System reliability analysis of the manned orbiting research laboratory.
MORL system reliability analysis, discussing Monte Carlo simulation, major parameters, constraints, program contingencies, etc
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
MORL system reliability analysis, discussing Monte Carlo simulation, major parameters, constraints, program contingencies, etc
The Lunar Atmosphere and Dust Environment Explorer (LADEE) spacecraft was launched on September 7, 2013 UTC, and completed its mission on April 17, 2014 UTC with a directed impact to the Lunar Surface. Its primary goals were to examine the lunar atmosphere, measure lunar dust, and to demonstrate high rate laser communications. The mission objectives, much of which can be attributed to careful LADEE mission was a resounding success, achieving all planning and preparation. This paper discusses the specific preparations for fault conditions that could occur during a highly-critical phase of the mission, the Lunar Orbit Insertion (LOI). highly critical phase of the mission.
Conceptual designs of (1) initial planetary base structures, and (2) an unmanned machine to perform the construction of these structures using materials local to the planet are presented. Rock melting is suggested as a possible technique to be used by the machine in fabricating roads, platforms, and interlocking bricks. Identification of problem areas in machine design and materials processing is accomplished. The feasibility of the designs is contingent upon favorable results of an analysis of the engineering behavior of the product materials. The analysis requires knowledge of several parameters for solution of the constitutive equations of the theory of elasticity. An initial collection of these parameters is presented which helps to define research needed to perform a realistic feasibility study. A qualitative approach to estimating power and mass lift requirements for the proposed machine is used which employs specifications of currently available equipment. An initial, unmanned mission scenario is discussed with emphasis on identifying uncompleted tasks and suggesting design considerations for vehicles and primitive structures which use the products of the machine processing.
I. Design: a) S/C designed to be largely single fault tolerant; b) Operate in flight demonstrated envelope, with margin; and c) Strict compliance with requirements & flight rules. II. Test: a) Baseline, fault & stress testing using flight system testbeds (H/W & S/W); b) In-flight checkout & demos to remove first time events. III. Failure Analysis: a) Critical event driven fault tree analysis; b) Risk mitigation & development of contingencies. IV) Residual Risks: a) Accepted pre-launch waivers to Single Point Failures; b) Unavoidable risks (e.g. natural disaster). V) Mission Assurance: a) Strict process for characterization of variances (ISAs, PFRs & Waivers; b) Full time Mission Assurance Manager reports to Program Manager: 1) Independent assessment of compliance with institutional standards; 2) Oversight & risk assessment of ISAs, PFRs & Waivers etc.; and 3) Risk Management Process facilitator.
A human-centered systems analysis was applied to the adverse aircraft weather encounter problem in order to identify desirable functions of weather and icing information. The importance of contingency planning was identified as emerging from a system safety design methodology as well as from results of other aviation decision-making studies. The relationship between contingency planning support and information on regions clear of adverse weather was investigated in a scenario- based analysis. A rapid prototype example of the key elements in the depiction of icing conditions was developed in a case study, and the implications for the components of the icing information system were articulated.
The identification, modelling, and analysis of root causes of accidents and incidents dominate conventional safety management approaches. However, the effect of humans’ safety-producing behavior on the overall resilience of the system is often neglected. Additionally, emerging aviation markets are giving rise to concepts of operation, such as urban air mobility and optionally piloted air cargo operations, that are leading to a shift in locus of control between humans and automation. Without an understanding of the human contribution to safety, it is difficult to assess the effects of these novel role allocations on overall system safety. In this work, safety-producing behaviors are identified and abstracted into resilient performance strategies. Production rules that encapsulate these strategies are then generated and classified in the Soar cognitive architecture. The strategies are then applied to a remotely-operated air cargo example to demonstrate how safe learning is facilitated. The learned rules and strategies are then formally verified.
As automated space systems become more complex, autonomous, and opaque to the flight crew, it becomes increasingly difficult to determine whether the total system is performing as it should. Some of the complex and interrelated human performance measurement issues are addressed that are related to total system validation. An evaluative throughput model is presented which can be used to generate a human operator-related benchmark or figure of merit for a given system which involves humans at the input and output ends as well as other automated intelligent agents. The concept of sustained and accurate command/control data information transfer is introduced. The first two input parameters of the model involve nominal and off-nominal predicted events. The first of these calls for a detailed task analysis while the second is for a contingency event assessment. The last two required input parameters involving actual (measured) events, namely human performance and continuous semi-automated system performance. An expression combining these four parameters was found using digital simulations and identical, representative, random data to yield the smallest variance.
As part of the Orbiter Repair Maneuver (ORM) planned for Return to Flight (RTF) operations, the Shuttle Remote Manipulator System (SRMS) must undock the Orbiter, maneuver it through a complex trajectory at extremely low rates, present it to an EVA crewman at the end of the Space Station Remote Manipulator System to perform the Thermal Protection System (TPS) repair, and then retrace back through the trajectory to dock the Orbiter with the Orbiter Docking System (ODS). The initial and final segments of this operation involve the interaction between the SRMS, ISS, Orbiter and ODS. Previously, a technique entitled "SRMS assisted docking" for installation of a payload to the ODS had been developed and was utilized for the Russian provided Docking Module on STS-74 during Shuttle-Mir missions and both the Node 1 and FGB elements on STS-88/Flight 2A. This procedure consisted of the SRMS grappling the respective payload, maneuvering it to a pre-install position inches above the ODS Androgynous Peripheral Attachment System (APAS) ring, commanding the SRMS into Test mode (which allows brakes-off motion of the joints), and then down-firing Primary Reaction Control System (PRCS) jets in order to effect a capture of the APAS latches. Once a successful capture had been achieved, then the AP AS was operated through its nominal retraction sequence to complete the mating sequence. While this technique can once again be used for the tail end docking portion of the ORM, the initial undocking of the orbiter and ISS vehicles with the assistance of the SRMS has yet to be attempted on orbit. The objective here is to determine the most efficient means to separate or extract the vehicles. Two techniques were analyzed in support of RTF: (1) the 'nominal' demating from the mated interface, and (2) the SRMS performing the operation (either in an active or passive fashion). In the first operation, the demating process would replicate standard undocking operations, with the exception that the SRMS is allowed to arrest the resulting motion. The second operation would be to extend the APAS ring to a ready to dock position, open the capture latches, and then detach the vehicles using the SRMS either actively or passively. In the active case, the APAS ring is extended and latched, and the SRMS is commanded to pull the two interfaces apart (assuming that the effective pull force of the SRMS can overcome the spec values of the combined latch resistance). In the passive case, the SRMS brakes are engaged and the AP AS mechanism is commanded to retract, pulling the two interfaces apart. Since the emphasis of both STS-74 and STS-88 had solely been on the installation operation, as opposed to the separation operation, two new models required development and incorporation within simulation tools designed to analyze those scenarios. These enhancements included: (1) a detailed demating dynamics model to characterize the pusher spring characteristics during undocking, and (2) contact and mechanical system modeling of the back side of the latches to represent unlatching dynamics. This paper first provides an overview of the Monte-Carlo screening analysis for the installation (both nominal and contingency), including the variation of separation distance, misalignment conditions, SRMS joint/brake parameter characteristics, and PRCS jet combinations and corresponding thrust durations. The resulting 'optimum' solution is presented based on trade studies between predicted capture success and integrated system loads. This paper then discusses the upgrades to the APAS math model associated with the new SRMS assisted undocking technique and reviews simulation results for various options investigated for either the active and passive separation of the ISS from the Orbiter.
The Public Entry Risk Assessment (PERA) program addresses risk to the public from shuttle or other spacecraft re-entry trajectories. Managing public risk to acceptable levels is a major component of safe spacecraft operation. PERA is given scenario inputs of vehicle trajectory, probability of failure along that trajectory, the resulting debris characteristics, and field size and distribution, and returns risk metrics that quantify the individual and collective risk posed by that scenario. Due to the large volume of data required to perform such a risk analysis, PERA was designed to streamline the analysis process by using innovative mathematical analysis of the risk assessment equations. Real-time analysis in the event of a shuttle contingency operation, such as damage to the Orbiter, is possible because PERA allows for a change to the probability of failure models, therefore providing a much quicker estimation of public risk. PERA also provides the ability to generate movie files showing how the entry risk changes as the entry develops. PERA was designed to streamline the computation of the enormous amounts of data needed for this type of risk assessment by using an average distribution of debris on the ground, rather than pinpointing the impact point of every piece of debris. This has reduced the amount of computational time significantly without reducing the accuracy of the results. PERA was written in MATLAB; a compiled version can run from a DOS or UNIX prompt.
- The design and development of robotic spaceflight instruments is a critical part of NASA’s vision to discover and expand knowledge for the benefit of humanity - For typical flight instrument projects, thermal engineers will develop initial instrument thermal models over weeks or months, then iterate them over a project’s lifespan – In each iteration, the engineer will: - Refine their thermal models and thermal designs in accordance with updates from other subsystems - Perform trade studies - Solve very detailed and complex analysis problems, including worst-cases and contingencies - Pick hardware and plan for testing and integration - However, prior to a project being established, or for proposal development at an early conceptual stage, the luxury of multiple instrument design iterations may be limited or nonexistent – Within a short timeline, how do you complete a thermal model or explore multiple possible instrument configurations? – What are the critical parameters for your model? Which details do you include or leave out?
We present the latest result of a community-wide space weather model validation effort coordinated among the Community Coordinated Modeling Center (CCMC), NOAA Space Weather Prediction Center (SWPC), model developers, and the broader science community. Validation of geospace models is a critical activity for both building confidence in the science results produced by the models and in assessing the suitability of the models for transition to operations. Indeed, a primary motivation of this work is supporting NOAA/SWPCs effort to select a model or models to be transitioned into operations. Our validation efforts focus on the ability of the models to reproduce a regional index of geomagnetic disturbance, the local K-index. Our analysis includes six events representing a range of geomagnetic activity conditions and six geomagnetic observatories representing midlatitude and high-latitude locations. Contingency tables, skill scores, and distribution metrics are used for the quantitative analysis of model performance. We consider model performance on an event-by-event basis, aggregated over events, at specific station locations, and separated into high-latitude and midlatitude domains. A summary of results is presented in this report, and an online tool for detailed analysis is available at the CCMC.
Future exploration missions require the development of a new liquid cooling garment (LCG) that offers greater system reliability, is more comfortable, and maximizes thermal performance. To inform the development of a future LCG a thermal performance test was conducted to evaluate three factors: (1) the effect of the thermal comfort undergarment (TCU) on tactile and thermal comfort, (2) the comparable thermal performance of an CSAFE developed engineering evaluation unit (EEU) LCG, which uses a commercial-off-the-shelf (COTS) wicking garment as the base, and (3) the performance of a torso or upper body only LCG configuration to evaluate a proposed auxiliary loop configuration. To evaluate the thermal performance of each configuration a metabolic suit test was conducted, utilizing suited subjects to generate metabolic heat by walking on a treadmill at various speeds. Three (3) test subjects of similar height and weight produced a metabolic load for five tests by either resting (300-600 BTU/hr), walking at a slow pace (1200 BTU/hr), and walking at a brisk pace (2200 BTU/hr). During the test, data was collected that would allow us to track the heat transfer to the LCG and ventilation system to determine the thermal performance of the LCG configurations. Four different test configurations were tested, with one configuration tested twice. The test results show that the CSAFE EEU LCG and EMU LCG had comparable performance. The testing also showed that an auxiliary loop LCG, sized similarly to the shirt-only configuration, should provide adequate cooling for contingency scenarios. Finally, the testing showed the previous analysis that assumed a UA deterioration from the TCU was too conservative and the TCU may prove to be acceptable for future development with additional analysis and testing.
Adverse events during implementation can affect final capabilities, schedule and cost of a computer system even though the system was accurately designed and evaluated. Risk analysis enables the manager to forecast the impact of those events and to timely ask for design revisions or contingency plans before making any decision. This paper presents a structured procedure for an effective risk analysis. The procedure identifies the required activities, separates subjective assessments from objective evaluations, and defines a risk measure to determine the analysis results. The procedure is consistent with the system design evaluation and enables a meaningful comparison among alternative designs.
The results of an analysis of the orbiter electrical power system for the case of a single failure tolerant (SFT) entry are presented. The analysis was performed using the shuttle electrical power system analysis computer program. It was performed to permit assessment of the capability of the orbiter systems to support the proposed entry configuration and to provide the data necessary to identify potential constraints and limitations. Three contingency modes have been identified which would require an SFT entry. This analysis addresses an SFT entry resulting from the loss of two fuel cell powerplants, while on orbit. The results of the analysis indicate that, even under near optimum conditions, the fuel cell power demand will exceed the tested operating capacity of 16 kw, and that various electrical components may experience voltages below 24 VDC.
Contingency planning, rescue vehicle requirements, operational considerations, and system analysis for space rescue operations - Vol. 2
The mid-lift-to-drag ratio (mid-L/D) lifting body is a fully autonomous spacecraft under design at NASA for enabling a rapid return of scientific payloads from the International Space Station (ISS). For contingency planning and risk assessment for the Earth-return trajectory, an entry demise analysis was performed to examine three potential failure scenarios: (1) nominal entry interface conditions with loss of control, (2) controlled entry at maximum flight path angle, and (3) controlled entry at minimum flight path angle. The objectives of the analysis were to predict the spacecraft breakup sequence and timeline, determine debris survival, and calculate the debris dispersion footprint. Sensitivity analysis was also performed to determine the effect of the initial pitch rate on the spacecraft stability and breakup during the entry. This report describes the mid-L/D lifting body and presents the results of the entry demise and sensitivity analyses.
CO2 Washout refers to the suit’s ability to remove exhaled metabolic waste gases from the helmet before the crewmember’s next consecutive inhale. Efficient removal of such waste gases is paramount as it prevents crewmember fatigue as well as hypoxia. A variety of hardware and conditions inside the suit contribute to the efficiency at which CO2 washout occurs including (but not limited to) the shape of the helmet bubble, crewmember head position, breathing type and metabolic rate, the configuration of the oxygen vent inside the helmet, etc. While designing the oxygen vent inside the helmet of the Extravehicular Mobility Unit (xEMU) both nominal and contingency scenarios were considered in order to optimize CO2 washout. During nominal Extravehicular Activity (EVA), the pressure gradient created by the vent loop inlets located in the arms and legs of the Pressure Garment Subsystem (PGS) aids in washout by pulling the metabolic waste out of the helmet. However, in the event that a contingency scenario occurs, where the flow of oxygen to the crewmember, or the removal of metabolic waste is disrupted, the primary oxygen regulator fails open and removal of waste is no longer performed by the vent loop, but rather by the Low Flow Purge Valve (LFPV) located in the helmet. The paper to follow will provide an overview of the analysis, design, and testing performed to optimize washout for both nominal and contingency scenarios for the most current design iteration of the xEMU.
Why do most space life support research groups build and investigate large models for systems simulation? The need for them seems accepted, but are we asking the right questions and solving the real problems? The modeling results leave many questions unanswered. How then should space life support be modeled and simulated? Life support system research and development uses modeling and simulation to study dynamic behavior as part of systems engineering and analysis. It is used to size material flows and buffers and plan contingent operations. A DoD sponsored study used the systems engineering approach to define a set of best practices for modeling and simulation. These best practices describe a systems engineering process of developing and validating requirements, defining and analyzing the model concept, and designing and testing the model. Other general principles for modeling and simulation are presented. Some specific additional advice includes performing a static analysis before developing a dynamic simulation, applying the mass and energy conservation laws, modeling on the appropriate system level, using simplified subsystem representations, designing the model to solve a specific problem, and testing the model on several different problems. Modeling and simulation is necessary in life support design but many problems are outside its scope.