NASA engineers got their parachute wires crossed for OSIRIS-REx mission
- Reference: 1701871213
- News link: https://www.theregister.co.uk/2023/12/06/osiris_rex_parachute_wiring/
- Source link:
The release triggers for the parachutes could have been [1]wired incorrectly , resulting in the signals designed to trigger the drogue parachute – a small parachute used to provide some control and stability before the main parachute is deployed – being fired out of order.
This meant that rather than deploy at an altitude of 100,000 feet, the drogue actually deployed at 9,000 feet. Worse, the signal triggered the system to cut the drogue free while it was still in the capsule , meaning that it was immediately released when the drogue was deployed.
[2]
The main parachute deployed as expected and, fortunately for the scientists eagerly awaiting the samples of asteroid Bennu collected by the mission, it had enough redundancy in the design to both slow and stabilize the capsule for a [3]safe landing . The upshot was that the landing took place more than a minute earlier than expected, but there was no negative impact to the sample.
[4]
[5]
The root cause looks to have been in the naming conventions used in the design. According to NASA, the word "main" was used inconsistently. On the signal side, "main" meant the main parachute. On the receiver side, "main" meant the pyrotechnic released the parachute canister for drogue deployment. Engineers simply connected the two mains, which resulted in the deployment actions occurring out of order.
[6]As NASA struggles to open OSIRIS-REx's asteroid sample can, probe heads off to next rock
[7]Bennu unboxing shows ancient asteroid holds carbon and water
[8]NASA taking its time unboxing asteroid sample because it grabbed too much stuff
[9]OSIRIS-REx successfully delivers NASA's first asteroid sample
NASA is no stranger to parachute malfunctions. In 2004, the sample return capsule of the Genesis probe crashed into a Utah desert after an acceleration sensor flaw resulted in the parachutes not being deployed. An [10]investigation [PDF] revealed that the sensors had been upside down.
In this instance, the issue appears to have been down to a whoopsie caused by what the agency called "inconsistent wiring label definitions."
Still, the material liberated from Bennu was returned successfully, and the probe itself has headed off on a new mission to asteroid Apophis. Roughly 1,000 feet (305 meters) wide, Apophis is expected to come within 20,000 miles (32,186 km) of Earth in 2029. The probe – now renamed OSIRIS-APEX – will enter the orbit of Apophis and study how the encounter with Earth affects the trajectory of the asteroid, its spin rate, and its surface.
[11]
NASA now needs to look at the system responsible for releasing the parachutes. This is currently locked away with the Bennu sample, the processing of which remains the mission's top priority. Once done, engineers will be able to look at the hardware and confirm that a wiring error caused the parachute problem. ®
Get our [12]Tech Resources
[1] https://blogs.nasa.gov/osiris-rex/2023/12/05/nasa-finds-likely-cause-of-osiris-rex-parachute-deployment-sequence/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXCouLQvEtNZ7GcdZQSxgAAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2023/09/25/osirisrex_sample_return_success/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXCouLQvEtNZ7GcdZQSxgAAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXCouLQvEtNZ7GcdZQSxgAAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/11/01/osirisapex_spacecraft_apophis_target/
[7] https://www.theregister.com/2023/10/12/ancient_dust_asteroid/
[8] https://www.theregister.com/2023/10/05/nasa_osiris_rex_bennu/
[9] https://www.theregister.com/2023/09/25/osirisrex_sample_return_success/
[10] https://www.nasa.gov/wp-content/uploads/2015/01/149414main_genesis_mib.pdf
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/science&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXCouLQvEtNZ7GcdZQSxgAAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://whitepapers.theregister.com/
Re: So easy to do...
Everything ^^^ said above, agreed, from an electrical engineer who works more with ground (wheels & tracks) and water stuff (but a certain unmentionable "d"-word -- check my nickname again -- gets lumped with "aerospace" all the time). The job is hard enough when the "wiring label definitions" are "inconsistent" (always!) without something actually being, you know, *incorrect*.
I've crossed my own wires between various documents/drawings/design artifacts, and the folks who are supposed to be checking me often don't catch the errors, which doubles my own workload. Thankfully, when I've also had to play technician and build some of my own designs, I found out many of the errors before they became (human and/or equipment) safety or performance issues.
Re: So easy to do...
When I was working on commissioning large plant at a UK Power Stations, all instrument cables were marshalled into terminal rails within junction boxes with the outgoing cables on a parallel but separate terminal rail. All cables were labelled/numbered, not always consistently. To get the sensors powered up and working, a procedure involving 'Temporary Jumpers' was used to connect the two rails. These jumpers had different labels on each end and a table was completed showing the status of each junction box and its cabling. Eventually, when things had been shown to work correctly, 'Permanent Jumpers' were made with a different coloured wire. You could not modify Permanent Jumpers without a Permit-to-Work. It was cumbersome but in my experience, very effective.
Re: So easy to do...
In a previous life I worked in a crew setting up electrically triggered fireworks for a local council display. About 100k's worth of fireworks, so not small but luckily not nuclear either.
The (council-owned, and probably custom-made by the local 6th form college) master firing box had about 100 banana plugs, two buttons and a badly positioned label saying Master Sequence Start, which sounded to us like they started the programmed timing sequence. We figured both buttons needed to be pressed together to act as a safety.
We found out during the pre-test that the two buttons did very different things. One was actually labelled Master Sequence, and it started the built-in sequence to set the connected fireworks off in the programmed order and timing.
The second button was labelled Start, and it fired a signal down all wires simultaneously. You used this when you had no directly connected fireworks, but were using multiple daisychained slave boxes each with their own programmed sequence and the fireworks connected to them . The Start signal just meant that they all started their sequences at the same time.
If we hadn't run the pre-test and had just pressed (what looked to be called) Master Sequence Start, we would have set off all the fireworks simultaneously; which would have been a hell of a bang.
Lessons were learned on that day.
Re: So easy to do...
That happened in Sandiego a few years back, where the whole display fired off over 30 seconds or so.
Re: So easy to do...
The "send" vs "receive" issue is familiar to me - I think of it as the "London Road problem". The only thing you know is that this road, eventually, gets to London. You could be in nearly any town in England.
Say you have to send a file to the Finance team, you call it the Finance File, and send it off to them. Finance end up getting dozens of 'Finance files' from all over the business, and every now and then some of them get confused with others!
Names are hard.
Space cyclists
https://m.youtube.com/watch?v=Yiu1uLgwF1E
No physical testing?
I'd have expected the (mostly) built systems to be tested prior to final assembly i.e. that the correct signals were being generated and going to the correct places prior to attaching to the mechanisms that deploy / cut parachute lines.
This may be a bit self-centred but I'm more worried about how the Apophis encounter affects the Earth, assuming I'm still in residence.
So easy to do...
On my current project, I am the responsible for cabling a large system together in an aircraft. I'm a mechanical aerospace engineer, and cables apparently belong to us, but that's another topic.
It is super easy if you don't pay attention to have connections not match correctly, due to incorrect or inconsistent naming conventions. What's a transmit signal on one device will be a receive on the other, what can be a primary signal for one device is only a secondary for another. You really need to have this being controlled at a high System level, with every signal being defined by the System, which allocates it to the lower equipment including to the level of defining exactly which pin on which connector gets the specific signal.
Let the individual boxes in your system control their own naming scheme and you are in for a world of hurt, which sounds a bit like what happened here.
You can't really blame the technicians who connected Main to Main for the issue here, because it sounds correct. Unless of course, it was clearly stated in their documentation, where each connection should be. Actually, there absolutely should have been a wiring diagram they were working to, which would not allow them to connect things up incorrectly without raising questions - which would/should also be checked by an inspector to see that the wiring matches the drawing - so that's a pretty big failure of management to allow any construction without the relevant documentation to make it failure free or the required level of inspection to find the error before it's integrated into the next assembly. Mistakes happen, even with documentation, but if you have the correct documentation, then hopefully those mistakes are picked up before the next stage of assembly...