Search NASA⌕ Search

SEARCH · Search NASA

Results for “fail operational”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Destructive Evaluation of a Xenon Hollow Cathode after a 28,000 Hour Life Test

International Space Station (ISS) plasma contactor system requires a hollow cathode assembly (HCA) with a lifetime of at least 18,000 hours. In order to demonstrate the lifetime capability of the HCA, a series of hollow cathode wear tests was performed which included a life test operated at the maximum current of the HCA. This test sought to verify hollow cathode lifetime capability and contamination control protocols. This hollow cathode accumulated 27,800 hours of operation before it failed during a restart attempt. The cathode was subsequently destructively analyzed in order to determine the failure mechanism. Microscopic examination of the cathode interior determined that relatively small changes in the cathode physical geometry had occurred and barium tungstates, which are known to limit the emission process, had formed over a majority of the electron emitter surface. Because the final state of the insert was consistent with expected impregnate chemistry, the hollow cathode was believed to have reached the end of its usable life under the test conditions.

Sarver-Verhey, Timothy R.↗

A Cognitive-System Model for En Route Air Traffic Management

NASA Ames Research Center has been engaged in the development of advanced air traffic management technologies whose basic form is cognitive aiding systems for air traffic controller and flight deck operations. In the design and evaluation of such systems the dynamic interaction between the airborne aiding system and the ground-based aiding systems forms a critical coupling for control. The human operator is an integral control element in the system and the optimal integration of human decision and performance parameters with those of the automation aiding systems offers a significant challenge to cognitive engineering. This paper presents a study in full mission simulation and the development of a predictive computational model of human performance. We have found that this combination of methodologies provide a powerful design-aiding process. We have extended the computational model Man Machine Integrated Design and Analysis System (N13DAS) to include representation of multiple cognitive agents (both human operators and intelligent aiding systems), operating aircraft airline operations centers and air traffic control centers in the evolving airspace. The demands of this application require the representation of many intelligent agents sharing world-models, and coordinating action/intention with cooperative scheduling of goals and actions in a potentially unpredictable world of operations. The operator's activity structures have been developed to include prioritization and interruption of multiple parallel activities among multiple operators, to provide for anticipation (knowledge of the intention and action of remote operators), and to respond to failures of the system and other operators in the system in situation-specific paradigms. We have exercised this model in a multi-air traffic sector scenario with potential conflict among aircraft at and across sector boundaries. We have modeled the control situation as a multiple closed loop system. The inner and outer loop alerting structure of air traffic management has many implications that need to be investigated to assure adequate design. First, there are control and stability factors implicit in the design. As the inner loop response time approaches that of the outer loop, system stability may be compromised in that controllers may be solving a problem the nature of which has already been changed by pilot action. Second, information exchange and information presentation for both air and ground must be designed to complement as opposed to compete with each other. Third, the level of individual and shared awareness in trajectory modification and flight conformance needs to be defined. Fourth, the level of required awareness and performance impact of mixed fleet operations and failed-mode recovery must be explored.

Corker, Kevin M.↗

Development of a Two-Wheel Contingency Mode for the MAP Spacecraft

The Microwave Anisotropy Probe (MAP) is a follow-on mission to the Cosmic Background Explorer (COBE), and is currently collecting data from its orbit near the second Sun-Earth libration point. Due to limited mass, power, and financial resources, a traditional reliability concept including fully redundant components was not feasible for MAP. Instead, the MAP design employs selective hardware redundancy in tandem with contingency software modes and algorithms to improve the odds of mission success. One direction for such improvement has been the development of a two-wheel backup control strategy. This strategy would allow MAP to position itself for maneuvers and collect science data should one of its three reaction wheels fail. Along with operational considerations, the strategy includes three new control algorithms. These algorithms would use the remaining attitude control actuators-thrusters and two reaction wheels-in ways that achieve control goals while minimizing adverse impacts on the functionality of other subsystems and software.

Starin, Scott R.↗

Evaluating and Addressing Potential Hazards of Fuel Tanks Surviving Atmospheric Reentry

In order to ensure reentering spacecraft do not pose an undue risk to the Earth's population it is important to design satellites and rocket bodies with end of life considerations in mind. In addition to considering the possible consequences of deorbiting a vehicle, consideration must also be given to the possible risks associated with a vehicle failing to become operational or reach its intended orbit. Based on recovered space debris and numerous reentry survivability analyses, fuel tanks are of particular concern in both of these considerations. Most spacecraft utilize some type of fuel tank as part of their propulsion system. These fuel tanks are most often constructed using stainless steel or titanium and are filled with potentially hazardous substances such as hydrazine and nitrogen tetroxide. For a vehicle which has reached its scheduled end of mission the contents of the tanks are typically depleted. In this scenario the use of stainless steel and titanium results in the tanks posing a risk to people and property do to the high melting point and large heat of ablation of these materials leading to likely survival of the tank during reentry. If a large portion of the fuel is not depleted prior to reentry, there is the added risk of hazardous substance being released when the tank impact the ground. This paper presents a discussion of proactive methods which have been utilized by NASA satellite projects to address the risks associated with fuel tanks reentering the atmosphere. In particular it will address the design of a demiseable fuel tank as well as the evaluation of off the shelf designs which are selected to burst during reentry.

Kelley, Robert L.↗

SMAP science recovery efforts

The Soil Moisture Active Passive (SMAP) spacecraft launched in January 2015, with a mission to produce global soil moisture maps every 1.5 days using a combination of active (radar) and passive (radiometer) L-band measurements. In July 2015, after 2.5 months in operation, the radar failed and was not able to transmit. While the radiometer was still producing excellent science measurements, the need to recover key active-passive soil moisture requirements was paramount. To that end, the science team found that the European Space Agency (ESA) had recently launched a C-band SAR spacecraft called Sentinel-1A (launched April 2014) in a similar orbit, which was seen as a potential replacement to the “active” part of the SMAP measurements. An analysis was performed to see what the resulting spatial and temporal coverage could be. The promising results of that coupled with the ramp up in global coverage from Sentinel-1A and 1B (launched April 2016) allowed SMAP to create a new joint science data product that strives to meet the original mission objectives. The joint product is now part of the routine release of SMAP data to the science community as of June 2018.

Ballard, Christopher G.↗

Integrating Planning, Diagnosis and Execution for Vehicle Systems Management

We describe a prototype Vehicle System Manager (VSM) for NASA’s Gateway, a human-capable spacecraft that will also be capable of autonomous operations. The VSM consists of an execution system, planner, and fault management system, integrated via an over-arching mission management compo- nent. We describe the VSM architecture and each of its com- ponents. We describe a series of use cases, centered on a spacecraft propulsive operation that can fail at different times, for different reasons, and how the VSM detects and responds to these failures. We show the VSM is capable of detecting faults and loss of capability, and subsequently replanning, in the presence of each failure scenario.

Planning↗

Going beyond reliability to achieve robustness

Reliability is the ability to perform well and consistently. More formally, reliability is defined as the mathematical probability that a system does not fail during a specified time period under its specified operating conditions. The specified operating conditions often go beyond the nominal environment to include variations and challenges encountered in operational use. The difficulty is that systems are often operated outside of their specified operating conditions and, if they fail, the designers are in theory blameless. Unanticipated damaging events include internal failures, external disruptions in supporting systems, accidents, and repurposing. The most common explanation of a system failure is human error, which is usually the first assumption of the system designers. Robustness is the capability to perform without failure under a wide range of conditions that go beyond the specified operating conditions. The first step towards improving robustness would be to expand the system’s specified operating conditions to include a wider range of anticipated challenges, especially human error. Beyond this, there is a need for general approach to reduce the impact of unanticipated future events, the unknown unknowns, by improving the system’s general ability to cope. Robustness can be improved by providing additional processing capacity, larger flow control buffers, increased backup storage, more online redundancy, and more capable supervisory monitoring and control.

Harry W Jones↗

Cooling Performance and Structural Reliability of a Modified Corrugated-insert Air-cooled Turbine Blade with an Integrally Cast Shell and Base

A modified corrugated-insert blade with integrally cast shell and base was developed. This blade was as light as a conventional fabricated corrugated-insert blade. Of four test blades operated in a full-scale turbojet engine, one failed after about 15 hours operation at an inlet gas temperature of 1670 degrees F, a coolant-flow ratio of 0.0064, and a 1/3-span centrifugal stress of approximately 28,000 psi. Three other test blades ran for approximately 16, 31, and 36 hours without failure at similar conditions.

Freche, John C↗

ATS-6 - Cesium bombardment engine north-south stationkeeping experiment

Two 0.004 N thrust cesium bombardment ion thrustors have been developed and used for north-south stationkeeping in the geostationary Applications Technology Satellite-6 (ATS-6). The thrustor subsystems are mounted on the north and south faces of the earth viewing module such that 0.0026 N of thrust is applied normal to the orbit plane and 0.0036 N is applied radially upward. The change in the orbit inclination of the satellite is maintained at zero by operating the two thrustors alternately so that their thrust components, normal to the orbital plane, are symmetrically applied about the nodal crossings. Initial operation of the thrustors was successful. There was no interference with the satellite communications systems and the predicted spacecraft operating potential was verified. Subsequent trials failed due to a defect in the operation of the propellant reservoirs in zero g. A feed line valve is under development to correct this difficulty.

Worlock, R. M.↗

Fuel/hydraulic transfer valve improves reliability of Atlas space launch vehicle

The Atlas fuel hydraulic transfer valve design is described. The design satisfies primary goals such as fuel and oil isolation before launch in order to use existing ground support and airborne hardware and procedures. The valve operates only after the vehicle has been committed to launch. Hydraulic system function is maintained if the valve fails to function. Valve operation is mechanical and interfaces only with the propulsion system.

Ogman, M.↗

Segmented Coil Fails In Steps

Electromagnetic coil degrades in steps when faults occur, continues to operate at reduced level instead of failing catastrophically. Made in segments connected in series and separated by electrically insulating barriers. Fault does not damage adjacent components or create hazard. Used to control valves in such critical applications as cooling systems of power generators and chemical process equipment, where flammable liquids or gases handled. Also adapts to electrical control of motors.

Stedman, Ronald S.↗

Can Collaboration Succeed in Siting a Spent Nuclear Fuel Facility in the United States?—A Challenge in Political Sustainability

We examine the U.S. Department of Energy (DOE)’s collaborative process to locate, build, and operate one or more federal consolidated interim storage facilities (FCISFs) for commercial U.S. spent nuclear fuel—instead of continuing to store the material at over 70 nuclear reactor sites. Technocratic siting of nuclear facilities in the U.S., most of which did not involve meaningful public participation, was not successful. We consider increasing pressure to find at least one FCISF site, as well as the critical role of trust in engaging communities and reaching agreement—leading some observers to assert that DOE is in the “trust building business”, not the siting business. We present case studies with the following: (1) illustrating community engagement that led to a more satisfactory outcome than had been anticipated (Fernald); (2) a planned voluntary process that failed to produce an operating CISF (Office of the Nuclear Waste Negotiator); and (3) a site that demonstrates the ongoing need for negotiations to keep a site open and operational (Waste Isolation Pilot Plant). The essay concludes with the observation that a collaboration-based siting effort can succeed in the U.S., but that five main challenges—related to trust and requiring patience—will need to be addressed.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

A simple, accurate depth check guage

Easily made, pen-light battery operated production check gauge has probe-activated switch with fail-safe features to insure proper operation. Parts can be reliably and quickly checked. Gauge is equipped with tolerance band adjustment and can use interchangeable probes for different applications. Accompanying tester permits frequent check of calibration.

Rauch, E. P.↗

Automated Impact Assessment: A New Approach to ISS Payload Operations Anomaly Response

The International Space Station (ISS) Payload Operations and Integration Center (POIC) is undergoing rapid growth as the space station program focuses on science and commercial activities. The ISS is expanding its onboard capabilities to support additional science activities. In parallel, the POIC is expanding the capabilities of our operations tools to support the higher pace of payload activities being executed each week. An effect of these changes is that anomaly resolution has become more challenging. In the event of a real-time system fault, operators are responsible for analyzing telemetry displays, anomaly monitoring tools, documentation, and system models in order to produce failure impacts and recovery strategies. This approach to operations relies on the operator to ingest, process, and analyze information from an array of deterministic sources to provide actionable data on impacted systems and activities. Changing the existing approach of anomaly response is necessary if the ISS community is to succeed in the age of science and commercialization of space. The creation of a tool that captures deterministic technical systems knowledge and integrates existing telemetry, documentation, and planning information will allow the burden of impact assessment to be automated, thereby allowing the operator to focus on non-deterministic tasks, such as recovering failed systems and restoring critical payload operations.

Hall, R. Mason↗

Technological and Medical Human Health and Well-Being Options in Deep Space

Zeroth order, maintenance of human health requires supportive protection from the hazards of space, including supplying breathable air, comfortable temperatures, a supportive diet/nutrition, radiation protection, and sufficient gravity to avoid the combinatorial impacts of such effecting human operability and health. Spacecraft operability must be “fail-safe” to ensure these basic human life support conditions are maintained throughout the mission and the mission(s) must be affordable. There are known effects and unknowns effects regarding aspects of human health for Mars duration missions. Mars has the order of a third g. We have no data regarding the health impacts of this on humans or the combinatorial effects associated with 45% GCR on the Martian surface over time. There is a suspicion that if humans survive such conditions over long times they will evolve to living at reduced g and become “Martians”. Cascading failures and subcritical degradations in systems of systems causing an overall unrecoverable failure are a potential issue. There are two exremely complex systems associated with humans-Mars missions: the technical, engineering, and architectural system of systems that enable the mission and the humans. Both need to be mutually configured and operated to mitigate the overall risks and hazards of the mission. Regarding the humans that mitigation includes both the mission risks and supporting-to-increasing the human immune and other concomitant physiological systems. This report will summarize the risks, current mitigation approaches, and putative approaches including lifestyle, nutrition, and “wellness” approaches to possibly improve the human capacity to withstand the large number of combinatorial human physiological rigors of the missions. The wellness observations also apply to and are derived from Earth terrestrial applicable research.

Dennis M Bushnell↗

Advancing Li-plating detection: Motivating a multi-signal correlation approach

Facilitating fast charging in lithium-ion batteries (LiBs) is often linked to Li-plating, which harms performance, longevity, and safety. Early detection of Li-plating is essential for rapid technological development and for preventing performance deterioration and ensuring safety during operation. Fast and real-time detection, using commonly collected measurements like voltage (V), current (I), temperature (T), and pressure (P), is highly desirable. Existing standalone methods relying on electrochemical and mechanical signatures, using half, smaller, or specially designed cells often operated at lower temperatures, fail to account for real-world fast-charging conditions. These signatures may also have inherent unreliability in aged LiBs, a phenomenon currently not-well understood. All these uncertainties have complicated practical implementation of a robust Li-plating detection technique. This study, through multiple case studies involving real-world fast-charging conditions using automotive-grade 11.6 Ah LiBs, shows that many single signal-based diagnostic techniques may be inadequate to detect Li-plating. Among various signatures, end-of-charge rest pressure, differential pressure-sensing, and end-of-charge rest voltage were identified as particularly useful in detecting Li-plating. Furthermore, A multi-signal-based detection technique is shown to be more robust in detecting Li-plating. Using both fresh and aged cells, the results and analysis highlight how detection capabilities are influenced by various factors, including battery design, size, charging speed, operating temperature, and degradation level. Adopting such a multi-signal Li-plating detection approach may be instrumental in the rapid development of battery technology in laboratories, as well as ensuring the enhanced safety of next-generation LiBs in real-world fast-charging applications.

25 ENERGY STORAGE↗

Welding space vacuum technology

The objective was to assist the EH 42 Division in putting together a vacuum system that could attain the desired pressure and be large enough to accommodate the gas-metal arc (GMA) welding fixture apparatus. A major accomplishment was the design and fabrication of the controller/annunciator for the 4' by 8' system. It contains many safety features such as thermocouple set point relays that will only allow inlet and exit gas and vacuum valves to be operated at pre-selected system pressures, and a fail safe mode for power interruptions and operator mistakes. It is felt that significant progress was made in this research effort to weld in a vacuum environment. With continued efforts to increase the pump speeds for vacuum chambers and further studies on weld fixtures and gas inlet pressures, the NASA program will be successful.

Johnson, R. Barry↗

Enhancing EV Charging Station Resilience with Multifunctional Converter Leg Integration

In this paper, a multifunctional converter leg is integrated into an EV charger’s power circuit to enhance EV charging station resilience under power electronics converter device faults and grid outages. In the event of a device fault, it substitutes the failed converter leg, maintaining operation. During a grid outage, it assists the system as a fourth leg to the front-end converter, enabling grid-forming capability to supply power to the charging station critical loads while allowing limited power vehicle charging. The proposed approach’s effectiveness under both front-end power converter device faults and grid outage scenarios are validated through simulation and controller hardware-in-the-loop results.

Pereira Pinto, Joao [ORNL]↗