Engineering PapersSearch

SEARCH · Engineering Papers

Results for “fault protection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Methodology for Designing Fault-Protection Software

A document describes a methodology for designing fault-protection (FP) software for autonomous spacecraft. The methodology embodies and extends established engineering practices in the technical discipline of Fault Detection, Diagnosis, Mitigation, and Recovery; and has been successfully implemented in the Deep Impact Spacecraft, a NASA Discovery mission. Based on established concepts of Fault Monitors and Responses, this FP methodology extends the notion of Opinion, Symptom, Alarm (aka Fault), and Response with numerous new notions, sub-notions, software constructs, and logic and timing gates. For example, Monitor generates a RawOpinion, which graduates into Opinion, categorized into no-opinion, acceptable, or unacceptable opinion. RaiseSymptom, ForceSymptom, and ClearSymptom govern the establishment and then mapping to an Alarm (aka Fault). Local Response is distinguished from FP System Response. A 1-to-n and n-to- 1 mapping is established among Monitors, Symptoms, and Responses. Responses are categorized by device versus by function. Responses operate in tiers, where the early tiers attempt to resolve the Fault in a localized step-by-step fashion, relegating more system-level response to later tier(s). Recovery actions are gated by epoch recovery timing, enabling strategy, urgency, MaxRetry gate, hardware availability, hazardous versus ordinary fault, and many other priority gates. This methodology is systematic, logical, and uses multiple linked tables, parameter files, and recovery command sequences. The credibility of the FP design is proven via a fault-tree analysis "top-down" approach, and a functional fault-mode-effects-and-analysis via "bottoms-up" approach. Via this process, the mitigation and recovery strategy(s) per Fault Containment Region scope (width versus depth) the FP architecture.

Barltrop, Kevin

Space Station automated systems testing/verification and the Galileo Orbiter fault protection design/verification

Aspects of Space Station automated systems testing and verification are discussed, taking into account several program requirements. It is found that these requirements lead to a number of issues of uncertainties which require study and resolution during the Space Station definition phase. Most, if not all, of the considered uncertainties have implications for the overall testing and verification strategy adopted by the Space Station Program. A description is given of the Galileo Orbiter fault protection design/verification approach. Attention is given to a mission description, an Orbiter description, the design approach and process, the fault protection design verification approach/process, and problems of 'stress' testing.

Landano, M. R.

DC wiring system grounding and ground fault protection issues for central station photovoltaic power plants

The DC wiring system for a photovoltaic power plant presents a number of unique challenges to be overcome by the plant designers. There are a number of different configurations that the grounding of the DC wiring system can take, and the choice will affect the number and type of protective devices required to ensure safety of personnel and protection of equipment. The major grounding and fault protection considerations that must be taken into account when selecting the basic overall circuit configuration are summarized. The inherent advantages and disadvantages of each type of circuit grounding (resistance or solid) along with the personnel safety and equipment protection issues for each of these grounding methods are presented.

Simburger, E. J.

Fault Protection Design for the Command and Data Subsystem on the Cassini Spacecraft

The Command and Data Subsystem (CDS) on Cassini is responsible for uplink command processing, spacecraft intercommunications and control, and downlink telemetry formatting. The 10.7 year mission life, 160 minute round-trip light time, and extended periods of operation without continuous ground communications drive the CDS design in directions of redundancy, autonomy, and fault protection to accomodate the mission objectives.

Cassini

Cassini Attitude Control Fault Protection Design: Launch to End of Prime Mission Performance

The Cassini Attitude and Articulation Control Subsystem (AACS) Fault Protection (FP) has been successfully supporting operations for over 10 years from launch through the end of the prime mission. Cassini's AACS FP is complex, containing hundreds of error monitors and thousands of tunable parameters. Since launch there have been environmental, hardware, personnel and mission event driven changes which have required AACS FP to adapt and be robust to a variety of scenarios. This paper will discuss the process of monitoring, maintaining and updating the AACS FP during Cassini's lengthy prime mission as well as provide some insight into lessons learned during tour operations.

Meakin, Peter C.

Grounding and fault protection of the SMUD PVI array

If large terrestrial photovoltaic (PV) power plants are to provide an economic source of generation, low-cost, reliable and easily maintainable systems must be developed. In addition, if the system is to be a central station powerplant owned and operated by an electric utility, the design must also be consistent with utility specifications and design standards. The particular solutions developed to address these issues, with regard to grounding and fault protection, for the first phase of the Sacramento Municipal Utility District's (SMUD) 100 mw(ac) PV powerplant are presented. This plant, known as PV1, is nominally rated at 1 mw(ac) and is scheduled to be in operation by the spring of 1984.

Rosen, D.

Cassini Attitude and Articulation Control Subsystem Fault Protection Challenges During Saturn Proximal Orbits

NASA's Cassini Spacecraft, launched on October 15th, 1997 arrived at Saturn on June 30th, 2004, is the largest and most ambitious interplanetary spacecraft in history. As the first spacecraft to achieve orbit at Saturn, Cassini has collected science data throughout its four-year prime mission (2004-08), and has since been approved for a first and second extended mission through 2017. As part of the final extended mission, Cassini will begin an aggressive and exciting campaign of high inclination low altitude flybys within the inner most rings of Saturn, skimming Saturn's outer atmosphere, until the spacecraft is finally disposed of via planned impact with the planet. This final campaign, known as the proximal orbits, presents unique fault protection related challenges, the details of which are discussed in this paper.

Bates, David M.

Fault Protection Design and Testing for the Cassini Spacecraft in a "Mixed" Thruster Configuration

NASA's Cassini Spacecraft, launched on October 15th, 1997 and arrived at Saturn on June 30th, 2004, is the largest and most ambitious interplanetary spacecraft in history. In order to meet the challenging attitude control and navigation requirements of the orbit profile at Saturn, Cassini is equipped with a monopropellant thruster based Reaction Control System (RCS), a bipropellant Main Engine Assembly (MEA) and a Reaction Wheel Assembly (RWA). In 2008, after 11 years of reliable service, several RCS thrusters began to show signs of end of life degradation, which led the operations team to successfully perform the swap from the A-branch to the B-branch RCS system. If similar degradation begins to occur on any of the B-branch thrusters, Cassini might have to assume a "mixed" thruster configuration, where a subset of both A and B branch thrusters will be designated as prime. The Cassini Fault Protection FSW was recently updated to handle this scenario. The design, implementation, and testing of this update is described in this paper.

propellant

Hard Fault Protection for a Silicon Carbide-Based Aerospace Motor Drive

Due to increasingly high DC link voltages and further advancements in the current density of silicon carbide (SiC) MOSFETs, it has become evident that conventional IGBT protection methods are not sufficient to protect these devices from overcurrent during low-inductance fault events. The use of an air core Rogowski coil topology was explored to see if it could mitigate these hard fault events. The design of this circuit resulted in safe shutdown of a low impedance phase-tophase fault, tested up to DC link voltages of 1 kV.

High Voltage

Design and Testing of a Hard-Fault Protection Circuit for a 1 kV SiC MOSFET Inverter

Due to increasingly high DC link voltages and further advancements in the current density of silicon carbide (SiC) MOSFETs, it has become evident that conventional IGBT protection methods are not sufficient to prevent exceeding the current rating of these devices during low-inductance fault events. This paper explores the use of an air core Rogowski coil topology to mitigate these hard fault events. The design of this circuit resulted in safe shutdown of a low impedance phase-to-phase fault in under one microsecond, tested up to DC link voltages of 1 kV. This paper details the theory, design, simulation, and successful test results of this method.

hard fault protection

Automatic Fault Protection in the Voyager Spacecraft

Due to reliability requirements placed on the Voyager spacecraft system design and a mission resulting in long two-way, light time communication links, on-board automatic fault detection and correction capabilities are a significant feature of that spacecraft's design. Most of the protection to otherwise mission-catastrophic failures is implemented in the software of the voyager's central computer, while some resides in an attitude control-dedicated processor. This paper will present the role that automatic fault protection plans in achieving Voyager's overall reliability, its design evolution, and how its design was validated during system testing. In-flight experience will also be described, and from the lessons learned there-in, conclusions and recommendations will be drawn for the benefit of future designs.

Jones, C. P.