Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Common Cause Failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Resilience Design Patterns: A Structured Approach to Resilience at Extreme Scale (V.2.0)

Reliability is a serious concern for future extreme-scale high-performance computing (HPC) systems. Projections based on the current generation of HPC systems and technology roadmaps suggest the prevalence of very high fault rates in future systems. The errors resulting from these faults will propagate and generate various kinds of failures, which may result in outcomes ranging from result corruptions to catastrophic application crashes. Therefore, the resilience challenge for extreme-scale HPC systems requires coordination between various hardware and software technologies that are capable of handling a broad set of fault models at accelerated fault rates. Also, due to practical limits on power consumption in future HPC systems, they are likely to embrace innovative architectures, increasing the levels of hardware and software complexities. Therefore, the techniques that seek to improve resilience must navigate the complex trade-off space between resilience and the overheads to power consumption and performance. While the HPC community has developed various resilience solutions, application-level techniques as well as system-based solutions, the solution space of HPC resilience techniques remains fragmented. There are no formal methods to integrate the various HPC resilience techniques into composite solutions, nor are there methods to holistically evaluate the adequacy and efficacy of such solutions in terms of their protection coverage, and their performance & power efficiency characteristics. Additionally, few implementations of current resilience solutions are portable to newer architectures and software environments that will be deployed on future systems. We developed a new structured approach to the management of HPC resilience using the concept of resilience-based design patterns. In general, a design pattern is a repeatable solution to a commonly occurring problem. We identified the well-known solutions that are commonly used to deal with faults, errors and failures in HPC systems. In the initial design patterns specification (version 1.0), we described the various solutions, which address specific problems in the design of resilient HPC environments, in the form of patterns. Each pattern describes a problem caused by a fault, error or failure event in an HPC environment, and then describes the core of the solution of the problem in such a way that this solution may be adapted to different systems and implemented at different layers of the system stack. The catalog of these resilience design patterns provides designers with a collection of design elements. To construct complete resilience solutions using combinations of various patterns, we defined a framework that enhances HPC designers' understanding of the important constraints and the opportunities for the design patterns to be implemented and deployed at various layers of the system stack. The design framework is also useful for establishing interfaces and mechanisms to coordinate flexible fault management across hardware and software components, as well as to consider the trade-off between performance, resilience, and power consumption when constructing a solution. The resilience design patterns specification version 1.1 included more detailed explanations of the pattern solutions, the context in which the patterns are applicable, and the implications for hardware or software design. It also provided several additional examples and detailed case studies to demonstrate the use of patterns to build realistic solutions. In version 1.2 of the specification document, we have improved the pattern descriptions, including graphical representations of the pattern components. These improvements are largely based on critical comments, feedback and suggestions received from pattern experts and readers of the previous versions of the specification. The pattern classification has been modified to further clarify the relationships between pattern categories. This version of the specification also introduces a pattern language for resilience design patterns. The pattern language presents the patterns in the catalog as a network, revealing the relations among the resilience patterns. The language provides designers with the means to explore alternative techniques for handling a specific fault model that may have different efficiency and complexity characteristics. Using the pattern language also enables the design and implementation of comprehensive resilience solutions as a set of interconnected resilience patterns that can be instantiated across layers of the system stack. The overall goal of this work is to provide hardware and software designers, as well as the users and operators of HPC systems, a systematic methodology for the design and evaluation of resilience technologies in HPC systems that keep scientific applications running to a correct solution in a timely and cost-efficient manner despite frequent faults, errors, and failures of various types. Version 2.0 expands the resilience design pattern classification and catalog to include self-stabilization patterns and reliability, availability and performance models for each structural pattern.

97 MATHEMATICS AND COMPUTING↗

Recovering from On-orbit Anomalies on the Astrobee Free Flyers and its Systems

Since 2019, NASA has been operating three Astrobee free flying robots on board the International Space Station (ISS) providing an autonomous and flexible research platform for national and international payload developers in microgravity and serving as a robotic assistant for astronauts on the ISS. During its use on the ISS, in particular with over 750 hours of free-flyer operation as of March 2022, Astrobee and its Docking Station have encountered multiple software and hardware anomalies. These anomalies were either resolved remotely via software and firmware updates, or, where not possible, with hardware replacements on orbit or by the return of the faulty unit to NASA’s ground facilities for its repair. Despite being inherently designed to be repaired or replaced on orbit, Astrobee and its systems can still suffer anomalies that would be complex enough to disassemble, cause risks of hardware damage, or use excessive crew time to perform the repair in orbit. That was the case for the anomaly the Astrobee unit ‘Honey’ encountered, reason why it needed to be down-massed for repair. One of the most common points of failure was found to be the SD card, which is used for the different Astrobee processors and for the Dock Station. Other comparable SD card anomalies were found also on the Astrobee ground units, which provided useful data in the effort of upgrading their systems. This presentation will focus on 1) The overview of the different faults and anomalies on Astrobee and its systems on orbit and on the ground 2) The processes and procedures implemented to resolve the anomalies 3) The implementation of software updates and hardware upgrades in order to reduce the risk on returning anomalies 4) The lessons learned in increasing Astrobee’s robustness and resilience to such anomalies.

International Space Station↗

AGR-5/6/7 Final Release-to-Birth Ratio Data Analysis

AGR-5/6/7 is the last of a series of Advanced Gas Reactor (AGR) experiments conducted in the Advanced Test Reactor (ATR) at Idaho National Laboratory (INL) in support of development and qualification of tristructural isotropic (TRISO) low-enriched fuel for use in the high-temperature gas cooled reactor (HTGR). AGR configuration and irradiation conditions are based on prismatic HTGR technology that is distinguished primarily through the use of helium coolant, a low-power-density ceramic core capable of withstanding very high temperatures, and TRISO-coated particle fuel. The AGR tests provide valuable irradiation-performance data to support fuel process development, qualify fuel for normal operation and accident conditions, and support development and validation of fuel performance and fission-product (FP) transport models and codes. Each AGR test consists of multiple independently controlled and monitored capsules containing fuel compacts placed in a graphite cylinder shrouded by a steel shell. Release-to-birth ratios (R/B) for fission-gas isotopes released from each capsule are calculated from release rates, measured by germanium detectors in the Fission Product Monitoring System (FPMS) installed downstream from each capsule, and birth rates calculated using numerical models of FG generation. The R/Bs are a critical measure of the ability of the fuel kernel, the particle coating layers, and the compact matrix to retain fission-gas atoms, preventing their release into the sweep-gas flow, and the impact of initially defective particles and/or particle-coating failures that occur during irradiation. For fission-gas isotopes, particle failure is defined as failure of all coating layers, allowing gaseous fission atoms to escape from a particle. During the first five cycles (162B ? 165A), R/Bs were stable in the 10-8?10-6 range, and no in-pile particle failures were observed, based on the gross gamma counts. The maximum R/B value of around 2 ? 10-6 for Kr-85m resulted from the presence of as-fabricated exposed kernels (based on the high exposed kernel fraction), the dispersed uranium, and high fuel particle temperatures in Capsule 1. Comparison of capsule-measured R/Bs from these early cycles to predictions using the previously developed AGR R/B model demonstrated FG release from the AGR-5/6/7 TRISO fuel was comparable to that of previous experiments. In addition, the Kr-85m R/B per-exposed-kernel values are comparable to R/B values obtained in AGR-3/4 irradiation experiment and four irradiation experiments performed during 1980s: (1) HRB-17/18, (2) COMEDIE-BD1, (3) HFR B1, and (4) HRB-21. In contrast, all measured R/B values are lower than predictions by the commonly used Richards and German models, which are intentionally conservative. A large number of in-pile particle failures occurred in Capsule 1 by the end of Cycle 166A. During the final four cycles (166A ? 168A), apparent damage to the Capsule 1 gas line appeared to cause FG leakage from that capsule into the other four capsules, resulting in an increase in fission gas (FG) detected in the effluent for all capsules. Isolation of the Capsule 1 gas line during the last three cycles also prevented measurement of its FG release. Thus, R/Bs in all capsules after Cycle 166A are highly uncertain because of undefined amount of leakage from Capsule 1, especially for long-lived isotopes. A few hundred in-pile particle failures were estimated for Capsule 1 before the end of Cycle 166A, but the total number of failures is unknown due to the lack of FG release data in the later cycles. Based primarily on evidence from the gross gamma counts during Cycle 168A, approximately 15 particles failed in Capsule 3 and four particles failed in Capsule 2. In-pile failures in Capsule 3 were anticipated because this capsule was designed to operate beyond the HTGR normal operating temperature range. In contrast, no in-pile failures were identified in the top two capsules (4 and 5) based on the absence of the typical spikes in gross gamma counts and low failure estimates using the AGR model, developed in INL/EXT-14-32970, for R/B of the short-lived isotopes (Kr-89 and Xe-137) with minimal leakage from Capsule 1.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Development of direct ink write radially graded alumina/zirconia

Functionally graded materials (FGMs) are of interest in multiple fields, yet many materials combinations are limited by coefficient of thermal expansion (CTE) mismatch. Here, a radially graded alumina/yttria-doped zirconia (Al 2 O 3 /8YZ) FGM is used to demonstrate processing strategies to mitigate CTE and sintering behavior differences between these oxides. FGM materials are especially sensitive to ink stability during printing, as all components (in this case, Al 2 O 3 and 8YZ) must be stabilized in the same dispersant or additive solution. Thus, this system is also ideal to demonstrate ink optimization best practices. Materials were characterized throughout processing to correlate the effects of common additives on both the ceramic particle suspensions and final sintered components. Aggregation observed in the initial additive-containing suspensions were present in the sintered component. The differences in sintering onset temperature and shrinkage rate resulted in internal stresses within the sintered component, which ultimately caused mechanical failure of the component under low stress. In conclusion, a processing strategy was recommended to mitigate the sintering behavior mismatch of alumina and 8 wt% yttria-stabilized zirconia.

Lamm, Benjamin W. [Oak Ridge National Laboratory (↗

Faulty behavior of asynchronous storage elements

It is often assumed that the faults in storage elements (SE's) can be modeled as output/input stuck-at-faults of the element. They are implicitly considered equivalent to the stuck-at faults in the combinational logic surrounding the SE cells. A more accurate higher level fault model for elementary SE's used in asynchronous circuits is presented. This model offers better representation of the physical failures. It is shown that the stuck-at model may be adequate if only modest fault coverage is desired. The enhanced model includes some common fault behaviors of SE's that are not covered by the stuck-at model. These include data-feed-through behaviors that cause the SE to be combinational. Fault models for complex SE cells can be obtained without a significant loss of information about the structure of the circuit.

Al-Assadi, Waleed K.↗

Comparing the Identification of Recommendations by Different Accident Investigators Using a Common Methodology

Accident reports play a key role in the safety of complex systems. These reports present the recommendations that are intended to help avoid any recurrence of past failures. However, the value of these findings depends upon the causal analysis that helps to identify the reasons why an accident occurred. Various techniques have been developed to help investigators distinguish root causes from contributory factors and contextual information. This paper presents the results from a study into the individual differences that can arise when a group of investigators independently apply the same technique to identify the causes of an accident. This work is important if we are to increase the consistency and coherence of investigations following major accidents.

Johnson, Chris W.↗

Can Applications Recover from fsync Failures?

We analyze how file systems and modern data-intensive applications react to fsync failures. First, we characterize how three Linux file systems (ext4, XFS, Btrfs) behave in the presence of failures. We find commonalities across file systems (pages are always marked clean, certain block writes always lead to unavailability) as well as differences (page content and failure reporting is varied). Next, we study how five widely used applications (PostgreSQL, LMDB, LevelDB, SQLite, Redis) handle fsync failures. Our findings show that although applications use many failure-handling strategies, none are sufficient: fsync failures can cause catastrophic outcomes such as data loss and corruption. Our findings have strong implications for the design of file systems and applications that intend to provide strong durability guarantees.

Computer Science↗

Advanced Reactor Cyber Analysis and Development Environment (ARCADE) for System-Level Design Analysis

Cybersecurity is a persistent concern to the safety and security of Nuclear Power Plants (NPPs), but has lacked data-driven, evidence-based research. Rigorous cybersecurity analysis is critical for the licensing of advanced reactors using a performance-based approach. One tool that enables cybersecurity analysis is modeling and simulation. The nuclear industry makes extensive use of modeling and simulation throughout the decision process but lacks a method to incorporate cybersecurity analysis with existing models. To meet this need, the Advanced Reactor Cyber Analysis and Development Environment (ARCADE) was developed. ARCADE is a suite of publicly available tools that can be used to develop emulations of industrial control system devices and networks and integrate those emulations with physics simulators. This integration of cyber emulations and physics models enables rigorous cyber-physical analysis of cyber-attacks on NPP systems. This report provides an overview of key considerations for using ARCADE with existing physics models and demonstrates ARCADE’s capabilities for cybersecurity analysis. Using a model of the Small Modular Advanced High Temperature Reactor (SmAHTR), ARCADE was able to determine the sensitivity of the primary heat exchangers (PHX) to coordinated cyber-attacks. The analysis determined that while the PHX’s failures cause disruption to the reactor, they did not cause any safety limits to be exceeded because of the plant design, including passive safety features. Further development of ARCADE will enable rigorous, repeatable, and automated cyber-physical analysis of advanced reactor control systems. These efforts will also help reduce regulatory uncertainty by presenting similar types of cybersecurity analyses in a common format, driving standard approaches and reporting.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Mechanisms of Waterflood Inefficiency: Analysis of Geological, Petrophysical and Reservoir History, a Field Case Study of FWU (East Section)

The petroleum reservoir represents a complex heterogeneous system that requires thorough characterization prior to the implementation of any incremental recovery technique. One of the most commonly utilized and successful secondary recovery techniques is waterflooding. However, a lack of sufficient investigation into the inherent behavior and characteristics of the reservoir formation in situ can result in failure or suboptimal performance of waterflood operations. Therefore, a comprehensive understanding of the geological history, static and dynamic reservoir characteristics, and petrophysical data is essential for analyzing the mechanisms and causes of waterflood inefficiency and failure. In this study, waterflood inefficiency was observed in the Morrow B reservoir located in the Farnsworth Unit, situated in the northwestern shelf of the Anadarko Basin, Texas. To assess the potential mechanisms behind the inefficiency of waterflooding in the east half, geological, petrophysical, and reservoir engineering data, along with historical information, were integrated, reviewed, and analyzed. The integration and analysis of these datasets revealed that several factors contributed to the waterflood inefficiency. Firstly, the presence of abundant dispersed authigenic clays within the reservoir, worsened by low reservoir quality and high heterogeneity, led to unfavorable conditions for waterflood operations. The use of freshwater for flooding exacerbated the adverse effects of sensitive and migratory clays, further hampering the effectiveness of the waterflood. In addition to these factors, several reservoir engineering issues played a significant role in the inefficiency of waterflooding. These issues included inadequate perforation strategies due to the absence of detailed hydraulic flow units (HFUs) and rock typing, random placement of injectors, and uncontrolled injected fresh water. These external controlling parameters further contributed to the overall inefficiencies observed during waterflood operations in the east half of the reservoir. A detailed understanding of the mechanistic factors of inefficient waterflood operation will provide adequate insights into the development of the improved recovery technique for the field.

Morgan, Anthony (ORCID:0000000211519153)↗

Orbital Anomalies in Goddard Spacecraft for Calendar Year 1994

This report summarizes and updates the annual on-orbit performance between January I and December 31, 1994, for spacecraft built by or managed by the Goddard Space Flight Center (GSFC). During 1994, GSFC had 27 active orbiting satellites and I Shuttle-launched and retrieved 'free flyer.' There were 310 reported anomalies among 21 satellites and one GSFC instrument (TOMS). GOES-8 accounted for 66 anomalies, and SAMPES reported 155 'anomalies'. Of the 155 anomalies reported for all but SAMPEX, only 4 affected the spacecraft missions 'substantially' or greater, that is, presented a loss of more than 33% of the total missions. The most frequent subsystem anomalies were Instrument/Payload(44), Timing Command and Control(40), and Attitude Control Systems(33). Of the non-SAMPEX anomalies, 29% had no effect on the missions and 28% caused subsystem or instrument degradation and, for another 28%, no anomaly effect on the mission could be determined. Fifty-three percent of non-SAMPEX anomalies could not be classified according to 'type'; the other most common types were 'systemic'(35), 'random'(19), and 'normal or expected operation'(15). Forty percent of the anomalies were not classified according to failure category; the remaining most frequent occurrences were 'design problems'(50) and 'other known problems'(35).

Thomas, Walter B.↗

Timing issues in the distributed execution of Ada programs

This paper examines, in the context of distributed execution, the meaning of Ada constructs involving time. In the process, unresolved questions of interpretation and problems with the implementation of a consistent notion of time across a network are uncovered. It is observed that there are two Ada mechanisms that can involve a distributed sense of time: the conditional entry call, and the timed entry call. It is shown that a recent interpretation by the Language Maintenance Committee resolves the questions for the conditional entry calls but results in an anomaly for timed entry calls. A detailed discussion of alternative implementations for the timed entry call is made, and it is aruged that: (1) timed entry calls imply a common sense of time between the machines holding the calling and called tasks; and (2) the measurement of time for the expiration of the delay and the decision of whether or not to perform the rendezvous should be made on the machine holding the called task. The need to distinguish the unreadiness of the called task from timeouts caused by network failure is pointed out. Finally, techniques for realizing a single sense of time across the distributed system (at least to within an acceptable degree of uncertainty) are also discussed.

Volz, Richard A.↗

Analysis of SSEM Sensor Data Using BEAM

A report describes analysis of space shuttle main engine (SSME) sensor data using Beacon-based Exception Analysis for Multimissions (BEAM) [NASA Tech Briefs articles, the two most relevant being Beacon-Based Exception Analysis for Multimissions (NPO- 20827), Vol. 26, No.9 (September 2002), page 32 and Integrated Formulation of Beacon-Based Exception Analysis for Multimissions (NPO- 21126), Vol. 27, No. 3 (March 2003), page 74] for automated detection of anomalies. A specific implementation of BEAM, using the Dynamical Invariant Anomaly Detector (DIAD), is used to find anomalies commonly encountered during SSME ground test firings. The DIAD detects anomalies by computing coefficients of an autoregressive model and comparing them to expected values extracted from previous training data. The DIAD was trained using nominal SSME test-firing data. DIAD detected all the major anomalies including blade failures, frozen sense lines, and deactivated sensors. The DIAD was particularly sensitive to anomalies caused by faulty sensors and unexpected transients. The system offers a way to reduce SSME analysis time and cost by automatically indicating specific time periods, signals, and features contributing to each anomaly. The software described here executes on a standard workstation and delivers analyses in seconds, a computing time comparable to or faster than the test duration itself, offering potential for real-time analysis.

Zak, Michail↗

Report of the Odyssey FPGA Independent Assessment Team

An independent assessment team (IAT) was formed and met on April 2, 2001, at Lockheed Martin in Denver, Colorado, to aid in understanding a technical issue for the Mars Odyssey spacecraft scheduled for launch on April 7, 2001. An RP1280A field-programmable gate array (FPGA) from a lot of parts common to the SIRTF, Odyssey, and Genesis missions had failed on a SIRTF printed circuit board. A second FPGA from an earlier Odyssey circuit board was also known to have failed and was also included in the analysis by the IAT. Observations indicated an abnormally high failure rate for flight RP1280A devices (the first flight lot produced using this flow) at Lockheed Martin and the causes of these failures were not determined. Standard failure analysis techniques were applied to these parts, however, additional diagnostic techniques unique for devices of this class were not used, and the parts were prematurely submitted to a destructive physical analysis, making a determination of the root cause of failure difficult. Any of several potential failure scenarios may have caused these failures, including electrostatic discharge, electrical overstress, manufacturing defects, board design errors, board manufacturing errors, FPGA design errors, or programmer errors. Several of these mechanisms would have relatively benign consequences for disposition of the parts currently installed on boards in the Odyssey spacecraft if established as the root cause of failure. However, other potential failure mechanisms could have more dire consequences. As there is no simple way to determine the likely failure mechanisms with reasonable confidence before Odyssey launch, it is not possible for the IAT to recommend a disposition for the other parts on boards in the Odyssey spacecraft based on sound engineering principles.

Mayer, Donald C.↗

Influence of Design Variations on Systems Performance

High-risk aerospace components have to meet very stringent quality, performance, and safety requirements. Any source of variation is a concern, as it may result in scrap or rework. poor performance, and potentially unsafe flying conditions. The sources of variation during product development, including design, manufacturing, and assembly, and during operation are shown. Sources of static and dynamic variation during development need to be detected accurately in order to prevent failure when the components are placed in operation. The Systems' Health and Safety (SHAS) research at the NASA Ames Research Center addresses the problem of detecting and evaluating the statistical variation in helicopter transmissions. In this work, we focus on the variations caused by design, manufacturing, and assembly of these components, prior to being placed in operation (DMV). In particular, we aim to understand and represent the failure and variation information, and their correlation to performance and safety and feed this information back into the development cycle at an early stage. The feedback of such critical information will assure the development of more reliable components with less rework and scrap. Variations during design and manufacturing are a common source of concern in the development and production of such components. Accounting for these variations, especially those that have the potential to affect performance, is accomplished in a variety ways, including Taguchi methods, FMEA, quality control, statistical process control, and variation risk management. In this work, we start with the assumption that any of these variations can be represented mathematically, and accounted for by using analytical tools incorporating these mathematical representations. In this paper, we concentrate on variations that are introduced during design. Variations introduced during manufacturing are investigated in parallel work.

Tumer, Irem Y.↗

Debonding Stress Concentrations in a Pressurized Lobed Sandwich-Walled Generic Cryogenic Tank

A finite-element stress analysis has been conducted on a lobed composite sandwich tank subjected to internal pressure and cryogenic cooling. The lobed geometry consists of two obtuse circular walls joined together with a common flat wall. Under internal pressure and cryogenic cooling, this type of lobed tank wall will experience open-mode (a process in which the honeycomb is stretched in the depth direction) and shear stress concentrations at the junctures where curved wall changes into flat wall (known as a curve-flat juncture). Open-mode and shear stress concentrations occur in the honeycomb core at the curve-flat junctures and could cause debonding failure. The levels of contributions from internal pressure and temperature loading to the open-mode and shear debonding failure are compared. The lobed fuel tank with honeycomb sandwich walls has been found to be a structurally unsound geometry because of very low debonding failure strengths. The debonding failure problem could be eliminated if the honeycomb core at the curve-flat juncture is replaced with a solid core.

Ko, William L.↗

Synthesizing a New Launch Vehicle Failure Probability Based on Historical Flight Data

New launch vehicles have historically had significantly higher failure probabilities in early flights than what has been predicted using Probabilistic Risk Assessment. Work on a new methodology originally started with ARES I-X and the Common Standards Working Group (CSWG) for range safety applications. CSWG consists of the Federal Aviation Administration (FAA), Air Force, and NASA. Historical launch vehicle data was viewed as the best predictor of success/failure for launches of new vehicles. A launch vehicle database was developed that includes all launches from 1980-2017 (both US and foreign). Entries to the database include: Vehicle by model type; Launch dates; Failure description; Failure Result (Loss Of Vehicle (LOV)/Loss Of Mission (LOM); Failure cause (when available); Vehicle designs (stages/engines/etc.)

Early flight risk↗

Quantifying Trapped Powder in Electron Beam Powder Bed Fusion

Abstract Electron beam powder bed fusion (PBF-EB) shows great potential for manufacturing complex parts including those with internal cavities for heat exchanger, manifold systems, or energy absorption purposes. PBF-EB allows for the manufacture of channel geometries without the need for support structures. Due to the nature of the powder spreading process, powder feedstock is often trapped in intentionally manufactured cavities. This trapped powder can often be difficult to remove and can disturb the intended flow of fluid through the cavity or damage downstream components in its use case. These trapped powder particles present a risk of contamination and component failure if not completely evacuated. Ti6Al4V is a choice material for aerospace applications due to its high strength to weight ratio and its composition as a nonferrous metal; however, in weight sensitive applications excess entrapped powders or powders loosely attached to the surface could cause undesirable weight increases. The inherent spreading process of PBF-EB is different than laser powder bed fusion (PBF-LB) in its operational temperature, sintering. In addition, PBF-EB is less commonly studied in literature compared to its PBF-LB counterpart, and as a result the complexity of the semi-sintered powder and its spreading behavior are not well understood. Prior work has investigated the difficulty in removing trapped powder from PBF-EB, but these studies do not address how to quantify the amount of trapped powder in the cavity. Thus, an accurate method to measure the amount of trapped powder in the cavity must be investigated. In this work, Ti6Al4V coupons were manufactured with horizontal and vertical cavities of three different sizes. Archimedes testing allows for the determination of density differences caused by porosity and trapped powders by measuring mass and volumetric dispersion. Computed tomography (CT) is well suited for segmenting the internal structure and features of a part and has been studied for applications including voids, porosity, and dross. Thus, CT was explored as a method for evaluating trapped powder content in this work. The volumetric representation of the segmentation of the reconstructed CT volume can vary greatly depending on the input filter and thresholding methods. In this study, four different types of segmentation approaches were evaluated to determine the best approach for segmenting the volume as compared to an operator labeled ground truth. The percentage density results from the Archimedes testing were compared to the volumetric percent density from the computed tomography approach. Differences in packing density between two different internal channel features were investigated. Overall, this work sought to validate the use of computed tomography for the detection of trapped powders and present a framework for volumetric segmentation.

Johnstone, Brian↗

Lessons Learned Entry: Hypergolic Propellant Related Spills and Fires

The attached report is a compilation of all credible, unintentional hypergolic fluid related spills, fires, and explosions from the Apollo Program, the Space Shuttle Program, Titan Program, and a few other programs. Spill sites include the following government facilities: KSC, JSC, WSTF, VAFB, CCAFS, EAFB, Little Rock AFB, and McConnell AFB. The root causes and consequences of the incidents contained in this document vary drastically; however, certain "themes" can be deduced and utilized for future hypergolic propellant handling. Some of those common "themes" are summarized below: (1) Improper configuration control and complacency can lead to being falsely comfortable with a system (2) Communication breakdown can escalate an incident to a level where injuries occur and/or hardware is damaged (3) Improper propulsion system and ground support system designs can destine a system for failure (4) Improper training of technicians, engineers, and safety personnel can put lives in danger (5) Improper PPE, spill protection, and staging of fire extinguishing equipment can result in unnecessary injuries or hardware damage if an incident occurs (6) Improper procedural oversight, development, and adherence to the procedure can be detrimental and quickly lead to an undesirable incident (7) Improper local cleanliness or compatibility can result in fires or explosions The items listed above are only a short list of the issues that should be recognized prior to handling of hypergolic fluids or processing of vehicles containing hypergolic propellants. The summary of incidents in this report is intended to cover many more issues than those listed above that have been found during nearly the entire spectrum. of hypergolic propellant and/or vehicle processing.

Nufer, Brian↗