Search NASASearch

SEARCH · Search NASA

Results for “SYSTEM FAILURE”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Spacecraft dynamics characterization and control system failure detection. Volume 3: Control system failure monitoring

We discuss the application of Generalized Parity Relations to two experimental flexible space structures, the NASA Langley Mini-Mast and Marshall Space Flight Center ACES mast. We concentrate on the generation of residuals and make no attempt to implement the Decision Function. It should be clear from the examples that are presented whether it would be possible to detect the failure of a specific component. We derive the equations from Generalized Parity Relations. Two special cases are treated: namely, Single Sensor Parity Relations (SSPR) and Double Sensor Parity Relations (DSPR). Generalized Parity Relations for actuators are also derived. The NASA Langley Mini-Mast and the application of SSPR and DSPR to a set of displacement sensors located at the tip of the Mini-Mast are discussed. The performance of a reduced order model that includes the first five models of the mast is compared to a set of parity relations that was identified on a set of input-output data. Both time domain and frequency domain comparisons are made. The effect of the sampling period and model order on the performance of the Residual Generators are also discussed. Failure detection experiments where the sensor set consisted of two gyros and an accelerometer are presented. The effects of model order and sampling frequency are again illustrated. The detection of actuator failures is discussed. We use Generalized Parity Relations to monitor control system component failures on the ACES mast. An overview is given of the Failure Detection Filter and experimental results are discussed. Conclusions and directions for future research are given.

Vanschalkwyk, Christiaan M.

Ampoule Failure System

An ampoule failure system for use in material processing furnaces comprising a containment cartridge and an ampoule failure sensor. The containment cartridge contains an ampoule of toxic material therein and is positioned within a furnace for processing. An ampoule failure probe is positioned in the containment cartridge adjacent the ampoule for detecting a potential harmful release of toxic material therefrom during processing. The failure probe is spaced a predetermined distance from the ampoule and is chemically chosen so as to undergo a timely chemical reaction with the toxic material upon the harmful release thereof. The ampoule failure system further comprises a data acquisition system which is positioned externally of the furnace and is electrically connected to the ampoule failure probe so as to form a communicating electrical circuit. The data acquisition system includes an automatic shutdown device for shutting down the furnace upon the harmful release of toxic material. It also includes a resistance measuring device for measuring the resistance of the failure probe during processing. The chemical reaction causes a step increase in resistance of the failure probe whereupon the automatic shutdown device will responsively shut down the furnace.

Watring, Dale A.

Techniques for Improving Pilot Recovery from System Failures

This project examined the application of intelligent cockpit systems to aid air transport pilots at the tasks of reacting to in-flight system failures and of planning and then following a safe four dimensional trajectory to the runway threshold during emergencies. Two studies were conducted. The first examined pilot performance with a prototype awareness/alerting system in reacting to on-board system failures. In a full-motion, high-fidelity simulator, Army helicopter pilots were asked to fly a mission during which, without warning or briefing, 14 different failures were triggered at random times. Results suggest that the amount of information pilots require from such diagnostic systems is strongly dependent on their training; for failures they are commonly trained to react to with a procedural response, they needed only an indication of which failure to follow, while for 'un-trained' failures, they benefited from more intelligent and informative systems. Pilots were also found to over-rely on the system in conditions were it provided false or mis-leading information. In the second study, a proof-of-concept system was designed suitable for helping pilots replan their flights in emergency situations for quick, safe trajectory generation. This system is described in this report, including: the use of embedded fast-time simulation to predict the trajectory defined by a series of discrete actions; the models of aircraft and pilot dynamics required by the system; and the pilot interface. Then, results of a flight simulator evaluation with airline pilots are detailed. In 6 of 72 simulator runs, pilots were not able to establish a stable flight path on localizer and glideslope, suggesting a need for cockpit aids. However, results also suggest that, to be operationally feasible, such an aid must be capable of suggesting safe trajectories to the pilot; an aid that only verified plans entered by the pilot was found to have significantly detrimental effects on performance and pilot workload. Results also highlight that the trajectories suggested by the aid must capture the context of the emergency; for example, in some emergencies pilots were willing to violate flight envelope limits to reduce time in flight - in other emergencies the opposite was found.

Pritchett, Amy R.

Analysis of Alerting System Failures in Commercial Aviation Accidents

The role of an alerting system is to make the system operator (e.g., pilot) aware of an impending hazard or unsafe state so the hazard can be avoided or managed successfully. A review of 46 commercial aviation accidents (between 1998 and 2014) revealed that, in the vast majority of events, either the hazard was not alerted or relevant hazard alerting occurred but failed to aid the flight crew sufficiently. For this set of events, alerting system failures were placed in one of five phases: Detection, Understanding, Action Selection, Prioritization, and Execution. This study also reviewed the evolution of alerting system schemes in commercial aviation, which revealed naive assumptions about pilot reliability in monitoring flight path parameters; specifically, pilot monitoring was assumed to be more effective than it actually is. Examples are provided of the types of alerting system failures that have occurred, and recommendations are provided for alerting system improvements.

aviation accidents

Spacecraft dynamics characterization and control system failure detection, volume 1

The work under this grant has been directed to two aspects of the control of flexible spacecraft: (1) the modeling of deployed or erected structures including nonlinear joint characteristics; and (2) the detection and isolation of failures of the components of control systems for large space structures. The motivation for the first of these research tasks is the fact that very large assemblies in space will have to be built or deployed in situ. A likely scenario is, in fact, a combination of these wherein modules which are folded for transportation into orbit are erected to their final configuration and then jointed with other such erected modules to form the full assembly. Any such erectable modules will have joints. It remains to be seen whether or not joints designed for operational assemblies will have nonlinear properties, but it seems prudent to develop a methodology for dealing with that possibility. The motivation for the second of these research tasks is the fact that we foresee large assemblies in space which will require active control to damp vibrations and/or hold a desired shape. Lightweight structures will be very flexible, with many elastic modes having very low frequencies. In order to control these modes well, the control system will likely require many sensors and many actuators, probably distributed over much of the structure. The combination of a large number of control system components with long operational periods virtually guarantees that these systems will suffer control system component failures during operation. The control system must be designed to tolerate failures of some sensors and actuators, and still be able to continue to perform its function.

Source record

The effects of participatory mode and task workload on the detection of dynamic system failures

The ability of operators to detect step changes in the dynamics of control systems is investigated as a joint function of, (1) participatory mode: whether subjects are actively controlling those dynamics or are monitoring an autopilot controlling them, and (2) concurrent task workload. A theoretical analysis of detection in the two modes identifies factors that will favor detection in either mode. Three subjects detected system failures in either an autopilot or manual controlling mode, under single-task conditions and concurrently with a subcritical tracking task. Latency and accuracy of detection were assessed and related through a speed accuracy tradeoff representation. It was concluded that failure detection performance was better during manual control than during autopilot control, and that the extent of this superiority was enhanced as dual-task load increased. Ensemble averaging and multiple regression techniques were then employed to investigate the cues utilized by the subjects in making their detection decisions.

Wickens, C. D.

Electronic systems failures and anomalies attributed to electromagnetic interference

The effects of electromagnetic interference can be very detrimental to electronic systems utilized in space missions. Assuring that subsystems and systems are electrically compatible is an important engineering function necessary to assure mission success. This reference publication will acquaint the reader with spacecraft electronic systems failures and anomalies caused by electromagnetic interference and will show the importance of electromagnetic compatibility activities in conjunction with space flight programs. It is also hoped that the report will illustrate that evolving electronic systems are increasingly sensitive to electromagnetic interference and that NASA personnel must continue to diligently pursue electromagnetic compatibility on space flight systems.

Leach, R. D.

Impact of Advanced Synoptics and Simplified Checklists During Aircraft Systems Failures

Abstract—Natural human capacities are becoming increasingly mismatched to the enormous data volumes, processing capabilities, and decision speeds demanded in today’s aviation environment. Increasingly Autonomous Systems (IAS) are uniquely suited to solve this problem. NASA is conducting research and development of IAS - hardware and software systems, utilizing machine learning algorithms, seamlessly integrated with humans whereby task performance of the combined system is significantly greater than the individual components. IAS offer the potential for significantly improved levels of performance and safety that are superior to either human or automation alone. A human-in-the-loop test was conducted in NASA Langley’s Integration Flight Deck B-737-800 simulator to evaluate advanced synoptic pages with simplified interactive electronic checklists as an IAS for routine air carrier flight operations and in response to aircraft system failures. Twelve U.S. airline crews flew various normal and non-normal procedures and their actions and performance were recorded in response to failures. These data are fundamental to and critical for the design and development of future increasingly autonomous systems that can better support the human in the cockpit. Synoptic pages and electronic checklists significantly improved pilot responses to non-normal scenarios, but implementation of these aids and other intelligent assistants have barriers to implementation (e.g., certification cost) that must overcome.

Etherington, Timothy J.

Quantifying Pilot Contribution to Flight Safety during Hydraulic Systems Failure

Accident statistics cite the flight crew as a causal factor in over 60% of large transport aircraft fatal accidents. Yet, a well-trained and well-qualified pilot is acknowledged as the critical center point of aircraft systems safety and an integral safety component of the entire commercial aviation system. The latter statement, while generally accepted, cannot be verified because little or no quantitative data exists on how and how many accidents/incidents are averted by crew actions. A joint NASA/FAA high-fidelity motion-base human-in-the-loop test was conducted using a Level D certified Boeing 737-800 simulator to evaluate the pilot's contribution to safety-of-flight during routine air carrier flight operations and in response to aircraft system failures. To quantify the human's contribution, crew complement (two-crew, reduced crew, single pilot) was used as the independent variable in a between-subjects design. This paper details the crew's actions, including decision-making, and responses while dealing with a hydraulic systems leak - one of 6 total non-normal events that were simulated in this experiment.

Kramer, Lynda J.

Control system failure monitoring using generalized parity relations

Many applications require that a control system must be tolerant to the failure of its components. This is especially true for large space-based systems that must work unattended and with long periods between maintenance. Fault tolerance can be obtained by detecting the failure of the control system component, determining which component has failed, and reconfiguring the system so that the failed component is isolated from the controller. Component failure detection experiments that were conducted on an experimental space structure, the NASA Langley Mini-Mast are presented. Two methodologies for failure detection and isolation (FDI) exist that do not require the specification of failure modes and are applicable to both actuators and sensors. These methods are known as the Failure Detection Filter and the method of Generalized Parity Relations. The latter method was applied to three different sensor types on the Mini-Mast. Failures were simulated in input-output data that were recorded during operation of the Mini-Mast. Both single and double sensor parity relations were tested and the effect of several design parameters on the performance of these relations is discussed. The detection of actuator failures is also treated. It is shown that in all the cases it is possible to identify the parity relations directly from input-output data. Frequency domain analysis is used to explain the behavior of the parity relations.

Vanschalkwyk, Christiaan Mauritz

Space shuttle orbital maneuvering system failure detection and identification software requirements (uncontrolled)

Candidate designs and their software implementation are presented for the Orbital Maneuvering System (OMS) Failure Detection and Identification (FDI) algorithms in the Redundance Management (RM) module of the Space Shuttle Guidance, Navigation, and Control (GN&C) software. The OMS engine FDI algorithm monitors OMS engine thrust performance, and the OMS actuator FDI algorithm monitors OMS gimbal actuator performance. The software functional requirements of the algorithms are described along with the objective of each algorithm. A list of the assumptions which have governed its design, input/output requirements, a functional description of the algorithm (including a functional block diagram), and input interface requirements are given. The HAL (the language of the space shuttle flight computer) software formulation of the algorithms is considered including structured flowcharts of the procedures, estimates of flight computer core storage and CPU time, and processing requirements. A glossary of the symbols used to define the software requirements and formulations is included.

Damario, L. A.

Managing Complex Airplane System Failures Through a Structured Assessment of Airplane Capabilities

This report describes an analysis of current transport aircraft system-management displays and the initial development of a set of display concepts for providing information about aircraft system status. The new display concepts are motivated by a shift away from the current approach to aircraft system alerting that reports the status of physical components, and towards displaying the implications for mission capability. Specifically, the proposed display concepts describe transport airplane component failures in terms of operational consequences of aircraft system degradations. The research activity described in this report is an effort to examine the utility of different representations of complex systems and operating environments to support real-time decision making during off-nominal situations. A specific focus is to develop display concepts that provide more highly integrated information to allow pilots to more easily reason about the operational consequences of the off-nominal situations. The work can also serve as a foundational element to autonomy-supported decision making since we are developing ideas for integrating information from the airplane and the operational environment to support decision making.

operational decision making