Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Common Cause Failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Development of a Numerical Model of Hypervelocity Impact into a Pressurized Composite Overwrapped Pressure Vessel

As the outlook for space exploration becomes more ambitious and spacecraft travel deeper into space than ever before, it is increasingly important that propulsion systems perform reliably within the space environment. The increased reliability compels designers to increase design margin at the expense of system mass, which contrasts with the need to limit vehicle mass to maximize payload. Such are the factors that motivate the integration of high specific strength composite materials in the construction of pressure vessels commonly referred to as composite overwrapped pressure vessels (COPV). The COPV consists of a metallic liner for the inner shell of the COPV that is stiff, negates fluid permeation and serves as the anchor for composite laminates or filaments, but the liner itself cannot contain the stresses from the pressurant it contains. The compo-site-fiber reinforced polymer (CFRP) is wound around the liner using a combination of hoop (circumferential) and helical orientations. Careful consideration of wrap orientation allows the composite to evenly bear structural loading and creates the COPV's characteristic high strength to weight ratio. As the CFRP overwrap carries most of the stresses induced by pressurization, damage to the overwrap can affect mission duration, mission success and potentially cause loss-of-vehicle/loss-of-crew. For this reason, it is critical to establish a fundamental understanding of the mechanisms involved in the failure of a stressed composite such as that of the COPV. One of the greatest external threats to the integrity of a spacecraft's COPV is an impact from the meteoroid and orbital debris environments (MMOD). These impacts, even from submillimeter particles, generate extremely high stress states in the CFRP that can damage numerous fibers. As a result of this possibility, initial assumptions in survivability analysis for some human-rated NASA space-craft have assumed that any alteration of the vessel due to impact is considered a catastrophic failure. This assumption is conservative and made due to lack of knowledge on the level of allow-able damage to the composite overwrap that can be sustained and still allow successful completion of the mission. To quantify the allowable damage level to the composite overwrap involves assessing stress redistribution following damage as well as evaluating possible time-dependent mechanisms involved in the COPV response to an impact event. Limited published work in this subject has shown that COPV can withstand at least some level of damage due to high energy impacts. These observations have been confirmed and expanded upon in recent experimental research performed by NASA. This research has demonstrated that there is not only robustness in a COPV to compensate for CFRP damage, but has also identified two significant failure modes for pressurized COPV. The lowest threshold failure mode involves the perforation of the vessel, and the highest threshold failure mode is the catastrophic rupture. While both of these failure modes mean a loss of the COPV, system robustness affords some tolerance to the venting as opposed to the more catastrophic rupture. As a consequence, it is necessary to understand the conditions that result in the transition between these failure modes. The aforementioned experimental research has been performed in both the unpressurized and pressurized condition to identify the damage level that triggered the failure thresh-old. This COPV test program was sponsored by the NASA Engineering and Safety Center (NESC), and tests were performed at NASA White Sands Test Facility (WSTF). Planning and coordination were provided by NASA JSC Hypervelocity Impact Technology (HVIT) group, and the COPVs were provided by the ISS Program. Unpressurized testing has been conducted at the pressure of the vacuum test chamber, while, the pressurized testing has been conducted at 290 +/- 10 bar (4,200  100 psi) using nitrogen as the pressurizing gas, which corresponds to the design pressure for the target COPV. In this research, spherical aluminum projectiles with varying diameter has been chosen as the impactor. For the unpressurized COPV, the dependence of penetration up to the dependence of hole size in the liner has been obtained as a function of impact conditions. For the pressurized research, the dependence of penetration up to rupture has been obtained as a function of im-pact conditions. Two representative post-test photographs of the failed COPV's from a nor-mal impact into the COPV surface are shown in Fig. 1. These images display the dramatic difference between failure modes, venting (Fig. 1a) and rupture (Fig. 1b). For venting, liner perforation, severed composite fibers/tows and ply delamination are commonly observed damage characteristics of this COPV failure mode. In the case of rupture, the COPV typically experienced a separation of its domed regions and severe break-up of the cylindrical region. Fully understanding the transition from venting to rupture experimentally is costly and potentially unachievable for conditions that cannot be generated in the laboratory. These shortcomings have motivated the performance of three-dimensional numerical simulations to expand the existing experimental database. These simulations have been carried out with the nonlinear-structural-dynamics, analysis-tool, CTH. A typical pressure contour plot from an impact simulation of an entire COPV is shown in Fig. 2. To generate the COPV stress state without initiating a shock wave, the pressure in the simulated COPV is ramped up to the final pressure over a millisecond prior to impact of the projectile with nitrogen gas. Figure 2a shows the system in this initial condition. After one millisecond, a projectile is initiated into the simulation and impacts the COPV. Figure 2b shows the system after this impact. In the figure, the onset of venting is represented as the change in pressure (μbar), red to green, at the perforation site. Also seen in the figure is the eroded projectile that had passed into the COPV vessel with the generated shock wave in the pressurant propagating just ahead of the material. In this paper, pertinent experimental details and the development of the material constitutive models necessary for this work along with the efforts to validate their use are dis-cussed. The simulation results are presented and compared with the NASA experimental observations. While work is on-going from this effort, early observations pertinent to the failure threshold are presented.

Garcia, M. A.↗

One-Step Ahead Prediction of Thermal Mixing Tee Sensors with Long Short Term Memory (LSTM) Neural Networks

High-temperature advanced reactors under development, such as sodium fast reactors (SFR) and molten salt cooled reactors (MSCR), are expected to offer lower levelized cost of energy (LCOE) compared to existing light water reactor (LWR’s). In the existing light water reactors (LWR’s), operation and maintenance (O&M) expenses constitute the largest fraction of the total operating cost. Some of the O&M costs are related maintenance of sensors which can fail due to exposure to harsh environment in a reactor. The O&M costs of Advanced Reactor (AR)’s are expected to constitute a significant fraction of the total cost as well, because of high temperature and radiation level in AR are likely to cause material fatigue and premature failure of sensors and components. The O&M costs in AR’s could be reduced through integration of advanced informatics of performance-related sensors into a digital twin designed for reactor monitoring. For example, machine learning (ML) could be employed for real-time validation and correction of performance-related sensors, and reducing the number of performance-related physical sensor units through virtual sensing. As part of the effort, we investigate real-time validation of thermal hydraulic sensors through one-step ahead forecasting of sensor values using long short-term memory (LSTM) recurrent neural networks (RNN). The sensors are installed in a flow loop containing a thermal mixing tee, which is a common experimental model to study thermal fatigue in a thermal hydraulic loop. In addition, nonlinear transients generated in a thermal mixing tee constitute a good challenge data set for training and validation of ML algorithms. Sensors in this study include thermocouples, flow meters, and optical fibers for distributed temperature sensing. In one experiment, measurement data sets were obtained for a loop was filled with water, and in another experiment, measurements were performed on a loop filled with liquid metal Galinstan. We have also conducted preliminary investigation of one-step ahead prediction of fiber optics-based distributed temperature sensing with LSTM networks. In predicting fiber-based temperature measurements, we treated each gauge pitch of the fiber as an independent sensor. Accuracy of one-step ahead forecasting was estimated by calculating root mean square error (RMSE) for the test segment of time series of each sensor. RMSE’s for temperature sensors in water loop were, for the most part, lower than for the same sensors in Galinstan loop. The RMSE’s for flow meters were similar for both loops. The RMSE’s for distributed temperature measured with the fiber optic sensor were similar to those of the point sensors. Results of this study demonstrated the capability of LSTM one-step ahead forecasting with RMSE comparable to uncertainty in sensor measurements.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Is Model-Based Development a Favorable Approach for Complex and Safety-Critical Computer Systems on Commercial Aircraft?

A system is safety-critical if its failure can endanger human life or cause significant damage to property or the environment. State-of-the-art computer systems on commercial aircraft are highly complex, software-intensive, functionally integrated, and network-centric systems of systems. Ensuring that such systems are safe and comply with existing safety regulations is costly and time-consuming as the level of rigor in the development process, especially the validation and verification activities, is determined by considerations of system complexity and safety criticality. A significant degree of care and deep insight into the operational principles of these systems is required to ensure adequate coverage of all design implications relevant to system safety. Model-based development methodologies, methods, tools, and techniques facilitate collaboration and enable the use of common design artifacts among groups dealing with different aspects of the development of a system. This paper examines the application of model-based development to complex and safety-critical aircraft computer systems. Benefits and detriments are identified and an overall assessment of the approach is given.

Torres-Pomales, Wilfredo↗

Towards Comprehensive Variation Models for Designing Vehicle Monitoring Systems

When designing vehicle vibration monitoring systems for aerospace devices, it is common to use well-established models of vibration features to determine whether failures or defects exist. Most of the algorithms used for failure detection rely on these models to detect significant changes in a flight environment. In actual practice, however, most vehicle vibration monitoring systems are corrupted by high rates of false alarms and missed detections. This crucial roadblock makes their implementation in real vehicles (e.g., helicopter transmissions and aircraft engines) difficult, making their operation costly and unreliable. Research conducted at the NASA Ames Research Center has determined that a major reason for the high rates of false alarms and missed detections is the numerous sources of statistical variations that are not taken into account in the modeling assumptions. In this paper, we address one such source of variations, namely, those caused during the design and manufacturing of rotating machinery components that make up aerospace systems. We present a novel way of modeling the vibration response by including design variations via probabilistic methods. Using such models, we develop a methodology to account for design and manufacturing variations, and explore the changes in the vibration response to determine its stochastic nature. We explore the potential of the methodology using a nonlinear cam-follower model, where the spring stiffness values are assumed to follow a normal distribution. The results demonstrate initial feasibility of the method, showing great promise in developing a general methodology for designing more accurate aerospace vehicle monitoring systems.

McAdams, Daniel A.↗

TTEthernet for Integrated Spacecraft Networks

Aerospace projects have traditionally employed federated avionics architectures, in which each computer system is designed to perform one specific function (e.g. navigation). There are obvious downsides to this approach, including excessive weight (from so much computing hardware), and inefficient processor utilization (since modern processors are capable of performing multiple tasks). There has therefore been a push for integrated modular avionics (IMA), in which common computing platforms can be leveraged for different purposes. This consolidation of multiple vehicle functions to shared computing platforms can significantly reduce spacecraft cost, weight, and design complexity. However, the application of IMA principles introduces significant challenges, as the data network must accommodate traffic of mixed criticality and performance levels - potentially all related to the same shared computer hardware. Because individual network technologies are rarely so competent, the development of truly integrated network architectures often proves unreasonable. Several different types of networks are utilized - each suited to support a specific vehicle function. Critical functions are typically driven by precise timing loops, requiring networks with strict guarantees regarding message latency (i.e. determinism) and fault-tolerance. Alternatively, non-critical systems generally employ data networks prioritizing flexibility and high performance over reliable operation. Switched Ethernet has seen widespread success filling this role in terrestrial applications. Its high speed, flexibility, and the availability of inexpensive commercial off-the-shelf (COTS) components make it desirable for inclusion in spacecraft platforms. Basic Ethernet configurations have been incorporated into several preexisting aerospace projects, including both the Space Shuttle and International Space Station (ISS). However, classical switched Ethernet cannot provide the high level of network determinism required by real-time spacecraft applications. Even with modern advancements, the uncoordinated (i.e. event-driven) nature of Ethernet communication unavoidably leads to message contention within network switches. The arbitration process used to resolve such conflicts introduces variation in the time it takes for messages to be forwarded. TTEthernet1 introduces decentralized clock synchronization to switched Ethernet, enabling message transmission according to a time-triggered (TT) paradigm. A network planning tool is used to allocate each device a finite amount of time in which it may transmit a frame. Each time slot is repeated sequentially to form a periodic communication schedule that is then loaded onto each TTEthernet device (e.g. switches and end systems). Each network participant references the synchronized time in order to dispatch messages at predetermined instances. This schedule guarantees that no contention exists between time-triggered Ethernet frames in the network switches, therefore eliminating the need for arbitration (and the timing variation it causes). Besides time-triggered messaging, TTEthernet networks may provide two additional traffic classes to support communication of different criticality levels. In the rate-constrained (RC) traffic class, the frame payload size and rate of transmission along each communication channel are limited to predetermined maximums. The network switches can therefore be configured to accommodate the known worst-case traffic pattern, and buffer overflows can be eliminated. The best-effort (BE) traffic class behaves akin to classical Ethernet. No guarantees are provided regarding transmission latency or successful message delivery. TTEthernet coordinates transmission of all three traffic classes over the same physical connections, therefore accommodating the full spectrum of traffic criticality levels required in IMA architectures. Common computing platforms (e.g. LRUs) can share networking resources in such a way that failures in non-critical systems (using BE or RC communication modes) cannot impact flight-critical functions (using TT communication). Furthermore, TTEthernet hardware (e.g. switches, cabling) can be shared by both TTEthernet and classical Ethernet traffic.

Loveless, Andrew↗

A Near-Term Concept for Trajectory Based Operations with Air/Ground Data Link Communication

An operating concept and required system components for trajectory-based operations with air/ground data link for today's en route and transition airspace is proposed. Controllers are fully responsible for separation as they are today, and no new aircraft equipage is required. Trajectory automation computes integrated solutions to problems like metering, weather avoidance, traffic conflicts and the desire to find and fly more time/fuel efficient flight trajectories. A common ground-based system supports all levels of aircraft equipage and performance including those equipped and not equipped for data link. User interface functions for the radar controller's display make trajectory-based clearance advisories easy to visualize, modify if necessary, and implement. Laboratory simulations (without human operators) were conducted to test integrated operation of selected system components with uncertainty modeling. Results are based on 102 hours of Fort Worth Center traffic recordings involving over 37,000 individual flights. The presence of uncertainty had a marginal effect (5%) on minimum-delay conflict resolution performance, and windfavorable routes had no effect on detection and resolution metrics. Flight plan amendments and clearances were substantially reduced compared to today s operations. Top-of-descent prediction errors are the largest cause of failure indicating that better descent predictions are needed to reliably achieve fuel-efficient descent profiles in medium to heavy traffic. Improved conflict detections for climbing flights could enable substantially more continuous climbs to cruise altitude. Unlike today s Conflict Alert, tactical automation must alert when an altitude amendment is entered, but before the aircraft starts the maneuver. In every other failure case tactical automation prevented losses of separation. A real-time prototype trajectory trajectory-automation system is running now and could be made ready for operational testing at an en route Center in 1-2 years.

McNally, David↗

Accounting for Point Estimate Uncertainty in Space Systems Reliability and Risk Analysis

Understanding and accounting for uncertainty in risk analysis is a critical step in the management and communication of risk in engineered systems. The component and system-level analysis to determine the probability of a negative outcome and its consequence is often quantified by a point estimate. Many Program and Enterprise decisions involving technical concerns and issues rely on reliability engineering activities to produce quantified risk analysis to inform the decision making process. At NASA, it is common to use a Probabilistic Risk Analysis (PRA) to inform the overall risk to Loss of Mission or Loss of Crew that involves integration across all spacecraft subsystem fault trees to produce an overall probability of mission failure. The point estimate is an estimate of this overall probability and is an immediate result of a fault tree model. It is the result of a model where the probability of each event is taken to be equal to its mean. The value provides an approximation of the overall mean without running any uncertainty calculations (e.g., no sampling). Using only the point estimate can lead to a false sense of precision and the point estimate may not match the resulting mean when uncertainty is taken into consideration. This paper will explore five conditions that can cause the PRA model mean to diverge from the point estimate and will provide engineers and managers insight into the importance of understanding uncertainty in the elements of PRA models.

Paul J Collier↗

Radiation portal monitor data file format for comprehensive background radiation monitoring

Radiation portal monitors (RPMs) are widely used at border security checkpoints to detect the presence of radioactive materials in people, vehicles, and cargo. Typically, RPM detection systems consist of two pillars equipped with gamma and neutron detectors. To improve detection efficiency, RPMs employ techniques such as a limited energy window, dynamic alarm thresholds, and lead shielding. However, without continuous monitoring of background radiation, signal interpretation can be compromised, because environmental factors and mechanical failures can cause fluctuations. Here, we introduce a daily file format that logs gamma background and neutron background radiation levels continuously over a 24 h period; this format is different from traditional formats that record data only when the RPM is active or occupied. The approach enables RPM operators and analysts to (1) identify and diagnose malfunctioning components, (2) adjust system settings to account for dynamic environmental factors, and (3) use the recorded data to characterize outer space phenomena. Continuous background reporting is essential for identifying issues such as faulty connections, voltage divider failures, and errors in background updates. Continuous background reporting also enables the detection of external influences, including nearby X-ray scanners, temperature fluctuations, rainfall, cosmic radiation, and lunar phase changes. These data files are designed to be easily evaluated and parsed using common tools, and a quick review by an expert is often sufficient for problem diagnosis. We anticipate that continuous background radiation monitoring and these new strategies will significantly improve the accuracy and reliability of RPM systems, reducing the rate of false alarms and enhancing overall system performance.

Background radiation monitoring↗

Timeouts Best Practices

This study investigates common timeouts encountered in the electric vehicle (EV) charging communications process. Many different timeouts are defined within the EV charging communications protocols. These timeouts can either be a fixed value or a defined range of values. In both cases, the timeout defines the duration of time for which one or both parties in the communications session are expected to wait for some action or process to complete before terminating the charge attempt. These timeout-based terminations are intended to prevent the charging process from becoming stuck indefinitely in any particular step. These terminations also enable a retry of the terminated charging session to begin. However, misaligned timeout values can have a significant negative impact on the user experience. Premature termination of charging sessions due to inappropriate timeout settings can lead to charging failures, causing inconvenience, wasted time, and frustration for users. These disruptions can degrade the overall user experience, making it essential to carefully manage and align timeout values with the relevant actions and processes to ensure reliable and satisfactory EV charging sessions. The core objective of this study is to boost reliability and enhance user experience by conducting a thorough review of timeout-based issues in EV charging and delivering a set of recommendations to modify these existing timeouts. These recommendations are informed by feedback gathered from multiple EV charging partners. This document is intended to inform electric vehicle supply equipment (EVSE) and EV manufacturers, EV charging infrastructure developers, and policymakers responsible for designing and implementing EV charging protocols and systems.

33 ADVANCED PROPULSION SYSTEMS↗

Independence of Environmental and Mechanical Damages on Silicone Adhesive Stored in a Thermo-Oxidative Environment

Abstract Elastomeric polymer materials hold a special place in today’s industrial sectors with respect to structural application needs. Low quality materials are detrimental to industries like aerospace, and automotive engineering. Assessment of the durability of elastomers for structural applications has been of much interest among the literary circles for decades and new materials keep outperforming the existing ones. Polymeric adhesives are one of the most abundantly used materials in these industries. All polymeric materials get damaged when in contact with aggressive environments in presence of high temperature and oxygen. Commonly referred to as thermo-oxidation, this environment exposes the material to heat and oxidation reactions in presence of oxygen. Resultantly, during service life, the damage to the polymer matrix is primarily caused by two factors: mechanical damage and environmental aging. Environmental aging is an irreversible phenomenon caused by changes in the molecular structure while mechanical damage maintains the shape of the polymer matrix, and the deterioration is mostly due to polymer chain mobility. Environmental aging can be caused by a single environmental agent or by a synergized impact of several environmental elements. Increasing temperature is found to be proportional to decreasing tensile strength and toughness of material. The rate and extent of degradation can be accessed by scrutinizing the changes in constitutive behavior of material through mechanical and chemical properties. Accelerated thermal aging is among the most common modes of process related degradation, leading generally to chain scission, and crosslinking phenomena and reduced resistance to fracture stress, and strain. In this experimental study, our goal is to separate the environmental degradation from mechanical damage. A silicone-based adhesive was aged in thermo-oxidative at (0%RH) aging environment. The damage and decay mechanisms have been used to draw a distinction between environmental degradation and mechanical damage. Material characterization included uniaxial tensile test (failure and cyclic) and scanning electron microscopy (SEM) tests on as-received and aged samples. Aging was conducted at three different temperatures (60°C, 80°C and 95°C) and six different exposure durations (1, 3, 10, 30, 90 and 200 days). This work confirms that environmental damage is superposed on top of the mechanical damage, and thus, they are separable. The total mechanical and environmental damage is a synergized effect of all exposure conditions and parameters involved i.e., aging time, temperature, and oxygen. The chemistry and mechanics of the polymer degradation were found to be in good agreement with each other.

Alazhary, Sharif↗

International Space Station Crew Quarters Ventilation and Acoustic Design Implementation

The International Space Station (ISS) United States Operational Segment has four permanent rack sized ISS Crew Quarters (CQs) providing a private crew member space. The CQs use Node 2 cabin air for ventilation/thermal cooling, as opposed to conditioned ducted air-from the ISS Common Cabin Air Assembly (CCAA) or the ISS fluid cooling loop. Consequently, CQ can only increase the air flow rate to reduce the temperature delta between the cabin and the CQ interior. However, increasing airflow causes increased acoustic noise so efficient airflow distribution is an important design parameter. The CQ utilized a two fan push-pull configuration to ensure fresh air at the crew member's head position and reduce acoustic exposure. The CQ ventilation ducts are conduits to the louder Node 2 cabin aisle way which required significant acoustic mitigation controls. The CQ interior needs to be below noise criteria curve 40 (NC-40). The design implementation of the CQ ventilation system and acoustic mitigation are very inter-related and require consideration of crew comfort balanced with use of interior habitable volume, accommodation of fan failures, and possible crew uses that impact ventilation and acoustic performance. Each CQ required 13% of its total volume and approximately 6% of its total mass to reduce acoustic noise. This paper illustrates the types of model analysis, assumptions, vehicle interactions, and trade-offs required for CQ ventilation and acoustics. Additionally, on-orbit ventilation system performance and initial crew feedback is presented. This approach is applicable to any private enclosed space that the crew will occupy.

Broyan, James L., Jr.↗

Collective Summary of sCO2 Materials Development (Supercritical Transformational Electric Power Generation (STEP) Level 2 Milestone Report) (Parts I - II)

Polymers such as PTFE (polytetrafluorethylene or Teflon), EPDM (ethylene propylene diene monomer) rubber, FKM fluoroelastomer (Viton), Nylon 11, Nitrile butadiene (NBR) rubber, hydrogenated nitrile rubber (HNBR) and perfluoroelastomers (FF_202) are commonly employed in super critical CO 2 (sCO2) energy conversion systems. O-rings and gaskets made from these polymers face stringent performance conditions such as elevated temperatures, high pressures, pollutants, and corrosive humid environments. In FY 2019, we conducted experiments at high temperatures (100°C and 120°C) under isobaric conditions (20 MPa). Findings showed that elevated temperatures accelerated degradation of polymers in sCO2, and that certain polymer microstructures are more susceptible to degradation over others. In FY 2020, the focus was to understand the effect of sCO2 on polymers at low (10 MPa) and high pressures (40 MPa) under isothermal conditions (100°C). It was clear that the same selectivity was observed in these experiments wherein certain polymeric functionalities showed more propensity to failure over others. Fast diffusion, supported by higher pressures and long exposure times (1000 hours) at the test temperature, caused increased damage in sCO2 environments to even the most robust polymers. We also looked at polymers under compression in sCO2 at 100°C and 20 MPa pressure to imitate actual sealing performance required of these materials in sCO2 systems. Compression worsened the physical damage that resulted from chemical attack of the polymers under these test conditions. In FY 2021, the effect of cycling temperature (from 50°C to 150°C to 50°C) for polymers under a steady sCO2 pressure of 20 MPa was studied. The aim was to understand the influence of cycling temperatures of sCO2 for typical polymers under isobaric (20 MPa) conditions. Thermoplastic polymers (Nylon, and PTFE) and elastomers (EPDM, Viton, Buna N, Neoprene, FF202, and HNBR) were subjected to 20 MPa sCO2 pressure for 50 cycles and 100 cycles in separate experiments. Samples were extracted for ex-situ characterization at 50 cycles and upon the completion of 100 cycles. Each cycle constituted of 175 minutes of cycling from 50°C to 150°C. The polymer samples were examined for physical and chemical changes by Dynamic Mechanical and Thermal Analysis (DMTA), Fourier Transform Infrared (FTIR) spectroscopy, and compression set. Density and mass changes immediately after removal from test were measured for degree of swell comparisons. Optical microscopy techniques and micro computer tomography (micro CT) images were collected on select specimens. Evaluations conducted showed that exposures to super-critical CO2 environments resulted in combinations of physical and/or chemical changes. For each polymer, the dominance of cycling temperatures under sCO2 pressures, were evaluated. Attempts were made to qualitatively link the permanent sCO2 effects to polymer micro- structure, free volume, backbone substitutions, presence of polar groups, and degree of crystallinity differences. This study has established that soft polymeric materials are conducive to failure in sCO2 through mechanisms of failure that are dependent on polymer microstructure and chemistry. Polar pendant groups, large atom substitutions on the backbone are some of the factors that are influential structural factors.

36 MATERIALS SCIENCE↗

Managing the techno-economic impacts of partial string failure in multistring energy storage systems

The role of energy storage systems (ESSs) is becoming increasingly important for today’s electric power systems. Unavailability of an ESS assigned to critical grid services may cause unwanted disruption of those services and hence, may have a significant techno-economic impact. Like any physical equipment, an ESS is vulnerable to various types of faults. Failure of one or more strings in a multistring ESS does not have to be the cause of shutting down the entire ESS. It can still operate with a partial number of strings and continue providing critical services to the grid, if there are no reliability or safety issues and is acceptable under applicable standards. However, it is important to make sure that the control strategies are adaptable to the changes in ESS capacity caused by failed strings. Also, depending on the previous operation and type of failure, the reallocation of duty cycle burden among available strings could be non-uniform. These complexities suggest that mitigation of the impact of partial failure in multistring ESSs is not trivial and needs careful consideration. This is the topic of this paper. The proposed work investigates the impact of partial failure of a large multistring ESS on the assigned service and develops strategies to adjust the ESS control duty cycles for reducing such impacts. In doing so, the paper proposes a novel two-stage framework that plans for the multistring failure using robust optimization theory and then adjusts in real-time using a rule-based algorithm, based on the real-time information on the power availability of the string. Illustrations provided in this work are based on frequency regulation use-case, which is a common application for many utility-scale ESSs. A 750 kilowatt (kW)/1500 kilowatt-hour (kWh) 3-string ESS is used for the demonstration in this work and the efficacy of the proposed method is demonstrated and compared against methods that do not incorporate string failure in their strategy. In particular, here we show that revenue loss of 93% can be incurred when partial string failure is not included in operation and planning. These losses in revenue are reduced by 60% with the proposed method.

25 ENERGY STORAGE↗

Space station common module network topology and hardware development

Conceptual space station common module power management and distribution (SSM/PMAD) network layouts and detailed network evaluations were developed. Individual pieces of hardware to be developed for the SSM/PMAD test bed were identified. A technology assessment was developed to identify pieces of equipment requiring development effort. Equipment lists were developed from the previously selected network schematics. Additionally, functional requirements for the network equipment as well as other requirements which affected the suitability of specific items for use on the Space Station Program were identified. Assembly requirements were derived based on the SSM/PMAD developed requirements and on the selected SSM/PMAD network concepts. Basic requirements and simplified design block diagrams are included. DC remote power controllers were successfully integrated into the DC Marshall Space Flight Center breadboard. Two DC remote power controller (RPC) boards experienced mechanical failure of UES 706 stud-mounted diodes during mechanical installation of the boards into the system. These broken diodes caused input to output shorting of the RPC's. The UES 706 diodes were replaced on these RPC's which eliminated the problem. The DC RPC's as existing in the present breadboard configuration do not provide ground fault protection because the RPC was designed to only switch the hot side current. If ground fault protection were to be implemented, it would be necessary to design the system so the RPC switched both the hot and the return sides of power.

Anderson, P.↗

Dispenser Reliability: Materials R&D. A Hydrogen Fueling Infrastructure Research and Station Technology (H2FIRST) Report

Dispensers are the top cause of maintenance events and down-time at hydrogen fueling stations. In an effort to help characterize and enable improvements in dispenser reliability, an extensive accelerated lifetime testing set-up was designed and built at NREL involving components typically part of dispensing operations at fueling stations. Device Under Test (DUTs) included different components such as normally open valves, normally closed valves, fueling nozzles, breakaways devices and filters. Conditions of testing included pressures, and flow rates similar to light duty fuel cell electric vehicles fueling at -40°C, and -20°C for thousands of cycles in hydrogen. Tested components (failed and non-failed) were disassembled at SNL and polymeric O-rings were carefully retrieved and cataloged for chemical and physical characterization. Data collected was compared to similar O-rings from unexposed or non-tested components for hydrogen effects, and failure modes. Degradation analyses, based on select polymer chemistries common across all component types, their location within components, visual assessment of damage coupled with strong hydrogen effects from chemical characterization, was completed and presented to NREL and DOE. Overall, the failure rate amongst the components was not as high as expected for the test conditions. Among the component types tested, breakaways were the most susceptible to damage under these test conditions, with fueling nozzles a close second. The proper combination of selection of the right polymer and optimum component design was found to make a strong difference in component reliability under severe dispenser operating conditions. Physical degradation of polymers, rather than chemical changes due to low temperature hydrogen exposure, is more prevalent as failure mode for these test conditions. The nature and the extent of the degradation was much less at -20°C as compared to -40°C. The damage and failure rates were higher at lower temperatures than at higher test temperatures. As expected, increasing the number of cycles at the lowest test temperature (-40°C) increased damage. This indicates that cycling at the low temperature of -40°C required by SAE J2601 can reduce component life in fuel dispensing operations

08 HYDROGEN↗

A Risk Analysis Tool for Estimating the Risk of Electrical Failures Due to Human Induced Defects

Aerospace electrical systems are required to withstand and adequately operate in extremely harsh environments that include, for example, high radiation exposure, temperature extremes, intense vibrational stress and drastic temperature cycling. The nature of aerospace electronics also demands high reliability since, with very few exceptions, there is no chance for hardware servicing or repairs. Common risk mitigation techniques for this type of situation are to perform a Reliability Analysis of the system throughout the development cycle, and to use electrical components that are regarded as “high reliability” because of additional controls and requirements applied in their design, manufacturing and testing. Unfortunately, studies have shown that even though these techniques are used, many systems fail to meet mission requirements well before the predicted lifetimes. This paper presents the analysis of failures of electrical parts, experienced during various stages of system development, at NASA Goddard Space Flight Center, Greenbelt MD, between the years 2001 and 2013. These components were subjected to qualification, screening and testing in which the goal was to ensure that the components would survive the stresses of the mission. The analysis categorizes failures by part type and failure mechanisms. One of the results of the analysis was the realization that a surprising proportion of failures experienced during system integration and testing were caused by human error (i.e. human induced defect). Further analysis included the determination of root failure mechanisms and any influencing factors contributing to these failures. The major causes of these defects were attributed to electrostatic damage (ESD), electrical overstress (EOS), mechanical overstress (MOS), and thermal overstress (TOS). Finally, the study proposes a risk analysis tool which incorporates these major causes for the failures, termed error-producing conditions (EPCs), and a proportionality factor representing the number of each type of failure that has occurred at the facility under study. These factors are quantified and used to communicate the risk of human induced defects for the assembly, integration and testing of space hardware based on the system’s electrical parts list. The new risk identification can trigger risk-mitigating actions more effectively, based on the presence of component categories or other hazardous conditions that have a history of failure due to human error.

Majewicz, Peter J.↗

X-31 Mishap: Lessons Learned

The experimental X-31 High Angle of Attack Research Aircraft crashed during a 1995 test mission flight conducted by NASA at Edwards Air Force Base, California. The pilot lost control of the airplane and was forced to eject, sustaining a permanent back injury that ended his flying career. Prior to this incident the airplane had a perfect record of several hundred non-eventful flights supported by an experienced team. During the subsequent investigation by a mishap committee it was discovered that a series of cascading events contributed to this accident. Some of the identified contributing factors that resulted in this mishap are common to aircraft design and to flight-test in general. The mistakes and the solutions are presented here so that the flight-test community may consider and learn from them. The primary cause of the crash was icing and, ultimately, a complete blockage of the pitot-static nose probe. The icing was caused by a freak weather phenomenon that was neither expected nor known to exist on the day of the mishap. The normal probe had been replaced with a special Kiel probe to allow total pressure measurements of up to 70 degrees angle of attack for flight-test purposes. The Kiel probe did not include a heater, because it was assumed that the airplane would not be flown in the clouds or in conditions conducive to icing. This assumption was later proven to be incorrect. The iced Kiel probe caused incorrect gain scheduling in the flight control system, resulting in an unstable aircraft. This failure was essentially undetected because of a faulty design in the flight control system architecture. There were, however, also a number of other issues that lead up to this situation that never should have happened. This presentation discusses what the issues were that contributed to the incident. After the incident was investigated, some of these issues were addressed and some changes were made. The second X-31 aircraft flew the remainder of the flight tests, and the program was successfully completed without incident. This presentation also shows a video of the mishap including lessons learned, and the changes that were made to resume the flight-test program are presented.

Larson, Richard R.↗

Natural Language Processing Techniques for Intelligent Knowledge Management of Safety Reports

Safety, failure, and incident reports are common artifacts across various domains, including aviation and wildfire response. These reports are often mandatory to submit, resulting in the culmination of large repositories of text-based documents. Simultaneously, these reports and corresponding repositories are often only manually analyzed and queried by users via out-of-date search engines. As a consequence, we have been developing the Manager for Intelligent Knowledge Access (MIKA) toolkit, which uses natural language processing to improve information access and reuse. In this presentation, we discuss natural language processing techniques for knowledge discovery and apply these methods to a repository of aerial wildfire mishap reports. Two methods are used for knowledge discovery: topic modeling and named-entity recognition. We use topic modeling to identify hazards and perform a trend analysis to produce a data-driven risk matrix. A custom named-entity recognition model, build from fine tuning a pre-trained language model, is used to identify failure modes, failure causes, failure effects, control processes, and recommendations to aid in failure modes and effects analysis (FMEA). Throughout the presentation, we discuss and apply natural language processing techniques to better leverage the vast amount of information contained in report repositories.

Machine learning↗