Monday, 8 September 2014

Overview of Quantum Entanglement - Einstein Versus Bohr





Quantum Entanglement



It’s a popular myth that identical twins, it's said, can sometimes sense when one of the pair is in danger, even if they're oceans apart. Tales of telepathy abound. Scientists cast a skeptical eye over such claims, largely because it isn't clear how these weird connections could possibly work. Yet they've had to come to terms with something that's no less strange in the world of physics: an instantaneous link between particles that remains strong, secure, and undiluted no matter how far apart the particles may be – even if they're on opposite sides of the universe. It's a link that Einstein went to his grave denying, yet its existence is now beyond dispute. This quantum equivalent of telepathy is demonstrated daily in laboratories around the world. It holds the key to future hyperspeed computing and underpins the science of teleportation. Its name is entanglement.


The discovery of entanglement



The concept, but not the name of entanglement, was first put under the scientific spotlight on May 15, 1935, when a paper by Einstein and two younger associates, Boris Podolosky and Nathen Rosen, appeared in the journal Physical Review.[1]


Its title – "Can a Quantum-Mechanical Description of Physical Reality Be Considered Complete?" – leaves no doubt that the paper was a challenged to Niels Bohr and his vision of the subatomic world. On June 7, Erwin Schrödinger, himself no lover of quantum weirdness, wrote to Einstein, congratulating him on the paper and using in his letter the word entanglement – or, rather, its German equivalent verschränkung – for the first time. This new term soon found its way into print in an article – sent to the Cambridge Philosophical Society on August 14 that was published a couple of months later.[2]

In it he wrote:

When two systems ... enter into temporary physical interaction ... and when after a time of mutual influence the systems separate again, then they can no longer be described in the same way as before, viz. by endowing each of them with a representative of its own. I would not call that one but rather the characteristic trait of quantum mechanics, the one that enforces its entire departure from classical lines of thought. By the interaction the two representatives [the quantum states] have become entangled.
The characteristic trait of quantum mechanics ... the one that enforces its entire departure from classical lines of thought – here was an early sign of the importance attached to this remarkable effect.

Entanglement lay at the very heart of quantum reality – its most startling and defining feature and Einstein would have none of it.

For the best part of a decade, the man who revealed the particle nature of light (see Einstein and the photoelectric effect) had been trying to undermine Bohr's interpretation of quantum theory. Einstein couldn't stomach the notion that particles didn't have properties, such as momentum and position, with real, determinable (if only we knew how), preexisting values. Yet that notion was spelled out in a relationship discovered in 1927 by Werner Heisenberg. 

Known as the uncertainty principle, it stems from the rule that the result of multiplying together two matrices representing certain pairs of quantum properties, such as position and momentum, depends on the order of multiplication. The same oddball math that says X times Y doesn't have to equal Y times X implies that we can never know simultaneously the exact values of both position and momentum. Heisenberg proved that the uncertainty in momentum can never be smaller than a particular number that involves Planck's constant. 



In one sense, this relationship quantifies wave-particle duality. Momentum is a property that waves can have (related to their wavelength); position is a particlelike property because it refers to a localization in space. Heisenberg's formula reveals the extent to which one of these aspects fades out as the other becomes the focus of attention.



 In a different but related sense, the uncertainty principle tells how much the complementary descriptions of a quantum object overlap. Position and momentum are complimentary properties because to pin down one is to lose track of the other; they coexist but are mutually exclusive, like the opposite sides of the same object. Heisenberg's formula quantifies the extent to which knowledge of one limits knowledge of the other.(For More see my article on the life and work of Werner Heisenberg which has a more detailed description of the uncertainty principle and the context of wave particle duality)

Einstein didn't buy this. He believed that a particle does have a definite position and momentum all the time, whether we're watching it or not, despite what quantum theory says. From his point of view, the Heisenberg uncertainty principle isn't a basic rule of nature; it's just an artifact of our inadequate understanding of the subatomic realm. In the same way, he though, wave-particle duality isn't grounded in reality but instead arises from a statistical description of how large numbers of particles behave. Given a better theory, there'd be no wave-particle duality or uncertainty principle to worry about. The problem was, as Einstein saw it, that quantum mechanics wasn't telling the whole story: it was incomplete.


Einstein versus Bohr



Intent on exposing this fact to the world and championing a return to a more classical pragmatic view of nature, Einstein devised several thought experiments between the late 1920s and the mid-1930s. Targeted specifically at the idea of complementarity, these experiments were designed to point out ways to simultaneously measure a particle's position and momentum, or its precise energy at a precise time (another complementary pair), thus pulling the rug from under the uncertainty principle and wave-particle duality.

The first of these experiments was talked about informally in 1927, in hallway discussions at the fifth Solvay Conference in Brussels. Einstein put to Bohr a modified version of the famous double-slit experiment in which quantum objects – electrons, say – emerging from the twin slits are observed by shining light onto them. Coherent Photons bouncing off a particle would have their momenta changed by an amount that would reveal the particle's trajectory and, therefore, which slit it had passed through. The particle would then go on to strike the detector screen and contribute to the buildup of an interference pattern. Wave-particle duality would be circumvented, Einstein argued, because we would have simultaneously measured particlelike behavior (the trajectory the particle took) and wavelike behavior (the interference pattern on the screen).

But Bohr spotted something about this thought experiment that Einstein had overlooked. To be able to tell which slit a particle went through, you'd have to fix its position with an accuracy better than the distance between the slits. Bohr then applied Heisenberg's uncertainty principle, which demands that if you pin down the particle's position to such and such a precision, you have to give up a corresponding amount of knowledge of its momentum. Bohr said that this happens because the photons deliver random kicks as they bounce off the particle. The result of these kicks is to inject uncertainty into the whereabouts of the particle when it strikes the screen. And here's the crucial caveat: the uncertainty turns out to be roughly as large as the spacing between the interference bands. The pattern is smeared out and lost as the quantum mechanical wavefunction becomes decoherent. With this it disappears Einstein's hoped-for contradiction.

On several other occasions, Einstein confronted Bohr with thought experiments cunningly contrived to blow duality out of the water. Each time, Bohr used the uncertainty principle to exploit a loophole and win the say against his arch rival (and, incidentally, good friend). In the battle for the future of quantum physics, Bohr defeated Einstein and, in the process, showed just how important Heisenberg's little formula was in the quantum scheme of things.


These arguments between Bohr and Einstein were never truly resolved and got evermore technical. At the sixth Congress of Solvay, in 1930, the indeterminacy relation was Einstein's target of criticism. His idea contemplates the existence of an experimental apparatus which was subsequently designed by Bohr in such a way as to emphasize the essential elements and the key points which he would use in his response.

In this Einstein considers a box, sometime's called "Einstein's Box" or "Einstein's Box of Light". With this thought experiment, which was designed with Bohr's assistance, Einstein's was supposed to prove the violation of the indeterminacy relation between time and energy. The schematic of Einetin and Bohr's apparatus is shown below:

                 "Einstein's Box of Light" - Einstein's secret weapon to destroy quantum mechanics?

Einstein described a box full of light and said that it was possible to measure both the energy 'E' of a single photon and the time 't' when it was emitted. This was not allowed by a variant on Heisenberg’s uncertainty principle, namely .

Einstein said that the box could be weighed at first and then a single photon be allowed to escape through a shutter controlled by a clock inside the box. The box would then be weighed again and the mass difference 'm' determined. The energy of the photon 'E' is simply E = mc^2.

It appeared that both the photon's energy and its time of emission could be determined! This caused a bit of a shock when first seen by Bohr, he genuinely did not see the solution at once and Einstein seemed at first sight to have one the battle this time, meaning that the uncertainty of quantum mechanics was going to be finally wiped out!

Bohr, after sleeping on the problem, finally realized that there was a flaw in Einstein's reasoning. When the photon is released, the box will recoil (to conserve momentum) and the position of the box in the earth's gravitational field will be uncertain. Einstein's very own general theory of relativity said that this would cause a corresponding uncertainty in the time recorded.







An illustration of this, in context of Einstein's light box is shown on the left - critically it depends on the presence of a clock in the device recording the time at which particles are measured and weighted at precise time intervals by recoil from the light source; clocks are effected by gravity in special relativity and run slower in a gravitational field than in zero gravity. Hence, gravitation affects the measurement, and thus induces uncertainties in the weight of quanta - as quantum mechanics predicts. *

*(although this may not be a successful tool for disproving quantum mechanics, as Einstein intended, this may be an important way however to measure certain weakly interacting affects of gravity in context of the predictions of general relativity -such as local gravitational waves and instances of spatial warping.)


So Bohr had been saved by defeat by Einstein forgetting his own theory of general relativity!

This was to be the last serious assault – approximately 28 years after its inception at the hands of Planck, the foundations of quantum mechanics seemed to be complete and depended wholly on this uncertainty business which Einstein never accepted and always saw it as a kind of a magician's curtain, hiding the true mechanism of what appears to be a trick of nature itself.


Such is the version of this clash of 20th-century titans that's been dutifully repeated in textbooks and spoon fed to physics students for many years. But evidence has recently come to light that Bohr had unwittingly hoodwinked Einstein with arguments that were fundamentally unsound. This disclosure doesn't throw quantum mechanics back into the melting pot, but it does mean that the record needs setting straight, and that the effect that really invalidates Einstein's position should be given proper credit.

The revisionist picture of the Bohr-Einstein debates stems partly from a suggestion made in 1991 by Marlan Scully, Berthold-Georg Englert, and Herbert Walther of the Max Planck Institute for Quantum Optics in Garching, Germany.[3] These researchers proposed using atoms as quantum objects in a version of Young's two-slit experiment.



Atoms have an important advantage over simpler particles, such as photons or electrons: they have a variety of internal states, including a coherent ground state (lowest energy state) and a series of decoherent excited states. These different states, the German team reckoned, could be used to track the atom's path.

This two-state example of coherence and decoherence is what allowed this formulation of a quantum version of the famous Two-Slit Experiment.


We can label the probability-amplitude wave function passing through the left hand slit in the figure ψleft and the waves passing through the right-hand slit ψright. These are coherent and show the characteristic quantum interference fringes on the detector screen (a photographic plate or CCD array). This is the case even if the intensity of particles is so low that only one particle at a time arrives at the screen.

In a dramatic experimental proof of decoherence, physicist Gerhard Rempe sent matter waves of heavy Rubidium atoms through two slits. He then irradiated the left slit with microwaves that could excite the hyperfine structure in Rb atoms passing through that slit. As he turned up the intensity, the interference fringes diminished in proportion to the number of photons falling on the left slit. The photons decohere the otherwise coherent wave functions.[4]



The crucial factor in this version of the double-slit experiment is that the microwaves have hardly any momentum of their own, so they can cause virtually no change to the atom's momentum – nowhere near enough to smear out the interference pattern.

Heisenberg's uncertainty principle can't possibly play a significant hand in the outcome. Yet with the microwaves turned on so that we can tell which way the atoms went, the interference pattern suddenly vanishes. Bohr had argued that when such a pattern is lost, it happens because a measuring device gives random kicks to the particles. But there aren't any random kicks to speak of in the rubidium atom experiment; at most, the microwaves deliver momentum taps ten thousand times too small to destroy the interference bands. Yet, destroyed the bands are. It isn't that the uncertainty principle is proved wrong, but there's no way it can account for the results.

The only reason momentum kicks seemed to explain the classic double slit experiment discussed by Bohr and Einstein turns out to be a fortunate conspiracy of numbers. There's a mechanism at work far deeper than random jolts and uncertainty. What destroys the interference pattern is the very act of trying to get information about which paths is followed. The effect at work is entanglement.


Nonlocality



Ordinarily, we think of separate objects as being independent of one another. They live on their own terms, and anything tying them together has to be forged by some tangible particles, A and B, which have come into contact, interacted for a brief while, and then flown apart. Each particle is described by (among other properties) its own position and momentum. The uncertainty principle insists that one of these can't be measured precisely without destroying knowledge of the other. However, because A and B have interacted and, in the eyes of quantum physics, have effectively merged to become one interconnected system, it turns out that the momentum of both particles taken together and the distance between them can be measured as precisely as we like. Suppose we measure the momentum of A, which we'll assume has remained behind in the lab where we can keep an eye on it. We can then immediately deduce the momentum of B without having to do any measurement on it at all. Alternatively, if we choose to observe the position of A, we would know, again without having to measure it, the position of B. This is true whether B is in the same room or a great distance away.

From Heisenberg's relationship, we know that measuring the position of, say, A will lead to an uncertainty in its momentum, Einstein, Podolosky, and Rosen pointed out, however, that by measuring the position of A, we gain precise knowledge of the position of B. Therefore, if we take quantum mechanics at face value, by gaining precise knowledge of its position, an uncertainty in momentum has been introduced for B. In other words, the state of B depends on what we choose to do with A in our lab. And, again, this is true whatever the separation distance may be. EPR considered such a result patently absurd. How could B possibly know whether it should have a precisely defined position or momentum? The fact that quantum mechanics led to such an unreasonable conclusion, they argued, showed that it was flawed – or, at best, that it was only a halfway house toward some more complete theory.

At the core of EPR's challenge is the notion of locality: the common sense idea that things can only be affected directly if they're nearby. To change something that's far away, there's a simple choice: you can either go there yourself or send some kind of signal. Either way, information or energy has to pass through the intervening space to the remote site in order to affect it. The fastest this can happen, according to Einstein's special theory of relativity, is the speed of light.

The trouble with entanglement is that it seems to ride roughshod over this important principle. It's fundamentally nonlocal. A measurement of particle A affects its entangled partner B instantaneously, whatever the separation distance, and without signal or influence passing between the two locations. This bizarre quantum connection isn't mediated by fields of force, like gravity or electromagnetism. It doesn't weaken as the particles move apart, because it doesn't actually stretch across space. As far as entanglement is concerned, it's as if the particles were right next to one another: the effect is as potent at a million light-years as it is at a millimeter. And because the link operates outside space, it also operates outside time. What happens at A is immediately known at B. No wonder Einstein used words such as "spook" and "telepathic" to describe – and deride – it. No wonder that as the author of relativity he argued that the tie that binds entangled particles is a physical absurdity. Any claim that an effect could work at faster-than-light speeds, that it could somehow serve to connect otherwise causally isolated objects, was to Einstein an intellectual outrage.

A close look at the EPR scenario reveals that it doesn't actually violate causality, because no information passes between the entangled particles. The information is already, as it were, built into the combined system, and no measurement can add to it. But entanglement certainly does throw locality out the window, and that development is powerfully counterintuitive. It was far too much for Einstein and his colleagues to accept, and they were firmly convinced that quantum mechanics, as it stood, couldn't be the final word. It was, they suggested, a mere approximation of some as yet undiscovered description of nature. This description would involve variables that contain missing information about a system that quantum mechanics doesn't reveal, and that tell particles how to behave before a measurement is carried out. A theory along these lines – a theory of so-called local hidden variables – would restore determinism and mark a return to the principle of locality.

The shock waves from the EPR paper quickly reached the shores of Europe. In Copenhagen, Bohr was once again cast into a fever of excitement and concern as he always was by Einstein's attacks on his beloved quantum worldview. He suspended all other work in order to prepare a counterstrike. Three months later, Bohr's rebuttal was published in the same American journal that had run the EPR paper. Basically, it argued that the nonlocality objection to the standard interpretation of quantum theory didn't represent a practical challenge. It wasn't yet possible to test it, and so physicists should just get on with using the mathematics of the subject, which worked so well, and not fret about the more obscure implications.


David Bohm's View on The EPR Paradox

                                                       David Joseph Bohm, FRS, London

Most scientists, whose interest was simply in using quantum tools to probe the structure of atoms and molecules were happy to follow Bohr's advice. But a few theorists continued to dig away at the philosophical roots. In 1952, American Physicist David Bohm, at Birkbeck College, London, who had been hounded out of his homeland during the McCarthy "Red Scare" inquisitions, came up with a variation on the EPR experiment that paved the way for further progress in the matter.[5] Instead of using two properties, position and momentum, as in the original version, Bohm focused on just one: the property known as spin.

The spin of subatomic particles, such as electrons, is analogous to spin in the everyday world but with a few important differences. Crudely speaking, an electron can be thought of as spinning around the way a basketball does on top of an athlete's finger. But whereas spinning basketballs eventually slow down, all electrons in the universe, whatever their circumstances, spin all the time and at exactly the same rate. What's more, they can only spin in one of two directions, clockwise or counterclockwise, referred to as spin-up and spin-down.

Bohm's revised EPR thought experiment starts with the creation, in a single event, of two particles with opposite spin. This means that if we measure particle A and find that its spin-up, then, from that point on, B must be spin-down. The only other possible result is that A is measured to be spin-up, which forces B to be spin-down. Taking this second case as an example, we're not to infer, says quantum mechanics, that A was spin-up before we measured it and therefore that B was spin-down, in a manner similar to a coin being heads or tails. Quantum interactions always produce superpositions. The state of each particle in Bohm's revised EPR scenario is a mixed superposition that we can write as: psi = (A spin-up and B spin-down) + (A spin-down + B spin-up). A measurement to determine A's spin causes this wave function to collapse and a random choice to be made of spin-up or spin-down. At that very same moment, B also ceases to be in a superposition of states and assumes the opposite spin.

This is the standard quantum mechanical view of the situation and it leads to the same kind of weird conclusion that troubled Einstein and friends. No matter how widely separated the spinning pair of particles may be, measuring the spin of one causes the wave function of the combined system to collapse instantaneously so that the unmeasured twin assumes a definite (opposite) spin state, too. The mixed superposition of states, which is the hallmark of entanglement, ensures nonlocality. Set against this is the Einsteinian view that "spooky action at a distance" stems not from limitations about what the universe is able to tell us but instead from limitations in our current knowledge of science. At a deeper, more basic level than that of wave functions and complementary properties, are hidden variables that will restore determinism and locality to physics.


John Bell's inequality

John Stewart Bell at CERN


Bohm's new version of the EPR paradox didn't in itself offer a way to test these radically different worldviews, but it set the scene for another conceptual breakthrough that did eventually lead to a practical experiment. This breakthrough came in 1964 from Irish physicist, John S. Bell, who worked at CERN, the European center for high-energy particle research in Switzerland. Colleagues considered Bell to be the only physicist of his generation to rank with the pioneers of quantum mechanics, such as Niels Bohr and Max Born, in the depth of his philosophical understanding of the implications of the theory. What Bell found is that it makes an experimentally observable difference whether the particles described in the EPR experiment have definite properties before measurement, or whether they're entangled in a ghostlike hybrid reality that transcends normal ideas of space and time.

Bell's test hinges on the fact that a particle's spin can be measured independently in three directions, conventionally called x, y, and z, at right angles to one another. If you measure the spin of particle A along the x direction, for example, this measurement also affects the spin of entangled particle B in the x direction, but not in the y and z directions. In the same way, you can measure the spin of B in, say, the y direction without affecting A's spin along x or z. Because of these independent readings, it's possible to build up a picture of the complementary spin states of both particles. Being a statistical effect, lots of measurements are needed in order to reach a definite conclusion. What Bell showed is that measurements of the spin states in the x, y, and z directions on large numbers of real particles could in principle distinguish between the local hidden variable hypothesis championed by the Einstein-Bohm camp and the standard nonlocal interpretation of quantum mechanics.

If Einstein was right and particles really did always have a predetermined spin, then, said Bell, a Bohm-type EPR experiment ought to produce a certain result. If the experiment were carried out on many pairs of particles, the number of pairs of particles in which both are measured to be spin-up, in both the x and y directions ("xy up"), is always less than the combined total of measurements showing xz up and yz up. This statement became known as Bell's inequality. Standard quantum theory, on the other hand, in which entanglement and nonlocality are facts of life, would be upheld if the inequality worked the other way around. The decisive factor is the degree of correlation between the particles, which is significantly higher if quantum mechanics rules.

This was big news. Bell's inequality, although the subject of a modest little paper and hardly a poplar rival to the first Beatles tour of America going on at the same time, provided a way to tell by actual experiment which of the two major, opposing visions of subatomic reality was closer to the truth.[6] Bell made no bones about what his analysis revealed: Einstein;s ideas about locality and determinism were incompatible with the predictions of orthodox quantum mechanics. Bell's paper offered a clear alternative that lay between the EPR/Bohemian local hidden variables viewpoint and Bohrian, nonlocal weirdness. The way that Bell's inequality was set up, its violation would mean that the universe was inherently nonlocal*, allowing particles to form and maintain mysterious connections with each other no matter how far apart they were. All that was needed now was for someone to come along and set up an experiment to see for whom Bell's inequality tolled.

But that was easier said than done. Creating, maintaining, and measuring individual entangled particles is a delicate craft, and any imperfection in the laboratory setup masks the subtle statistical correlations being sought. Several attempts were made in the 1970s to measure Bell's inequality but none was completely successful. Then a young French graduate student, Alain Aspect, at the Institute of Optics in Orsay, took up the challenge for his doctoral research.


*  If we want to study the applicability of Classical Probability Theory, i.e. Bayes theorem, to all of quantum mechanics, beyond the Copenhagen interpretation, we have to recognize that quantum entanglement states, such as basic singlet states, are nonfactorizable and therefore will not follow the simple factorizable relations used in proving the consistency of Bayes theorem with quantum probability functions.

This is again a result of the paradox that entanglement is a non-local effect and therefore there isn't any possibility of decomposing/factorizing the density of
states of such an entangled quantum state locally.

Even by applying a locality condition to the Bell inequalities, in the stochastic Clauser-Horne Model say, it can be shown that this (local) model, as far as applied to the singlet-state and without using quantum mechanical formalism, is not completely stochastic (i.e. there are possible configurations for which the model is deterministic). However as soon as you apply quantum mechanical formalism it becomes non-local again.

Even in experiment, where the so-called Clauser-Horne inequalities correspond to the fixed conditional probabilities of light polariser orientations for entangled photon ensembles which have not been identified show that unless they were exactly identical, the different conditional probability values of the photons themselves could not be factorized.

So the paradox is based on non-locality which is in direct contradiction to the pure local cause and effect framework of special relativity. Any theory combined with quantum mechanics becomes non-local, it has to whenever any form of quantum formalism is used. EPR is purely a paradox of relativity, not of quantum mechanics.


First Indirect Evidence of EPR Entanglement 



The first efforts to relate theory and thought experiment with actual experiment came from the pioneering work of Australian physicist John Clive Ward working with British physicist Maurice Pryce along with the work of one of the greatest experimental physicists of the 20th century, Chinese-American Physicist Chien-Shiung Wu.


Their work was on formulating and experimentally verifying the probability amplitude for quantum entanglement was the first attempt to develop a way to find such "spooky actions" in an EPR apparatus.

In a 1947 paper, published in Nature[7], Ward and Pryce were the first to calculate, and use, the probability amplitudes for the polarisation of two entangled photons moving in opposite directions.

For polarisations x and y, Ward derived this probability amplitude to be



which once normalised can be expressed as



where 1 and 2 refer to the two quanta propagating in different directions. Ward's probability amplitude is then applied to derive the correlation of the quantum polarisations of the two photons propagating in opposite directions.

This prediction was experimentally confirmed by Wu and Shaknov in 1950.[8] In current terminology this result corresponds to a pair of entangled photons and is directly relevant to a typical Einstein-Podolsky-Rosen (EPR) paradox


Chien-Shiung Wu – often referred to as Madame Wu or the First Lady of Physics – from the University of Columbia was first to give indirect evidence of entanglement in the laboratory.

She showed an Einstein-type correlation between the polarisation of two well-separated photons, which are tiny localised particles of light.

                                Chien-Shiung Wu at her Columbia University Physics Lab, 1963.

Madame Wu's work led to the confirmation of the Pryce and Ward calculations on the correlation of the quantum polarizations of two photons propagating in opposite directions. This was the first experimental confirmation of quantum results relevant to a pair of entangled photons as applicable to the Einstein-Podolsky-Rosen (EPR) paradox.

However, direct evidence of the EPR paradox, one which would include a complete isolation of local effects and test the effect of nonlocality of quantum phenomina would require a few more decades, until the laser was invented, which allowed the French physicist Alain Aspect to form an experiment that we would recognize today as a quantum entanglement circuit.





Alain Aspect's experiment

                                                        Experimental Physicist Alain Aspect


Aspect was set upon his way by his supervising professor, Bernard d'Espagnat, whose career centered around gathering experimental evidence to uncover the deep nature of reality. "I had the luck," said d'Espagnat, "to discover in my university a young French physicist, Alain Aspect, who was looking for a thesis subject and I suggested that testing the Bell inequalities might be a good idea. I also suggested that he go and talk to Bell, who convinced him it was a good idea and the outcome of this was that quantum mechanics won.”

Aspect's experiment used particles of light – photons – rather than material particles such as electrons or protons. Then, as now, photons are by far the easiest quantum objects from which to produce entangled pairs. There is, however, a minor complication concerning the property that is actually recorded in a photon-measuring experiments such as Aspect's or those of other researchers we'll be talking about later. Both Bell and Bohm presented their theoretical arguments in terms of the particle spin. Photons do have a spin (they're technically known as spin-1 particles), but because they travel at the speed of light, their spin axes always lie exactly along their direction of motion, like that of a spinning bullet shot from a rifle barrel. You can imagine photons to be right-handed or left-handed depending on which way they rotate as you look along their path of approach. What's actually measured in the lab isn't spin, however, but the very closely related property of polarization.

Effectively, polarization is the wavelike property of light that corresponds to the particlelike property of spin. Think of polarization in terms of Maxwell's equations, which tell us that the electric and magnetic fields of a light wave oscillate at right angles to each other and also to the direction in which the light is traveling. The polarization of a photon is the direction of the oscillation of its electric field: up and down, side to side, or any orientation in between. Ordinarily, light consists of photons polarized every which way. But if light is passed through a polarizing filter, like that used in Polaroid sunglasses, only photons with a particular polarization – the one that matches the slant of the filter – can get through. (The same happens if two people make waves by flicking one end of a rope held between them. If they do this through a gap between iron railings only waves that vibrate in the direction of the railings can slip through to the other side.)

Aspect designed his experiment to examine correlations in the polarization of photons produced by calcium atoms – a technique that had already been used by other researchers. He shone laser light onto the calcium atoms, which caused the electrons to jump from the ground state to a higher energy level. As the electrons tumbled back down to the ground state, they cascaded through two different energy states, like a two-step waterfall, emitting a pair of entangled photons – one photon per step – in the process.

                                            
                                                  Illustration of the Aspect Experiment

The photons passed through a slit, known as a collimator, designed to reduce and guide the light beam. Then they fell into an automatic switching device that randomly sent them in one of two directions before arriving, in each case, at a polarization analyzer – a device that recorded their polarization state.

An important consideration in Aspect's setup was the possibility, however small, that information might leak from one photon to its partner. It was important to rule out a scenario in which a photon arrived at a polarization analyzer, found that polarization was being measured along say the vertical direction, and then somehow communicated this information to the other photon. (How this might happen doesn't matter: the important thing was to exclude it as an option.) By carefully setting up the distances through which the photons traveled and randomly assigning the direction in which the polarization would be measured while the photons were in flight, Aspect ensured that under no circumstances could such a communicating signal be sent between photons. The switches operated within 10 nanoseconds, while the photons took 20 nanoseconds to travel the 6.6 meters to the analyzers. Any signal crossing from one analyzer to the other at the speed of light would have taken 40 nanoseconds to complete the journey – much too long to have any effect on the measurement.

In a series of these experiments in the 1980s, Aspect's team showed what most quantum theorists expected all along: Bell's inequality was violated.[9] The result agreed completely with the predictions of standard quantum mechanics and discredited any theories based on local hidden variables. More recent work had backed up this conclusion. What's more, these newer experiments have included additional refinements designed to plug any remaining loopholes in the test. For example, special crystals have enabled experimenters to produce entangled photons that are indistinguishable, because each member of the pair has the same wavelength. Such improvements have allowed more accurate measurements of the correlation between the photons. In all cases, however, the outcomes have upheld Aspect's original discovery. Entanglement and nonlocality are indisputable facts of the world in which we live, even if we may find it uncomfortable or "spooky" as Einstein himself did.

Einstein found it "Spooky" because the experiment is a paradox of special relativity, which is based on the idea of local causality, i.e. in a given event in space-time the distance between cause and effect must be separated by a time lapse which depends on the speed of light. In quantum entanglement a measurement, of spin say, of one particle allows you to know the spin of the other particle without disturbing it, such that the measurement of one particle is imposing an equal, but opposite, property, i.e. spin, on the other.

This is a paradox of special relativity because no events can affect another in a non-local way and must be mediated by signals. However the entangled particles, separated in space, are not separated in time. They both share a common time, however mathematically the time of one particle is real and the other is complex (i.e.using complex or imaginary numbers). So in unifying quantum mechanics with special relativity we get scenarios where, instead of the states being predetermined, one state measures time in a negative frame relative to the other and so cancel each other out.

This is why, in drawing Feynman diagrams in space-time, it appears that antimatter particles move backwards in time relative to the matter particles in pair production events for example. The particles do not travel backwards in time, this is just a consequence of unifying a local theory, special relativity, and a non-local theory, quantum mechanics. The paradox lies within this, as why should the local nature vanish? we know "how" to interpret it but we cannot really know the "why".

Niels Bohr felt as if we have no real right to know the "why", which displeased Einstein as all of his theories relied on a local space-time and to accept quantum correlations means having to violate the cosmic speed limit. Setting up the quantum systems however is determined by local events, the particles must be after all carried under local cause and effect events limited by the speed of light, so the paradox can be ironed out by what sets up the system, i.e. me bringing an entangled partner to the moon and leaving its partner on earth but as for the determination of the states of the particles themselves, in special relativity alone the paradox exists so we must interpret it using quantum mechanical non-locality.

Its kind of like saying "we see the world is flat around us, in a local frame, but by travelling around it, in a non-local frame, we know it is round" - so experimental determination of this effect, which has been done for almost 30 years now, is our equivalent of determining the roundness of the world despite it locally appearing flat in this analogy.

Applications of Quantum Entanglement


The phenomenon of entanglement has already begun to be exploited for practical purposes. In the late 1980s, theoreticians started to see entanglement not just as a puzzle and a way to penetrate more deeply into the mysteries of the quantum world, but also as a resource. Entanglement could be exploited to yield new forms of communication and computing. It was a vital missing link between quantum mechanics and another field of explosive growth: information theory. The proof of nonlocality and the quickly evolving ability to work with entangled particles in the laboratory were important factors in the birth of a new science. Out of the union of quantum mechanics and information theory sprang quantum information science – the fast-developing field whose most important fields of development are quantum cryptography, quantum teleportation, and quantum computers.

To see some of the applications of quantum entanglement in the context of quantum computer technology, see my article on quantum computer physics and architecture.

To see a nice example of merging quantum information theory with game theory see my short article here

References


Einstein, A., B. Podolsky, and N. Rosen. "Can a quantum-mechanical description of physical reality be considered incomplete? Physical Review 47 (1935): 777-80.

Schrödinger, E. "Discussion of probability relations between separated systems." Proceedings of the Cambridge Philosophical Society 31 (1935): 555-63.

Scully, M. O., B. G. Englert, and H. Walther. "Quantum optical tests of complimentarity." Nature 351 (1991): 111-16.

Dürr, S., T. Nonn, and G. Rempe. "Origin of QM complementarity probed by a 'which-way' experiment in an atom interferometer." Nature 395 (1998): 33.

Bohm, D. "A suggested reinterpretation of quantum theory in terms of hidden variables." Physical Review 85 (1952): 611-23.

Bell, J. S. "On the Einstein-Podolsky-Rosen paradox." Physics 1 (1964): 195-200.

M. H. L. Pryce and J. C. Ward, Angular correlation effects with annihilation radiation, Nature 160, 435 (1947).

C. S. Wu and I. Shaknov, The angular correlation of scattered annihilation radiation, Phys. Rev. 77, 136 (1950).

Aspect, A. P., P. Grangier, and G. Roger. "Experimental tests of relaistic local theories via Bell's theorem." Physical Review Letters 47 (1981): 460.




Quantum Entanglement Documentary Film, on which this article is based:




Monday, 23 June 2014

Richard Feynman's NASA Space Shuttle Challenger Disaster Report Appendix

Personal observations on the reliability of the Shuttle     
 by R. P. Feynman, 1986.

Richard Feynman With Neil Armstrong at  the Rogers Commission Report Press Conference, June 1986.


Introduction

   It appears that there are enormous differences of opinion as to the
probability of a failure with loss of vehicle and of human life. The
estimates range from roughly 1 in 100 to 1 in 100,000. The higher
figures come from the working engineers, and the very low figures from
management. What are the causes and consequences of this lack of
agreement? Since 1 part in 100,000 would imply that one could put a
Shuttle up each day for 300 years expecting to lose only one, we could
properly ask "What is the cause of management's fantastic faith in the
machinery?"

   We have also found that certification criteria used in Flight
Readiness Reviews often develop a gradually decreasing strictness. The
argument that the same risk was flown before without failure is often
accepted as an argument for the safety of accepting it again. Because
of this, obvious weaknesses are accepted again and again, sometimes
without a sufficiently serious attempt to remedy them, or to delay a
flight because of their continued presence.

   There are several sources of information. There are published criteria
for certification, including a history of modifications in the form of
waivers and deviations. In addition, the records of the Flight
Readiness Reviews for each flight document the arguments used to
accept the risks of the flight. Information was obtained from the
direct testimony and the reports of the range safety officer, Louis
J. Ullian, with respect to the history of success of solid fuel
rockets. There was a further study by him (as chairman of the launch
abort safety panel (LASP)) in an attempt to determine the risks
involved in possible accidents leading to radioactive contamination
from attempting to fly a plutonium power supply (RTG) for future
planetary missions. The NASA study of the same question is also
available. For the History of the Space Shuttle Main Engines,
interviews with management and engineers at Marshall, and informal
interviews with engineers at Rocketdyne, were made. An independent
(Cal Tech) mechanical engineer who consulted for NASA about engines
was also interviewed informally. A visit to Johnson was made to gather
information on the reliability of the avionics (computers, sensors,
and effectors). Finally there is a report "A Review of Certification
Practices, Potentially Applicable to Man-rated Reusable Rocket
Engines," prepared at the Jet Propulsion Laboratory by N. Moore, et
al., in February, 1986, for NASA Headquarters, Office of Space
Flight. It deals with the methods used by the FAA and the military to
certify their gas turbine and rocket engines.  These authors were also
interviewed informally.

Solid Rockets (SRB)

   An estimate of the reliability of solid rockets was made by the range
safety officer, by studying the experience of all previous rocket
flights. Out of a total of nearly 2,900 flights, 121 failed (1 in
25). This includes, however, what may be called, early errors, rockets
flown for the first few times in which design errors are discovered
and fixed. A more reasonable figure for the mature rockets might be 1
in 50. With special care in the selection of parts and in inspection,
a figure of below 1 in 100 might be achieved but 1 in 1,000 is
probably not attainable with today's technology. (Since there are two
rockets on the Shuttle, these rocket failure rates must be doubled to
get Shuttle failure rates from Solid Rocket Booster failure.)

   NASA officials argue that the figure is much lower. They point out
that these figures are for unmanned rockets but since the Shuttle is a
manned vehicle "the probability of mission success is necessarily very
close to 1.0." It is not very clear what this phrase means. Does it
mean it is close to 1 or that it ought to be close to 1? They go on to
explain "Historically this extremely high degree of mission success
has given rise to a difference in philosophy between manned space
flight programs and unmanned programs; i.e., numerical probability
usage versus engineering judgment." (These quotations are from "Space
Shuttle Data for Planetary Mission RTG Safety Analysis," Pages 3-1,
3-1, February 15, 1985, NASA, JSC.) It is true that if the probability
of failure was as low as 1 in 100,000 it would take an inordinate
number of tests to determine it ( you would get nothing but a string
of perfect flights from which no precise figure, other than that the
probability is likely less than the number of such flights in the
string so far). But, if the real probability is not so small, flights
would show troubles, near failures, and possible actual failures with
a reasonable number of trials. and standard statistical methods could
give a reasonable estimate. In fact, previous NASA experience had
shown, on occasion, just such difficulties, near accidents, and
accidents, all giving warning that the probability of flight failure
was not so very small. The inconsistency of the argument not to
determine reliability through historical experience, as the range
safety officer did, is that NASA also appeals to history, beginning
"Historically this high degree of mission success..."

   Finally, if we are to replace standard numerical probability usage
with engineering judgment, why do we find such an enormous disparity
between the management estimate and the judgment of the engineers? It
would appear that, for whatever purpose, be it for internal or
external consumption, the management of NASA exaggerates the
reliability of its product, to the point of fantasy.

   The history of the certification and Flight Readiness Reviews will not
be repeated here. (See other part of Commission reports.) The
phenomenon of accepting for flight, seals that had shown erosion and
blow-by in previous flights, is very clear. The Challenger flight is
an excellent example. There are several references to flights that had
gone before. The acceptance and success of these flights is taken as
evidence of safety. But erosion and blow-by are not what the design
expected. They are warnings that something is wrong. The equipment is
not operating as expected, and therefore there is a danger that it can
operate with even wider deviations in this unexpected and not
thoroughly understood way. The fact that this danger did not lead to a
catastrophe before is no guarantee that it will not the next time,
unless it is completely understood. When playing Russian roulette the
fact that the first shot got off safely is little comfort for the
next. The origin and consequences of the erosion and blow-by were not
understood. They did not occur equally on all flights and all joints;
sometimes more, and sometimes less.  Why not sometime, when whatever
conditions determined it were right, still more leading to
catastrophe?

  In spite of these variations from case to case, officials behaved as
if they understood it, giving apparently logical arguments to each
other often depending on the "success" of previous flights. For
example. in determining if flight 51-L was safe to fly in the face of
ring erosion in flight 51-C, it was noted that the erosion depth was
only one-third of the radius. It had been noted in an experiment
cutting the ring that cutting it as deep as one radius was necessary
before the ring failed. Instead of being very concerned that
variations of poorly understood conditions might reasonably create a
deeper erosion this time, it was asserted, there was "a safety factor
of three." This is a strange use of the engineer's term ,"safety
factor." If a bridge is built to withstand a certain load without the
beams permanently deforming, cracking, or breaking, it may be designed
for the materials used to actually stand up under three times the
load. This "safety factor" is to allow for uncertain excesses of load,
or unknown extra loads, or weaknesses in the material that might have
unexpected flaws, etc. If now the expected load comes on to the new
bridge and a crack appears in a beam, this is a failure of the
design. There was no safety factor at all; even though the bridge did
not actually collapse because the crack went only one-third of the way
through the beam. The O-rings of the Solid Rocket Boosters were not
designed to erode. Erosion was a clue that something was wrong.
Erosion was not something from which safety can be inferred.

  There was no way, without full understanding, that one could have
confidence that conditions the next time might not produce erosion
three times more severe than the time before. Nevertheless, officials
fooled themselves into thinking they had such understanding and
confidence, in spite of the peculiar variations from case to case. A
mathematical model was made to calculate erosion. This was a model
based not on physical understanding but on empirical curve fitting. To
be more detailed, it was supposed a stream of hot gas impinged on the
O-ring material, and the heat was determined at the point of
stagnation (so far, with reasonable physical, thermodynamic laws). But
to determine how much rubber eroded it was assumed this depended only
on this heat by a formula suggested by data on a similar material. A
logarithmic plot suggested a straight line, so it was supposed that
the erosion varied as the .58 power of the heat, the .58 being
determined by a nearest fit. At any rate, adjusting some other
numbers, it was determined that the model agreed with the erosion (to
depth of one-third the radius of the ring). There is nothing much so
wrong with this as believing the answer! Uncertainties appear
everywhere. How strong the gas stream might be was unpredictable, it
depended on holes formed in the putty. Blow-by showed that the ring
might fail even though not, or only partially eroded through. The
empirical formula was known to be uncertain, for it did not go
directly through the very data points by which it was
determined. There were a cloud of points some twice above, and some
twice below the fitted curve, so erosions twice predicted were
reasonable from that cause alone. Similar uncertainties surrounded the
other constants in the formula, etc., etc. When using a mathematical
model careful attention must be given to uncertainties in the model.

Liquid Fuel Engine (SSME)

  During the flight of 51-L the three Space Shuttle Main Engines all
worked perfectly, even, at the last moment, beginning to shut down the
engines as the fuel supply began to fail. The question arises,
however, as to whether, had it failed, and we were to investigate it
in as much detail as we did the Solid Rocket Booster, we would find a
similar lack of attention to faults and a deteriorating
reliability. In other words, were the organization weaknesses that
contributed to the accident confined to the Solid Rocket Booster
sector or were they a more general characteristic of NASA? To that end
the Space Shuttle Main Engines and the avionics were both
investigated. No similar study of the Orbiter, or the External Tank
were made.

  The engine is a much more complicated structure than the Solid
Rocket Booster, and a great deal more detailed engineering goes into
it. Generally, the engineering seems to be of high quality and
apparently considerable attention is paid to deficiencies and faults
found in operation.

   The usual way that such engines are designed (for military or
civilian aircraft) may be called the component system, or bottom-up
design. First it is necessary to thoroughly understand the properties
and limitations of the materials to be used (for turbine blades, for
example), and tests are begun in experimental rigs to determine
those. With this knowledge larger component parts (such as bearings)
are designed and tested individually. As deficiencies and design
errors are noted they are corrected and verified with further
testing. Since one tests only parts at a time these tests and
modifications are not overly expensive. Finally one works up to the
final design of the entire engine, to the necessary
specifications. There is a good chance, by this time that the engine
will generally succeed, or that any failures are easily isolated and
analyzed because the failure modes, limitations of materials, etc.,
are so well understood. There is a very good chance that the
modifications to the engine to get around the final difficulties are
not very hard to make, for most of the serious problems have already
been discovered and dealt with in the earlier, less expensive, stages
of the process.

   The Space Shuttle Main Engine was handled in a different manner,
top down, we might say. The engine was designed and put together all
at once with relatively little detailed preliminary study of the
material and components.  Then when troubles are found in the
bearings, turbine blades, coolant pipes, etc., it is more expensive
and difficult to discover the causes and make changes. For example,
cracks have been found in the turbine blades of the high pressure
oxygen turbopump. Are they caused by flaws in the material, the effect
of the oxygen atmosphere on the properties of the material, the
thermal stresses of startup or shutdown, the vibration and stresses of
steady running, or mainly at some resonance at certain speeds, etc.?
How long can we run from crack initiation to crack failure, and how
does this depend on power level? Using the completed engine as a test
bed to resolve such questions is extremely expensive. One does not
wish to lose an entire engine in order to find out where and how
failure occurs.  Yet, an accurate knowledge of this information is
essential to acquire a confidence in the engine reliability in use.
Without detailed understanding, confidence can not be attained.

   A further disadvantage of the top-down method is that, if an
understanding of a fault is obtained, a simple fix, such as a new
shape for the turbine housing, may be impossible to implement without
a redesign of the entire engine.

   The Space Shuttle Main Engine is a very remarkable machine. It has
a greater ratio of thrust to weight than any previous engine. It is
built at the edge of, or outside of, previous engineering
experience. Therefore, as expected, many different kinds of flaws and
difficulties have turned up. Because, unfortunately, it was built in
the top-down manner, they are difficult to find and fix. The design
aim of a lifetime of 55 missions equivalent firings (27,000 seconds of
operation, either in a mission of 500 seconds, or on a test stand) has
not been obtained. The engine now requires very frequent maintenance
and replacement of important parts, such as turbopumps, bearings,
sheet metal housings, etc. The high-pressure fuel turbopump had to be
replaced every three or four mission equivalents (although that may
have been fixed, now) and the high pressure oxygen turbopump every
five or six. This is at most ten percent of the original
specification. But our main concern here is the determination of
reliability.

   In a total of about 250,000 seconds of operation, the engines have
failed seriously perhaps 16 times. Engineering pays close attention to
these failings and tries to remedy them as quickly as possible. This
it does by test studies on special rigs experimentally designed for
the flaws in question, by careful inspection of the engine for
suggestive clues (like cracks), and by considerable study and
analysis. In this way, in spite of the difficulties of top-down
design, through hard work, many of the problems have apparently been
solved.

   A list of some of the problems follows. Those followed by an
asterisk (*) are probably solved:

   1.Turbine blade cracks in high pressure fuel turbopumps (HPFTP). (May have been solved.)

   2.Turbine blade cracks in high pressure oxygen turbopumps (HPOTP).

   3.Augmented Spark Igniter (ASI) line rupture.*

   4.Purge check valve failure.*

   5.ASI chamber erosion.*

   6.HPFTP turbine sheet metal cracking.

   7.HPFTP coolant liner failure.*

   8.Main combustion chamber outlet elbow failure.*

   9.Main combustion chamber inlet elbow weld offset.*

  10.HPOTP subsynchronous whirl.*

  11.Flight acceleration safety cutoff system (partial failure in a redundant system).*

  12.Bearing spalling (partially solved).

  13.A vibration at 4,000 Hertz making some engines inoperable, etc.

   Many of these solved problems are the early difficulties of a new
design, for 13 of them occurred in the first 125,000 seconds and only
three in the second 125,000 seconds. Naturally, one can never be sure
that all the bugs are out, and, for some, the fix may not have
addressed the true cause. Thus, it is not unreasonable to guess there
may be at least one surprise in the next 250,000 seconds, a
probability of 1/500 per engine per mission. On a mission there are
three engines, but some accidents would possibly be contained, and
only affect one engine. The system can abort with only two
engines. Therefore let us say that the unknown suprises do not, even
of themselves, permit us to guess that the probability of mission
failure do to the Space Shuttle Main Engine is less than 1/500. To
this we must add the chance of failure from known, but as yet
unsolved, problems (those without the asterisk in the list
above). These we discuss below. (Engineers at Rocketdyne, the
manufacturer, estimate the total probability as 1/10,000. Engineers at
marshal estimate it as 1/300, while NASA management, to whom these
engineers report, claims it is 1/100,000. An independent engineer
consulting for NASA thought 1 or 2 per 100 a reasonable estimate.)

   The history of the certification principles for these engines is
confusing and difficult to explain. Initially the rule seems to have
been that two sample engines must each have had twice the time
operating without failure as the operating time of the engine to be
certified (rule of 2x). At least that is the FAA practice, and NASA
seems to have adopted it, originally expecting the certified time to
be 10 missions (hence 20 missions for each sample). Obviously the best
engines to use for comparison would be those of greatest total (flight
plus test) operating time -- the so-called "fleet leaders." But what
if a third sample and several others fail in a short time? Surely we
will not be safe because two were unusual in lasting longer. The short
time might be more representative of the real possibilities, and in
the spirit of the safety factor of 2, we should only operate at half
the time of the short-lived samples.

   The slow shift toward decreasing safety factor can be seen in many
examples. We take that of the HPFTP turbine blades. First of all the
idea of testing an entire engine was abandoned. Each engine number has
had many important parts (like the turbopumps themselves) replaced at
frequent intervals, so that the rule must be shifted from engines to
components. We accept an HPFTP for a certification time if two samples
have each run successfully for twice that time (and of course, as a
practical matter, no longer insisting that this time be as large as 10
missions). But what is "successfully?" The FAA calls a turbine blade
crack a failure, in order, in practice, to really provide a safety
factor greater than 2. There is some time that an engine can run
between the time a crack originally starts until the time it has grown
large enough to fracture. (The FAA is contemplating new rules that
take this extra safety time into account, but only if it is very
carefully analyzed through known models within a known range of
experience and with materials thoroughly tested. None of these
conditions apply to the Space Shuttle Main Engine.

   Cracks were found in many second stage HPFTP turbine blades. In one
case three were found after 1,900 seconds, while in another they were
not found after 4,200 seconds, although usually these longer runs
showed cracks. To follow this story further we shall have to realize
that the stress depends a great deal on the power level.  The
Challenger flight was to be at, and previous flights had been at, a
power level called 104% of rated power level during most of the time
the engines were operating. Judging from some material data it is
supposed that at the level 104% of rated power level, the time to
crack is about twice that at 109% or full power level (FPL). Future
flights were to be at this level because of heavier payloads, and many
tests were made at this level. Therefore dividing time at 104% by 2,
we obtain units called equivalent full power level (EFPL). (Obviously,
some uncertainty is introduced by that, but it has not been studied.)
The earliest cracks mentioned above occurred at 1,375 EFPL.

   Now the certification rule becomes "limit all second stage blades
to a maximum of 1,375 seconds EFPL." If one objects that the safety
factor of 2 is lost it is pointed out that the one turbine ran for
3,800 seconds EFPL without cracks, and half of this is 1,900 so we are
being more conservative. We have fooled ourselves in three ways. First
we have only one sample, and it is not the fleet leader, for the other
two samples of 3,800 or more seconds had 17 cracked blades between
them. (There are 59 blades in the engine.) Next we have abandoned the
2x rule and substituted equal time. And finally, 1,375 is where we did
see a crack. We can say that no crack had been found below 1,375, but
the last time we looked and saw no cracks was 1,100 seconds EFPL. We
do not know when the crack formed between these times, for example
cracks may have formed at 1,150 seconds EFPL. (Approximately 2/3 of
the blade sets tested in excess of 1,375 seconds EFPL had cracks. Some
recent experiments have, indeed, shown cracks as early as 1,150
seconds.) It was important to keep the number high, for the Challenger
was to fly an engine very close to the limit by the time the flight
was over.

   Finally it is claimed that the criteria are not abandoned, and the
system is safe, by giving up the FAA convention that there should be
no cracks, and considering only a completely fractured blade a
failure. With this definition no engine has yet failed. The idea is
that since there is sufficient time for a crack to grow to a fracture
we can insure that all is safe by inspecting all blades for cracks. If
they are found, replace them, and if none are found we have enough
time for a safe mission. This makes the crack problem not a flight
safety problem, but merely a maintenance problem.

   This may in fact be true. But how well do we know that cracks
always grow slowly enough that no fracture can occur in a mission?
Three engines have run for long times with a few cracked blades (about
3,000 seconds EFPL) with no blades broken off.

   But a fix for this cracking may have been found. By changing the
blade shape, shot-peening the surface, and covering with insulation to
exclude thermal shock, the blades have not cracked so far.

   A very similar story appears in the history of certification of the
HPOTP, but we shall not give the details here.

   It is evident, in summary, that the Flight Readiness Reviews and
certification rules show a deterioration for some of the problems of
the Space Shuttle Main Engine that is closely analogous to the
deterioration seen in the rules for the Solid Rocket Booster.

Avionics

   By "avionics" is meant the computer system on the Orbiter as well
as its input sensors and output actuators. At first we will restrict
ourselves to the computers proper and not be concerned with the
reliability of the input information from the sensors of temperature,
pressure, etc., nor with whether the computer output is faithfully
followed by the actuators of rocket firings, mechanical controls,
displays to astronauts, etc.

   The computer system is very elaborate, having over 250,000 lines of
code. It is responsible, among many other things, for the automatic
control of the entire ascent to orbit, and for the descent until well
into the atmosphere (below Mach 1) once one button is pushed deciding
the landing site desired. It would be possible to make the entire
landing automatically (except that the landing gear lowering signal is
expressly left out of computer control, and must be provided by the
pilot, ostensibly for safety reasons) but such an entirely automatic
landing is probably not as safe as a pilot controlled landing. During
orbital flight it is used in the control of payloads, in displaying
information to the astronauts, and the exchange of information to the
ground. It is evident that the safety of flight requires guaranteed
accuracy of this elaborate system of computer hardware and software.

   In brief, the hardware reliability is ensured by having four
essentially independent identical computer systems. Where possible
each sensor also has multiple copies, usually four, and each copy
feeds all four of the computer lines. If the inputs from the sensors
disagree, depending on circumstances, certain averages, or a majority
selection is used as the effective input. The algorithm used by each
of the four computers is exactly the same, so their inputs (since each
sees all copies of the sensors) are the same. Therefore at each step
the results in each computer should be identical.  From time to time
they are compared, but because they might operate at slightly
different speeds a system of stopping and waiting at specific times is
instituted before each comparison is made. If one of the computers
disagrees, or is too late in having its answer ready, the three which
do agree are assumed to be correct and the errant computer is taken
completely out of the system. If, now, another computer fails, as
judged by the agreement of the other two, it is taken out of the
system, and the rest of the flight canceled, and descent to the
landing site is instituted, controlled by the two remaining
computers. It is seen that this is a redundant system since the
failure of only one computer does not affect the mission. Finally, as
an extra feature of safety, there is a fifth independent computer,
whose memory is loaded with only the programs of ascent and descent,
and which is capable of controlling the descent if there is a failure
of more than two of the computers of the main line four.

   There is not enough room in the memory of the main line computers
for all the programs of ascent, descent, and payload programs in
flight, so the memory is loaded about four time from tapes, by the
astronauts.

   Because of the enormous effort required to replace the software for
such an elaborate system, and for checking a new system out, no change
has been made to the hardware since the system began about fifteen
years ago. The actual hardware is obsolete; for example, the memories
are of the old ferrite core type. It is becoming more difficult to
find manufacturers to supply such old-fashioned computers reliably and
of high quality. Modern computers are very much more reliable, can run
much faster, simplifying circuits, and allowing more to be done, and
would not require so much loading of memory, for the memories are much
larger.

   The software is checked very carefully in a bottom-up
fashion. First, each new line of code is checked, then sections of
code or modules with special functions are verified. The scope is
increased step by step until the new changes are incorporated into a
complete system and checked. This complete output is considered the
final product, newly released. But completely independently there is
an independent verification group, that takes an adversary attitude to
the software development group, and tests and verifies the software as
if it were a customer of the delivered product. There is additional
verification in using the new programs in simulators, etc. A discovery
of an error during verification testing is considered very serious,
and its origin studied very carefully to avoid such mistakes in the
future. Such unexpected errors have been found only about six times in
all the programming and program changing (for new or altered payloads)
that has been done. The principle that is followed is that all the
verification is not an aspect of program safety, it is merely a test
of that safety, in a non-catastrophic verification. Flight safety is
to be judged solely on how well the programs do in the verification
tests. A failure here generates considerable concern.

   To summarize then, the computer software checking system and
attitude is of the highest quality. There appears to be no process of
gradually fooling oneself while degrading standards so characteristic
of the Solid Rocket Booster or Space Shuttle Main Engine safety
systems. To be sure, there have been recent suggestions by management
to curtail such elaborate and expensive tests as being unnecessary at
this late date in Shuttle history. This must be resisted for it does
not appreciate the mutual subtle influences, and sources of error
generated by even small changes of one part of a program on
another. There are perpetual requests for changes as new payloads and
new demands and modifications are suggested by the users. Changes are
expensive because they require extensive testing. The proper way to
save money is to curtail the number of requested changes, not the
quality of testing for each.

   One might add that the elaborate system could be very much improved
by more modern hardware and programming techniques. Any outside
competition would have all the advantages of starting over, and
whether that is a good idea for NASA now should be carefully
considered.

   Finally, returning to the sensors and actuators of the avionics
system, we find that the attitude to system failure and reliability is
not nearly as good as for the computer system. For example, a
difficulty was found with certain temperature sensors sometimes
failing. Yet 18 months later the same sensors were still being used,
still sometimes failing, until a launch had to be scrubbed because two
of them failed at the same time. Even on a succeeding flight this
unreliable sensor was used again. Again reaction control systems, the
rocket jets used for reorienting and control in flight still are
somewhat unreliable. There is considerable redundancy, but a long
history of failures, none of which has yet been extensive enough to
seriously affect flight. The action of the jets is checked by sensors,
and, if they fail to fire the computers choose another jet to
fire. But they are not designed to fail, and the problem should be
solved.

Conclusions

   If a reasonable launch schedule is to be maintained, engineering
often cannot be done fast enough to keep up with the expectations of
originally conservative certification criteria designed to guarantee a
very safe vehicle. In these situations, subtly, and often with
apparently logical arguments, the criteria are altered so that flights
may still be certified in time. They therefore fly in a relatively
unsafe condition, with a chance of failure of the order of a percent
(it is difficult to be more accurate).

   Official management, on the other hand, claims to believe the
probability of failure is a thousand times less. One reason for this
may be an attempt to assure the government of NASA perfection and
success in order to ensure the supply of funds. The other may be that
they sincerely believed it to be true, demonstrating an almost
incredible lack of communication between themselves and their working
engineers.

   In any event this has had very unfortunate consequences, the most
serious of which is to encourage ordinary citizens to fly in such a
dangerous machine, as if it had attained the safety of an ordinary
airliner. The astronauts, like test pilots, should know their risks,
and we honor them for their courage. Who can doubt that McAuliffe was
equally a person of great courage, who was closer to an awareness of
the true risk than NASA management would have us believe?

   Let us make recommendations to ensure that NASA officials deal in a
world of reality in understanding technological weaknesses and
imperfections well enough to be actively trying to eliminate
them. They must live in reality in comparing the costs and utility of
the Shuttle to other methods of entering space. And they must be
realistic in making contracts, in estimating costs, and the difficulty
of the projects. Only realistic flight schedules should be proposed,
schedules that have a reasonable chance of being met. If in this way
the government would not support them, then so be it. NASA owes it to
the citizens from whom it asks support to be frank, honest, and
informative, so that these citizens can make the wisest decisions for
the use of their limited resources.

For a successful technology, reality must take precedence over
public relations, for nature cannot be fooled.

                                   Space Shuttle Challenger Disaster. Date: January 28th, 1986