Engineering PapersSearch

Engineering topics

Jones, Harry W.

Publications and source records attributed to Jones, Harry W..

At least 19 records

The New NASA Approach to Reliability and Maintainability

In 2017, after 20 years, NASA issued a major revision of its reliability and maintainability (R&M) policy, NASA-STD- 8729.1A. Formerly NASA required certain specific R&M activities during each succeeding phase of project development. Now NASA requires a project to start by including the initial development of R&M requirements and the devising of strategies to implement and verify them. Rather than resolving all the requirements first and then designing the system, as has been usual in systems design, the design process now is to work top down by layers. It begins by first identifying the top level requirements and suggesting top level design strategies for those, then making these higher strategies the basis for a lower level set of requirements, and so on down to the lowest components. This approach is intended to ensure that R&M is designed in from the beginning rather than added later with difficulty to a completed design concept. The new R&M standard uses an innovative and effective top-down system design approach intended to effectively implement R&M.

Jones, Harry W.

The New NASA Approach to Reliability and Maintainability

In 2017, after 20 years, NASA issued a major revision of its reliability and maintainability (R&M) policy, NASA-STD-8729.1A [1]. Formerly NASA required certain specific R&M activities during each succeeding phase of project development. Now NASA requires a project to start by including the initial development of R&M requirements and the devising of strategies to implement and verify them. Rather than resolving all the requirements first and then designing the system, as has been usual in systems design, the design process now is to work top down by layers. It begins by first identifying the top level requirements and suggesting top level design strategies for those, then making these higher strategies the basis for a lower level set of requirements, and so on down to the lowest components. This approach is intended to ensure that R&M is designed in from the beginning rather than added later with difficulty to a completed design concept. The new R&M standard uses an innovative and effective top-down system design approach intended to effectively implement R&M.

Jones, Harry W.

A Method and Model to Predict Initial Failure Rates

It has long been well known that actual system reliability typically falls well short of early estimates. Failure rates are often ten or more times higher than anticipated. Many reasons have been given for this, but over-optimism is the fundamental cause of too-favorable reliability predictions. Most forecasts of reliability are essentially best-case scenarios, as are predictions of budget and schedule. Confident engineers assemble estimates bottom-up, including the known factors and ignoring problems that they hope won’t happen. Traditional reliability estimation is based on simply summing up the component failure rates. This ignores most actual failure causes. The way to reduce over-optimism is to use the historical system level failure rate from similar projects. Adjustments should not be made based purely on engineering judgment, but only if there is so logical quantitative justification. The traditional component-based reliability estimate is useful as a lower bound on the system failure rate. The difference between this lower bound component-based reliability and the historical system level reliability indicates how much of the total failure rate is due to system level problems rather than component failures.

Jones, Harry W.

A Method and Model to Predict Initial Failure Rates

It has long been well known that actual system reliability typically falls well short of early estimates. Failure rates are often ten or more times higher than anticipated. Many reasons have been given for this, but over-optimism is the fundamental cause of too-favorable reliability predictions. Most forecasts of reliability are essentially best-case scenarios, as are predictions of budget and schedule. Confident engineers assemble estimates bottom-up, including the known factors and ignoring problems that they hope won't happen. Traditional reliability estimation is based on simply summing up the component failure rates. This ignores most actual failure causes. The way to reduce over-optimism is to use the historical system level failure rate from similar projects. Adjustments should not be made based purely on engineering judgment, but only if there is so logical quantitative justification. The traditional component-based reliability estimate is useful as a lower bound on the system failure rate. The difference between this lower bound component-based reliability and the historical system level reliability indicates how much of the total failure rate is due to system level problems rather than component failures

Jones, Harry W.

Space Program Advocacy Can Distort Project Management and Damage Systems Engineering

Over-optimistic project advocacy often causes exaggerated performance claims and underestimated costs and schedules. This can distort project management and damage systems engineering. NASA projects such as the space shuttle and Hubble are extreme examples. NASA's spectacular success in the Apollo moon landings seems to have produced overconfidence and carelessness, but also to have gained tolerance for unrealistic claims and forgiveness when they were proven wrong. Apollo risk analysis predicted many astronaut fatalities. This was believed but was potentially damaging to the Apollo program, so risk analysis was discontinued. The moon landings beat bad odds because Apollo obsessively reduced risk. Its success seemed to confirm that risk analysis was unreasonably pessimistic and that risk could be overcome by good engineering. This understanding caused risk to be increased during space shuttle engineering and led to an unnecessarily dangerous approach. The shuttle design placed a fragile spacecraft next to the fuel tanks and failed to provide crew escape or launch abort. These design decisions directly caused the Challenger and Columbia tragedies. After Challenger, risk analysis was re-established. The current rocket and capsule design does consider risk and the result strongly resembles Apollo. Apollo advocacy led NASA to abandon risk analysis and this was ultimate cause of the Shuttle tragedies. Excessive advocacy that distorts risk, cost, and schedule could be prevented in an ideal organization that used systems engineering to make rational and fair decisions. However, most real organizations accommodate human and group needs using informal methods often described as "the system." Humans have biases, use innate decision making heuristics, instinctively rely on "gut feel," and establish deviant groups through groupthink. Expecting organizations to become totally rational is impractical, but specific problems such as neglecting risk and underestimating cost and schedule can be directly challenged with some hope of success.

Jones, Harry W.

Space Research Project Management Can Benefit from Engineering Technology Selection Methods

Many engineering methods have been developed to help management select technology for a system design or further research. The simplest way to compare technologies is to use a checklist containing all the more or less important selection criteria, so that nothing is overlooked. The criteria usually include cost, safety, reliability and maintainability, and potential problems such as noise generation and microgravity sensitivity. The next step typically is to weight and score all the criteria. The process of weighting and scoring is helpful in bringing out different priorities and reaching a shared point of view. Group technology selection methods are designed to highlight initial disagreements and produce a shared consensus. Often a frank discussion led by management rather than decision analysts can be more effective. The final selection depends on management and engineering judgment and may include programmatic and organizational factors that are beyond the engineering checklist. The objective of engineering technology selection methods is to provide engineering information to assist management in making sound decisions. Project management and technology selection are assumed to use rational engineering analytic methods, but they often do not. The reason is that human insight, intuition, and “gut feel,” rather than logic, more frequently determine our decisions. Project selection and management are strongly influenced by nonrational psychological influences, which can produce unjustified confidence and determination. Nevertheless, there is a strong need for space projects to do rational project analysis and selection. Demonstrating a rational spirit is necessary for a scientific and technical organization. Professional ethics at its best requires an open, honest, and fair process, without damaging politics. Rational analysis can help improve good projects and avoid selecting bad ones. A sanity check using rational analysis guided by a checklist can help avoid egregious and damaging errors.

Jones, Harry W.

High Reliability Requires More than Providing Spares

It is sometimes optimistically hoped that a space life support system can be kept working throughout a long duration mission by repairing failed components, as long as sufficient spares are flown. It is usually assumed that the components have constant known failure rates. Then the needed numbers of spares can be computed to have any particular probability that all failed components can be replaced by available spares. This approach can provide high reliability if its favorable assumptions, including constant known failure rates, are satisfied. Other favorable assumptions are that the failures are statistically independent, repair will be successful without causing further failures, and all failures are due to internal component failures. These assumptions are not usually justified. The failure rates may be estimates that are inadequately verified because of insufficient testing. Failure rates may change due to materials substitutions, manufacturing changes, redesigns to fix failures, and new failures caused by redesigns. Failures that are not statistically independent may result from one common cause, such as a design or manufacturing error or a cascade of cause and effect, possibly caused by an external event such as a power outage. Repair may be unsuccessful or cause damage. Many failures occur at component interfaces or at the overall systems level, not within isolated components. Other failures causes are completely external to the system, due to assembly, maintenance, and operational errors or to unexpected environmental challenges. Replacement with sufficient spares can compensate for expected internal component failures but may not be able to cope with unpredictable design and manufacturing flaws, human errors, and environmental impacts. Reliability estimates based on providing sufficient spares to compensate for expected failures may be far too high. They are essentially upper bounds on reliability that might be approached if many frequent but often unconsidered failure causes can be eliminated.

spares

Program Promotion Can Distort Space Systems Engineering and Deny Risk

NASA's spectacular success in the Apollo moon landings was achieved against the odds by an obsessive dedication to reducing the great risk. But risk analysis predicted so many astronaut fatalities that it was thought to be unreasonably pessimistic and potentially damaging to the Apollo program. Risk analysis was discontinued, risk was neglected in space shuttle engineering, and so the space shuttle design was unnecessarily dangerous. Since the Apollo era it has been understood that long human space missions would recycle oxygen and water to avoid the very high launch cost of directly supplying them. The development of recycling systems was justified by the need to increase material closure and reduce launch mass. When it was recognized that increasing closure leads to rapidly diminishing returns, the program goal was changed to reducing launch mass and reliability, cost, and risk were considered irrelevant. Systems engineering and especially the discouraging problems of risk and cost have been deliberately ignored because they detract from program promotion, with unfortunate results. Current human launch system design does account for risk and the result strongly resembles Apollo. Current life support design continues to assume recycling, even though the recent great reduction in launch cost now allows direct supply of oxygen and water with significantly better quality, reliability, cost, and risk.

Advocacy

Controls and Automation Research in Space Life Support

A highly controlled and automated life support system has long been a NASA goal. It is usually assumed that life support for future long duration missions will use physical/chemical recycling systems that substantially close the oxygen and water circulation loops. Such a tightly coupled life support system has been thought to require an overall supervisory control system to minimize crew operation and maintenance activities. The International Space Station (ISS) Environmental Control and Life Support System (ECLSS) was at first expected to have supervisory control and automation. After this was found infeasible during the design of the ISS ECLSS in the early 1990's, it was then expected that the ISS or future mission systems would be upgraded to meet the original expectations. Since then NASA has extensively researched life support system controls and automation. Automation and Artificial Intelligence (AI) have gone through several cycles of enthusiasm and neglect before their recent great achievements, and NASA life support interest has similarly varied. Since the ISS ECLSS was launched, its on-board operational problems have led NASA to deemphasize system level controls and automation in favor of improving subsystem reliability and maintainability. Recent work has investigated supervisory control for a system similar to the ISS ECLSS. This paper reviews past planning and work on the supervisory control of closed, integrated physical/chemical life support systems similar to the ISS ECLSS and its precursors dating back to the 1960's.

life support

Moon Base Life Support Design Depends on Launch Cost, Crew Size, and Mission Duration

Brief human space missions such as Apollo and the Space Shuttle used material storage for life support but a long mission such as a space station uses a recycling life support system. The upcoming Moon visits will probably be brief with few crew at first but in the future there may be a long-term or even permanent Moon base with a large crew. The initial life support system will probably use storage and resupply of materials from Earth, but it could be replaced later by recycling, especially if launch cost per kilogram is high. Moon base life support design is investigated considering requirements, performance, reliability, cost, and risk. The launch cost, crew size, and mission duration are variable parameters that affect the life support design choice. Greater launch cost, crew size, or mission duration all tend to make recycling more cost-effective than resupply.

Jones, Harry W.

Dormancy Should Be Avoided for Mars and Deep Space Recycling Life Support

Mars is the crucial goal of human exploration beyond the Earth-moon system. The Mars round trip transit vehicle has been expected to use a regenerative Life Support System (LSS) similar to the one on the International Space Station (ISS). It often assumed that the Mars transit LSS will be operated on the outward trip to Mars, placed in dormancy while the full crew explores the surface, and then restored to operation for the return trip to Earth. The major difference between Mars missions and operations in the Earth-moon system is the need for much higher reliability for Mars missions, since rapid resupply of parts and materials or a quick crew return to Earth are not possible. Mars systems must achieve intrinsic high reliability by design, test, failure analysis, and redesign and then increase operational robustness by providing spare parts and redundant systems. Further requiring the LSS to be capable of dormancy and restoration to operation greatly increases the difficulty of design, test, and verification. The process of implementing dormancy and then restoring operation would add significant risk to the mission. Dormancy should be avoided for Mars and can be avoided several ways. First and most obvious, some crew can remain continually on board. If no crew can remain onboard, dormancy can still be avoided if an unused spare LSS is activated for the return trip, rather than restarting the used out bound system. Systems similar to the ISS LSS would have a significant probability of failure on a Mars trip and therefore would require two or three spares. Another full spare LSS could be provided as the return trip system, rather than refurbishing a used LSS.

dormancy

Cost-Effective High Reliability for Space Life Support Requires Using Storage

Cost-effective high reliability can be achieved in future space life support systems through careful systems analysis and design. This paper outlines a comprehensive approach. Potential future human space missions are described. The mission parameter impacts on life support system design and reliability requirements are discussed. Not all human space missions require high reliability life support. The potential reliability and cost of storage and of recycling life support systems are investigated. Simple storage systems can provide cost-effective high reliability life support where it is needed. More complex recycling systems with lower reliability and higher cost can be used when suitable.

Jones, Harry W.

NASA's Understanding of Risk in Apollo and Shuttle

Mathematical risk analysis was used in Apollo, but it gave unacceptably pessimistic resultsand was discontinued. Shuttle was designed without using risk analysis, under the assumptionthat good engineering would make it very safe. This approach led to an unnecessarily riskydesign, which directly led to the Shuttle tragedies. Although the Challenger disaster wasdirectly due to a mistaken launch decision, it might have been avoided by a safer design. Theultimate cause of the Shuttle tragedies was the Apollo era decision to abandon risk analysis.

Jones, Harry W.

Axiomatic Design Based Analysis and Equivalent Mass Comparison of Alternate Air Revitalization Systems

A proposed Photocatalytic Air Processor (PAP) would combine two atmosphere revitalization functions for a crewed spacecraft, carbon dioxide removal and oxygen provision. The axiomatic design method is used to develop the general requirements and alternate system designs that combine these two atmosphere revitalization functions. There are two current atmosphere revitalization approaches. Short missions such as the space shuttle use lithium hydroxide (LiOH) to remove carbon dioxide and tanks to provide oxygen. The ISS (International Space Station) uses the CDRA (Carbon Dioxide Removal Assembly) to remove carbon dioxide and a Sabatier reactor and OGA (Oxygen Generation Assembly) to provide oxygen. The PAP could replace either of these combined systems, LiOH and oxygen tanks or the CDRA, Sabatier, and OGA. Axiomatic design is used to investigate these alternate high level system designs for atmosphere revitalization. The axiomatic design approach develops the requirements and design together from higher to lower system level, using a back-and-forth and top-down process. One objective is to reduce the coupling between design elements, which is a measure of system complexity. The equivalent system mass of the alternate systems is compared.

Jones, Harry W.

The Future Impact of Much Lower Launch Cost

For decades, the high cost of space launch has been the greatest limiting factor on the nu ber and size of space missions. Recently commercial rockets have reduced launch cost to about one-twentieth of the space shuttle cost. This provides opportunities for a matching reduction in the cost of space systems and more and more massive missions. High launch costs greatly increase the cost of developing space systems, since the need to reduce mass forces the use of light materials, high packaging densities, and fragile structures that are difficult to manufacture and test. Lower launch costs allow the use of more robust and well tested off-the-shelf systems. Increased mass can be used to increase single string reliability and also to provide spares and redundancy. A crewed mission can benefit from lower launch costs by using mass to provide more accepted fully hydrated food, additional hygiene water, laundry, radiation shielding, and even artificial gravity. The crew can be made healthier, safer, more comfortable, and more productive. Lower launch cost makes every space activity easier, whether it is science, human exploration, commercial including communications, weather, surveillance, and geo-positioning services, or the defense of similar military services. Most of the solar system is empty space, with the energy of the sun’s radiation passing through to the cold of deep space. The missing mass needed to support human activities is now much easier to provide.

Jones, Harry W.

Improving Reliability and Maintainability (R&M) in Space Life Support

This paper considers how to improve the reliability and maintainability (R&M) of future NASA space life support systems. If these systems are procured under an industry contract, defining the R&M requirements would take precedence over providing technical guidance on designing the system. Imposing a specific R&M design could be over constraining. However, the mission may define the overall R&M approach, as the International Space Station (ISS) did by requiring Orbital Replacement Units (ORUs). Before defining the R&M requirements for the next mission, the life support research program should understand and plan the R&M approach. The recent NASA technical standard on R&M has moved away from requiring specific R&M activities during each of the traditional project phases to instead developing and planning to implement the R&M requirements to meet the top level project R&M objectives. The emphasis is on providing the evidence to show that the R&M requirements are met, rather than on conducting specific prescribed R&M activities. The technical standard on R&M defines a comprehensive hierarchy of specific R&M objectives and identifies particular strategies to implement them at each level. That is, the top level R&M objective is defined and then one or more design strategies to implement it are developed immediately, before the next lower objectives are defined and the strategies to achieve those are designed. This step-by-step, top-down approach is similar to the axiomatic design method. The objectives are the R&M requirements, and the strategies are the hardware designs or operations plans developed to meet these requirements. The new R&M process is aligned with the systems design process and helps ensure that the methods to meet the R&M requirements are built into the design.

Jones, Harry W.

The Recent Large Reduction in Space Launch Cost

The development of commercial launch systems has substantially reduced the cost of space launch. NASA’s space shuttle had a cost of about $1.5 billion to launch 27,500 kg to Low Earth Orbit (LEO), $54,500/kg. SpaceX’s Falcon 9 now advertises a cost of $62 million to launch 22,800 kg to LEO, $2,720/kg. Commercial launch has reduced the cost to LEO by a factor of 20. This will have a substantial impact on the space industry, military space, and NASA. Existing launch providers are reducing their costs and so are satellite developers. The military foresees an opportunity to rapidly replace compromised space assets that provided communications, weather, surveillance, and positioning. NASA supported the development of commercial space launch and NASA science anticipates lower cost missions, but human space flight planning seems unreactive. Specifically, it has been claimed that commercial spaceflight has not reduced the cost to provide cargo to the International Space Station (ISS). The key factor is that the space shuttle can provide cargo and crew to ISS while the Falcon 9 must also use the Dragon capsule, which adds cost and reduces payload. The cost of a Falcon 9 and Dragon capsule mission to ISS is about $140 million with a payload of 6,000 kg, $23,300/kg. The shuttle payload to ISS is less than to LEO, 16,050 kg, so its cost is also higher at $93,400/kg. The launch cost to ISS has been reduced by a factor of 4. Calculations that show commercial launch provides no cost reduction to ISS assume half the usually cited shuttle cost and allocate it to the actual delivered payload, about half the full capacity. In a split mission, with crew and pressurized cargo launched separately from hardware and materials, the higher Falcon 9 plus Dragon costs would apply only to a fraction of the launch mass. A 4 to 1 cost reduction saves most, 75%, of the total cost. A further reduction to 10 or 20 to 1 saves 90 or 95%, but this is only a small, 15 or 20%, portion of the original cost. The recently reduced space launch cost can be expected to substantially impact human space flight.

Jones, Harry W.