Search NASA⌕ Search

SEARCH · Search NASA

Results for “common cause failures”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Radiation portal monitor data file format for comprehensive background radiation monitoring

Radiation portal monitors (RPMs) are widely used at border security checkpoints to detect the presence of radioactive materials in people, vehicles, and cargo. Typically, RPM detection systems consist of two pillars equipped with gamma and neutron detectors. To improve detection efficiency, RPMs employ techniques such as a limited energy window, dynamic alarm thresholds, and lead shielding. However, without continuous monitoring of background radiation, signal interpretation can be compromised, because environmental factors and mechanical failures can cause fluctuations. Here, we introduce a daily file format that logs gamma background and neutron background radiation levels continuously over a 24 h period; this format is different from traditional formats that record data only when the RPM is active or occupied. The approach enables RPM operators and analysts to (1) identify and diagnose malfunctioning components, (2) adjust system settings to account for dynamic environmental factors, and (3) use the recorded data to characterize outer space phenomena. Continuous background reporting is essential for identifying issues such as faulty connections, voltage divider failures, and errors in background updates. Continuous background reporting also enables the detection of external influences, including nearby X-ray scanners, temperature fluctuations, rainfall, cosmic radiation, and lunar phase changes. These data files are designed to be easily evaluated and parsed using common tools, and a quick review by an expert is often sufficient for problem diagnosis. We anticipate that continuous background radiation monitoring and these new strategies will significantly improve the accuracy and reliability of RPM systems, reducing the rate of false alarms and enhancing overall system performance.

Background radiation monitoring↗

Timeouts Best Practices

This study investigates common timeouts encountered in the electric vehicle (EV) charging communications process. Many different timeouts are defined within the EV charging communications protocols. These timeouts can either be a fixed value or a defined range of values. In both cases, the timeout defines the duration of time for which one or both parties in the communications session are expected to wait for some action or process to complete before terminating the charge attempt. These timeout-based terminations are intended to prevent the charging process from becoming stuck indefinitely in any particular step. These terminations also enable a retry of the terminated charging session to begin. However, misaligned timeout values can have a significant negative impact on the user experience. Premature termination of charging sessions due to inappropriate timeout settings can lead to charging failures, causing inconvenience, wasted time, and frustration for users. These disruptions can degrade the overall user experience, making it essential to carefully manage and align timeout values with the relevant actions and processes to ensure reliable and satisfactory EV charging sessions. The core objective of this study is to boost reliability and enhance user experience by conducting a thorough review of timeout-based issues in EV charging and delivering a set of recommendations to modify these existing timeouts. These recommendations are informed by feedback gathered from multiple EV charging partners. This document is intended to inform electric vehicle supply equipment (EVSE) and EV manufacturers, EV charging infrastructure developers, and policymakers responsible for designing and implementing EV charging protocols and systems.

33 ADVANCED PROPULSION SYSTEMS↗

International Space Station Crew Quarters Ventilation and Acoustic Design Implementation

The International Space Station (ISS) United States Operational Segment has four permanent rack sized ISS Crew Quarters (CQs) providing a private crew member space. The CQs use Node 2 cabin air for ventilation/thermal cooling, as opposed to conditioned ducted air-from the ISS Common Cabin Air Assembly (CCAA) or the ISS fluid cooling loop. Consequently, CQ can only increase the air flow rate to reduce the temperature delta between the cabin and the CQ interior. However, increasing airflow causes increased acoustic noise so efficient airflow distribution is an important design parameter. The CQ utilized a two fan push-pull configuration to ensure fresh air at the crew member's head position and reduce acoustic exposure. The CQ ventilation ducts are conduits to the louder Node 2 cabin aisle way which required significant acoustic mitigation controls. The CQ interior needs to be below noise criteria curve 40 (NC-40). The design implementation of the CQ ventilation system and acoustic mitigation are very inter-related and require consideration of crew comfort balanced with use of interior habitable volume, accommodation of fan failures, and possible crew uses that impact ventilation and acoustic performance. Each CQ required 13% of its total volume and approximately 6% of its total mass to reduce acoustic noise. This paper illustrates the types of model analysis, assumptions, vehicle interactions, and trade-offs required for CQ ventilation and acoustics. Additionally, on-orbit ventilation system performance and initial crew feedback is presented. This approach is applicable to any private enclosed space that the crew will occupy.

Broyan, James L., Jr.↗

Space station common module network topology and hardware development

Conceptual space station common module power management and distribution (SSM/PMAD) network layouts and detailed network evaluations were developed. Individual pieces of hardware to be developed for the SSM/PMAD test bed were identified. A technology assessment was developed to identify pieces of equipment requiring development effort. Equipment lists were developed from the previously selected network schematics. Additionally, functional requirements for the network equipment as well as other requirements which affected the suitability of specific items for use on the Space Station Program were identified. Assembly requirements were derived based on the SSM/PMAD developed requirements and on the selected SSM/PMAD network concepts. Basic requirements and simplified design block diagrams are included. DC remote power controllers were successfully integrated into the DC Marshall Space Flight Center breadboard. Two DC remote power controller (RPC) boards experienced mechanical failure of UES 706 stud-mounted diodes during mechanical installation of the boards into the system. These broken diodes caused input to output shorting of the RPC's. The UES 706 diodes were replaced on these RPC's which eliminated the problem. The DC RPC's as existing in the present breadboard configuration do not provide ground fault protection because the RPC was designed to only switch the hot side current. If ground fault protection were to be implemented, it would be necessary to design the system so the RPC switched both the hot and the return sides of power.

Anderson, P.↗

A Risk Analysis Tool for Estimating the Risk of Electrical Failures Due to Human Induced Defects

Aerospace electrical systems are required to withstand and adequately operate in extremely harsh environments that include, for example, high radiation exposure, temperature extremes, intense vibrational stress and drastic temperature cycling. The nature of aerospace electronics also demands high reliability since, with very few exceptions, there is no chance for hardware servicing or repairs. Common risk mitigation techniques for this type of situation are to perform a Reliability Analysis of the system throughout the development cycle, and to use electrical components that are regarded as “high reliability” because of additional controls and requirements applied in their design, manufacturing and testing. Unfortunately, studies have shown that even though these techniques are used, many systems fail to meet mission requirements well before the predicted lifetimes. This paper presents the analysis of failures of electrical parts, experienced during various stages of system development, at NASA Goddard Space Flight Center, Greenbelt MD, between the years 2001 and 2013. These components were subjected to qualification, screening and testing in which the goal was to ensure that the components would survive the stresses of the mission. The analysis categorizes failures by part type and failure mechanisms. One of the results of the analysis was the realization that a surprising proportion of failures experienced during system integration and testing were caused by human error (i.e. human induced defect). Further analysis included the determination of root failure mechanisms and any influencing factors contributing to these failures. The major causes of these defects were attributed to electrostatic damage (ESD), electrical overstress (EOS), mechanical overstress (MOS), and thermal overstress (TOS). Finally, the study proposes a risk analysis tool which incorporates these major causes for the failures, termed error-producing conditions (EPCs), and a proportionality factor representing the number of each type of failure that has occurred at the facility under study. These factors are quantified and used to communicate the risk of human induced defects for the assembly, integration and testing of space hardware based on the system’s electrical parts list. The new risk identification can trigger risk-mitigating actions more effectively, based on the presence of component categories or other hazardous conditions that have a history of failure due to human error.

Majewicz, Peter J.↗

X-31 Mishap: Lessons Learned

The experimental X-31 High Angle of Attack Research Aircraft crashed during a 1995 test mission flight conducted by NASA at Edwards Air Force Base, California. The pilot lost control of the airplane and was forced to eject, sustaining a permanent back injury that ended his flying career. Prior to this incident the airplane had a perfect record of several hundred non-eventful flights supported by an experienced team. During the subsequent investigation by a mishap committee it was discovered that a series of cascading events contributed to this accident. Some of the identified contributing factors that resulted in this mishap are common to aircraft design and to flight-test in general. The mistakes and the solutions are presented here so that the flight-test community may consider and learn from them. The primary cause of the crash was icing and, ultimately, a complete blockage of the pitot-static nose probe. The icing was caused by a freak weather phenomenon that was neither expected nor known to exist on the day of the mishap. The normal probe had been replaced with a special Kiel probe to allow total pressure measurements of up to 70 degrees angle of attack for flight-test purposes. The Kiel probe did not include a heater, because it was assumed that the airplane would not be flown in the clouds or in conditions conducive to icing. This assumption was later proven to be incorrect. The iced Kiel probe caused incorrect gain scheduling in the flight control system, resulting in an unstable aircraft. This failure was essentially undetected because of a faulty design in the flight control system architecture. There were, however, also a number of other issues that lead up to this situation that never should have happened. This presentation discusses what the issues were that contributed to the incident. After the incident was investigated, some of these issues were addressed and some changes were made. The second X-31 aircraft flew the remainder of the flight tests, and the program was successfully completed without incident. This presentation also shows a video of the mishap including lessons learned, and the changes that were made to resume the flight-test program are presented.

Larson, Richard R.↗

Natural Language Processing Techniques for Intelligent Knowledge Management of Safety Reports

Safety, failure, and incident reports are common artifacts across various domains, including aviation and wildfire response. These reports are often mandatory to submit, resulting in the culmination of large repositories of text-based documents. Simultaneously, these reports and corresponding repositories are often only manually analyzed and queried by users via out-of-date search engines. As a consequence, we have been developing the Manager for Intelligent Knowledge Access (MIKA) toolkit, which uses natural language processing to improve information access and reuse. In this presentation, we discuss natural language processing techniques for knowledge discovery and apply these methods to a repository of aerial wildfire mishap reports. Two methods are used for knowledge discovery: topic modeling and named-entity recognition. We use topic modeling to identify hazards and perform a trend analysis to produce a data-driven risk matrix. A custom named-entity recognition model, build from fine tuning a pre-trained language model, is used to identify failure modes, failure causes, failure effects, control processes, and recommendations to aid in failure modes and effects analysis (FMEA). Throughout the presentation, we discuss and apply natural language processing techniques to better leverage the vast amount of information contained in report repositories.

Machine learning↗

Application of Fault Management Theory to the Quantitative Selection of a Launch Vehicle Abort Trigger Suite

The theory of System Health Management (SHM) and of its operational subset Fault Management (FM) states that FM is implemented as a "meta" control loop, known as an FM Control Loop (FMCL). The FMCL detects that all or part of a system is now failed, or in the future will fail (that is, cannot be controlled within acceptable limits to achieve its objectives), and takes a control action (a response) to return the system to a controllable state. In terms of control theory, the effectiveness of each FMCL is estimated based on its ability to correctly estimate the system state, and on the speed of its response to the current or impending failure effects. This paper describes how this theory has been successfully applied on the National Aeronautics and Space Administration's (NASA) Space Launch System (SLS) Program to quantitatively estimate the effectiveness of proposed abort triggers so as to select the most effective suite to protect the astronauts from catastrophic failure of the SLS. The premise behind this process is to be able to quantitatively provide the value versus risk trade‐off for any given abort trigger, allowing decision makers to make more informed decisions. All current and planned crewed launch vehicles have some form of vehicle health management system integrated with an emergency launch abort system to ensure crew safety. While the design can vary, the underlying principle is the same: detect imminent catastrophic vehicle failure, initiate launch abort, and extract the crew to safety. Abort triggers are the detection mechanisms that identify that a catastrophic launch vehicle failure is occurring or is imminent and cause the initiation of a notification to the crew vehicle that the escape system must be activated. While ensuring that the abort triggers provide this function, designers must also ensure that the abort triggers do not signal that a catastrophic failure is imminent when in fact the launch vehicle can successfully achieve orbit. That is, the abort triggers must have low false negative rates to be sure that real crew‐threatening failures are detected, and also low false positive rates to ensure that the crew does not abort from non‐crew‐threatening launch vehicle behaviors. The analysis process described in this paper is a compilation of over six years of lessons learned and refinements from experiences developing abort triggers for NASA's Constellation Program (Ares I Project) and the SLS Program, as well as the simultaneous development of SHM/FM theory. The paper will describe the abort analysis concepts and process, developed in conjunction with SLS Safety and Mission Assurance (S&MA) to define a common set of mission phase, failure scenario, and Loss of Mission Environment (LOME) combinations upon which the SLS Loss of Mission (LOM) Probabilistic Risk Assessment (PRA) models are built. This abort analysis also requires strong coordination with the Multi‐Purpose Crew Vehicle (MPCV) and SLS Structures and Environments (STE) to formulate a series of abortability tables that encapsulate explosion dynamics over the ascent mission phase. The design and assessment of abort conditions and triggers to estimate their Loss of Crew (LOC) Benefits also requires in‐depth integration with other groups, including Avionics, Guidance, Navigation and Control(GN&C), the Crew Office, Mission Operations, and Ground Systems. The outputs of this analysis are a critical input to SLS S&MA's LOC PRA models. The process described here may well be the first full quantitative application of SHM/FM theory to the selection of a sensor suite for any aerospace system.

Lo, Yunnhon↗

Evaluating Process Effectiveness to Reduce Risk

It is well documented that government agencies do not have the same incentive as the private sector to focus on process effectiveness and continual improvement of those processes. It is also well documented whenever government agencies fail to deliver efficient, effective, consistent, and fair services to the citizens. In spite of the various "reinventing government" and "effectiveness initiatives" of the past decades, and in spite of the efforts on the part of many agencies to improve, government in general still lags behind industry in creating a culture of effective processes and systems. While the tragic events that unfolded recently in Flint, Michigan, teach us that running government "like a business" does not always take the needs of the citizenry into account, there are many lessons and techniques from the private sector that government agencies can use to improve. The incentive to improve, while mandated by various administrations1, needs to come from within the workforce, in order to effectively take root. The best, most effective incentive is to reduce, control or eliminate risk. Government agencies face some of the same risks as the private sector, while some are unique. While ISO 310002 has been around since 2009, risk has taken on increased visibility within the private sector with the advent of the emphasis on risk-based thinking in ISO 9001:20153. The relationship between risk-based thinking and effective processes is simple and direct. Those processes that are well thought out and standardized (i.e. Plan-Do-Check-Act), will have taken into account the applicable policy, statutory, regulatory, safety, quality and technical parameters, which may not occur to someone performing the process with minimal experience or training; and thus protect the employees, the public and the agency from statutory and regulatory violations; delay in providing services; non-delivery of services; harm to public or employee safety and health; cost overruns; breaches in security; loss of confidence in government; failure of publicly funded projects; damage to the environment; ethics violations, and the list goes on; with local, national and even international consequences. The Plan-Do-Check-Act process, also known as the "process approach" can be used at any time to establish and standardize a process, and it can also be used to check periodically for "process creep" (i.e., informal, unauthorized changes that have occurred over time), any necessary updates and improvements. While ISO 9001 compliance is not mandated for all government agencies, if interpreted correctly, it can be useful in establishing a framework and implementing effective management systems and processes.4 Another method that can be used to evaluate effectiveness is the scorecard definitions in Mallory's Process Management Standard5 as a basis for evaluating work on the process level on effective, and continuously improved and improving processes. With processes on the lower end of the scale, agencies are vulnerable to a great many risks, with employees and managers making up many of the rules as they go, leading to the above listed negative results. Without clear guidance for nominal operations, off-nominal situations can, and do, increase the likelihood of chaos. In an increasingly technical environment, with inter-agency communication and collaboration becoming the norm, agencies need to come to grips with the fact that processes can become rapidly outdated, and that the technical community should take on an increased role in the maturation of the agency's processes. Industry has long known that effective processes are also efficient, and process improvement methods such as Kaizen, Lean, Six Sigma, 5S, and mistake proofing lead to increased productivity, improved quality, and decreased cost. Again, government agencies have different concerns, but inefficiencies and mistakes can have dire and wide reaching consequences for the public that they serve. While no one goes to work planning to cause harm, it is up to agencies to establish upper level systems, which make establishment and compliance with processes possible. Again, Mallory provides us with a Systems Management Standard6, similar to the Process Management Standard, with a scale of 0-5 for systems effectiveness and maturity. Deming determined that "eighty-five percent of the reasons for failure are deficiencies in the systems and process rather than the employee. The role of management is to change the process rather than badgering individual employees to do better." 7 It is not just the working level employees who need effective processes, but the mid-and upper level managers as well. A disciplined management culture sets the tone for the employees, aids both routine and off-nominal decision-making, and incorporates risk -based thinking into the systems and processes as a matter of normal activity. Figure 1, illustrates the relationship between ineffective and effective processes and risk, through the use of the "stoplight" colors that are commonly used to show serious situations (red), situations which may be improving or deteriorating depending on trends (yellow), and situations that are under control and continuously improved (green).

Shepherd, Christena C.↗

[High Pressure Gas Tanks]

Four high-pressure gas tanks, the basis of this study, were especially made by a private contractor and tested before being delivered to NASA Kennedy Space Center. In order to insure 100% reliability of each individual tank the staff at KSC decided to again submit the four tanks under more rigorous tests. These tests were conducted during a period from April 10 through May 8 at KSC. This application further validates the predictive safety model for accident prevention and system failure in the testing of four high-pressure gas tanks at Kennedy Space Center, called Continuous Hazard Tracking and Failure Prediction Methodology (CHTFPM). It is apparent from the variety of barriers available for a hazard control that some barriers will be more successful than others in providing protection. In order to complete the Barrier Analysis of the system, a Task Analysis and a Biomechanical Study were performed to establish the relationship between the degree of biomechanical non-conformities and the anomalies found within the system on particular joints of the body. This relationship was possible to obtain by conducting a Regression Analysis to the previously generated data. From the information derived the body segment with the lowest percentage of non-conformities was the neck flexion with 46.7%. Intense analysis of the system was conducted including Preliminary Hazard Analysis (PHA), Failure Mode and Effect Analysis (FMEA), and Barrier Analysis. These analyses resulted in the identification of occurrences of conditions, which may be becoming hazardous in the given system. These conditions, known as dendritics, may become hazards and could result in an accident, system malfunction, or unacceptable risk conditions. A total of 56 possible dendritics were identified. Work sampling was performed to observe the occurrence each dendritic. The out of control points generated from a Weighted c control chart along with a Pareto analysis indicate that the dendritics "Personnel not Wearing Proper Protective and Hose/tubing located in high-traffic area" which account for 59.18% of total dendritic frequency need to be addressed to reduce the chance of a hazard from occurring. However, the occurrences of some dendritics are more important than others. As a result immediate, from a Weighted c perspective, corrective action should be taken to ameliorate the cause of the Class A dendritic "Personnel located under suspended or moving loads" rather than just the most commonly occurring dendritics. In any case the vast majority of data obtained indicates that testing operations possess a relatively high degree of safety.

Quintana, Rolando↗

Nature-Inspired Motivation for Developing Self-Healable Electrical Insulation

Polymeric aircraft electrical insulation normally degrade by partial discharge with increasing voltage, which causes excessive localized Joule heating in the material and ultimately leads to dielectric failure of the insulator through thermal breakdown. Self-healing insulation may be a viable option to mitigate permanent mechanical degradation, thus increasing the longevity of the material. Instead of relying on catalyst and monomer-filled microcapsules to crack, flow, and cure at the damaged sites described in well-published mechanisms, self-healing through establishment of ionic crosslinks allows for multiple healing events to occur as well as achieving full recovery strength under certain thermal environments. Surlyn®, a commercial ionically-crosslinked material, was investigated as a self-healing insulation candidate based on prior demonstrations of self-healing behavior. Thin films of varying thicknesses were investigated and the effects of thickness on the dielectric strength were evaluated and compared to representative polymer insulators. The effects of thermal conditioning on the recovery strength and healing were observed as a function of time following dielectric breakdown. Moisture absorption was studied to determine if moisture absorption rates in Surlyn® were lower than that of common polyimide insulators. Preliminary data showed that when cut, Surlyn® films lost nearly 60 percent of its original dielectric strength. However, when Surlyn® was cut and subsequently annealed, the films not only re-mended, but also recouped approximately 93 percent of its original dielectric strength, along with 90-97 percent of its mechanical strength.

electrical↗

Radiometric and Radiation Response of Visible FPAs

The readout integrated circuit (ROIC) used in these devices was originally developed for use in space based infrared systems operating at deep cryogenic temperatures and was selected because of its proven tolerance to total ionizing radiation? The detectors are a 128 x 128 array of 60 pm x 60 pm pixel elements that have been anti-reflection (AR) coated to improve the response at very short wavelengths. These visible focal plane arrays were operated at -40 C (233 K). Two focal planes were characterized using cobalt-60 radiation to produce ionizing total dose damage in the VFPAs. Both operational and performance data were obtained as functions of total dose. The first device tested showed no appreciable change in responsivity or noise up to 300 krad(Si). However, at the next dose level of 600 krad(Si), the readout was non-operational due to failure in the digital circuitry. The second device was characterized to a total dose of 750 krad(Si) with no observed change in responsivity. An increase dark current was observed in both devices, and in the second device, the dark current caused an increase in noise at low irradiance at 400 krad(Si) and above. The increase in dark current was somewhat un-expected for visible PIN detectors. The median dark current increased more than two orders of magnitude at 300 krad(Si) for the first device and a factor of 350 at 750 krad(Si) for pixels near the edge for the second device. The dark current was found to be a strong function of detector bias, with pixels near the edge of the array showing a greater increase in dark current with bias than those near the center. Since the optical response was not a function of bias, it is hypothesized that the dark current is a surface effect and that the variation in dark current with location is due to a variation in pixel bias, caused by a voltage drop across the pixel common lead. As the total dose increased, the dark current and the voltage drop increased

Hubbs, John↗

Photo-oxidation of semicrystalline polymers: Effect of stress triaxiality on ductility

The effect of stress triaxiality on the strain-to-fracture of as-received and photo-oxidized polyamide-6 (PA-6) was investigated using mechanical testing, synchrotron X-ray tomography, and finite element analyses. Mechanical tests were conducted on cylindrical and round notched specimens, where different notch radii were used to vary the stress triaxiality. The specimens were aged by exposure to ultra-violet (UV) radiation at 60∘, causing photo-oxidation. As-received and so-aged specimens were loaded to failure (complete loss of load carrying capacity). For both unaged and aged specimens, a higher triaxiality led to a lower strain-to-fracture. To elucidate the micromechanical damage that mediates fracture in both conditions, specimens with an intermediate notch sharpness were loaded to the peak load, unloaded, and scanned ex situ using synchrotron X-ray tomography. Damage in the unaged bar was found to occur by cavitation and was concentrated at the center of the specimen, where the triaxiality is highest. In the UV-aged bar, a network of inter-connected chemical cracks were found on the notch surface, where the triaxiality is lowest. Finite element analyses were deployed to approximate the local triaxiality at damaged regions in the unaged and UV-aged specimens using a constitutive relation for semicrystalline polymers. From these analyses, the relationship between local triaxiality and strain-to-fracture was quantified for both unaged and photo-oxidized PA-6. Both unaged and photo-oxidized PA-6 showed similar decreases in ductility with triaxiality, hinting at common ductile fracture processes.

36 MATERIALS SCIENCE↗

High-Performance Acousto-Ultrasonic Scan System Being Developed

Acousto-ultrasonic (AU) interrogation is a single-sided nondestructive evaluation (NDE) technique employing separated sending and receiving transducers. It is used for assessing the microstructural condition and distributed damage state of the material between the transducers. AU is complementary to more traditional NDE methods, such as ultrasonic cscan, x-ray radiography, and thermographic inspection, which tend to be used primarily for discrete flaw detection. Throughout its history, AU has been used to inspect polymer matrix composites, metal matrix composites, ceramic matrix composites, and even monolithic metallic materials. The development of a high-performance automated AU scan system for characterizing within-sample microstructural and property homogeneity is currently in a prototype stage at NASA. This year, essential AU technology was reviewed. In addition, the basic hardware and software configuration for the scanner was developed, and preliminary results with the system were described. Mechanical and environmental loads applied to composite materials can cause distributed damage (as well as discrete defects) that plays a significant role in the degradation of physical properties. Such damage includes fiber/matrix debonding (interface failure), matrix microcracking, and fiber fracture and buckling. Investigations at the NASA Glenn Research Center have shown that traditional NDE scan inspection methods such as ultrasonic c-scan, x-ray imaging, and thermographic imaging tend to be more suited to discrete defect detection rather than the characterization of accumulated distributed microdamage in composites. Since AU is focused on assessing the distributed microdamage state of the material in between the sending and receiving transducers, it has proven to be quite suitable for assessing the relative composite material state. One major success story at Glenn with AU measurements has been the correlation between the ultrasonic decay rate obtained during AU inspection and the mechanical modulus (stiffness) seen during fatigue experiments with silicon carbide/silicon carbide (SiC/SiC) ceramic matrix composite samples. As shown in the figure, ultrasonic decay increased as the modulus decreased for the ceramic matrix composite tensile fatigue samples. The likely microstructural reason for the decrease in modulus (and increase in ultrasonic decay) is the matrix microcracking that commonly occurs during fatigue testing of these materials. Ultrasonic decay has shown the capability to track the pattern of transverse cracking and fiber breakage in these composites.

Roth, Don J.↗

High-Performance Acousto-Ultrasonic Scan System Being Developed

Acousto-ultrasonic (AU) interrogation is a single-sided nondestructive evaluation (NDE) technique employing separated sending and receiving transducers. It is used for assessing the microstructural condition and distributed damage state of the material between the transducers. AU is complementary to more traditional NDE methods, such as ultrasonic cscan, x-ray radiography, and thermographic inspection, which tend to be used primarily for discrete flaw detection. Throughout its history, AU has been used to inspect polymer matrix composites, metal matrix composites, ceramic matrix composites, and even monolithic metallic materials. The development of a high-performance automated AU scan system for characterizing within-sample microstructural and property homogeneity is currently in a prototype stage at NASA. This year, essential AU technology was reviewed. In addition, the basic hardware and software configuration for the scanner was developed, and preliminary results with the system were described. Mechanical and environmental loads applied to composite materials can cause distributed damage (as well as discrete defects) that plays a significant role in the degradation of physical properties. Such damage includes fiber/matrix debonding (interface failure), matrix microcracking, and fiber fracture and buckling. Investigations at the NASA Glenn Research Center have shown that traditional NDE scan inspection methods such as ultrasonic c-scan, x-ray imaging, and thermographic imaging tend to be more suited to discrete defect detection rather than the characterization of accumulated distributed micro-damage in composites. Since AU is focused on assessing the distributed micro-damage state of the material in between the sending and receiving transducers, it has proven to be quite suitable for assessing the relative composite material state. One major success story at Glenn with AU measurements has been the correlation between the ultrasonic decay rate obtained during AU inspection and the mechanical modulus (stiffness) seen during fatigue experiments with silicon carbide/silicon carbide (SiC/SiC) ceramic matrix composite samples. As shown in the figure, ultrasonic decay increased as the modulus decreased for the ceramic matrix composite tensile fatigue samples. The likely microstructural reason for the decrease in modulus (and increase in ultrasonic decay) is the matrix microcracking that commonly occurs during fatigue testing of these materials. Ultrasonic decay has shown the capability to track the pattern of transverse cracking and fiber breakage in these composites.

Roth, Don J.↗

Historical Aerospace Software Errors Categorized to Influence Fault Tolerance

Since the first use of computers in space and aircraft, software errors have occurred. These errors can manifest as loss-of-life or less catastrophically. As the demand for automation increases, software in mission or safety-critical systems should be designed to be tolerant to the most likely software faults. This paper categorizes a set of 55 historic aerospace software error incidents from 1962 to 2023 to determine trends of how and where automation is most likely to fail, behaving unexpectedly. A distinction between software producing unexpected (erroneous) output versus no output (failsilent) is introduced. Of the historical incidents analyzed, 85% were from software producing wrong output rather than simply stopping. Rebooting was found to be ineffective to clear erroneous behavior, and not reliable to recover from silent failures. Error origin was within the code/logic itself in 58% of cases, 16% from configurable data, 15% from unexpected sensor input, and 11% from command/operator input. A substantial forty percent (40%) of unexpected software behavior was indicated by the absence of code, arising from unanticipated situations and missing requirements, and 16% of incidents were subjectively deemed “unknown-unknowns”. No incidents were found to be the result of programming language, compiler, tool, or operating system; and only sixteen percent (16%) of all incidents were considered errors traditional computer science/programming in nature. These findings indicate that for fault tolerance, erroneous automation behavior must be a primary consideration especially at critical moments, and reboot recoverability may not be viable. Special care should be taken to validate configurable data and commands prior to use. “Test-like-you-fly”, including hardware-in-the-loop combined with robust off-nominal testing should be used to uncover missing logic arising from unanticipated situations not covered by requirements alone. This study uniquely focuses on manifestations of unexpected flight software behavior, independent of ultimate root cause. We characterize software error behavior and origin to improve software design, test, and operations for resilience to the most common manifestations, and provide a rich dataset for further study.

Aerospace↗

High reliability bond program using small diameter aluminum wire

The program was undertaken to characterize the performance of small diameter aluminum wire ultrasonically bonded to conductors commonly encountered in hybrid assemblies, and to recommend guidelines for improving this performance. Wire, 25.4, 38.1 and 50.8 um (1, 1.5 and 2 mil), was used with bonding metallization consisting of thick film gold, thin film gold and aluminum as well as conventional aluminum pads on semiconductor chips. The chief tool for evaluating the performance was the double bond pull test in conjunction with a 72 hour - 150 C heat soak and -65 C to +150 C thermal cycling. In practice the thermal cycling was found to have relatively little effect compared to the heat soak. Pull strength will decrease after heat soak as a result of annealing of the aluminum wire; when bonded to thick film gold, the pull strength decreased by about 50% (weakening of the bond interface was the major cause of the reduction). Bonds to thin film gold lost about 30 - 40% of their initial pull strenth; weakening of the wire itself at the bond heel was the predominant cause. Bonds to aluminum substrate metallization lost only about 22%. Bonds between thick and thin film gold substrate metallization and semiconductor chips substantiated the previous conclusions but also showed that in about 20 to 25% of the cases, bond interface failure occurred at the semiconductor chip.

Macha, M.↗

Mode I Toughness Measurements of Core/Facesheet Bonds in Honeycomb Sandwich Structures

Composite sandwich structures will be used in many future applications in aerospace, marine and offshore industries due to the fact that the strength and stiffness to mass ratios surpass any other structural type. Sandwich structure also offers advantages over traditional stiffened panels such as ease of manufacturing and repair. During the last three decades, sandwich structure has been used extensively for secondary structure in aircraft (fuselage floors, rudders and radome structure). Sandwich structure is also used as primary structure in rotorcraft, the most common example being the trailing edge of rotor blades. As with other types of composite construction, sandwich structure exhibits several types of failure mode such as facesheet wrinkling, core crushing and sandwich buckling. Facesheet/core debonding has also been observed in the marine and aerospace industry. During this failure mode, peel stresses applied to an existing facesheet/core debond or an interface low in toughness, results in the facesheet being peeled from the core material, possibly leading to a significant loss in structural integrity of the sandwich panel. In an incident during a test on a liquid hydrogen fuel tank of the X-33 prototype vehicle, the outer graphite/epoxy facesheet and honeycomb core became debonded from the inner facesheet along significant areas, leading to failure of the tank. As a consequence of the accident; significant efforts were made to characterize the toughness of the facesheet/core bond. Currently, the only standardized method available for assessing the quality of the facesheet/core interface is the climbing drum peel test (ASTM D1781). During this test a sandwich beam is removed from a panel and the lip of one of the facesheets is attached to a drum, as shown in Fig. 1. The drum is then rotated along the sandwich beam, causing the facesheet to peel from the core. This method has two major drawbacks. First, it is not possible to obtain quantitative fracture data from the test and so the results can only be used in a qualitative manner. Second, only sandwich structure with thin facesheets can be tested (to facilitate wrapping of the facesheet around the climbing drum). In recognition of the need for a more quantitative facesheet/core fracture test, several workers have devised experimental techniques for characterizing the toughness of the facesheet/core interface. In all of these cases, the tests are designed to yield a mode I-dominated fracture toughness of the facesheet/core interface in a manner similar to that used to determine mode I fracture toughness of composite laminates. In the current work, a modified double cantilever beam is used to measure the mode I-dominated fracture toughness of the interface in a sandwich consisting of glass/phenolic honeycomb core reinforced with graphite epoxy facesheets. Two specimen configurations were tested as shown in Fig 2. The first configuration consisted of reinforcing the facesheets with aluminum blocks (Fig. 2a). In the second configuration unreinforced specimens were tested (Fig. 2b). Climbing drum peel tests were also conducted to compare the fracture behavior observed between this test and the modified double cantilever beam. This paper outlines the test procedures and data reduction strategies used to compute fracture toughness values from the tests. The effect of specimen reinforcement on fracture toughness of the facesheet/core interface is discussed.

Nettles, Alan T.↗