Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Common Cause Failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 199 records · Page 11

International Space Station Crew Quarters Ventilation and Acoustic Design Implementation

The International Space Station (ISS) United States Operational Segment has four permanent rack sized ISS Crew Quarters (CQs) providing a private crew member space. The CQs use Node 2 cabin air for ventilation/thermal cooling, as opposed to conditioned ducted air-from the ISS Common Cabin Air Assembly (CCAA) or the ISS fluid cooling loop. Consequently, CQ can only increase the air flow rate to reduce the temperature delta between the cabin and the CQ interior. However, increasing airflow causes increased acoustic noise so efficient airflow distribution is an important design parameter. The CQ utilized a two fan push-pull configuration to ensure fresh air at the crew member's head position and reduce acoustic exposure. The CQ ventilation ducts are conduits to the louder Node 2 cabin aisle way which required significant acoustic mitigation controls. The CQ interior needs to be below noise criteria curve 40 (NC-40). The design implementation of the CQ ventilation system and acoustic mitigation are very inter-related and require consideration of crew comfort balanced with use of interior habitable volume, accommodation of fan failures, and possible crew uses that impact ventilation and acoustic performance. Each CQ required 13% of its total volume and approximately 6% of its total mass to reduce acoustic noise. This paper illustrates the types of model analysis, assumptions, vehicle interactions, and trade-offs required for CQ ventilation and acoustics. Additionally, on-orbit ventilation system performance and initial crew feedback is presented. This approach is applicable to any private enclosed space that the crew will occupy.

Broyan, James L., Jr.↗

Collective Summary of sCO2 Materials Development (Supercritical Transformational Electric Power Generation (STEP) Level 2 Milestone Report) (Parts I - II)

Polymers such as PTFE (polytetrafluorethylene or Teflon), EPDM (ethylene propylene diene monomer) rubber, FKM fluoroelastomer (Viton), Nylon 11, Nitrile butadiene (NBR) rubber, hydrogenated nitrile rubber (HNBR) and perfluoroelastomers (FF_202) are commonly employed in super critical CO 2 (sCO2) energy conversion systems. O-rings and gaskets made from these polymers face stringent performance conditions such as elevated temperatures, high pressures, pollutants, and corrosive humid environments. In FY 2019, we conducted experiments at high temperatures (100°C and 120°C) under isobaric conditions (20 MPa). Findings showed that elevated temperatures accelerated degradation of polymers in sCO2, and that certain polymer microstructures are more susceptible to degradation over others. In FY 2020, the focus was to understand the effect of sCO2 on polymers at low (10 MPa) and high pressures (40 MPa) under isothermal conditions (100°C). It was clear that the same selectivity was observed in these experiments wherein certain polymeric functionalities showed more propensity to failure over others. Fast diffusion, supported by higher pressures and long exposure times (1000 hours) at the test temperature, caused increased damage in sCO2 environments to even the most robust polymers. We also looked at polymers under compression in sCO2 at 100°C and 20 MPa pressure to imitate actual sealing performance required of these materials in sCO2 systems. Compression worsened the physical damage that resulted from chemical attack of the polymers under these test conditions. In FY 2021, the effect of cycling temperature (from 50°C to 150°C to 50°C) for polymers under a steady sCO2 pressure of 20 MPa was studied. The aim was to understand the influence of cycling temperatures of sCO2 for typical polymers under isobaric (20 MPa) conditions. Thermoplastic polymers (Nylon, and PTFE) and elastomers (EPDM, Viton, Buna N, Neoprene, FF202, and HNBR) were subjected to 20 MPa sCO2 pressure for 50 cycles and 100 cycles in separate experiments. Samples were extracted for ex-situ characterization at 50 cycles and upon the completion of 100 cycles. Each cycle constituted of 175 minutes of cycling from 50°C to 150°C. The polymer samples were examined for physical and chemical changes by Dynamic Mechanical and Thermal Analysis (DMTA), Fourier Transform Infrared (FTIR) spectroscopy, and compression set. Density and mass changes immediately after removal from test were measured for degree of swell comparisons. Optical microscopy techniques and micro computer tomography (micro CT) images were collected on select specimens. Evaluations conducted showed that exposures to super-critical CO2 environments resulted in combinations of physical and/or chemical changes. For each polymer, the dominance of cycling temperatures under sCO2 pressures, were evaluated. Attempts were made to qualitatively link the permanent sCO2 effects to polymer micro- structure, free volume, backbone substitutions, presence of polar groups, and degree of crystallinity differences. This study has established that soft polymeric materials are conducive to failure in sCO2 through mechanisms of failure that are dependent on polymer microstructure and chemistry. Polar pendant groups, large atom substitutions on the backbone are some of the factors that are influential structural factors.

36 MATERIALS SCIENCE↗

Managing the techno-economic impacts of partial string failure in multistring energy storage systems

The role of energy storage systems (ESSs) is becoming increasingly important for today’s electric power systems. Unavailability of an ESS assigned to critical grid services may cause unwanted disruption of those services and hence, may have a significant techno-economic impact. Like any physical equipment, an ESS is vulnerable to various types of faults. Failure of one or more strings in a multistring ESS does not have to be the cause of shutting down the entire ESS. It can still operate with a partial number of strings and continue providing critical services to the grid, if there are no reliability or safety issues and is acceptable under applicable standards. However, it is important to make sure that the control strategies are adaptable to the changes in ESS capacity caused by failed strings. Also, depending on the previous operation and type of failure, the reallocation of duty cycle burden among available strings could be non-uniform. These complexities suggest that mitigation of the impact of partial failure in multistring ESSs is not trivial and needs careful consideration. This is the topic of this paper. The proposed work investigates the impact of partial failure of a large multistring ESS on the assigned service and develops strategies to adjust the ESS control duty cycles for reducing such impacts. In doing so, the paper proposes a novel two-stage framework that plans for the multistring failure using robust optimization theory and then adjusts in real-time using a rule-based algorithm, based on the real-time information on the power availability of the string. Illustrations provided in this work are based on frequency regulation use-case, which is a common application for many utility-scale ESSs. A 750 kilowatt (kW)/1500 kilowatt-hour (kWh) 3-string ESS is used for the demonstration in this work and the efficacy of the proposed method is demonstrated and compared against methods that do not incorporate string failure in their strategy. In particular, here we show that revenue loss of 93% can be incurred when partial string failure is not included in operation and planning. These losses in revenue are reduced by 60% with the proposed method.

25 ENERGY STORAGE↗

Space station common module network topology and hardware development

Conceptual space station common module power management and distribution (SSM/PMAD) network layouts and detailed network evaluations were developed. Individual pieces of hardware to be developed for the SSM/PMAD test bed were identified. A technology assessment was developed to identify pieces of equipment requiring development effort. Equipment lists were developed from the previously selected network schematics. Additionally, functional requirements for the network equipment as well as other requirements which affected the suitability of specific items for use on the Space Station Program were identified. Assembly requirements were derived based on the SSM/PMAD developed requirements and on the selected SSM/PMAD network concepts. Basic requirements and simplified design block diagrams are included. DC remote power controllers were successfully integrated into the DC Marshall Space Flight Center breadboard. Two DC remote power controller (RPC) boards experienced mechanical failure of UES 706 stud-mounted diodes during mechanical installation of the boards into the system. These broken diodes caused input to output shorting of the RPC's. The UES 706 diodes were replaced on these RPC's which eliminated the problem. The DC RPC's as existing in the present breadboard configuration do not provide ground fault protection because the RPC was designed to only switch the hot side current. If ground fault protection were to be implemented, it would be necessary to design the system so the RPC switched both the hot and the return sides of power.

Anderson, P.↗

Dispenser Reliability: Materials R&D. A Hydrogen Fueling Infrastructure Research and Station Technology (H2FIRST) Report

Dispensers are the top cause of maintenance events and down-time at hydrogen fueling stations. In an effort to help characterize and enable improvements in dispenser reliability, an extensive accelerated lifetime testing set-up was designed and built at NREL involving components typically part of dispensing operations at fueling stations. Device Under Test (DUTs) included different components such as normally open valves, normally closed valves, fueling nozzles, breakaways devices and filters. Conditions of testing included pressures, and flow rates similar to light duty fuel cell electric vehicles fueling at -40°C, and -20°C for thousands of cycles in hydrogen. Tested components (failed and non-failed) were disassembled at SNL and polymeric O-rings were carefully retrieved and cataloged for chemical and physical characterization. Data collected was compared to similar O-rings from unexposed or non-tested components for hydrogen effects, and failure modes. Degradation analyses, based on select polymer chemistries common across all component types, their location within components, visual assessment of damage coupled with strong hydrogen effects from chemical characterization, was completed and presented to NREL and DOE. Overall, the failure rate amongst the components was not as high as expected for the test conditions. Among the component types tested, breakaways were the most susceptible to damage under these test conditions, with fueling nozzles a close second. The proper combination of selection of the right polymer and optimum component design was found to make a strong difference in component reliability under severe dispenser operating conditions. Physical degradation of polymers, rather than chemical changes due to low temperature hydrogen exposure, is more prevalent as failure mode for these test conditions. The nature and the extent of the degradation was much less at -20°C as compared to -40°C. The damage and failure rates were higher at lower temperatures than at higher test temperatures. As expected, increasing the number of cycles at the lowest test temperature (-40°C) increased damage. This indicates that cycling at the low temperature of -40°C required by SAE J2601 can reduce component life in fuel dispensing operations

08 HYDROGEN↗

A Risk Analysis Tool for Estimating the Risk of Electrical Failures Due to Human Induced Defects

Aerospace electrical systems are required to withstand and adequately operate in extremely harsh environments that include, for example, high radiation exposure, temperature extremes, intense vibrational stress and drastic temperature cycling. The nature of aerospace electronics also demands high reliability since, with very few exceptions, there is no chance for hardware servicing or repairs. Common risk mitigation techniques for this type of situation are to perform a Reliability Analysis of the system throughout the development cycle, and to use electrical components that are regarded as “high reliability” because of additional controls and requirements applied in their design, manufacturing and testing. Unfortunately, studies have shown that even though these techniques are used, many systems fail to meet mission requirements well before the predicted lifetimes. This paper presents the analysis of failures of electrical parts, experienced during various stages of system development, at NASA Goddard Space Flight Center, Greenbelt MD, between the years 2001 and 2013. These components were subjected to qualification, screening and testing in which the goal was to ensure that the components would survive the stresses of the mission. The analysis categorizes failures by part type and failure mechanisms. One of the results of the analysis was the realization that a surprising proportion of failures experienced during system integration and testing were caused by human error (i.e. human induced defect). Further analysis included the determination of root failure mechanisms and any influencing factors contributing to these failures. The major causes of these defects were attributed to electrostatic damage (ESD), electrical overstress (EOS), mechanical overstress (MOS), and thermal overstress (TOS). Finally, the study proposes a risk analysis tool which incorporates these major causes for the failures, termed error-producing conditions (EPCs), and a proportionality factor representing the number of each type of failure that has occurred at the facility under study. These factors are quantified and used to communicate the risk of human induced defects for the assembly, integration and testing of space hardware based on the system’s electrical parts list. The new risk identification can trigger risk-mitigating actions more effectively, based on the presence of component categories or other hazardous conditions that have a history of failure due to human error.

Majewicz, Peter J.↗

X-31 Mishap: Lessons Learned

The experimental X-31 High Angle of Attack Research Aircraft crashed during a 1995 test mission flight conducted by NASA at Edwards Air Force Base, California. The pilot lost control of the airplane and was forced to eject, sustaining a permanent back injury that ended his flying career. Prior to this incident the airplane had a perfect record of several hundred non-eventful flights supported by an experienced team. During the subsequent investigation by a mishap committee it was discovered that a series of cascading events contributed to this accident. Some of the identified contributing factors that resulted in this mishap are common to aircraft design and to flight-test in general. The mistakes and the solutions are presented here so that the flight-test community may consider and learn from them. The primary cause of the crash was icing and, ultimately, a complete blockage of the pitot-static nose probe. The icing was caused by a freak weather phenomenon that was neither expected nor known to exist on the day of the mishap. The normal probe had been replaced with a special Kiel probe to allow total pressure measurements of up to 70 degrees angle of attack for flight-test purposes. The Kiel probe did not include a heater, because it was assumed that the airplane would not be flown in the clouds or in conditions conducive to icing. This assumption was later proven to be incorrect. The iced Kiel probe caused incorrect gain scheduling in the flight control system, resulting in an unstable aircraft. This failure was essentially undetected because of a faulty design in the flight control system architecture. There were, however, also a number of other issues that lead up to this situation that never should have happened. This presentation discusses what the issues were that contributed to the incident. After the incident was investigated, some of these issues were addressed and some changes were made. The second X-31 aircraft flew the remainder of the flight tests, and the program was successfully completed without incident. This presentation also shows a video of the mishap including lessons learned, and the changes that were made to resume the flight-test program are presented.

Larson, Richard R.↗

Natural Language Processing Techniques for Intelligent Knowledge Management of Safety Reports

Safety, failure, and incident reports are common artifacts across various domains, including aviation and wildfire response. These reports are often mandatory to submit, resulting in the culmination of large repositories of text-based documents. Simultaneously, these reports and corresponding repositories are often only manually analyzed and queried by users via out-of-date search engines. As a consequence, we have been developing the Manager for Intelligent Knowledge Access (MIKA) toolkit, which uses natural language processing to improve information access and reuse. In this presentation, we discuss natural language processing techniques for knowledge discovery and apply these methods to a repository of aerial wildfire mishap reports. Two methods are used for knowledge discovery: topic modeling and named-entity recognition. We use topic modeling to identify hazards and perform a trend analysis to produce a data-driven risk matrix. A custom named-entity recognition model, build from fine tuning a pre-trained language model, is used to identify failure modes, failure causes, failure effects, control processes, and recommendations to aid in failure modes and effects analysis (FMEA). Throughout the presentation, we discuss and apply natural language processing techniques to better leverage the vast amount of information contained in report repositories.

Machine learning↗

Application of Fault Management Theory to the Quantitative Selection of a Launch Vehicle Abort Trigger Suite

The theory of System Health Management (SHM) and of its operational subset Fault Management (FM) states that FM is implemented as a "meta" control loop, known as an FM Control Loop (FMCL). The FMCL detects that all or part of a system is now failed, or in the future will fail (that is, cannot be controlled within acceptable limits to achieve its objectives), and takes a control action (a response) to return the system to a controllable state. In terms of control theory, the effectiveness of each FMCL is estimated based on its ability to correctly estimate the system state, and on the speed of its response to the current or impending failure effects. This paper describes how this theory has been successfully applied on the National Aeronautics and Space Administration's (NASA) Space Launch System (SLS) Program to quantitatively estimate the effectiveness of proposed abort triggers so as to select the most effective suite to protect the astronauts from catastrophic failure of the SLS. The premise behind this process is to be able to quantitatively provide the value versus risk trade‐off for any given abort trigger, allowing decision makers to make more informed decisions. All current and planned crewed launch vehicles have some form of vehicle health management system integrated with an emergency launch abort system to ensure crew safety. While the design can vary, the underlying principle is the same: detect imminent catastrophic vehicle failure, initiate launch abort, and extract the crew to safety. Abort triggers are the detection mechanisms that identify that a catastrophic launch vehicle failure is occurring or is imminent and cause the initiation of a notification to the crew vehicle that the escape system must be activated. While ensuring that the abort triggers provide this function, designers must also ensure that the abort triggers do not signal that a catastrophic failure is imminent when in fact the launch vehicle can successfully achieve orbit. That is, the abort triggers must have low false negative rates to be sure that real crew‐threatening failures are detected, and also low false positive rates to ensure that the crew does not abort from non‐crew‐threatening launch vehicle behaviors. The analysis process described in this paper is a compilation of over six years of lessons learned and refinements from experiences developing abort triggers for NASA's Constellation Program (Ares I Project) and the SLS Program, as well as the simultaneous development of SHM/FM theory. The paper will describe the abort analysis concepts and process, developed in conjunction with SLS Safety and Mission Assurance (S&MA) to define a common set of mission phase, failure scenario, and Loss of Mission Environment (LOME) combinations upon which the SLS Loss of Mission (LOM) Probabilistic Risk Assessment (PRA) models are built. This abort analysis also requires strong coordination with the Multi‐Purpose Crew Vehicle (MPCV) and SLS Structures and Environments (STE) to formulate a series of abortability tables that encapsulate explosion dynamics over the ascent mission phase. The design and assessment of abort conditions and triggers to estimate their Loss of Crew (LOC) Benefits also requires in‐depth integration with other groups, including Avionics, Guidance, Navigation and Control(GN&C), the Crew Office, Mission Operations, and Ground Systems. The outputs of this analysis are a critical input to SLS S&MA's LOC PRA models. The process described here may well be the first full quantitative application of SHM/FM theory to the selection of a sensor suite for any aerospace system.

Lo, Yunnhon↗

Evaluating Process Effectiveness to Reduce Risk

It is well documented that government agencies do not have the same incentive as the private sector to focus on process effectiveness and continual improvement of those processes. It is also well documented whenever government agencies fail to deliver efficient, effective, consistent, and fair services to the citizens. In spite of the various "reinventing government" and "effectiveness initiatives" of the past decades, and in spite of the efforts on the part of many agencies to improve, government in general still lags behind industry in creating a culture of effective processes and systems. While the tragic events that unfolded recently in Flint, Michigan, teach us that running government "like a business" does not always take the needs of the citizenry into account, there are many lessons and techniques from the private sector that government agencies can use to improve. The incentive to improve, while mandated by various administrations1, needs to come from within the workforce, in order to effectively take root. The best, most effective incentive is to reduce, control or eliminate risk. Government agencies face some of the same risks as the private sector, while some are unique. While ISO 310002 has been around since 2009, risk has taken on increased visibility within the private sector with the advent of the emphasis on risk-based thinking in ISO 9001:20153. The relationship between risk-based thinking and effective processes is simple and direct. Those processes that are well thought out and standardized (i.e. Plan-Do-Check-Act), will have taken into account the applicable policy, statutory, regulatory, safety, quality and technical parameters, which may not occur to someone performing the process with minimal experience or training; and thus protect the employees, the public and the agency from statutory and regulatory violations; delay in providing services; non-delivery of services; harm to public or employee safety and health; cost overruns; breaches in security; loss of confidence in government; failure of publicly funded projects; damage to the environment; ethics violations, and the list goes on; with local, national and even international consequences. The Plan-Do-Check-Act process, also known as the "process approach" can be used at any time to establish and standardize a process, and it can also be used to check periodically for "process creep" (i.e., informal, unauthorized changes that have occurred over time), any necessary updates and improvements. While ISO 9001 compliance is not mandated for all government agencies, if interpreted correctly, it can be useful in establishing a framework and implementing effective management systems and processes.4 Another method that can be used to evaluate effectiveness is the scorecard definitions in Mallory's Process Management Standard5 as a basis for evaluating work on the process level on effective, and continuously improved and improving processes. With processes on the lower end of the scale, agencies are vulnerable to a great many risks, with employees and managers making up many of the rules as they go, leading to the above listed negative results. Without clear guidance for nominal operations, off-nominal situations can, and do, increase the likelihood of chaos. In an increasingly technical environment, with inter-agency communication and collaboration becoming the norm, agencies need to come to grips with the fact that processes can become rapidly outdated, and that the technical community should take on an increased role in the maturation of the agency's processes. Industry has long known that effective processes are also efficient, and process improvement methods such as Kaizen, Lean, Six Sigma, 5S, and mistake proofing lead to increased productivity, improved quality, and decreased cost. Again, government agencies have different concerns, but inefficiencies and mistakes can have dire and wide reaching consequences for the public that they serve. While no one goes to work planning to cause harm, it is up to agencies to establish upper level systems, which make establishment and compliance with processes possible. Again, Mallory provides us with a Systems Management Standard6, similar to the Process Management Standard, with a scale of 0-5 for systems effectiveness and maturity. Deming determined that "eighty-five percent of the reasons for failure are deficiencies in the systems and process rather than the employee. The role of management is to change the process rather than badgering individual employees to do better." 7 It is not just the working level employees who need effective processes, but the mid-and upper level managers as well. A disciplined management culture sets the tone for the employees, aids both routine and off-nominal decision-making, and incorporates risk -based thinking into the systems and processes as a matter of normal activity. Figure 1, illustrates the relationship between ineffective and effective processes and risk, through the use of the "stoplight" colors that are commonly used to show serious situations (red), situations which may be improving or deteriorating depending on trends (yellow), and situations that are under control and continuously improved (green).

Shepherd, Christena C.↗

[High Pressure Gas Tanks]

Four high-pressure gas tanks, the basis of this study, were especially made by a private contractor and tested before being delivered to NASA Kennedy Space Center. In order to insure 100% reliability of each individual tank the staff at KSC decided to again submit the four tanks under more rigorous tests. These tests were conducted during a period from April 10 through May 8 at KSC. This application further validates the predictive safety model for accident prevention and system failure in the testing of four high-pressure gas tanks at Kennedy Space Center, called Continuous Hazard Tracking and Failure Prediction Methodology (CHTFPM). It is apparent from the variety of barriers available for a hazard control that some barriers will be more successful than others in providing protection. In order to complete the Barrier Analysis of the system, a Task Analysis and a Biomechanical Study were performed to establish the relationship between the degree of biomechanical non-conformities and the anomalies found within the system on particular joints of the body. This relationship was possible to obtain by conducting a Regression Analysis to the previously generated data. From the information derived the body segment with the lowest percentage of non-conformities was the neck flexion with 46.7%. Intense analysis of the system was conducted including Preliminary Hazard Analysis (PHA), Failure Mode and Effect Analysis (FMEA), and Barrier Analysis. These analyses resulted in the identification of occurrences of conditions, which may be becoming hazardous in the given system. These conditions, known as dendritics, may become hazards and could result in an accident, system malfunction, or unacceptable risk conditions. A total of 56 possible dendritics were identified. Work sampling was performed to observe the occurrence each dendritic. The out of control points generated from a Weighted c control chart along with a Pareto analysis indicate that the dendritics "Personnel not Wearing Proper Protective and Hose/tubing located in high-traffic area" which account for 59.18% of total dendritic frequency need to be addressed to reduce the chance of a hazard from occurring. However, the occurrences of some dendritics are more important than others. As a result immediate, from a Weighted c perspective, corrective action should be taken to ameliorate the cause of the Class A dendritic "Personnel located under suspended or moving loads" rather than just the most commonly occurring dendritics. In any case the vast majority of data obtained indicates that testing operations possess a relatively high degree of safety.

Quintana, Rolando↗

Flammable Gas Generation and Control at the Idaho Completion Project Legacy Combustible Gas Generation - 20191

On April 11, 2018, four drums containing transuranic waste at the Idaho National Laboratory underwent over-pressurization, ejecting their lids and spreading radiological waste within a facility. An investigation has found that waste in the drums generated methane gas, which contributed to the event. Subsequent to the investigation, the potential for drums to have methane and other flammable analytes whose concentrations could approach or exceed the lower flammability limit (LFL) and the adequacy of the controls to prevent or mitigate a possible deflagration was evaluated. An extensive review of the historical records was performed to determine how many drums exceed the LFL. The historical record identified a small quantity of drums that exceeded the LFL for xylene, hydrogen, and methane. The primary codified applicable code or standard for handling drums is 29 CFR 1910.120 (j) 'Handling Drums and Containers.' It is used throughout the commercial and government sector. This code is integrated throughout the Fluor Idaho safety management programs and procedures to control the Standard Industrial Hazards (SIHs) associated with drum and container handling. Example requirements include: - Drums and containers are inspected, and their integrity assured prior to being moved. - Site operations are organized to minimize the amount of drum or container movement. - When there is a reasonable possibility of flammable atmospheres being present, material handling equipment and hand tools are of the type to prevent sources of ignition. Drums and containers under pressure, as evidenced by bulging or swelling, are not moved until the cause for excess pressure is determined and appropriate containment procedures have been implemented to protect employees from explosive relief of the drum. Drums which exceed the WIPP FGA limit have NCRs associated with them. Once a drum fails flammable gas sampling, an NCR is initiated. The NCR drives placement into NCR dense pack rows. A standing order drives placement of the FGA failures to a single planer segregation location. These drums are not allowed for further processing or shipment until the NCR has been cleared. Once in the single planer rows, follow-up FGA testing is performed by CCP. The NCR is dispositioned by follow-up sampling occurring after adequate time has been provided for the gas to diffuse through the filter assembly, or, in some cases, the drums are repackaged into additional drums to reduce the source term. To date, the ICP project has performed approximately 1.5 million drums moves without a deflagration event due to combustible gas generation. Flammable gas generation in a transuranic waste drum is not unique to the ICP but is common across the DOE complex. Based on the experience at Idaho, application of industry standards is sufficient to control the risk of drum deflagration due to drum movements. (authors)

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Nature-Inspired Motivation for Developing Self-Healable Electrical Insulation

Polymeric aircraft electrical insulation normally degrade by partial discharge with increasing voltage, which causes excessive localized Joule heating in the material and ultimately leads to dielectric failure of the insulator through thermal breakdown. Self-healing insulation may be a viable option to mitigate permanent mechanical degradation, thus increasing the longevity of the material. Instead of relying on catalyst and monomer-filled microcapsules to crack, flow, and cure at the damaged sites described in well-published mechanisms, self-healing through establishment of ionic crosslinks allows for multiple healing events to occur as well as achieving full recovery strength under certain thermal environments. Surlyn®, a commercial ionically-crosslinked material, was investigated as a self-healing insulation candidate based on prior demonstrations of self-healing behavior. Thin films of varying thicknesses were investigated and the effects of thickness on the dielectric strength were evaluated and compared to representative polymer insulators. The effects of thermal conditioning on the recovery strength and healing were observed as a function of time following dielectric breakdown. Moisture absorption was studied to determine if moisture absorption rates in Surlyn® were lower than that of common polyimide insulators. Preliminary data showed that when cut, Surlyn® films lost nearly 60 percent of its original dielectric strength. However, when Surlyn® was cut and subsequently annealed, the films not only re-mended, but also recouped approximately 93 percent of its original dielectric strength, along with 90-97 percent of its mechanical strength.

electrical↗

Radiometric and Radiation Response of Visible FPAs

The readout integrated circuit (ROIC) used in these devices was originally developed for use in space based infrared systems operating at deep cryogenic temperatures and was selected because of its proven tolerance to total ionizing radiation? The detectors are a 128 x 128 array of 60 pm x 60 pm pixel elements that have been anti-reflection (AR) coated to improve the response at very short wavelengths. These visible focal plane arrays were operated at -40 C (233 K). Two focal planes were characterized using cobalt-60 radiation to produce ionizing total dose damage in the VFPAs. Both operational and performance data were obtained as functions of total dose. The first device tested showed no appreciable change in responsivity or noise up to 300 krad(Si). However, at the next dose level of 600 krad(Si), the readout was non-operational due to failure in the digital circuitry. The second device was characterized to a total dose of 750 krad(Si) with no observed change in responsivity. An increase dark current was observed in both devices, and in the second device, the dark current caused an increase in noise at low irradiance at 400 krad(Si) and above. The increase in dark current was somewhat un-expected for visible PIN detectors. The median dark current increased more than two orders of magnitude at 300 krad(Si) for the first device and a factor of 350 at 750 krad(Si) for pixels near the edge for the second device. The dark current was found to be a strong function of detector bias, with pixels near the edge of the array showing a greater increase in dark current with bias than those near the center. Since the optical response was not a function of bias, it is hypothesized that the dark current is a surface effect and that the variation in dark current with location is due to a variation in pixel bias, caused by a voltage drop across the pixel common lead. As the total dose increased, the dark current and the voltage drop increased

Hubbs, John↗

Photo-oxidation of semicrystalline polymers: Effect of stress triaxiality on ductility

The effect of stress triaxiality on the strain-to-fracture of as-received and photo-oxidized polyamide-6 (PA-6) was investigated using mechanical testing, synchrotron X-ray tomography, and finite element analyses. Mechanical tests were conducted on cylindrical and round notched specimens, where different notch radii were used to vary the stress triaxiality. The specimens were aged by exposure to ultra-violet (UV) radiation at 60∘, causing photo-oxidation. As-received and so-aged specimens were loaded to failure (complete loss of load carrying capacity). For both unaged and aged specimens, a higher triaxiality led to a lower strain-to-fracture. To elucidate the micromechanical damage that mediates fracture in both conditions, specimens with an intermediate notch sharpness were loaded to the peak load, unloaded, and scanned ex situ using synchrotron X-ray tomography. Damage in the unaged bar was found to occur by cavitation and was concentrated at the center of the specimen, where the triaxiality is highest. In the UV-aged bar, a network of inter-connected chemical cracks were found on the notch surface, where the triaxiality is lowest. Finite element analyses were deployed to approximate the local triaxiality at damaged regions in the unaged and UV-aged specimens using a constitutive relation for semicrystalline polymers. From these analyses, the relationship between local triaxiality and strain-to-fracture was quantified for both unaged and photo-oxidized PA-6. Both unaged and photo-oxidized PA-6 showed similar decreases in ductility with triaxiality, hinting at common ductile fracture processes.

36 MATERIALS SCIENCE↗

High-Performance Acousto-Ultrasonic Scan System Being Developed

Acousto-ultrasonic (AU) interrogation is a single-sided nondestructive evaluation (NDE) technique employing separated sending and receiving transducers. It is used for assessing the microstructural condition and distributed damage state of the material between the transducers. AU is complementary to more traditional NDE methods, such as ultrasonic cscan, x-ray radiography, and thermographic inspection, which tend to be used primarily for discrete flaw detection. Throughout its history, AU has been used to inspect polymer matrix composites, metal matrix composites, ceramic matrix composites, and even monolithic metallic materials. The development of a high-performance automated AU scan system for characterizing within-sample microstructural and property homogeneity is currently in a prototype stage at NASA. This year, essential AU technology was reviewed. In addition, the basic hardware and software configuration for the scanner was developed, and preliminary results with the system were described. Mechanical and environmental loads applied to composite materials can cause distributed damage (as well as discrete defects) that plays a significant role in the degradation of physical properties. Such damage includes fiber/matrix debonding (interface failure), matrix microcracking, and fiber fracture and buckling. Investigations at the NASA Glenn Research Center have shown that traditional NDE scan inspection methods such as ultrasonic c-scan, x-ray imaging, and thermographic imaging tend to be more suited to discrete defect detection rather than the characterization of accumulated distributed microdamage in composites. Since AU is focused on assessing the distributed microdamage state of the material in between the sending and receiving transducers, it has proven to be quite suitable for assessing the relative composite material state. One major success story at Glenn with AU measurements has been the correlation between the ultrasonic decay rate obtained during AU inspection and the mechanical modulus (stiffness) seen during fatigue experiments with silicon carbide/silicon carbide (SiC/SiC) ceramic matrix composite samples. As shown in the figure, ultrasonic decay increased as the modulus decreased for the ceramic matrix composite tensile fatigue samples. The likely microstructural reason for the decrease in modulus (and increase in ultrasonic decay) is the matrix microcracking that commonly occurs during fatigue testing of these materials. Ultrasonic decay has shown the capability to track the pattern of transverse cracking and fiber breakage in these composites.

Roth, Don J.↗

High-Performance Acousto-Ultrasonic Scan System Being Developed

Acousto-ultrasonic (AU) interrogation is a single-sided nondestructive evaluation (NDE) technique employing separated sending and receiving transducers. It is used for assessing the microstructural condition and distributed damage state of the material between the transducers. AU is complementary to more traditional NDE methods, such as ultrasonic cscan, x-ray radiography, and thermographic inspection, which tend to be used primarily for discrete flaw detection. Throughout its history, AU has been used to inspect polymer matrix composites, metal matrix composites, ceramic matrix composites, and even monolithic metallic materials. The development of a high-performance automated AU scan system for characterizing within-sample microstructural and property homogeneity is currently in a prototype stage at NASA. This year, essential AU technology was reviewed. In addition, the basic hardware and software configuration for the scanner was developed, and preliminary results with the system were described. Mechanical and environmental loads applied to composite materials can cause distributed damage (as well as discrete defects) that plays a significant role in the degradation of physical properties. Such damage includes fiber/matrix debonding (interface failure), matrix microcracking, and fiber fracture and buckling. Investigations at the NASA Glenn Research Center have shown that traditional NDE scan inspection methods such as ultrasonic c-scan, x-ray imaging, and thermographic imaging tend to be more suited to discrete defect detection rather than the characterization of accumulated distributed micro-damage in composites. Since AU is focused on assessing the distributed micro-damage state of the material in between the sending and receiving transducers, it has proven to be quite suitable for assessing the relative composite material state. One major success story at Glenn with AU measurements has been the correlation between the ultrasonic decay rate obtained during AU inspection and the mechanical modulus (stiffness) seen during fatigue experiments with silicon carbide/silicon carbide (SiC/SiC) ceramic matrix composite samples. As shown in the figure, ultrasonic decay increased as the modulus decreased for the ceramic matrix composite tensile fatigue samples. The likely microstructural reason for the decrease in modulus (and increase in ultrasonic decay) is the matrix microcracking that commonly occurs during fatigue testing of these materials. Ultrasonic decay has shown the capability to track the pattern of transverse cracking and fiber breakage in these composites.

Roth, Don J.↗

Historical Aerospace Software Errors Categorized to Influence Fault Tolerance

Since the first use of computers in space and aircraft, software errors have occurred. These errors can manifest as loss-of-life or less catastrophically. As the demand for automation increases, software in mission or safety-critical systems should be designed to be tolerant to the most likely software faults. This paper categorizes a set of 55 historic aerospace software error incidents from 1962 to 2023 to determine trends of how and where automation is most likely to fail, behaving unexpectedly. A distinction between software producing unexpected (erroneous) output versus no output (failsilent) is introduced. Of the historical incidents analyzed, 85% were from software producing wrong output rather than simply stopping. Rebooting was found to be ineffective to clear erroneous behavior, and not reliable to recover from silent failures. Error origin was within the code/logic itself in 58% of cases, 16% from configurable data, 15% from unexpected sensor input, and 11% from command/operator input. A substantial forty percent (40%) of unexpected software behavior was indicated by the absence of code, arising from unanticipated situations and missing requirements, and 16% of incidents were subjectively deemed “unknown-unknowns”. No incidents were found to be the result of programming language, compiler, tool, or operating system; and only sixteen percent (16%) of all incidents were considered errors traditional computer science/programming in nature. These findings indicate that for fault tolerance, erroneous automation behavior must be a primary consideration especially at critical moments, and reboot recoverability may not be viable. Special care should be taken to validate configurable data and commands prior to use. “Test-like-you-fly”, including hardware-in-the-loop combined with robust off-nominal testing should be used to uncover missing logic arising from unanticipated situations not covered by requirements alone. This study uniquely focuses on manifestations of unexpected flight software behavior, independent of ultimate root cause. We characterize software error behavior and origin to improve software design, test, and operations for resilience to the most common manifestations, and provide a rich dataset for further study.

Aerospace↗