartments); Hazardous Gas Detection System (HGDS) (monitors hazardous gas concentrations); Window Cavity Conditioning System (WCCS) (maintains clear windows and provides pressure control of the window cavities); and External Tank/Orbiter Disconnect Purge System (prevents cryo-pumping/icing of disconnect hardware). Each level of hardware was evaluated and analyzed for possible failure modes and effects. Criticality was assigned based upon the severity of the effect for each failure mode. Four of the sixty-two failure modes analyzed were determined as single failures which could result in the loss of crew or vehicle. A possible loss of mission could result if any of twelve single failures occurred. Two of the criticality 1/1 failures are in the Window Cavity Conditioning System (WCCS) outer window cavity, where leakage and/or restricted flow will cause failure to depressurize/repressurize the window cavity. Two criticality 1/1 failures represent leakage and/or restricted flow in the Orbiter/ET disconnect purge network which prevent cryopumping/icing of disconnect hardware. Each level of hardware was evaluated and analyzed for possible failure modes and effects. Criticality was assigned based upon the severity of the effect for each failure mode.

Bynum, M. C., III

Rock failure analysis by combined thermal weakening and water jet impact

The influence of preheating on the initiation of fracture in rocks subjected to the impingement of a continuous water jet is studied. Preheating the rock is assumed to degrade its mechanical properties and strength in accordance with existing experimental data. The water jet is assumed to place a quasi-static loading on the surface of the rock. The loading is approximated by elementary functions which permit analytic computation of the induced stresses in a rock half-space. The resulting stresses are subsequently coupled with the Griffith criteria for tensile failure to estimate the change, due to heating, in the critical stagnation pressure and velocity of the water jet required to cause failure in the rock.

Nayfeh, A. H.

Progressive Failure Analysis Methodology for Laminated Composite Structures

A progressive failure analysis method has been developed for predicting the failure of laminated composite structures under geometrically nonlinear deformations. The progressive failure analysis uses C(exp 1) shell elements based on classical lamination theory to calculate the in-plane stresses. Several failure criteria, including the maximum strain criterion, Hashin's criterion, and Christensen's criterion, are used to predict the failure mechanisms and several options are available to degrade the material properties after failures. The progressive failure analysis method is implemented in the COMET finite element analysis code and can predict the damage and response of laminated composite structures from initial loading to final failure. The different failure criteria and material degradation methods are compared and assessed by performing analyses of several laminated composite structures. Results from the progressive failure method indicate good correlation with the existing test data except in structural applications where interlaminar stresses are important which may cause failure mechanisms such as debonding or delaminations.

Sleight, David W.

Reliability Growth in Space Life Support Systems

A hardware system's failure rate often increases over time due to wear and aging, but not always. Some systems instead show reliability growth, a decreasing failure rate with time, due to effective failure analysis and remedial hardware upgrades. Reliability grows when failure causes are removed by improved design. A mathematical reliability growth model allows the reliability growth rate to be computed from the failure data. The space shuttle was extensively maintained, refurbished, and upgraded after each flight and it experienced significant reliability growth during its operational life. In contrast, the International Space Station (ISS) is much more difficult to maintain and upgrade and its failure rate has been constant over time. The ISS Carbon Dioxide Removal Assembly (CDRA) reliability has slightly decreased. Failures on ISS and with the ISS CDRA continue to be a challenge.

life support

Practical Application of PRA as an Integrated Design Tool for Space Systems

This paper presents the application of the first comprehensive Probabilistic Risk Assessment (PRA) during the design phase of a joint NASA/NOAA weather satellite program, Geostationary Operational Environmental Satellite Series R (GOES-R). GOES-R is the next generation weather satellite primarily to help understand the weather and help save human lives. PRA has been used at NASA for Human Space Flight for many years. PRA was initially adopted and implemented in the operational phase of manned space flight programs and more recently for the next generation human space systems. Since its first use at NASA, PRA has become recognized throughout the Agency as a method of assessing complex mission risks as part of an overall approach to assuring safety and mission success throughout project lifecycles. PRA is now included as a requirement during the design phase of both NASA next generation manned space vehicles as well as for high priority robotic missions. The influence of PRA on GOES-R design and operation concepts are discussed in detail. The GOES-R PRA is unique at NASA for its early implementation. It also represents a pioneering effort to integrate risks from both Spacecraft (SC) and Ground Segment (GS) to fully assess the probability of achieving mission objectives. PRA analysts were actively involved in system engineering and design engineering to ensure that a comprehensive set of technical risks were correctly identified and properly understood from a design and operations perspective. The analysis included an assessment of SC hardware and software, SC fault management system, GS hardware and software, common cause failures, human error, natural hazards, solar weather and infrastructure (such as network and telecommunications failures, fire). PRA findings directly resulted in design changes to reduce SC risk from micro-meteoroids. PRA results also led to design changes in several SC subsystems, e.g. propulsion, guidance, navigation and control (GNC), communications, mechanisms, and command and data handling (C&DH). The fault tree approach assisted in the development of the fault management system design. Human error analysis, which examined human response to failure, indicated areas where automation could reduce the overall probability of gaps in operation by half. In addition, the PRA brought to light many potential root causes of system disruptions, including earthquakes, inclement weather, solar storms, blackouts and other extreme conditions not considered in the typical reliability and availability analyses. Ultimately the PRA served to identify potential failures that, when mitigated, resulted in a more robust design, as well as to influence the program's concept of operations. The early and active integration of PRA with system and design engineering provided a well-managed approach for risk assessment that increased reliability and availability, optimized lifecyc1e costs, and unified the SC and GS developments.

Kalia, Prince

Heroic Reliability Improvement in Manned Space Systems

System reliability can be significantly improved by a strong continued effort to identify and remove all the causes of actual failures. Newly designed systems often have unexpected high failure rates which can be reduced by successive design improvements until the final operational system has an acceptable failure rate. There are many causes of failures and many ways to remove them. New systems may have poor specifications, design errors, or mistaken operations concepts. Correcting unexpected problems as they occur can produce large early gains in reliability. Improved technology in materials, components, and design approaches can increase reliability. The reliability growth is achieved by repeatedly operating the system until it fails, identifying the failure cause, and fixing the problem. The failure rate reduction that can be obtained depends on the number and the failure rates of the correctable failures. Under the strong assumption that the failure causes can be removed, the decline in overall failure rate can be predicted. If a failure occurs at the rate of lambda per unit time, the expected time before the failure occurs and can be corrected is 1/lambda, the Mean Time Before Failure (MTBF). Finding and fixing a less frequent failure with the rate of lambda/2 per unit time requires twice as long, time of 1/(2 lambda). Cutting the failure rate in half requires doubling the test and redesign time and finding and eliminating the failure causes.Reducing the failure rate significantly requires a heroic reliability improvement effort.

life support

Bayesian And Human Reliability Analysis (hra)-aided Method For The Reliability Analysis Of Software (bahamas)

The purpose of the BAHAMAS code is to provide a simplified process for performing quantitative evaluations of software reliability. The Bayesian and Human Reliability Analysis (HRA)-Aided method for the Reliability Analysis of software (BAHAMAS) was developed specifically to perform quantification under limited data conditions, i.e., when limited testing or operational data are available, such as during early development stages. BAHAMAS essentially examines the quality of a software development life cycle to determine the probability of specific types of software failure. BAHAMAS will have modules to support user input for detailed and simplified analyses. The user interface will also support software common cause failure analysis.

Wang, Congjian (0000000207789927)

Experimental stress analysis of large plastic deformations in a hollow sphere deformed by impact against a concrete block

An experimental plastic strain measurement system is presented for use on the surface of high velocity impact test models. The system was used on a hollow sphere tested in impact against a reinforced concrete block. True strains, deviatoric stresses, and true stresses were calculated from experimental measurements. The maximum strain measured in the model was small compared to the true failure strain obtained from static tensile tests of model material. This fact suggests that a much greater impact velocity would be required to cause failure of the model shell structure.

Morris, R. E.

ISS Fiber Optic Failure Investigation Root Cause Report

In August of 1999, Boeing Corporation (Boeing) engineers began investigating failures of optical fiber being used on International Space Station flight hardware. Catastrophic failures of the fiber were linked to a defect in the glass fiber. Following several meetings of Boeing and NASA engineers and managers, Boeing created and led an investigation team, which examined the reliability of the cable installed in the U.S. Lab. NASA Goddard Space Flight Center's Components Technologies and Radiation Effects Branch (GSFC) led a team investigating the root cause of the failures. Information was gathered from: regular telecons and other communications with the investigation team, investigative trips to the cable distributor's plant, the cable manufacturing plant and the fiber manufacturing plant (including a review of build records), destructive and non-destructive testing, and expertise supplied by scientists from Dupont, and Lucent-Bell Laboratories. Several theories were established early on which were not able to completely address the destructive physical analysis and experiential evidence. Lucent suggested hydrofluoric acid (HF) etching of the glass and successfully duplicated the "rocket engine" defect. Strength testing coupled with examination of the low strength break sites linked features in the polyimide coating with latent defect sites. The information provided below explains what was learned about the susceptibility of the pre-cabled fiber to failure when cabled as it was for Space Station and the nature of the latent defects.

Leidecker, Henning