Configuration design and efficient operation of redundant multi-jet systems.
Spacecraft control systems with computer command redundant jets for linear and angular pulses, relating configuration design to level-of- redundancy and task dimension
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Spacecraft control systems with computer command redundant jets for linear and angular pulses, relating configuration design to level-of- redundancy and task dimension
At present, the most common method of increasing reliability of a system against permanent random component failures is to triplicate the entire system and use voters. This method, though it enhances the reliability, does exact a heavy toll in weight and power consumption which increase by about 225%. In the future, computers will be required to perform complex tasks under adverse conditions on surfaces of planets for long periods of time (6 months or more), without any human intervention. At the same time there will be severe limitations on the weight and power consumption of these computers. For such systems it is obvious that simple triple-redundancy will not do. A more efficient and sophisticated design in redundancy has to evolve. This study has been directed toward that goal. It is understood that the initial design of such a system will be too complex and expensive to be used in a commercial computer; but for a space computer, reduction in weight (without reducing reliability) of every ounce means a great deal.
A triplex digital fly-by-wire flight control system was developed and then installed in a NASA F-8C aircraft to provide fail-operative, full authority control. Hardware and software redundancy management techniques were designed to detect and identify failures in the system. Control functions typical of those projected for future actively controlled vehicles were implemented. This paper describes the principal design features of the system, the implementation of computer, sensor, and actuator redundancy management, and the ground test results. An automated test program to verify sensor redundancy management software is also described.
Circuits for redundant space-borne systems - detection and location of failure
An approach to implementing a compact, highly reliable and precise Master Time and Frequency subsystem usable in a variety of applications is described. These applications include, among others, Satellite Ground Terminals, Range Timing Stations, Communications Terminals, and Power Station Timing subsystems. All time and frequency output signals are locked to Universal Time via the GPS Satellite system. The system provides for continued output of precise signals in the event of GPS signal interruption from antenna or lead-in breakage or other causes. Cost/performance tradeoffs affecting system accuracy over the short, medium, and long term are discussed. A unique approach to redundant system design provides an architecture with the reliability advantage of triple-redundant majority voting and the cost advantages of dual-redundant elements. The system can be configured to output a variety of precise time and frequency signals and the design can be tailored to output as few, or as many, types and quantities of signals as are required by the application.
The SUbsonic Single Aft eNgine (SUSAN) Electrofan is a NASA concept jet transport aircraft with a 2040 entry-into-service date. It utilizes electrified aircraft propulsion (EAP) to enable propulsive and aerodynamic benefits to reduce fuel usage, emissions, and cost. The powertrain consists of a single thrust producing, boundary layer-ingesting (BLI) turbofan gas turbine engine (GTE) with generators driving a series/parallel partial hybrid EAP system. The architecture includes 16 underwing contrarotating BLI fans, eight on each side, in a mailslot configuration. The 16 fans run on power extracted from the GTE through four 5 MW motor/generators connected to the Low-Pressure Spool, and a single 1 MW motor/generator on the High-Pressure Spool. The distributed fans can be used by the flight control to augment or replace the rudder function. At top of climb, the power extracted from the GTE for the fans is boosted by batteries. The design provides redundancy, and the capacity for boost means that the fans are designed to be able to provide additional thrust when necessary. These features can be leveraged in case of a fan or generator failure. This paper sets up the optimal control problem of setpoint determination for individual fans in the distributed propulsion system, accounting for electrical string efficiencies, saturations, and failures. The solution minimizes power consumption while maintaining thrust and torque on the airframe for maneuvering. Additionally, thrust that would have been lost due to temporary fan speed or power saturation is optimally redistributed to maintain overall desired thrust and torque on the aircraft. The power extraction range constraints derive from the gas turbine engine design and the small amount of variation allowed for the engine to maintain operability. The problem formulation allows the number and location of fan failures for which the thrust and torque can be maintained to be investigated, which has implications for certification. Simulations of a coordinated turn utilizing the distributed electric propulsion for yaw rate control under different failure scenarios demonstrate the robustness of the powertrain design to failures and help define its limitations.
Requirements for a redundant strapdown inertial sensor complex applied to V/STOL aircraft as developed by NASA are presented. Flight test data of a redundant, skewed axis strapdown inertial system are given, demonstrating the feasibility of the primary design aspects. This data consisted of parity equation responses through various flight conditions, showing residual noise levels on redundant gyro and accelerometer comparisons as a measure of minimum failure-level detectability, plus failure isolation and navigation performance through several simulated instrument failures.
C-Prolog can conveniently be used for logical inferences on knowledge bases. However, as similar to many search methods using backward chaining, a large number of redundant computation may be produced in recursive calls. To overcome this problem, the 'rid-redundant' procedure was designed to rid all redundant computations in running multi-recursive procedures. Experimental results obtained for C-Prolog on the Vax 11/780 computer show that there is an order of magnitude improvement in the running time and solvable problem size.
Airplane wing trusses are generally designed to contain redundant members (stagger wires and external drag wires) which, according to common practice, are not taken into account in calculations, so as to simplify the stress analysis by rendering the structure statically determinate. A more accurate method, in which the redundancies are included, involves a solution by means of Castigliano's method of least work. For the purpose of demonstrating the practical application of the method of least work this report presents examples for stresses of several cases of loading worked out for a structure similar to that of the Curtiss JN-4h. Case 1 was taken as the condition of velocity of 100 miles per hour combined with the angle of attack of maximum lift. Case 1a assumed the same loading but neglected the distortion of wooden members in the least-work analysis. So little error was involved in case 1a that this simplified method was employed for each succeeding case. Case 2 assumed a diving speed of 120 miles per hour and an angle of attack of no lift. Case 3 was worked out for the conditions imposed by the sand load recommended in NACA technical note no. 6.
Partial redundancy for improved reliability of computing machine
The development and initial evaluation of a strapdown inertial reference unit (SIRU) system are discussed. The SIRU configuration is a modular inertial subsystem with hardware and software features that achieve fault tolerant operational capabilities. The SIRU redundant hardware design is formulated about a six gyro and six accelerometer instrument module package. The six axes array provides redundant independent sensing and the symmetry enables the formulation of an optimal software redundant data processing structure with self-contained fault detection and isolation (FDI) capabilities. The basic SIRU software coding system used in the DDP-516 computer is documented.
Topics include NASA centers around the country; 2009 highlights of significant successes in space transportation, exploration, and science; significant accomplishments; places to explore include Lagrange points, near-Earth objects, Mars and the Moon, and International Space Station research; Marshall's missions include propulsion and transportation systems, life support systems, and earth and space science spacecraft, systems, and operations; project lifecycle management model; motivation of avionics fault-tolerance, redundancy needs and concerns, redundancy versus reliability; parallel-series configurations; effect of adding redundancy on mission success; example of rules-based approach where reliability and safety interaction impacts design; impact of common cause failure; approach ot bottom-up reliability analysis; three factors that lead to redundant system failure; Apollo 13 multi-functional reliability and example; and mitigating the risk of single string spacecraft architecture;.
A new way of employing hardware redundancy to reduce the number of tests for fault detection in both combinational and synchronous sequential circuits is investigated. An approach is presented for utilizing systematic redundancy to simplify design work. Models for PLM (programmable logic module) and CMM (controllable memory module) are depicted. Systematic design and detection procedures are described. Using these procedures, an easily testable circuit (for stuck faults) can be designed. In contrast to the earlier results on fault detection in logic circuit, two tests are needed to detect any stuck faults of combinational logic circuit. Four tests are necessary and sufficient to detect any stuck faults of elementary logic gates and the malfunction of flip-flops of synchronous sequential circuit using Delay flip-flops or trigger flip-flops.
The in Situ Spectroscopic Europa Explorer (iSEE) instrument is an ultra-compact laser-enabled Raman spectrometer instrument that meets the top-level science requirements for multiple future planetary in situ missions to explore the surface and atmospheric chemistry of planetary bodies across the Solar System. Enceladus, Europa, the Moon, Mars, and Venus are some of the primary targets for future NASA missions to search for extraterrestrial life and potentially habitable environments beyond Earth, further our understanding of the timing and formation of the Solar System and identify potentially viable economic resources such as water and/or valuable metal assets. We report on the advancement and space flight qualification of a compact, robust, solid-state laser operating at 515 nm that serves as the excitation source for the iSEE investigation. The iSEE instrument is being developed under a NASA Maturation of Instruments for Solar System Exploration (MatISSE) program. The iSEE laser is a diode pumped 1030 nm Yb:YAG microchip laser with a second harmonic generator to achieve an output wavelength of 515 nm and coupled to a multi-mode fiber for delivery to the Raman spectrometer probe. The fundamental 1030 nm laser operates at a pulse repetition frequency (PRF) of 1-10 kHz with pulse energy of 95 μJ and ~800 ps pulse width. A 15 mm long Type II KTP crystal is used for second harmonic generation from 1030 nm to 515 nm. The residual fundamental 1030 nm is separated from the 515 nm beam using a pair of dichroic filters. A focusing lens couples the 515 nm beam to the optical fiber to produce an output laser pulse energy of 20 μJ. A custom vacuum fiber feedthrough assembly was designed with two 105 μm core fibers, and two 200 μm core fibers. One fiber is needed for coupling the laser to the iSEE instrument, and the additionally fibers provide redundancy and design flexibility. The laser enclosure is pressurized with >1 atm of clean dry air. The laser has been designed to minimize the size, weight, and power (SWaP) for a lander instrument with minimal resources. The laser will go through environmental testing including vibration and thermal vacuum testing for space flight qualification. Here we discuss the design, trade studies, performance, and environmental qualificationtesting of the iSEE laser.
This paper contributes to the magnetic bearing literature in two distinct areas: high temperature and redundant actuation. Design considerations and test results are given for the first published combined 538 C (1000 F) high speed rotating test performance of a magnetic bearing. Secondly, a significant extension of the flux isolation based, redundant actuator control algorithm is proposed to eliminate the prior deficiency of changing position stiffness after failure. The benefit of the novel extension was not experimentally demonstrated due to a high active stiffness requirement. In addition, test results are given for actuator failure tests at 399 C (750 F), 12,500 rpm. Finally, simulation results are presented confirming the experimental data and validating the redundant control algorithm.
This report describes work developing fault tolerant redundant robotic architectures and adaptive control strategies for robotic manipulator systems which can dynamically accommodate drastic robot manipulator mechanism, sensor or control failures and maintain stable end-point trajectory control with minimum disturbance. Kinematic designs of redundant, modular, reconfigurable arms for fault tolerance were pursued at a fundamental level. The approach developed robotic testbeds to evaluate disturbance responses of fault tolerant concepts in robotic mechanisms and controllers. The development was implemented in various fault tolerant mechanism testbeds including duality in the joint servo motor modules, parallel and serial structural architectures, and dual arms. All have real-time adaptive controller technologies to react to mechanism or controller disturbances (failures) to perform real-time reconfiguration to continue the task operations. The developments fall into three main areas: hardware, software, and theoretical.
The design and theory of operation of the servoactuator used for thrust vector control of the space shuttle solid rocket booster is described accompanied by highlights from the development and qualification test programs. Specific details are presented concerning major anomalies that occurred during the test programs and the corrective courses of action pursued.
In 2006, the Photovoltaic Thermal Control System (PVTCS) for the International Space Station's 2B power channel began leaking ammonia at a rate of approximately 1.5lbm/year (out of a starting approximately 53lbm system ammonia mass). Initially, the operations strategy was "feed the leak," a strategy successfully put into action via Extra Vehicular Activity during the STS‐134 mission. During this mission the system was topped off with ammonia piped over from a separate thermal control system. This recharge was to have allowed for continued power channel operation into 2014 or 2015, at which point another EVA would have been required. Without these periodic EVAs to refill the 2B coolant system, the channel would eventually leak enough fluid as to risk pump cavitation and system failure, resulting in the loss of the 2B power channel - the most critical of the Space Station's 8 power channels. In mid‐2012, the leak rate increased to approximately 5lbm/year. Once discovered, an EVA was planned and executed within a 5 week timeframe to drastically alter the architecture of the PVTCS via connection to a dormant thermal control system not intended to be utilized as anything other than spare components. The purpose of this rerouting of the TCS was to increase system volume and to isolate the photovoltaic radiator, thought to be the likely leak source. This EVA was successfully executed on November 1st, 2012 and left the 2B PVTCS in a configuration where the system was now being adequately cooled via a totally different radiator than what the system was designed to utilize. Unfortunately, data monitoring over the next several months showed that the isolated radiator was not leaking, and the system itself continued to leak steadily until May 9th, 2013. It was on this day that the ISS crew noticed the visible presence of ammonia crystals escaping from the 2B channel's truss segment, signifying a rapid acceleration of the leak from 5lbm/year to 5lbm/day. Within 48 hours of the crew noticing the leak, an EVA was in progress to replace the coolant pump - the only other replaceable leak source. This paper will explore the management of the 2B PVTCS leak from the operations perspective. It will discuss the methodology of performing the STS‐134 refill, the considerations and contingency plans which went into the architectural overhaul of the system in 2012, and the unprecedented effort which went into the EVA response to the visible leak of May 2013. In particular the paper will focus on the techniques utilized by flight controllers to monitor the system health and to respond to such instances as the rapid May 2013 leak by putting the electrical system in a safe configuration for loss of cooling, and will use recorded telemetry of these events to describe system response to EVA crew and ground actions. It will discuss the innovative design for redundancy of the integrated truss structure's cooling systems which allowed for this leak to be managed with minimal impact to other ISS operations and electrical services, contrasted against the real unintended operations consequences of utilizing the flexibility of the spacecraft's design in this manner. The paper will discuss how the training of the crew and flight controller personnel has adapted to the changing architecture of the power system and the unpredictable nature of the 2B leak.