Search NASA⌕ Search

SEARCH · Search NASA

Results for “Flight Failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Final Dawn Reaction Control System (RCS) propulsion system in-flight characterization

The Dawn spacecraft concluded eleven years of operations on 31-Oct-2018, upon depletion of its hydrazine supply in Ceres orbit during the second extended mission. Dawn’s Reaction Control System performed admirably during this lengthy campaign, including years of unanticipated and novel operation given Reaction Wheel Assembly failures during flight. New and modified modes of thruster operations were implemented during the mission. Pressure transducer drift was negligible, consumable limits were generally not exceeded (except for minor violations in Reaction Control System thruster cycles), and thruster performance was nominal throughout this long interplanetary journey. Tank models of hydrazine remaining mass were consistent with depletion within uncertainties, although thruster consumption-based models ended up being conservative by 15%. Unexpectedly, apparent nitrogen permeation through the hydrazine tank elastomer diaphragm allowed hydrazine in the lines below the tank to be pressurized and subsequently utilized during the final days of the mission.

Mizukami, Masashi↗

Final Dawn Reaction Control System (RCS) propulsion system in-flight characterization

The Dawn spacecraft concluded eleven years of operations on 31-Oct-2018, upon depletion of its hydrazine supply in Ceres orbit during the second extended mission. Dawn’s Reaction Control System performed admirably during this lengthy campaign, including years of unanticipated and novel operation given Reaction Wheel Assembly failures during flight. New and modified modes of thruster operations were implemented during the mission. Pressure transducer drift was negligible, consumable limits were generally not exceeded (except for minor violations in Reaction Control System thruster cycles), and thruster performance was nominal throughout this long interplanetary journey. Tank models of hydrazine remaining mass were consistent with depletion within uncertainties, although thruster consumption-based models ended up being conservative by 15%. Unexpectedly, apparent nitrogen permeation through the hydrazine tank elastomer diaphragm allowed hydrazine in the lines below the tank to be pressurized and subsequently utilized during the final days of the mission.

Mizukami, Masashi↗

Addressing Control Research Issues Leading to Piloted Simulations in Support of the IFCS F-15

This report summarizes the research effort by a team of researchers at West Virginia University in support of the NASA Intelligent Flight Control System (IFCS) F-15 program. In particular, WVU researchers assisted NASA Dryden researchers in the following technical tasks leading to piloted simulation of the 'Gen_2' IFCS control laws. Task #1- Performance comparison of different neural network (NN) augmentation for the Dynamic Inversion (DI) -based VCAS 'Gen_2' control laws. Task #2- Development of safety monitor criteria for transition to research control laws with and without failure during flight test. Task #3- Fine-tuning of the 'Gen_2' control laws for cross-coupling reduction at post-failure conditions. Matlab/Simulink-based simulation codes were provided to the technical monitor on a regular basis throughout the duration of the project. Additional deliverables for the project were Power Point-based slides prepared for different project meetings. This document provides a description of the methodology and discusses the general conclusions from the simulation results.

Napolitano, Marcello↗

Space Shuttle Main Engine Liquid Air Insulation Redesign Lessons Learned

The Space Shuttle Main Engine Liquid Air Insulation redesign was required to prevent the reoccurance of the STS-111 High Pressure Speed Sensor In-Flight Anomaly. The STS-111 In-Flight Anomaly Failure Investigation Team's initial redesign of the High Pressure Fuel Turbopump Pump End Ball Bearing Liquid Air Insulation failed the certification test by producing Liquid Air. The certification test failure indicated not only the High Pressure Fuel Turbopump Liquid Air Insulation, but all other Space Shuttle Main Engine Liquid Air Insulation. This paper will document the original Space Shuttle Main Engine Liquid Air STS-111 In-Flight Anomaly investigation, the heritage Space Shuttle Main Engine Insulation certification testing faults, the techniques and instrumentation used to accurately test the Liquid Air Insulation systems on the Stennis Space Center SSME test stand, the analysis techniques used to identify the Liquid Air Insulation problem areas and the analytical verification of the redesign before entering certification testing, Trade study down selected to three potential design solutions, the results of the development testing which down selected the final Liquid Air Redesign are also documented within this paper.

Darrell Gaddy↗

Failure of Nd:YVO4 Amplifier Crystals

Brittle single crystals are used in NASA applications ranging from lenses to centrally heated laser slabs. Despite standard procedures to design such components, unexpected failures occasionally occur. The ICEsat-2 (Ices, cloud, and elevation satellite) employs Yttrium orthovanadate single crystals in laser amplifiers and oscillators. Although the systems are currently flying and successfully operating, some unexpected crystal fractures occurred just prior to flight. The failures were traced to poor crystal quality along with time depend chemical reaction within the system assembly that increased stress beyond expectations and promoted both fast fracture and stress corrosion. This presentation will discuss failure analysis of the crystals and the chemical reactions that promoted failures, along with corrective actions taken to reduce likelihood of fracture over the three year mission. Re-designed lasers were stored for 12 months and operated for a total of 1,000 hours without signs of degradation.

Salem, Jon↗

Failure of Nd:YVO4 Amplifier Crystals

Brittle single crystals are used in NASA applications ranging from lenses to centrally heated laser slabs. Despite standard procedures to design such components, unexpected failures occasionally occur. The ICEsat-2 (Ices,Cloud, and Elevation satellite-2) employs Yttrium orthovanadate single crystals in laser amplifiers and oscillators. Although the systems are currently flying and successfully operating, some unexpected crystal fractures occurred just prior to flight. The failures were traced to poor crystal quality along with time-dependent chemical reaction within the system assembly that increased stress beyond expectations and promoted both fast fracture and stress corrosion. This presentation will discuss failure analysis of the crystals and the chemical reactions that promoted failures, along with corrective actions taken to reduce likelihood of fracture over the three-year mission. Re-designed lasers were stored for 12 months and operated for a total of 1,000 hours without signs of degradation.

Design↗

Fault Management Algorithm Risk Assessment for the NASA Space Launch System

This paper presents the false positive (FP) and false negative (FN) risk assessment process currently being conducted for the Space Launch System (SLS) Artemis II Fault Management (FM) detection functions. The analysis scope, general assumptions and guide rules, and key modeling concepts were discussed to establish the basis of the risk assessments conducted. Initial analyses indicated a dominance in the total risk by software and firmware failures. This paper presents efforts applied to refine the software risks and the overall impact of implementing those modifications. Current analyses conducted on the detection functions implemented for the SLS Artemis II mission indicate primary risk drivers for the individual FM detection functions are flight software failures, firmware design failures, and hardware Common Cause Failures (CCFs). There still remains issues of how to account for time and redundancy in the software risk estimations.

probability risk analysis↗

Fault Management Algorithm Risk Assessment for the NASA Space Launch System

This presentation describes the false positive (FP) and false negative (FN) risk assessment process currently being conducted for the Space Launch System (SLS) Artemis II Fault Management (FM) detection functions. The analysis scope, general assumptions and guide rules, and key modeling concepts were discussed to establish the basis of the risk assessments conducted. Initial analyses indicated a dominance in the total risk by software and firmware failures. This paper presents efforts applied to refine the software risks and the overall impact of implementing those modifications. Current analyses conducted on the detection functions implemented for the SLS Artemis II mission indicate primary risk drivers for the individual FM detection functions are flight software failures, firmware design failures, and hardware Common Cause Failures (CCFs). There still remains issues of how to account for time and redundancy in the software risk estimations.

probability risk analysis↗

Chapter 12 - Flight Envelope

The term "flight envelope" is used to refer to the boundaries of aircraft loading and flight conditions within which operation of the aircraft is satisfactory, and beyond which some aspect becomes unacceptable. This flight envelope represents, in fact, the limiting conditions arising from a matrix of inter-related flight envelopes covering the appropriate variables. Thus, for each loading (i.e., external stores configuration and its associated range of weight and center of gravity (c.g.) position) and aircraft configuration (i.e., position of undercarriage (u/c), flaps, slats, etc.), the envelopes of airspeed versus altitude, airspeed versus load factor, angle of attack versus angle of sideslip, etc., must be investigated to establish the limits within which all aspects such as handling qualities, engine behavior, structural loads, etc., remain acceptable. Flight testing of new or derivative aircraft models is carried out with the initial purpose of defining a flight envelope which is, first and foremost, safe and secondarily, which enables the effective use of the vehicle for its intended purpose. Flight testing occurs only after numerous reviews of the design and review of results from ground tests and predictions of flight characteristics in such areas as structures, aerodynamics, stability and control, flight controls (particularly fly-by-wire control systems, propulsion, etc.). Accordingly, opening and expanding the envelope is a task that must be approached cautiously, systematically, and with coordination and cooperation of the many disciplines involved in the design and test of an airplane. (Sections 8 and 10 cover test planning and safety of flight considerations, respectively). The fundamental tenet in establishing a flight envelope via flight test is risk reduction. This is reflected in the typical sequence of events leading to initial flight test - design reviews (both hardware and software), then ground test involving singular disciplines (windtunnel tests for aerodynamics, structurally loading the wing/fuselage/nacelle on a ground test article with loads anticipated to occur in flight, flight control system control law checkout, propulsion test cell runs and/or flying test bed tests, etc.), and then ground tests involving multi-disciplines (See Section 9). Only after these have been accomplished will an initial, limited, low-risk, flight envelope be established. The limited envelope will typically be in the middle of the projected final flight envelope. Subsequent flight tests will then be devoted to expanding the initial envelope by operating the airplane at increasing ranges - representing increasing risk - of engine operation, airspeeds both fast and slow, altitude, load factor both above and below 1g, centers of gravity (fore and aft), and with system/subsystem failures. Whether flight tests are to define a flight envelope on a new model airplane with the attendant new airframe, new engine(s), and new subsystems (hydraulics, pressurization, etc.), or on an airplane involving only a few of these areas such as new engines in an old airframe, the fundamental approach to establishing an envelope is the same.

H Walgemoed↗

Space Launch System Implementation of Adaptive Augmenting Control

Given the complex structural dynamics, challenging ascent performance requirements, and rigorous flight certification constraints owing to its manned capability, the NASA Space Launch System (SLS) launch vehicle requires a proven thrust vector control algorithm design with highly optimized parameters to provide stable and high-performance flight. On its development path to Preliminary Design Review (PDR), the SLS flight control system has been challenged by significant vehicle flexibility, aerodynamics, and sloshing propellant. While the design has been able to meet all robust stability criteria, it has done so with little excess margin. Through significant development work, an Adaptive Augmenting Control (AAC) algorithm has been shown to extend the envelope of failures and flight anomalies the SLS control system can accommodate while maintaining a direct link to flight control stability criteria such as classical gain and phase margin. In this paper, the work performed to mature the AAC algorithm as a baseline component of the SLS flight control system is presented. The progress to date has brought the algorithm design to the PDR level of maturity. The algorithm has been extended to augment the full SLS digital 3-axis autopilot, including existing load-relief elements, and the necessary steps for integration with the production flight software prototype have been implemented. Several updates which have been made to the adaptive algorithm to increase its performance, decrease its sensitivity to expected external commands, and safeguard against limitations in the digital implementation are discussed with illustrating results. Monte Carlo simulations and selected stressing case results are also shown to demonstrate the algorithm's ability to increase the robustness of the integrated SLS flight control system.

Wall, John H.↗

Space Launch System Implementation of Adaptive Augmenting Control

Given the complex structural dynamics, challenging ascent performance requirements, and rigorous flight certification constraints owing to its manned capability, the NASA Space Launch System (SLS) launch vehicle requires a proven thrust vector control algorithm design with highly optimized parameters to robustly demonstrate stable and high performance flight. On its development path to preliminary design review (PDR), the stability of the SLS flight control system has been challenged by significant vehicle flexibility, aerodynamics, and sloshing propellant dynamics. While the design has been able to meet all robust stability criteria, it has done so with little excess margin. Through significant development work, an adaptive augmenting control (AAC) algorithm previously presented by Orr and VanZwieten, has been shown to extend the envelope of failures and flight anomalies for which the SLS control system can accommodate while maintaining a direct link to flight control stability criteria (e.g. gain & phase margin). In this paper, the work performed to mature the AAC algorithm as a baseline component of the SLS flight control system is presented. The progress to date has brought the algorithm design to the PDR level of maturity. The algorithm has been extended to augment the SLS digital 3-axis autopilot, including existing load-relief elements, and necessary steps for integration with the production flight software prototype have been implemented. Several updates to the adaptive algorithm to increase its performance, decrease its sensitivity to expected external commands, and safeguard against limitations in the digital implementation are discussed with illustrating results. Monte Carlo simulations and selected stressing case results are shown to demonstrate the algorithm's ability to increase the robustness of the integrated SLS flight control system.

VanZwieten, Tannen S.↗

Getting expert systems off the ground: Lessons learned from integrating model-based diagnostics with prototype flight hardware

As an initial attempt to introduce expert system technology into an onboard environment, a model based diagnostic system using the TRW MARPLE software tool was integrated with prototype flight hardware and its corresponding control software. Because this experiment was designed primarily to test the effectiveness of the model based reasoning technique used, the expert system ran on a separate hardware platform, and interactions between the control software and the model based diagnostics were limited. While this project met its objective of showing that model based reasoning can effectively isolate failures in flight hardware, it also identified the need for an integrated development path for expert system and control software for onboard applications. In developing expert systems that are ready for flight, artificial intelligence techniques must be evaluated to determine whether they offer a real advantage onboard, identify which diagnostic functions should be performed by the expert systems and which are better left to the procedural software, and work closely with both the hardware and the software developers from the beginning of a project to produce a well designed and thoroughly integrated application.

Stephan, Amy↗

STS-55 pad abort: Engine 2011 oxidizer preburner augmented spark igniter check valve leak

The STS-55 initial launch attempt of Columbia (OV102) was terminated on KSC launch pad A March 22, 1993 at 9:51 AM E.S.T. due to violation of an ME-3 (Engine 2011) Launch Commit Criteria (LCC) limit exceedance. The event description and timeline are summarized. Propellant loading was initiated on 22 March, 1993 at 1:15 AM EST. All SSME chill parameters and launch commit criteria (LCC) were nominal. At engine start plus 1.44 seconds, a Failure Identification (FID) was posted against Engine 2011 for exceeding the 50 psia Oxidizer Preburner (OPB) purge pressure redline. The engine was shut down at 1.50 seconds followed by Engines 2034 and 2030. All shut down sequences were nominal and the mission was safely aborted. The OPB purge pressure redline violation and the abort profile/overlay for all three engines are depicted. SSME Avionics hardware and software performed nominally during the incident. A review of vehicle data table (VDT) data and controller software logic revealed no failure indications other than the single FID 013-414, OPB purge pressure redline exceeded. Software logic was executed according to requirements and there was no anomalous controller software operation. Immediately following the abort, a Rocketdyne/NASA failure investigation team was assembled. The team successfully isolated the failure cause to the oxidizer preburner augmented spark igniter purge check valve not being fully closed due to contamination. The source of the contaminant was traced to a cut segment from a rubber O-ring which was used in a fine clean tool during valve production prior to 1992. The valve was apparently contaminated during its fabrication in 1985. The valve had performed acceptably on four previous flights of the engine, and SSME flight history shows 780 combined check valve flights without failure. The failure of an Engine 3 (SSME No. 2011) check valve to close was sensed by onboard engine instruments even though all other engine operations were normal. This resulted in an engine shutdown and safe sequential shutdown of all three engines prior to ignition of the solid boosters.

Source record↗

A failure effects simulation of a low authority flight control augmentation system on a UH-1H helicopter

A two-pilot moving base simulator experiment was conducted to assess the effects of servo failures of a flight control system on the transient dynamics of a Bell UH-1H helicopter. The flight control hardware considered was part of the V/STOLAND system built with control authorities of from 20-40%. Servo hardover and oscillatory failures were simulated in each control axis. Measurements were made to determine the adequacy of the failure monitoring system time delay and the servo center and lock time constant, the pilot reaction times, and the altitude and attitude excursions of the helicopter at hover and 60 knots. Safe recoveries were made from all failures under VFR conditions. Pilot reaction times were from 0.5 to 0.75 sec. Reduction of monitor delay times below these values resulted in significantly reduced excursion envelopes. A subsequent flight test was conducted on a UH-1H helicopter with the V/STOLAND system installed. Series servo hardovers were introduced in hover and at 60 knots straight and level. Data from these tests are included for comparison.

Corliss, L. D.↗

Fluidic emergency roll control system

A fluidic emergency roll control system for aircraft stabilization in the event of primary flight control failure was evaluated. The fluidic roll control units were designed to provide roll torque proportional to an electrical command as operated by two diametrically opposed thrust nozzles located in the wing tips. The control package consists of a solid propellant gas generator, two diametrically opposed vortex valve modulated thrust nozzles, and an electromagnetic torque motor. The procedures for the design, development, and performance testing of the system are described.

Haefner, K. B.↗

Thematic mapper flight model preshipment review data package. Volume 4: Appendix. Part B: Scan mirror assembly data

Data from the thematic mapper scan mirror assembly (SMA) acceptance test are presented. Documentation includes: (1) a list of the acceptance test discrepancies; (2) flight 1 SMA test data book; (3) flight 1 SMA environmental report; (4) the configuration verification index; (5) the flight 1 SMA test failure reports; (6) the flight 1 data tapes log; and (7) the requests for deviation/waivers.

Source record↗

Restructurable controls for aircraft

Future aircraft with highly sophisticated controls are likely to have multiple interdependent failure modes which will be difficult for the pilot to recognize. Such failures may lead to unanticipated sequences of events from which the pilot cannot intuitively recover. Advances in the state-of-the-art in failure detection, failure identification, and control system technology suggest it may be feasible to detect and identify potentially catastrophic failures in flight controls and to restructure the controls in real time to execute a safe landing. Two accidents are reviewed, one in which the pilot successfully restructured the controls and one in which he did not, but for which a solution existed. The problem requirements and potential theoretical techniques which apply are also discussed.

Howell, W. E.↗

Reliability with imperfect diagnostics

A reliability estimation method for systems that continually accumulate faults because of imperfect diagnostics is developed and an application for redundant digital avionics is presented. The present method assumes that if a fault does not appear in a short period of time, it will remain hidden until a majority of components are faulty and the system fails. A certain proportion of a component's faults are detected in a short period of time, and a description of their detection is included in the reliability model. A Markov model of failure during flight for a nonreconfigurable five-plex is presented for a sequence of one-hour flights followed by maintenance.

White, A. L.↗