Tuesday, March 12, 2019

Boeing 737 Crash

Many are talking about the crash of the Boeing 737, but few really have anything to offer.  As a pilot and systems engineer, I think that I have a right to an opinion.  Here goes.

Considering the thousands of take offs and landing in the past few years, the fact that we have had two in the past year is statistically insignificant.  That does not diminish the concern since we would like to have zero crashes and loss of life.  There is a saying among systems engineers that goes, "Keep it simple if you want it to be reliable."  I am still amazed that we were able to get too and from the Moon considering how complex everything was.  I was involved in making a few parts that went on the vehicle and I can assure you that the processes to make them may have been complicated, but not the end product.

A problem that faces all of technology is that those who design electronics and control systems are among the most difficult people to manage.  To manage technology, one has to be more competent in the technology than those who actually do the design and coding work.  This means that the manager can't be an MBA from Harvard, but he might be a graduate of MIT. This sets the stage.

All control systems rely on sensors.  The advances in sensors has been one of the most understated parts of modern technology.  Just look at the GPS in your telephone or the chip in your kid's little drone.  None of these were possible just 10 years ago.  That is how fast this technology has progressed, but along with this progress have our controls and computer engineers kept up?

One of the worst things that can happen to the typical airplane is for it to "stall".  A stall is when the air flow over the wings does not produce enough lift to support the plane.  The corrective action is to gain speed or reduce the lift required.  During a climb the wings have to produce more lift to counter the weight of the plane, plus the additional forces of the climbing rate.  At this same time the air is getting thinner at higher altitudes and thus provides less lift.  Starting to see how complex this is?

Here is another thing.  The engines on the plane have a minimum safety factor which means that they can produce more hp for short periods of time, such as during take off.  Once climbing is over the engines have to be throttled back so that they can cool down.  It is the same with your car.  You can drive with the peddle to the metal for a few minutes, but not for hours.  It was during this 6 minute period of climbing that the failure occurred.  It could have been an engine problem where one or more of the engines could not produce the needed thrust or some kind of "false" sensor to the computer where it thought it was in or near a stall.  A problem with an engine would be something that most control engineers would know how to deal with so I am discounting this.  After 6 minutes after take off, the plane should have enough altitude to be able to nose down to avoid stall speed.  If there was a "false" speed or lift sensor that predicted the stall, they would not have then shown that the stall had been corrected.  The result would be a power on dive into the ground.

Here is where I defend the pilot.  The pilot has no seat of the pants idea how fast the plane is going.  He has to rely on his instruments.  If the instrument is fed by the same sensor that feeds the computer, the pilot has to conclude that the computer must be doing the correct thing and thus does not take over control.  In your car when the speedometer says that you are going 60 mph and you see kids on bicycles keeping up with you, you know your speedometer is wrong.  A pilot does not have this kind of reference.

I once had a speed sensor problem on my plane and I could not get back on the ground fast enough, but I was at low altitude and the sensor showed "zero" which I knew was clearly in error.  I would think that any sophisticated system would compare air speed with a GPS speed to prevent taking the wrong emergency action.

We will have to wait and see what really caused the crash, but it is interesting to speculate anyway.

PS--Here is a point that came up with my coffee group.  Let's say that we have a sensor that is the main source of determining if the plane is in or near a stall and it is programed this way.  The output of the sensor gives a 0 to 10 signal with anything below 5 indicating a stall.  The programmer uses this input to trigger anti-stall action.  If the failure mode of the sensor due to anything including loss of power to or an open in the output is interpreted by the program as being below 5 and thus a stall.  This means that there are two malfunctions of the sensor that could trigger a "false" stall.  If the design required the signal from the sensor to be between 2 and 10 as a test for the sensor working properly, the "false" stall could have been avoided.

In my example above where I lost air speed on my plane, I knew that the signal was in error because it indicated "zero" and I knew that was impossible if the sensor was working correctly.  As a result I ignored the signal and landed as soon as possible.

PS--Weight and balance is a key component of any plane.  All planes that I am aware of specify the balance range. As long as a plane is thus properly balanced if the pilot takes his hands off the controls the plane will tend to nose down slightly and thus avoid a possible stall.  The loading of baggage on a plane is critical so that it is not out of balance.  Once in flight, the pilot can "trim" the plane so that it will fly level.  I don't know about the 737, but it was not at cruse altitude where "trimming" is normally done.  After reading up on the 737, it appears that it was "not" designed normally so that Boeing had to add special anti stall systems which appear to be the root cause of the problem. It is during the lower airspeed climbing period that planes are most likely to stall.  All pilots know this.

Based on my experience, I have gained a lot more confidence in the design abilities of the old time air plane designers compared to our modern university graduate engineers and programmers.  They would never have designed a plane that was out side of their normal weight and balance rules.

PS--Boeing 737 correction is to "add" weight in the nose so that the plane is within "normal" trim standards.  This will reduce the amount of freight and number of passengers that the plane can carry.  Making more money is the reason that Boeing allowed a design with the trim out of "normal".  Their software "patch" put the plane at additional risk. 

PS--Wait till we get data on  how the plane was loaded.  It could have been over loaded or the load put in the wrong place or the load could have been improperly secured such that it shifted when the plane nosed up.  One set of data showed the plane's path oscillating up and down.  That could be due to a shifting in loaded baggage and freight.