Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Redundant Designs”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Prototype data terminal-multiplexer/demultiplexer

The design and operation of a quad redundant data terminal and a multiplexer/demultiplexer (MDU) is described. The most unique feature is the design of the quad redundant data terminal. This is one of the few designs where the unit is fail/op, fail/op, fail/safe. Laboratory tests confirm that the unit will operate satisfactorily with the failure of three out of four channels. Although the design utilizes state-of-the-art technology, the waveform error checks, the voting techniques, and the parity bit checks are believed to be used in unique configurations. Correct word selection routines are also novel. The MDU design, while not redundant, utilizes, the latest state-of-the-art advantages of light coupler and interested amplifiers. Much of the technology employed was an evolution of prior NASA contracts related to the Addressable Time Division Data System. A good example of the earlier technology development was the development of a low level analog multiplexer, a high level analog multiplexer, and a digital multiplexer. A list of all drawings is included for reference and all schematic, block and timing diagrams are incorporated.

Leck, D. E.↗

Viking dynamics experience with application to future payload design

Analytical and test techniques are discussed. Areas in which hindsight indicated erroneous, redundant, or unnecessarily severe design and test specifications are identified. Recommendations are made for improvements in the dynamic design and criteria philosophy, aimed at reducing costs for payloads.

Barrett, S.↗

Lessons from NASA

Particular requirements related to the design and the operation of spacecraft have forced NASA to take a reliability approach that differs somewhat from that used in many other applications. NASA has found that some of the traditional tools of reliability engineering, such as life testing, reliability demonstration testing, maintainability analysis, and direct failure analysis, are impractical for spacecraft. In place of a statistical approach, the space agency uses an engineering approach to mission reliability. Reliability is to be obtained with the aid of three different approaches, including the application of effective design principles, the control and screening of all parts, and the testing of the entire spacecraft or its prototype for predicted capabilities. Attention is given to failure-mode analysis, the enhancement of Voyager reliability by autonomous operation, the redundancy in Shuttle design, the weeding out of bad hardware, and the preference for off-the-shelf devices.

Williams, W. C.↗

Flight Plasma Diagnostics for High-Power, Solar-Electric Deep-Space Spacecraft

NASA's Asteroid Redirect Robotic Mission (ARRM) project plans included a set of plasma and space environment instruments, the Plasma Diagnostic Package (PDP), to fulfill ARRM requirements for technology extensibility to future missions. The PDP objectives were divided into the classes of 1) Plasma thruster dynamics, 2) Solar array-specific environmental effects, 3) Plasma environmental spacecraft effects, and 4) Energetic particle spacecraft environment. A reference design approach and interface requirements for ARRM's PDP was generated by the PDP team at JPL and GRC. The reference design consisted of redundant single-string avionics located on the ARRM spacecraft bus as well as solar array, driving and processing signals from multiple copies of several types of plasma, effects, and environments sensors distributed over the spacecraft and array. The reference design sensor types were derived in part from sensors previously developed for USAF Research Laboratory (AFRL) plasma effects campaigns such as those aboard TacSat-2 in 2007 and AEHF-2 in 2012.

Johnson, Lee↗

Flight Plasma Diagnostics for High-Power, Solar-Electric Deep-Space Spacecraft

NASA’s Asteroid Redirect Robotic Mission (ARRM) mission concept plans included a set of plasma and space environment instruments, the Plasma Diagnostic Package (PDP), to fulfill ARRM requirements for technology extensibility to future missions. The PDP objectives were divided into the classes of 1) Plasma thruster dynamics, 2) Solar array-specific environmental effects, 3) Plasma environmental spacecraft effects, and 4) Energetic particle spacecraft environment. A reference design approach and interface requirements for ARRM’s PDP was generated by the PDP team at JPL and GRC. The reference design consisted of redundant single-string avionics located on the ARRM spacecraft bus as well as solar array, driving and processing signals from multiple copies of several types of plasma, effects, and environments sensors distributed over the spacecraft and array. The reference design sensor types were derived in part from sensors previously developed for USAF Research Laboratory (AFRL) plasma effects campaigns such as those aboard TacSat-2 in 2007 and AEHF-2 in 2012. ARRM project leadership also encouraged the PDP team to convene a team of topical subject matter experts from across the country to review and confirm the reference design and to consider effective alternatives and/or enhancements to the reference design. This activity was proposed and accepted as an interactive, informal JPL “A-team” study and a cadre of 25 participants gathered in early 2017 for discussions. The outcome of the two-day A-team study was that the PDP reference design would allow the most important induced-environment unknowns to be measured in the appropriate space environment. Another outcome addressed technology developments of new or improved space plasma environmental sensors. The A-team study concluded that selected developments would lead to improved measurements that could efficiently provide important and otherwise unavailable information about plasma thruster operation in the space environment as well as the plasma induced spacecraft environment. Specifically, the A-team group recommended greater sensor diversity, by inclusion of deployed sensor capabilities in the thruster plume, or by occasional gimbaling of the thruster(s) toward the sensor arrays. The A-team also recommended developing high-speed probes, optical plasma probes, energy selective probes, and direct erosion/deposition sensors, among others; and recommended the inclusion of cameras as well as, since ARRM was to be recovered in cis-lunar orbit by a crewed mission, astronaut assessments of thruster induced environments and collection of sample coupons. Overall, the PDP A-team study provided a clear, consensus supported validation of the reference design PDP approach and pointed out important directions for future flight plasma sensor development.

Choi, Maria↗

Markov chains for testing redundant software

A preliminary design for a validation experiment has been developed that addresses several problems unique to assuring the extremely high quality of multiple-version programs in process-control software. The procedure uses Markov chains to model the error states of the multiple version programs. The programs are observed during simulated process-control testing, and estimates are obtained for the transition probabilities between the states of the Markov chain. The experimental Markov chain model is then expanded into a reliability model that takes into account the inertia of the system being controlled. The reliability of the multiple version software is computed from this reliability model at a given confidence level using confidence intervals obtained for the transition probabilities during the experiment. An example demonstrating the method is provided.

White, Allan L.↗

Modeling Common Cause Failures of Thrusters on ISS Visiting Vehicles

This paper discusses the methodology used to model common cause failures of thrusters on the International Space Station (ISS) Visiting Vehicles. The ISS Visiting Vehicles each have as many as 32 thrusters, whose redundancy and similar design make them susceptible to common cause failures. The Global Alpha Model (as described in NUREG/CR-5485) can be used to represent the system common cause contribution, but NUREG/CR-5496 supplies global alpha parameters for groups only up to size six. Because of the large number of redundant thrusters on each vehicle, regression is used to determine parameter values for groups of size larger than six. An additional challenge is that Visiting Vehicle thruster failures must occur in specific combinations in order to fail the propulsion system; not all failure groups of a certain size are critical.

Haught, Megan↗

Space Tug laser gyro IMU

A redundant inertial measuring unit (IMU) incorporating six strapdown laser gyros and six accelerometers, arranged so that sensitive axes are normal to the faces of a dodecahedron, provides enhanced reliability with reduced hardware weight. Software monitoring of sensor outputs senses failure of sensors and the system is designed for triple redundancy, with built-in test equipment. Attention is centered on redundancy and fail-safe features, and on the closed-path ring laser gyro arrangement.

Morrison, R.↗

Development of a Two-Wheel Contingency Mode for the MAP Spacecraft

The Microwave Anisotropy Probe (MAP) is a follow-on mission to the Cosmic Background Explorer (COBE), and is currently collecting data from its orbit near the second Sun-Earth libration point. Due to limited mass, power, and financial resources, a traditional reliability concept including fully redundant components was not feasible for MAP. Instead, the MAP design employs selective hardware redundancy in tandem with contingency software modes and algorithms to improve the odds of mission success. One direction for such improvement has been the development of a two-wheel backup control strategy. This strategy would allow MAP to position itself for maneuvers and collect science data should one of its three reaction wheels fail. Along with operational considerations, the strategy includes three new control algorithms. These algorithms would use the remaining attitude control actuators-thrusters and two reaction wheels-in ways that achieve control goals while minimizing adverse impacts on the functionality of other subsystems and software.

Starin, Scott R.↗

Finite element analysis of the Space Shuttle 2.5-inch frangible nut

Finite element analysis of the Space Shuttle 2.5-inch frangible nut was conducted to improve understanding of the current design and proposed design changes to this explosively-actuated nut. The 2.5-inch frangible nut is used in two places to attach the aft end of the Space Shuttle Orbiter to the External Tank. Both 2.5-inch frangible nuts must function to complete safe separation. The 2.5-inch frangible nut contains two explosive boosters containing RDX explosive each capable of splitting the nut in half, on command from the Orbiter computers. To ensure separation, the boosters are designed to be redundant. The detonation of one booster is sufficient to split the nut in half. However, beginning in 1987 some production lots of 2.5-inch frangible nuts have demonstrated an inability to separate using only a single booster. The cause of the failure has been attributed to differences in the material properties and response of the Inconel 718 from which the 2.5-inch frangible nut is manufactured. Subsequent tests have resulted in design modifications of the boosters and frangible nut. Model development and initial analysis was conducted by Sandia National Laboratories (SNL) under funding from NASA Lyndon B. Johnson Space Center (NASA-JSC) starting in 1992. Modeling codes previously developed by SNL were transferred to NASA-JSC for further analysis on this and other devices. An explosive bolt with NASA Standard Detonator (NSD) charge, a 3/4-inch frangible nut, and the Super*Zip linear separation system are being modeled by NASA-JSC.

Darin N. McKinnis↗

Viking lander design and systems integration

Malfunction protection requires redundancy planning and mechanization in Viking lander design and systems integration in order to maximize the chance of getting the data back through the Orbiter. Various subsystems are discussed that protect the downlink to man on the ground in the framework of systems integration and insure the basic objectives of Viking: to land on a planet and to acquire data from its surface.

Goodlette, J.↗

Attitude Control System Design for the Solar Dynamics Observatory

The Solar Dynamics Observatory mission, part of the Living With a Star program, will place a geosynchronous satellite in orbit to observe the Sun and relay data to a dedicated ground station at all times. SDO remains Sun- pointing throughout most of its mission for the instruments to take measurements of the Sun. The SDO attitude control system is a single-fault tolerant design. Its fully redundant attitude sensor complement includes 16 coarse Sun sensors, a digital Sun sensor, 3 two-axis inertial reference units, 2 star trackers, and 4 guide telescopes. Attitude actuation is performed using 4 reaction wheels and 8 thrusters, and a single main engine nominally provides velocity-change thrust. The attitude control software has five nominal control modes-3 wheel-based modes and 2 thruster-based modes. A wheel-based Safehold running in the attitude control electronics box improves the robustness of the system as a whole. All six modes are designed on the same basic proportional-integral-derivative attitude error structure, with more robust modes setting their integral gains to zero. The paper details the mode designs and their uses.

Starin, Scott R.↗

Advances in Thrust-Based Emergency Control of an Airplane

Engineers at NASA's Dryden Flight Research Center have received a patent on an emergency flight-control method implemented by a propulsion-controlled aircraft (PCA) system. Utilizing the preexisting auto-throttle and engine-pressure-ratio trim controls of the airplane, the PCA system provides pitch and roll control for landing an airplane safely without using aerodynamic control surfaces that have ceased to function because of a primary-flight-control-system failure. The installation of the PCA does not entail any changes in pre-existing engine hardware or software. [Aspects of the method and system at previous stages of development were reported in Thrust-Control System for Emergency Control of an Airplane (DRC-96-07), NASA Tech Briefs, Vol. 25, No. 3 (March 2001), page 68 and Emergency Landing Using Thrust Control and Shift of Weight (DRC-96-55), NASA Tech Briefs, Vol. 26, No. 5 (May 2002), page 58.]. Aircraft flight-control systems are designed with extensive redundancy to ensure low probabilities of failure. During recent years, however, several airplanes have exhibited major flight-control-system failures, leaving engine thrust as the last mode of flight control. In some of these emergency situations, engine thrusts were successfully modulated by the pilots to maintain flight paths or pitch angles, but in other situations, lateral control was also needed. In the majority of such control-system failures, crashes resulted and over 1,200 people died. The challenge lay in creating a means of sufficient degree of thrust-modulation control to safely fly and land a stricken airplane. A thrust-modulation control system designed for this purpose was flight-tested in a PCA an MD-11 airplane. The results of the flight test showed that without any operational control surfaces, a pilot can land a crippled airplane (U.S. Patent 5,330,131). The installation of the original PCA system entailed modifications not only of the flight-control computer (FCC) of the airplane but also of each engine-control computer. Inasmuch as engine-manufacturer warranties do not apply to modified engines, the challenge became one of creating a PCA system that does not entail modifications of the engine computers.

Creech, Gray↗