Search NASA⌕ Search

SEARCH · Search NASA

Results for “REDUNDANT SYSTEM”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Integrity Monitoring of Mercury Discharge Lamps

Mercury discharge lamps are critical in many trapped ion frequency standard applications. An integrity monitoring system can be implemented using end-of-life signatures observed in operational mercury discharge lamps, making it possible to forecast imminent failure and to take action to mitigate the consequences (such as switching to a redundant system). Mercury lamps are used as a source of 194-nm ultraviolet radiation for optical pumping and state selection of mercury trapped ion frequency standards. Lamps are typically fabricated using 202Hg distilled into high-purity quartz, or other 194-nm transmitting material (e.g., sapphire). A buffer gas is also placed into the bulb, typically a noble gas such as argon, neon, or krypton. The bulbs are driven by strong RF fields oscillating at .200 MHz. The lamp output may age over time by two internal mechanisms: (1) the darkening of the bulb that attenuates light transmission and (2) the loss of mercury due to migration or chemical interactions with the bulb surface. During fabrication, excess mercury is placed into a bulb, so that the loss rate is compensated with new mercury emanating from a cool tip or adjacent reservoir. The light output is nearly constant or varies slightly at a constant rate for many months/years until the mercury source is depleted. At this point, the vapor pressure abruptly falls and the total light output and atomic clock SNR (signal-to-noise ratio) decrease. After several days to weeks, the light levels decrease to a point where the atomic clock SNR is no longer sufficient to stay in lock, or the lamp self-extinguishes. This signature has been observed in four separate end-of-life lamp failures while operating in the Deep Space Network (DSN). A simple integrator circuit can observe and document steady-state lamp behavior. When the light levels drop over a predetermined time interval by a specified amount (e.g., 20 percent), an alarm is set. For critical operational applications, such as the DSN or in space flight, this warning provides notice that a failure may be imminent, and for operators or control algorithm to take action.

Tjoelker, Robert L.↗

Software Health Management: A Short Review of Challenges and Existing Techniques

Modern spacecraft (as well as most other complex mechanisms like aircraft, automobiles, and chemical plants) rely more and more on software, to a point where software failures have caused severe accidents and loss of missions. Software failures during a manned mission can cause loss of life, so there are severe requirements to make the software as safe and reliable as possible. Typically, verification and validation (V&V) has the task of making sure that all software errors are found before the software is deployed and that it always conforms to the requirements. Experience, however, shows that this gold standard of error-free software cannot be reached in practice. Even if the software alone is free of glitches, its interoperation with the hardware (e.g., with sensors or actuators) can cause problems. Unexpected operational conditions or changes in the environment may ultimately cause a software system to fail. Is there a way to surmount this problem? In most modern aircraft and many automobiles, hardware such as central electrical, mechanical, and hydraulic components are monitored by IVHM (Integrated Vehicle Health Management) systems. These systems can recognize, isolate, and identify faults and failures, both those that already occurred as well as imminent ones. With the help of diagnostics and prognostics, appropriate mitigation strategies can be selected (replacement or repair, switch to redundant systems, etc.). In this short paper, we discuss some challenges and promising techniques for software health management (SWHM). In particular, we identify unique challenges for preventing software failure in systems which involve both software and hardware components. We then present our classifications of techniques related to SWHM. These classifications are performed based on dimensions of interest to both developers and users of the techniques, and hopefully provide a map for dealing with software faults and failures.

Pipatsrisawat, Knot↗

Communication Research in Aviation and Space Operations: Symptoms and Strategies of Crew Coordination

The day-to-day operators of today's aerospace systems work under increasing pressures to accomplish more with less. They work in operational systems which are complex, technology-based, and high-risk; in which incidents and accidents have far-reaching and costly consequences. For these and other reasons, there is concern that the safety net formerly built upon redundant systems and abundant resources may become overburdened. Although we know that human ingenuity can overcome incredible odds, human nature can also fail in unpredictable ways. Over the last 20 years, a large percentage of aviation accidents and incidents have been attributed to human errors rather than hardware or environmental factors alone. A class of errors have been identified which are not due to a lack of individual, technical competencies. Rather, they are due to the failure of teams to utilize readily available resources or information in a timely fashion. These insights began a training revolution in the aviation industry called Cockpit Resource Management, which later became known as Crew Resource Management (CRM) as its concepts and applications extended to teams beyond the flightdeck. Then, as now, communication has been a cornerstone in CRM training since crew coordination and resource management largely resides within information transfer processes--both within flightcrews, and between flightcrews and the ground operations teams that support them. The research I will describe takes its roots in CRM history as we began to study communication processes in order to discover symptoms of crew coordination problems, as well as strategies of effective crew management. On the one hand, communication is often the means or the tool by which team members manage their resources, solve problems, maintain situational awareness and procedural discipline. Conversely, it is the lack of planning and resource management, loss of vigilance and situational awareness, and non-standard communications that are implicated in accidents and incidents. NASA/Ames Crew Factors researchers have been developing a model of effective crew coordination in order to understand the sources of performance breakdowns, and to develop effective solutions and interventions. Because communication is a primary mechanism by which information is received and transmitted, and because it is observable behavior, we focus on these group processes in order to identify patterns of communication that distinguish effective from less effective crew performance. Since a prime objective is to develop training recommendations for enhancing communication skills, we interpret our findings in the context of relevant task and environmental conditions, role and procedural constraints, and the normal real-time parameters of flight operations. Another research objective is to consider how communication and coordination can be enhanced through design. For example, flight deck and hardware design as well as procedural and software design may greatly influence the efficiency with which crews communicate and coordinate their work. In addition, teams and tasks may be designed, organized, and trained so that team interactions with each other are based upon appropriately shared knowledge, procedures and situation awareness. In short, we are interested in enhancing communication practices through (1) the training of specific communication skills, and (2) the design of equipment, tasks, procedures, and teams that optimize smooth, unambiguous communication processes. Two examples of communication research will be described; one in aviation and one in space operations. The first example is a high-fidelity full mission simulation study which investigates the affect of flightdeck automation on crew coordination and communication (contrasting crew performance in the DC-9 vs. MD88). Additional information is contained in the original extended abstract.

Kanki, Barbara G.↗

Study of a heat rejection system using capillary pumping

Results of an analytical study investigating the application of capillary pumping to the heat rejection loop of an advanced Rankine cycle power conversion system are presented. The feasibility of the concept of capillary pumping as an alternate to electromagnetic pumping is analytically demonstrated. Capillary pumping is shown to provide a potential for weight and electrical power saving and reliability through the use of redundant systems. A screen wick pump design with arterial feed lines was analytically developed. Advantages of this design are high thermodynamic and hydrodynamic efficiency, which provide a lightweight easily packaged system. Operational problems were identified which must be solved for successful application of capillary pumping. The most important are the development of start up and shutdown procedures, and development of a means of keeping noncondensibles from the system and of earth-bound testing procedures.

Neal, L. G.↗

Evaluation of TILS for use as the orbiter landing NAVAID

An evaluation of the tactical instrument landing systems (TILS) for use in the orbiter autoland system was made. It was found that with certain modifications, the TILS can satisfy orbiter autoland requirements. These modifications, include (1) addition of DME equipment, (2) expansion of elevation coverage from 0-10 deg to 0-30 deg, and (3) expansion to redundant systems with associated ground monitors. Additional modifications that are not necessary to meet the orbiter requirements, but that can enhance performance margin are (1) tightening of elevation antenna beam width from 1.3 deg to 0.5 deg and (2) split site configuration to provide azimuth and range coverage through rollout.

Tate, J. M.↗

Preliminary design of a flight control system for a V/STOL airplane with geared variable pitch fans

A flight control system designed for an aircraft powered by three variable pitch fans, interconnected by shafts to provide lifting system redundancy is considered for application to a Navy Type A V/STOL aircraft with similar configurational features. The differences and similarities in the applications are discussed with emphasis on a design approach for safety in the event of failures in the propulsion and flight control systems. Differences in flying qualities and system design criteria are considered.

Gotleib, P.↗

Spacecraft systems design trade-offs for the Earth Resources Technology Satellite.

The Earth Resources Technology Satellite Program's use of flight proven hardware in the design of a satellite for earth sensor payload support and data handling is discussed. The use of an existing satellite as the building block around which additional support systems such as the orbit adjust system, the redundant wideband telemetry systems, the second regulated power system, and the quad redundant command system is analyzed. System performance seen in orbit vs design objectives are discussed to point up the success of the design approach chosen. Also discussed are the schedule and cost benefits derived from the use of previously developed hardware with additional subsystems as required to meet program requirements.

Branchflower, G. A.↗

Designing to Mitigate Food Growing Failures in Space

Future space life support systems may use crop plants to grow most of the crew s food. A harvest failure can reduce the food available for future consumption. If the previously stored food is insufficient to reach the next harvest, the crew may go hungry. This paper considers how the overall food supply system should be modified to cope with food production failures. The food supply concept for a mission will use grown food, or stored food, cIr both. The optimum food supply mix depends on the costs and failure probabilities of stored and grown food. A simple food system model assumes that either we obtain the nominal harvest or a failure occurs and no food is harvested. Given the probability that any particular harvest fails, it is easy to compute the expected number of failures and the total food shortfall over a mission. If some food is grown and the probability of harvest failure is high, a non-redundant system has an unacceptable likelihood that the crew will have no food for a full harvest period. Food supply reliability must be increased either by supplying more food initially or by increasing food production capacity. We can obtain a very reliable food supply even when the harvest failure rate is high. If the cost of growing food is much less than the cost of providing stored food, it is better to provide redundant food growing capacity than to increase initial storage. A more realistic biomass production failure model allows the harvest amount or time to vary around the nominal values, using stochastic modeling with repeated Monte Carlo simulation, but such failures have minor impact compared to a complete harvest failure.

Jones, Harry↗

Common Cause Failure Modes

High technology industries with high failure costs commonly use redundancy as a means to reduce risk. Redundant systems, whether similar or dissimilar, are susceptible to Common Cause Failures (CCF). CCF is not always considered in the design effort and, therefore, can be a major threat to success. There are several aspects to CCF which must be understood to perform an analysis which will find hidden issues that may negate redundancy. This paper will provide definition, types, a list of possible causes and some examples of CCF. Requirements and designs from NASA projects will be used in the paper as examples.

Wetherholt, Jon↗

Lessons Learned in Space Life Support System Testing

The earlier problems can be found and corrected, the easier and cheaper it is to fix them. Doing less testing saves cost and time but doing too little testing increases the risk of operational failures causing large costs and delays. Integrated test is necessary to determine if the subsystems work together and the overall architecture performs as intended. This report reviews the testing lessons learned from the NASA Systems Engineering Handbook, a National Research Council report, and five reviews of International Space Station (ISS) lessons learned. The five reviews all mention two important points. First, that testing should be performed on the final integrated system, one as close as possible to the intended flight system. Second, “test as you fly,” while operating as planned in an environment as close as possible to the expected flight environment. Other lessons are the need for extensive preflight ground testing, the need to establish and defend an adequate budget, the problems using protoflight hardware on ISS, and the benefit of having ISS as a zero gravity test bed. The major ISS life support systems, carbon dioxide removal, water recycling, and oxygen recovery, were protoflight systems with little testing before launch to ISS. The failure rates of these systems have been much greater than predicted and this has caused dissatisfaction with the protoflight approach. The more costly traditional approach builds qualification and test units in addition to flight units. The test units are used to find, analyze, and fix failure modes. Other work shows that there is an optimum cost-effective amount of testing when redundant systems must have a specified reliability and confidence.

Harry W. Jones↗

Rocketdyne - Lunar Ascent Engine

The ascent engine was the last one from the moon, and I want to focus on the idea of redundancy and teams in regard to the engine. By teams, I mean teamwork - not just within Rocketdyne. It was teamwork within Rocketdyne; it was teamwork within Grumman; it was teamwork within NASA. These were all important elements leading to the successful development of the lunar excursion module (LEM) engine. Communication, rapid response, and cooperation were all important. Another aspect that went into the development of the ascent engine was the integration of technology and of lessons learned. We pushed all the above, plus technology and lessons learned, into a program, and that led to a successful result. One of the things that I like to think about - again in retrospect - is how it is very "in" now to have integrated product and process teams. These are buzzwords for teamwork in all program phases. That s where you combine a lot of groups into a single organization to get a job done. The ascent engine program epitomized that kind of integration and focus, and because this was the mid- to late-1960s; this was new ground for Rocketdyne, Grumman, and NASA. Redundancy was really a major hallmark of the Apollo Program. Everything was redundant. Once you got the rocket going, you could even lose one of the big F-1 engines, and it would still make it to orbit. And once the first stage separated from the rest of the vehicle, the second stage could do without an engine and still make a mission. This redundancy was demonstrated when an early Apollo launch shut down a J-2 second-stage engine. Actually, they shut down two J-2 engines on that flight. Even the third stage, with its single J-2 engine, was backed up because the first two stages could toss it into a recoverable orbit. If the third stage didn't work, you were circling the earth, and you had time to recover the command module and crew. Remember how on the Apollo 13 flight, there was sufficient system redundancy even when we lost the service module. That was a magnificent effort. TRW Inc. really ought to be proud of their engine for that. (See Slide 2, Appendix I) We had planned for redundancy; we had landed on the moon. However, weight restrictions in the architecture said, "You can t have redundancy for ascent from the moon. You've got one engine. It s got to work. There is no second chance. If that ascent engine doesn't work, you re stuck there." It would not have looked good for NASA. It wouldn't have looked good for the country. There was a letter written that President Richard Nixon would read if the astronauts got stuck on the moon, expressing how sorry we were and so forth. It was a scary letter, really. The ascent engine was an engine that had to work. (See Slide 3, Appendix I).

Harmon, Tim↗

NASA's Moon to Mars Autonomous Habitat Status

NASA is developing a strategy for sending humans to the Mars vicinity, known broadly as the Moon to Mars (M2M) Campaign. A critical part of this campaign is the development of in-space and surface habitation systems capable of substantially extending human presence beyond Low Earth Orbit (LEO). Mars missions feature an in-space transit habitat capable of supporting crews of four on ~850-1200-day missions, including transit to and from Mars and time in Mars orbit. Surface and transit habitats are complex elements which must keep crewmembers healthy and productive in deep-space environments with limited resources, long rescue times in contingency situations, and communication delays; all within constrained mass, volume, and power budgets. These habitats provide crew both living and workspace as well as most of the resources needed to support crew life. For deep space habitats, automation needs to be employed due to latency and for significant amounts of time when the habitats are uncrewed. Automation of systems is possible in space applications, but there are limitations. Outside of the Earth’s (or any) magnetosphere, radiation environments are harsh to both the physical hardware and the software components. Radiation (charged particles and ionizing electromagnetic waves) degrades and damages the hardware and causes single event upsets (SEUs) in software. If the hardware is damaged, data can be lost, or control actions not made. For software, SEUs cause algorithms to result in different solutions, or incorrect commands to be sent out. This means that algorithms and hardware used for deep space systems are different than what is used on Earth. Radiation-tolerant hardware is generations behind the current state-of-the-art hardware. Recent NASA missions, such as James Webb Space Telescope, continue to rely on older technologies such as the RAD750 processor, and the most advanced processors are still single core and less than 1.5 GHz. There have been attempts to use higher performance processors, but these often take multiple mitigation steps to handle the radiation environments, which limits the processing power and/or throughput. Current techniques for radiation mitigation have been redundancies, voting, physical separation of hardware, encasing materials, under-clocking hardware, and more. Some radiation mitigation techniques do provide benefits such as having a redundant system to improve the probability that a system will be available when needed. Autonomous software systems will have fewer interactions with humans on deep space missions and therefore need to be able to handle more off-nominal conditions. Microgravity also complicates the autonomous aspects of the mission because autonomous systems are usually built from known deterministic states, but microgravity causes physical objects to shift and move changing the location an autonomous system placed the object. Not only does the software need to be reliable and deterministic, losing resources due to a software error is not only costly but detrimental to reputation. The combination of having lower performance hardware and having to be able to verify and deterministically run software and an ever-changing environment makes deep space autonomous systems more complicated. Multiple gaps have been identified including verification of autonomous software algorithms (including artificial intelligence and machine learning), higher performance processors (graphics and general purpose), high speed networks (onboard and transmissions), memory, power distribution, data security, and variations from these. These gaps need to be closed for more advanced systems to be deployed and reduce the size, weight, and power impacts on the habitats.

Scott B. Tashakkor↗

Advanced information processing system: Authentication protocols for network communication

In safety critical I/O and intercomputer communication networks, reliable message transmission is an important concern. Difficulties of communication and fault identification in networks arise primarily because the sender of a transmission cannot be identified with certainty, an intermediate node can corrupt a message without certainty of detection, and a babbling node cannot be identified and silenced without lengthy diagnosis and reconfiguration . Authentication protocols use digital signature techniques to verify the authenticity of messages with high probability. Such protocols appear to provide an efficient solution to many of these problems. The objective of this program is to develop, demonstrate, and evaluate intercomputer communication architectures which employ authentication. As a context for the evaluation, the authentication protocol-based communication concept was demonstrated under this program by hosting a real-time flight critical guidance, navigation and control algorithm on a distributed, heterogeneous, mixed redundancy system of workstations and embedded fault-tolerant computers.

Harper, Richard E.↗

Evaluation of an Interferometric Sensor for In-Space Detection of Gas Leaks

Space mission planning often involves long-term storage of volatile liquids or high-pressure gases. These may include cryogenic fuels and oxidizers, high-pressure gases, and life-support-critical consumables. The risk associated with the storage of fluids and gases in space systems has long been an issue and the ability to retain these fluids is often tied to mission success. A leak in the storage or distribution system can cause many different problems, including a simple, but mission endangering, loss of inventory or, in severe cases, unbalanced thrust loads on a flight vehicle. Cryogenic propellants are especially difficult to store, especially over a long duration. The propellant can boil off and be lost through the insulating walls of the tank or simple thermal cycling of the fittings, valves, and propellant feed lines may unseat seals allowing the fluid to escape. Current NASA missions call for long-duration in-space storage of propellants, oxidizers, and life support supplies. Leaks of a scale detectable through a pressure drop in the storage tank are often catastrophic and have long been the focus of ground-based mitigation efforts where redundant systems are often employed. However, there is presently no technology available for detecting and monitoring low-level, but still mission-endangering, gas leaks in space. Standard in-space gas detection methods either have a very limited pressure range over which they operate effectively or are limited to certain gases. Mass spectrometer systems are able to perform the detection tasks, but their size, mass and use of high voltage, which could potentially lead to an arc that ignites a combustible propellent, severely limit their usefulness in a space system. In this paper, we present results from testing of the light-based interferometric gas monitoring and leak detection sensor shown in Fig. 1. The output of the sensor is an interference fringe pattern that is a function of the gas density, and commensurate index of refraction, in the sample region. Changes in the density of gas cause the interference fringes to move across a photodiode detector, providing a temporal history of the leak. The sensor is fiber coupled and constructed from solid optics, allowing for placement almost anywhere on the spacecraft. It is also advantageous in that it consumes very little power and does not introduce an ignition source. Data are presented demonstrating the capability of the sensor to measure density variations in different gas species. In addition, the transient response of the sensor in vacuum is demonstrated. These data extend and improve upon the results previously presented by the authors in Ref. [1].

Polzin, Kurt A.↗

Intercommunications in Real Time, Redundant, Distributed Computer System

An investigation into the applicability of fiber optic communication techniques to real time avionic control systems, in particular the total automatic flight control system used for the VSTOL aircraft is presented. The system consists of spatially distributed microprocessors. The overall control function is partitioned to yield a unidirectional data flow between the processing elements (PE). System reliability is enhanced by the use of triple redundancy. Some general overall system specifications are listed here to provide the necessary background for the requirements of the communications system.

Zanger, H.↗

An adaptive technique for a redundant-sensor navigation system.

An on-line adaptive technique is developed to provide a self-contained redundant-sensor navigation system with a capability to utilize its full potentiality in reliability and performance. This adaptive system is structured as a multistage stochastic process of detection, identification, and compensation. It is shown that the detection system can be effectively constructed on the basis of a design value, specified by mission requirements, of the unknown parameter in the actual system, and of a degradation mode in the form of a constant bias jump. A suboptimal detection system on the basis of Wald's sequential analysis is developed using the concept of information value and information feedback. The developed system is easily implemented, and demonstrates a performance remarkably close to that of the optimal nonlinear detection system. An invariant transformation is derived to eliminate the effect of nuisance parameters such that the ambiguous identification system can be reduced to a set of disjoint simple hypotheses tests. By application of a technique of decoupled bias estimation in the compensation system the adaptive system can be operated without any complicated reorganization.

Chien, T.-T.↗

An Adaptive Technique for a Redundant-Sensor Navigation System

An on-line adaptive technique is developed to provide a self-contained redundant-sensor navigation system with a capability to utilize its full potentiality in reliability and performance. The gyro navigation system is modeled as a Gauss-Markov process, with degradation modes defined as changes in characteristics specified by parameters associated with the model. The adaptive system is formulated as a multistage stochastic process: (1) a detection system, (2) an identification system and (3) a compensation system. It is shown that the sufficient statistics for the partially observable process in the detection and identification system is the posterior measure of the state of degradation, conditioned on the measurement history.

Chien, T. T.↗

National facilities study. Volume 5: Space research and development facilities task group

With the beginnings of the U.S. space program, there was a pressing need to develop facilities that could support the technology research and development, testing, and operations of evolving space systems. Redundancy in facilities that was once and advantage in providing flexibility and schedule accommodation is instead fast becoming a burden on scarce resources. As a result, there is a clear perception in many sectors that the U.S. has many space R&D facilities that are under-utilized and which are no longer cost-effective to maintain. At the same time, it is clear that the U.S. continues to possess many space R&D facilities which are the best -- or among the best -- in the world. In order to remain world class in key areas, careful assessment of current capabilities and planning for new facilities is needed. The National Facility Study (NFS) was initiated in 1992 to develop a comprehensive and integrated long-term plan for future aerospace facilities that meets current and projected government and commercial needs. In order to assess the nation's capability to support space research and development (R&D), a Space R&D Task Group was formed. The Task Group was co-chaired by NASA and DOD. The Task Group formed four major, technologically- and functionally- oriented working groups: Human and Machine Operations; Information and Communications; Propulsion and Power; and Materials, Structures, and Flight Dynamics. In addition to these groups, three supporting working groups were formed: Systems Engineering and Requirements; Strategy and Policy; and Costing Analysis. The Space R&D Task Group examined several hundred facilities against the template of a baseline mission and requirements model (developed in common with the Space Operations Task Group) and a set of excursions from the baseline. The model and excursions are described in Volume 3 of the NFS final report. In addition, as a part of the effort, the group examined key strategic issues associated with space R&D facilities planning for the U.S., and these are discussed in Section 4 of this volume.

Source record↗