Engineering PapersSearch

SEARCH · Engineering Papers

Results for “REDUNDANCY”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Visualization of redundancy resolution for kinematically redundant robots through the Jacobian null space

We present a unified formulation for the inverse kinematics of redundant arms, based on a special formulation of the null space of the Jacobian. By extending (appropriately re-scaling) previously used null space parameterizations, we obtain, in a unified fashion, the manipulability measure, the null space projector, and particular solutions for the joint velocities. We obtain the minimum norm pseudo-inverse solution as a projection from any particular solution, and the method provides an intuitive visualization of the self-motion. The result is a computationally efficient, consistent approach to computing redundant robot inverse kinematics.

Chen, Yu-Che

Localized Triple Modular Redundancy vs. Distributed Triple Modular Redundancy on a ProASIC3E Reprogrammable FPGA

Field programmable gate arrays (FPGA) are used in every space application. Currently, most space flight applications use radiation hardened (RH) FPGAs, which are very expensive. There is a desire to use cheaper, commercial off the shelf reprogrammable FPGAs, which are more susceptible to radiation effects known as single-event effects (SEE). The RH parts have SEE and total ionizing dose (TID) hardened elements pre-integrated into the part. This means that the designer does not need to implement any hardening techniques while configuring the device. The COTS parts on the other hand must be mitigated by design in order to insure any form of mitigation. The design techniques this project examines concern the use of localized triple modular redundancy (LTMR) and distributed triple modular redundancy (DTMR). LTMR triples every flip flop in the device architecture while DTMR triples everything except for the global routes (clocks, resets, and enables). The testing was performed on a ProASIC3E FPGA at the Texas A&M cyclotron facility. Two design architectures were used: shift registers and counters, both with LTMR and DTMR mitigation techniques. The test results prove that DTMR is more effective at reducing SEE than LTMR. We also determined that there was not a significant difference between the use of shift registers and counters for test purposes. More testing is required to obtain additional linear energy transfer values for each architecture and mitigation technique in order to determine the most cost-effective method of SEE mitigation.

McGuffey, Alex

Space Shuttle Avionics: a Redundant IMU On-Board Checkout and Redundancy Management System

A failure detection and isolation philosophy applicable to multiple off-the-shelf gimbaled IMUs are discussed. The equations developed are implemented and evaluated with actual shuttle trajectory simulations. The results of these simulations are presented for both powered and unpowered flight phases and at operational levels of four, three, and two IMUs. A multiple system checkout philosophy is developed and simulation results presented. The final task develops a laboratory test plan and defines the hardware and software requirements to implement an actual multiple system and evaluate the interim study results for space shuttle application.

Mckern, R. A.

A unified motion planning approach for redundant and non-redundant manipulators with actuator constraints

The term trajectory planning has been used to refer to the process of determining the time history of joint trajectory of each joint variable corresponding to a specified trajectory of the end effector. The trajectory planning problem was solved as a purely kinematic problem. The drawback is that there is no guarantee that the actuators can deliver the effort necessary to track the planned trajectory. To overcome this limitation, a motion planning approach which addresses the kinematics, dynamics, and feedback control of a manipulator in a unified framework was developed. Actuator constraints are taken into account explicitly and a priori in the synthesis of the feedback control law. Therefore the result of applying the motion planning approach described is not only the determination of the entire set of joint trajectories but also a complete specification of the feedback control strategy which would yield these joint trajectories without violating actuator constraints. The effectiveness of the unified motion planning approach is demonstrated on two problems which are of practical interest in manipulator robotics.

Chung, Ching-Luan

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures

Past and Present Biophysical Redundancy of Countries as a Buffer to Changes in Food Supply

Spatially diverse trends in population growth, climate change, industrialization, urbanization and economic development are expected to change future food supply and demand. These changes may affect the suitability of land for food production, implying elevated risks especially for resource constrained, food-importing countries. We present the evolution of biophysical redundancy for agricultural production at country level, from 1992 to 2012. Biophysical redundancy, defined as unused biotic and abiotic environmental resources, is represented by the potential food production of 'spare land', available water resources (i.e., not already used for human activities), as well as production increases through yield gap closure on cultivated areas and potential agricultural areas. In 2012, the biophysical redundancy of 75 (48) countries, mainly in North Africa, Western Europe, the Middle East and Asia, was insufficient to produce the caloric nutritional needs for at least 50% (25%) of their population during a year. Biophysical redundancy has decreased in the last two decades in 102 out of 155 countries, 11 of these went from high to limited redundancy, and nine of these from limited to very low redundancy. Although the variability of the drivers of change across different countries is high, improvements in yield and population growth have a clear impact on the decreases of redundancy towards the very low redundancy category. We took a more detailed look at countries classified as 'Low Income Economies (LIEs)' since they are particularly vulnerable to domestic or external food supply changes, due to their limited capacity to offset for food supply decreases with higher purchasing power on the international market. Currently, nine LIEs have limited or very low biophysical redundancy. Many of these showed a decrease in redundancy over the last two decades, which is not always linked with improvements in per capita food availability.

biophysics

Redundancy: How Many Unreliable Spares are Needed for High Reliability and Confidence?

This paper investigates the number of redundant units needed to achieve high reliability with high confidence. The approach is developed for the case when the system failure rate is too high for a single unit to provide the required reliability over the mission duration. To achieve high reliability, N redundant units can be used, one operating unit and N – 1 spares. If the unit failure rate is f, the mission length is L, and f * L is small (not the case assumed here), the unit failure probability over the mission duration is F1 = f * L << 1. In this case, the probability that all N units will fail is Ffail = F1 N , and the needed redundancy N = LN(F)/LN(F1). For the case of large f * L assumed here, F1 = f * L > 1, and F1 is the expected number of failures during the mission. (When F1 = f * L << 1, F1 is the probability that a unit will fail during the mission. When F1 = f * L > 1, F1 is the expected number of failures during the mission.) The needed redundancy, N, to achieve the required N redundant unit reliability, FN, can be computed using the cumulative Poisson distribution with mean equal to F1. The number of spares, N - 1, is increased until the probability - that the total number of failures will be less than N -1 - is equal to the required reliability. The confidence that this reliability can be achieved can be computed using the cumulative Poisson distribution or the chi-square distribution. Since the measured unit failure rate, f, has some probabilistic uncertainty, the actual failure rate will be randomly higher or lower. This means that the reliability of the N redundant systems will be overestimated about half the time. Adding more redundant units increases the confidence that the required reliability will be achieved. For a fixed number of redundant units, the expected reliability and confidence can be traded off, since lower reliability goals will be achieved with higher confidence. Both the desired reliability and confidence can be specified as initial requirements and the needed number of redundant units estimated using the measured failure rate.

Redundancy

Tutorial: Performance and reliability in redundant disk arrays

A disk array is a collection of physically small magnetic disks that is packaged as a single unit but operates in parallel. Disk arrays capitalize on the availability of small-diameter disks from a price-competitive market to provide the cost, volume, and capacity of current disk systems but many times their performance. Unfortunately, relative to current disk systems, the larger number of components in disk arrays leads to higher rates of failure. To tolerate failures, redundant disk arrays devote a fraction of their capacity to an encoding of their information. This redundant information enables the contents of a failed disk to be recovered from the contents of non-failed disks. The simplest and least expensive encoding for this redundancy, known as N+1 parity is highlighted. In addition to compensating for the higher failure rates of disk arrays, redundancy allows highly reliable secondary storage systems to be built much more cost-effectively than is now achieved in conventional duplicated disks. Disk arrays that combine redundancy with the parallelism of many small-diameter disks are often called Redundant Arrays of Inexpensive Disks (RAID). This combination promises improvements to both the performance and the reliability of secondary storage. For example, IBM's premier disk product, the IBM 3390, is compared to a redundant disk array constructed of 84 IBM 0661 3 1/2-inch disks. The redundant disk array has comparable or superior values for each of the metrics given and appears likely to cost less. In the first section of this tutorial, I explain how disk arrays exploit the emergence of high performance, small magnetic disks to provide cost-effective disk parallelism that combats the access and transfer gap problems. The flexibility of disk-array configurations benefits manufacturer and consumer alike. In contrast, I describe in this tutorial's second half how parallelism, achieved through increasing numbers of components, causes overall failure rates to rise. Redundant disk arrays overcome this threat to data reliability by ensuring that data remains available during and after component failures.

Gibson, Garth A.

Analytical Redundancy Using Kalman Filters for Rocket Engine Sensor Validation

The use of sensor redundancy is crucial in aerospace systems to maintain safe, reliable operation. While hardware redundancy is more common in application, analytical redundancy can provide a viable alternative in systems where the installation of multiple redundant sensors is not viable. To this end, the use of Kalman filters to analytically validate sensor measurements within rocket engines was explored. First, a dynamic model of the RS 25 engine, a derivative of the Space Shuttle Main Engine (SSME), was reduced to a subset of relations, focused around the main combustion chamber pressure. These relations were used within the Kalman filter algorithm to generate an estimate of sensor measurements to be compared with true measurements for data validation purposes. By using a bank of Kalman filters, the residuals between the estimated and true measurements were used to detect and isolate sensor faults. Through fault simulations, the sensor validation performance of this Kalman filter bank design was compared to a hardware redundancy check. Sensor bias and drift faults of various magnitudes were injected into nominal RS 25 engine test data. Results for both approaches show comparable fault detection with most bias faults found nearly instantaneously by both algorithms. Drift fault detection results show certain cases where one algorithm is faster than the other. The key advantage of the Kalman filter algorithm is shown in fault isolation performance where it can isolate faults between two redundant sensors while the hardware redundancy comparisons cannot.

sensors

Application of redundancy in the Saturn 5 guidance and control system

The Saturn launch vehicle's guidance and control system is so complex that the reliability of a simplex system is not adequate to fulfill mission requirements. Thus, to achieve the desired reliability, redundancy encompassing a wide range of types and levels was employed. At one extreme, the lowest level, basic components (resistors, capacitors, relays, etc.) are employed in series, parallel, or quadruplex arrangements to insure continued system operation in the presence of possible failure conditions. At the other extreme, the highest level, complete subsystem duplication is provided so that a backup subsystem can be employed in case the primary system malfunctions. In between these two extremes, many other redundancy schemes and techniques are employed at various levels. Basic redundancy concepts are covered to gain insight into the advantages obtained with various techniques. Points and methods of application of these techniques are included. The theoretical gain in reliability resulting from redundancy is assessed and compared to a simplex system. Problems and limitations encountered in the practical application of redundancy are discussed as well as techniques verifying proper operation of the redundant channels. As background for the redundancy application discussion, a basic description of the guidance and control system is included.

Moore, F. B.

Cartesian control of redundant robots

A Cartesian-space position/force controller is presented for redundant robots. The proposed control structure partitions the control problem into a nonredundant position/force trajectory tracking problem and a redundant mapping problem between Cartesian control input F is a set member of the set R(sup m) and robot actuator torque T is a set member of the set R(sup n) (for redundant robots, m is less than n). The underdetermined nature of the F yields T map is exploited so that the robot redundancy is utilized to improve the dynamic response of the robot. This dynamically optimal F yields T map is implemented locally (in time) so that it is computationally efficient for on-line control; however, it is shown that the map possesses globally optimal characteristics. Additionally, it is demonstrated that the dynamically optimal F yields T map can be modified so that the robot redundancy is used to simultaneously improve the dynamic response and realize any specified kinematic performance objective (e.g., manipulability maximization or obstacle avoidance). Computer simulation results are given for a four degree of freedom planar redundant robot under Cartesian control, and demonstrate that position/force trajectory tracking and effective redundancy utilization can be achieved simultaneously with the proposed controller.

Colbaugh, R.

Effectiveness of Redundant Communications Systems in Maintaining Operational Control of Small Unmanned Aircraft

NASA has been researching prototype technologies for an Unmanned Aircraft System (UAS) Traffic Management (UTM) system to facilitate enabling of safe and efficient civilian low-altitude airspace and UAS operations, in a series of Technical Capability Levels (TCL) activities that are increasingly complex. In TCL1, completed in 2015, visual line-of-sight operations such as agriculture, firefighting and infrastructure monitoring were addressed with a focus on geofencing and operations scheduling. Technologies and requirements needed for beyond visual line-of-sight (BVLOS) operations in sparsely populated areas were examined in TCL2 in 2016, and those for operations over moderately populated areas in TCL3 in 2017 and 2018. TCL4 will build on the earlier TCLs and focus on technologies and requirements for operations in higher-density urban areas for tasks such as news gathering, package delivery and for managing large-scale contingencies. This paper describes a communications test conducted in TCL3 and discusses insights gained from the test. In the test, operators were directed to equip UAS with redundant Command and Control (C2) communications systems, send a maneuver command to Unmanned Aircraft (UA) via the primary system, then verify execution of the sent command. This exercise was repeated with each redundant system. The test was designed to assess effectiveness of redundant C2 systems in maintaining operational control of UA. Several UAS were configured with varying arrangements to achieve redundancy, including two identical radio modems using the same frequency band, WiFi and Long-Term Evolution (LTE) cellular modems, etc. From the test, digital data such as time maneuver command sent, time maneuver verified, etc., were collected. Descriptions of methods to detect loss of C2 communications and contingency steps for such event were collected and assessed. The final paper will include a detailed analysis of the collected data leading to the following insights. First, effectiveness of redundant C2 systems depends on several factors, such as operational environment and communications service availability. For example, use of two identical point-to-point radio to connect operator and UA on the same frequency band can be effective in mitigating radio malfunction when operating in an environment where possibility of Radio Frequency (RF) interference is low, such as over open plains. However, the same arrangement may not be effective where high level of RF transmissions in broad spectrum ranges can be expected, such as over or near urban areas. For redundant systems that consist of external communications services, such as cellular and satellite communications network, redundancy is maintained only in the areas where more than one services are available. Therefore, UAS operators should have the means to plan for and monitor the performance of external communications services they are relying on to control UA. Second, communications performance needs, such as the minimum data transfer rate and the maximum tolerable latency, should be assessed to reflect the potential hazard that can come from loss of UA control. For example, UA operations over desolate area pose less hazard to people than operations over densely populated area and performance need for the former would be less than the latter.

Jung, Jaewoo

Redundancy: How Many Unreliable Spares are Needed for High Reliability and Confidence on a Time Limited Mission?

This paper investigates the number of redundant units needed to achieve high reliability with high confidence. The approach applies to the case where the unit failure rate is too high for a single unit to provide the required reliability over the mission duration. To achieve high reliability, the design then uses N redundant units, one operating unit and N – 1 spares. If the unit failure rate is f, the mission length is L, and f * L is small (not the case assumed here), the unit failure probability over the mission duration is F1 = f * L << 1. In this case, the probability that all N units will fail is FN = F1N, and the needed N = LN(FN)/LN(F1). For the case of large f * L assumed here, F1 = f * L > 1, and F1 is the expected number of failures during the mission. The needed redundancy, N, to achieve the specified N unit reliability, FN, can be computed using the cumulative Poisson distribution with mean equal to F1. The number of spares, N - 1, is increased until the probability - that the total number of failures will be less than N -1 - achieves the required reliability. The confidence that this reliability can be achieved can be computed using the cumulative Poisson distribution or the chi-square distribution. Since the measured unit failure rate, f, has some uncertainty, the confidence that the rate is not lower than the actual failure rate and the required reliability is not overestimated is about 50%. Adding more redundant units increases the confidence that the required reliability, FN, will be achieved. For a fixed number of redundant units, the expected reliability and confidence can be traded off, since lower reliability goals have higher confidence in being achieved. Both the required reliability and confidence can be specified initially and the needed number of redundant units computed using the measured failure rate. The unit failure rate is determined by initial reliability growth testing to remove design errors and to better estimate the final constant failure rate. Reducing the failure rate and reducing its variance both reduce the number of redundant units needed for the required reliability and confidence. Since the total cost is the sum of the costs of the units and of the testing, there is an optimum test time that produces minimum cost.

Harry W. Jones