Assignment 2: Challenger Space Shuttle Disaster Analysis

profiledr_mic
contentserver.pdf

I

V

I

/

,�\

\ I.

• I¸

It's public knowledge that ill-fitting O-rings in the space shuttle solid rocket boosters (SRB), com- bined with low air temperatures before the sched- uled launch, precipitated the actual explosion. But the reality is not that simple. Tragically, there were several opportunities to break this deadly chain of events dur- ing the 14 years leading up to the event.

But what went wrong? What kept this ultimately di- sastrous process in motion? At the time, there was no shortage of quality assurance tools and best practices being used, but the chain that caused the Challenger disaster was completely impervious to virtially all known quality tools available at the time.

What advancements in quality thinking have we seen since then? How can we apply this thinking to other complex systems and processes? What can we learn from this tragedy?

System vs. process What happened in the chain that led to the Chal- lenger disaster is the direct result of an obvious but often overlooked fact: Tools designed for process improvement are not always scalable to the level of complex systems.

In most cases, process tools are largely quantitative, focused on functional sequences and are mostly iso- lated from external influence. Moreover, variables in proýesses are usually more easily identifiable and con- trollable than they were in the Challenger example.

The same isn't true of larger complex systems,

Logical thinking pr i Intermediate objectives (10) map Defines the expected standard of overal success factors, and necessary conditioj

FCuirrent reality tree (CR~T)A:deta'olted , logically verifiable cause and Oevia tions i n system performance from' Evaporating cloud A means of identifying hidden conflict th opportunity to create breakthroughs for

Future realilty tree (FRT) A detailed, :logcaly verifiable cause aind outcomes of changes contemplated to e Prerequisite tree A parallel sequential arrangement of the identified in the FRT. Includes obstacles

Iprojectizing system change implementat

"ocess / TABLE 1

I system performance. Establishes a goal, ns.

effect diagram depicting critical root caus the desired standard set forth in the 10 ml

iat frustrates policy change. Provides the resolving the conflict.

effect diagram projecting the anti cipated liminate the deviations identified in the C

tasks required to execute the changes to be overcome. Provides the basis for tion.--- -- --

which experience much more significant interaction with the external environment. Not only can that inter- action give rise to greater uncertainty and variability, but decisions on the most important issues often can't be evaluated quantitatively.

Processes are repetitive. They're governed by stan- dard operating procedures and best practices, which are designed to guide consistently and precisely re- peatable situations.

Systems are governed by policies, which are intend- ed to address a much wider variety of circumstances and still remain effective, while admitting greater vari- ability in conditions and circumstances. This is not a situation in which quantitative data is expected to be universally relevant

Problem solving in complex systems Problem solving in complex systems demands capabil- ities that process improvement tools, by their nature, can't provide. The tools must be able to: * Deal with a preponderance of qualitative, rather

than quantitative, data.

SSynthesize qualitative data into useful information. * Consider complex interactions among system com-

ponents.

* Incorporate the effects of policies and management decisions into an analysis of system causality. In other words, process tools are considerably more

stratified and narrowly focused. System tools are,' by design, broader in scope and address a wider variety

of situations.

Process tools tell us how to trouble- shoot and fix component system parts.

System tools tell us why a specific pro-

critical cess improvement action seems to have no significant impact on overall system

performance and what to do about it. es of Why are system tools so important?

Because any organization lives or dies as a complex system, not as a collection of isolated parts. The interactions among the parts are as important-or perhaps more so-as the polish on the individual

RT. parts or processes themselves. Contrary to traditional wisdom, the

system is not the sum of its parts, nor is it more than the sum of its parts. It's the product of system component and envi-

24 QP • www.qualityprogress.com

" PROBLEM SOLVING

LOOKING FOR ANSWERS: Members of the Rogers Commission investigating the space shuttle Challeqger accident inspect the joint of an SR8.

During the weeks following the accident, the commission spent two days touring the Kennedy Space Center. The joint being observed is similar

to the suspected area In the SRB that caused the explosion.

ronment interactions, which might not be linear nor

additive.

Logical thinking process If effective system management is ultimately the de-

terminant of success for organizations, what tools are

available to improve it? Perhaps the best tool I've en-

countered in 30 years of studying and teaching systems

management is the logical thinking process (TP).

The TP is a series of five trees originally conceived

by E.M. Goldratt to facilitate the successful application

of constraint theory.2 In the 15 years since it was intro-

duced, the TP has evolved beyond constraint theory

alone into a powerful systems thinking and manage-

ment tool.

The five logic trees and their functions are described

in Table 1.

These trees are designed to take a whole-to-parts approach to policy analysis and problem solving. They

begin with a possibly ill-defined problem, articulate the

specific gaps between what should be happening and

what is happening in the system, facilitate develop-

ment of a strategy to eliminate the gaps and lay out the

change implementation plan.

One aspect of complex system change is resolving

conflict that tends to frustrate robust system improve-

ment. Before it's appropriate to start designing solutions

for system problems, such problems must be accurate-

ly and completely identified. The second step in the

TP, the current reality tree (CRT), is the system prob-

lem identification tool. It's designed to focus on the

few factors-critical root causes-that produce the

system's biggest pioblems?

January2008 e QP. 25

AVLHculate conflict /

Prerequisit

Redesign t space shu solid rock

booster (S

Prerequisit

SRB conflict While the critical root cause of the Challenger accident

could be attributed to acquisition policies that award-

ed the booster contract to the lowest bidder in 1972,

understanding that decision, though potentially useful for future acquisition programs, was a moot point.

It did nothing to help engineers deal with the first

manifestation of a problem in 1976. A major dilemma

revealed itself during engineering development of the

program. Ironically, it presented a then-unrecognized

opportunity to create a win-win resolution that would

have prevented the Challenger accident and saved

seven lives.

Morton Thiokol Corp. (MTC) had been awarded the space shuttle SRB contract based largely on the fact

that it was the lowest bidder for the work by a signifi-

cant margin. MTC felt confident in its low bid because

it envisioned the space shuttle SRB as simply a scaled

up version of its highly reliable Titan HIB SRB.

What MTC did not anticipate were the problems as-

sociated with fabricating a substantially larger booster

of the same basic configuration.

The Titan TIB SRBs were narrower in diameter than the shuttle boosters. They were assembled, or stacked,

vertically in segments to ensure the integrity of the

perfectly round cross section of the cylindrical booster

segments. The joining of the booster segments was

effected with a clevis-and-tang design, secured with

-----------. neoprene O-rings to produce a seal

between segments that could with- t he stand the pressures of combustion

FIGURE 1 during launch.

The space shuttle boosters werete1 - twice the diameter of the Titan IIIB

the boosters and nearly twice the height, ttle et yet the booster skin was nearly the

RB) same thickness. Because of the height of the assembled b6osters, the space shuttle SRBs could not be assembled

vertically like Titan IIIB boosters.

So MTC decided to assemble the space shuttle SRBs horizontally. The

completed booster, filled with propel-

Slant, would then be shipped by rail

ý2 from MTC's facility in Utah to Cape ranaveral, FL, for assembly with the

te 2 space shuttle main tank and orbiter vehicle.

Determine the requirements/ FIGURE 2

Requirement 1 Prerequisite 1

Ensure Redesign the functional•ity space shuttlefncti•naflety solid rocket andsafet booster (SRB)

Adhere Don't redesign to NASA the space budget shuttle SRB

Requirement 2 Prerequisite 2

In 1976, MTC encountered an unanticipated prob-

lem. The larger diameter of the space shuttle SRB,

coupled with the weight of each of the four casing seg-

ments, caused distortion of the intended round shape

when the booster segments were laid horizontally.

Because the clevis ends were slightly more rigid

than the tang ends, they didn't distend as much. The

tolerance between the clevis and tang was very tight.

The net result was that the tang of one segment would

not fit into the clevis of its mated segment.

Critical dilemma Of course, what happened 10 years later wasn't appar-

ent to the MTC engineers in 1976. All they knew was

that they found themselves pulled in two different

directions at the same time: Redesign the assembly

equipment so that the boosters could be assembled

vertically (like the Titan HIB), or trade off design speci-

fications to make the assembly work horizontally.

The business decision trumped the engineering rec-

ommendation. Rather than invest the money to build the huge assembly tower required to assemble the

120-foot SRBs-which, besides incurring substantial

cost, would cause unacceptable delays to the project-

MTC and NASA program managers opted to trade off

the design.

MTC engineers increased the space between the in-

ner and outer parts of the clevis to accommodate the

26 QP 9 www.qualityprogress.com

PROBLEM SOLVING

slightly out of round distortion of the tang

and to allow the segments to fit together.

But, as newsman Eric Sevareid once ob-

served, "The 'chief cause of problems is

solutions."4

MTC discovered the problem this solu-

tion created when it conducted hydrostatic

tests to simulate launch pressures inside

the booster casing. MTC test engineers

pumped water into a sealed booster and

increased the hydraulic pressure. At a

pressure considerably less than projected

launch conditions would produce, the mat-

ed segments leaked like a sieve.

MTC's solution, approved by NASA, was

to specify a larger 0-ring to seal the offend-

ing segments. In addition, 180 shims had to

be wedged into the clevis around the cir-

cumference of the lower booster segment

to ensure an adequate seal after the clevis

gap had been enlarged. A sealing paste of

potassium chromate was used to protect

the 0-rings from burning during rocket

motor operation, and this appeared to do

the trick.

Unfortunately, it was later determined

that low ambient temperature, stiffened

the 0-rings, making them inflexible during

the vibrations of launch and compromising

their sealing ability. A succession of events

and management decisions that relaxed

safety precautions-and did nothing to im-

prove the functional safety of the system-

eventually led to the Challenger accident.

Applying an evaporating cloud The logical thinking process did not ex-

ist when MTC experienced its SRB design

dilemma. In fact, the Challenger accident

itself predated the creation of the thinking

process by more than five years. But it's

interesting to consider how history might

have changed had the MTC personnel been

able to apply an evaporating cloud to their

engineering dilemma With the luxury of

'hindsight, we can do that now. 5

An evaporating cloud is the means of

identifying hidden conflict that.frustrates

Formulate the Common objective / FIGURE 3 Requirement I Prerequisite 1

FRedesign the functionality space shuttleand safetyJ solid rocket

and sfetybooster (SRB)

objective

effective space transportation

to AS the ;spa:ce ••::

tbudget shuttl • Si•e:RB i•j

Requirement 2 Prerequisite 2

nevelop underlying assumptions / FIGURE 4 Assumptions: 6. SRB redesign is the only way to ensure

safety and functionality. 7. Redesign requires vertical assembly or

complete booster redesign. 8. Maximum safety requires the SRB design

to function as intended.

Assumptions: Requirement I Prerequisite 1 1. An effective STS is one " g

that functions as intended. Ensuredsnt 2. Effectiveness implies functionality space shuttle

acceptable safety risk. solid rocket andesafet boostef (SRB)

e ct Assumptions: ispace 12. we can't redesign

tasot i and not redesigntasy or tatio at the same time.

Assumptions: 3. Costs must be reasonable Adhere Don't redesign

(politically acceptable). to NASA the space 4. The NASA budget was budget

approved by Congress. b 5. Congress will likely be

intolerant of excessive Requirement 2 Prerequisite 2 cost overruns.

Assumptions: 9. Retaining existing design keeps the project

"Invalid assumption within budget. f 10. Retaining horizontal assembly keeps the

project within budget. "*11. Safety and functionality are not adversely

f impacted by relaxing tolerances.

January 2008 9 QP 27

An G,- is the means of identifying hidden-conflict that frustrates policy change.

policy change. It provides the opportunity to create breakthroughs for resolving conflict. The construction of an evaporating cloud begins with the articulation of the two conflicting prerequisites.

In the case of the space shuttle SRB design, the two prerequisites would be to completely redesign the SRB versus not to redesign the SRB, as shown in Figure 1 (p. 26). Remember that MTC management foreclosed the option of assembling the booster vertically.

Once the opposing'sides are stated, the requirements each side are supposed to satisfy are determined. In the SRB situation, shown in Figure 2 (p. 26), one require- ment was to ensure functionality and safety. The other was to adhere to the NASA budget. Notice that there is no inherent conflict between these two requirements.

After the requirements are established, the common objective that both requirements support must be for- mulated. For the SRB, the common objective is a cost ef- fective space transportation system, which also implies

----------------------------------------------------- '~

Create injections / FIGURE 5 Requirement 1 Prerequisite'l

* Ensure f ,ýsut' j (~~unctionali|: erity ,,he"spac - r uttle|'so li NXet and safety bo ter taRB)

S- objective

A cost Create injection by * effective space maintaining circular integrity transportation of booster segments in a system (STS) horizontal orientation

AdhereDon't redesign toNASA . :the space budget , shuttle SRB

Requirement 2 Prerequisite 2

that it is safe to use. Figure 3 (p. 27) includes this objective. The result is

a completed evaporating cloud.

Exposing underlying assumptions After the evaporating cloud is

constructed, the next step is to de-

velop the assumptions underlying

each arrow in the cloud. Figure 4 (p. 27) shows some assumptions for this cloud. There undoubtedly were more assumptions than we've shown here.

At first glance, most of these assumptions appear to be valid. Only one assumrýption on each side seems to be invalid. But in the space shuttle case, politics tipped the scales in favor of not redesigning the system.

However, whether one side is weaker won't be a fac- tor when constructing the evaporating cloud. In fact, it's possible to find no obvious invalid assumptions. Yet we can still evaporate the'conflict by rendering one or more of the assuimptions irrelevant. That's what we'll do in this case.

Creating injections This particular'conflict is clearly an engineering chal- lenge as much as it is apolitical or financial one. It boils down to how to solve a technical problem within finan- cial constraints. The solution in Figure 5 represents the resolution to this challenge. The solution to an evapo- rating cloud is called an injection-it's something new that must be injected into the situation to resolve the conflict.

Sometimes, when you're not sure how to do some- thing, you can write the injection as an outcome condi- tion you want to achieve. The injection in Figure 5 is just such a statement: Maintain the circular integrity of the two booster segments in a horizontal orientation while they're being mated.

Fortunately, there are a number of ways to generate creative ideas for solutions. One that particularly lends itself to the engineering environment is TRIZ (Russian acronym for the theory of inventive problem solving). One of the principles of TRIZ is to start by defining the ideal final result. Our injection is such a statement.

As an exercise at a 1999 constraints management conference, TRIZ was demonstrated as an idea genera-' tor to resolve the space shuttle SRB conflict.6

28 QP * www.qualityprogress.com

...................................... ............

PROBLEM SOLVING

Components of TRIZ include a set of 40 principles

of problem solving and a contradiction matrix.7 The

contradiction matrix suggests a number of different

possible principles to apply, depending on what you're

trying to achieve..

Not all principles suggested will apply to every

situation, but they represent factors to consider first

Two principles that seemed to help preserve shape

and ease of manufacture when trying to hold cross

sectional area constant are:.

Principle 24: Use a mediator (an intermediary ob-

ject to transfer or carry out action) that can be tempo-

rarily connected and easily removed.

Principle 34: After it has completed its function,

remove an element of the object.

The creative result of these principles was the jig

arrangement depicted in Figure 6. It's one of several

solutions proposed by participants in an exercise at

the conference, and it's a powerful demonstration of

the potential to integrate other tools with the thinking

process.

What might have been Unfortunately, TRIZ was not known in the United

States in 1976, and the evaporating cloud as a conflict

resolution tool didn't exist. Ultimately, MTO and NASA

jointly decided to trade off clevis-tang tolerances in

the interest of making the booster assemblies fit into L

the existing design. They accepted the degradation

that came with it and applied Band-Aid solutions (bigger

0-rings, shims and zinc chromate), and the rest, as they

say, is history.

This article isjust a taste of the potential of the logical

thinking process. The process is particularly effective in

complex system policy problems that don't lend them-

selves to easy quantification. The process follows a prov-

en scientific method approach for identifying and solving

poorly defined system ills, and it functions in a way that

process oriented tools can't hope-to achieve.

As with any other worthwhile tool, the thinking pro-

cess requires time and effort to do it well. But the pay-

back can be extraordinary. -------------------------------------------------------

FINIJD SOLU70CDWS Additional articles on problem solving can be found at www.asq.org/ learn-about-quality/problem-solving/overview/read-more.htmL.

Engineered solution / FIGURE 6

Curved flanges Crade toholdfold over SRB

SRB segment segment

S~~Rollers on •, "*•aligned rails

M-

Tang Clevis

* Jigs enclose booster segments to retain round shape. * Rollers on rails facilitate mating of segments.

- - - - - - - - - - - - - - - - - - - - - - - -----------

This article is adapted from the authors book, The Logical Thinking Process (ASQ Quality Press, 2007).

REFERENCES AND NOTES: 1. H. William Dettmer, Breaking the Constraints to World.Class Performance, ASQ Quality Press, 1998. 2. Eliyahu M. Goldratt, Theoty of Constraints, North River Press, 1990. 3. For more information on CRT and the effectiveness of a quality policy analysis tool, visit http://goalsys.com/books/papershtm. , 4.Thomas L Martin, Malice in Blunderland, McGraW-Hill, 1973. Eric Sevareid's statement during a CBS News broadcast on Dec. 29,1970, has become knoffl as Eric Sevareid's Law. 5. Ellen Domb and H. William Dettmer, 'Breakthrough Innovation In Conflict

,Resolution: MarryngTRVZ and theTOC Thinking Process,APICS Constraints Management Special Interest Group Symposium, Alexandria, VA, 1999. 6. Ibid. 7. "Contradiction Matrix and the 40 Principles for Innovative Problem SoMng. "The TRIZ Journal, www.triz-joumal.comlarchives/contradiction-matrix/.

H. WIU4AM DEITMER is a senior partner at Goal Systems International in Port Angeles, WA He has a masters degree in systems management from

k the University of Southern California.

January 2008 9 QP 29

COPYRIGHT INFORMATION

TITLE: Conflict and Complexity SOURCE: Qual Prog 41 no1 Ja 2008

The magazine publisher is the copyright holder of this article and it is reproduced with permission. Further reproduction of this article in violation of the copyright is prohibited.