You cannot derate your way out of a radiation requirement

Dr Elena Voss Principal Engineer, Radiation Effects, Chantilly

The request arrives in roughly the same form every time. We have a part with no radiation data, the programme cannot afford beam time, can we apply a derating factor and move on.

You can. It will probably even work, for a while. But it is worth being precise about what you are actually doing, because the failure mode is not the one people expect.

What derating does and does not address

Derating handles parametric degradation. As a device accumulates total ionising dose, thresholds shift, leakage rises, timing margins erode. If you know the shape of that degradation you can operate the part well inside its limits and stay functional as those limits close in.

That is a reasonable engineering approach and we use it constantly. It requires knowing the shape of the curve — which requires data.

What derating does nothing about is single-event effects. A heavy ion strike causing latch-up does not care that you are running the part at 60% of its rated current. Latch-up threshold is a property of the device structure. There is no operating point that makes an unqualified part immune.

Total ionising dose is a wear-out mechanism. Single-event effects are a probability per unit fluence. Margin helps with the first and is irrelevant to the second.

The specific way it goes wrong

A derated part with no single-event data works fine through integration, environmental test and early operations. The upset rate is low. The programme gains confidence.

Then the mission passes through the South Atlantic Anomaly enough times, or a solar particle event happens, and the integrated fluence at high linear energy transfer reaches a level the part has never been characterised at. What follows is not gradual degradation. It is a latch-up event, which is either recoverable by a power cycle or destructive, and you have no basis to predict which.

The uncomfortable part is that the design review before launch looked fine. The part was operating well within its derated limits, and every measurement supported the decision, because the mechanism that eventually kills it produces no early warning.

What to do when there is genuinely no budget

Sometimes there really is no beam time and no money, and the honest options are narrow:

  • Find a part that has been characterised. Usually slower, lower density, more expensive per unit — and cheaper than the alternative. This is the right answer more often than it is chosen.
  • Design around the failure rather than the part. Current-limit every rail below the destructive threshold, autonomous power cycling, and a fault-management system that treats a latch-up as an expected event rather than an anomaly.
  • Write down what you do not know. If you fly an uncharacterised part, the programme record should say so explicitly, with the reasoning and who accepted the risk. Not to distribute blame — so that the anomaly investigation in year three starts from the right place.

What it actually costs

A heavy-ion campaign on a small part count is a few tens of thousands of dollars and a few weeks of lead time, assuming beam availability. That is genuinely a lot on a small programme.

It is considerably less than a spacecraft that stops responding in year two, and much less than the investigation that follows, which will begin by asking what radiation data existed for each part and will find the derating memo.

We test parts we could probably get away with not testing. Not out of caution — because the alternative is telling a customer, later, that we chose not to find out.

Related

Read next

The twenty-year fleet and the seven-year part

Read

Talk to us

Bring us the awkward one.

The problems worth writing up are rarely the ones that arrive well specified. If yours is not, that is a reason to call rather than a reason to wait.

Start a conversation