RAMSynapse
Log inSign up

Safety · Worked example

Space systems

Satellite attitude control

Industry overview: Space systems at RAMSynapse

Four reaction wheels of which three are needed, two star trackers, three magnetorquers and an onboard computer with a cold spare, in orbit for seven years with no possibility of repair. Every other system in this chapter has somewhere to fail towards. The crossing drops its barriers, the compressor trips, the vehicle falls back to hydraulics, the diesel is itself a fallback. An uncontrolled spacecraft does not settle into a benign condition, and nobody can go and put it right.

That makes the hazard analysis unusual in two ways. There is no protective function to design, so the entire argument has to be carried by prevention. And the consequence does not end when the mission does: if attitude control is lost together with the ability to command a deorbit, the vehicle becomes a hazard to other operators for as long as it stays in orbit, and that obligation outlives the programme that created it. The safety question is therefore not "how reliable is the attitude control system" but "with what probability does this vehicle end its life as an uncontrolled object, and who is exposed when it does".

The technique, and why this one

A consequence classification carried past end of mission, quantified as the probability of a hazardous end state rather than as a rate, with the ageing wheel population modelled by a Weibull and the third-party exposure split out on an event-tree branch. A rate per hour is the wrong currency for a one-shot mission with no repair: nothing is renewed, so the quantity of interest is the survival probability at a fixed epoch. And the wheels wear, so the exponential that serves the electronics elsewhere in this chapter would be wrong about exactly the part of the mission the deorbit obligation falls in.

ItemModelParametersRole in the hazard
Reaction wheel, 4 fitted, 3 neededWeibullβ = 2.2, η = 15 years (131,400 h)ageing; the dominant branch
Star tracker, 2 fittedexponential150 per 10⁶ h eachattitude knowledge
Magnetorquer, 3 fittedexponential60 per 10⁶ h eachmomentum management
Onboard computer plus cold spareexponential200 per 10⁶ h, spare dormant at 10%control authority
Ground reconfigurationone-shot protection layermean 7.2 h, no second attemptrecovery, may fail
Whole AOCS at 7 yearsMonte CarloR = 0.81probability of the hazard

The wheel branch, worked with the shape it has

Seven years is 61,320 hours. Per-wheel survival at end of design life is

R_wheel(61,320) = exp(−(61,320 / 131,400)^2.2) = exp(−(0.4667)^2.2) = exp(−0.1837) = 0.832

Four identical wheels of the same age, three required, gives the binomial form

R_3oo4 = R⁴ + 4R³(1 − R) = 0.479 + 4(0.5758)(0.168) = 0.479 + 0.387 = 0.866

so the wheel branch alone contributes a failure probability of 0.134. Folding in the trackers, the magnetorquers, the computer and a ground reconfiguration that can itself fail, the simulated whole-subsystem figure is 0.81, giving

P(loss of attitude control in 7 years) = 1 − 0.81 = 0.19

The wheels are roughly 70 per cent of that, and they are the part that is not constant. The hazard function makes the point:

h(t) = (β/η)(t/η)^(β−1) = (2.2 / 131,400) × (t / 131,400)^1.2

At the mission midpoint, 30,660 hours, that is 1.674 × 10⁻⁵ × 0.1744 = 2.9 × 10⁻⁶ per hour, or 2.9 per 10⁶ hours. At seven years it is 1.674 × 10⁻⁵ × 0.4007 = 6.7 × 10⁻⁶ per hour, 6.7 per 10⁶ hours. The risk is back-loaded by a factor of 2.3, and it is back-loaded onto exactly the part of the mission when the deorbit burn falls due.

Who is exposed, and the branch that decides it

Loss of attitude control is 19% over seven years and is an economic consequence with an end date. What follows from it is not, and the page can only bound it between 3.6% and 19%. Publishing the range and the reason for it is the honest deliverable; a point estimate inside it would not be.
Loss of attitude control is 19% over seven years and is an economic consequence with an end date. What follows from it is not, and the page can only bound it between 3.6% and 19%. Publishing the range and the reason for it is the honest deliverable; a point estimate inside it would not be.

Loss of attitude control is, in itself, loss of an asset the operator owns. A 0.19 probability of that would be indefensible as a probability of injury and is entirely defensible as a business risk. What converts it into a safety matter is the second branch: whether the deorbit capability survives the event that took the attitude control.

P(uncontrolled residual object) = P(loss of attitude control) × P(deorbit unavailable | loss of attitude control)

The second factor is the number the programme must establish, and it is an independence claim rather than a measurement. Two bounds fix its importance without inventing it. If the deorbit function depends wholly on the same wheels, trackers and computer, the conditional probability is 1 and the residual-object probability is 0.19. If it were fully independent and no better than the AOCS itself, the product would be

0.19 × 0.19 = 0.036

A factor of 5.3 in the only figure a third party cares about, decided entirely by whether one function shares hardware with another. That is a design decision, not an analysis result, and a hazard analysis that stopped at "loss of mission" would never have surfaced it.

The ground segment is a protection layer, and a one-shot one

The restoration path is telemetry detection with a median of 40 minutes, diagnosis and decision at 4 hours, uplink and confirmation at 2.5 hours:

0.67 + 4 + 2.5 = 7.2 h

with no second attempt if the reassignment is wrong. That is a protection layer implemented as a human procedure, and it is inside the 0.81. Layers of that kind are legitimate, but they have to be analysed with the same seriousness as hardware, failure modes included, and their probability of success is a claim about a rota, a decision authority and a ground station pass, not about a component. The maintainability column takes those 7.2 hours apart.

There is a partial safe state, and it is worth being precise about what it protects. Safe mode is entered 2.5 times a year at 18 hours each, and it puts the vehicle sun-pointing and power-positive. It is a safe state for the spacecraft and it is not a safe state for this hazard, because entering it requires attitude control to be working. A safe state that depends on the function whose loss defines the hazard is not a mitigation, and mistaking one for the other is a routine error in systems that have a fallback mode for everything else.

The blind spot in the only test access there will ever be

Telemetry is the only diagnostic channel this vehicle will ever have, and its coverage is 96 per cent of failure rate, constrained by a housekeeping downlink budget of 4 per cent of the total. Summing the item rates gives 4 × 400 + 2 × 150 + 3 × 60 + 200 = 2,280 per 10⁶ hours, so the uncovered fraction is

0.04 × 2,280 = 91 per 10⁶ h

and over the 61,320-hour mission the expected number of failures that produce no telemetry signature at all is 91 × 10⁻⁶ × 61,320 = 5.6. Most will be benign and redundancy will absorb them. Any that is not is permanently undiagnosable, which means the ground segment's 7.2-hour recovery cannot be initiated because nobody knows there is anything to recover from. That is a hazard-analysis input, not a testability footnote, and the testability page prices the downlink budget that causes it.

What the analysis tells the engineer to do

Make the deorbit path independent of the wheels. It moves the third-party outcome by a factor of 5.3, and it is the only change on this page that moves anything by that much.

Deorbit while margin exists. Because the wheel hazard rises as t^1.2, waiting costs more each year. Consider a two-year extension granted because the payload still works, taking the mission to 78,840 hours:

R_wheel(78,840) = exp(−(0.6)^2.2) = exp(−0.3251) = 0.7225

R_3oo4 = 0.2725 + 4(0.3772)(0.2775) = 0.2725 + 0.4186 = 0.691

The wheel branch's failure probability goes from 0.134 to 0.309. A life extension that looks free because the instrument still images more than doubles the probability that the vehicle cannot control its own attitude at the moment it is asked to leave orbit. Extensions should be granted against a re-run of the wheel Weibull, not against payload health.

Book the 4 per cent telemetry blind spot in the hazard log, because it is the one place where a failure and its recovery are decoupled by design.

What a different technique would have given

Model the wheels as exponential with the same mean life and the seven-year figure comes out at 0.93 rather than 0.81, so the probability of losing attitude control reads 0.07 instead of 0.19: optimistic by a factor of 2.7 in the headline number. The worse damage is structural. A constant hazard says the last year of the mission is no more dangerous than the first, which erases the entire argument about when the deorbit burn should be commanded, makes a life extension look free, and removes any reason to re-analyse before granting one. The optimism is in the number; the error is in the recommendation.

The other plausible alternative is a component FMEA with severity assessed at system level. It would enumerate the wheel, tracker and computer failure modes correctly, assign each the effect "loss of attitude control, loss of mission", and stop there, because loss of an asset the operator owns is where a functional analysis naturally terminates. Nothing in that method asks who else is in the orbit, or for how long, or what the operator still owes them after the mission is over.


Want to see this on a live system model? Request a walkthrough.