Up to last timeExplanation of the engine, which is the power source.I have been doing that.

The birth of the jet engineThis ensured that a power source for high-altitude flight was secured.

On the other hand, the aircraft itself faced significant challenges in achieving high-altitude flight.
That is the environment inside the aircraft.
Furthermore, although it's not particularly interesting, this time it involves not only people who create physical products but also those who create systems and other things.Functional safety conceptThis section introduces the basics.
Let's take a closer look.
Challenges and solutions in aircraft technology for high-altitude flight
Engines underwent significant advancements during World War II.
Meanwhile, the aircraft itself was evolving at an incredible pace.
For example, biplanes became monoplanes, wooden frames were replaced with metal monocoque frames, and the shape of the wings, including the cross-sectional shape, changed from a simple flat surface to a wing shape.
ButLarge for high-altitude flightThe technical challenges were, surprisingly, the cockpit and passenger cabins, the parts where people actually sit.
Technical challenges for aircraft designed for high-altitude flight.
So far, we've created the engine necessary for flying at high altitudes.
However, the aircraft itself cannot be left as is, which makes things even more difficult.
First of all, it's something that's completely unimaginable in everyday life, but for example, if the Comet were flying at an altitude of 12000 meters, the air would be extremely thin, and the passengers would probably die.
Also, at high altitudes, it can get so cold that you could die.
Of course, that's to be expected; at altitudes above 10000m, the air density is about $ \frac{1}{10$ compared to ground level, and the temperature will be colder than -50°C.

This is easy to understand if you climb Mount Fuji in the middle of summer, as it gets incredibly cold at the summit.
But even then, it's only around 3500m, so there's still a long way to go.
An altitude of 12000 meters is probably not an environment where most mammals can survive (tardigrades might be able to make it).
At the time, Zero fighters could reach altitudes of over 6000 meters if they tried hard enough, so according to Saburo Sakai, the nori rolls in his lunchbox would freeze and become inedible.
Japan did provide flight suits with heating elements as a countermeasure, but apparently it was still quite cold (which is understandable).
Even so, interceptor planes and fighter jets only go to high altitude for a short time between combat preparation and actual combat, so it might be tolerable. However, for bombers and passenger planes that cruise at high altitudes, it's not a matter of endurance or willpower; it's genuinely cold, the air is thin, and you could die.
At that time, there were many brilliant minds who worked very hard to design the aircraft.
Aircraft technology revolution: Pressurized cabin
The technologies developed for this purpose were the pressurized chamber and the air conditioner.
Well, while air conditioners work differently, you can think of them as air conditioners, which are indispensable in modern life.
with accommodation.A pressurized chamber, simply put, is a device that maintains a constant pressure (atmospheric pressure) inside a sealed container.
This is an incredibly difficult technique, but when it comes to drawing it, it's easy and simple.
The device is quite simplified, but it looks like the following diagram.

By adjusting the amount of compressed air entering through the air compressor and the amount of air leaving through the control valve to a constant level, the pressure (atmospheric pressure) inside the sealed container will always be constant.
It might be a little similar to a refrigerator.
It's easy to draw in pictures,The most difficult point is that if the device breaks down, there is a 100% chance that the person inside will die.
usually,Any machine, even if it malfunctions, should be designed with the utmost care to prevent it from immediately harming people (although it might be frustrating when it breaks down).
However, no matter how you look at it, if this pressurized chamber malfunctions, the people inside will die.
At an altitude of 12000 meters (the summit of Mount Everest is around 8800 meters), even if the pressurized cabin broke down and people were able to escape, they probably wouldn't survive.
Parachutes are practically useless, and in the worst-case scenario, even if the pressurized chamber breaks down, safety must be maintained until the aircraft descends to an altitude where human life can survive (approximately 4000m).

So what do we do?
There is no such thing as a machine that is absolutely indestructible.
In this case,Logically speaking, the only way to ensure safety is through the design and placement of the system.
In other words, the reliability of the equipment is determined by calculations and tests, and then combined and arranged to reduce the failure rate to something like 0.00001%.
Safety design concepts (fail-safe philosophy, functional safety)
Let's consider safety design using this pressurized chamber as an example.
First, even when trying to design something to prevent malfunctions, there are the following challenges.
First, the environment continuously changes between ground level pressure of 1 atm and temperature of 20°C, and altitude of 12000m with pressure below 0.1 atm and temperature of around -40°C.
Next, since it's an airplane, a simple sealed container won't suffice, so windows and entrances are necessary (to prevent compressed air from leaking out).
Furthermore, the power source (engine) must function properly under all conditions.
In other words, it needs to function properly at all times, regardless of whether it's at low power during engine startup or at maximum power during high-speed flight.
Meeting all these requirements is extremely difficult, but high-altitude flight is impossible without achieving them.
It absolutely must not break under these conditions. Moreover, since airplanes are very weight-sensitive, it must be as light as possible.
FirstLet's introduce the redundancy system, which is fundamental to safety design.
Multiple systems
The concept of multiple systems is quite simple.
Let's look at the pressurized chamber we just discussed as an example.
For example, each pressurized chamber could have four intake compressors and four exhaust valves, meaning four separate systems plus manual valves (in the worst-case scenario, a person could operate the valves to adjust them).

in this wayWhile a single component would suffice if only functionality were considered, multiple components are included for backup purposes and other considerations.
Next, we will introduce how to use this for the safety of redundant systems.
1. Series method
This system involves operating one system while keeping the others for emergencies, and changing into a different system as needed if one malfunctions.
Well, it's perfectly normal to have a spare.
In cases where a large space can be secured for a large device like a nuclear power plant, in addition to this series system, it is common to install different systems for each spare part.
2. Parallel method
By operating all four systems, the load on each system is reduced, decreasing the probability of failure. If one system fails, the remaining three systems work at full capacity to compensate for the combined capacity of all four systems while the system moves to a safe zone.
To explain briefly, if a total capacity of 100 is required, the capacity of each component in the four systems is operated at 25 out of 100, resulting in a total capacity of 25 x 4 systems = 100.
In other words, a component that originally had a capacity of 100 is used with a capacity of 25, thus increasing reliability.
If one of the systems fails, the remaining three systems can be operated at a capacity of 33.3, which will provide the required capacity of 100 (33.3 x 3 systems).

This involves choosing the appropriate device based on its mechanism and the performance of its components.
In the case of transport equipment such as airplanes, weight has a critical impact on performance, so I think parallel configurations are often used.
In a series configuration, spare parts become mere dead weights unless a failure occurs.
Next, we will eliminate hazards other than the failure of the component itself.
Reduce the likelihood of failures occurring due to factors other than component design.
Next, we will use wind turbines, valves, and other parts that are as different as possible in terms of the manufacturing date, the people involved in their manufacture, and the machinery used in their production.
In other words, Use parts from different production lots.Furthermore, parts from similar production lots should be used as far apart as possible.
That's why the numbers on the windmill and valve in the diagram are in an odd combination.
This is to eliminate any defects (manufacturing defects) in materials, production, or transportation, as all items in the same batch are likely to have the same defect.

like thisWith small considerations, we try to disrupt the combinations of parts and their relationships with neighboring parts as much as possible.
This aloneThe risk of a chain reaction of failures caused by manufacturing defects, etc., is significantly reduced.
A familiar example
If we broaden our perspective a bit, this isn't limited to identical devices. In my area of expertise, the automotive industry, when building 2 to 6 race cars, the parts that are assembled into each car are intentionally made from different batches to avoid the risk of all cars retiring due to manufacturing defects.
As a way of thinking, if we consider the system in the diagram above as vehicles such as car number 1, and view the air compressor as the engine and the valve as the car body, then we can produce four units with different production lots.
When I was a rookie and building race engines, I used Excel to manage the parts and created a kind of lottery-like table to distribute the parts to each vehicle.
When selling vehicles like this, limited to 100 units worldwide, and with the ability to manage parts, we try to make the production lots of the parts as varied as possible.
A more familiar but often overlooked example is power plant generators (nuclear, thermal, etc.). When only a small number of the same model are produced (roughly 5 to 20 units), the production lots of the parts that assemble them are basically supplied separately to each machine.
This means that essential machinery for daily life can be disassembled from production lots of parts and reassembled, ensuring that even if one part breaks, others can continue to function, thus preventing any interruption in power supply.
Furthermore, because the production lots of the parts are different, the timing of maintenance can be staggered, which increases the overall operating time and improves efficiency.
I want to believe that such considerations are being implemented, especially in infrastructure facilities. Incidentally, the cause of the Fukushima nuclear accident was a problem that existed before that.
Furthermore, in the military, elite B-2 stealth aircraft and small-batch production F-22 Raptors and ships definitely reduce the probability of failure by using different parts batches.
This ensures a constant supply of operational machines, which is why valuable and crucial machinery for military use, especially in small-scale production, is almost certainly being adopted.
In this wayWe will do everything we can to diversify the risks and ensure that even if multiple parts fail, the entire system can survive and avoid complete failure.
Last resort: human power
However, in case all the parts fail for some reason...Always include a simple, durable device (manual valve) that can be manually adjusted so that the user can control it.
With this, if all the wind turbines stop, we can manually close the valve and quickly lower the altitude, and even if the air compressor malfunctions and too much compressed air enters, we can manually open the valve and adjust it, so we can rest assured for the time being.
Basically, any decent designerAs a last resort, a manual device that can be adjusted by a person must be installed.
As an engineer of my caliber, I can only think of two patterns: these four systems plus one (manual device).
We must not forget that even this will not reach 100%.
like thisWhile safety-related concepts are taught in school, it's difficult to truly grasp them practically without actually putting them into practice.
The most famous example of this kind of story is the return of the Apollo 13 spacecraft.
This happened when the liquid oxygen agitator, which was needed for fuel, broke down in space on the way to the moon, causing the oxygen tank to explode.
Then, since the oxygen and electricity needed for the return trip were generated by fuel cells, there wasn't enough electricity either.
They used the oxygen and electricity from the last remaining lunar lander, calculating the distribution manually, to return to Earth.
If you have the time, watching the following movies or reading the following novels will be educational (although they are heavily dramatized).
- Apollo 13 (novel, Shincho Bunko edition)
Many authors have written novels about Apollo 13, but personally, I recommend the ones written by the astronauts themselves, such as Jim Lovell, as they are the most vivid and compelling.
Apollo 13 movie
A fantastic film made by the team behind the legendary actor Tom Hanks.
Engines are actually quite simple; all you need to do is make sure that when an engine breaks down, it doesn't explode or have parts fly off and cause trouble for anything other than the engine itself (perhaps because I used to work in the engine business?).
Specifically, this involves making the engine casing more robust so that even if an explosion occurs inside the engine, the fuel doesn't escape.
Even with a single-engine plane, if only the engine fails, you can either glide like a glider or parachute down.
Furthermore, in the case of an airplane with multiple engines, even if one engine fails, to put it extremely, the failed engine can be left as is.
If it's getting in the way, just load it with an explosive bolt and throw it away.
This is just my amateur prediction, but at the time of writing, the U.S. Navy is being forced to use the F-35C (a single-engine multirole aircraft) by the Department of Defense, but I'm certain that in the near future they will either switch to twin-engine aircraft as their main force or continue to use the current F/A-18 E/F Super Hornet while modifying it.
No matter how reliable a machine is, it can never be 100%.
In other words, for safety reasons, there is an insurmountable barrier between the two systems.
like thisA design philosophy that ensures that even if a component fails, it does not affect other components and that alternative solutions remain is called fail-safe.
Functional safety (ISO 26262), which has become popular in the last five years, is a concept and system that ensures safety through other functions even if the function of a component, such as an engine, is lost.
このFunctional safety (ISO 26262) is sure to become the standard in industry going forward, so it's a good idea to remember it (in all fields).
Current status of functional safety standards: ISO 26262
For some reason, this hasn't made big news, but the EU is already gradually applying functional safety standards.
そのIn the very near future (2-3 years from now), it will be prohibited to sell products in the EU unless they meet functional safety standards.
Of course, this applies to all industrial products, including automobiles, which are a major product in modern Japan, as well as home appliances and other industrial products.
In other words, if you don't comply with the functional safety rules set by the EU, you won't be allowed to do business.
MoreoverThe global trend is towards increasing demands for functional security in all areas: politics, economics, industry, and defense.
This requires something just as challenging as the electrification process we discussed last time.
I think this way of thinking applies not only to machines, but to systems and everything else.
In fact, the same principle applies to national security strategies. The United States and European countries have been adopting this approach for quite some time.
I don't know how many systems the Comet's pressurized chamber uses, but it must be designed with at least two systems, based on the same fail-safe principle.
Next time, I will introduce in more detail the difficulties in designing pressurized chambers.

To those who found this article helpful in understanding design:
Since we're on the subject, I'd like to recommend a book that's essential for mechanical design.
To be honest, the content is extremely unhelpful, but it can be used like a dictionary when you forget the details. If you read this article, you should be able to understand the content and use it effectively. It also includes commonly used standards, making it quite useful.
If you don't already own one, I highly recommend getting one, even though it's a bit pricey. However, new ones are expensive, so if you're considering buying a used one, I strongly recommend checking that the surface roughness conforms to the new JIS standard.





Comment: