Search NASA⌕ Search

SEARCH · Search NASA

Results for “Redundant Designs”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Resolving Phase Ambiguities In OQPSK

Improved design for modulator and demodulator in offset-quaternary-phase-key-shifting (OQPSK) communication system enables receiver to resolve ambiguity in estimated phase of received signal. Features include unique-code-word modulation and detection and digital implementation of Costas loop in carrier-recovery subsystem. Enchances performance of carrier-recovery subsystem, reduces complexity of receiver by removing redundant circuits from previous design, and eliminates dependence of timing in receiver upon parallel-to-serial-conversion clock.

Nguyen, Tien M.↗

How Can We Efficiently Build A Spacecraft That Has Longevity? Experiences From the GSFC Perspective to Inform Lunar Exploration and Science Orbiter’s Architecture

Recent successes in NASA planetary science missions has shown that long-lived missions can yield significant science return. These missions, despite their longevity, were not planned to operate beyond their deign life. For example, the Lunar Reconnaissance Orbiter has a design life of 2-3 years, and yet we are entering its 14th year on orbit. Spacecraft longevity in practice has been related to: 1) mission class; 2) did we test it long enough and resolve all the anomalies to be beyond the early failure curve; 3) consumables budgets, and 4) how components are de-signed and tested. Mission class has been perceived as one of the primary ways to drive longevity. But higher mission class is a significant cost and mission driver. Parts selection only from the limited military standard parts and extensive parts qualification adds to development time and cost. Largely redundant (often erroneously interpreted as fully redundant) adds to launch mass and increases testing complexity (which may reduce the amount of testing in the nominal con-figuration). Lower Risk Posture (reflected in a higher mission class) drives significant additional processes and quality assurance analyses. Higher mission class also drives significantly greater sparing and life testing costs. This discussion focuses on whether this is indeed the best way to achieve longevity efficiently or whether there are more efficient ways to achieve longevity. Empirical evidence shows that lower mission classes that implement effective risk reduction and selective redundancy generally results in long life at a lower Spacecraft bus cost. By evaluating redundancy careful-ly, spacecraft cost can be lowered which can enable a more capable payload. Risk of the mission is highly dependent on the complexity of the mission and is only loosely dependent on Class of Mission. High complexity missions can have many single point failures and require the development of new technology, while lower class mission can have lower risk by baselining or incorporating: (selective) redundancy, fault-tolerant design, design for minimum risk, ability to reset, and/or design for graceful degradation. The team met with Goddard Space Flight Center Space Systems Mission Operations leaders to discuss which avionics have proven in flight to be the most reliable and which have had lifetime issues. The paper proposes a list of components to focus on for redundancy for a long-lived lunar mission. Reliability numbers are presented for both single string and dual string missions. The history of life-time performance versus planned mission life according to mission class is presented. A mission with well thought out selective redundancy and effective on the ground test program, can be expected to last well beyond its mission lifetime and provided enhanced return for the community. This approach minimizes project expenditures that do not retire significant risk and allows the project to focus risk mitigation efforts on those risks that will have a significant likelihood of threatening mission success. This is aided by keeping the amount of technology maturation and mission complexity low, while focusing effort on ensuring all component stress-ing parameters well within the bounds of their capabilities.

Lessons Learned↗

Flat H Frangible Joint Evolution

Space vehicle staging and separation events require pyrotechnic devices. They are single-use mechanisms that cannot be tested, nor can failure-tolerant performance be demonstrated in actual flight articles prior to flight use. This necessitates the implementation of a robust design and test approach coupled with a fully redundant, failure-tolerant explosive mechanism to ensure that the system functions even in the event of a single failure. Historically, NASA has followed the single failure-tolerant (SFT) design philosophy for all human-rated spacecraft, including the Space Shuttle Program. Following the end of this program, aerospace companies proposed building the next generation human-rated vehicles with off-the-shelf, non-redundant, zero-failure-tolerant (ZFT) separation systems. Currently, spacecraft and launch vehicle providers for both the Orion and Commercial Crew Programs (CCPs) plan to deviate from the heritage safety approach and NASA's SFT human rating requirements. Both programs' partners have base-lined ZFT frangible joints for vehicle staging and fairing separation. These joints are commercially available from pyrotechnic vendors. Non-human-rated missions have flown them numerous times. The joints are relatively easy to integrate structurally within the spacecraft. In addition, the separation event is debris free, and the resultant pyro shock is lower than that of other design solutions. It is, however, a serious deficiency to lack failure tolerance. When used for critical applications on human-rated vehicles, a single failure could potentially lead to loss of crew (LOC) or loss of mission (LOM)). The Engineering and Safety & Mission Assurance directorates within the NASA Johnson Space Center took action to address this safety issue by initiating a project to develop a fully redundant, SFT frangible joint design, known as the Flat H. Critical to the ability to retrofit on launch vehicles being developed, the SFT mechanisms must fit within the same three-dimensional envelope as current designs as well as meet structural loads requirements. There is increased mass associated with the redundant design, and the goal is to minimize the weight impact as much as possible. These requirements presented significant challenges, both technically and financially; these challenges will be explored in this paper. Perhaps greater than the technical issues confronted during this design process, were the financial considerations. These were a significant part of the story of this design and development plan. Insufficient financial and labor resources were formidable barriers to completing this project. Nevertheless, JSC personnel successfully conducted several test series at JSC with very useful results. The many lessons learned drove design improvements, performance efficiency, and increased functional reliability. This paper examines the significant technical and financial challenges that these requirements posed to the project team. It discusses the evolution of the SFT frangible joint design, including optimization, testing, and successful partnering of the Johnson Space Center (JSC) engineering and JSC safety organizations, to enhance the flight safety margin for America's next generation of human-rated space vehicles.

Diegelman, Thomas E.↗

The Solar Anomalous and Magnetospheric Particle Explorer (SAMPEX) yo-yo despin and solar array deployment mechanism

The SAMPEX spacecraft, successfully launched in July 1992, carried a yo-yo despin system and deployable solar arrays. The despin and solar array mechanisms formed an integral system as the yo-yo cables held the solar array release mechanism in place. The SAMPEX design philosophy was to minimize size and weight through the use of a predominantly single string system. The design challenge was to build a system in a limited space, which was reliable with minimal redundancy. This paper covers the design and development of the SAMPEX yo-yo despin and solar array deployment mechanisms. The problems encountered during development and testing will also be discussed.

Kellogg, James W.↗

Experiences with Extra-Vehicular Activities in Response to Critical ISS Contingencies

The maturation of the International Space Station (ISS) design from the proposed Space Station Freedom to today's current implementation resulted in external hardware redundancy vulnerabilities in the final design. Failure to compensate for or respond to these vulnerabilities could put the ISS in a posture to where it could no longer function as a habitable space station. In the first years of ISS assembly, these responses were to largely be addressed by the continued resupply and Extra-Vehicular Activity (EVA) capabilities of the Space Shuttle. Even prior to the decision to retire the Space Shuttle, it was realized that ISS needed to have its own capability to be able to rapidly repair or replace external hardware without needing to wait for the next cargo resupply mission. As documented in a previous publicatoin5, in 2006 development was started to baseline Extra- Vehicular Activity (EVA, or spacewalk) procedures to replace hardware components whose failure would expose some of the ISS vulnerabilities should a second failure occur. This development work laid the groundwork for the onboard crews and the ground operations and engineering teams to be ready to replace any of this failed hardware. In 2010, this development work was put to the test when one of these pieces of hardware failed. This paper will provide a brief summary of the planning and processes established in the original Contingency EVA development phase. It will then review how those plans and processes were implemented in 2010, highlighting what went well as well as where there were deficiencies between theory and reality. This paper will show that the original approach and analyses, though sound, were not as thorough as they should have been in the realm of planning for next worse failures, for documenting Programmatic approval of key assumptions, and not pursuing sufficient engineering analysis prior to the failure of the hardware. The paper will further highlight the changes made to the Contingency EVA preparation team structure, approach, goals, and the resources allocated to its work after the 2010 events. Finally, the authors will overview the implementation of these updates in addressing failures onboard the ISS in 2012, 2013, and 2014. The successful use of the updated approaches, and the application of the approaches to other spacewalks, will demonstrate the effectiveness of this additional work and make a case for putting significant time and resources into pre-failure planning and analysis for critical hardware items on human-tended spacecraft.

Van Cise, E. A.↗

Experiences with Extra-Vehicular Activities in Response to Critical ISS Contingencies

The maturation of the International Space Station (ISS) design from the proposed Space Station Freedom to today's current implementation resulted in external hardware redundancy vulnerabilities in the final design. Failure to compensate for or respond to these vulnerabilities could put the ISS in a posture where it could no longer function as a habitable space station. In the first years of ISS assembly, these responses were to largely be addressed by the continued resupply and Extra-Vehicular Activity (EVA) capabilities of the Space Shuttle. Even prior to the decision to retire the Space Shuttle, it was realized that ISS needed to have its own capability to be able to rapidly repair or replace external hardware without needing to wait for the next cargo resupply mission. As documented in a previous publication, in 2006 development was started to baseline Extra-Vehicular Activity (EVA, or spacewalk) procedures to replace hardware components whose failure would expose some of the ISS vulnerabilities should a second failure occur. This development work laid the groundwork for the onboard crews and the ground operations and engineering teams to be ready to replace any of this failed hardware. In 2010, this development work was put to the test when one of these pieces of hardware failed. This paper will provide a brief summary of the planning and processes established in the original Contingency EVA development phase. It will then review how those plans and processes were implemented in 2010, highlighting what went well as well as where there were deficiencies between theory and reality. This paper will show that the original approach and analyses, though sound, were not as thorough as they should have been in the realm of planning for next worse failures, for documenting Programmatic approval of key assumptions, and not pursuing sufficient engineering analysis prior to the failure of the hardware. The paper will further highlight the changes made to the Contingency EVA preparation team structure, approach, goals, and the resources allocated to its work after the 2010 events. Finally, the authors will overview the implementation of these updates in addressing failures onboard the ISS in 2012, 2013, and 2014. The successful use of the updated approaches, and the application of the approaches to other spacewalks, will demonstrate the effectiveness of this additional work and make a case for putting significant time and resources into pre-failure planning and analysis for critical hardware items on human-tended spacecraft.

Van Cise, E. A.↗

Compiler-Assisted Multiple Instruction Rollback Recovery Using a Read Buffer

Multiple instruction rollback (MIR) is a technique to provide rapid recovery from transient processor failures and was implemented in hardware by researchers and slow in mainframe computers. Hardware-based MIR designs eliminate rollback data hazards by providing data redundancy implemented in hardware. Compiler-based MIR designs were also developed which remove rollback data hazards directly with data flow manipulations, thus eliminating the need for most data redundancy hardware. Compiler-assisted techniques to achieve multiple instruction rollback recovery are addressed. It is observed that data some hazards resulting from instruction rollback can be resolved more efficiently by providing hardware redundancy while others are resolved more efficiently with compiler transformations. A compiler-assisted multiple instruction rollback scheme is developed which combines hardware-implemented data redundancy with compiler-driven hazard removal transformations. Experimental performance evaluations were conducted which indicate improved efficiency over previous hardware-based and compiler-based schemes. Various enhancements to the compiler transformations and to the data redundancy hardware developed for the compiler-assisted MIR scheme are described and evaluated. The final topic deals with the application of compiler-assisted MIR techniques to aid in exception repair and branch repair in a speculative execution architecture.

Alewine, Neal Jon↗

Design of an ammonia two-phase Prototype Thermal Bus for Space Station

The feasibility of two-phase heat transport systems for use on Space Station was demonstrated by testing the Thermal Bus Technology Demonstrator (TBTD) as part of the Integrated Two-Phase System Test in NASA-JSC's Thermal Test Bed. Under contract to NASA-JSC, Grumman is currently developing the successor to the TBTD, the Prototype Thermal Bus System (TBS). The TBS design, which uses ammonia as the working fluid, is intended to achieve a higher fidelity level than the TBTD by incorporating both improvements based on TBTD testing and realistic design margins, and by addressing Space Station issues such as redundancy and maintenance. The TBS is currently being fabricated, with testing scheduled for late 1987/early 1988. This paper describes the TBS design which features fully redundant plumbing loops, five evaporators designed to represent different heat acquisition interfaces, 14 condensers which mate with either space radiators or facility heat exchangers, and several modular components.

Brown, Richard F.↗

Architecture Options for Navigation in Cislunar Space for Human Landing System Vehicles

As part of architecture studies and insight analysis focused on requirements development into Human Landing System lunar architecture designs, multiple studies are underway to understand the sensitivities and options for achieving high precision landing on the lunar surface. The baseline approach utilizes a combination of multiple sensors to capture autonomous state observations of the lander with respect to the lunar surface. These systems are typically constrained in terms of operational altitudes by parameters such as onboard map size, camera focus, or sensor transmitted power (for altimeter observations). While these sensor suites do enable high precision landing, they are typically very complex and expensive. For a human-rated vehicle, fault detection algorithms are needed in addition to redundant sensors drive additional design complexity. Conversely, for these early missions, mass performance is key, so extended analysis is required to identify numbers of sensors, their ideal placement, and integration algorithms. A key part of this analysis is to help identify key sensor suites and options to help alleviate this design tension. An alternate approach is to take advantage and build out in-situ assets to allow for GPS-like navigation within the lunar regime through the use of navigation references or beacons. This can be achieved through the integration of navigation services into potential relays and pre-placed lunar surface assets. This research focuses on the capability of this infrastructure to support navigation in all areas of cislunar space such as: approach to the moon, in orbit around the moon, and ascent/descent operations to the surface. An augmented state linear covariance analysis (LinCov) and navigation state covariance analysis (NavCov) tools were used to assess a variety of navigation reference locations and how they can support vehicle operations through both understanding of state uncertainties and trajectory dispersions. This research helps to supplement existing studies focused on communication link analysis by providing additional insight into specific vehicle operational scenarios that are tied closely to potential Human Landing System scenarios. Key aspect of this analysis focus on the sensitivity to state knowledge of the references, the accuracy of inter-asset measurements, and placement in support of the various scenarios.

Evan J Anzalone↗

A Real-Time Control System for a Mobile Redundant 7DOF Arm

This paper describes the design and implementation of a real-time control system with multiple modes of operation for a mobile redundant dexterous manipulator. The paper describes the hardware and software components of the VME bus environment. Experimental results on real-time control of the Robotics Research arm using the manipulator control system are also presented in the paper.

avoidance angle control↗

Compiler-assisted multiple instruction rollback recovery using a read buffer

Multiple instruction rollback (MIR) is a technique that has been implemented in mainframe computers to provide rapid recovery from transient processor failures. Hardware-based MIR designs eliminate rollback data hazards by providing data redundancy implemented in hardware. Compiler-based MIR designs have also been developed which remove rollback data hazards directly with data-flow transformations. This paper focuses on compiler-assisted techniques to achieve multiple instruction rollback recovery. We observe that some data hazards resulting from instruction rollback can be resolved efficiently by providing an operand read buffer while others are resolved more efficiently with compiler transformations. A compiler-assisted multiple instruction rollback scheme is developed which combines hardware-implemented data redundancy with compiler-driven hazard removal transformations. Experimental performance evaluations indicate improved efficiency over previous hardware-based and compiler-based schemes.

Alewine, N. J.↗

A Radiation-Hard 8-Channel 15-Bit 40-MSPS ADC for the ATLAS Liquid Argon Calorimeter Readout

The custom design of a radiation-hardened, 8-channel, 40-MSPS, 15-bit resolution, 14.2-bit dynamic range, 11.4-ENOB ADC data acquisition ASIC fabricated in a commercial 65-nm triple-well CMOS technology is presented. The ADC is developed for and integrates seamlessly into the readout system for the ATLAS liquid argon (LAr) calorimeter in the high-luminosity large hadron collider (HLLHC) upgrade at CERN, which will require a total of 364 936 ADC channels. A three-stage MDAC+SAR pipelined ADC architecture was designed to meet the physics requirements and scientific goals of the ATLAS experiment. The ADC is a fully self-contained data acquisition system that includes foreground calibration, digital data processing, digital control, and supporting circuitry. The measured performance shows the ADC achieves a competitive dynamic range and SNDR, and it meets or exceeds the ATLAS analog requirements. Radiation tolerance and scalability design considerations were implemented at the device-, circuit-, and system-level. Radiation-hardening-by-design techniques used include redundancy for digital circuits, the use of MiM capacitors, and a hybrid RC-DAC for the ADC core. The ADC ASIC was demonstrated to be robust against the effects of the intense radiation expected in the HL-LHC experimental environment.

DAQ↗

Reliability considerations in long-life outer planet spacecraft system design

A Mariner Jupiter/Saturn mission has been planned for 1977. System reliability questions are discussed, taking into account the actual and design lifetime, causes of mission termination, in-flight failures and their consequences for the mission, and the use of redundancy to avoid failures. The design process employed optimizes the use of proven subsystem and system designs and then makes the necessary improvements to increase the lifetime as required.

Casani, E. K.↗

Advanced helium regulator for a fluorine propellant system

The space storable propulsion module is an advanced high performance (375 seconds Isp minimum) planetary spacecraft propulsion system with a mission life of 5-10 years. The propellants used are liquid fluorine and amine fuel. This application requires high pressure regulator accuracy to optimize propellant depletion characteristics. An advanced regulator concept was prepared which is compatible with both fuel and oxidizer and which features design concepts such as redundant bellows, all-metallic/ceramic construction, friction-free guidance of moving parts and gas damping. Computer simulation of the propulsion module performance over two mission profiles indicated satisfactory minimization of those propellant residual requirements imposed by regulator performance variables.

Wichmann, H.↗

Ground and flight test experience with a triple redundant digital fly by wire control system

A triplex digital fly by wire flight control system was developed and installed in an F-8C aircraft to provide fail operative, full authority control. Hardware and software redundancy management techniques were designed to detect and identify failures in the system. Control functions typical of those projected for future actively controlled vehicles were implemented.

Jarvis, C. R.↗

Distributed processing and fiber optic communications in air data measurement

This paper describes the application of distributed processing, fiber optics, and hardware redundancy to collecting airstream data in Princeton's digitally controlled Variable-Response Research Aircraft (VRA). Microprocessor-controlled instrumentation packages in each wingtip of the aircraft collect angle-of-attack and sideslip data in digital form; after scaling, filtering, and calibrating the data, they send it to the aircraft's microprocessor Digital Flight Control System (micro-DFCS) via digital fiber optic data links. Each wingtip's package is independent of the other; therefore, the system has dual hardware redundancy. The fiber optic link design is presented as well as a description of the calibration and communications software. Translation of the system's dual redundancy into fault tolerance is also covered. Results of preliminary flight tests are included.

Farry, K. A.↗

A xenon ion propulsion module for enhanced spacecraft capability

Design, development and preliminary testing of a two-engine xenon ion propulsion module for early flight evaluation is described. Extensive use is made of flight spare propellant system components and also engineering model 30-cm ion engines and assemblies originally developed for the Solar Electric Propulsion System program. Significant design features include a redundant propellant feed system that incorporates a novel gas pulse assembly for rapid and completely reliable engine startup, a central neutralizer subsystem with dual neutralizers for redundancy, and major ion engine performance improvements resulting in a nearly doubling of the 30-cm engine thrust in addition to operating on xenon rather than mercury propellant. At a module input power of 10.0 kw, maximum thrust and specific impulse are projected to be 0.4 N and 3,500 sec. respectively, for a total module efficiency of 67 percent. Total mass of the xenon ion module, including the propellant tank, is only 70.2 kg. The technical approaches taken towards developing and integrating the subsystems comprising this ion propulsion module are presented and discussed in detail.

Aston, G.↗