Limitations of Spacecraft Redundancy: A Case Study Analysis

Redundancy can increase spacecraft safety by providing the crew or ground with multiple means of achieving a given function. However, redundancy can also decrease spacecraft safety by 1) adding additional failure modes to the system, 2) increasing design “opaqueness”, 3) encouraging operational risk, and 4) masking or “normalizing” design flaws. Two Loss of Crew (LOC) events—Soyuz 11 and Challenger STS 51-L—are presented as examples of these limitations. Together, these case studies suggest that redundancy is not necessarily a fail-safe means of improving spacecraft safety.