Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “communication failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Operational characteristics of the dispersed sensor processor mesh

The dispersed sensor processing mesh (DSPM) is part of an experimental system used to pursue a proof of concept for an advanced fault-tolerant communication strategy. The DSPM experiments incorporate sensors and effectors into an ultra-reliable nodal network in which a central bus controller performs algorithms to grow and maintain the network. The experiments demonstrate that DSPM is an achievable communication network that can sustain failures and continue to function properly. The results of the experiment give insights into the unique characteristics of the DSPM network and the network's capacity to limit physical damage propagation, limit damaged-data propagation, and to survive cyclic communication paths. This paper describes the concept, mechanization, and performance of the DSPM system in a real-time flight-critical environment.

Abbott, L. W.↗

The Raid distributed database system

Raid, a robust and adaptable distributed database system for transaction processing (TP), is described. Raid is a message-passing system, with server processes on each site to manage concurrent processing, consistent replicated copies during site failures, and atomic distributed commitment. A high-level layered communications package provides a clean location-independent interface between servers. The latest design of the package delivers messages via shared memory in a configuration with several servers linked into a single process. Raid provides the infrastructure to investigate various methods for supporting reliable distributed TP. Measurements on TP and server CPU time are presented, along with data from experiments on communications software, consistent replicated copy control during site failures, and concurrent distributed checkpointing. A software tool for evaluating the implementation of TP algorithms in an operating-system kernel is proposed.

Bhargava, Bharat↗

7.3 Communications and Navigation

This presentation gives an overview of the networks NASA currently uses to support space communications and navigation, and the requirements for supporting future deep space missions, including manned lunar and Mars missions. The presentation addresses the Space Network, Deep Space Network, and Ground Network, why new support systems are needed, and the potential for catastrophic failure of aging antennas. Space communications and navigation are considered during Aerocapture, Entry, Descent and Landing (AEDL) only in order to precisely position, track and interact with the spacecraft at its destination (moon, Mars and Earth return) arrival. The presentation recommends a combined optical/radio frequency strategy for deep space communications.

Manning, Rob↗

Pilot errors as a source of workload

A pilot opinion survey was conducted to develop a database for creating simulation scenarios that impose predetermined levels of pilot workload. Twelve pilots estimated the effect of 163 events and activities (which they had encountered during their previous flying experiences) on performance, effort, workload, and stress. The events, described in the context of flight scenario segments, included control, navigation and communications activities, aircraft and system failures, and pilot errors. In general, workload, stress, and effort ratings were significantly correlated with each other but not with performance ratings; however, some different response patterns were found as a function of flight segment (e.g., workload, stress, and performance, but not effort, ratings varied with flight phase) and type of event. Errors were rated as a significant source of change for workload, stress, and performance, suggesting that errors could be conceptualized as a cause of workload rather than as a symptom.

Hart, S. G.↗

Applying formal methods and object-oriented analysis to existing flight software

Correctness is paramount for safety-critical software control systems. Critical software failures in medical radiation treatment, communications, and defense are familiar to the public. The significant quantity of software malfunctions regularly reported to the software engineering community, the laws concerning liability, and a recent NRC Aeronautics and Space Engineering Board report additionally motivate the use of error-reducing and defect detection software development techniques. The benefits of formal methods in requirements driven software development ('forward engineering') is well documented. One advantage of rigorously engineering software is that formal notations are precise, verifiable, and facilitate automated processing. This paper describes the application of formal methods to reverse engineering, where formal specifications are developed for a portion of the shuttle on-orbit digital autopilot (DAP). Three objectives of the project were to: demonstrate the use of formal methods on a shuttle application, facilitate the incorporation and validation of new requirements for the system, and verify the safety-critical properties to be exhibited by the software.

Cheng, Betty H. C.↗

Study Of Corrosion Of Lead-Sheathed Cables

Report presents statistical analysis of corrosion failures of lead-sheathed cables that serve as primary communication links at Kennedy Space Center. In study, corrosion-failure data analyzed by use of Weibull distribution in effort to assess effectiveness of cathodic protection and to predict future failures.

Lee, Rupert U.↗

A Major Threat of Satellite Radio Systems in Low Earth Orbit

Over the last two years several satellites in Low Earth Orbit (LEO) and geosynchronous orbit (GEO) have experienced serious or catastrophic failures including interruption of desired communications due especially to non linear interference.

Low Earth Orbit Satellite Radio Systems↗

Advanced Technologies for Future Spacecraft Cockpits and Space-based Control Centers

The National Aeronautics and Space Administration (NASA) is embarking on a new era of Space Exploration, aimed at sending crewed spacecraft beyond Low Earth Orbit (LEO), in medium and long duration missions to the Lunar surface, Mars and beyond. The challenges of such missions are significant and will require new technologies and paradigms in vehicle design and mission operations. Current roles and responsibilities of spacecraft systems, crew and the flight control team, for example, may not be sustainable when real-time support is not assured due to distance-induced communication lags, radio blackouts, equipment failures, or other unexpected factors. Therefore, technologies and applications that enable greater Systems and Mission Management capabilities on-board the space-based system will be necessary to reduce the dependency on real-time critical Earth-based support. The focus of this paper is in such technologies that will be required to bring advance Systems and Mission Management capabilities to space-based environments where the crew will be required to manage both the systems performance and mission execution without dependence on the ground. We refer to this concept as autonomy. Environments that require high levels of autonomy include the cockpits of future spacecraft such as the Mars Exploration Vehicle, and space-based control centers such as a Lunar Base Command and Control Center. Furthermore, this paper will evaluate the requirements, available technology, and roadmap to enable full operational implementation of onboard System Health Management, Mission Planning/re-planning, Autonomous Task/Command Execution, and Human Computer Interface applications. The technology topics covered by the paper include enabling technology to perform Intelligent Caution and Warning, where the systems provides directly actionable data for human understanding and response to failures, task automation applications that automate nominal and Off-nominal task execution based on human input or integrated health state-derived conditions. Shifting from Systems to Mission Management functions, we discuss the role of automated planning applications (tactical planning) on-board, which receive data from the other cockpit automation systems and evaluate the mission plan against the dynamic systems and mission states and events, to provide the crew with capabilities that enable them to understand, change, and manage the timeline of their mission. Lastly, we discuss the role of advanced human interface technologies that organize and provide the system md mission information to the crew in ways that maximize their situational awareness and ability to provide oversight and control of aLl the automated data and functions.

Garcia-Galan, Carlos↗

The HAL 9000 Space Operating System Real-Time Planning Engine Design and Operations Requirements

In support of future deep space manned missions, an autonomous/automated vehicle, providing crew autonomy and an autonomous response planning system, will be required due to the light time delays in communication. Vehicle capabilities as a whole must provide for tactical response to vehicle system failures and space environmental effects induced failures, for risk mitigation of permanent loss of communication with Earth, and for assured crew return capabilities. The complexity of human rated space systems and the limited crew sizes and crew skills mix drive the need for a robust autonomous capability on-board the vehicle. The HAL 9000 Space Operating System[2] designed for such missions and space craft includes the first distributed real-time planning / re-planning system. This paper will detail the software architecture of the multiple planning engine system, and the interface design for plan changes, approval and implementation that is performed autonomously. Operations scenarios will be defined for analysis of the planning engines operations and its requirements for nominal / off nominal activities. An assessment of the distributed realtime re-planning system, in the defined operations environment, will be provided as well as findings as it pertains to the vehicle, crew, and mission control requirements needed for implementation.

Stetson, Howard↗

Independent Orbiter Assessment (IOA): Assessment of the communication and tracking subsystem, volume 1

The results of the Independent Orbiter Assessment (IOA) of the Failure Modes and Effects Analysis (FMEA) and Critical Items List (CIL) are presented. The IOA effort first completed and analysis of the Communication and Tracking hardware, generating draft failure modes and potential critical items. To preserve independence, this analysis was accomplished without reliance upon the results contained within the NASA FMEA/CIL documentation. The IOA results were then compared to the NASA FMEA/CIL baseline. A resolution of each discrepancy from the comparison is provided through additional analysis as required. This report documents the results of that comparison for the Orbiter Communication and Tracking hardware. The IOA product for the Communication and Tracking consisted of 1,108 failure mode worksheets that resulted in 298 critical items being identified. Comparison was made to the NASA baseline which consists of 697 FMEAs and 239 CIL items. The comparison determined if there were any results which had been found by IOA but were not in the NASA baseline. This comparison produced agreement on all but 407 FMEAs which caused differences in 294 CIL items. Volume 1 contains the subsystem description, assessment results, ground rules and assumptions, and some of the IOA worksheets.

Long, W. C.↗

Space Plasma Shown to Make Satellite Solar Arrays Fail

In 1997, scientists and engineers of the Photovoltaic and Space Environments Branch of the NASA Lewis Research Center, Maxwell Technologies, and Space Systems/Loral discovered a new failure mechanism for solar arrays on communications satellites in orbit. Sustained electrical arcs, initiated by the space plasma and powered by the solar arrays themselves, were found to have destroyed solar array substrates on some Space Systems/Loral satellites, leading to array failure. The mechanism was tested at Lewis, and mitigation strategies were developed to prevent such disastrous occurrences on-orbit in the future. Deep Space 1 is a solar-electric-powered space mission to a comet, launched on October 24, 1998. Early in 1998, scientists at Lewis and Ballistic Missile Defense Organization (BMDO) realized that some aspects of the Deep Space 1 solar arrays were nearly identical to those that had led to the failure of solar arrays on Space Systems/Loral satellites. They decided to modify the Deep Space 1 arrays to prevent catastrophic failure in space. The arrays were suitably modified and are now performing optimally in outer space. Finally, the Earth Observing System (EOS) AM1, scheduled for launch in mid-1999, is a NASA mission managed by the Goddard Space Flight Center. Realizing the importance of Lewis testing on the Loral arrays, EOS-AM1 management asked Lewis scientists to test their solar arrays to show that they would not fail in the same way. The first phase of plasma testing showed that sustained arcing would occur on the unmodified EOS-AM1 arrays, so the arrays were removed from the spacecraft and fixed. Now, Lewis scientists have finished plasma testing of the modified array configuration to ensure that EOS-AM1 will have no sustained arcing problems on-orbit.

Ferguson, Dale C.↗

Inductive Learning Approaches for Improving Pilot Awareness of Aircraft Faults

Neural network flight controllers are able to accommodate a variety of aircraft control surface faults without detectable degradation of aircraft handling qualities. Under some faults, however, the effective flight envelope is reduced; this can lead to unexpected behavior if a pilot performs an action that exceeds the remaining control authority of the damaged aircraft. The goal of our work is to increase the pilot s situational awareness by informing him of the type of damage and resulting reduction in flight envelope. Our methodology integrates two inductive learning systems with novel visualization techniques. One learning system, the Inductive Monitoring System (IMS), learns to detect when a simulation includes faulty controls, while two others, Inductive Classification System (INCLASS) and multiple binary decision tree system (utilizing C4.5), determine the type of fault. In off-line training using only non-failure data, IMS constructs a characterization of nominal flight control performance based on control signals issued by the neural net flight controller. This characterization can be used to determine the degree of control augmentation required in the pitch, roll, and yaw command channels to counteract control surface failures. This derived information is typically sufficient to distinguish between the various control surface failures and is used to train both INCLASS and C4.5. Using data from failed control surface flight simulations, INCLASS and C4.5 independently discover and amplify features in IMS results that can be used to differentiate each distinct control surface failure situation. In real-time flight simulations, distinguishing features learned during training are used to classify control surface failures. Knowledge about the type of failure can be used by an additional automated system to alter its approach for planning tactical and strategic maneuvers. The knowledge can also be used directly to increase the pilot s situational awareness and inform manual maneuver decisions. Our multi-modal display of this information provides speech output to issue control surface failure warnings to a lesser-used communication channel and provides graphical displays with pilot-selectable !eve!s of details to issues additional information about the failure. We also describe a potential presentation for flight envelope reduction that can be viewed separately or integrated with an existing attitude indicator instrument. Preliminary results suggest that the inductive approach is capable of detecting that a control surface has failed and determining the type of fault. Furthermore, preliminary evaluations suggest that the interface discloses a concise summary of this information to the pilot.

Spikovska, Lilly↗

Independent Orbiter Assessment (IOA): Assessment of the communication and tracking subsystem, volume 2

The results of the Independent Orbiter Assessment (IOA) of the Failure Modes and Effects Analysis (FMEA) and Critical Items List (CIL) are presented. The IOA effort first completed and analysis of the Communication and Tracking hardware, generating draft failure modes and potential critical items. The IOA results were then compared to the NASA FMEA/CIL baseline. A resolution of each discrepancy from the comparison is provided through additional analysis as required. This report documents the results of that comparison for the Orbiter Communication and Tracking hardware. Volume 2 continues the presentation of IOA worksheets.

Long, W. C.↗

Independent Orbiter Assessment (IOA): Assessment of the communication and tracking subsystem, volume 3

The results of the Independent Orbiter Assessment (IOA) of the Failure Modes and Effects Analysis (FMEA) and Critical Items List (CIL) are presented. The IOA effort first completed and analysis of the Communication and Tracking hardware, generating draft failure modes and potential critical items. The IOA results were then compared to the NASA FMEA/CIL baseline. A resolution of each discrepancy from the comparison is provided through additional analysis as required. This report documents the results of that comparison for the Orbiter Communication and Tracking hardware. Volume 3 continues the presentation of IOA worksheets and contains the potential critical items list, detailed analysis, and the NASA FMEA to IOA worksheet cross reference and recommendations.

Long, W. C.↗

SNE Industrial Fieldbus Interface

Programmable logic controllers (PLCs) have very limited diagnostic and no prognostic capabilities, while current smart sensor designs do not have the capability to communicate over Fieldbus networks. The aim is to interface smart sensors with PLCs so that health and status information, such as failure mode identification and measurement tolerance, can be communicated via an industrial Fieldbus such as ControlNet. The SNE Industrial Fieldbus Interface (SIFI) is an embedded device that acts as a communication module in a networked smart sensor. The purpose is to enable a smart sensor to communicate health and status information to other devices, such as PLCs, via an industrial Fieldbus networking protocol. The SNE (Smart Network Element) is attached to a commercial off-the-shelf Any bus-S interface module through the SIFI. Numerous Anybus-S modules are available, each one designed to interface with a specific Fieldbus. Development of the SIFI focused on communications using the ControlNet protocol, but any of the Anybus-S modules can be used. The SIFI communicates with the Any-bus module via a data buffer and mailbox system on the Anybus module, and supplies power to the module. The Anybus module transmits and receives data on the Fieldbus using the proper protocol. The SIFI is intended to be connected to other existing SNE modules in order to monitor the health and status of a transducer. The SIFI can also monitor aspects of its own health using an onboard watchdog timer and voltage monitors. The SIFI also has the hardware to drive a touchscreen LCD (liquid crystal display) unit for manual configuration and status monitoring.

Lucena, Angel↗

Ampoule Failure System

An ampoule failure system for use in material processing furnaces comprising a containment cartridge and an ampoule failure sensor. The containment cartridge contains an ampoule of toxic material therein and is positioned within a furnace for processing. An ampoule failure probe is positioned in the containment cartridge adjacent the ampoule for detecting a potential harmful release of toxic material therefrom during processing. The failure probe is spaced a predetermined distance from the ampoule and is chemically chosen so as to undergo a timely chemical reaction with the toxic material upon the harmful release thereof. The ampoule failure system further comprises a data acquisition system which is positioned externally of the furnace and is electrically connected to the ampoule failure probe so as to form a communicating electrical circuit. The data acquisition system includes an automatic shutdown device for shutting down the furnace upon the harmful release of toxic material. It also includes a resistance measuring device for measuring the resistance of the failure probe during processing. The chemical reaction causes a step increase in resistance of the failure probe whereupon the automatic shutdown device will responsively shut down the furnace.

Watring, Dale A.↗

Cluster Inter-Spacecraft Communications

A document describes a radio communication system being developed for exchanging data and sharing data-processing capabilities among spacecraft flying in formation. The system would establish a high-speed, low-latency, deterministic loop communication path connecting all the spacecraft in a cluster. The system would be a wireless version of a ring bus that complies with the Institute of Electrical and Electronics Engineers (IEEE) standard 1393 (which pertains to a spaceborne fiber-optic data bus enhancement to the IEEE standard developed at NASA's Jet Propulsion Laboratory). Every spacecraft in the cluster would be equipped with a ring-bus radio transceiver. The identity of a spacecraft would be established upon connection into the ring bus, and the spacecraft could be at any location in the ring communication sequence. In the event of failure of a spacecraft, the ring bus would reconfigure itself, bypassing a failed spacecraft. Similarly, the ring bus would reconfigure itself to accommodate a spacecraft newly added to the cluster or newly enabled or re-enabled. Thus, the ring bus would be scalable and robust. Reliability could be increased by launching, into the cluster, spare spacecraft to be activated in the event of failure of other spacecraft.

Cox, Brian↗