Search NASA⌕ Search

SEARCH · Search NASA

Results for “Fault Injection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

140 records · Page 8

Automated Generation and Assessment of Autonomous Systems Test Cases

This slide presentation reviews some of the issues concerning verification and validation testing of autonomous spacecraft routinely culminates in the exploration of anomalous or faulted mission-like scenarios using the work involved during the Dawn mission's tests as examples. Prioritizing which scenarios to develop usually comes down to focusing on the most vulnerable areas and ensuring the best return on investment of test time. Rules-of-thumb strategies often come into play, such as injecting applicable anomalies prior to, during, and after system state changes; or, creating cases that ensure good safety-net algorithm coverage. Although experience and judgment in test selection can lead to high levels of confidence about the majority of a system's autonomy, it's likely that important test cases are overlooked. One method to fill in potential test coverage gaps is to automatically generate and execute test cases using algorithms that ensure desirable properties about the coverage. For example, generate cases for all possible fault monitors, and across all state change boundaries. Of course, the scope of coverage is determined by the test environment capabilities, where a faster-than-real-time, high-fidelity, software-only simulation would allow the broadest coverage. Even real-time systems that can be replicated and run in parallel, and that have reliable set-up and operations features provide an excellent resource for automated testing. Making detailed predictions for the outcome of such tests can be difficult, and when algorithmic means are employed to produce hundreds or even thousands of cases, generating predicts individually is impractical, and generating predicts with tools requires executable models of the design and environment that themselves require a complete test program. Therefore, evaluating the results of large number of mission scenario tests poses special challenges. A good approach to address this problem is to automatically score the results based on a range of metrics. Although the specific means of scoring depends highly on the application, the use of formal scoring - metrics has high value in identifying and prioritizing anomalies, and in presenting an overall picture of the state of the test program. In this paper we present a case study based on automatic generation and assessment of faulted test runs for the Dawn mission, and discuss its role in optimizing the allocation of resources for completing the test program.

Testing challenges↗

Synthetic Failure Mode Generation for Resilience Analysis and Failure Mechanism Discovery

Traditional risk-based design processes seek to mitigate operational hazards by manually identifying possible faults and corresponding mitigation strategies—a tedious process which critically relies on the designer’s limited knowledge. Resilience-based design, on the other hand, seeks to embody generic hazard-mitigating properties in the system to mitigate unknown hazards, often by modelling the system's response to potential hazardous events. This work adapts this approach to the traditional risk-based design process to synthetically generate hazardous modes, by representing them as a unique combination of internal component health-states which can then be injected and simulated in a model of the system failure dynamics. The design process may then reduce the risk of unknown internal hazards by iteratively mitigating the effects of these modes. The performance of this approach is evaluated in a model of an autonomous rover, where cluster analysis shows that elaborating the space of synthetic faults in the drive system using this approach uncovers a wider range of possible hazardous trajectories and failure consequences within each trajectory. However, this increase in hazard information comes at a high computational expense, highlighting the need for advanced, efficient methods to search and sample the hazard space.

Simulation↗

Synthetic Failure Mode Generation for Resilience Analysis and Failure Mechanism Discovery

Traditional risk-based design processes seek to mitigate operational hazards by manually identifying possible faults and corresponding mitigation strategies—a tedious process which critically relies on the designer’s limited knowledge. Resilience-based design, on the other hand, seeks to embody generic hazard-mitigating properties in the system to mitigate unknown hazards, often by modelling the system's response to potential hazardous events. This work adapts this approach to the traditional risk-based design process to synthetically generate hazardous modes, by representing them as a unique combination of internal component health-states which can then be injected and simulated in a model of the system failure dynamics. The design process may then reduce the risk of unknown internal hazards by iteratively mitigating the effects of these modes. The performance of this approach is evaluated in a model of an autonomous rover, where cluster analysis shows that elaborating the space of synthetic faults in the drive system using this approach uncovers a wider range of possible hazardous trajectories and failure consequences within each trajectory. However, this increase in hazard information comes at a high computational expense, highlighting the need for advanced, efficient methods to search and sample the hazard space.

Simulation↗

Application of the integrated modular engine (IME) to space vehicle concepts

The incorporation of integrated modular engines (IME) in space vehicles offers attractive benefits which include improved system reliability and fault tolerance, increased I(sp) and thrust/weight ratio, and improved operability and maintainability. This paper summarizes a study that was performed to define concepts for three cryogenic space vehicles incorporating the IME: a trans-lunar injection stage, a lunar lander, and an upper stage for a launch vehicle. The goals of the study were to quantify potential IME benefits, identify issues that must be addressed, and define the technical and programmatic actions required to develop the IME.

Cramer, John M.↗

Space Launch Systems Block 1B Preliminary Navigation System Design

NASA is currently building the Space Launch Systems (SLS) Block 1 launch vehicle for the Exploration Mission 1 (EM-1) test flight. In parallel, NASA is also designing the Block 1B launch vehicle. The Block 1B vehicle is an evolution of the Block 1 vehicle and extends the capability of the NASA launch vehicle. This evolution replaces the Interim Cryogenic Propulsive Stage (ICPS) with the Exploration Upper Stage (EUS). As the vehicle evolves to provide greater lift capability, increased robustness for manned missions, and the capability to execute more demanding missions so must the SLS Integrated Navigation System evolved to support those missions. This paper describes the preliminary navigation systems design for the SLS Block 1B vehicle. The evolution of the navigation hard-ware and algorithms from an inertial-only navigation system for Block 1 ascent flight to a tightly coupled GPS-aided inertial navigation system for Block 1B is described. The Block 1 GN&C system has been designed to meet a LEO insertion target with a specified accuracy. The Block 1B vehicle navigation system is de-signed to support the Block 1 LEO target accuracy as well as trans-lunar or trans-planetary injection accuracy. Additionally, the Block 1B vehicle is designed to support human exploration and thus is designed to minimize the probability of Loss of Crew (LOC) through high-quality inertial instruments and robust algorithm design, including Fault Detection, Isolation, and Recovery (FDIR) logic.

Oliver, T. Emerson↗

Non-Intrusive Cable Tester

A cable tester is described for low frequency testing of a cable for faults. The tester allows for testing a cable beyond a point where a signal conditioner is installed, minimizing the number of connections which have to be disconnected. A magnetic pickup coil is described for detecting a test signal injected into the cable. A narrow bandpass filter is described for increasing detection of the test signal. The bandpass filter reduces noise so that a high gain amplifier provided for detecting a test signal is not completely saturate by noise. To further increase the accuracy of the cable tester, processing gain is achieved by comparing the signal from the amplifier with at least one reference signal emulating the low frequency input signal injected into the cable. Different processing techniques are described evaluating a detected signal.

Medelius, Pedro J.↗

Early Oscillation Detection for DC/DC Converter Fault Diagnosis

The electrical power system of a spacecraft plays a very critical role for space mission success. Such a modern power system may contain numerous hybrid DC/DC converters both inside the power system electronics (PSE) units and onboard most of the flight electronics modules. One of the faulty conditions for DC/DC converter that poses serious threats to mission safety is the random occurrence of oscillation related to inherent instability characteristics of the DC/DC converters and design deficiency of the power systems. To ensure the highest reliability of the power system, oscillations in any form shall be promptly detected during part level testing, system integration tests, flight health monitoring, and on-board fault diagnosis. The popular gain/phase margin analysis method is capable of predicting stability levels of DC/DC converters, but it is limited only to verification of designs and to part-level testing on some of the models. This method has to inject noise signals into the control loop circuitry as required, thus, interrupts the DC/DC converter's normal operation and increases risks of degrading and damaging the flight unit. A novel technique to detect oscillations at early stage for flight hybrid DC/DC converters was developed.

Wang, Bright L.↗

Compact, Low-Force, Low-Noise Linear Actuator

Actuators are critical to all the robotic and manipulation mechanisms that are used in current and future NASA missions, and are also needed for many other industrial, aeronautical, and space activities. There are many types of actuators that were designed to operate as linear or rotary motors, but there is still a need for low-force, low-noise linear actuators for specialized applications, and the disclosed mechanism addresses this need. A simpler implementation of a rotary actuator was developed where the end effector controls the motion of a brush for cleaning a thermal sensor. The mechanism uses a SMA (shape-memory alloy) wire for low force, and low noise. The linear implementation of the actuator incorporates a set of springs and mechanical hard-stops for resetting and fault tolerance to mechanical resistance. The actuator can be designed to work in a pull or push mode, or both. Depending on the volume envelope criteria, the actuator can be configured for scaling its volume down to 4 2 1 cm3. The actuator design has an inherent fault tolerance to mechanical resistance. The actuator has the flexibility of being designed for both linear and rotary motion. A specific configuration was designed and analyzed where fault-tolerant features have been implemented. In this configuration, an externally applied force larger than the design force does not damage the active components of the actuator. The actuator housing can be configured and produced using cost-effective methods such as injection molding, or alternatively, its components can be mounted directly on a small circuit board. The actuator is driven by a SMA -NiTi as a primary active element, and it requires energy on the order of 20 Ws(J) per cycle. Electrical connections to points A and B are used to apply electrical power in the resistive NiTi wire, causing a phase change that contracts the wire on the order of 5%. The actuation period is of the order of a second for generating the stroke, and 4 to 10 seconds for resetting. Thus, this design allows the actuator to work at a frequency of up to 0.1 Hz. The actuator does not make use of the whole range of motion of the SMA material, allowing for large margins on the mechanical parameters of the design. The efficiency of the actuator is of the order of 10%, including the margins. The average dissipated power while driving at full speed is of the order of 1 W, and can be scaled down linearly if the rate of cycling is reduced. This design produces an extremely quiet actuator; it can generate a force greater than 2 N and a stroke greater than 1 cm. The operational duration of SMA materials is of the order of millions of cycles with some reduced stroke over a wide temperature range up to 150 C.

Badescu, Mircea↗

Compact, Low-Force, Low-Noise Linear Actuator

Actuators are critical to all the robotic and manipulation mechanisms that are used in current and future NASA missions, and are also needed for many other industrial, aeronautical, and space activities. There are many types of actuators that were designed to operate as linear or rotary motors, but there is still a need for low-force, low-noise linear actuators for specialized applications, and the disclosed mechanism addresses this need. A simpler implementation of a rotary actuator was developed where the end effector controls the motion of a brush for cleaning a thermal sensor. The mechanism uses a SMA (shape-memory alloy) wire for low force, and low noise. The linear implementation of the actuator incorporates a set of springs and mechanical hard-stops for resetting and fault tolerance to mechanical resistance. The actuator can be designed to work in a pull or push mode, or both. Depending on the volume envelope criteria, the actuator can be configured for scaling its volume down to 4x2x1 cu cm. The actuator design has an inherent fault tolerance to mechanical resistance. The actuator has the flexibility of being designed for both linear and rotary motion. A specific configuration was designed and analyzed where fault-tolerant features have been implemented. In this configuration, an externally applied force larger than the design force does not damage the active components of the actuator. The actuator housing can be configured and produced using cost-effective methods such as injection molding, or alternatively, its components can be mounted directly on a small circuit board. The actuator is driven by a SMA -NiTi as a primary active element, and it requires energy on the order of 20 Ws(J) per cycle. Electrical connections to points A and B are used to apply electrical power in the resistive NiTi wire, causing a phase change that contracts the wire on the order of 5%. The actuation period is of the order of a second for generating the stroke, and 4 to 10 seconds for resetting. Thus, this design allows the actuator to work at a frequency of up to 0.1 Hz. The actuator does not make use of the whole range of motion of the SMA material, allowing for large margins on the mechanical parameters of the design. The efficiency of the actuator is of the order of 10%, including the margins. The average dissipated power while driving at full speed is of the order of 1 W, and can be scaled down linearly if the rate of cycling is reduced. This design produces an extremely quiet actuator; it can generate a force greater than 2 N and a stroke greater than 1 cm. The operational duration of SMA materials is of the order of millions of cycles with some reduced stroke over a wide temperature range up to 150 C.

Badescu, Mircea↗

Parametric Testing of Launch Vehicle FDDR Models

For the safe operation of a complex system like a (manned) launch vehicle, real-time information about the state of the system and potential faults is extremely important. The on-board FDDR (Failure Detection, Diagnostics, and Response) system is a software system to detect and identify failures, provide real-time diagnostics, and to initiate fault recovery and mitigation. The ERIS (Evaluation of Rocket Integrated Subsystems) failure simulation is a unified Matlab/Simulink model of the Ares I Launch Vehicle with modular, hierarchical subsystems and components. With this model, the nominal flight performance characteristics can be studied. Additionally, failures can be injected to see their effects on vehicle state and on vehicle behavior. A comprehensive test and analysis of such a complicated model is virtually impossible. In this paper, we will describe, how parametric testing (PT) can be used to support testing and analysis of the ERIS failure simulation. PT uses a combination of Monte Carlo techniques with n-factor combinatorial exploration to generate a small, yet comprehensive set of parameters for the test runs. For the analysis of the high-dimensional simulation data, we are using multivariate clustering to automatically find structure in this high-dimensional data space. Our tools can generate detailed HTML reports that facilitate the analysis.

Schumann, Johann↗

SLS Block 1-B and Exploration Upper Stage Navigation System Design

The SLS Block 1B vehicle is planned to extend NASA's heavy lift capability beyond the initial SLS Block 1 vehicle. The most noticeable change for this vehicle from SLS Block 1 is the swapping of the upper stage from the Interim Cryogenic Propulsion stage (ICPS), a modified Delta IV upper stage, to the more capable Exploration Upper Stage (EUS). As the vehicle evolves to provide greater lift capability and execute more demanding missions so must the SLS Integrated Navigation System to support those missions. The SLS Block 1 vehicle carries two independent navigation systems. The responsibility of the two systems is delineated between ascent and upper stage flight. The Block 1 navigation system is responsible for the phase of flight between the launch pad and insertion into Low-Earth Orbit (LEO). The upper stage system assumes the mission from LEO to payload separation. For the Block 1B vehicle, the two functions are combined into a single system intended to navigate from ground to payload insertion. Both are responsible for self-disposal once payload delivery is achieved. The evolution of the navigation hardware and algorithms from an inertial-only navigation system for Block 1 ascent flight to a tightly coupled GPS-aided inertial navigation system for Block 1-B is described. The Block 1 GN&C system has been designed to meet a LEO insertion target with a specified accuracy. The Block 1-B vehicle navigation system is designed to support the Block 1 LEO target accuracy as well as trans-lunar or trans-planetary injection accuracy. This is measured in terms of payload impact and stage disposal requirements. Additionally, the Block 1-B vehicle is designed to support human exploration and thus is designed to minimize the probability of Loss of Crew (LOC) through high-quality inertial instruments and Fault Detection, Isolation, and Recovery (FDIR) logic. The preliminary Block 1B integrated navigation system design is presented along with the challenges associated with meeting the design objectives. This paper also addresses the design considerations associated with the use of Block 1 and Commercial Off-the-Shelf (COTS) avionics for Block 1-B/EUS as part of an integrated vehicle suite for orbital operations.

Oliver, T. Emerson↗

Design for testability and diagnosis at the system-level

The growing complexity of full-scale systems has surpassed the capabilities of most simulation software to provide detailed models or gate-level failure analyses. The process of system-level diagnosis approaches the fault-isolation problem in a manner that differs significantly from the traditional and exhaustive failure mode search. System-level diagnosis is based on a functional representation of the system. For example, one can exercise one portion of a radar algorithm (the Fast Fourier Transform (FFT) function) by injecting several standard input patterns and comparing the results to standardized output results. An anomalous output would point to one of several items (including the FFT circuit) without specifying the gate or failure mode. For system-level repair, identifying an anomalous chip is sufficient. We describe here an information theoretic and dependency modeling approach that discards much of the detailed physical knowledge about the system and analyzes its information flow and functional interrelationships. The approach relies on group and flow associations and, as such, is hierarchical. Its hierarchical nature allows the approach to be applicable to any level of complexity and to any repair level. This approach has been incorporated in a product called STAMP (System Testability and Maintenance Program) which was developed and refined through more than 10 years of field-level applications to complex system diagnosis. The results have been outstanding, even spectacular in some cases. In this paper we describe system-level testability, system-level diagnoses, and the STAMP analysis approach, as well as a few STAMP applications.

Simpson, William R.↗

Performance analysis of a fault inferring nonlinear detection system algorithm with integrated avionics flight data

This paper presents the performance analysis results of a fault inferring nonlinear detection system (FINDS) using integrated avionics sensor flight data for the NASA ATOPS B-737 aircraft in a Microwave Landing System (MLS) environment. First, an overview of the FINDS algorithm structure is given. Then, aircraft state estimate time histories and statistics for the flight data sensors are discussed. This is followed by an explanation of modifications made to the detection and decision functions in FINDS to improve false alarm and failure detection performance. Next, the failure detection and false alarm performance of the FINDS algorithm are analyzed by injecting bias failures into fourteen sensor outputs over six repetitive runs of the five minutes of flight data. Results indicate that the detection speed, failure level estimation, and false alarm performance show a marked improvement over the previously reported simulation runs. In agreement with earlier results, detection speed is faster for filter measurement sensors such as MLS than for filter input sensors such as flight control accelerometers. Finally, the progress in modifications of the FINDS algorithm design to accommodate flight computer constraints is discussed.

Caglayan, A. K.↗

Evaluation of a fault tolerant system for an integrated avionics sensor configuration with TSRV flight data

The performance analysis results of a fault inferring nonlinear detection system (FINDS) using sensor flight data for the NASA ATOPS B-737 aircraft in a Microwave Landing System (MLS) environment is presented. First, a statistical analysis of the flight recorded sensor data was made in order to determine the characteristics of sensor inaccuracies. Next, modifications were made to the detection and decision functions in the FINDS algorithm in order to improve false alarm and failure detection performance under real modelling errors present in the flight data. Finally, the failure detection and false alarm performance of the FINDS algorithm were analyzed by injecting bias failures into fourteen sensor outputs over six repetitive runs of the five minute flight data. In general, the detection speed, failure level estimation, and false alarm performance showed a marked improvement over the previously reported simulation runs. In agreement with earlier results, detection speed was faster for filter measurement sensors soon as MLS than for filter input sensors such as flight control accelerometers.

Caglayan, A. K.↗