Investigation of the Challenger Accident

3.3 ANALYSIS REOUIREMENTS

3.3 ANALYSIS REOUIREMENTS

  1. FMEA's W i l l be perforned f o r each functional mode o f a subsystem or functional k i t . Electrical FMEA's w i l l be conducted t o the "black box" level and wfthin the 'black box" t o pursue functions whkh have ,single f a i l u r e point potential e f f e c t on the o r b i t e r safety or mission success. The level o f detail required i n mechanical FMEA's below the component level i n pursuit o f c r i t f c a l f a i l u r e modes w i l l vary. Standard design, such as check valves. r e l i e f valves, i s o l a t i o n valves. etc.. require only c m o n types o f f a i l u r e causes t o be l i s t e d .

02463 /4

331

DI No. 100-26 Page 5 of 34 EXAMPLE: - Failure Mode internal /external leakage. - Cause poppet/seat damage, contamination, structural failure. Uhen a cmponent is a non-standard type of design or i s unique i n application o r contains unusual /unique f a i l u r e modes o f a c r i t i c a l nature, a more detailed analysis i s required. Piece parts and t h e i r failure modes and effects t h a t could result i n component c r i t i c a l f a i l u r e modes must be identified and included i n t h e 'CAUSE' section of '* the component FMEA f o r each component f a i l u r e mode of concern. - EXAMPLE: Spring fracture, structural failure poppet - f a i l s t o seat.

  1. FMEA's f o r mechanical systems and avionics w i l l interface a t the connector. (See section 4.3.4, Mechanical E l e c t r i c a l Interface.)
  1. A l l identified failure modes will be assigned two c r i t i c a l i t i e s (functional and hardware) based on the definitions i n section 2 .0. Definitions. and procedures contained i n sections 4.3.1 and 4.3.2. Hardware and Functional Criticality Determination.
  1. The c r i t i c a l i t y assigned t o pressure carriers (pressure lines and vessels) shall r e f l e c t t h e worst case f a i l u r e effect. These include potential shrapnel damage t o the vehicle/subsystems resulting from rupture of n o n - f i l a m e n t wound tanks, potential overpressurization caused by releasing substantial quantities of fluids frun ruptured l i n e s o r tanks, or depletion of consumables. Yhere released fluids are f l m a b l e or oxidizers and the possibility of an i g n i t i o n source exists, appropriate notation will be entered under "HAZARDS" f o r Safety action. (See Appendix 8, paragraph 3.1.1, Ground Rules, subparagraphs 13, 14. and 15.) --_ 5. Failures which could occur during a l l mission phases frun prelaunch through deactiviation (including safing b purging) of subsystems subsequent t o landing and d u r i n g ferry f l i g h t s shall be:considered, regardless of occurrence probability. Documentation of prelaunch analysis i s required only f o r items classified as c r i t i c a l i t y 1/1.

D246jf 5

332

DI NO. 100-X Page 6 of 34 6. A l l ordnance/pyrotechnic items w i l l be l i s t e d i n t h e CIL according t o t h e most severe effect ( c r i t i c a l i t y 1 o r 2) of a premature operation. ~ .. 7. Each hardware or function c r i t i c a l item s m r y will include a count of the total number of c r i t i c a l f a i l u r e modes per item. by c r i t i c a l i t y . classified either structural or functional (see paragraph 4.1.11).

  1. Critical i t e n s m a r i e s f o r kits w i l l be included. but identified ". separately.
  1. FMEA's will not be required on structures, wire harnesses, cables and electrical connectors. For a l l c r i t i c a l c i r c u i t s where a short between adjacent connector con?,acts could reslut i n loss o f crew (MSC IMP Standard No. 32). t h e design schematics shall be reviewed t o verify t h a t t h i s condition does not exist. The incorporation of a switch on the ground side t h a t precludes an adjacent contact short t o result i n crew loss I s considered acceptable f o r meeting t h e MSC O N Standard N o .32 Bid., p. 291. requi rement . For a l l other c r i t i c a l circuits, separation o f redundant functions will be verified by selective review of design schematics t o insure t h a t the requirements f o r separation have been incorporated and canplied with.
  1. Logic diagrams ( r e f . Desk Instruction 100-1, Reliability EValUitfan) will be developed only where required t o provide proper correlation between schematics and FMEA's.
  1. Those components t h a t are c r i t i c a l i t y 3 (functional and hardware) i n t h e electrical c i r c u i t s by "black box" c r i t i c a l i t y may be l i s t e d on one MEA f o r f o r t h a t circuit. Those cmponents t h a t are hardware c r i t i c a l f t y 1 or 2 will have individual FMEA's. Those components t h a t are c r i t i c a l i t y 1 R or 2R. and appear i n the CIL. will have individual FMEA's.

4.0 IMPLEMENTATION

A program has been developef t o provide computer p r i n t o u t of F14EA and CIL data. Fonnat examples of these p r i n t o u t s are shown i n FIGURES 2 and 3. The f o l l h n g section contains instructions for documenting the FMEA. Data entry

333

01 NO. 100-26 Page 7 of 34

sheets (FIGURES 4 and 5) will be completed by the RSA a s information becomes available. The information will be entered i n t o the computer and the RSA w i l l receive a copy of t h e resultant data printout (FIGURES 6 and 7) which will comprise a working document of the information stored i n the computer and a baseline f o r additional i n p u t s o r revisions.

4.1 DATA E L EM E NTS

The following procedure describes the information t o be f i l l e d out on Data Sheets 1 and 2 (FIGURES 4 and 5). Each data descriptor Is preceded by the entry code for t h a t i t e m (e.g.. LV1, Subsystem ID). These codes also are shown on t h e examples of the FMEA and CIL formats. FIGURES 2 and 3. f o r infomation.

DATA SHEET NO. 1

4.1.1 (DI, LV1, LV2) D ATA IDENTIFIER: T h i s l i n e uniquely identifies t h e component

being analyzed and the 'update" infomation t o be taken. a. Circle "A'. "R" o r 'D" t o indicate appropriate action -- - A Add a new record (casponent or assembly). - R Review an existing record by adding, deleting, o r revising an element(sl of t h a t record. - D Delete an e n t i r e record and a l l information f n that record. b- S u B S Y S ~ID ( L V 1 ) :Enter the l a s t two d i g i t s of the applicable designator and dash number. (See TABLE 4.01. C. COMPONENT ID (l.v2): Enter a number which uniquely identifies the particular cmponent being available. If an existing schematic Identifier is available, i t may be used. For canputer printout purposes, t h e f i r s t d i g i t f s ) of the number shall b e selected t o indicate the assembly. The use of special characters such a s periods or dashes will be avolded. -.-

4.1.2 ( C l ) ASSEMBLY NAME: Enter the name of the assembly.

4.1.3 ( C l , J1) I

T EM NOMENCLATURE: Enter the nomenclature f o r t h e component. In the f i r s t block (C2). give the basic identifying noun. Enter any additional modifiers or description on the J1 line. A typical example i s *Valve. Solenoid", where "valve" i s the basic identifier.

0246517

334

DI NO. 100-26 Page 8 of 34 Table 4.0 - IDENTIFIERS & SUBSYSTEM NAMES - ...

01-5 PURGE, YENT 6 DRAIN 05-1 GUIDANCE. NAVIGATION-& CONTROL 02-1 LANDING OECELERATION

W U N I C A T I O N S a TUCKING

02-2 DOCKING MECHANISM 05-ZA AUDIO 02-3 SEPARATION MECHANISM 05-26 UHF

05-2C TACAN ACTUATION MECHANISMS 05-ZD ALT IMffER

05-2F MICROWAVE SCAN BEAM LANDING (MSBLS)

02-4 OOORS 05-26 S-BAND

05-25 PAYLOAD INTERRAGATOR

ET Umbil door 05-ZK CLOSED CIRCUIT TV ( N ) Star Tracker 05-2R KU-BAND COW4 6 RADAR Air Data Sensor

02-4A HATCHES 05-3 DISPUYS 6 CONTROLS 02-48 PAYLOAD BAY DOORS 05-4 INSTRUMENTATION 0 2 - 4 RUDDER/SPEEDBRAKE. 05-5 DATA PROCESSING 6 SOFTWARE BOOY FLAP & COMPUTERS 02-5 PAYLOAD RETENTION/DEPLOYMENT '05-6 ELECTRICAL POUER DISTRIBUTION WECWNISMS 6 CONTROL 02-6 HYDRAULICS 05-8 BACKUP FLIGKT CONTROL 03-1 MAIN PROPULSION 06-1 ATMOSPHERIC REVITALIZATION

(ARS, ARPCS. Airlock)

03-2 REACTION CONTROL

03-24 AFT 06-2 LIFE SUPPORT

03-26 FORWARD 06-3 ACTIVE THERMAL CONTROL WATER SPRAY BOILER 03- 3 ORBITAL MANEUVER 07-1 CREW PROVISIONS, ACCDMMODATIONS & EMERGENCY EGRESS

04-1 ELECTRICAL POWER - CYRO 07-2 CREW ESCAPE - 102 PRE-AAMOD ONLY

04-1A ELECTRICAL POWER - FUEL CELL 07-3 TUNNEL ADAPTER 04-2 AUXILIARY POWER (APU)

+See TABLE 5.0 f o r EPD&C/INTERFACING SUBSYSTEM IDENTIFIERS

..

335

01 NO. 100-26 Page 9o f 34 Table 5.0 - EPO&C/INTERFACING SUBSYSTEM IOENTIFIERS

ELECTRICAL INTERFACE MECHANI C AL SUBSYSTEMS

05-64A 01-5 Purge, Vent & Drain 05-6AB 01 -5 Vent Doors 05-66 02-1 Landing Deceleration 05-6EA 02-1 Landing Gear Control 05-668 02-1 Brake 1 A n t i -Skid 05-WC 02-1 Nosewheel Steering 05-6C 02-2 Docking Mechanism 05-6D 02-3 Separation 05-6DA 02-3 Carrier A/C Separation

ACTUATI O NMECHANI S MS SUBSYSTEMS

05-6EA 02-4A Hatches 05-6EB 02-46 Payload Bay Door 05-6EC 02-4C Rudder/Speedbrake, Body Flap 05-6E0 02-4 ET Umbilical Doors 05-6EE 02-4 AOP Deploy L H t r 05-6EF ' 02-4 S t a r Tracker Doors 05dEG - 02-4 . - Freon Radiator Deploy 05-6EH 02-4 Rendezvous Radar 6 Corn. Antenna Deploy 05-6F 02-5 Pay1 oad Retention, Manipulator

Posi tioning 05-66 02-6 Hydraulics 05-61A 02-5 Remote Manipulator Arm 05-6IB 02- 5 Manipulator Deploy Control 05-61C 02-5 Manipulator Latch Control 05-610 02-5 I Manipulator Arm Shoulder Jettison &

Retention A n n Jettison OSdIE 02-5 DAC Camera-PLE OPS

PROPULSION SUBSYSTEMS

05-65 03-1 Main Propul si on 05-6KA 03-2A Reaction Control -Aft 05-6KF 03-2F Reaction Control-Fwd 0 5 4 03-3 Orbital Maneuvering 05-6l.A 03-3 OMS Auxiliary K i t

-.-

POWER GENERATION SUBSYSTEMS

05-B(A 05-6MB

04-1A 04-1 Electrical Power Generation Electrical Power Generation - Fuel Cell - Cyro

05-6N 04- 2 Auxiliary Power U n i t

336

DI NO. 100-26 Page 1 0of 34 Table 5.0 - (Cont'd.)

ELECTRICAL INTERFACE AVIONICS SUBSYSTEMS

05-60 05-1 Guidance, Navigation 6 Cantrol

Comnunicati ons 6 Track1 ng: 05-6PA 05-2A Audio 05-6PB 05-28 UHF 05-6PC 05-2C TAC A N 05-6PD 05-20 A1 t i m e t e r 05-6PF 05-2F Microwave Scan Beam Landing (MSBLS) 05-6PG 05-26 S-Band 05-6P J 05-25 Payload Interragator 05-6PK 05-x Closed C i r c u i t TV (TW 05-6PH Ground Camnand Interface Logic (GCIL) 05-6PR 05-2R Ku-Band Corn. & Radar 05-69 05-3 Displays 6 Controls 05-6R 05-4 Instrumentation

~ _. ~

05-65 05-5 Data Processing 6 Software 05-6T 05-8 Backup F l i g h t Control 05-6 05-6 E l e c t r i c a l Power Oistrfbutian 6 Control