11.2 ESDS Damage Mechanisms: Catastrophic versus Latent Failures
Key Takeaways
- Catastrophic ESD damage is an immediate functional failure: a dead LRU, a failed power-on built-in test, an open or shorted pin, or a fully punctured gate oxide.
- Latent ESD damage is partial: the device still works at test, but oxide leakage, threshold shift or reduced remaining ESD withstand remain.
- Latent damage is airworthiness-dangerous because a weakened CMOS LRU can be released after Certificate of Release to Service and then fail in flight, often returning from the shop as no fault found.
- Ordinary BITE and go/no-go tests prove present function, not an undamaged gate oxide; a unit that still works is not evidence that handling was acceptable.
- The same unprotected pin touch can produce either outcome, so procedures treat every unrecorded discharge as a potential latent defect.
11.2 ESDS Damage Mechanisms: Catastrophic versus Latent Failures
The former detailed Appendix I description for 5.12 paired risks and damage from improper handling with special handling. The airworthiness trap is not only the module that is dead on the bench. It is the module that still works after a discharge, is released to service, and then fails in flight. That second outcome is latent ESD damage. This section distinguishes it from catastrophic failure, names the silicon mechanisms, and explains why ordinary BITE and a green functional test do not make an unrecorded handling event safe.
Knowledge levels remain A/B3 level 1 (recognise that improper handling can destroy or weaken ESDS) and B1/B2 level 2 (explain catastrophic versus latent outcomes and why latent damage is the more dangerous maintenance product).
Catastrophic ESD failure
A catastrophic ESD event produces an immediate, detectable loss of function. Typical signatures:
- The component or LRU will not power up, will not initialise, or fails power-on built-in test (PBIT).
- A pin is shorted to ground or to another pin, or is open because a bond wire or metallisation track has fused.
- A MOS gate oxide is punctured so that the gate leaks heavily or is stuck, and the logic node never switches.
- In severe pulses, a visible crater, discoloured passivation or a blown input network appears under a microscope; the line technician usually sees only a dead box.
Catastrophic damage is operationally painful — an EFIS display computer that dies during a ramp test delays the aircraft — but it is honest. The defect is present before Certificate of Release to Service (CRS). Troubleshooting, replacement and shop screening can contain it.
Physical paths to a hard fail include:
-
Gate-oxide rupture. The electric field exceeds dielectric strength (section 11.1). A filament of silicon or melted oxide shorts the gate to the channel. Gate current, which should be picoamperes, becomes microamperes to milliamperes. The transistor is no longer a voltage-controlled device.
-
Junction burnout. HBM or CDM current crowds into a small diode or parasitic bipolar structure. Local temperature exceeds the aluminium–silicon eutectic (about 577 °C) or melts silicon. The junction becomes a short or a leaky mess.
-
Metallisation melt and contact spiking. Energy ½CV² dumped into a narrow metal track vaporises aluminium. The circuit opens. This needs more energy than a thin-oxide puncture, so it is more typical of higher-voltage or lower-resistance pulses (machine-like or CDM).
-
Protection-network sacrifice. Clamp diodes at the pad take the hit and fail short or open. The input is then dead even if the internal gates never saw the full voltage.
Latent ESD damage
Latent damage is partial. The device still performs its function at the moment of test, within specification or close enough to pass a go/no-go procedure, but the silicon has been weakened.
Typical latent mechanisms:
- A partial oxide puncture that has not yet grown into a full short. Leakage is elevated (nanoamperes instead of picoamperes). Threshold voltage has shifted by tens of millivolts. The gate still switches today.
- A junction with a reduced remaining ESD withstand. The next ordinary handling event, or a smaller in-service transient, finishes the job.
- Parametric drift: increased input leakage on an analogue pin, reduced noise margin on a CMOS input, a timing path that only fails at high temperature or low aircraft bus voltage.
- Intermittent behaviour under vibration or thermal cycling as a damaged filament opens and closes.
The technician’s experience of latent damage is infuriatingly ordinary: the unit passed the AMM functional test, the aircraft flew, and hours or cycles later the same computer logs a hard fault, a blank display or a spurious comparator disagree. Replacing the box appears to fix the snag. The shop may even fail to reproduce the fault on the bench if the filament has changed state. Nothing in that story looks like a classic electrostatic puncture — which is why shops that skip EPA discipline generate untraceable repeat defects.
Worked scenario — latent failure after an unrecorded discharge
A B2 technician removes a CMOS-based display processor from an EFIS rack on a dry winter day, holding the connector body and brushing the pins across a nylon cuff. No wrist strap is worn. The unit is carried to a plastic-covered bench, tested, and found serviceable. It is refitted. Twenty-two flight hours later the display blanks on approach; PBIT now fails.
A possible physical timeline:
- A few-kilovolt HBM-like pulse (section 11.1) injects ampere-class current into an input clamp and stresses a 16 V-class gate oxide.
- The oxide does not form a dead short. Leakage rises. A protection diode is partially melted.
- At shop ambient, with the 28 V rail high and no vibration, the logic still meets timing. Functional test passes.
- In service, cabin temperature cycles, the rail sags during engine start, and vibration works the damaged site. The leakage path avalanches into a catastrophic short. The failure appears random.
The airworthiness point is not the last short. It is the release of a damaged article as serviceable.
Why latent damage is airworthiness-dangerous
Catastrophic ESD failure keeps the aircraft on the ground or returns it to maintenance with a clear defect. Latent ESD damage does the opposite:
| Question | Catastrophic ESD damage | Latent ESD damage |
|---|---|---|
| When does the function fail? | Immediately, at the handling event or at the next power-up | Later, in service, often after a successful test |
| Will BITE or an AMM functional test catch it? | Usually yes | Often no — the parametric shift is inside pass limits |
| Dispatch risk | Low once the failed unit is isolated | High: the aircraft may be released with a hidden defect |
| Repeatability in the shop | High | Poor; no fault found (NFF) is common |
| Typical maintenance product | A known unserviceable LRU | An unreliable LRU and a misleading NFF history |
| Safety implication | Delay and cost | Possible loss of a display, computer or sensor function after CRS |
A no-fault-found shop visit after an in-service blanking event is a classic ESD-latent pattern, especially when the same part number repeats. Treating NFF as the aircraft imagined it, without reviewing handling, packaging and EPA logs, is how latent damage becomes a fleet reliability and safety problem rather than a single dead integrated circuit.
Latent damage is dangerous because:
- It defeats the test you trust. PBIT, BITE and many functional tests prove that the box works now, not that the oxide is undamaged.
- It is not logged. The discharge was invisible. There is no fault code for a technician’s cuff at 4 kV on pin 17.
- It can sit in a spare. A module zapped in stores, then fitted months later, transfers the defect onto an aircraft that never had an avionics snag.
- It can be progressive. Each extra unprotected handling event lowers the remaining withstand until a small in-service transient completes the failure.
- It attacks systems whose loss is operationally serious. EFIS, FMS, FADEC computers, radios and air-data modules are CMOS-rich. A latent defect in a display computer is not a cabin-light nuisance.
[!WARNING] Do not use a unit that still works as evidence that handling was acceptable. A passed functional test after unprotected handling is consistent with latent damage. The correct response is to stop the practice, not to argue from a green light.
Improper handling that produces each outcome
The same physics (section 11.1) feeds both outcomes; the difference is how much of the oxide or junction is consumed.
High-risk acts:
- Touching pins, connector contacts or board edge connectors rather than the case (section 11.3).
- Removing a device from a shielding bag before a wrist strap is connected, or placing a naked board on an insulator (plastic, painted wood, polystyrene).
- Sliding an LRU across a seat, carpet or vinyl cover.
- Using ordinary polyethylene bubble wrap or adhesive tape near exposed modules.
- Stacking bare cards so that one board’s charged surface discharges into another’s pins.
- Working outside an EPA because the aircraft is composite or the rack is earthed while the person is not bonded.
A large, low-resistance pulse (CDM from a charged board onto an earthed pin, or a metal tool) is more likely to be catastrophic. A smaller HBM event from a person who only brushed the connector is a typical latent recipe. You cannot choose the outcome in the hangar, which is why procedures assume every unprotected event is a potential latent defect, not only a possible dead box.
B2 and B1 candidates should be able to define both damage classes, explain the oxide-filament picture, and state why latent damage after CRS is the airworthiness-critical risk. Category A and B3 candidates should know that mishandling can destroy a unit now or make it fail later, and that a unit which still lights up is not automatically undamaged.
How does latent ESDS damage differ from catastrophic ESDS damage?
Why is latent ESD damage particularly dangerous for airworthiness?
Which outcome is characteristic of catastrophic ESD damage to a CMOS avionics LRU?
After unprotected handling, a CMOS display computer still passes the AMM functional test. What is the correct interpretation?