Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “fault injection”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Validation of the Mars 2020 Fault Protection Design: Navigating the Infinity of the Off-Nominal

On July 30th 2020, the Mars 2020 mission successfully launched out of Cape Canaveral, Florida, passed through the Earth’s shadow, and began its short cruise to Mars. Less than seven months later, the Perseverance rover touched down safely in Jezero Crater to begin its ambitious mission that includes looking for signs of ancient life and collecting samples for future return to Earth. Getting to the successful landing, or “Tango Delta Nominal,” could not have been achieved without also considering the off-nominal. One of the teams supporting this ambitious mission is the fault protection (FP) team. This team is tasked with assessing the various failures, or faults, that could prevent mission success and with ensuring that the autonomous behaviors built into the software and hardware can detect faults and recover the vehicle to a safe state. As part of its charter, the FP team designed a test campaign to provide confidence in the system’s robustness to off-nominal scenarios across all of Mars 2020’s mission phases. The greatest challenge associated with designing such a validation campaign was reducing the infinite number of anomalous scenarios into a finite test suite. In addition, the tests needed to be executed efficiently in order to utilize the team’s limited test venue access, but still needed to maintain a level of rigor that guaranteed confidence in the test outcomes. Given that each test scenario generated massive amounts of data, the team also developed methods for quickly ascertaining whether the autonomous fault protection behaviors maintained vehicle safety in the presence of an anomaly. This paper summarizes the processes that the Mars 2020 fault protection team employed to execute its off-nominal validation campaign. It captures both the methods of generating a suite of off-nominal tests, as well as reducing it to a subset that can be realistically executed within schedule and resource constraints. It also describes the various processes and philosophies that the team utilized to execute the tests efficiently, including creating a standardized procedure template, keeping the test cases modular so that they could be easily interchanged, and capturing common fault injections in a change-controlled database. Finally, it will describe the tools and processes for assessing the test data, focusing in particular on a tool that evaluated vehicle state using “secondary” sources of data to validate that the software had truly configured the spacecraft to the expected safe state.

Morantz, Chaz↗

Adaptive Independent Verification and Validation (IV&V) Reduces Risk of Software Impacting Safety in Artemis Missions

The National Aeronautics and Space Administration (NASA) is asking more of its human spaceflight programs than ever before through the collective Artemis Missions. The NASA Independent Verification and Validation (IV&V) Program contributes to NASA’s human spaceflight goals by providing IV&V services for NASA’s critical spacecraft and ground software. The IV&V Program is tasked with providing assurance from both individual and integrated mission software perspectives. The Artemis IV&V organization is actively supporting six distinct development efforts: Orion, the Space Launch System (SLS), Exploration Ground Systems (EGS), Mission Control Center (MCC), the Lunar Gateway, and the Human Landing System (HLS), representing a wide diversity of developer organizations, management structures, and development approaches. With much of this extremely complex flight and ground software being essential to human safety both on the ground and in space, Artemis IV&V is likewise challenged to provide more value-added assurance to future Artemis missions within a constrained budget. To meet this challenge, Artemis IV&V employs a variety of novel and evolving “Adaptive IV&V” approaches for planning and executing IV&V analysis to increase both the efficiency and effectiveness of the IV&V Program’s assurance activities, and to address the difficulties imposed by assuring software for a large, highly integrated, multi-mission enterprise managed and executed by physically and organizationally distinct programs. Instilling agile principles like iterative planning cycles, self-organizing teams, and regular retrospectives, into IV&V planning and execution has led to a more rapid turnaround of a minimum viable assurance product and allowed for increased alignment of assurance activities with development progress. Adopting an assurance case methodology has led to greater consistency and clearer communication of assurance design and provided a foundation for long-term maintenance of assurance plans, products, and results across missions. The IV&V-developed Assurance / Safety Case Analytical Network (A-SCAN) framework and tool has enabled the quantification and tracking of system/software risk and confidence. These confidence measures provide a means to repeatedly express the impact of planned and completed assurance work and the remaining residual risk. Applied as part of a “Follow-the-Risk” organizational ethos, this allows consistent rightsizing of analysis rigor and intensity commensurate with the perceived risk of defects, as well as appropriate targeting of the highest risk areas of the software to find safety issues before they can manifest. Finally, the development of the IV&V Advanced Risk Reduction Integrated Software Test and Operations Tri-program Lightweight Environment (ARRISTOTLE), an integrated software-only simulation of Orion, SLS, and EGS systems, has made it possible to independently test integrated pad and flight scenarios and inject faults to observe how the Artemis multi-program, mission software behaves in degraded modes and in response to hazards. These adaptive IV&V investments have enabled Artemis IV&V to become more efficient and effective in IV&V planning and execution and respond more readily to changes in the risk landscape, increasing the breadth and depth of risk reduction possible within the available resources. Residual risk tracking allows IV&V to communicate more effectively with stakeholders, both internal and external at all levels, and inform key decision-making personnel. This evolving assurance design approach provides IV&V surety that work is performed in the highest risk, most value-added areas of the software, to keep our astronauts and ground crews safe and ensure mission success.

Gerek Whitman↗

Reusable Verification Components for High-Energy Physics readout ASICs

Verification is a critical aspect of designing front-end (FE) readout ASICs for High-Energy Physics (HEP) experiments. These ASICs share several similar functional features, resulting in similar verification objectives, which can be addressed using comparable verification strategies. This contribution presents a set of re-usable verification components for addressing common verification tasks, such as clock generation, reset handling, configuration, as well as hit and fault injections. The components were developed as part of the CHIPS initiative and they have been successfully used in the verification of multiple HEP ASICs.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Factors controlling injection-induced rupture of intersecting faults during geological sequestration of CO 2

This study addresses coupled multiphase fluid flow and geomechanics effects on potential fault activation associated with subsurface CO 2 injection around intersecting faults. An enhanced fault-representation model is used to capture geomechanical responses of two intersecting faults with finite length during CO 2 injection. The faults are embedded in a strike-slip stress regime of a caprock-reservoir-basement system with the faults represented by zero-thickness interfaces with adjacent finite-thickness damage zones. A sensitivity analysis is conducted to study the effect of fault permeability, slip-weakening behavior, well location relative to the orientation of faults, and well placement (the number and location of injection wells). Five metrics (pressure, CO 2 plume, shear state on the fault, as well as shear displacement and stress path at selected fault monitoring points) are selected to assess CO 2 migration and reactivation of intersecting faults. The results show that induced ruptures are favored by low permeability faults due to high pressure buildup and by slip-weakening behavior resulting from fault strength reduction. The location of one injection well relative to fault orientation determines the magnitude of changes in effective normal stress and shear stress, affecting the location of induced ruptures. Well placement (two injection wells used in the paper) dominates pressure diffusion around the intersection and tips of faults. This redistributes changes in effective normal stress caused by each injection well, influencing the spatial distribution of ruptures along faults. A larger injection volume induces far-field ruptures that are controlled by stress transfer within the injection layer. The findings presented here can provide valuable insights into engineering operations for a long-term, safe, and reliable geologic CO 2 storage.

Fault permeability↗

Utah FORGE: Fault Reactivation Through Fluid Injection Induced Seismicity Laboratory Experiments

Included are results from shear reactivation experiments on laboratory faults pre-loaded close to failure and reactivated by the injection of fluid into the fault. The sample comprises a single-inclined-fracture (SIF) transecting a cylindrical sample of Westerly granite. All experiments are conducted at ambient temperature and follow a similar protocol: (i) application of confining stresses (3MPa) on the fault fully saturated with DI water, (ii) shear-mobilization through the increase of axial loading at a constant displacement rate until a post-peak steady-state condition is reached, (iii) reduction of axial loading and related shear stress to a prescribed fraction of the peak steady-state frictional strength (typically 60% to 90%, representing intermediate to high magnitudes) and (iv), fault reactivation triggered by a stepwise increase of pore pressure on the fault in 0.1 MPa increments held constant for 1-5 minutes. Mechanical data from three ISCO pumps connected to a Temco pressure vessel measure axial, confining, and fault-related parameters, including fluid pressure (kPa), fluid flow rate (mL/min), and axial displacement (mm). See included code for initial data analysis and visualization for select experiments. Resource names represent experiment numbers found in the "Read Me" file, which describes each experimental setup and parameters.

15 GEOTHERMAL ENERGY↗

Design for dependability: A simulation-based approach

This research addresses issues in simulation-based system level dependability analysis of fault-tolerant computer systems. The issues and difficulties of providing a general simulation-based approach for system level analysis are discussed and a methodology that address and tackle these issues is presented. The proposed methodology is designed to permit the study of a wide variety of architectures under various fault conditions. It permits detailed functional modeling of architectural features such as sparing policies, repair schemes, routing algorithms as well as other fault-tolerant mechanisms, and it allows the execution of actual application software. One key benefit of this approach is that the behavior of a system under faults does not have to be pre-defined as it is normally done. Instead, a system can be simulated in detail and injected with faults to determine its failure modes. The thesis describes how object-oriented design is used to incorporate this methodology into a general purpose design and fault injection package called DEPEND. A software model is presented that uses abstractions of application programs to study the behavior and effect of software on hardware faults in the early design stage when actual code is not available. Finally, an acceleration technique that combines hierarchical simulation, time acceleration algorithms and hybrid simulation to reduce simulation time is introduced.

Goswami, Kumar K.↗

Evaluation of possible reactivation of undetected faults during CO 2 injection

Geologic storage of carbon dioxide can efficiently contribute to reduce greenhouse gas emissions to the atmosphere. Two major hazards of this technology are leakage towards the ground surface and fluid-induced seismicity. While major faults may be detected and avoided during site characterization, undetected subseismic faults could be encountered once injection has started. This paper investigates leakage and reactivation of undetected faults through coupled thermal–hydraulic–mechanical modeling. The simulations are performed using a recently developed sequential simulator, TOUGH-Pylith, that allows to accurately account for the thermodynamics of brine-CO 2 injection mixtures, and to model faults as surfaces of discontinuity using state-of-the-art fault friction laws. The simulator is benchmarked against well-known analytical solutions and subsequently applied to investigate two cases of CO 2 injection injection close to undetected faults under normal and strike-slip faulting regimes. Furthermore, although the scenarios are generic and represent unfavorable conditions, they suggest that leakage could occur and that undetected faults could trigger minor seismic events. Therefore, careful site characterization and continuous monitoring during operations should be always performed.

58 GEOSCIENCES↗

Modeling supercritical CO2 injection induced rupture of a minor fault embedded in a poroelastic layered reservoir-caprock system

CO2 injection for geologic carbon sequestration involves hydromechanical processes that lead to changes in fluid pressure and stresses that can activate existing faults. This paper presents a new method and workflow of modeling fault activation considering more complex three-dimensional geometry of natural faults using the TOUGH-FLAC multiphase fluid flow and geomechanical simulator. In this method and workflow, FLAC3D mechanical interfaces and TOUGH3 finite volume elements are discretized using computer aided design and gridding software along with a tailored mesh translation routine. The method and workflow are demonstrated with a model of a curved minor fault embedded in a poro-elastic layered reservoir-caprock system. The model is used for a comprehensive sensitivity analysis of fault responses to fault length, injection mass rate, injection schedule, well-fault distance, and well locations versus fault location. Four metrics (CO2 plume, shear state of fault, pressure and stress path at fault monitoring points) are selected to assess CO2 migration, pressure change, and the reactivation of faults. The results reveal that CO2 can bypass around the tip of the minor impermeable fault, building up pressure and poro-elastic stress on both sides that tends to impede fault rupture. Our study shows the benefit of carefully designing the injection to achieve the targeted final storage volume, starting at a relatively low rate for considerable time, and then ramping up the injection rate to the full rate of injection. The initial low injection has two distinct benefits: (1) it allows for the formation of an extensive CO2 plume with a much higher mobility through a low viscosity that will result in a lower pressure for a given injection rate, and (2) it allows for gradual build-up of horizontal poro-elastic stress within the reservoir that will tend to impede activation of steeply dipping faults. The injection scenario starting at a low injection rate, denoted here as conservative injection, can significantly reduce the risk of fault activation as high fluid mobility and reservoir strengthening poro-elastic stress has been established long before reaching the peak injection rates. Moreover, simultaneous injection in two injection wells on both sides of fault can provide further reservoir strengthening through poro-elastic stress buildup acting on a fault under normal faulting stress regime. The findings presented in the paper can provide practical and effective guidance on long-term, safe, and reliable geological CO2 storage.

Cao, Meng↗

Relationships between fault characteristics and seismic responses in a large lab-scale tri-axial injection test conducted on a faulted Castlegate Sandstone

Here to investigate mechanisms causing microseismicity (M w < 2) at a CO 2 injection site, a large-scale triaxial block experiment was carried out on a faulted (saw-cut) cubic-meter of Castlegate Sandstone. The experiment consisted of injection tests at varying differential stresses, while monitoring and recording pore pressure and acoustic emissions (AEs). During the experiment, ~33,000 AEs and ~14 mm of horizontal displacement/slip, like a strike-slip fault movement, occurred. To understand the AE responses and ascertain fault characteristics near the located AEs, we modeled the topography of the fault surface, fault aperture, and fault-gouge thickness using pre- and post-experiment laser scans of the fault surface on each half of the block. Additionally, we characterized surface roughness parallel and perpendicular to slip. Models show crushing and flattening of the fault surfaces can be linked to the spatiotemporal distribution of AEs within 50 mm of the fault surface. Approximately 65% of AEs were in areas with small aperture (≤300 μm); thicker fault gouge was observed in adjacent areas with wider aperture and shows a two-fold reduction in grain size relative to unaltered Castlegate Sandstone. This work provides a conceptual understanding on fault surface evolution, which can be applied towards modeling of seismic slip.

58 GEOSCIENCES↗

Load flows and faults considering dc current injections

The authors present novel methods for incorporating current injection sources into dc power flow computations and determining network fault currents when electronic devices limit fault currents. Combinations of current and voltage sources into a single network are considered in a general formulation. An example of relay coordination is presented. The present study is pertinent to the development of the Space Station Freedom electrical generation, transmission, and distribution system.

Kusic, G. L.↗

Fluid migration in low-permeability faults driven by decoupling of fault slip and opening

Understanding the response of faults to the injection of high-pressure fluids is important for several subsurface applications, for example, geologic carbon sequestration or energy storage. Lab-based experiments suggest that fluid injection can activate fault slip and that this slip can lead to increased fluid transmission along low-permeability faults. Here we present in situ observations from a cross-borehole fluid-injection experiment in a low-permeability shale-bearing fault, which show fault displacement occurring before fluid-pressure build-up. Comparing these observations with numerical models with differing permeability evolution histories, we find that the observed variation in fluid pressure is best explained by a change in permeability only after the fault fails and slips beyond the pressurized area. Once fluid migration occurs along the fault as a result of slip-induced permeability increase, the fault experiences further opening due to a decrease in the effective normal stress. We then suggest that decoupling of fault slip and opening, leading to a rapid increase in fluid pressurization following the initial fault slip, could be an efficient driver for fluid migration in low-permeability faults.

58 GEOSCIENCES↗

Measurement and analysis of workload effects on fault latency in real-time systems

The authors demonstrate the need to address fault latency in highly reliable real-time control computer systems. It is noted that the effectiveness of all known recovery mechanisms is greatly reduced in the presence of multiple latent faults. The presence of multiple latent faults increases the possibility of multiple errors, which could result in coverage failure. The authors present experimental evidence indicating that the duration of fault latency is dependent on workload. A synthetic workload generator is used to vary the workload, and a hardware fault injector is applied to inject transient faults of varying durations. This method makes it possible to derive the distribution of fault latency duration. Experimental results obtained from the fault-tolerant multiprocessor at the NASA Airlab are presented and discussed.

Woodbury, Michael H.↗

Viscosity determinations of some frictionally generated silicate melts: Implications for slip zone rheology during impact-induced faulting

Analytical scanning electron microscopy, using combined energy dispersive and wavelength dispersive spectrometry, was used to determine the major-element compositions of some natural and artificial glasses and their crystalline equivalents derived by the frictional melting of acid to intermediate protoliths. The major-element compositions are used to calculate the viscosities of their melt precursors using the model of Shaw at temperatures of 800-1400 C, with Fe(2+)/Fe(tot) = 0.5 and for 1-3 wt percent H2O. These results are then modified to account for suspension effects in order to determine viscosities. The results have implications for the generation of pseudotachylitic breccias as seen in the basement lithologies of the Sudbury and Vredefort structures and possibly certain dimict lunar breccias. Many of these breccias show similarities with the more commonly developed pseudotachylite fault and injection veins seen in endogenic fault zones that typically occur in thicknesses of a few centimeters or less. The main difference is one of scale: Impact-induced pseudotachylite breccias can attain several meters in thickness. This would suggest that they were generated under exceptionally high slip rates and hence high strain rates and that the friction melts generated possessed extremely low viscosities.

Spray, John G.↗

Development and evaluation of a Fault-Tolerant Multiprocessor (FTMP) computer. Volume 3: FTMP test and evaluation

The experimental test and evaluation of the Fault-Tolerant Multiprocessor (FTMP) is described. Major objectives of this exercise include expanding validation envelope, building confidence in the system, revealing any weaknesses in the architectural concepts and in their execution in hardware and software, and in general, stressing the hardware and software. To this end, pin-level faults were injected into one LRU of the FTMP and the FTMP response was measured in terms of fault detection, isolation, and recovery times. A total of 21,055 stuck-at-0, stuck-at-1 and invert-signal faults were injected in the CPU, memory, bus interface circuits, Bus Guardian Units, and voters and error latches. Of these, 17,418 were detected. At least 80 percent of undetected faults are estimated to be on unused pins. The multiprocessor identified all detected faults correctly and recovered successfully in each case. Total recovery time for all faults averaged a little over one second. This can be reduced to half a second by including appropriate self-tests.

Lala, J. H.↗

Graphics enhanced computer emulation for improved timing-race and fault tolerance control system analysis

A computer simulation system has been developed for the Space Shuttle's advanced Centaur liquid fuel booster rocket, in order to conduct systems safety verification and flight operations training. This simulation utility is designed to analyze functional system behavior by integrating control avionics with mechanical and fluid elements, and is able to emulate any system operation, from simple relay logic to complex VLSI components, with wire-by-wire detail. A novel graphics data entry system offers a pseudo-wire wrap data base that can be easily updated. Visual subsystem operations can be selected and displayed in color on a six-monitor graphics processor. System timing and fault verification analyses are conducted by injecting component fault modes and min/max timing delays, and then observing system operation through a red line monitor.

Szatkowski, G. P.↗

Development and validation of techniques for improving software dependability

A collection of document abstracts are presented on the topic of improving software dependability through NASA grant NAG-1-1123. Specific topics include: modeling of error detection; software inspection; test cases; Magnetic Stereotaxis System safety specifications and fault trees; and injection of synthetic faults into software.

Knight, John C.↗

Field-scale fault reactivation experiments by fluid injection highlight aseismic leakage in caprock analogs: Implications for CO 2 sequestration

Observations on tens-of-meter scale experiments of fault activation by fluid injection conducted in shales allow exploring how aseismic and seismic events may jeopardize the integrity of a sealing caprock overlying a CO 2 sequestration reservoir. We contrast the behavior of shale faults with another set of experiments conducted in carbonates. Significant fluid leakage occurs along the initially low-permeability shale faults when rupture is activated. Most of the leakage pathway closes when fluid injection ceases and fluid pressure drops. Dilatant slip on the fault plane alone does not explain the observed leakage behavior, which is also caused by fault opening favored by the softness of the shale, and by the structure of the fault zone that prevents fluids from diffusing into the adjacent damage zone. Experiments show a large amount of aseismic deformation. Small-magnitude seismicity (M w < -2.5) is observed outside the pressurized leakage patch. Stress transferred from this aseismic deformation patch can build up to stress-criticality and favor seismicity. Thus, in terms of fault activation in caprocks, aseismic fault slip leading to increased permeability and a loss of seal integrity is of great concern.

58 GEOSCIENCES↗

Injecting Artificial Memory Errors Into a Running Computer Program

Single-event upsets (SEUs) or bitflips are computer memory errors caused by radiation. BITFLIPS (Basic Instrumentation Tool for Fault Localized Injection of Probabilistic SEUs) is a computer program that deliberately injects SEUs into another computer program, while the latter is running, for the purpose of evaluating the fault tolerance of that program. BITFLIPS was written as a plug-in extension of the open-source Valgrind debugging and profiling software. BITFLIPS can inject SEUs into any program that can be run on the Linux operating system, without needing to modify the program s source code. Further, if access to the original program source code is available, BITFLIPS offers fine-grained control over exactly when and which areas of memory (as specified via program variables) will be subjected to SEUs. The rate of injection of SEUs is controlled by specifying either a fault probability or a fault rate based on memory size and radiation exposure time, in units of SEUs per byte per second. BITFLIPS can also log each SEU that it injects and, if program source code is available, report the magnitude of effect of the SEU on a floating-point value or other program variable.

Bornstein, Benjamin J.↗