Search NASA⌕ Search

SEARCH · Search NASA

Results for “common cause failures”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Low-Pressure Diffusion Bonding of Vanadium to Commercially Pure Titanium and Ti-6Al-4V

Modern technology increasingly requires components to be made from specific high-performance materials. To support complex multi-metal structures, a variety of techniques are required to join dissimilar metal parts with precise shapes. This study evaluates vacuum diffusion bonding as a method for joining titanium and vanadium, focusing on both pure titanium and the common alloy Ti-6Al-4V. We employ modest pressure provided by a weight and simple surface preparation to simulate the most commercially applicable process. Here, we show that Ti-6Al-4V alloy bonds readily to V, forming a continuous, clearly defined interdiffusion layer with predictable kinetics. Conversely, commercially pure Ti forms a crack-prone bond with V that fails to improve at higher bonding temperatures or longer times. We attribute this failure to the concentration of stress caused by the ß-to-α phase transformation in Ti. The contrasting bonding efficacy between pure Ti and the alloy provides insight into the crystallographic interactions that occur at the interface during bonding and cooling. These results provide surprising insight into a new method for bonding Ti alloys to V and possibly other metals that share the body-centered cubic crystal structure.

36 MATERIALS SCIENCE↗

A Summary of NASA and USAF Hypergolic Propellant Related Spills and Fires

Several unintentional hypergolic fluid related spills, fires, and explosions from the Apollo Program, the Space Shuttle Program, the Titan Program, and a few others have occurred over the past several decades. Spill sites include the following government facilities: Kennedy Space Center (KSC), Johnson Space Center (JSC), White Sands Test Facility (WSTF), Vandenberg Air Force Base (VAFB), Cape Canaveral Air Force Station (CCAFS), Edwards Air Force Base (EAFB), Little Rock AFB, and McConnell AFB. Until now, the only method of capturing the lessons learned from these incidents has been "word of mouth" or by studying each individual incident report. The root causes and consequences of the incidents vary drastically; however, certain "themes" can be deduced and utilized for future hypergolic propellant handling. Some of those common "themes" are summarized below: (1) Improper configuration control and internal or external human performance shaping factors can lead to being falsely comfortable with a system (2) Communication breakdown can escalate an incident to a level where injuries occur and/or hardware is damaged (3) Improper propulsion system and ground support system designs can destine a system for failure (4) Improper training of technicians, engineers, and safety personnel can put lives in danger (5) Improper PPE, spill protection, and staging of fire extinguishing equipment can result in unnecessary injuries or hardware damage if an incident occurs (6) Improper procedural oversight, development, and adherence to the procedure can be detrimental and quickly lead to an undesirable incident (7) Improper materials cleanliness or compatibility and chemical reactivity can result in fires or explosions (8) Improper established "back-out" and/or emergency safing procedures can escalate an event The items listed above are only a short list of the issues that should be recognized prior to handling hypergolic fluids or processing vehicles containing hypergolic propellants. The summary of incidents in this report is intended to cover many more issues than those listed above.

Nufer, Brian M.↗

Fault Management Techniques in Human Spaceflight Operations

This paper discusses human spaceflight fault management operations. Fault detection and response capabilities available in current US human spaceflight programs Space Shuttle and International Space Station are described while emphasizing system design impacts on operational techniques and constraints. Preflight and inflight processes along with products used to anticipate, mitigate and respond to failures are introduced. Examples of operational products used to support failure responses are presented. Possible improvements in the state of the art, as well as prioritization and success criteria for their implementation are proposed. This paper describes how the architecture of a command and control system impacts operations in areas such as the required fault response times, automated vs. manual fault responses, use of workarounds, etc. The architecture includes the use of redundancy at the system and software function level, software capabilities, use of intelligent or autonomous systems, number and severity of software defects, etc. This in turn drives which Caution and Warning (C&W) events should be annunciated, C&W event classification, operator display designs, crew training, flight control team training, and procedure development. Other factors impacting operations are the complexity of a system, skills needed to understand and operate a system, and the use of commonality vs. optimized solutions for software and responses. Fault detection, annunciation, safing responses, and recovery capabilities are explored using real examples to uncover underlying philosophies and constraints. These factors directly impact operations in that the crew and flight control team need to understand what happened, why it happened, what the system is doing, and what, if any, corrective actions they need to perform. If a fault results in multiple C&W events, or if several faults occur simultaneously, the root cause(s) of the fault(s), as well as their vehicle-wide impacts, must be determined in order to maintain situational awareness. This allows both automated and manual recovery operations to focus on the real cause of the fault(s). An appropriate balance must be struck between correcting the root cause failure and addressing the impacts of that fault on other vehicle components. Lastly, this paper presents a strategy for using lessons learned to improve the software, displays, and procedures in addition to determining what is a candidate for automation. Enabling technologies and techniques are identified to promote system evolution from one that requires manual fault responses to one that uses automation and autonomy where they are most effective. These considerations include the value in correcting software defects in a timely manner, automation of repetitive tasks, making time critical responses autonomous, etc. The paper recommends the appropriate use of intelligent systems to determine the root causes of faults and correctly identify separate unrelated faults.

O'Hagan, Brian↗

High Voltage Solar Array ARC Testing for a Direct Drive Hall Effect Thruster System

The deleterious effects of spacecraft charging are well known, particularly when the charging leads to arc events. The damage that results from arcing can severely reduce system lifetime and even cause critical system failures. On a primary spacecraft system such as a solar array, there is very little tolerance for arcing. Motivated by these concerns, an experimental investigation was undertaken to determine arc thresholds for a high voltage (200-500 V) solar array in a plasma environment. The investigation was in support of a NASA program to develop a Direct Drive Hall-Effect Thruster (112HET) system. By directly coupling the solar array to a Hall-effect thruster, the D2HET program seeks to reduce mass, cost and complexity commonly associated with the power processing in conventional power systems. In the investigation, multiple solar array technologies and configurations were tested. The cell samples were biased to a negative voltage, with an applied potential difference between them, to imitate possible scenarios in solar array strings that could lead to damaging arcs. The samples were tested in an environment that emulated a low-energy, HET-induced plasma. Short duration "trigger" arcs as well as long duration "sustained" arcs were generated. Typical current and voltage waveforms associated with the arc events are presented. Arc thresholds are also defined in terms of vo!tage, (current and power. The data will be used to propose a new, high-voltage (>300 V) solar array design for which the likelihood of damage from arcing is minimal.

Schneider, T.↗

High Voltage Solar Array Arc Testing for a Direct Drive Hall Effect Thruster System

The deleterious effects of spacecraft charging are well known, particularly when the charging leads to arc events. The damage that results from arcing can severely reduce system lifetime and even cause critical system failures. On a primary spacecraft system such as a solar array, there is very little tolerance for arcing. Motivated by these concerns, an experimental investigation was undertaken to determine arc thresholds for a high voltage (200-500 V) solar array in a plasma environment. The investigation was in support of a NASA program to develop a Direct Drive Hall-Effect Thruster (D2HET) system. By directly coupling the solar array to a Hall-effect thruster, the D2HET program seeks to reduce mass, cost and complexity commonly associated with the power processing in conventional power systems. In the investigation, multiple solar array technologies and configurations were tested. The cell samples were biased to a negative voltage, with an applied potential difference between them, to imitate possible scenarios in solar array strings that could lead to damaging arcs. The samples were tested in an environment that emulated a low-energy, HET-induced plasma. Short duration trigger arcs as well as long duration sustained arcs were generated. Typical current and voltage waveforms associated with the arc events are presented. Arc thresholds are also defined in terms of voltage, current and power. The data will be used to propose a new, high-voltage (greater than 300 V) solar array design for which the likelihood of damage from arcing is minimal.

Schneider, Todd↗

Reactive transport modeling of the Aquifer Thermal Energy Storage (ATES) system at Stockton University, New Jersey during seasonal operations

Hydrogeochemical processes associated with Aquifer Thermal Energy Storage (ATES) operations can often impact the system performance owing to mineral precipitation either at the wellbore or in the aquifer owing to changes in temperature and fluid disequilibria. Although failure of ATES systems due to mineral precipitation ("fouling") is common, predictive reactive-transport models have rarely been applied to plan their design and operation. Here, the objective of this study is to develop a reactive-transport model by coupling thermal, hydrological, and chemical (THC) processes to evaluate effects of introduced atmospheric oxygen on water chemistry, mineral precipitation/dissolution, porosity, and permeability changes associated with an ATES system at Stockton University (New Jersey, USA). The THC model builds on a Thermal-Hydrological-Mechanical (THM) model of the site that evaluated system failure owing to possible fracturing in the caprock or around the wellbore. The causes of the system failure are not known – potential causes include hydraulic fracturing owing to elevated pump pressures that took place, a flow pathway created by one of the boreholes, or a pre-existing natural hydrologic connection between the upper unconfined aquifer and the ATES aquifer, any of which could have led to oxygenated water entering the reservoir and causing the observed Fe-oxide fouling on well screens. The THC model is used to evaluate some of the hypotheses and observations regarding system failure owing to geochemical processes. The reactive-transport code TOUGHREACT V4 was used to model the THC processes during seasonal heating and cooling operations at the Stockton ATES site over 6 years of operation. In the THC simulations, the primary effects on geochemistry were observed when the injection water is saturated with atmospheric oxygen. Simulations show greater precipitation of goethite near the cold wells as compared to the warm wells. Although volume fractions of Fe-hydroxides were relatively small, the model was aimed at processes in the aquifer at the scale of meters and larger rather than at the scale of mm or cm (i.e., a well screen). Kaolinite is the dominant precipitating phase, also around the cold wells. Illite dissolves near the cold wells and precipitates near the warm wells. There is a net decrease in the porosity near the cold wells and increase near the warm wells, although a slight amount of thermal contraction near the cold wells and expansion near the warm wells is responsible for a significant proportion of the porosity change. Owing to the coarse discretization of the numerical grid near the wells (compared to the screen thickness) the magnitude of permeability changes at the wellbore are likely underestimated. The reactive transport model in this study can be used for characterization of aquifers, optimizing the operational parameters (temperature, pressure, pH etc.), and planning of mitigation strategies for ATES systems.

15 GEOTHERMAL ENERGY↗

Subacute diabetic proximal neuropathy

OBJECTIVE: To evaluate the clinical, electrophysiologic, autonomic, and neuropathologic characteristics and the natural history of subacute diabetic proximal neuropathy and its response to immunotherapy. MATERIAL AND METHODS: For the 12-year period from 1983 to 1995, we conducted a retrospective review of medical records of Mayo Clinic patients with diabetes who had subacute onset and progression of proximal weakness. The responses of treated versus untreated patients were compared statistically. RESULTS: During the designated study period, 44 patients with subacute diabetic proximal neuropathy were encountered. Most patients were middle-aged or elderly, and no sex preponderance was noted. The proximal muscle weakness often was associated with reduced or absent lower extremity reflexes. Associated weight loss was a common finding. Frequently, patients had some evidence of demyelination on nerve conduction studies, but it invariably was accompanied by concomitant axonal degeneration. The cerebrospinal fluid protein concentration was usually increased. Diffuse and substantial autonomic failure was generally present. In most cases, a sural nerve biopsy specimen suggested demyelination, although evidence of an inflammatory infiltrate was less common. Of 12 patients who received treatment (with prednisone, intravenous immune globulin, or plasma exchange), 9 had improvement of their conditions, but 17 of 29 untreated patients (59%) with follow-up also eventually had improvement, albeit at a much slower rate. Improvement was usually incomplete. CONCLUSION: We suggest that the entity of subacute diabetic proximal neuropathy is an extensive and severe variant of bilateral lumbosacral radiculoplexopathy, with some features suggestive of an immune-mediated cause. It differs from chronic inflammatory demyelinating polyradiculoneuropathy in that most cases have a more restricted distribution and seem to be monophasic and self-limiting. The efficacy of immunotherapy is unproved, but such intervention may be considered in the severe and progressive cases or ones associated with severe neuropathic pain.

Non-NASA Center↗

A transport-based framework for solidification cracking in Ni-based superalloys processed by laser powder bed fusion

Solidification cracking remains a persistent barrier to laser powder bed fusion (LPBF) processing of solid-solution-strengthened (SSS) Ni-based superalloys and is commonly attributed to carbide formation, liquation-type failure, or elemental segregation. In this work, the cracking behavior of three SSS Ni-based superalloys—Inconel 625 (625), Inconel 617 (617), and Haynes 230 (230)—is examined under comparable LPBF conditions to evaluate the origins of their cracking susceptibility. Carbides were present in both 625 and 230, yet cracking behavior differed significantly. MC-type carbides in 625 remain discrete and preserve liquid connectivity, whereas Cr-rich M23C6 carbides in 230 form at cellular triple junctions that bottleneck the interdendritic liquid network, influencing cracking through liquid connectivity rather than as an independent cause. Alloy 617 exhibited anomalous segregation without resolvable secondary phases yet cracked mildly, indicating that extensive carbide formation is not a prerequisite for cracking. To rationalize these observations, a transport-limited framework is proposed in which cracking occurs when terminal-liquid feeding cannot accommodate solidification-induced strain; among the mechanisms evaluated, this framework is most consistent with the physical constraints imposed by LPBF solidification. Transport-based crack-susceptibility indexes incorporating permeability, viscosity, and solidification kinetics distinguish the alloy hierarchy; permeability ratios Krat increased from approximately 7 (625) to 11.5 (617) and 14.5 (230), with corresponding increases in the μ-weighted mushy zone risk index (CSIMZRM). These results are consistent with transport-limited liquid feeding as a rate-limiting contributor to solidification cracking in LPBF-processed SSS Ni-based superalloys, providing a physically grounded basis for alloy and process design.

Hyer, Holden [ORNL] (ORCID:0000000343915561)↗

Stochastic Microgrid Scheduling With Chance‐Constrained Resilience Consideration

Traditionally, it is assumed that microgrids transition seamlessly from grid‐connected operation to islanded mode in the event of sudden main grid outages. In reality, the islanding process, especially unintentional islanding, is rarely seamless. Instead, it is subject to voltage and frequency fluctuations caused by the instantaneous disconnection of the point of common coupling (PCC) switch, variations in loads and renewable generation output and even the protection tripping of distributed energy resources (DERs). To mitigate these fluctuations and facilitate a smooth islanding process, we propose a stochastic microgrid scheduling model that incorporates chance‐constrained resilience measures. Specifically, the resilience measure is defined as the probability of successful islanding (PSI), that is, the probability that a microgrid can mitigate the generation‐demand imbalance caused by the disconnection of the PCC switch, variations in load and renewable generation and DER tripping. This measure is modelled using chance constraints. Unlike existing reliability and resilience indices, which typically neglect the possibility of microgrid/DER failure under extreme events and assume their survival while primarily focussing on reducing impact duration or magnitude, the proposed PSI‐based framework explicitly addresses microgrid and DER survival during the islanding transition. The formulated nonlinear chance constraints are approximated using a multiinterval approach and equivalently represented as a mixed‐integer linear programming (MILP) formulation. Case study results validate the proposed method, showing that the PSI estimation error is reduced to less than 8%, compared to approximately 28% with existing methods. Various sensitivity analyses on the DER tripping rate and PSI settings were performed to validate the robustness of the proposed method. In particular, the necessity of accounting for DER tripping in the PSI calculation was demonstrated.

chance constrained optimization↗

Toward Failure Modeling In Complex Dynamic Systems: Impact of Design and Manufacturing Variations

When designing vehicle vibration monitoring systems for aerospace devices, it is common to use well-established models of vibration features to determine whether failures or defects exist. Most of the algorithms used for failure detection rely on these models to detect significant changes during a flight environment. In actual practice, however, most vehicle vibration monitoring systems are corrupted by high rates of false alarms and missed detections. Research conducted at the NASA Ames Research Center has determined that a major reason for the high rates of false alarms and missed detections is the numerous sources of statistical variations that are not taken into account in the. modeling assumptions. In this paper, we address one such source of variations, namely, those caused during the design and manufacturing of rotating machinery components that make up aerospace systems. We present a novel way of modeling the vibration response by including design variations via probabilistic methods. The results demonstrate initial feasibility of the method, showing great promise in developing a general methodology for designing more accurate aerospace vehicle vibration monitoring systems.

Tumer, Irem Y.↗

Current and Future Impact Risks from Small Debris to Operational Satellites

The collision between Iridium 33 and Cosmos 2251 in 2009 signaled the potential onset of the collision cascade effect, commonly known as the "Kessler Syndrome", in the low Earth orbit (LEO) region. Recent numerical simulations have shown that the 10 cm and larger debris population in LEO will continue to increase even with a good implementation of the commonly-adopted mitigation measures. This increase is driven by collisions involving large and massive intacts, i.e., rocket bodies and spacecraft. Therefore, active debris removal (ADR) of large and massive intacts with high collision probabilities has been argued as a direct and effective means to remediate the environment in LEO. The major risk for operational satellites in the environment, however, comes from impacts with debris just above the threshold of the protection shields. In general, these are debris in the millimeter to centimeter size regime. Although impacts by these objects are insufficient to lead to catastrophic breakup of the entire vehicle, the damage is certainly severe enough to cause critical failure of the key instruments or the entire payload. The focus of this paper is to estimate the impact risks from 5 mm and 1 cm debris to active payloads in LEO (1) in the current environment and (2) in the future environment based on different projection scenarios, including ADR. The goal of the study is to quantify the benefits of ADR in reducing debris impact risks to operational satellites.

Liou, Jer-Chyi↗

Piezoelectrically Initiated Pyrotechnic Igniter

This innovation consists of a pyrotechnic initiator and piezoelectric initiation system. The device will be capable of being initiated mechanically; resisting initiation by EMF, RF, and EMI (electromagnetic field, radio frequency, and electromagnetic interference, respectively); and initiating in water environments and space environments. Current devices of this nature are initiated by the mechanical action of a firing pin against a primer. Primers historically are prone to failure. These failures are commonly known as misfires or hang-fires. In many cases, the primer shows the dent where the firing pin struck the primer, but the primer failed to fire. In devices such as "T" handles, which are commonly used to initiate the blowout of canopies, loss of function of the device may result in loss of crew. In devices such as flares or smoke generators, failure can result in failure to spot a downed pilot. The piezoelectrically initiated ignition system consists of a pyrotechnic device that plugs into a mechanical system (activator), which on activation, generates a high-voltage spark. The activator, when released, will strike a stack of electrically linked piezo crystals, generating a high-voltage, low-amperage current that is then conducted to the pyro-initiator. Within the initiator, an electrode releases a spark that passes through a pyrotechnic first-fire mixture, causing it to combust. The combustion of the first-fire initiates a primary pyrotechnic or explosive powder. If used in a "T" handle, the primary would ramp the speed of burn up to the speed of sound, generating a shock wave that would cause a high explosive to go "high order." In a flare or smoke generator, the secondary would produce the heat necessary to ignite the pyrotechnic mixture. The piezo activator subsystem is redundant in that a second stack of crystals would be struck at the same time with the same activation force, doubling the probability of a first strike spark generation. If the first activation fails to ignite, the device is capable of multiple attempts. Another unique aspect is in the design of the pyrotechnic device. There is an electrode that aids the generation of a directed spark and the use of a conductive matrix to support the first-fire material so that the spark will penetrate to the second electrode.

Quince, Asia↗

Development of a Numerical Model of Hypervelocity Impact into a Pressurized Composite Overwrapped Pressure Vessel

As the outlook for space exploration becomes more ambitious and spacecraft travel deeper into space than ever before, it is increasingly important that propulsion systems perform reliably within the space environment. The increased reliability compels designers to increase design margin at the expense of system mass, which contrasts with the need to limit vehicle mass to maximize payload. Such are the factors that motivate the integration of high specific strength composite materials in the construction of pressure vessels commonly referred to as composite overwrapped pressure vessels (COPV). The COPV consists of a metallic liner for the inner shell of the COPV that is stiff, negates fluid permeation and serves as the anchor for composite laminates or filaments, but the liner itself cannot contain the stresses from the pressurant it contains. The compo-site-fiber reinforced polymer (CFRP) is wound around the liner using a combination of hoop (circumferential) and helical orientations. Careful consideration of wrap orientation allows the composite to evenly bear structural loading and creates the COPV's characteristic high strength to weight ratio. As the CFRP overwrap carries most of the stresses induced by pressurization, damage to the overwrap can affect mission duration, mission success and potentially cause loss-of-vehicle/loss-of-crew. For this reason, it is critical to establish a fundamental understanding of the mechanisms involved in the failure of a stressed composite such as that of the COPV. One of the greatest external threats to the integrity of a spacecraft's COPV is an impact from the meteoroid and orbital debris environments (MMOD). These impacts, even from submillimeter particles, generate extremely high stress states in the CFRP that can damage numerous fibers. As a result of this possibility, initial assumptions in survivability analysis for some human-rated NASA space-craft have assumed that any alteration of the vessel due to impact is considered a catastrophic failure. This assumption is conservative and made due to lack of knowledge on the level of allow-able damage to the composite overwrap that can be sustained and still allow successful completion of the mission. To quantify the allowable damage level to the composite overwrap involves assessing stress redistribution following damage as well as evaluating possible time-dependent mechanisms involved in the COPV response to an impact event. Limited published work in this subject has shown that COPV can withstand at least some level of damage due to high energy impacts. These observations have been confirmed and expanded upon in recent experimental research performed by NASA. This research has demonstrated that there is not only robustness in a COPV to compensate for CFRP damage, but has also identified two significant failure modes for pressurized COPV. The lowest threshold failure mode involves the perforation of the vessel, and the highest threshold failure mode is the catastrophic rupture. While both of these failure modes mean a loss of the COPV, system robustness affords some tolerance to the venting as opposed to the more catastrophic rupture. As a consequence, it is necessary to understand the conditions that result in the transition between these failure modes. The aforementioned experimental research has been performed in both the unpressurized and pressurized condition to identify the damage level that triggered the failure thresh-old. This COPV test program was sponsored by the NASA Engineering and Safety Center (NESC), and tests were performed at NASA White Sands Test Facility (WSTF). Planning and coordination were provided by NASA JSC Hypervelocity Impact Technology (HVIT) group, and the COPVs were provided by the ISS Program. Unpressurized testing has been conducted at the pressure of the vacuum test chamber, while, the pressurized testing has been conducted at 290 +/- 10 bar (4,200  100 psi) using nitrogen as the pressurizing gas, which corresponds to the design pressure for the target COPV. In this research, spherical aluminum projectiles with varying diameter has been chosen as the impactor. For the unpressurized COPV, the dependence of penetration up to the dependence of hole size in the liner has been obtained as a function of impact conditions. For the pressurized research, the dependence of penetration up to rupture has been obtained as a function of im-pact conditions. Two representative post-test photographs of the failed COPV's from a nor-mal impact into the COPV surface are shown in Fig. 1. These images display the dramatic difference between failure modes, venting (Fig. 1a) and rupture (Fig. 1b). For venting, liner perforation, severed composite fibers/tows and ply delamination are commonly observed damage characteristics of this COPV failure mode. In the case of rupture, the COPV typically experienced a separation of its domed regions and severe break-up of the cylindrical region. Fully understanding the transition from venting to rupture experimentally is costly and potentially unachievable for conditions that cannot be generated in the laboratory. These shortcomings have motivated the performance of three-dimensional numerical simulations to expand the existing experimental database. These simulations have been carried out with the nonlinear-structural-dynamics, analysis-tool, CTH. A typical pressure contour plot from an impact simulation of an entire COPV is shown in Fig. 2. To generate the COPV stress state without initiating a shock wave, the pressure in the simulated COPV is ramped up to the final pressure over a millisecond prior to impact of the projectile with nitrogen gas. Figure 2a shows the system in this initial condition. After one millisecond, a projectile is initiated into the simulation and impacts the COPV. Figure 2b shows the system after this impact. In the figure, the onset of venting is represented as the change in pressure (μbar), red to green, at the perforation site. Also seen in the figure is the eroded projectile that had passed into the COPV vessel with the generated shock wave in the pressurant propagating just ahead of the material. In this paper, pertinent experimental details and the development of the material constitutive models necessary for this work along with the efforts to validate their use are dis-cussed. The simulation results are presented and compared with the NASA experimental observations. While work is on-going from this effort, early observations pertinent to the failure threshold are presented.

Garcia, M. A.↗

Is Model-Based Development a Favorable Approach for Complex and Safety-Critical Computer Systems on Commercial Aircraft?

A system is safety-critical if its failure can endanger human life or cause significant damage to property or the environment. State-of-the-art computer systems on commercial aircraft are highly complex, software-intensive, functionally integrated, and network-centric systems of systems. Ensuring that such systems are safe and comply with existing safety regulations is costly and time-consuming as the level of rigor in the development process, especially the validation and verification activities, is determined by considerations of system complexity and safety criticality. A significant degree of care and deep insight into the operational principles of these systems is required to ensure adequate coverage of all design implications relevant to system safety. Model-based development methodologies, methods, tools, and techniques facilitate collaboration and enable the use of common design artifacts among groups dealing with different aspects of the development of a system. This paper examines the application of model-based development to complex and safety-critical aircraft computer systems. Benefits and detriments are identified and an overall assessment of the approach is given.

Torres-Pomales, Wilfredo↗

Towards Comprehensive Variation Models for Designing Vehicle Monitoring Systems

When designing vehicle vibration monitoring systems for aerospace devices, it is common to use well-established models of vibration features to determine whether failures or defects exist. Most of the algorithms used for failure detection rely on these models to detect significant changes in a flight environment. In actual practice, however, most vehicle vibration monitoring systems are corrupted by high rates of false alarms and missed detections. This crucial roadblock makes their implementation in real vehicles (e.g., helicopter transmissions and aircraft engines) difficult, making their operation costly and unreliable. Research conducted at the NASA Ames Research Center has determined that a major reason for the high rates of false alarms and missed detections is the numerous sources of statistical variations that are not taken into account in the modeling assumptions. In this paper, we address one such source of variations, namely, those caused during the design and manufacturing of rotating machinery components that make up aerospace systems. We present a novel way of modeling the vibration response by including design variations via probabilistic methods. Using such models, we develop a methodology to account for design and manufacturing variations, and explore the changes in the vibration response to determine its stochastic nature. We explore the potential of the methodology using a nonlinear cam-follower model, where the spring stiffness values are assumed to follow a normal distribution. The results demonstrate initial feasibility of the method, showing great promise in developing a general methodology for designing more accurate aerospace vehicle monitoring systems.

McAdams, Daniel A.↗

TTEthernet for Integrated Spacecraft Networks

Aerospace projects have traditionally employed federated avionics architectures, in which each computer system is designed to perform one specific function (e.g. navigation). There are obvious downsides to this approach, including excessive weight (from so much computing hardware), and inefficient processor utilization (since modern processors are capable of performing multiple tasks). There has therefore been a push for integrated modular avionics (IMA), in which common computing platforms can be leveraged for different purposes. This consolidation of multiple vehicle functions to shared computing platforms can significantly reduce spacecraft cost, weight, and design complexity. However, the application of IMA principles introduces significant challenges, as the data network must accommodate traffic of mixed criticality and performance levels - potentially all related to the same shared computer hardware. Because individual network technologies are rarely so competent, the development of truly integrated network architectures often proves unreasonable. Several different types of networks are utilized - each suited to support a specific vehicle function. Critical functions are typically driven by precise timing loops, requiring networks with strict guarantees regarding message latency (i.e. determinism) and fault-tolerance. Alternatively, non-critical systems generally employ data networks prioritizing flexibility and high performance over reliable operation. Switched Ethernet has seen widespread success filling this role in terrestrial applications. Its high speed, flexibility, and the availability of inexpensive commercial off-the-shelf (COTS) components make it desirable for inclusion in spacecraft platforms. Basic Ethernet configurations have been incorporated into several preexisting aerospace projects, including both the Space Shuttle and International Space Station (ISS). However, classical switched Ethernet cannot provide the high level of network determinism required by real-time spacecraft applications. Even with modern advancements, the uncoordinated (i.e. event-driven) nature of Ethernet communication unavoidably leads to message contention within network switches. The arbitration process used to resolve such conflicts introduces variation in the time it takes for messages to be forwarded. TTEthernet1 introduces decentralized clock synchronization to switched Ethernet, enabling message transmission according to a time-triggered (TT) paradigm. A network planning tool is used to allocate each device a finite amount of time in which it may transmit a frame. Each time slot is repeated sequentially to form a periodic communication schedule that is then loaded onto each TTEthernet device (e.g. switches and end systems). Each network participant references the synchronized time in order to dispatch messages at predetermined instances. This schedule guarantees that no contention exists between time-triggered Ethernet frames in the network switches, therefore eliminating the need for arbitration (and the timing variation it causes). Besides time-triggered messaging, TTEthernet networks may provide two additional traffic classes to support communication of different criticality levels. In the rate-constrained (RC) traffic class, the frame payload size and rate of transmission along each communication channel are limited to predetermined maximums. The network switches can therefore be configured to accommodate the known worst-case traffic pattern, and buffer overflows can be eliminated. The best-effort (BE) traffic class behaves akin to classical Ethernet. No guarantees are provided regarding transmission latency or successful message delivery. TTEthernet coordinates transmission of all three traffic classes over the same physical connections, therefore accommodating the full spectrum of traffic criticality levels required in IMA architectures. Common computing platforms (e.g. LRUs) can share networking resources in such a way that failures in non-critical systems (using BE or RC communication modes) cannot impact flight-critical functions (using TT communication). Furthermore, TTEthernet hardware (e.g. switches, cabling) can be shared by both TTEthernet and classical Ethernet traffic.

Loveless, Andrew↗

A Near-Term Concept for Trajectory Based Operations with Air/Ground Data Link Communication

An operating concept and required system components for trajectory-based operations with air/ground data link for today's en route and transition airspace is proposed. Controllers are fully responsible for separation as they are today, and no new aircraft equipage is required. Trajectory automation computes integrated solutions to problems like metering, weather avoidance, traffic conflicts and the desire to find and fly more time/fuel efficient flight trajectories. A common ground-based system supports all levels of aircraft equipage and performance including those equipped and not equipped for data link. User interface functions for the radar controller's display make trajectory-based clearance advisories easy to visualize, modify if necessary, and implement. Laboratory simulations (without human operators) were conducted to test integrated operation of selected system components with uncertainty modeling. Results are based on 102 hours of Fort Worth Center traffic recordings involving over 37,000 individual flights. The presence of uncertainty had a marginal effect (5%) on minimum-delay conflict resolution performance, and windfavorable routes had no effect on detection and resolution metrics. Flight plan amendments and clearances were substantially reduced compared to today s operations. Top-of-descent prediction errors are the largest cause of failure indicating that better descent predictions are needed to reliably achieve fuel-efficient descent profiles in medium to heavy traffic. Improved conflict detections for climbing flights could enable substantially more continuous climbs to cruise altitude. Unlike today s Conflict Alert, tactical automation must alert when an altitude amendment is entered, but before the aircraft starts the maneuver. In every other failure case tactical automation prevented losses of separation. A real-time prototype trajectory trajectory-automation system is running now and could be made ready for operational testing at an en route Center in 1-2 years.

McNally, David↗

Accounting for Point Estimate Uncertainty in Space Systems Reliability and Risk Analysis

Understanding and accounting for uncertainty in risk analysis is a critical step in the management and communication of risk in engineered systems. The component and system-level analysis to determine the probability of a negative outcome and its consequence is often quantified by a point estimate. Many Program and Enterprise decisions involving technical concerns and issues rely on reliability engineering activities to produce quantified risk analysis to inform the decision making process. At NASA, it is common to use a Probabilistic Risk Analysis (PRA) to inform the overall risk to Loss of Mission or Loss of Crew that involves integration across all spacecraft subsystem fault trees to produce an overall probability of mission failure. The point estimate is an estimate of this overall probability and is an immediate result of a fault tree model. It is the result of a model where the probability of each event is taken to be equal to its mean. The value provides an approximation of the overall mean without running any uncertainty calculations (e.g., no sampling). Using only the point estimate can lead to a false sense of precision and the point estimate may not match the resulting mean when uncertainty is taken into consideration. This paper will explore five conditions that can cause the PRA model mean to diverge from the point estimate and will provide engineers and managers insight into the importance of understanding uncertainty in the elements of PRA models.

Paul J Collier↗