Search NASA⌕ Search

SEARCH · Search NASA

Results for “reliability requirements”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

A First and Second Order Moment Approach to Probabilistic Control Synthesis

This paper presents a robust control design methodology based on the estimation of the first two order moments of the random variables and processes that describe the controlled response. Synthesis is performed by solving an multi-objective optimization problem where stability and performance requirements in time- and frequency domains are integrated. The use of the first two order moments allows for the efficient estimation of the cost function thus for a faster synthesis algorithm. While reliability requirements are taken into account by using bounds to failure probabilities, requirements related to undesirable variability are implemented by quantifying the concentration of the random outcome about a deterministic target. The Hammersley Sequence Sampling and the First- and Second-Moment- Second-Order approximations are used to estimate the moments, whose accuracy and associated computational complexity are compared numerically. Examples using output-feedback and full-state feedback with state estimation are used to demonstrate the ideas proposed.

Crespo, Luis G.↗

Optimized Biasing of Pump Laser Diodes in a Highly Reliable Metrology Source for Long-Duration Space Missions

Optical metrology system reliability during a prolonged space mission is often limited by the reliability of pump laser diodes. We developed a metrology laser pump module architecture that meets NASA SIM Lite instrument optical power and reliability requirements by combining the outputs of multiple single-mode pump diodes in a low-loss, high port count fiber coupler. We describe Monte-Carlo simulations used to calculate the reliability of the laser pump module and introduce a combined laser farm aging parameter that serves as a load-sharing optimization metric. Employing these tools, we select pump module architecture, operating conditions, biasing approach and perform parameter sensitivity studies to investigate the robustness of the obtained solution.

808 mm diode pumps↗

Increasing Small Satellite Reliability- A Public-Private Initiative

At present, CubeSat components and buses are generally not appropriate for missions where significant risk of failure, or the inability to quantify risk or confidence, is acceptable. However, in the future we anticipate that CubeSats will be used for missions requiring reliability of 1-3 years for Earth-observing missions and even longer for Planetary, Heliophysics, and Astrophysics missions. Their growing potential utility is driving an interagency effort to improve and quantify CubeSat reliability, and more generally, small satellite mission risk. The Small Satellite Reliability Initiative (SSRI)—an ongoing activity with broad collaborative participation from civil, DoD, and commercial space systems providers and stakeholders—targets this challenge. The Initiative seeks to define implementable and broadly-accepted approaches to achieve reliability and acceptable risk postures associated with several SmallSat mission risk classes—from “do no harm” missions, to those associated with missions whose failure would result in loss or delay of key national objectives. These approaches will maintain, to the extent practical, cost efficiencies associated with small satellite missions and consider constraints associated with supply chain elements, as appropriate. The SSRI addresses this challenge from two architectural levels—the mission- or system-level, and the component- or subsystem-level. The mission- or system-level scope targets assessment approaches that are efficient and effective, with mitigation strategies that facilitate resiliency to mission or system anomalies while the component- or subsystem-level scope addresses the challenge at lower architectural levels. The initiative does not limit strategies and approaches to proven and traditional methodologies, but is focused on fomenting thought on novel and innovative solutions. This paper discusses the genesis of and drivers for this initiative, how the public-private collaboration is being executed, findings and recommendations derived to date, and next steps towards broadening small satellite mission potential.

SmallSat↗

Tokamak Disruption Simulation (Final Technical Report)

The Tokamak Disruption Simulation collaboration was a SciDAC (Scientific Discovery through Advanced Computing) program led by Xianzhu Tang of the Los Alamos National Laboratory but with separate grants to each institution. I was the PI for Columbia University and the only person at Columbia directly funded by this SciDAC. Disruptions are a sudden loss of confinement in tokamaks, and a reliable method of preventing disruptions must be developed before tokamak fusion power plants become feasible. A related plasma confinement concept, the stellarator, is the only way known way of preventing disruptions with the required reliability. The largest devices, both existing and under construction, for confining plasmas for fusion using magnetic fields are tokamaks, so it is important to solve their disruption issues. The sudden loss of confinement in tokamaks can be from a bit of material falling into the plasma, which causes the plasma energy to be quickly lost by radiation, or by an instability causing a breakup of the confining surfaces formed by the magnetic field. This breakup can occur more than a million times faster than one would naively think possible. The sudden breakup of surfaces is called a fast magnetic reconnection and also results in a sudden cooling of the plasma.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Information and display requirements for independent landing monitors

The ways an Independent Landing Monitor (ILM) may be used to complement the automatic landing function were studied. In particular, a systematic procedure was devised to establish the information and display requirements of an ILM during the landing phase of the flight. Functionally, the ILM system is designed to aid the crew in assessing whether the total system (e.g., avionics, aircraft, ground navigation aids, external disturbances) performance is acceptable, and, in case of anomaly, to provide adequate information to the crew to select the least unsafe of the available alternatives. Economically, this concept raises the possibility of reducing the primary autoland system redundancy and associated equipment and maintenance costs. The required level of safety for the overall system would in these cases be maintained by upgrading the backup manual system capability via the ILM. A safety budget analysis was used to establish the reliability requirements for the ILM. These requirements were used as constraints in devising the fault detection scheme. Covariance propagation methods were used with a linearized system model to establish the time required to correct manually perturbed states due to the fault. Time-to-detect and time-to-correct requirements were combined to devise appropriate altitudes and strategies for fault recovery.

Karmarker, J. S.↗

Interrelation Between Safety Factors and Reliability

An evaluation was performed to establish relationships between safety factors and reliability relationships. Results obtained show that the use of the safety factor is not contradictory to the employment of the probabilistic methods. In many cases the safety factors can be directly expressed by the required reliability levels. However, there is a major difference that must be emphasized: whereas the safety factors are allocated in an ad hoc manner, the probabilistic approach offers a unified mathematical framework. The establishment of the interrelation between the concepts opens an avenue to specify safety factors based on reliability. In cases where there are several forms of failure, then the allocation of safety factors should he based on having the same reliability associated with each failure mode. This immediately suggests that by the probabilistic methods the existing over-design or under-design can be eliminated. The report includes three parts: Part 1-Random Actual Stress and Deterministic Yield Stress; Part 2-Deterministic Actual Stress and Random Yield Stress; Part 3-Both Actual Stress and Yield Stress Are Random.

Elishakoff, Isaac↗

Improved Aerothermal Reliability Analysis Enabled by the Mars Sample Return Earth Entry System Aerothermal Database

The Mars Sample Return (MSR) campaign is a series of missions designed to retrieve Martian rock and soil samples for detailed study on Earth. The campaign is split into three primary phases: sample collection with the Mars2020 rover, retrieval with the Sample Return Lander (SRL) and Mars Ascent Vehicle (MAV), and then return to Earth with the Earth Return Orbiter (ERO) and Capture, Containment, and Return System (CCRS) [1]. The final sequence in the Earth return phase is the delivery and entry of the Earth Entry System (EES) sample return capsule. Due to unprecedented planetary protection concerns, the sample return capsule is subject to strict reliability requirements. To this end, the MSR-EES aerothermal team has implemented a flexible aerothermal database architecture capable of integration with state-of-the-art trajectory codes to provide a more rigorous aerothermal reliability analysis. The EES database enables the generation of environments at any location on the heatshield and can incorporate trajectory uncertainties to both statistically quantify aerothermal environments for arcjet testing and produce material response boundary conditions to rigorously select thermal protection system (TPS) sizing environments. This poster will not discuss the fundamental modeling assumptions included in the database, and will instead focus on the downstream reliability analyses that can be performed with a database of this architecture.

MSR-EES↗

DRIRU I/SKIRU - The application of the DTG to spacecraft attitude control

The dynamically tuned gyro (DTG) was developed to replace the floated, rate integrating gyro used for space attitude control, as the DTG fulfills cost, performance, and reliability requirements not satisfied by its predecessor. The use of this gyro in the Dry Gyro Inertial Reference Unit I (DRIRU I) marked the first application of a DTG in a spacecraft attitude reference unit. Design and performance characteristics of DTG application in the Singer-Kearfott Inertial Reference Unit (SKIRU) are outlined, for example its minimal weight (7 lb), and operational reliability. The DTG has accomplished 156,000 failure-free hours, and a chart, logging test performance, indicates that this and other requirements were more than sufficiently satisfied. The unit has an unparalleled life span, with several units still operating after 70,000 to 130,000 hours, and a random drift which always remains under 0.0005 deg/h. Potential for improvements, such as drift performance, are considered.

Swanson, C. O.↗

The development and test of a long-life, high reliability solar array drive actuator

To meet the life and reliability requirements of five to ten year space missions, a new solar array drive mechanism for 3-axis stabilized vehicles has been developed and is undergoing life testing. The drive employs a redundant lubrication system to increase its reliability. An overrunning clutch mechanism is used to permit block redundant application of two or more drives to a common array drive shaft. Two prototype actuator and clutch assemblies, in continuous vacuum life test under load at 10 to the minus 8th power torr for more than sixteen months, have each accumulated more than 34,000 output revolutions without anomaly, the equivalent of more than seven years of operation in a 1000 km orbit or nearly ninety-five years at synchronous altitude.

Kirkpatrick, D. L.↗

Cyclone: A close air support aircraft for tomorrow

To meet the threat of the battlefield of the future, the U.S. ground forces will require reliable air support. To provide this support, future aircrews demand a versatile close air support aircraft capable of delivering ordinance during the day, night, or in adverse weather with pin-point accuracy. The Cyclone aircraft meets these requirements, packing the 'punch' necessary to clear the way for effective ground operations. Possessing anti-armor, missile, and precision bombing capability, the Cyclone will counter the threat into the 21st Century. Here, it is shown that the Cyclone is a realistic, economical answer to the demand for a capable close air support aircraft.

Cox, George↗

A proposed group management scheme for XTP multicast

The purpose of a group management scheme is to enable its associated transfer layer protocol to be responsive to user determined reliability requirements for multicasting. Group management (GM) must assist the client process in coordinating multicast group membership, allow the user to express the subset of the multicast group that a particular multicast distribution must reach in order to be successful (reliable), and provide the transfer layer protocol with the group membership information necessary to guarantee delivery to this subset. GM provides services and mechanisms that respond to the need of the client process or process level management protocols to coordinate, modify, and determine attributes of the multicast group, especially membership. XTP GM provides a link between process groups and their multicast groups by maintaining a group membership database that identifies members in a name space understood by the underlying transfer layer protocol. Other attributes of the multicast group useful to both the client process and the data transfer protocol may be stored in the database. Examples include the relative dispersion, most recent update, and default delivery parameters of a group.

Dempsey, Bert J.↗

Identification and Study of Validation Level Test Cases for Computational Modeling of Non-Charring Ablators

Computational modeling of Thermal Protection System (TPS) materials, used for aerospace applications, provides numerous advantages in preliminary selection and design of a heatshield material and shape for atmospheric entry vehicles. However, to serve as a reliable tool for prediction of material thermal and ablative behavior, the modeling approach needs to be validated against real experimental and flight data, preferably at a range of applied conditions. The validation study is typically very complex as it requires reliable measured data not only for the material thermal response and surface recession, but also well characterized environmental conditions. The validation problem becomes even more complex when the material thermal response is dictated by multi-physics effects such as solid conduction, in-depth thermal decomposition, pyrolysis gas flow and chemical reactions. The multi-physics effects complicate not only the modeling effort, but also the experimental measurement for validation of various aspects of the highly coupled problem. In this study, an attempt is made to identify suitable experimental data that could serve as a source for validation of material thermal response modeling tools. To reduce the computational complexity, this study focuses only on non-charring ablators, where the material thermal response could be modeled with a single governing equation for solid conduction and the ablation is limited only to the surface of the material. With a well characterized and publicly available experimental data being sparse, the study is limited in presenting test cases for only three materials: camphor, graphite and FiberForm® in the sequence of increased modeling complexity. Graphite is a commonly used TPS material for aerospace applications, both for leading edges of high-speed vehicles and internal insulation of solid rocket motors. FiberForm® is a porous carbon pre-form used in preparation of the well known PICA material Tran et al. [1996]. Inclusion of camphor into the list is conditioned with the relative simplicity in modeling the material thermal and chemical response and the low-enthalpy flow environment. In addition, camphor has been used as a simple test material for study of flow transition behavior by Stock and Ginoux [1973] and assessment of a heatshield shape change at flight relevant conditions by Rotondi et al. [2022]. In this work, the identified experimental data was extracted from the public literature and test cases that yet have been published. As it was found from the review, not a single test case contains an exhaustive set of data that would validate every aspect of the material physics. However, in the data collected, various aspects of the material behavior can be still validated, such as surface and in-depth temperature, amount of recession and a shape change. The identified experimental data for each case is accompanied with a characterized flow environment and simulated boundary conditions predicted by a Data-Parallel Line Relaxation (DPLR) code Wright et al. [1998]. In addition, material thermal response numerical simulations in each test case are performed with Kentucky Aerothermodynamics and Thermal Response System (KATS-MR) Zibitsker et al. [2022] providing a comparative study and a sanity check for the proposed validation data. Sample results from the performed numerical study are shown below. Figure 1 shows distribution of surface heat flux and pressure values on a hemi-cylinder model made of FiberForm® and tested in HyMETS arc-jet facility. The results are shown for the high pressure condition among the two tests. Flow simulation was performed with DPLR code on a quarter of original geometry. In the figure, the quarter shape was mirrored across zx and xy planes to show the complete distribution. Figure 2 shows the material response results for the high pressure case (7500 Pa), simulated with KATS-MR and a comparison to the experimental data for the surface temperature and shape shape. The simulation was performed on a 2-D slice, extracted in the xy plane at the middle of the sample. Figure 3 shows the material response simulation for the low pressure case (3500 Pa) and a comparison to the experimental data for surface temperature and shape change.

ablation↗

Hierarchical specification of the SIFT fault tolerant flight control system

The specification and mechanical verification of the Software Implemented Fault Tolerance (SIFT) flight control system is described. The methodology employed in the verification effort is discussed, and a description of the hierarchical models of the SIFT system is given. To meet the objective of NASA for the reliability of safety critical flight control systems, the SIFT computer must achieve a reliability well beyond the levels at which reliability can be actually measured. The methodology employed to demonstrate rigorously that the SIFT computer meets as reliability requirements is described. The hierarchy of design specifications from very abstract descriptions of system function down to the actual implementation is explained. The most abstract design specifications can be used to verify that the system functions correctly and with the desired reliability since almost all details of the realization were abstracted out. A succession of lower level models refine these specifications to the level of the actual implementation, and can be used to demonstrate that the implementation has the properties claimed of the abstract design specifications.

Melliar-Smith, P. M.↗

System Analysis and Performance Benefits of an Optimized Rotorcraft Propulsion System

The propulsion system of rotorcraft vehicles is the most critical system to the vehicle in terms of safety and performance. The propulsion system must provide both vertical lift and forward flight propulsion during the entire mission. Whereas propulsion is a critical element for all flight vehicles, it is particularly critical for rotorcraft due to their limited safe, un-powered landing capability. This unparalleled reliability requirement has led rotorcraft power plants down a certain evolutionary path in which the system looks and performs quite similarly to those of the 1960 s. By and large the advancements in rotorcraft propulsion have come in terms of safety and reliability and not in terms of performance. The concept of the optimized propulsion system is a means by which both reliability and performance can be improved for rotorcraft vehicles. The optimized rotorcraft propulsion system which couples an oil-free turboshaft engine to a highly loaded gearbox that provides axial load support for the power turbine can be designed with current laboratory proven technology. Such a system can provide up to 60% weight reduction of the propulsion system of rotorcraft vehicles. Several technical challenges are apparent at the conceptual design level and should be addressed with current research.

Bruckner, Robert J.↗

Data Applicability of Heritage and New Hardware For Launch Vehicle Reliability Models

Bayesian reliability requires the development of a prior distribution to represent degree of belief about the value of a parameter (such as a component's failure rate) before system specific data become available from testing or operations. Generic failure data are often provided in reliability databases as point estimates (mean or median). A component's failure rate is considered a random variable where all possible values are represented by a probability distribution. The applicability of the generic data source is a significant source of uncertainty that affects the spread of the distribution. This presentation discusses heuristic guidelines for quantifying uncertainty due to generic data applicability when developing prior distributions mainly from reliability predictions.

Al Hassan, Mohammad↗

Reliable "Unlatch"

Reliable unlatching mechanism utilizes preloading, a favorable geometric arrangement of mating surfaces, and redundancy to assure release. Even if only one rocking arm initially releases, the entire assembly will rotate or rock sideways to complete unlatching. Device could be useful in other applications requiring reliable remote disconnection of cables or pipes.

Killgrove, T. O.↗

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures↗

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures↗