Search NASA⌕ Search

SEARCH · Search NASA

Results for “addressing failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Safety Expertise and the Perils of Novelty

Emerging aviation markets such as urban air mobility are giving rise to new technologies and means of operation. However, novelty may hide ‘unknown unknowns,’ raising new hazards. This paper examines how expertise and safety techniques enable transformative technologies such as reduced crew operations, hybrid wing-borne and rotor-born flight, federated air traffic services, and urban operations. We explore how analysts use expertise to address common-cause failures, collect and interpret safety data, and perform exacting tradeoffs between dissimilarity, redundancy, independence, and diversity (human, process lifecycle, or otherwise) to ensure safety. When novelty is present, analysts might not possess the expertise needed to fully understand the implications of design decisions and tradeoffs being made, especially in early lifecycle phases, on emergent properties such as safety. Safety expertise must be carefully cultivated. The conflicting views of safety experts must be unpacked to identify the divergence in fundamental assumptions, models, means, and methods that may be causing them. Once systems venture beyond the basis of what safety expertise can reliably guarantee, projects take on risk that must be managed. The paper contains key takeaways and actionable recommendations for novel OEMs and regulators touching on topics such as robust monitoring; clear and transparent reporting; incremental approaches to fielding novel systems in hazard-rich, risk-tolerant environments; the cultivation of safety culture and expertise in an organization; and the use of scientific study to reduce epistemic uncertainty in novel operations with new technologies. Since excessive novelty in aviation can undermine the current foundation of safety, humility and incrementalism are necessary to enable emerging aviation markets safely.

safety expertise↗

Safety Expertise and the Perils of Novelty

Emerging aviation markets such as urban air mobility are giving rise to new technologies and means of operation. However, novelty may hide ‘unknown unknowns,’ raising new hazards. This paper examines how expertise and safety techniques enable transformative technologies such as reduced crew operations, hybrid wing-borne and rotor-born flight, federated air traffic services, and urban operations. We explore how analysts use expertise to address common-cause failures, collect and interpret safety data, and perform exacting tradeoffs between dissimilarity, redundancy, independence, and diversity (human, process lifecycle, or otherwise) to ensure safety. When novelty is present, analysts might not possess the expertise needed to fully understand the implications of design decisions and tradeoffs being made, especially in early lifecycle phases, on emergent properties such as safety. Safety expertise must be carefully cultivated. The conflicting views of safety experts must be unpacked to identify the divergence in fundamental assumptions, models, means, and methods that may be causing them. Once systems venture beyond the basis of what safety expertise can reliably guarantee, projects take on risk that must be managed. The paper contains key takeaways and actionable recommendations for novel OEMs and regulators touching on topics such as robust monitoring; clear and transparent reporting; incremental approaches to fielding novel systems in hazard-rich, risk-tolerant environments; the cultivation of safety culture and expertise in an organization; and the use of scientific study to reduce epistemic uncertainty in novel operations with new technologies. Since excessive novelty in aviation can undermine the current foundation of safety, humility and incrementalism are necessary to enable emerging aviation markets safely.

safety expertise↗

Model-Biased, Data-Driven Adaptive Failure Prediction

This final report, which contains a research summary and a viewgraph presentation, addresses clustering and data simulation techniques for failure prediction. The researchers applied their techniques to both helicopter gearbox anomaly detection and segmentation of Earth Observing System (EOS) satellite imagery.

Leen, Todd K.↗

Failure recovery control for space robotic systems

The problem of controlling a failed joint of a space manipulator is addressed. It is shown that failure-recovery control is possible when dynamic coupling exists between the link whose joint has failed and some other link whose joint is working and when the system inertia matrix is invariant with respect to the failed joint angle. A failure-recovery control technique is developed and applied to two simple examples.

Papadopoulos, Evangelos↗

Diagnosing faults in autonomous robot plan execution

A major requirement for an autonomous robot is the capability to diagnose faults during plan execution in an uncertain environment. Many diagnostic researches concentrate only on hardware failures within an autonomous robot. Taking a different approach, the implementation of a Telerobot Diagnostic System that addresses, in addition to the hardware failures, failures caused by unexpected event changes in the environment or failures due to plan errors, is described. One feature of the system is the utilization of task-plan knowledge and context information to deduce fault symptoms. This forward deduction provides valuable information on past activities and the current expectations of a robotic event, both of which can guide the plan-execution inference process. The inference process adopts a model-based technique to recreate the plan-execution process and to confirm fault-source hypotheses. This technique allows the system to diagnose multiple faults due to either unexpected plan failures or hardware errors. This research initiates a major effort to investigate relationships between hardware faults and plan errors, relationships which were not addressed in the past. The results of this research will provide a clear understanding of how to generate a better task planner for an autonomous robot and how to recover the robot from faults in a critical environment.

Lam, Raymond K.↗

Diagnosing faults in autonomous robot plan execution

A major requirement for an autonomous robot is the capability to diagnose faults during plan execution in an uncertain environment. Many diagnostic researches concentrate only on hardware failures within an autonomous robot. Taking a different approach, the implementation of a Telerobot Diagnostic System that addresses, in addition to the hardware failures, failures caused by unexpected event changes in the environment or failures due to plan errors, is described. One feature of the system is the utilization of task-plan knowledge and context information to deduce fault symptoms. This forward deduction provides valuable information on past activities and the current expectations of a robotic event, both of which can guide the plan-execution inference process. The inference process adopts a model-based technique to recreate the plan-execution process and to confirm fault-source hypotheses. This technique allows the system to diagnose multiple faults due to either unexpected plan failures or hardware errors. This research initiates a major effort to investigate relationships between hardware faults and plan errors, relationships which were not addressed in the past. The results of this research will provide a clear understanding of how to generate a better task planner for an autonomous robot and how to recover the robot from faults in a critical environment.

Lam, Raymond K.↗

Failure Modes and Mitigation Strategies for a Turboelectric Aircraft Concept with Turbine Electrified Energy Management

The electrification of gas turbine engines represents a major step-change in aircraft propulsion systems commonly known as Electrified Aircraft Propulsion (EAP). EAP involves the integration of electric machines potentially functioning as generators for large scale power extraction, as motors providing electrical augmentation of the engine spools, and even as a means of driving propulsors beyond the immediate scope of the engine. It may also include the use of energy storage. These and other characteristics of hybrid electric propulsion systems are relatively new to aircraft propulsion. The expanded propulsion architecture can be leveraged to improve propulsive efficiency and achieve better vehicle aerodynamics and controllability. It can also allow for additional benefits such as those enabled through Turbine Electrified Energy Management (TEEM). As the propulsion system and its functions expand, new failure modes are introduced. Due to the highly coupled nature of the propulsion system, failures could propagate throughout the system in ways that are unique to the new EAP architectures. To build confidence in the safety and practicality of EAP concepts, these failure modes need to be identified, explored, and addressed through mitigation strategies. This paper seeks to evaluate failure modes and failure mitigation strategies for the EAP concept known as the Single aisle Turboelectric AiRCaft with Aft Boundary Layer propulsor (STARC-ABL). The TEEM control concept is applied to improve transient operability. Several failure modes are considered and control based failure mitigation strategies are proposed with the goal of retaining operability and overall thrust. The results demonstrate the ability to maintain operability and a substantial amount of thrust in the event of various types of failures. Some challenges are also identified and discussed.

Turbine Electrified Energy Management↗

The Role of Alerting System Failures in Loss of Control Accidents CAST SE-210 Output 2

This report is part of a series of reports that address flight deck design and evaluation, written as a response to loss of control accidents. In particular, this activity is directed at failures in airplane state awareness in which the pilot loses awareness of the airplane's energy state or attitude and enters an upset condition. In a report by the Commercial Aviation Safety Team, an analysis of accidents and incidents related to loss of airplane state awareness determined that hazard alerting was not effective in producing the appropriate pilot response to a hazard (CAST, 2014). In the current report, we take a detailed look at 28 airplane state awareness accidents and incidents to determine how well the hazard alerting worked. We describe a five-step integrated alerting-to-recovery sequence that prescribes how hazard alerting should lead to effective flight crew actions for managing the hazard. Then, for each hazard in each of the 28 events, we determine if that sequence failed and, if so, how it failed. The results show that there was an alerting failure in every one of the 28 safety events, and that the most frequent failure (20/28) was tied to the flight crew not orienting to (not being aware of) the hazard. The discussion section summarizes findings and identifies alerting issues that are being addressed and issues that are not currently being addressed. We identify a few recent upgrades that have addressed certain alerting failures. Two of these upgrades address alerting design, but one response to the safety events is to upgrade training for approach to stall and stall recovery. We also describe issues that are not being addressed adequately: better alert integration for flight path management types of hazards, airplanes in the fleet that do not meet the current alerting regulations, a lack of innovation for addressing cases of channelized attention, and existing vulnerabilities in managing data validity.

aviation safety↗

Reliability Assessment of Cooling Fans for PV Inverters: Testing, Modeling, and Case Studies

The reliability of photovoltaic (PV) inverters is critical for long-term solar system performance, with cooling fan failures frequently leading to costly downtime. While much research exists on general cooling fan reliability, little attention has been given to fans operating within PV inverters and their unique environmental challenges. Here, this article proposes a comprehensive methodology to address this gap. First, a failure mode and effects analysis is performed on fans to identify the key failure mechanisms in PV applications, their corresponding stressors, and the models necessary for lifetime prediction. Second, an accelerated life test is designed and conducted to collect valuable experimental data for PV inverter fans in a reasonable amount of time. Third, a mathematical conversion of dynamic mission profiles into effective constant stress levels is derived. Fourth, case studies are given, showcasing lifetime estimates that account for geographic variations in mission profile data. The results demonstrate that this integrated approach leads to an accurate reliability assessment for PV inverter cooling fans.

accelerated life testing (ALT)↗

Space transfer vehicle concepts and requirements. Volume 1: Executive summary

The objectives of the Space Transfer Vehicle (STV) Concepts and Requirements studies were to provide sensitivity data on usage, economics, and technology associated with new space transportation systems. The study was structured to utilize data on the emerging launch vehicles, the latest mission scenarios, and Space Exploration Initiative (SEI) payload manifesting and schedules, to define a flexible, high performance, cost effective, evolutionary space transportation system for NASA. Initial activities were to support the MSFC effort in the preparation of inputs to the 90 Day Report to the National Space Council (NSC). With the results of this study establishing a point-of-departure for continuing the STV studies in 1990, additional options and mission architectures were defined. The continuing studies will update and expand the parametrics, assess new cargo and manned ETO vehicles, determine impacts on the redefined Phase 0 Space Station Freedom, and to develop a design that encompasses adequate configuration flexibility to ensure compliance with on-going NASA study recommendations with major system disconnects. In terms of general requirements, the objectives of the STV system and its mission profiles will address crew safety and mission success through a failure-tolerant and forgiving design approach. These objectives were addressed through the following: engine-out capability for all mission phases; built-in-test for vehicle health monitoring to allow testing of all critical functions such as, verification of lunar landing and ascent engines before initiating the landing sequence; critical subsystems will have multiple strings for redundancy plus adequate supplies of onboard spares for removal and replacement of failed items; crew radiation protection; and trajectories that optimize lunar and Mars performance and flyby abort capabilities.

Source record↗

Three-Dimensional Gear Crack Propagation Studied

Gears used in current helicopters and turboprops are designed for light weight, high margins of safety, and high reliability. However, unexpected gear failures may occur even with adequate tooth design. To design an extremely safe system, the designer must ask and address the question, "What happens when a failure occurs?" With gear-tooth bending fatigue, tooth or rim fractures may occur. A crack that propagates through a rim will be catastrophic, leading to disengagement of the rotor or propeller, loss of an aircraft, and possible fatalities. This failure mode should be avoided. A crack that propagates through a tooth may or may not be catastrophic, depending on the design and operating conditions. Also, early warning of this failure mode may be possible because of advances in modern diagnostic systems. One concept proposed to address bending fatigue fracture from a safety aspect is a splittooth gear design. The prime objective of this design would be to control crack propagation in a desired direction such that at least half of the tooth would remain operational should a bending failure occur. A study at the NASA Lewis Research Center analytically validated the crack-propagation failsafe characteristics of a split-tooth gear. It used a specially developed three-dimensional crack analysis program that was based on boundary element modeling and principles of linear elastic fracture mechanics. Crack shapes as well as the crack-propagation life were predicted on the basis of the calculated stress intensity factors, mixed-mode crack-propagation trajectory theories, and fatigue crack-growth theories. The preceding figures show the effect of the location of initial cracks on crack propagation. Initial cracks in the fillet of the teeth produced stress intensity factors of greater magnitude (and thus, greater crack growth rates) than those in the root or groove areas of the teeth. Crack growth was simulated in a case study to evaluate crack-propagation paths. Tooth fracture was predicted from the crackgrowth simulation for an initial crack in the tooth fillet region. This was the desired failure mode for an ultrasafe design. Lastly, tooth loads on the uncracked mesh of the split-tooth design were up to five times greater than those on the cracked mesh if equal deflections of the cracked and uncracked teeth were considered. This effect needs to be considered in the design of a split-tooth configuration. This work was done in-house at Lewis in support of the National Rotorcraft Technology Center project, Ultra-Safe Gear Design, with the Boeing Defense and Space Group. The crack-propagation package was developed by the Cornell Fracture Group at Cornell University. The reported results, which are the initial findings of Lewis gear-crackpropagation research for the Rotorcraft Base Program, will be further investigated to develop generalized gear design guidelines.

Lewicki, David G.↗

An Autonomous Distributed Fault-Tolerant Local Positioning System

We describe a fault-tolerant, GPS-independent (Global Positioning System) distributed autonomous positioning system for static/mobile objects and present solutions for providing highly-accurate geo-location data for the static/mobile objects in dynamic environments. The reliability and accuracy of a positioning system fundamentally depends on two factors; its timeliness in broadcasting signals and the knowledge of its geometry, i.e., locations and distances of the beacons. Existing distributed positioning systems either synchronize to a common external source like GPS or establish their own time synchrony using a scheme similar to a master-slave by designating a particular beacon as the master and other beacons synchronize to it, resulting in a single point of failure. Another drawback of existing positioning systems is their lack of addressing various fault manifestations, in particular, communication link failures, which, as in wireless networks, are increasingly dominating the process failures and are typically transient and mobile, in the sense that they typically affect different messages to/from different processes over time.

Mahyar R Malekpour↗

Launch Pad Flame Trench Refractory Materials

The launch complexes at NASA's John F. Kennedy Space Center (KSC) are critical support facilities for the successful launch of space-based vehicles. These facilities include a flame trench that bisects the pad at ground level. This trench includes a flame deflector system that consists of an inverted, V-shaped steel structure covered with a high temperature concrete material five inches thick that extends across the center of the flame trench. One side of the "V11 receives and deflects the flames from the orbiter main engines; the opposite side deflects the flames from the solid rocket boosters. There are also two movable deflectors at the top of the trench to provide additional protection to shuttle hardware from the solid rocket booster flames. These facilities are over 40 years old and are experiencing constant deterioration from launch heat/blast effects and environmental exposure. The refractory material currently used in launch pad flame deflectors has become susceptible to failure, resulting in large sections of the material breaking away from the steel base structure and creating high-speed projectiles during launch. These projectiles jeopardize the safety of the launch complex, crew, and vehicle. Post launch inspections have revealed that the number and frequency of repairs, as well as the area and size of the damage, is increasing with the number of launches. The Space Shuttle Program has accepted the extensive ground processing costs for post launch repair of damaged areas and investigations of future launch related failures for the remainder of the program. There currently are no long term solutions available for Constellation Program ground operations to address the poor performance and subsequent failures of the refractory materials. Over the last three years, significant liberation of refractory material in the flame trench and fire bricks along the adjacent trench walls following Space Shuttle launches have resulted in extensive investigations of failure mechanisms, load response, ejected material impact evaluation, and repair design analysis (environmental and structural assessment, induced environment from solid rocket booster plume, loads summary, and repair integrity), assessment of risk posture for flame trench debris, and justification of flight readiness rationale. Although the configuration of the launch pad, water and exhaust direction, and location of the Mobile Launcher Platform between the flame trench and the flight hardware should protect the Space Vehicle from debris exposure, loss of material could cause damage to a major element of the ground facility (resulting in temporary usage loss); and damage to other facility elements is possible. These are all significant risks that will impact ground operations for Constellation and development of new refractory material systems is necessary to reduce the likelihood of the foreign object debris hazard during launch. KSC is developing an alternate refractory material for the launch pad flame trench protection system, including flame deflector and flame trench walls, that will withstand launch conditions without the need for repair after every launch, as is currently the case. This paper will present a summary of the results from industry surveys, trade studies, life cycle cost analysis, and preliminary testing that have been performed to support and validate the development, testing, and qualification of new refractory materials.

Calle, Luz M.↗

Failure prediction techniques for compression loaded composite laminates with holes

The degree of notch sensitivity of composites in compression and whether their failures can be predicted over a wide range of plate and hole sizes. The notch sensitivity of composites is investigated by comparing actual failure loads of laminates with circular holes, with the extreme failure that would be expected from an ideal notch insensitive material and from an ideal notch sensitive material. The predictability question is addressed by applying the point stress failure criterion to a wide range of plate widths and hole sizes and comparing with available experimental data. The severity of impact is explored by comparing strength reductions resulting from impact with those resulting from comparable size circular holes. Finally, comparison is made of the differences to be expected from the effects of cracks and circular holes on failure strength.

Mikulas, M. M., Jr.↗

Experiences with Extra-Vehicular Activities in Response to Critical ISS Contingencies

Initial "Big 14" work was put to the test for the first time in 2010. Deficiencies were found in some of the planning and approaches to that work; Failure Response Assessment Team created in 2010 to address deficiencies -Identify and perform engineering analysis in operations products prior to failure; incorporate results into operations products -Identify actions for protecting ISS against a Next Worse Failure after the first failure occurs -Better document not only EVA products but also planning products, assumptions, and open actions; Pre-failure investments against critical failures best postures ISS for swift response and recovery -A type of insurance policy -Has proven effective in a number of contingency EVA cases since 2010. Planning for MBSU R&R in 2012, Second PM R&R in 2013, EXT MDM R&R in 2014; Current FRAT schedule projects completion of all analysis in 2018

Van Cise, Edward A.↗

Robustness and printed sensor qualification

A limiting factor of additive manufactured (AM) sensors for in-pile applications is the development of appropriate interconnection and packaging strategies that can maintain reliable performance in extreme environments. Failure mechanisms in these harsh conditions could include, but not limited to, materials interaction (i.e., intermetallic formation) and coefficient of thermal expansion (CTE) mismatch between the individual components of the sensors. To mitigate premature failure and enable the successful sustained operation of AM sensors, non-destructive qualification tests are used as an intermediate process control step used for verifying robustness and reliability of the sensor before they are deployed. A materials system of interest is the use of barium strontium titanium oxide (BST) films on stainless steel 316L (SS316L) substrate. Due to BST’s high dielectric constant and tunable dielectric properties, there is an interest for its application as an insulation/encapsulation layer for capacitive strain gauges when printed on structural materials. Previous work on the BST/SS316L material system, however, showed that the BST cracks when exposed to temperatures up to 600 °C due to CTE mismatch between the printed BST film and the metallic substrate. When comparing different fabrication techniques, less surface cracking was observed in the samples that deposited thinner (i.e., 2-20 μm) than samples that were thicker (i.e., 135 µm – 300 µm). The objective of this report is to establish a qualification process that will determine and address any challenges (i.e., mechanical failure of thick prints) of the AM sensor prior to its application in experimental tests. To demonstrate the qualification process in this report, laser spallation and uniaxial tensile tests using dynamic and quasi-static loading, respectively, will be discussed.

36 - MATERIALS SCIENCE↗

Effect of stress concentrations in composite structures

Composite structures have found wide use in many engineering fields and a sound understanding of their response under load is important to their utilization. An experimental program is being carried out to gain a fundamental understanding of the failure mechanics of multilayered composite structures at GALCIT. As a part of this continuing study, the performance of laminated composite plates in the presence of a stress gradient and the failure of composite structures at points of thickness discontinuity is assessed. In particular, the questions of initiation of failure and its subsequent growth to complete failure of the structure are addressed.

Babcock, C. D.↗

Cooperating intelligent systems

Some of the issues connected to the development of a bureaucratic system are discussed. Emphasis is on a layer multiagent approach to distributed artificial intelligence (DAI). The division of labor in a bureaucracy is considered. The bureaucratic model seems to be a fertile model for further examination since it allows for the growth and change of system components and system protocols and rules. The first part of implementing the system would be the construction of a frame based reasoner and the appropriate B-agents and E-agents. The agents themselves should act as objects and the E-objects in particular should have the capability of taking on a different role. No effort was made to address the problems of automated failure recovery, problem decomposition, or implementation. Instead what has been achieved is a framework that can be developed in several distinct ways, and which provides a core set of metaphors and issues for further research.

Rochowiak, Daniel↗