NASA tech often seems to outlive its initial mission length by a massive margin. The Mars rovers spring to mind. It's incredibly impressive, and almost embarrassing! Surely this isn't accidental. Is the kit massively over-specced? Do the uncertainties and risks necessitate such a depth of redundancy that when stuff goes kinda smoothly the thing lasts 9 times longer than it was designed to? Is it a political thing: they set their success criteria low just in case something goes wrong, but actually intend a much longer lifespan?
Sorry if this seems an incredibly cynical way of looking at the world. I actually love all this stuff - I'm just curious if there is a pattern here and what the reason is if so.
In addition to what other people mentioned (if you design something to have a 99.99% chance of lasting x years, it'll probably last some multiple of x), a lot of failures follow what's called a bathtub curve (visual depiction: https://en.m.wikipedia.org/wiki/Bathtub_curve#/media/File%3A...).
Once you can make something work for 1 day, you're past the most dangerous phase.
NASA definitely does overengineer things at the beginning, but it's worth noting that an incredible amount of work goes into keeping these things alive past their end date. For example regularly updating the software to be more efficient so probes can keep functioning and communicating despite having less and less power and being further and further away.
There's also lessons learned once a mission is in progress, like "if we move in this weird pattern we can shake some dust off the solar panels."
Finally, a lot of these missions that continue long past the predicted end date do so with some limitations - maybe going forward a particular sensor is unavailable or certain maneuvers can't be done anymore - but there's still enough to justify keeping the mission going.
If you design so that it has a 99.9999% chance of working for 5 years it's going to work for much longer. It'd be very hard to design it in a way that it didn't.
Overengineering is building in buffers that you didn't actually need. But it may be much later when anyone can prove it.
See also the roman aqueducts. Today we would have used about half as much stone, and they'd be falling apart in our lifetimes. Instead, lucky chunks of them have lasted 20 times as long as anyone ever could have expected to need them.
Designing things such that they don't require/ use steel reinforcement goes a long way towards having a (potentially) indefinite lifespan.
Reinforced concrete and masonry design are underappreciated disciplines of modern engineering, but their Achilles heel is that reinforcement rusts, rust expands, and expansion ruptures. All at relatively accelerated speeds.
Things like the aqueducts weren't necessarily overengineered, they were just designed (mostly) without quickly deteriorating elements, like steel.
Which is to say, 2000 yrs ago, the design of an aqueduct with a 10yr lifespan didn't differ much compared to a hypothetical one with a 100yr or even 1000yr lifespan. At least compared to how things would be done today.
Much of space design seems to be similar, where the minimum requirements aren't that far off from what seems like excessive engineering. But that doesn't necessarily mean anything was "overengineered".
And even if you design everything so it has a 75% chance of working for 5 years, some of the things won't last 5 years, but you'll still only hear about and remember the ones that work for much longer.
But a large part of the cost is not just construction but testing and verification. Not only that it does what it needs to do, but that it survives launch without destroying itself, survives being in a vacuum etc.
Most of that testing is specific to how each individual item was manufactured, so there's little cost saving if any to be had there.
Then there's the price of the launch, and the time on the radio dishes to follow them.
That's actually part of the thinking behind the "faster, better, cheaper" (FBC) policy of NASA in the late 1990s / early 2000s:
The intent of FBC was to decrease the amount of time and cost for each mission and to increase the number of missions and overall scientific results obtained on each mission
That was something of a mixed bag: numerous missions did succeed and returned phenomenal science, but there were also some spectacular and humiliating failures:
In 1999, after the failure of four missions that used the FBC approach for project
management, you commissioned several independent reviews to examine FBC and
mission failures, search for root causes, and recommend changes.
(Both quotes from the transmittal letter for NASA's 2001 report on the policy, as subsequent sentences.)
It turns out that space is an unbelievably unforgiving environment, and attempting to perform repairs, maintenance, tune-ups, and/or mitigations at distances of hundreds of millions or billions of kilometers, often at the end of hours-long round-trip speed-of-light lags, is challenging at best.
At the same time, FBC mitigated risks, and some of the problem may well have been a failure to manage expectations: with FBC, some missions would succeed, whilst others would not. But even in that context, gambling losses on $150 million bets remain painful. (It's worth considering that there have since been numerous failures by other nations attempting various space missions, this isn't a failing of the US alone.)
It's also worth considering that earlier missions, notably Apollo & Skylab, suffered numerous critical incidents, one fatally catastrophic (and that on the ground), but any one of which could have resulted in total mission losses, including lighting strikes on launch, computer failures on Lunar landing (Apollo 11), wiring-induced oxygen tank explosion (Apollo 13, resulting in abort of the planned landing), and failure to deploy Skylab's solar panel and sunsheild. People tend to remember the major incidents of Apollos 1 and 13, but not the numerous other close calls. The US Space Shuttle programme similarly had two catastrophic failures but each occurred within the context of numerous other close calls. The envelope for both error and deviance is vanishingly thin.
Since the early 2000s, NASA have modulated their approach to FBC. Some missions, such as the JWST, are absolute monoliths and relied on extensive and expensive testing and development, which has paid off with absolutely flawless execution of launch and deployment and truly universe-expanding insights. Others, such as the Mars rover programs, have iterated on concepts starting with small, cheap, and simple rovers of limited range to incorporating a "technology demonstrator" in the form of the Ingenuity heliocopter which accompanies the SUV-sized Perseverance rover. The Huygans lander (part of the Saturn-based Cassini mission, landing on the moon Titan), and Galileo probe (part of the Galileo orbiter mission) both rode along with and extended orbiter-probe missions to provide actual contact with planetary or lunar atmosphere and/or surfaces.
More on FBC:
"'Faster, better, and cheaper' at NASA: Lessons learned in managing and accepting risk"
On a real note, it is hard to do accidentally, but very much possible to do on purpose - so much so that it is currrently a driving factor of our evonomies.
I think it's not so much a question of deliberate overspeccing, but more that each of these missions is its own prototype. You're asked to design something to do a small part of the task, but you won't get a chance to try again if it goes wrong. You really really don't want your part to be the reason the mission fails. And you don't get to test your part in the real deployment environment and find out everything you need to know before your design the production part. So you have to design for every eventuality you can foresee, and then add some margin for the events you cannot foresee. So even if the spec is exactly right, to ensure you satisfy the spec first time with the uncertainties of the production environment, you end up producing a part that has as much margin for error as you can get away with in the mass and financial budget. Everyone involved does the same thing, because no-one really knows what the production environment will be like, and no-one wants to be the reason the mission fails. And so you end up with a spacecraft that is as overengineered as possible given the budget, even if it isn't specced that way.
The game is, if you get funding for X years, but you can remain on mission for X+N years, you have an opportunity to get easy funding after your initial funding runs out.
That's a major incentive to over build things. Engineers also love making things better, so, your workforce is defacto onboard with that mission.
And then, there's the issue that, basically every long term mission to space requires bespoke spacecraft. That makes things very, very expensive, but also, presents a requirement to engineer your way around unknown mission requirements. They know what they want to do, but, they don't really know how it'll work in reality. They can test some things, sure, but it's impossible to know every variable.
For instance, you're building a bridge with a 100ft span that's 50ft above the ground at the highest, in an area with a maximum wind speed of 50mph, and a maximum load capacity of 2000 tons of traffic moving 65mph. Now, that's basically enough information to build that bridge.
Now imagine that, you're asked to build that same bridge, but, you don't know how fast the traffic is moving, that's more difficult. Now, in addition to that, you don't know how much wind loading you have to deal with, more difficult still. Now imagine that, your load capacity isn't certain either.
Could you still build the bridge?
Of course you could, but, you'll have to build it with what you think are reasonable requirements. You might do some research into those requirements, but you also might not be able to. Where you end up is, the bridge you build is going to be over built, likely by a significant margin, if you desire to build a successful bridge.
This is the issue with designing spacecraft, you have more questions about requirements than you have answers, and sure, we have more answers than we used to, and the available pool of knowledge has only increased, but many points of uncertainty still remain. Not an unusual engineering problem, we'll get there eventually. It was about 100 years of thinking for us to learn to fly at all, another 100 years to learn how to do it well, and there's still plenty of room for improvement. Space flight will be much the same, and eventually we'll have the space equivalent of the honda civic
I think it’s political. It’s untenable to tell the public that it will work for “15 years with a 95% confidence interval” and have it fail after 14 years. There would be congressional hearings.
But you must give a number, so sandbagging makes sense.
It’s the same thing with telling your wife when you’ll be home…if you say 7pm and it’s 7:05, you’re late and dinner is cold. But if you say 8:30 and it’s 7:05, you’re a hero.
Organizations always react to incentives and all of the above and more are probably at play.
The funding incentives are probably such that failure means leadership is hauled before political theatre and accused of wasting people's taxes Vs say SpaceX where it's let's blow up one more rocket.
The political situation also probably makes it infeasible to ask for or rely on long term program commitments (which is tied to scientist & engineer employment) but once the hardware is already in place, getting extensions is probably quite cheap and non controversial
All these probably incentivize a risk averse and over engineering culture. Of course that benefits science fans, so I'd say more power to them :-)
I guess the problem is lead time. You want overspecced because you get one shot every 10-20 years between design, launch windows and the all too present political angle.
There is certainly a political element, when they tried doing cheaper missions they had two failures in a row which was really embarassing, even though probably if they had stuck with it it would have still worked out cheaper than using the low risk approach.
Mainly though if you design a spacecraft to have a 99% chance of lasting five years it ends up with a pretty high chance of lasting 30 years.
Based on some JPL documentary videos, I recall the engineers involved intentionally over-specced the components on the hopes that the mission would be later extended to go further out into the solar system. Check out the JPL channel on YouTube. There is a video series about the different missions throughout NASA history. Its really worthwhile watching.
Trick I learned from an old wrench: overestimate time and cost, then when you deliver something in half the time and half the cost they'll think you're twice the mechanic.
I'm not sure that's what NASA does, but it certainly doesn't hurt their PR.
Some missions blow up on the launch pad, or fail to reach orbit, or are lost mid-flight, or crash on landing. I wonder if the average actual mission length exceeds the average expected mission length.
NASA tech often seems to outlive its initial mission length by a massive margin. The Mars rovers spring to mind. It's incredibly impressive, and almost embarrassing! Surely this isn't accidental. Is the kit massively over-specced? Do the uncertainties and risks necessitate such a depth of redundancy that when stuff goes kinda smoothly the thing lasts 9 times longer than it was designed to? Is it a political thing: they set their success criteria low just in case something goes wrong, but actually intend a much longer lifespan?
Sorry if this seems an incredibly cynical way of looking at the world. I actually love all this stuff - I'm just curious if there is a pattern here and what the reason is if so.