Search NASA⌕ Search

SEARCH · Search NASA

Results for “SYSTEM FAILURE”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Development and Flight Evaluation of an Emergency Digital Flight Control System Using Only Engine Thrust on an F-15 Airplane

A propulsion-controlled aircraft (PCA) system for emergency flight control of aircraft with no flight controls was developed and flight tested on an F-15 aircraft at the NASA Dryden Flight Research Center. The airplane has been flown in a throttles-only manual mode and with an augmented system called PCA in which pilot thumbwheel commands and aircraft feedback parameters were used to drive the throttles. Results from a 36-flight evaluation showed that the PCA system can be used to safety land an airplane that has suffered a major flight control system failure. The PCA system was used to recover from a severe upset condition, descend, and land. Guest pilots have also evaluated the PCA system. This paper describes the principles of throttles-only flight control; a history of loss-of-control accidents; a description of the F-15 aircraft; the PCA system operation, simulation, and flight testing; and the pilot comments.

Burcham, Frank W., Jr.↗

Beyond the sterile cockpit

Consideration is given to some of the negative aspects of the trend toward increased automation of aircraft flight decks. The history of automated devices for navigation, communications and detection on board aircraft is reviewed. Instances of automatic system failure are identified which have led to accidents, and the events surrounding the downing of Korean Airlines Flight 747 are reexamined within the context of a computer-based system failure. Finally, new software and interactive systems to reduce navigational error due to inadequate computer-assisted flight instruction (CAI) are described, with emphasis given to speech processing and intelligent CAI systems.

Wiener, E. L.↗

Supportability Concepts for Crewed Deep Space Exploration

Supportability—defined as the set of system characteristics that influence the logistics and support required to enable safe and effective operations—will be a much larger driver of mass, risk, and crew time for future human space exploration due to the more challenging mission context. For Mars, systems must operate in a logistically isolated environment for much longer durations than previous missions, which results in a higher probability of system failure and therefore an increased need for maintenance or contingency options. Mars missions also lack access to quick aborts, which increases the consequences of an unrecoverable system failure. Together, this higher likelihood and consequence of failure results in an increase in supportability-related risk. Supportability analysis is an important part of systems development that helps designers better understand the impacts of system and mission decisions on risk, mass, and crew time. The real-world processes that drive maintenance requirements and other supportability-related characteristics are probabilistic, and therefore they require different conceptual approaches and models than are used for more deterministic aspects of space systems. This paper provides an overview of supportability analysis, addresses key concepts, and provides examples of how supportability analysis can be incorporated into system development. Specifically, system supportability involves stochastic processes, and therefore must be evaluated using probabilistic models. These models can be used to perform sensitivity analysis even if system characteristics are not yet fully defined. Failure rates cannot be measured directly, but tests provide valuable data that can help refine those estimates. Human spaceflight architectures are complex, and exhibit coupled behavior that should be examined with integrated systems analysis that includes an assessment of supportability.

Supportability↗

Supportability Concepts for Crewed Deep Space Exploration

Supportability—defined as the set of system characteristics that influence the logistics and support required to enable safe and effective operations—will be a much larger driver of mass, risk, and crew time for future human space exploration due to the more challenging mission context. For Mars, systems must operate in a logistically isolated environment for much longer durations than previous missions, which results in a higher probability of system failure and therefore an increased need for maintenance or contingency options. Mars missions also lack access to quick aborts, which increases the consequences of an unrecoverable system failure. Together, this higher likelihood and consequence of failure results in an increase in supportability-related risk. Supportability analysis is an important part of systems development that helps designers better understand the impacts of system and mission decisions on risk, mass, and crew time. The real-world processes that drive maintenance requirements and other supportability-related characteristics are probabilistic, and therefore they require different conceptual approaches and models than are used for more deterministic aspects of space systems. This paper provides an overview of supportability analysis, addresses key concepts, and provides examples of how supportability analysis can be incorporated into system development. Specifically, system supportability involves stochastic processes, and therefore must be evaluated using probabilistic models. These models can be used to perform sensitivity analysis even if system characteristics are not yet fully defined. Failure rates cannot be measured directly, but tests provide valuable data that can help refine those estimates. Human spaceflight architectures are complex, and exhibit coupled behavior that should be examined with integrated systems analysis that includes an assessment of supportability.

Supportability↗

Extended Testability Analysis Tool

The Extended Testability Analysis (ETA) Tool is a software application that supports fault management (FM) by performing testability analyses on the fault propagation model of a given system. Fault management includes the prevention of faults through robust design margins and quality assurance methods, or the mitigation of system failures. Fault management requires an understanding of the system design and operation, potential failure mechanisms within the system, and the propagation of those potential failures through the system. The purpose of the ETA Tool software is to process the testability analysis results from a commercial software program called TEAMS Designer in order to provide a detailed set of diagnostic assessment reports. The ETA Tool is a command-line process with several user-selectable report output options. The ETA Tool also extends the COTS testability analysis and enables variation studies with sensor sensitivity impacts on system diagnostics and component isolation using a single testability output. The ETA Tool can also provide extended analyses from a single set of testability output files. The following analysis reports are available to the user: (1) the Detectability Report provides a breakdown of how each tested failure mode was detected, (2) the Test Utilization Report identifies all the failure modes that each test detects, (3) the Failure Mode Isolation Report demonstrates the system s ability to discriminate between failure modes, (4) the Component Isolation Report demonstrates the system s ability to discriminate between failure modes relative to the components containing the failure modes, (5) the Sensor Sensor Sensitivity Analysis Report shows the diagnostic impact due to loss of sensor information, and (6) the Effect Mapping Report identifies failure modes that result in specified system-level effects.

Melcher, Kevin↗

Quantifying Pilot Contribution to Flight Safety During Dual Generator Failure

Accident statistics cite flight crew error in over 60% of accidents involving transport category aircraft. Yet, a well-trained and well-qualified pilot is acknowledged as the critical center point of aircraft systems safety and an integral safety component of the entire commercial aviation system. No data currently exists that quantifies the contribution of the flight crew in this role. Neither does data exist for how often the flight crew handles non-normal procedures or system failures on a daily basis in the National Airspace System. A pilot-in-the-loop high fidelity motion simulation study was conducted by the NASA Langley Research Center in partnership with the Federal Aviation Administration (FAA) to evaluate the pilot's contribution to flight safety during normal flight and in response to aircraft system failures. Eighteen crews flew various normal and non-normal procedures over a two-day period and their actions were recorded in response to failures. To quantify the human's contribution, crew complement was used as the experiment independent variable in a between-subjects design. Pilot actions and performance when one of the flight crew was unavailable were also recorded for comparison against the nominal two-crew operations. This paper details diversion decisions, perceived safety of flight, workload, time to complete pertinent checklists, and approach and landing results while dealing with a complete loss of electrical generators. Loss of electrical power requires pilots to complete the flight without automation support of autopilots, flight directors, or auto throttles. For reduced crew complements, the additional workload and perceived safety of flight was considered unacceptable.

Etherington, Timothy J.↗

Reliability analysis of forty-five strain-gage systems mounted on the first fan stage of a YF-100 engine

The reliability of 45 state-of-the-art strain gage systems under full scale engine testing was investigated. The flame spray process was used to install 23 systems on the first fan rotor of a YF-100 engine; the others were epoxy cemented. A total of 56 percent of the systems failed in 11 hours of engine operation. Flame spray system failures were primarily due to high gage resistance, probably caused by high stress levels. Epoxy system failures were principally erosion failures, but only on the concave side of the blade. Lead-wire failures between the blade-to-disk jump and the control room could not be analyzed.

Holanda, R.↗

Failure Behavior and Control Based Mitigation for a Parallel Hybrid Propulsion System

NASA is pursuing research to advance Electrified Aircraft Propulsion (EAP) technologies that address fuel burn and emission reduction goals. EAP brings the potential for improved performance over the state of the art. However, for these systems to be practical and certifiable, they need to possess adequate robustness to adverse conditions including a variety of system failures that are not applicable to conventional turbofans today. Numerous EAP concepts interface gas turbine engines with an electrical power system that includes electric machines and sometimes electrical energy storage. The expansion of the powertrain increases the probability of encountering a failure and introduces new failure modes. Failures within the electrical power system may also impact the gas turbine engine(s) to which the electrical powertrain is coupled. This effort investigates failures originating in the electrical power system and their impact on the parallel hybrid propulsion system. Reversionary control strategies are also demonstrated to reduce the impact of the failures. Failure mitigation strategies were devised and employed in simulation. Various failure scenarios were simulated including those occurring during steady state operation, transients, and takeoff and landing scenarios. The timing of the failure and delay in failure identification and activation of mitigation strategies are noteworthy variables in the study. While the system remained stable throughout all failure scenarios, delays in failure identification could result in undesirable conditions such as increased operating temperatures and reduced stall margin. The results demonstrate successful mitigation of failures through reversionary control modes and help to generate confidence in the robustness of the conceptual parallel hybrid propulsion system.

Failure behavior↗

LDEF electronic systems: Successes, failures and lessons

Following LDEF retrieval, a series of tests were performed of various NASA and experimenter electronics, including the NASA provided data and initiate systems. The post-flight test program objectives and observations are discussed, as well as the 'lessons learned' from these examinations. Results are also included of an evaluation of electronic hardware flown on Boeing's LDEF experiment. Overall the electronic systems performed remarkably well, even though most were developed under budget restraints and used some non-space qualified components. Several anomalies were observed, however, including some which resulted in loss of data. Suggestions for avoiding similar problems on future programs are presented.

Miller, E. A.↗

A New Monte Carlo Filtering Method for the Diagnosis of Mission-Critical Failures

Testing large-scale systems is expensive in terms of both time and money. Running simulations early in the process is a proven method of finding the design faults likely to lead to critical system failures, but determining the exact cause of those errors is still time-consuming and requires access to a limited number of domain experts. It is desirable to find an automated method that explores the large number of combinations and is able to isolate likely fault points. Treatment learning is a subset of minimal contrast-set learning that, rather than classifying data into distinct categories, focuses on finding the unique factors that lead to a particular classification. That is, they find the smallest change to the data that causes the largest change in the class distribution. These treatments, when imposed, are able to identify the settings most likely to cause a mission-critical failure. This research benchmarks two treatment learning methods against standard optimization techniques across three complex systems, including two projects from the Robust Software Engineering (RSE) group within the National Aeronautics and Space Administration (NASA) Ames Research Center. It is shown that these treatment learners are both faster than traditional methods and show demonstrably better results.

Gay, Gregory↗

Design and performance of a no-single-failure control system for the mini-Brayton power conversion system

The control system consists of the ac-dc conversion, voltage regulation, speed regulation through parasitic load control, and overload control. A no-single-failure configuration was developed to attain the required reliability for a 10-year design life of unattended operation. The design principles, complete schematics, and performance are reported. Testing was performed on an alternator simulator pending construction of the actual Mini-Brayton alternator.

Brichenough, A. G.↗

Failure Behavior and Control-Based Mitigation for a Parallel Hybrid Propulsion System

NASA is pursuing research to advance Electrified Aircraft Propulsion (EAP) technologies that address fuel burn and emission reduction goals. EAP brings the potential for improved performance over the state of the art. However, for these systems to be practical and certifiable, they need to possess adequate robustness to adverse conditions including a variety of system failures that are not applicable to conventional turbofans today. Numerous EAP concepts interface gas turbine engines with an electrical power system that includes electric machines and sometimes electrical energy storage. The expansion of the powertrain increases the probability of encountering a failure and introduces new failure modes. Failures within the electrical power system may also impact the gas turbine engine(s) to which the electrical powertrain is coupled. This effort investigates failures originating in the electrical power system and their impact on the parallel hybrid propulsion system. Reversionary control strategies are also demonstrated to reduce the impact of the failures. Failure mitigation strategies were devised and employed in simulation. Various failure scenarios were simulated including those occurring during steady state operation, transients, and takeoff and landing scenarios. The timing of the failure and delay in failure identification and activation of mitigation strategies are noteworthy variables in the study. While the system remained stable throughout all failure scenarios, delays in failure identification could result in undesirable conditions such as increased operating temperatures and reduced stall margin. The results demonstrate successful mitigation of failures through reversionary control modes and help to generate confidence in the robustness of the conceptual parallel hybrid propulsion system.

Failure behavior↗

Spacecraft Escape Capsule

A report discusses the Gumdrop capsule a conceptual spacecraft that would enable the crew to escape safely in the event of a major equipment failure at any time from launch through atmospheric re-entry. The scaleable Gumdrop capsule would comprise a command module (CM), a service module (SM), and a crew escape system (CES). The CM would contain a pressurized crew environment that would include avionic, life-support, thermal control, propulsive attitude control, and recovery systems. The SM would provide the primary propulsion and would also supply electrical power, life-support resources, and active thermal control to the CM. The CES would include a solid rocket motor, embedded within the SM, for pushing the CM away from the SM in the event of a critical thermal-protection-system failure or loss of control. The CM and SM would normally remain integrated with each other from launch through recovery, but could be separated using the CES, if necessary, to enable the safe recovery of the crew in the CM. The crew escape motor could be used, alternatively, as a redundant means of de-orbit propulsion for the CM in the event of a major system failure in the SM.

Robertson, Edward A.↗

Assessing the Relative Risk of Aerocapture Using Probabalistic Risk Assessment

A recent study performed for the Aerocapture Technology Area in the In-Space Propulsion Technology Projects Office at the Marshall Space Flight Center investigated the relative risk of various capture techniques for Mars missions. Aerocapture has been proposed as a possible capture technique for future Mars missions but has been perceived by many in the community as a higher risk option as compared to aerobraking and propulsive capture. By performing a probabilistic risk assessment on aerocapture, aerobraking and propulsive capture, a comparison was made to uncover the projected relative risks of these three maneuvers. For mission planners, this knowledge will allow them to decide if the mass savings provided by aerocapture warrant any incremental risk exposure. The study focuses on a Mars Sample Return mission currently under investigation at the Jet Propulsion Laboratory (JPL). In each case (propulsive, aerobraking and aerocapture), the Earth return vehicle is inserted into Martian orbit by one of the three techniques being investigated. A baseline spacecraft was established through initial sizing exercises performed by JPL's Team X. While Team X design results provided the baseline and common thread between the spacecraft, in each case the Team X results were supplemented by historical data as needed. Propulsion, thermal protection, guidance, navigation and control, software, solar arrays, navigation and targeting and atmospheric prediction were investigated. A qualitative assessment of human reliability was also included. Results show that different risk drivers contribute significantly to each capture technique. For aerocapture, the significant drivers include propulsion system failures and atmospheric prediction errors. Software and guidance hardware contribute the most to aerobraking risk. Propulsive capture risk is mainly driven by anomalous solar array degradation and propulsion system failures. While each subsystem contributes differently to the risk of each technique, results show that there exists little relative difference in the reliability of these capture techniques although uncertainty for the aerocapture estimates remains high given the lack of in-space demonstration.

Percy, Thomas K.↗

A theoretical basis for the analysis of redundant software subject to coincident errors

Fundamental to the development of redundant software techniques fault-tolerant software, is an understanding of the impact of multiple-joint occurrences of coincident errors. A theoretical basis for the study of redundant software is developed which provides a probabilistic framework for empirically evaluating the effectiveness of the general (N-Version) strategy when component versions are subject to coincident errors, and permits an analytical study of the effects of these errors. The basic assumptions of the model are: (1) independently designed software components are chosen in a random sample; and (2) in the user environment, the system is required to execute on a stationary input series. The intensity of coincident errors, has a central role in the model. This function describes the propensity to introduce design faults in such a way that software components fail together when executing in the user environment. The model is used to give conditions under which an N-Version system is a better strategy for reducing system failure probability than relying on a single version of software. A condition which limits the effectiveness of a fault-tolerant strategy is studied, and it is posted whether system failure probability varies monotonically with increasing N or whether an optimal choice of N exists.

Eckhardt, D. E., Jr.↗

Sensory redundancy management: The development of a design methodology for determining threshold values through a statistical analysis of sensor output data

Sensor redundancy management (SRM) requires a system which will detect failures and reconstruct avionics accordingly. A probability density function to determine false alarm rates, using an algorithmic approach was generated. Microcomputer software was developed which will print out tables of values for the cummulative probability of being in the domain of failure; system reliability; and false alarm probability, given a signal is in the domain of failure. The microcomputer software was applied to the sensor output data for various AFT1 F-16 flights and sensor parameters. Practical recommendations for further research were made.

Scalzo, F.↗

Advances in Thrust-Based Emergency Control of an Airplane

Engineers at NASA's Dryden Flight Research Center have received a patent on an emergency flight-control method implemented by a propulsion-controlled aircraft (PCA) system. Utilizing the preexisting auto-throttle and engine-pressure-ratio trim controls of the airplane, the PCA system provides pitch and roll control for landing an airplane safely without using aerodynamic control surfaces that have ceased to function because of a primary-flight-control-system failure. The installation of the PCA does not entail any changes in pre-existing engine hardware or software. [Aspects of the method and system at previous stages of development were reported in Thrust-Control System for Emergency Control of an Airplane (DRC-96-07), NASA Tech Briefs, Vol. 25, No. 3 (March 2001), page 68 and Emergency Landing Using Thrust Control and Shift of Weight (DRC-96-55), NASA Tech Briefs, Vol. 26, No. 5 (May 2002), page 58.]. Aircraft flight-control systems are designed with extensive redundancy to ensure low probabilities of failure. During recent years, however, several airplanes have exhibited major flight-control-system failures, leaving engine thrust as the last mode of flight control. In some of these emergency situations, engine thrusts were successfully modulated by the pilots to maintain flight paths or pitch angles, but in other situations, lateral control was also needed. In the majority of such control-system failures, crashes resulted and over 1,200 people died. The challenge lay in creating a means of sufficient degree of thrust-modulation control to safely fly and land a stricken airplane. A thrust-modulation control system designed for this purpose was flight-tested in a PCA an MD-11 airplane. The results of the flight test showed that without any operational control surfaces, a pilot can land a crippled airplane (U.S. Patent 5,330,131). The installation of the original PCA system entailed modifications not only of the flight-control computer (FCC) of the airplane but also of each engine-control computer. Inasmuch as engine-manufacturer warranties do not apply to modified engines, the challenge became one of creating a PCA system that does not entail modifications of the engine computers.

Creech, Gray↗