Search NASA⌕ Search

SEARCH · Search NASA

Results for “REDUNDANT SYSTEM”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

A three-failure-tolerant computer system.

Two basic factors influence the design of highly reliable computer systems: the amount of failures required to be tol erated and the reliability or MTBF required. A computer system designed to tolerate any three single failures in a fail-operational-fail-operational-fail-safe manner for a real-time control application is presented. The design approach uses adaptive majority voting in both hardware and software with a four-level redundant system. Various methods of performing the adaptive majority voting functions were evaluated with the selected approach using a special module termed a voter-comparator switch (VCS). The VCS module allows the computer system to be operated in a variety of redundant modes, depending on the failure tolerance required at any particular time.

Koczela, L. J.↗

Measuring the Liquid Helium Volume on XRISM and Predicting the Liquid Lifetime

The XRISM/Resolve instrument uses an adiabatic demagnetization refrigerator (ADR) to cool microcalorimeters to 50 mK. The cryogenic system to support the ADR consists of a liquid helium dewar and 5 cryocoolers that provide a semi-redundant system. Operation of the ADR requires either a liquid helium heat sink at 1.2 K or 4.5 K heat sink provided by a multi-stage cryocooler system. The 5 cryocoolers also provide thermal protection to the liquid helium dewar. To calculate the expected lifetime of the liquid helium system, the liquid helium volume was measured before launch and several techniques were employed to determine on-orbit boil off rate.

Michael Dipirro↗

Common Cause Failures and Ultra Reliability

A common cause failure occurs when several failures have the same origin. Common cause failures are either common event failures, where the cause is a single external event, or common mode failures, where two systems fail in the same way for the same reason. Common mode failures can occur at different times because of a design defect or a repeated external event. Common event failures reduce the reliability of on-line redundant systems but not of systems using off-line spare parts. Common mode failures reduce the dependability of systems using off-line spare parts and on-line redundancy.

reliability↗

SP-100 power system conceptual design for lunar base applications

A conceptual design is presented for a nuclear power system utilizing an SP-100 reactor and multiple Stirling cycle engines for operation on the lunar surface. Based on the results of this study, it was concluded that this power plant could be a viable option for an evolutionary lunar base. The design concept consists of a 2500 kWt (kilowatt thermal) SP-100 reactor coupled to eight free-piston Stirling engines. Two of the engines are held in reserve to provide conversion system redundancy. The remaining engines operate at 91.7 percent of their rated capacity of 150 kWe. The design power level for this system is 825 kWe. Each engine has a pumped heat-rejection loop connected to a heat pipe radiator. Power system performance, sizing, layout configurations, shielding options, and transmission line characteristics are described. System components and integration options are compared for safety, high performance, low mass, and ease of assembly. The power plant was integrated with a proposed human lunar base concept to ensure mission compatibility. This study should be considered a preliminary investigation; further studies are planned to investigate the effect of different technologies on this baseline design.

Mason, Lee S.↗

Some effects of bias errors in redundant flight control systems.

The controllability and steady-state response of parallel-redundant flight control systems are examined. It is found that state components which appear in the parallel signal paths, e.g., individual actuator commands, are not controllable, although the sum of the command signals is well-behaved. If the response modes associated with these components are not stable, bias errors can cause the components to diverge, leading to the possibility of 'nuisance trips' in failure detection/isolation logic and eventual control system lockup (at saturation). Combining the inputs to the control computers assures that sensor bias will not cause divergence, while cross-strapping control strings bounds divergent response to all bias error inputs. Results of numerical solutions confirm the problem and its solutions.

Stengel, R. F.↗

Some effects of bias errors in redundant flight control systems

The controllability and steady-state response of parallel-redundant flight control systems are examined. It is found that state components which appear in the parallel signal paths, or individual actuator commands, are not controllable, although the sum of the command signals is well-behaved. If the response modes associated with these components are not stable, bias errors can cause the components to diverge, leading to the possibility of nuisance trips in failure detection/isolation logic and eventual control system lockup (at saturation). Combining the inputs to the control computers assures that sensor bias will not cause divergence, while cross-strapping control strings bounds divergent response to all bias error inputs. Results of numerical solutions confirm the problem and its solutions.

Stengel, R. F.↗

Some effects of bias errors in redundant flight control systems.

The controllability and steady-state response of parallel-redundant flight control systems are examined. It is found that state components which appear in the parallel signal paths, e.g., individual actuator-commands, are not controllable, although the sum of the command signals is well behaved. If the response modes associated with these components are not stable, bias errors can cause the components to diverge, leading to the possibility of nuisance trips in failure detection/isolation logic and eventual control system lockup (at saturation). Combining the inputs to the control computers assures that sensor bias will not cause divergence, while cross-strapping control strings bounds divergent response to all bias error inputs.

Stengel, R. F.↗

Maintainable design for Space Station Freedom

Space Station Freedom poses a unique challenge from the standpoint-of-logistical support and maintainability. There is limited on-orbit stowage volume available for supply of replacement parts for critical systems, and crew time required for maintenance and repair of on-board systems is an extremely valuable commodity. These considerations, plus the high cost of ground-to-orbit resupply, give special importance to the consideration of maintainability in system design. Use of common parts and system redundancy have important influences on logistics and maintenance requirements, and the requirements for specialized crew training and tools are directly related to system design for maintainability. This paper describes the approach for maintainable design of Space Station Freedom systems.

Hopson, George D.↗

How much redundancy: Some cost considerations, including examples for spacecraft systems

How much redundancy should be built into a subsystem such as a space power subsystem. How does a reliability or design engineer choose between a power subsystem with 0.990 reliability and a more costly subsystem with 0.995 reliability. How does the engineer designing a power subsystem for a satellite decide between one power subsystem and a more reliable but heavier power subsystem. High reliability is not necessarily an end in itself. High reliability may be desirable in order to reduce the statistically expected loss due to a subsystem failure. However, this may not be the wisest use of funds since the expected loss due to subsystem failure is not the only cost involved. The subsystem itself may be very costly. The cost of the subsystem or the expected loss due to subsystem failure may not be considered separately. Therefore, the total of the two costs is minimized, i.e., the total of the cost of the subsystem plus the expected loss due to subsystem failure. A specific type of redundant system is considered, called a k-out-of-n: G subsystem. Such a subsystem has n modules, of which k are required to be good for the subsystem to be good. Five models are discussed which can be applied in the design of a power subsystem to select the unique redundancy method which will minimize the total of the cost of the power subsystem plus the expected loss due to the power subsystem failure. A BASIC computer program is available.

Suich, Ronald C.↗

Experience gained in operation of the VLF ATD lightning location system

The United Kingdom (UK) Meteorological Office's Very Low Frequency (VLF) Arrival Time Difference (ATD) System for long-range location of lightning flashes started automatic international issue of lightning-location products on 17 Jun. 1988. Data from before and after this formal start-date were carefully scrutinized to judge performance. Techniques for estimating location accuracy include internal consistency and comparisons against other systems. Other areas studied were range (up to several thousand km); detection efficiency, saturation effects in active situations, and communication difficulties (for this redundant system); and spurious fix rate. Care was taken to assess the potential of the system, in addition to identifying the operational difficulties of the present implementation.

Lee, Anthony C. L.↗

The Light That Doesn't Fail

Rayovac Corporation's Luma 2 flashlight incorporates NASA's systems redundancy. The company also received assistance from NERAC. The flashlight has an extra-bright Super Krypton primary bulb and an independent backup system including a separate lithium power cell (a NASA developed technology), its own bulb and switch with corrosion proof sealed contacts. NERAC has also assisted Rayovac in developing other products.

Source record↗

Dormancy Should Be Avoided for Mars and Deep Space Recycling Life Support

Mars is the crucial goal of human exploration beyond the Earth-moon system. The Mars round trip transit vehicle has been expected to use a regenerative Life Support System (LSS) similar to the one on the International Space Station (ISS). It often assumed that the Mars transit LSS will be operated on the outward trip to Mars, placed in dormancy while the full crew explores the surface, and then restored to operation for the return trip to Earth. The major difference between Mars missions and operations in the Earth-moon system is the need for much higher reliability for Mars missions, since rapid resupply of parts and materials or a quick crew return to Earth are not possible. Mars systems must achieve intrinsic high reliability by design, test, failure analysis, and redesign and then increase operational robustness by providing spare parts and redundant systems. Further requiring the LSS to be capable of dormancy and restoration to operation greatly increases the difficulty of design, test, and verification. The process of implementing dormancy and then restoring operation would add significant risk to the mission. Dormancy should be avoided for Mars and can be avoided several ways. First and most obvious, some crew can remain continually on board. If no crew can remain onboard, dormancy can still be avoided if an unused spare LSS is activated for the return trip, rather than restarting the used out bound system. Systems similar to the ISS LSS would have a significant probability of failure on a Mars trip and therefore would require two or three spares. Another full spare LSS could be provided as the return trip system, rather than refurbishing a used LSS.

dormancy↗

Cosmic Background Explorer (COBE) transfer orbit attitude control system

The Cosmic Background Explorer (COBE) spacecraft will be launched by the Shuttle from Vandenberg AFB into a 300 km altitude, 99 deg inclination, 6 a.m. or 6 p.m. ascending node orbit. After release from the Remote Manipulator System (RMS) arm, an on-board monopropellant hydrazine propulsion system will raise the orbit altitude to 900 km. The spacecraft continuously spins during transfer orbit operations with the spin axis nominally horizontal and in or near the orbit plane. The blowdown propulsion system consists of twelve 5 lb thrusters (3 'spin', 3 'despin', and 6 'axial') with the latter providing initially 30 lb of force parallel to the spin axis for orbit raising. The spin/despin jets provide a constant roll rate during the transfer orbit phase of the mission and the axials control pitch and yaw. The axial thrusters are pulsed on for attitude control during coast periods and are normally on- and off-modulated for control during orbit raising. Attitude sensors employed in the control loops include an array of two-axis digital sun sensors and three planar earth scanners for position measurements, as well as six gyroscopes for rate information. System redundancy is achieved by means of unique three-axes-in-a-plane geometry. This triaxial concept results in a fail-safe operational system with no performance degradation for many different component failure modes.

Placanica, Samuel J.↗

First flight test results of the Simplified Aid For EVA Rescue (SAFER) propulsion unit

The Simplified Aid for EVA Rescue (SAFER) is a small, self-contained, propulsive-backpack system that provides free-flying mobility for an astronaut engaged in a space walk, also known as extravehicular activity (EVA.) SAFER contains no redundant systems and is intended for contingency use only. In essence, it is a small, simplified version of the Manned Maneuvering Unit (MMU) last flown aboard the Space Shuttle in 1985. The operational SAFER unit will only be used to return an adrift EVA astronaut to the spacecraft. Currently, if an EVA crew member inadvertently becomes separated from the Space Shuttle, the Orbiter will maneuver to within the crew member's reach envelope, allowing the astronaut to regain contact with the Orbiter. However, with the advent of operations aboard the Russian MIR Space Station and the International Space Station, the Space Shuttle will not be available to effect a timely rescue. Under these conditions, a SAFER unit would be worn by each EVA crew member. Flight test of the pre-production model of SAFER occurred in September 1994. The crew of Space Shuttle Mission STS-64 flew a 6.9 hour test flight which included performance, flying qualities, systems, and operational utility evaluations. We found that the unit offers adequate propellant and control authority to stabilize and enable the return of a tumbling/separating crew member. With certain modifications, production model of SAFER can provide self-rescue capability to a separated crew member. This paper will present the program background, explain the flight test results and provide some insight into the complex operations of flight test in space.

Meade, Carl J.↗

Developing Reliable Life Support for Mars

A human mission to Mars will require highly reliable life support systems. Mars life support systems may recycle water and oxygen using systems similar to those on the International Space Station (ISS). However, achieving sufficient reliability is less difficult for ISS than it will be for Mars. If an ISS system has a serious failure, it is possible to provide spare parts, or directly supply water or oxygen, or if necessary bring the crew back to Earth. Life support for Mars must be designed, tested, and improved as needed to achieve high demonstrated reliability. A quantitative reliability goal should be established and used to guide development t. The designers should select reliable components and minimize interface and integration problems. In theory a system can achieve the component-limited reliability, but testing often reveal unexpected failures due to design mistakes or flawed components. Testing should extend long enough to detect any unexpected failure modes and to verify the expected reliability. Iterated redesign and retest may be required to achieve the reliability goal. If the reliability is less than required, it may be improved by providing spare components or redundant systems. The number of spares required to achieve a given reliability goal depends on the component failure rate. If the failure rate is under estimated, the number of spares will be insufficient and the system may fail. If the design is likely to have undiscovered design or component problems, it is advisable to use dissimilar redundancy, even though this multiplies the design and development cost. In the ideal case, a human tended closed system operational test should be conducted to gain confidence in operations, maintenance, and repair. The difficulty in achieving high reliability in unproven complex systems may require the use of simpler, more mature, intrinsically higher reliability systems. The limitations of budget, schedule, and technology may suggest accepting lower and less certain expected reliability. A plan to develop reliable life support is needed to achieve the best possible reliability.

life support↗

Reliability/safety analysis of a fly-by-wire system

An analysis technique has been developed to estimate the reliability of a very complex, safety-critical system by constructing a diagram of the reliability equations for the total system. This diagram has many of the characteristics of a fault-tree or success-path diagram, but is much easier to construct for complex redundant systems. The diagram provides insight into system failure characteristics and identifies the most likely failure modes. A computer program aids in the construction of the diagram and the computation of reliability. Analysis of the NASA F-8 Digital Fly-by-Wire Flight Control System is used to illustrate the technique.

Brock, L. D.↗

The 747 primary flight control systems reliability and maintenance study

The major operational characteristics of the 747 Primary Flight Control Systems (PFCS) are described. Results of reliability analysis for separate control functions are presented. The analysis makes use of a NASA computer program which calculates reliability of redundant systems. Costs for maintaining the 747 PFCS in airline service are assessed. The reliabilities and cost will provide a baseline for use in trade studies of future flight control system design.

Source record↗

Nanosat Intelligent Power System Development

NASA Goddard Space Flight Center is developing a class of satellites called nano-satellites. The technologies developed for these satellites will enable a class of constellation missions for the NASA Space Science Sun-Earth Connections theme and will be of great benefit to other NASA enterprises. A major challenge for these missions is meeting significant scientific- objectives with limited onboard and ground-based resources. Total spacecraft power is limited by the small satellite size. Additionally, it is highly desirable to minimize operational costs by limiting the ground support required to manage the constellation. This paper will describe how these challenges are met in the design of the nanosat power system. We will address the factors considered and tradeoffs made in deriving the nanosat power system architecture. We will discuss how incorporating onboard fault detection and correction capability yields a robust spacecraft power bus without the mass and volume penalties incurred from redundant systems and describe how power system efficiency is maximized throughout the mission duration.

Johnson, Michael A.↗