The thing I wish someone had hammered into me earlier is that damage tolerance starts with a choice, and the choice happens way before any analysis. The regs (FAR/CS 25.571, and on the military side MIL-STD-1530 with the old MIL-A-83444 thinking underneath it) hand you a short menu of ways to show the structure stays safe with a flaw already in it. For most metallic primary structure it comes down to two: slow crack growth, or fail-safe. People treat these as interchangeable. They really aren’t. They’re two different promises about how the part behaves once it has a crack, and they pull you toward different load cases, different tests, different inspection programmes.
Slow crack growth is the lonely one. A crack grows in a single load path, slowly and stably enough that you can inspect it out before it gets to critical size. There’s no backup. The whole argument rests on a believable starting flaw, a growth curve you actually trust, and an inspection interval the operator can really fly. Miss the inspection or get the curve wrong and the part is gone. No safety net.
Fail-safe buys safety a different way. You arrange the structure so that after one member lets go (or a crack arrests at a feature you designed for it), load redistributes and what’s left still carries a defined residual-strength load until the next inspection. Crack stoppers, tear straps, multiple spars. You pay for it in mass and part count, and in return you get to do a much gentler inspection.
So why decide first? Because the two don’t land on the same model. Slow-crack-growth thinking sends you hunting for the worst single detail. Fail-safe thinking sends you to the load path that has to pick up the slack after something breaks, which is often somewhere else entirely. Fail-safe also needs the broken-element case with the right dynamic factor on the redistributed load, and slow crack growth never asks for that. The residual-strength requirement is different. The inspection programme you’re selling the operator is completely different. Pick the philosophy late and you re-run all of it.
For the slow-crack-growth interval the logic is pretty mechanical and worth carrying in your head:
Set the initial flaw, usually a rogue/manufacturing flaw per the cert basis. The classic is a quarter-circular corner crack at a fastener hole (the public MIL-A-83444-lineage sizes are 0.05 in for the primary flaw, 0.005 in for continuing damage).
Find the critical crack length a_c from residual strength, the size where K reaches K_c (or net section gives up) under the residual-strength load.
Integrate the growth curve, and keep two intervals separate because they answer different questions. Initial-flaw-to-critical life over a factor (usually 2) sets the threshold, when the first inspection is due. The recurring interval is the detectable-to-critical leg over the same factor, so that any crack reaching detectable size gets two looks before it can reach critical. That factor is basically the entire safety argument; it’s why one missed inspection doesn’t lose the aircraft.
Growth is da/dN = C·(ΔK)^m in the Paris regime, with the usual constants. Real spectra spend most of the time down near threshold and most of the length in the last few percent where things run away toward K_c, so the integral is dominated by the small-crack end for life and the big-crack end for the critical size. Get either end wrong and the interval is wrong.
The whole slow-crack-growth argument: catch the crack between detectable and critical, with a factor of 2 so two inspections bracket the window.
Where I tend to land: on monolithic stuff, a machined bulkhead, a one-piece spar cap, I lean slow crack growth, because real redundancy costs mass you usually don’t have on a fighter. The catch is that your NDI capability (the smallest crack you can reliably find, the 90/95 PoD size) becomes a load-bearing part of the certification rather than a footnote. On built-up structure, multi-spar wings, skin-stringer fuselage, the redundancy is often already sitting there in the architecture and fail-safe is the natural fit. Then the job is proving the redundancy is real, that load genuinely redistributes, that the arrest feature actually arrests. On a CS-23 trainer that built-up redundancy is frequently the only thing that makes the cert tractable at all.
Anyway. The first thing you owe on one of these tasks is a sentence, not a number: “this region is substantiated by slow crack growth, because…”. Get that agreed with the chief engineer and the authority before you build anything, and most of the rest follows from it. (Easier said than done when the loads aren’t frozen yet, but that’s a different gripe.)
esc
✦
Ask my CV
AI
Hi — I answer questions about Berkay's CV, projects and skills.
Türkçe de sorabilirsiniz.