SlideShare a Scribd company logo
1 of 16
Download to read offline
"Requirements Driven versus Risk Informed Design"
Requirements Driven versus
Risk Informed Design




Randy Rust
SR&QA Lead,
Altair Project
Johnson Space Center
                       Sensitive But Unclassified– For NASA Internal Use Only
Transportation Components of Program
                   Constellation
             Earth Departure
             Stage



                                             Crew Exploration
                                             Vehicle



Heavy Lift
Launch
Vehicle
                                    Lunar
                   Crew Launch      Lander
                   Vehicle




                                                                2
Typical Lunar Reference Mission

 MOON
                                 Vehicles are not to scale.

                                                                                          Ascent Stage
100 km                             Lander Performs LOI                                    Expended
Low Lunar
Orbit




                                                         Earth Departure
                                                         Stage Expended                     Service
Low                                                                                         Module
Earth                                                                                       Expended
Orbit
             EDS, Lander




                           CEV




                                                                           Direct Entry
                                                                           Land Landing

 EARTH
                                                                                                         3
Altair Lunar Lander

♦ 4 crew to and from the surface
   • Seven days on the surface
   • Lunar outpost crew rotation
♦ Global access capability
♦ Anytime return to Earth
♦ Capability to land 14 to 17
  metric tons of dedicated cargo
♦ Airlock for surface activities
♦ Descent stage:
   • Liquid oxygen / liquid hydrogen
     propulsion
♦ Ascent stage:
   • Hypergolic Propellants or Liquid
     oxygen/methane




                                                   4
Design Approach

♦ Project examined the multitude of concepts developed in the post-ESAS era, took
  lessons learned and began to develop a real design.

♦ Altair took a true risk informed design approach, starting with a minimum
  functionality design and adding from there to reduce risk.

♦ Lunar Design Analysis Cycle (LDAC) 1 developed a “minimum functional”
  vehicle.
    •   “Minimum Functionality” is a design philosophy that begins with a vehicle that will perform the
        mission, and no more than that
    •   Does not consider contingencies
    •   Does not have added redundancy (“single string” approach)
    •   Provides early, critical insight into the overall viability of the end-to-end architecture
    •   Provides a starting point to make informed cost/risk trades and consciously buy down risk
    •   A “Minimum Functionality” vehicle is NOT a design that would ever be contemplated as a
        “flyable” design!

♦ LDAC-2 determined the most significant contributors to loss of crew (LOC) and
  the optimum cost/risk trades to reduce those risks.

♦ LDAC-3 (current LDAC) is assessing biggest contributors to loss of mission
  (LOM) and optimum cost/risk trades to reduce those risks.

♦ Goal of the design process is to do enough real design work to understand and
  develop the requirements for SRR.
                                                                                                          5
Lander Design Analysis Cycle 1
      ♦ Lander design process kicked off with Design Analysis Cycle 1
      ♦ Took a “minimal functionality” approach for LDAC-1
      ♦ LDAC-1 completed November 2007

        Jun 07     Sept 07   Dec 07   Mar 08     Jun 08  Sept 08   Dec 08     Mar 09      Jun 09     Sept 09
                                                      CxP LCCR

                  LDAC-1      Minimum Functional Vehicle
In-House Design




                                LDAC-2             Safety / Reliability Upgrades (LOC)
     Effort




                                                                          Upgraded Flyable Vehicle
                                                          LDAC-3          Additional safety, reliability and
                                                                          functionality (LOM); Global access

                                                                                    LDAC-4
                                                                                    Upgraded Flyable Vehicle
                                                                                    Close the gap with the CARD
                                                                                                         LDAC-X

                                               Requirements Development




                                                                                                                  6
New Philosophy Needed

♦ For previous programs and projects, the general thought was to
  apply a failure tolerance philosophy
   •   One failure tolerant for loss of mission failures, and two failure tolerant to prevent loss of
       crew.
♦ For the Lander, where mass is extremely critical, this philosophy
  alone will not yield an optimal design solution.
   •   There are ways other than redundancy to improve reliability and still reduce the risk of loss
       of crew.
♦ We needed a new philosophy where we could develop a spacecraft
  that provides a required level of safety for the crew and is reliable
  enough to perform the mission.
   •   Defined the minimum set of functions necessary to accomplish the mission objectives.

   •   Made it work. Created the simplest & lowest mass conceptual design of the contemplated
       system.

   •   Consistent with NESC RP-06-108, Design, Development, Test, and Evaluation (DDT&E)
       Considerations for Safe and Reliable Human Rated Spacecraft Systems)




                                                                                                        7
LDAC-1 Starting Point

♦ ‘Hard’ Requirements
    •   4 Crew
    •   7 Day Sortie
    •   210 Day Outpost
    •   Airlock (implemented on sortie mission only)
    •   CxP transportation architecture
         − 8.4 meter shroud, TLI Loads, Lander performs LOI burn, CEV IRD, etc
    • Control Mass
         − Total Lander mass at TLI for crewed missions: 45,000 kg
         − Total Lander mass at TLI for cargo missions: 53,600 kg
♦ 3 DRMs with Mission Timelines and Functional Allocations
    • Sortie Mission to South Pole
         − 4 Crew / 7 Days on Surface / No support from surface assets
         − No restrictions on ‘when’ (accommodating eclipse periods)
    • Outpost Mission to South Pole
         − 4 Crew with Cargo Element (LAT Campaign option 2)
         − Outpost provides habitation on surface (down and out)
         − 210 Days with surface support (power)
    • Cargo Mission to South Pole
         − Short duration, large payload
♦ One Lander design, with variants (kits) if required for the different DRMs


                                                                                 8
Results of LDAC1

                                 Sortie Variant                                                  Outpost Variant
                                      45,000 kg                                                     45,000 kg
                                 Descent Module                                                   Descent Module
                                 Ascent Module                                                    Ascent Module
                                     Airlock




                                 Avionics   Power
    Mass Available for Payload
                                              Structures and Mechanisms

Manager's Reserve
                                                           Propulsion



                                                                    Thermal Control
                                                                        Life Support                 Cargo Variant
                                                                        Other                           53,600 kg
                                                                         Non-Propellant Fluids       Descent Module
                                                                                                   Cargo on Upper Deck




                    Propellant


                       Sortie Mission Lander
                         Mass distribution                                                                               9
Lander Design Analysis Cycle 2
    ♦             LDAC2's focus was to buy down the Loss of Crew (LOC) safety risks in the point of
                  departure design.
    ♦             LDAC2 completion date was May 2008.


        Jun 07          Sept 07   Dec 07   Mar 08     Jun 08  Sept 08   Dec 08     Mar 09      Jun 09     Sept 09
                                                           CxP LCCR

                     LDAC-1        Minimum Functional Vehicle
In-House Design




                                     LDAC-2             Safety / Reliability Upgrades (LOC)
     Effort




                                                                               Upgraded Flyable Vehicle
                                                               LDAC-3          Additional safety, reliability and
                                                                               functionality (LOM); Global access

                                                                                         LDAC-4
                                                                                         Upgraded Flyable Vehicle
                                                                                         Close the gap with the CARD
                                                                                                              LDAC-X

                                                    Requirements Development




                                                                                                                       10
Overview of LDAC-2 risk buy back process


                                                             System Teams
     DAC1                     Vehicle Top Risks            Develop Options &
  Baseline LOC              Divided into 33 Tasks         Safety estimates LOC
                                                            For Each Option




                        Task Options Chosen
                        By Mass ∆ and LOC ∆




   Task’s Option LOC             System Level Rolled Up              DAC2
Rolled Up to System Level            to Vehicle Level             Baseline LOC

                                                                                 11
Example Risk Buyback Task:
                   #33, Improve Comm System Reliability

♦ Purpose: Improve Comm System Reliability to be able to update the state
  vector
♦ Brief description of problem addressed by your task
    • There are currently 6 single point failures that could cause loss of the state vector
      input to the bus to the flight computer. This study identifies several options increase
      communications reliability.
    • Inability to obtain state vector results in LOC for ascent.
Proposed Solutions:
    • (A) Redundancy with 2 SDRs (instead of XPDR’s), cross-strapped to single
      diplexer/antenna pair (common EVA comm)
    • (B1) PA/LNA Bypass (with switches)
    • (B2) PA/LNA Bypass (with cables - IFM)
    • (C) Redundancy with 1 XPDR & 1 Dissimilar comm system
    • (D) Redundancy with 2 XPDRs, cross-strapped to single diplexer/antenna
      pair
    • (E1) Full Redundancy with 2 SDRs strings (common EVA comm)
    • (E2) Full Redundancy with 2 XPDRs strings
    • (E3) Full Redundancy, 1 XPDR & 1 SDR strings (common EVA comm)

                                                                                                12
Example Risk Buyback Task: #33, Improve Comm System Reliability
                   Graphical Summary of Options


       (Baseline)
                              (D)
                                     (E1)
               (B2)
                                          (E2)
                             (E3)

                      (C)


Top Contenders:




                                                                           13
Another Example: Active Thermal


                                L D A C 2 T h erm al S y s tem  O p tio n s  (D elta Mas s  V s . L O C ) vs. LOC)
                                                                              (Unallocated Differential
               1.00E ‐01
                                                                                                      B as eline L D A C 1_delta


                                                                                                      O ption A 1 dual internal loop


                                                                                                      O ption A 1f dual internal loop


                                                                                                      O ption B 1 dual c ritic al
                                                                                                      c omponents  

                                                                                                      O ption C 1 emergenc y  loop 


                                                                                                      O ption C 1f emergenc y  loop 
P robability




                                                                                                      O ption D 1 s ublimator driven
               1.00E ‐02
                                                                                                      c oldplate 

                                                                                                      O ption E 1 fully  redundant loops  


                                                                                                      O ption E 1fh fully  redundant loops  


                                                                                                      O ption E 1f fully  redundant loops  


                                                                                                      O ption F 1 s ingle loops  with
                                                                                                      redundant c omponents

                                                                                                      O ption G 1 mix  and matc h 


                                                                                                      O ption G 1f mix  and matc h 

               1.00E ‐03
                           0   100       200          300          400         500     600     700


                                               UnallocatedDe lta  Ma ss (K g .) (kg)
                                                           Differential

                                                                                                                                               14
LDAC-2 Overview
♦ The initial Lander Design and Analysis Cycles (May-November 2007) created a
  “minimal functionality” lander design that serves as a baseline upon which to add
  safety, reliability and functionality back into the design with known changes to
  performance, cost and risk.
♦ LDAC-2 completed in May 2008. Goal was to “buy down” Loss of Crew (LOC) risks.
♦ “Spent” approximately 1.3 t to buy down loss of crew (LOC) risks.
♦ “Spent” an additional 680kg on design maturity.

              P a y lo a d M a s s to S u rfa c e - C re w S o rtie                                                                        LO C
        (45.0 m t c ontrol m as s ; perform anc e reflec ts M G A and P M R )
                                                                                                          0 .1 7              0 .1 6 6
     4000
             3651                                                       CA RD s p e c                     0 .1 2
     3500                                                               p a y lo a d ma s s
                                                                                                                                                                       C AR D S p e c



                                                                                                P LO C
     3000
                                                                                                          0 .0 7
                                                                        B o tto ms -u p                                                                                L D AC P L O C
     2500
                                                                        DA C p a y lo a d
                                                                        ma s s                            0 .0 2                                          0 .0 0 5
     2000
kg




                                                                                                                              0 .0 0 4                      0 .0 0 4
                                                        1671
     1500                                                               Pa ra me tric f u lly            -0 .0 3   L D AC -1 1 1 /0 7           L D AC 2 * 0 5 /0 8
                                                                        f u n c tio n a l
     1000                                                               p a y lo a d ma s s                                              LDAC

      500    500                                        500

        0                                                                                       * Note: Based on simplified models that address identified risks.
       LD A C -1                                 LD A C -2
        11/07                                     5/08
                          D A C /D a te




                                                                                                                                                                                        15
Lessons Learned During Risk
                              Buy-down

♦ Full redundancy was usually heaviest, frequently NOT most effective for
  improving LOC
    • Conclusion may be different for LOM
♦ Quantitative risk tool was necessary to inform good design decisions
    • Always necessary to correlate engineering judgment with tool results
    • Tool forces team to reconsider
    • However, cannot rely solely on tool results. Must be able to technically explain
      decision.
♦ A risk tool the designers can interact with is a significant aid – improves
  tool and design
    • e.g., when a result did not correlate with engineering experience, designers could
      easily understand model in tool. Sometimes changed model and sometimes did not.
♦ Designing for minimum risk
    • results in lower weight design
    • is much harder and time consuming than simply adding redundancy
   • But, design team ends up much more intelligent on risk and design
     drivers
♦ Design for Minimum Risk is the way to go if you are trying to build a smart
  design team

                                                                                           16

More Related Content

What's hot

Garrett.skrobot
Garrett.skrobotGarrett.skrobot
Garrett.skrobotNASAPMC
 
Ann over
Ann overAnn over
Ann overNASAPMC
 
Ed.mango
Ed.mangoEd.mango
Ed.mangoNASAPMC
 
Ess.robert
Ess.robertEss.robert
Ess.robertNASAPMC
 
Dumbacher2012 pmchallenge
Dumbacher2012 pmchallengeDumbacher2012 pmchallenge
Dumbacher2012 pmchallengeNASAPMC
 
Fred.ouellette
Fred.ouelletteFred.ouellette
Fred.ouelletteNASAPMC
 
Hanley jeff
Hanley jeffHanley jeff
Hanley jeffNASAPMC
 
Crumbley.tim
Crumbley.timCrumbley.tim
Crumbley.timNASAPMC
 
Frost.jim
Frost.jimFrost.jim
Frost.jimNASAPMC
 
Unger massey
Unger masseyUnger massey
Unger masseyNASAPMC
 
Mitchell.michael
Mitchell.michaelMitchell.michael
Mitchell.michaelNASAPMC
 
TH3.L10.4 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...
TH3.L10.4	 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...TH3.L10.4	 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...
TH3.L10.4 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...grssieee
 
Mitskevich amanda
Mitskevich amandaMitskevich amanda
Mitskevich amandaNASAPMC
 
Smith.marshall.bryant
Smith.marshall.bryantSmith.marshall.bryant
Smith.marshall.bryantNASAPMC
 
Randall.taylor
Randall.taylorRandall.taylor
Randall.taylorNASAPMC
 
Norman.beck
Norman.beckNorman.beck
Norman.beckNASAPMC
 

What's hot (18)

Garrett.skrobot
Garrett.skrobotGarrett.skrobot
Garrett.skrobot
 
Ann over
Ann overAnn over
Ann over
 
Ed.mango
Ed.mangoEd.mango
Ed.mango
 
Ess.robert
Ess.robertEss.robert
Ess.robert
 
Dumbacher2012 pmchallenge
Dumbacher2012 pmchallengeDumbacher2012 pmchallenge
Dumbacher2012 pmchallenge
 
Fred.ouellette
Fred.ouelletteFred.ouellette
Fred.ouellette
 
9797v00 Boeing Smv Roi
9797v00 Boeing Smv Roi9797v00 Boeing Smv Roi
9797v00 Boeing Smv Roi
 
Hanley jeff
Hanley jeffHanley jeff
Hanley jeff
 
Crumbley.tim
Crumbley.timCrumbley.tim
Crumbley.tim
 
Frost.jim
Frost.jimFrost.jim
Frost.jim
 
Unger massey
Unger masseyUnger massey
Unger massey
 
Mitchell.michael
Mitchell.michaelMitchell.michael
Mitchell.michael
 
TH3.L10.4 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...
TH3.L10.4	 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...TH3.L10.4	 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...
TH3.L10.4 - SOIL MOISTURE ACTIVE PASSIVE (SMAP) CALIBRATION AND VALIDATION P...
 
Mitskevich amanda
Mitskevich amandaMitskevich amanda
Mitskevich amanda
 
Smith.marshall.bryant
Smith.marshall.bryantSmith.marshall.bryant
Smith.marshall.bryant
 
Dirks cgsic brief 2012
Dirks cgsic brief 2012Dirks cgsic brief 2012
Dirks cgsic brief 2012
 
Randall.taylor
Randall.taylorRandall.taylor
Randall.taylor
 
Norman.beck
Norman.beckNorman.beck
Norman.beck
 

Viewers also liked

Cameron pm cpresentation ii of 2-15-12
Cameron pm cpresentation ii of 2-15-12Cameron pm cpresentation ii of 2-15-12
Cameron pm cpresentation ii of 2-15-12NASAPMC
 
Kremic.tibor
Kremic.tiborKremic.tibor
Kremic.tiborNASAPMC
 
Sheives.tom
Sheives.tomSheives.tom
Sheives.tomNASAPMC
 
2012 02-22 rittweger orlando ipmc
2012 02-22 rittweger orlando ipmc2012 02-22 rittweger orlando ipmc
2012 02-22 rittweger orlando ipmcNASAPMC
 
Diaz franklin
Diaz franklinDiaz franklin
Diaz franklinNASAPMC
 
Manzer fred
Manzer fredManzer fred
Manzer fredNASAPMC
 
Freaner.claude
Freaner.claudeFreaner.claude
Freaner.claudeNASAPMC
 
Marco.sampietro
Marco.sampietroMarco.sampietro
Marco.sampietroNASAPMC
 
Bauer.frank
Bauer.frankBauer.frank
Bauer.frankNASAPMC
 
Grubbs teams and digital collaboration pmc2012
Grubbs teams and digital collaboration pmc2012Grubbs teams and digital collaboration pmc2012
Grubbs teams and digital collaboration pmc2012NASAPMC
 
Mc nally
Mc nallyMc nally
Mc nallyNASAPMC
 
Brockhurst.lane
Brockhurst.laneBrockhurst.lane
Brockhurst.laneNASAPMC
 
Inter pech bounds
Inter pech boundsInter pech bounds
Inter pech boundsNASAPMC
 
C null 01-17-2011
C null 01-17-2011C null 01-17-2011
C null 01-17-2011NASAPMC
 
Neiberding
NeiberdingNeiberding
NeiberdingNASAPMC
 
Kirsch.mike
Kirsch.mikeKirsch.mike
Kirsch.mikeNASAPMC
 
Serrato.be be
Serrato.be beSerrato.be be
Serrato.be beNASAPMC
 
M washington
M washingtonM washington
M washingtonNASAPMC
 
Patrick.guske.update
Patrick.guske.updatePatrick.guske.update
Patrick.guske.updateNASAPMC
 
Michael.aucoin
Michael.aucoinMichael.aucoin
Michael.aucoinNASAPMC
 

Viewers also liked (20)

Cameron pm cpresentation ii of 2-15-12
Cameron pm cpresentation ii of 2-15-12Cameron pm cpresentation ii of 2-15-12
Cameron pm cpresentation ii of 2-15-12
 
Kremic.tibor
Kremic.tiborKremic.tibor
Kremic.tibor
 
Sheives.tom
Sheives.tomSheives.tom
Sheives.tom
 
2012 02-22 rittweger orlando ipmc
2012 02-22 rittweger orlando ipmc2012 02-22 rittweger orlando ipmc
2012 02-22 rittweger orlando ipmc
 
Diaz franklin
Diaz franklinDiaz franklin
Diaz franklin
 
Manzer fred
Manzer fredManzer fred
Manzer fred
 
Freaner.claude
Freaner.claudeFreaner.claude
Freaner.claude
 
Marco.sampietro
Marco.sampietroMarco.sampietro
Marco.sampietro
 
Bauer.frank
Bauer.frankBauer.frank
Bauer.frank
 
Grubbs teams and digital collaboration pmc2012
Grubbs teams and digital collaboration pmc2012Grubbs teams and digital collaboration pmc2012
Grubbs teams and digital collaboration pmc2012
 
Mc nally
Mc nallyMc nally
Mc nally
 
Brockhurst.lane
Brockhurst.laneBrockhurst.lane
Brockhurst.lane
 
Inter pech bounds
Inter pech boundsInter pech bounds
Inter pech bounds
 
C null 01-17-2011
C null 01-17-2011C null 01-17-2011
C null 01-17-2011
 
Neiberding
NeiberdingNeiberding
Neiberding
 
Kirsch.mike
Kirsch.mikeKirsch.mike
Kirsch.mike
 
Serrato.be be
Serrato.be beSerrato.be be
Serrato.be be
 
M washington
M washingtonM washington
M washington
 
Patrick.guske.update
Patrick.guske.updatePatrick.guske.update
Patrick.guske.update
 
Michael.aucoin
Michael.aucoinMichael.aucoin
Michael.aucoin
 

Similar to Rust.randy

Nasa commercial space dec 2012
Nasa commercial space dec 2012Nasa commercial space dec 2012
Nasa commercial space dec 2012Dmitry Tseitlin
 
CANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDY
CANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDYCANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDY
CANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDYAlexandre Parent
 
Chris.hardcastle
Chris.hardcastleChris.hardcastle
Chris.hardcastleNASAPMC
 
Conceptual Design of a Crewed Lunar Lander
Conceptual Design of a Crewed Lunar LanderConceptual Design of a Crewed Lunar Lander
Conceptual Design of a Crewed Lunar Landerguinness
 
Kelso.robert
Kelso.robertKelso.robert
Kelso.robertNASAPMC
 
Kelso.robert
Kelso.robertKelso.robert
Kelso.robertNASAPMC
 
Thomas.londrigan
Thomas.londriganThomas.londrigan
Thomas.londriganNASAPMC
 
Thomas.londrigan
Thomas.londriganThomas.londrigan
Thomas.londriganNASAPMC
 
NTR - NETS 2009
NTR -  NETS 2009NTR -  NETS 2009
NTR - NETS 2009jdbess
 
LauncherOne Virgin Galactic 2013
LauncherOne  Virgin Galactic  2013LauncherOne  Virgin Galactic  2013
LauncherOne Virgin Galactic 2013Dmitry Tseitlin
 
Embry Riddle Final
Embry Riddle FinalEmbry Riddle Final
Embry Riddle Finaljschrell
 
Fred.ouellette
Fred.ouelletteFred.ouellette
Fred.ouelletteNASAPMC
 
Newman lengyel dartpm-chal_case
Newman lengyel dartpm-chal_caseNewman lengyel dartpm-chal_case
Newman lengyel dartpm-chal_caseNASAPMC
 

Similar to Rust.randy (20)

Altair: Constellation Returns Humans to the Moon
Altair: Constellation Returns Humans to the MoonAltair: Constellation Returns Humans to the Moon
Altair: Constellation Returns Humans to the Moon
 
Nasa commercial space dec 2012
Nasa commercial space dec 2012Nasa commercial space dec 2012
Nasa commercial space dec 2012
 
CANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDY
CANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDYCANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDY
CANADIAN ON-ORBIT AUTOMATED ROBOTIC SERVICING EXPERIMENT (COARSE) STUDY
 
Chris.hardcastle
Chris.hardcastleChris.hardcastle
Chris.hardcastle
 
Conceptual Design of a Crewed Lunar Lander
Conceptual Design of a Crewed Lunar LanderConceptual Design of a Crewed Lunar Lander
Conceptual Design of a Crewed Lunar Lander
 
Goddard 2015: Pamela Melroy, DARPA
Goddard 2015: Pamela Melroy, DARPAGoddard 2015: Pamela Melroy, DARPA
Goddard 2015: Pamela Melroy, DARPA
 
Kelso.robert
Kelso.robertKelso.robert
Kelso.robert
 
Kelso.robert
Kelso.robertKelso.robert
Kelso.robert
 
Ankit ppt
Ankit pptAnkit ppt
Ankit ppt
 
Thomas.londrigan
Thomas.londriganThomas.londrigan
Thomas.londrigan
 
Thomas.londrigan
Thomas.londriganThomas.londrigan
Thomas.londrigan
 
Robotic Refueling Mission
Robotic Refueling MissionRobotic Refueling Mission
Robotic Refueling Mission
 
NTR - NETS 2009
NTR -  NETS 2009NTR -  NETS 2009
NTR - NETS 2009
 
LauncherOne Virgin Galactic 2013
LauncherOne  Virgin Galactic  2013LauncherOne  Virgin Galactic  2013
LauncherOne Virgin Galactic 2013
 
LauncherOne VG 2013
LauncherOne VG 2013LauncherOne VG 2013
LauncherOne VG 2013
 
Sema History and Overview
Sema History and OverviewSema History and Overview
Sema History and Overview
 
Embry Riddle Final
Embry Riddle FinalEmbry Riddle Final
Embry Riddle Final
 
Fred.ouellette
Fred.ouelletteFred.ouellette
Fred.ouellette
 
Customer Success Story
Customer Success StoryCustomer Success Story
Customer Success Story
 
Newman lengyel dartpm-chal_case
Newman lengyel dartpm-chal_caseNewman lengyel dartpm-chal_case
Newman lengyel dartpm-chal_case
 

More from NASAPMC

Bejmuk bo
Bejmuk boBejmuk bo
Bejmuk boNASAPMC
 
Baniszewski john
Baniszewski johnBaniszewski john
Baniszewski johnNASAPMC
 
Yew manson
Yew mansonYew manson
Yew mansonNASAPMC
 
Wood frank
Wood frankWood frank
Wood frankNASAPMC
 
Wood frank
Wood frankWood frank
Wood frankNASAPMC
 
Wessen randi (cd)
Wessen randi (cd)Wessen randi (cd)
Wessen randi (cd)NASAPMC
 
Vellinga joe
Vellinga joeVellinga joe
Vellinga joeNASAPMC
 
Trahan stuart
Trahan stuartTrahan stuart
Trahan stuartNASAPMC
 
Snow lee
Snow leeSnow lee
Snow leeNASAPMC
 
Smalley sandra
Smalley sandraSmalley sandra
Smalley sandraNASAPMC
 
Seftas krage
Seftas krageSeftas krage
Seftas krageNASAPMC
 
Sampietro marco
Sampietro marcoSampietro marco
Sampietro marcoNASAPMC
 
Rudolphi mike
Rudolphi mikeRudolphi mike
Rudolphi mikeNASAPMC
 
Roberts karlene
Roberts karleneRoberts karlene
Roberts karleneNASAPMC
 
Rackley mike
Rackley mikeRackley mike
Rackley mikeNASAPMC
 
Paradis william
Paradis williamParadis william
Paradis williamNASAPMC
 
Osterkamp jeff
Osterkamp jeffOsterkamp jeff
Osterkamp jeffNASAPMC
 
O'keefe william
O'keefe williamO'keefe william
O'keefe williamNASAPMC
 
Muller ralf
Muller ralfMuller ralf
Muller ralfNASAPMC
 
Mulenburg jerry
Mulenburg jerryMulenburg jerry
Mulenburg jerryNASAPMC
 

More from NASAPMC (20)

Bejmuk bo
Bejmuk boBejmuk bo
Bejmuk bo
 
Baniszewski john
Baniszewski johnBaniszewski john
Baniszewski john
 
Yew manson
Yew mansonYew manson
Yew manson
 
Wood frank
Wood frankWood frank
Wood frank
 
Wood frank
Wood frankWood frank
Wood frank
 
Wessen randi (cd)
Wessen randi (cd)Wessen randi (cd)
Wessen randi (cd)
 
Vellinga joe
Vellinga joeVellinga joe
Vellinga joe
 
Trahan stuart
Trahan stuartTrahan stuart
Trahan stuart
 
Snow lee
Snow leeSnow lee
Snow lee
 
Smalley sandra
Smalley sandraSmalley sandra
Smalley sandra
 
Seftas krage
Seftas krageSeftas krage
Seftas krage
 
Sampietro marco
Sampietro marcoSampietro marco
Sampietro marco
 
Rudolphi mike
Rudolphi mikeRudolphi mike
Rudolphi mike
 
Roberts karlene
Roberts karleneRoberts karlene
Roberts karlene
 
Rackley mike
Rackley mikeRackley mike
Rackley mike
 
Paradis william
Paradis williamParadis william
Paradis william
 
Osterkamp jeff
Osterkamp jeffOsterkamp jeff
Osterkamp jeff
 
O'keefe william
O'keefe williamO'keefe william
O'keefe william
 
Muller ralf
Muller ralfMuller ralf
Muller ralf
 
Mulenburg jerry
Mulenburg jerryMulenburg jerry
Mulenburg jerry
 

Recently uploaded

Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integrationmarketing932765
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationKnoldus Inc.
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesBernd Ruecker
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI AgeCprime
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Strongerpanagenda
 
Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Kaya Weers
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observabilityitnewsafrica
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfpanagenda
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxfnnc6jmgwh
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructureitnewsafrica
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...itnewsafrica
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 

Recently uploaded (20)

Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
 
Data governance with Unity Catalog Presentation
Data governance with Unity Catalog PresentationData governance with Unity Catalog Presentation
Data governance with Unity Catalog Presentation
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architectures
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
A Framework for Development in the AI Age
A Framework for Development in the AI AgeA Framework for Development in the AI Age
A Framework for Development in the AI Age
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
 
Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)Design pattern talk by Kaya Weers - 2024 (v2)
Design pattern talk by Kaya Weers - 2024 (v2)
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
 
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 

Rust.randy

  • 1. "Requirements Driven versus Risk Informed Design" Requirements Driven versus Risk Informed Design Randy Rust SR&QA Lead, Altair Project Johnson Space Center Sensitive But Unclassified– For NASA Internal Use Only
  • 2. Transportation Components of Program Constellation Earth Departure Stage Crew Exploration Vehicle Heavy Lift Launch Vehicle Lunar Crew Launch Lander Vehicle 2
  • 3. Typical Lunar Reference Mission MOON Vehicles are not to scale. Ascent Stage 100 km Lander Performs LOI Expended Low Lunar Orbit Earth Departure Stage Expended Service Low Module Earth Expended Orbit EDS, Lander CEV Direct Entry Land Landing EARTH 3
  • 4. Altair Lunar Lander ♦ 4 crew to and from the surface • Seven days on the surface • Lunar outpost crew rotation ♦ Global access capability ♦ Anytime return to Earth ♦ Capability to land 14 to 17 metric tons of dedicated cargo ♦ Airlock for surface activities ♦ Descent stage: • Liquid oxygen / liquid hydrogen propulsion ♦ Ascent stage: • Hypergolic Propellants or Liquid oxygen/methane 4
  • 5. Design Approach ♦ Project examined the multitude of concepts developed in the post-ESAS era, took lessons learned and began to develop a real design. ♦ Altair took a true risk informed design approach, starting with a minimum functionality design and adding from there to reduce risk. ♦ Lunar Design Analysis Cycle (LDAC) 1 developed a “minimum functional” vehicle. • “Minimum Functionality” is a design philosophy that begins with a vehicle that will perform the mission, and no more than that • Does not consider contingencies • Does not have added redundancy (“single string” approach) • Provides early, critical insight into the overall viability of the end-to-end architecture • Provides a starting point to make informed cost/risk trades and consciously buy down risk • A “Minimum Functionality” vehicle is NOT a design that would ever be contemplated as a “flyable” design! ♦ LDAC-2 determined the most significant contributors to loss of crew (LOC) and the optimum cost/risk trades to reduce those risks. ♦ LDAC-3 (current LDAC) is assessing biggest contributors to loss of mission (LOM) and optimum cost/risk trades to reduce those risks. ♦ Goal of the design process is to do enough real design work to understand and develop the requirements for SRR. 5
  • 6. Lander Design Analysis Cycle 1 ♦ Lander design process kicked off with Design Analysis Cycle 1 ♦ Took a “minimal functionality” approach for LDAC-1 ♦ LDAC-1 completed November 2007 Jun 07 Sept 07 Dec 07 Mar 08 Jun 08 Sept 08 Dec 08 Mar 09 Jun 09 Sept 09 CxP LCCR LDAC-1 Minimum Functional Vehicle In-House Design LDAC-2 Safety / Reliability Upgrades (LOC) Effort Upgraded Flyable Vehicle LDAC-3 Additional safety, reliability and functionality (LOM); Global access LDAC-4 Upgraded Flyable Vehicle Close the gap with the CARD LDAC-X Requirements Development 6
  • 7. New Philosophy Needed ♦ For previous programs and projects, the general thought was to apply a failure tolerance philosophy • One failure tolerant for loss of mission failures, and two failure tolerant to prevent loss of crew. ♦ For the Lander, where mass is extremely critical, this philosophy alone will not yield an optimal design solution. • There are ways other than redundancy to improve reliability and still reduce the risk of loss of crew. ♦ We needed a new philosophy where we could develop a spacecraft that provides a required level of safety for the crew and is reliable enough to perform the mission. • Defined the minimum set of functions necessary to accomplish the mission objectives. • Made it work. Created the simplest & lowest mass conceptual design of the contemplated system. • Consistent with NESC RP-06-108, Design, Development, Test, and Evaluation (DDT&E) Considerations for Safe and Reliable Human Rated Spacecraft Systems) 7
  • 8. LDAC-1 Starting Point ♦ ‘Hard’ Requirements • 4 Crew • 7 Day Sortie • 210 Day Outpost • Airlock (implemented on sortie mission only) • CxP transportation architecture − 8.4 meter shroud, TLI Loads, Lander performs LOI burn, CEV IRD, etc • Control Mass − Total Lander mass at TLI for crewed missions: 45,000 kg − Total Lander mass at TLI for cargo missions: 53,600 kg ♦ 3 DRMs with Mission Timelines and Functional Allocations • Sortie Mission to South Pole − 4 Crew / 7 Days on Surface / No support from surface assets − No restrictions on ‘when’ (accommodating eclipse periods) • Outpost Mission to South Pole − 4 Crew with Cargo Element (LAT Campaign option 2) − Outpost provides habitation on surface (down and out) − 210 Days with surface support (power) • Cargo Mission to South Pole − Short duration, large payload ♦ One Lander design, with variants (kits) if required for the different DRMs 8
  • 9. Results of LDAC1 Sortie Variant Outpost Variant 45,000 kg 45,000 kg Descent Module Descent Module Ascent Module Ascent Module Airlock Avionics Power Mass Available for Payload Structures and Mechanisms Manager's Reserve Propulsion Thermal Control Life Support Cargo Variant Other 53,600 kg Non-Propellant Fluids Descent Module Cargo on Upper Deck Propellant Sortie Mission Lander Mass distribution 9
  • 10. Lander Design Analysis Cycle 2 ♦ LDAC2's focus was to buy down the Loss of Crew (LOC) safety risks in the point of departure design. ♦ LDAC2 completion date was May 2008. Jun 07 Sept 07 Dec 07 Mar 08 Jun 08 Sept 08 Dec 08 Mar 09 Jun 09 Sept 09 CxP LCCR LDAC-1 Minimum Functional Vehicle In-House Design LDAC-2 Safety / Reliability Upgrades (LOC) Effort Upgraded Flyable Vehicle LDAC-3 Additional safety, reliability and functionality (LOM); Global access LDAC-4 Upgraded Flyable Vehicle Close the gap with the CARD LDAC-X Requirements Development 10
  • 11. Overview of LDAC-2 risk buy back process System Teams DAC1 Vehicle Top Risks Develop Options & Baseline LOC Divided into 33 Tasks Safety estimates LOC For Each Option Task Options Chosen By Mass ∆ and LOC ∆ Task’s Option LOC System Level Rolled Up DAC2 Rolled Up to System Level to Vehicle Level Baseline LOC 11
  • 12. Example Risk Buyback Task: #33, Improve Comm System Reliability ♦ Purpose: Improve Comm System Reliability to be able to update the state vector ♦ Brief description of problem addressed by your task • There are currently 6 single point failures that could cause loss of the state vector input to the bus to the flight computer. This study identifies several options increase communications reliability. • Inability to obtain state vector results in LOC for ascent. Proposed Solutions: • (A) Redundancy with 2 SDRs (instead of XPDR’s), cross-strapped to single diplexer/antenna pair (common EVA comm) • (B1) PA/LNA Bypass (with switches) • (B2) PA/LNA Bypass (with cables - IFM) • (C) Redundancy with 1 XPDR & 1 Dissimilar comm system • (D) Redundancy with 2 XPDRs, cross-strapped to single diplexer/antenna pair • (E1) Full Redundancy with 2 SDRs strings (common EVA comm) • (E2) Full Redundancy with 2 XPDRs strings • (E3) Full Redundancy, 1 XPDR & 1 SDR strings (common EVA comm) 12
  • 13. Example Risk Buyback Task: #33, Improve Comm System Reliability Graphical Summary of Options (Baseline) (D) (E1) (B2) (E2) (E3) (C) Top Contenders: 13
  • 14. Another Example: Active Thermal L D A C 2 T h erm al S y s tem  O p tio n s  (D elta Mas s  V s . L O C ) vs. LOC) (Unallocated Differential 1.00E ‐01 B as eline L D A C 1_delta O ption A 1 dual internal loop O ption A 1f dual internal loop O ption B 1 dual c ritic al c omponents   O ption C 1 emergenc y  loop  O ption C 1f emergenc y  loop  P robability O ption D 1 s ublimator driven 1.00E ‐02 c oldplate  O ption E 1 fully  redundant loops   O ption E 1fh fully  redundant loops   O ption E 1f fully  redundant loops   O ption F 1 s ingle loops  with redundant c omponents O ption G 1 mix  and matc h  O ption G 1f mix  and matc h  1.00E ‐03 0 100 200 300 400 500 600 700 UnallocatedDe lta  Ma ss (K g .) (kg) Differential 14
  • 15. LDAC-2 Overview ♦ The initial Lander Design and Analysis Cycles (May-November 2007) created a “minimal functionality” lander design that serves as a baseline upon which to add safety, reliability and functionality back into the design with known changes to performance, cost and risk. ♦ LDAC-2 completed in May 2008. Goal was to “buy down” Loss of Crew (LOC) risks. ♦ “Spent” approximately 1.3 t to buy down loss of crew (LOC) risks. ♦ “Spent” an additional 680kg on design maturity. P a y lo a d M a s s to S u rfa c e - C re w S o rtie LO C (45.0 m t c ontrol m as s ; perform anc e reflec ts M G A and P M R ) 0 .1 7 0 .1 6 6 4000 3651 CA RD s p e c 0 .1 2 3500 p a y lo a d ma s s C AR D S p e c P LO C 3000 0 .0 7 B o tto ms -u p L D AC P L O C 2500 DA C p a y lo a d ma s s 0 .0 2 0 .0 0 5 2000 kg 0 .0 0 4 0 .0 0 4 1671 1500 Pa ra me tric f u lly -0 .0 3 L D AC -1 1 1 /0 7 L D AC 2 * 0 5 /0 8 f u n c tio n a l 1000 p a y lo a d ma s s LDAC 500 500 500 0 * Note: Based on simplified models that address identified risks. LD A C -1 LD A C -2 11/07 5/08 D A C /D a te 15
  • 16. Lessons Learned During Risk Buy-down ♦ Full redundancy was usually heaviest, frequently NOT most effective for improving LOC • Conclusion may be different for LOM ♦ Quantitative risk tool was necessary to inform good design decisions • Always necessary to correlate engineering judgment with tool results • Tool forces team to reconsider • However, cannot rely solely on tool results. Must be able to technically explain decision. ♦ A risk tool the designers can interact with is a significant aid – improves tool and design • e.g., when a result did not correlate with engineering experience, designers could easily understand model in tool. Sometimes changed model and sometimes did not. ♦ Designing for minimum risk • results in lower weight design • is much harder and time consuming than simply adding redundancy • But, design team ends up much more intelligent on risk and design drivers ♦ Design for Minimum Risk is the way to go if you are trying to build a smart design team 16