Engineering PapersSearch

SEARCH · Engineering Papers

Results for “TOLERANCE”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

The software-implemented fault tolerance /SIFT/ approach to fault tolerant computing

SIFT is an experimental computer designed for highly reliable flight-control service in advanced air transports. Its development was intended to integrate and demonstrate the latest techniques in fault-tolerant computing. During its development, several new problems of some generality were uncovered and solved. The technology developed for the validation of its design is seen as being perhaps as important as the design itself. The SIFT design is described, as is the way in which the design and its validation were shaped by the requirements of its intended application. Attention is also given to reliability and fault tolerance. The most significant feature of the hardware design is the absence of elements that can generate multiple faults, such as shared clocks or data buses. It is noted that the software is realized in only 800 lines of code, of which 80% are in a high-level language.

Goldberg, J.

Rapid recovery from transient faults in the fault-tolerant processor with fault-tolerant shared memory

The Draper fault-tolerant processor with fault-tolerant shared memory (FTP/FTSM), which is designed to allow application tasks to continue execution during the memory alignment process, is described. Processor performance is not affected by memory alignment. In addition, the FTP/FTSM incorporates a hardware scrubber device to perform the memory alignment quickly during unused memory access cycles. The FTP/FTSM architecture is described, followed by an estimate of the time required for channel reintegration.

Harper, Richard E.

Advanced information processing system: The Army fault tolerant architecture conceptual study. Volume 2: Army fault tolerant architecture design and analysis

Described here is the Army Fault Tolerant Architecture (AFTA) hardware architecture and components and the operating system. The architectural and operational theory of the AFTA Fault Tolerant Data Bus is discussed. The test and maintenance strategy developed for use in fielded AFTA installations is presented. An approach to be used in reducing the probability of AFTA failure due to common mode faults is described. Analytical models for AFTA performance, reliability, availability, life cycle cost, weight, power, and volume are developed. An approach is presented for using VHSIC Hardware Description Language (VHDL) to describe and design AFTA's developmental hardware. A plan is described for verifying and validating key AFTA concepts during the Dem/Val phase. Analytical models and partial mission requirements are used to generate AFTA configurations for the TF/TA/NOE and Ground Vehicle missions.

Harper, R. E.

Advanced information processing system: The Army fault tolerant architecture conceptual study. Volume 1: Army fault tolerant architecture overview

Digital computing systems needed for Army programs such as the Computer-Aided Low Altitude Helicopter Flight Program and the Armored Systems Modernization (ASM) vehicles may be characterized by high computational throughput and input/output bandwidth, hard real-time response, high reliability and availability, and maintainability, testability, and producibility requirements. In addition, such a system should be affordable to produce, procure, maintain, and upgrade. To address these needs, the Army Fault Tolerant Architecture (AFTA) is being designed and constructed under a three-year program comprised of a conceptual study, detailed design and fabrication, and demonstration and validation phases. Described here are the results of the conceptual study phase of the AFTA development. Given here is an introduction to the AFTA program, its objectives, and key elements of its technical approach. A format is designed for representing mission requirements in a manner suitable for first order AFTA sizing and analysis, followed by a discussion of the current state of mission requirements acquisition for the targeted Army missions. An overview is given of AFTA's architectural theory of operation.

Harper, R. E.

Tolerance and UQ4SIM: Nimble Uncertainty Documentation and Analysis Software

Ultimately, scientific numerical models need quantified output uncertainties so that modeling can evolve to better match reality. Documenting model input uncertainties and variabilities is a necessary first step toward that goal. Without known input parameter uncertainties, model sensitivities are all one can determine, and without code verification, output uncertainties are simply not reliable. The basic premise of uncertainty markup is to craft a tolerance and tagging mini-language that offers a natural, unobtrusive presentation and does not depend on parsing each type of input file format. Each file is marked up with tolerances and optionally, associated tags that serve to label the parameters and their uncertainties. The evolution of such a language, often called a Domain Specific Language or DSL, is given in [1], but in final form it parallels tolerances specified on an engineering drawing, e.g., 1 +/- 0.5, 5 +/- 10%, 2 +/- 10 where % signifies percent and o signifies order of magnitude. Tags, necessary for error propagation, can be added by placing a quotation-mark-delimited tag after the tolerance, e.g., 0.7 +/- 20% 'T_effective'. In addition, tolerances might have different underlying distributions, e.g., Uniform, Normal, or Triangular, or the tolerances may merely be intervals due to lack of knowledge (uncertainty). Finally, to address pragmatic considerations such as older models that require specific number-field formats, C-style format specifiers can be appended to the tolerance like so, 1.35 +/- 10U_3.2f. As an example of use, consider figure 1, where a chemical reaction input file is has been marked up to include tolerances and tags per table 1. Not only does the technique provide a natural method of specifying tolerances, but it also servers as in situ documentation of model uncertainties. This tolerance language comes with a utility to strip the tolerances (and tags), to provide a path to the nominal model parameter file. And, as shown in [1], having the ability to quickly mark and identify model parameter uncertainties facilitates error propagation, which in turn yield output uncertainties.

Kleb, Bil

Effects of cholinergic and beta-adrenergic blockade on orthostatic tolerance in healthy subjects

Cardiovascular responses during a graded lower body negative pressure (LBNP) protocol were compared before and after atropine and propranolol administration to test the hypothesis that both sympathetic and parasympathetic control of cardio-acceleration are associated with syncopal predisposition to orthostatic stress in healthy subjects. Eleven men were categorized into two groups having high (HT, N = 6) or low (LT, N = 5) tolerance based on their total time before the onset of presyncopal symptoms. HT and LT groups were similar in physical characteristics, fitness, and baseline cardiovascular measurements. Atropine treatment had no effect on LBNP tolerance or mean arterial pressure at presyncope, despite an atropine-induced increase in heart rate. Propranolol treatment reduced (p<0.05) LBNP tolerance in both groups. Diminished LBNP tolerance after propranolol administration was associated with reductions in cardiac output, whereas increase in systemic peripheral resistance from baseline to presyncope was unaffected by propranolol. Reduction in cardiac output and LBNP tolerance after beta blockade reflected a chronotropic effect because lower LBNP tolerance for the HT (-50%) and LT (-39%) groups was associated with dramatic reductions (p <0.05) in the magnitude of LBNP-induced tachycardia without significant effects on stroke volume at presyncope. Absence of an atropine-induced difference in cardiac output and systemic peripheral resistance between HT and LT groups failed to support the notion that cardiac vagal withdrawal represents a predominant mechanism that could account for differences in orthostatic tolerance. Because a reduction in LBNP tolerance in both HT and LT groups after propranolol treatment was most closely associated with reduced tachycardia, the data suggest that a primary autonomically mediated mechanism for maintenance of mean arterial pressure and orthostatic tolerance in healthy subjects is beta adrenergic-induced tachycardia.

Non-NASA Center

Issues on human acceleration tolerance after long-duration space flights

This report reviewed the literature on human tolerance to acceleration at 1 G and changes in tolerance after exposure to hypogravic fields. It was found that human tolerance decreased after exposure to hypokinetic and hypogravic fields, but the magnitude of such reduction ranged from 0 to 30 percent for plateau G forces and 30 to 70 percent for time tolerance on sustained G forces. A logistic regression model of the probability of individuals with 25 percent reduction in +Gz tolerance after 1 to 41 days of hypogravic exposures was constructed. The estimated values from the model showed a good correlation with the observed data. A brief review of the need for in-flight centrifuge during long-duration missions was also presented. Review of the available data showed that the use of countermeasures (such as anti-G suits, periodic acceleration, and exercise) reduced the decrement in acceleration tolerance after long-duration space flights. Areas of further research include quantification of the effect of countermeasures on tolerance, and methods to augment tolerance during and after exposures to hypogravic fields. Such data are essential for planning long-duration human missions.

Kumar, K. Vasantha

On the design of fault-tolerant robotic manipulator systems

Robotic systems are finding increasing use in space applications. Many of these devices are going to be operational on board the Space Station Freedom. Fault tolerance has been deemed necessary because of the criticality of the tasks and the inaccessibility of the systems to maintenance and repair. Design for fault tolerance in manipulator systems is an area within robotics that is without precedence in the literature. In this paper, we will attempt to lay down the foundations for such a technology. Design for fault tolerance demands new and special approaches to design, often at considerable variance from established design practices. These design aspects, together with reliability evaluation and modeling tools, are presented. Mechanical architectures that employ protective redundancies at many levels and have a modular architecture are then studied in detail. Once a mechanical architecture for fault tolerance has been derived, the chronological stages of operational fault tolerance are investigated. Failure detection, isolation, and estimation methods are surveyed, and such methods for robot sensors and actuators are derived. Failure recovery methods are also presented for each of the protective layers of redundancy. Failure recovery tactics often span all of the layers of a control hierarchy. Thus, a unified framework for decision-making and control, which orchestrates both the nominal redundancy management tasks and the failure management tasks, has been derived. The well-developed field of fault-tolerant computers is studied next, and some design principles relevant to the design of fault-tolerant robot controllers are abstracted. Conclusions are drawn, and a road map for the design of fault-tolerant manipulator systems is laid out with recommendations for a 10 DOF arm with dual actuators at each joint.

Tesar, Delbert

CORSSTOL: Cylinder Optimization of Rings, Skin, and Stringers with Tolerance sensitivity

Cylinder Optimization of Rings, Skin, and Stringers with Tolerance (CORSSTOL) sensitivity is a design optimization program incorporating a method to examine the effects of user-provided manufacturing tolerances on weight and failure. CORSSTOL gives designers a tool to determine tolerances based on need. This is a decisive way to choose the best design among several manufacturing methods with differing capabilities and costs. CORSSTOL initially optimizes a stringer-stiffened cylinder for weight without tolerances. The skin and stringer geometry are varied, subject to stress and buckling constraints. Then the same analysis and optimization routines are used to minimize the maximum material condition weight subject to the least favorable combination of tolerances. The adjusted optimum dimensions are provided with the weight and constraint sensitivities of each design variable. The designer can immediately identify critical tolerances. The safety of parts made out of tolerance can also be determined. During design and development of weight-critical systems, design/analysis tools that provide product-oriented results are of vital significance. The development of this program and methodology provides designers with an effective cost- and weight-saving design tool. The tolerance sensitivity method can be applied to any system defined by a set of deterministic equations.

Finckenor, J.

The Evolution of Sulfide Tolerance in the Cyanobacteria

Understanding how the function of extant microorganisms has recorded both their evolutionary histories and their past interactions with the environment is a stated goal of astrobiology. We are taking a multidisciplinary approach to investigate the diversification of sulfide tolerance mechanisms in the cyanobacteria, which vary both in their degree of exposure to sulfide and in their capacity to tolerate this inhibitor of photosynthetic electron transport. Since conditions were very reducing during the first part of Earth's history and detrital sulfides have been found in Archean sediments, mechanisms conferring sulfide tolerance may have been important for the evolutionary success of the ancestors of extant cyanobacteria. Two tolerance mechanisms have been identified in this group: (1) resistance of photosystem II, the principal target of sulfide toxicity; and (2) maintenance of the ability to fix carbon despite photosystem II inhibition by utilizing sulfide as an electron donor in photosystem I - dependent, anoxygenic photosynthesis. We are presently collecting comparative data on aspects of sulfide physiology for laboratory clones isolated from a variety of habitats. These data will be analyzed within a phylogenetic framework inferred from molecular sequence data collected for these clones to test how frequently different mechanisms of tolerance have evolved and which tolerance mechanism evolved first. In addition, by analyzing these physiological data together with environmental sulfide data collected from our research sites using microelectrodes, we can also test whether the breadth of an organism's sulfide tolerance can be predicted from the magnitude of variation in environmental sulfide concentration it has experienced in its recent evolutionary past and whether greater average sulfide concentration and/or temporal variability in sulfide favors the evolution of a particular mechanism of sulfide tolerance.

Miller, Scott R.

Eigenstructure Assignment for Fault Tolerant Flight Control Design

In recent years, fault tolerant flight control systems have gained an increased interest for high performance military aircraft as well as civil aircraft. Fault tolerant control systems can be described as either active or passive. An active fault tolerant control system has to either reconfigure or adapt the controller in response to a failure. One approach is to reconfigure the controller based upon detection and identification of the failure. Another approach is to use direct adaptive control to adjust the controller without explicitly identifying the failure. In contrast, a passive fault tolerant control system uses a fixed controller which achieves acceptable performance for a presumed set of failures. We have obtained a passive fault tolerant flight control law for the F/A-18 aircraft which achieves acceptable handling qualities for a class of control surface failures. The class of failures includes the symmetric failure of any one control surface being stuck at its trim value. A comparison was made of an eigenstructure assignment gain designed for the unfailed aircraft with a fault tolerant multiobjective optimization gain. We have shown that time responses for the unfailed aircraft using the eigenstructure assignment gain and the fault tolerant gain are identical. Furthermore, the fault tolerant gain achieves MIL-F-8785C specifications for all failure conditions.

Sobel, Kenneth

Design and validation of fault-tolerant flight systems

Flight systems must be validated to show that they are consistent with the requirements of their intended applications. While high reliability is difficult to validate, the additional complexity of fault tolerance further compounds the validation problem. The objective of NASA’s research is to develop a methodology for designing validatable fault-tolerant systems. Under the design-for-validation philosophy, emphasis is placed on developing validation methods that can be incorporated into the design process right from the start and design methods and guidance which, while incorporating fault tolerance, can assure validatability. This paper examines the statistical issues of validating highly reliable, fault tolerant system. There are many problems associated with traditional methods of designing and validating these potentially complex hardware and software systems. Useful design-for-validation methods, which include structured specification and design methodologies, mathematical proof techniques, analytical modeling, simulation and emulation, and physical testing, are discussed. Important design issues associated with fault tolerance are presented along with the related validation concerns which must be addressed. Experience has shown that synchronization and Byzantine resilience must accompany fault tolerance. Other design attributes associated with fault tolerance may be used by a designer on the basis of cost, weight, performance, and validation considerations.

Computer systems

Fault-tolerant wait-free shared objects

A concurrent system consists of processes and shared objects. Previous research focused on the problem of tolerating process failure. We study the complementary problem of tolerating failures. We divide object failures into two broad classes: responsive and non-responsive. With responsive failures, a faulty object responds to every invocation, but responses may be incorrect. With non-responsive failures, a faulty object may also 'hang' without responding. For each class, we consider crash, and arbitrary types of failures. For each type of failure, we are seeking a universal implementation for fault-tolerant wait-free shared objects. We present (deterministic) implementations for all types of responsive failures, including arbitrary failures. In contrast, we show that even the most benign type of non-responsive failures requires the use of randomization. Of special interest is the problem of implementing fault-tolerant objects using only objects of the same type. We present such fault-tolerant self-implementations for many common object types. Graceful degradation is a desirable property of fault-tolerant implementations: the implemented object never fails more severely than the base objects it is derived from, even if all the base objects fail. For several failure models, we show whether this property can be achieved, and, if so, how. In addition to the above possibility/impossibility results, we also consider the resources complexity of fault-tolerant implementations. In many cases, we present lower bounds and give matching algorithms.

Jayanti, Prasad

Parallel fault-tolerant robot control

A shared memory multiprocessor architecture is used to develop a parallel fault-tolerant robot controller. Several versions of the robot controller are developed and compared. A robot simulation is also developed for control observation. Comparison of a serial version of the controller and a parallel version without fault tolerance showed the speedup possible with the coarse-grained parallelism currently employed. The performance degradation due to the addition of processor fault tolerance was demonstrated by comparison of these controllers with their fault-tolerant versions. Comparison of the more fault-tolerant controller with the lower-level fault-tolerant controller showed how varying the amount of redundant data affects performance. The results demonstrate the trade-off between speed performance and processor fault tolerance.

Hamilton, D. L.

Software fault tolerance in computer operating systems

This chapter provides data and analysis of the dependability and fault tolerance for three operating systems: the Tandem/GUARDIAN fault-tolerant system, the VAX/VMS distributed system, and the IBM/MVS system. Based on measurements from these systems, basic software error characteristics are investigated. Fault tolerance in operating systems resulting from the use of process pairs and recovery routines is evaluated. Two levels of models are developed to analyze error and recovery processes inside an operating system and interactions among multiple instances of an operating system running in a distributed environment. The measurements show that the use of process pairs in Tandem systems, which was originally intended for tolerating hardware faults, allows the system to tolerate about 70% of defects in system software that result in processor failures. The loose coupling between processors which results in the backup execution (the processor state and the sequence of events occurring) being different from the original execution is a major reason for the measured software fault tolerance. The IBM/MVS system fault tolerance almost doubles when recovery routines are provided, in comparison to the case in which no recovery routines are available. However, even when recovery routines are provided, there is almost a 50% chance of system failure when critical system jobs are involved.

Iyer, Ravishankar K.

Damage Tolerance Issues as Related to Metallic Rotorcraft Dynamic Components

In this paper issues related to the use of damage tolerance in life managing rotorcraft dynamic components are reviewed. In the past, rotorcraft fatigue design has combined constant amplitude tests of full-scale parts with flight loads and usage data in a conservative manner to provide "safe life" component replacement times. In contrast to the safe life approach over the past twenty years the United States Air Force and several other NATO nations have used damage tolerance design philosophies for fixed wing aircraft to improve safety and reliability. The reliability of the safe life approach being used in rotorcraft started to be questioned shortly after presentations at an American Helicopter Society's specialist meeting in 1980 showed predicted fatigue lives for a hypothetical pitch-link problem to vary from a low of 9 hours to a high in excess of 2594 hours. This presented serious cost, weight, and reliability implications. Somewhat after the U.S. Army introduced its six nines reliability on fatigue life, attention shifted towards using a possible damage tolerance approach to the life management of rotorcraft dynamic components. The use of damage tolerance in life management of dynamic rotorcraft parts will be the subject of this paper. This review will start with past studies on using damage tolerance life management with existing helicopter parts that were safe life designed. Also covered will be a successful attempt at certifying a tail rotor pitch rod using damage tolerance, which was designed using the safe life approach. The FAA review of rotorcraft fatigue design and their recommendations along with some on-going U.S. industry research in damage tolerance on rotorcraft will be reviewed.

Everett, R. A., Jr.

Damage Tolerance Issues as Related to Metallic Rotorcraft Dynamic Components

In this paper issues related to the use of damage tolerance in life managing rotorcraft dynamic components are reviewed. In the past, rotorcraft fatigue design has combined constant amplitude tests of full-scale parts with flight loads and usage data in a conservative manner to provide "safe life" component replacement times. In contrast to the safe life approach over the past twenty years the United States Air Force and several other NATO nations have used damage tolerance design philosophies for fixed wing aircraft to improve safety and reliability. The reliability of the safe life approach being used in rotorcraft started to be questioned shortly after presentations at an American Helicopter Society's specialist meeting in 1980 showed predicted fatigue lives for a hypothetical pitch-link problem to vary from a low of 9 hours to a high in excess of 2594 hours. This presented serious cost, weight, and reliability implications. Somewhat after the U.S. Army introduced its six nines reliability on fatigue life, attention shifted towards using a possible damage tolerance approach to the life management of rotorcraft dynamic components. The use of damage tolerance in life management of dynamic rotorcraft parts will be the subject of this paper. This review will start with past studies on using damage tolerance life management with existing helicopter parts that were safe life designed. Also covered will be a successful attempt at certifying a tail rotor pitch rod using damage tolerance, which was designed using the safe life approach. The FAA review of rotorcraft fatigue design and their recommendations along with some on-going U.S. industry research in damage tolerance on rotorcraft will be reviewed. Finally, possible problems and future needs for research will be highlighted.

Everett, R. A., Jr.

IRON-TOLERANT CYANOBACTERIA: IMPLICATIONS FOR ASTROBIOLOGY

The review is dedicated to the new group of extremophiles - iron tolerant cyanobacteria. The authors have analyzed earlier published articles about the ecology of iron tolerant cyanobacteria and their diversity. It was concluded that contemporary iron depositing hot springs might be considered as relative analogs of Precambrian environment. The authors have concluded that the diversity of iron-tolerant cyanobacteria is understudied. The authors also analyzed published data about the physiological peculiarities of iron tolerant cyanobacteria. They made the conclusion that iron tolerant cyanobacteria may oxidize reduced iron through the photosystem of cyanobacteria. The involvement of both Reaction Centers 1 and 2 is also discussed. The conclusion that iron tolerant protocyanobacteria could be involved in banded iron formations generation is also proposed. The possible mechanism of the transition from an oxygenic photosynthesis to an oxygenic one is also discussed. In the final part of the review the authors consider the possible implications of iron tolerant cyanobacteria for astrobiology.

Brown, Igor I.