Search NASA⌕ Search

SEARCH · Search NASA

Results for “Flight Failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Flight test results of a vector-based failure detection and isolation algorithm for a redundant strapdown inertial measurement unit

Flight test results of a vector-based fault-tolerant algorithm for a redundant strapdown inertial measurement unit are presented. Because the inertial sensors provide flight-critical information for flight control and navigation, failure detection and isolation is developed in terms of a multi-level structure. Threshold compensation techniques for gyros and accelerometers, developed to enhance the sensitivity of the failure detection process to low-level failures, are presented. Four flight tests, conducted in a commercial transport type environment, were used to determine the ability of the failure detection and isolation algorithm to detect failure signals, such a hard-over, null, or bias shifts. The algorithm provided timely detection and correct isolation of flight control- and low-level failures. The flight tests of the vector-based algorithm demonstrated its capability to provide false alarm free dual fail-operational performance for the skewed array of inertial sensors.

Morrell, F. R.↗

James Webb Space Telescope (JWST) Integrated Science Instruments Module (ISIM) Electronics Compartment (IEC) Conformal Shields Composite Bond Structure Qualification Test Method

The JWST IEC conformal shields are mounted onto a composite frame structure that must undergo qualification testing to satisfy mission assurance requirements. The composite frame segments are bonded together at the joints using epoxy, EA 9394. The development of a test method to verify the integrity of the bonded structure at its operating environment introduces challenges in terms of requirements definition and the attainment of success criteria. Even though protoflight thermal requirements were not achieved, the first attempt in exposing the structure to cryogenic operating conditions in a thermal vacuum environment resulted in approximately 1 bonded joints failure during mechanical pull tests performed at 1.25 times the flight loads. Failure analysis concluded that the failure mode was due to adhesive cracks that formed and propagated along stress concentrated fillets as a result of poor bond squeeze-out control during fabrication. Bond repairs were made and the structures successfully re-tested with an improved LN2 immersion test method to achieve protoflight thermal requirements.

Thermal Vacuum Testing Chamber↗

Aircraft Engine Run-To-Failure Data Set Under Real Flight Conditions

The generation of data-driven prognostics models requires the availability of datasets with run-to-failure trajectories. In order to contribute to the development of these methods, the dataset provides a new realistic dataset of run-to-failure trajectories for a small fleet of aircraft engines under realistic flight conditions. The damage propagation modelling used for the generation of this synthetic dataset builds on the modelling strategy from previous work [1] and incorporates two new levels of fidelity. First, it considers real flight conditions as recorded on board of a commercial jet [2]. Secondly, it extends the degradation modelling by relating the degradation process to the operation history. The dataset was generated with the Commercial Modular Aero-Propulsion System Simulation (C-MAPSS) dynamical model [3]. More details about the generation process can be found in [4].

CMAPSS↗

Test Facility Simulation Results for Aerospace Loss-of-Lubrication of Spur Gears

Prior to receiving airworthiness certification, extensive testing is required during the development of rotary wing aircraft drive systems. Many of these tests are conducted to demonstrate the drive system's ability to operate at extreme conditions, beyond that called for in the normal to maximum power operating range. One of the most extreme tests is referred to as the loss-of-lubrication or run dry test. During this test, the drive system is expected to last at least 30 min without failure while the primary lubrication system is disabled for predetermined, scripted flight conditions. Failure of this test can lead to a partial redesign of the drive system or the addition of an emergency lubrication system. Either of these solutions can greatly increase the aircraft drive system cost and weight and extend the schedule for obtaining airworthiness certification. Recent work at NASA Glenn Research Center focused on performing tests, in a relevant aerospace environment, to simulate the behavior of spur gears under loss-of-lubrication conditions. Tests were conducted using a test facility that was used in the past for spur gear contact fatigue testing. A loss-oflubrication test is initiated by shutting off the single into mesh lubricating jet. The test proceeds until the gears fail and can no longer deliver the applied torque. The observed failures are typically plastically deformed gear teeth, due to the high tooth temperatures, that are no longer in mesh. The effect of several different variables to gear tooth condition during loss-of-lubrication have been tested such as gear pitch, materials, shrouding, lubrication condition, and emergency supplied mist lubrication in earlier testing at NASA. Recent testing has focused on newer aerospace gear steels and imbedding thermocouples in the shrouding to measure the air-oil temperatures flung off the gear teeth. Along with the instrumented shrouding, an instrumented spur gear was also tested. The instrumented spur gear had five thermocouples installed at different locations on the gear tooth and web. The data from these two types of measurements provided important information as to the thermal environment during the loss-of-lubrication event. This data is necessary to validate on-going modeling efforts.

Gears↗

The evaluation of failure detection and isolation algorithms for restructurable control

Three failure detection and identification techniques were compared to determine their usefulness in detecting and isolating failures in an aircraft flight control system; excluding sensor and flight control computer failures. The algorithms considered were the detection filter, the Generalized Likelihood Ratio test and the Orthogonal Series Generalized Likelihood Ratio test. A modification to the basic detection filter is also considered which uses secondary filtering of the residuals to produce unidirectional failure signals. The algorithms were evaluated by testing their ability to detect and isolate control surface failures in a nonlinear simulation of a C-130 aircraft. It was found that failures of some aircraft controls are difficult to distinguish because they have a similar effect on the dynamics of the vehicle. Quantitative measures for evaluating the distinguishability of failures are considered. A system monitoring strategy for implementing the failure detection and identification techniques was considered. This strategy identified the mix of direct measurement of failures versus the computation of failure necessary for implementation of the technology in an aircraft system.

Motyka, P.↗

Quality Issues in Propulsion

Propulsion system quality is defined in this paper as having high reliability, that is, quality is a high probability of within-tolerance performance or operation. Since failures are out-of-tolerance performance, the probability of failures and their occurrence is the difference between high and low quality systems. Failures can be described at 3 levels: the system failure (which is the detectable end of a failure), the failure mode (which is the failure process), and the failure cause (which is the start). Failure causes can be evaluated & classified by type. The results of typing flight history failures shows that most failures are in unrecognized modes and result from human error or noise, i.e. failures are when engineers learn how things really work. Although the study based on US launch vehicles, a sampling of failures from other countries indicates the finding has broad application. The parameters of the design of a propulsion system are not single valued, but have dispersions associated with the manufacturing of parts. Many tests are needed to find failures, if the dispersions are large relative to tolerances, which could contribute to the large number of failures in unrecognized modes.

McCarty, John P.↗

Cause and Effects of Fluorocarbon Degradation in Electronics and Opto-Electronic Systems

Trace degradation of fluorocarbon or halocarbon materials must be addressed in their application in sensitive systems. As the dimensions and/or tolerances of components in a system decrease, the sensitivity of the system to trace fluorocarbon or halocarbon degradation products increases. Trace quantities of highly reactive degradation products from fluorocarbons have caused a number of failures of flight hardware. It is of utmost importance that the risk of system failure, resulting from trace amounts of reactive fluorocarbon degradation products be addressed in designs containing fluorocarbon or halocarbon materials. Thermal, electrical, and mechanical energy input into the system can multiply the risk of failure.

Predmore, Roamer E.↗

Failure detection and isolation investigation for strapdown skew redundant tetrad laser gyro inertial sensor arrays

The degree to which flight-critical failures in a strapdown laser gyro tetrad sensor assembly can be isolated in short-haul aircraft after a failure occurrence has been detected by the skewed sensor failure-detection voting logic is investigated along with the degree to which a failure in the tetrad computer can be detected and isolated at the computer level, assuming a dual-redundant computer configuration. The tetrad system was mechanized with two two-axis inertial navigation channels (INCs), each containing two gyro/accelerometer axes, computer, control circuitry, and input/output circuitry. Gyro/accelerometer data is crossfed between the two INCs to enable each computer to independently perform the navigation task. Computer calculations are synchronized between the computers so that calculated quantities are identical and may be compared. Fail-safe performance (identification of the first failure) is accomplished with a probability approaching 100 percent of the time, while fail-operational performance (identification and isolation of the first failure) is achieved 93 to 96 percent of the time.

Eberlein, A. J.↗

Techniques for Improving Pilot Recovery from System Failures

This project examined the application of intelligent cockpit systems to aid air transport pilots at the tasks of reacting to in-flight system failures and of planning and then following a safe four dimensional trajectory to the runway threshold during emergencies. Two studies were conducted. The first examined pilot performance with a prototype awareness/alerting system in reacting to on-board system failures. In a full-motion, high-fidelity simulator, Army helicopter pilots were asked to fly a mission during which, without warning or briefing, 14 different failures were triggered at random times. Results suggest that the amount of information pilots require from such diagnostic systems is strongly dependent on their training; for failures they are commonly trained to react to with a procedural response, they needed only an indication of which failure to follow, while for 'un-trained' failures, they benefited from more intelligent and informative systems. Pilots were also found to over-rely on the system in conditions were it provided false or mis-leading information. In the second study, a proof-of-concept system was designed suitable for helping pilots replan their flights in emergency situations for quick, safe trajectory generation. This system is described in this report, including: the use of embedded fast-time simulation to predict the trajectory defined by a series of discrete actions; the models of aircraft and pilot dynamics required by the system; and the pilot interface. Then, results of a flight simulator evaluation with airline pilots are detailed. In 6 of 72 simulator runs, pilots were not able to establish a stable flight path on localizer and glideslope, suggesting a need for cockpit aids. However, results also suggest that, to be operationally feasible, such an aid must be capable of suggesting safe trajectories to the pilot; an aid that only verified plans entered by the pilot was found to have significantly detrimental effects on performance and pilot workload. Results also highlight that the trajectories suggested by the aid must capture the context of the emergency; for example, in some emergencies pilots were willing to violate flight envelope limits to reduce time in flight - in other emergencies the opposite was found.

Pritchett, Amy R.↗

Preliminary system design study for a digital fly-by-wire flight control system for an F-8C aircraft

The design of a fly-by-wire control system having a mission failure probability of less than one millionth failures per flight hour is examined. Emphasis was placed on developing actuator configurations that would improve the system performance, and consideration of the practical aspects of sensor/computer and computer/actuator interface implementation. Five basic configurations were defined as appropriate candidates for the F-8C research aircraft. Options on the basic configurations were included to cover variations in flight sensors, redundancy levels, data transmission techniques, processor input/output methods, and servo actuator arrangements. The study results can be applied to fly by wire systems for transport aircraft in general and the space shuttle.

Seacord, C. L.↗

A combined Eulerian-Lagrangian two-phase flow analysis of SSME HPOTP nozzle plug trajectories. II - Results

An analysis of Space Shuttle Main Engine high-pressure oxygen turbopump nozzle plug trajectories has been performed, using a Lagrangian method to track nozzle plug particles expelled from a turbine through a high Reynolds number flow in a turnaround duct with turning vanes. Axisymmetric and parametric analyses reveal that if nozzle plugs exited the turbine they would probably impact the LOX heat exchanger with impact velocities which are significantly less than the penetration velocity. The finding that only slight to moderate damage will result from nozzle plug failure in flight is supported by the results of a hot-fire engine test with induced nozzle plug failures.

Mcconnaughey, P. K.↗

STS-51 pad abort. OV103-engine 2033 (ME-2) fuel flowmeter sensor open circuit

The STS-51 initial launch attempt of Discovery (OV-103) was terminated on KSC launch pad 39B on 12 Aug. 1993 at 9:12 AM E.S.T. due to a sensor redundancy failure in the liquid hydrogen system of ME-2 (Engine 2033). The event description and time line are summarized. Propellant loading was initiated on 12 Aug. 1993 at 12:00 AM EST. All space shuttle main engine (SSME) chill parameters and Launch Commit Criteria (LCC) were nominal. At engine start plus 1.34 seconds a Failure Identification (FID) was posted against Engine 2033 for exceeding the 1800 spin intra-channel (A1-A2) Fuel Flowrate sensor channel qualification limit. The engine was shut down at 1.50 seconds followed by Engines 2032 and 2030. All shut down sequences were nominal and the mission was safely aborted. SSME Avionics hardware and software performed nominally during the incident. A review of vehicle data table (VDT) data and controller software logic revealed no failure indications other than the single FID 111-101, Fuel Flowrate Intra-Channel Test Channel A disqualification. Software logic was executed according to requirements and there was no anomalous controller software operation. Immediately following the abort, a Rocketdyne/NASA failure investigation team was assembled. The team successfully isolated the failure cause to an open circuit in a Fuel Flowrate Sensor. This type of failure has occurred eight previous times in ground testing. The sensor had performed acceptably on three previous flights of the engine and SSME flight history shows 684 combined fuel flow rate sensor channel flights without failure. The disqualification of an Engine 2 (SSME No. 2033) Fuel Flowrate sensor channel was a result of an instrumentation failure and not engine performance. All other engine operations were nominal. This disqualification resulted in an engine shutdown and safe sequential shutdown of all three engines prior to ignition of the solid boosters.

Source record↗

Reliability and Safety Assessment of Urban Air Mobility Concept Vehicles

The following work was commissioned by the National Aeronautics and Space Administration (NASA) to guide industry and future regulation related to urban air mobility (UAM). Prior studies compared the relative safety of NASA concept vehicles, Figure ES1, designed for UAM and provided recommendations for industry research, aircraft architectural improvements, and regulatory updates. After the prior study completed, the European Aviation Safety Agency (EASA) released regulatory guidance in the form of a special condition (SC), SC-VTOL-01, for multirotors with distributed propulsion and flight controls (DPFC). The objective of the current work was to develop DPFC architectures that will comply with SC-VTOL-01. Vehicle designs, DPFC architectures, and stability & control (S&C) models were developed to find limitations and trends to guide industry. To guide this task, NASA developed quad, hex, and an octorotor to better define vehicle attributes and trade space. Aircraft for study included electric, hybrid-electric, and turboshaft powerplants and collective and RPM control schemes. Assessments are in terms of the safety level achieved, and/or aircraft component/features needed to meet SC-VTOL-01. The most challenging criteria being the catastrophic failure rate, ≤10-9 catastrophic failures per flight hour, and that no single failures may result in a catastrophic event. A disciplined process was followed, similar to that in Aerospace Recommended Practice (ARP) 4761. A preliminary system safety assessment (PSSA) leveraged prior work as a basis of creating failure rate budgets for system design teams. System designs were updated and iterated upon, working with reliability and safety subject matter experts to develop SC-VTOL-01 compliant designs. Design changes were reflected in updated PSSAs for initial verification of compliance. The DPFC architecture was broken into four system design teams, the (1) flight control system (FCS), (2) drive and power system, (3) thermal management system (TMS), and (4) electrical power and distribution system. The FCS including elements necessary to control the aircraft, drive and power including elements necessary to generate and transmit shaft power, the TMS including elements necessary to maintain temperature limits in all operating environments, and electrical pow-er and distribution including equipment necessary to store and transmit electrical energy. Results found that all aircraft evaluated may have paths to comply with SC-VTOL-01, Figure ES2. However, S&C models showed large power transients that must be addressed and PSSA results show that future work is needed in single load path structures, high voltage power storage and distribution, and in motor/rotor overspeed protection.

Boeing↗

Analysis of the Spread Across Liquid-5 (SAL-5) Experiment Failure to Fill Properly During Flight

When a pool of flammable liquid is ignited, the flame spread rate can vary widely depending on the initial fuel temperature, pool geometry, ambient atmospheric conditions, and gravitational level. There is substantial decades-old debate in the scientific literature about the role of gravity in these phenomena. The objective of the research was to measure ignition and flame spread across liquid pools in both normal and microgravity with and without forced airflow, and to obtain detailed thermal and velocity field data for comparison to a predictive numerical model that is concurrently being developed. To that end, an experiment known as Spread Across Liquids 5 (SAL 5) was designed to be conducted in a low-gravity environment on a sounding rocket. Unfortunately, during the sounding rocket flight the fuel tray for the experiment failed to fill properly prior to ignition. The primary cause of the failure to fill properly is the geometry of the fuel tray; that is, the presence of the gaps on the side walls and the sharp edge around the thermocouple through-holes. The contamination resulting from the cleaning process is a strong secondary factor which would have prevented proper, timely filling had the primary cause not been present.

Allen, Jeffrey Stuart↗

Robust Platinum Resistor Thermometer (PRT) Sensors and Reliable Bonding for Space Missions

Platinum resistance thermometers (PRTs) provide accurate temperature measurements over a wide temperature range and are used extensively on space missions due to their simplicity and linearity. A standard on spacecraft, PRTs are used to provide precision temperature control and vehicle health assessment. This paper reviews the extensive reliability testing of platinum resistor thermometer sensors (PRTs) and bonding methods used on the Mars Science Laboratory (MSL) mission and for the upcoming Soil Moisture Active Passive (SMAP) mission. During the Mars Exploration Rover (MER) mission, several key, JPL-packaged PRTs failed on those rovers prior to and within 1-Sol of landing due to thermally induced stresses. Similar failures can be traced back to other JPL missions dating back thirty years. As a result, MSL sought out a PRT more forgiving to the packaging configurations used at JPL, and extensively tested the Honeywell HRTS-5760-B-U-0-12 sensor to successfully demonstrate suitable robustness to thermal cycling. Specifically, this PRT was cycled 2,000 times, simulating three Martian winters and summers. The PRTs were bonded to six substrate materials (Aluminum 7050, treated Magnesium AZ231-B, Stainless Steel 304, Albemet, Titanium 6AL4V, and G-10), using four different aerospace adhesives--two epoxies and two silicones--that conformed to MSL's low out-gassing requirements. An additional epoxy was tested in a shorter environmental cycling test, when the need for a different temperature range adhesive was necessary for mobility and actuator hardware late in the fabrication process. All of this testing, along with electrostatic discharge (ESD) and destructive part analyses, demonstrate that this PRT is highly robust, and not subject to the failure of PRTs on previous missions. While there were two PRTs that failed during fabrication, to date there have been no in-flight PRT failures on MSL, including those on the Curiosity rover. Since MSL, the sensor has gone through a change in construction such that the manufacturer significantly restricts the minimum temperature. However, significant subsequent testing was performed with this new version of the part to show that it indeed is still robust to at least Mars minimum temperatures of -135(sup o)C. The additional completed testing will be described. This work has resulted in a successful sensor package qualification and a reliable bonding method suitable for use over large temperature extremes.

dectector↗

Robust Platinum Resistor Thermometer (PRT) Sensors and Reliable Bonding for Space Missions

Platinum resistance thermometers (PRTs) provide accurate temperature measurements over a wide temperature range and are used extensively on space missions due to their simplicity and linearity. A standard on spacecraft, PRTs are used to provide precision temperature control and vehicle health assessment. This paper reviews the extensive reliability testing of platinum resistor thermometer sensors (PRTs) and bonding methods used on the Mars Science Laboratory (MSL) mission and for the upcoming Soil Moisture Active Passive (SMAP) mission. During the Mars Exploration Rover (MER) mission, several key, JPL-packaged PRTs failed on those rovers prior to and within 1-Sol of landing due to thermally induced stresses. Similar failures can be traced back to other JPL missions dating back thirty years. As a result, MSL sought out a PRT more forgiving to the packaging configurations used at JPL, and extensively tested the Honeywell HRTS-5760-B-U-0-12 sensor to successfully demonstrate suitable robustness to thermal cycling. Specifically, this PRT was cycled 2,000 times, simulating three Martian winters and summers. The PRTs were bonded to six substrate materials (Aluminum 7050, treated Magnesium AZ231-B, Stainless Steel 304, Albemet, Titanium 6AL4V, and G-10), using four different aerospace adhesives--two epoxies and two silicones--that conformed to MSL's low out-gassing requirements. An additional epoxy was tested in a shorter environmental cycling test, when the need for a different temperature range adhesive was necessary for mobility and actuator hardware late in the fabrication process. All of this testing, along with electrostatic discharge (ESD) and destructive part analyses, demonstrate that this PRT is highly robust, and not subject to the failure of PRTs on previous missions. While there were two PRTs that failed during fabrication, to date there have been no in-flight PRT failures on MSL, including those on the Curiosity rover. Since MSL, the sensor has gone through a change in construction such that the manufacturer significantly restricts the minimum temperature. However, significant subsequent testing was performed with this new version of the part to show that it indeed is still robust to at least Mars minimum temperatures of -135 degrees Centigrade. The additional completed testing will be described. This work has resulted in a successful sensor package qualification and a reliable bonding method suitable for use over large temperature extremes

Platinum Resistor Thermometer (PRT)↗

Adaptive Control Allocation for Powered Descent Vehicles

The following work details a study into real-time failure adaptive control allocation method for powered descent vehicle systems. The motivation for this work is to enable future human and robotic missions utilizing a powered descent system to tolerate engine failures in flight without the loss of crew or assets. This study is conducted using a six degree-of-freedom trajectory simulation of a PDV (Powered Descent Vehicle) experiencing either a loss of thrust or an engine stuck full on failure scenario. Sequential least squares in the frequency domain is used on-board to process inertial measurement unit (IMU) data and generate an estimate of the PDV plant model, which is then fed to the guidance and control system. Data used by the sequential least squares method is generated from an in-flight maneuver. The work herein focuses on determining a maneuver that is least impactful to the PDV trajectory and enables a suitable plant model estimate. A 1.5-second-long maneuver with an amplitude of 5 percent throttle is determined to provide suitable data for the sequential least squares method to estimate a plant model. A PDV implementing this method can adapt to a single engine failure and continue to reach its touchdown conditions.

Green, Justin S.↗

Lessons Learned from the Space Shuttle Engine Hydrogen Flow Control Valve Poppet Breakage

The Main Propulsion System (MPS) uses three Flow Control Valves (FCV) to modulate the flow of pressurant hydrogen gas from the Space Shuttle Main Engines (SSME) to the hydrogen External Tank (ET). This maintains pressure in the ullage volume as the liquid level drops, preserving ET structural integrity and assuring the engines receive a sufficient amount of head pressure. On Space Transportation System (STS)-126 (2009), with only a handful of International Space Station (ISS) assembly flights from the end of the Shuttle program, a portion of a single FCV?s poppet head broke off at about a minute and a half after liftoff. The risk of the poppet head failure is that the increased flow area through the FCV could result in excessive gaseous hydrogen flow back to the external tank, which could result in overboard venting of hydrogen ullage pressure. If the hydrogen venting were to occur in first stage (i.e., lower atmosphere), a flammability hazard exists that could lead to catastrophic loss of crew and vehicle. Other failure risks included particle impact damage to MPS downstream hardware. Although the FCV design had been plagued by contamination-related sluggish valve response problems prior to a redesign at STS-80 (1996), contamination was ruled out as the cause of the STS-126 failure. Employing a combination of enhanced hardware inspection and a better understanding of the consequences of a poppet failure, safe flight rationale for subsequent flights (STS-119 and later) was achieved. This paper deals with the technical lessons learned during the investigation and mitigation of this problem at a time when assembly flights were each in the critical path to Space Station success.

Martinez, Hugo E.↗