Search NASASearch

Engineering topics

Degani, Asaf

Publications and source records attributed to Degani, Asaf.

At least 19 records

Designing Flightdeck Procedures: Literature Resources

This technical publication contains the titles, abstracts, summaries, descriptions, and/or annotations of available literature sources on procedure design and development, requirements, and guidance. It is designed to provide users with an easy access to available resources on the topic of procedure design, and with a sense of the contents of these sources. This repository of information is organized into the following publication sources: Research (e.g., journal articles, conference proceedings), Manufacturers' (e.g., operation manuals, newsletters), and Regulatory and/or Government (e.g., advisory circulars, reports). An additional section contains synopses of Accident/Incident Reports involving procedures. This work directly supports a comprehensive memorandum by Barshi, Mauro, Degani, & Loukopoulou (2016) that summarizes the results of a multi-year project, partially funded by the FAA, to develop technical reference materials that support guidance on the process of developing cockpit procedures (see "Designing Flightdeck Procedures" https://ntrs.nasa.gov/archive/nasa/casi.ntrs.nasa.gov/20160013263.pdf). An extensive treatment of this topic is presented in a forthcoming book by the same authors.

flightdeck

Designing Flightdeck Procedures

The primary goal of this document is to provide guidance on how to design, implement, and evaluate flight deck procedures. It provides a process for developing procedures that meet clear and specific requirements. This document provides a brief overview of: 1) the requirements for procedures, 2) a process for the design of procedures, and 3) a process for the design of checklists. The brief overview is followed by amplified procedures that follow the above steps and provide details for the proper design, implementation and evaluation of good flight deck procedures and checklists.

checklists

On Organization of Information: Approach and Early Work

In this report we describe an approach for organizing information for presentation and display. "e approach stems from the observation that there is a stepwise progression in the way signals (from the environment and the system under consideration) are extracted and transformed into data, and then analyzed and abstracted to form representations (e.g., indications and icons) on the user interface. In physical environments such as aerospace and process control, many system components and their corresponding data and information are interrelated (e.g., an increase in a chamber s temperature results in an increase in its pressure). "ese interrelationships, when presented clearly, allow users to understand linkages among system components and how they may affect one another. Organization of these interrelationships by means of an orderly structure provides for the so-called "big picture" that pilots, astronauts, and operators strive for.

Degani, Asaf

Designing Flight Deck Procedures

Three reports address the design of flight-deck procedures and various aspects of human interaction with cockpit systems that have direct impact on flight safety. One report, On the Typography of Flight- Deck Documentation, discusses basic research about typography and the kind of information needed by designers of flight deck documentation. Flight crews reading poorly designed documentation may easily overlook a crucial item on the checklist. The report surveys and summarizes the available literature regarding the design and typographical aspects of printed material. It focuses on typographical factors such as proper typefaces, character height, use of lower- and upper-case characters, line length, and spacing. Graphical aspects such as layout, color coding, fonts, and character contrast are discussed; and several cockpit conditions such as lighting levels and glare are addressed, as well as usage factors such as angular alignment, paper quality, and colors. Most of the insights and recommendations discussed in this report are transferable to paperless cockpit systems of the future and computer-based procedure displays (e.g., "electronic flight bag") in aerospace systems and similar systems that are used in other industries such as medical, nuclear systems, maritime operations, and military systems.

Degani, Asaf

UIVerify: A Web-Based Tool for Verification and Automatic Generation of User Interfaces

In this poster, we describe a web-based tool for verification and automatic generation of user interfaces. The verification component of the tool accepts as input a model of a machine and a model of its interface, and checks that the interface is adequate (correct). The generation component of the tool accepts a model of a given machine and the user's task, and then generates a correct and succinct interface. This write-up will demonstrate the usefulness of the tool by verifying the correctness of a user interface to a flight-control system. The poster will include two more examples of using the tool: verification of the interface to an espresso machine, and automatic generation of a succinct interface to a large hypothetical machine.

Shiffman, Smadar

On Abstractions and Simplifications in the Design of Human-Automation Interfaces

This report addresses the design of human-automation interaction from a formal perspective that focuses on the information content of the interface, rather than the design of the graphical user interface. It also addresses the issue of the information provided to the user (e.g., user-manuals, training material, and all other resources). In this report, we propose a formal procedure for generating interfaces and user-manuals. The procedure is guided by two criteria: First, the interface must be correct, that is, with the given interface the user will be able to perform the specified tasks correctly. Second, the interface should be succinct. The report discusses the underlying concepts and the formal methods for this approach. Two examples are used to illustrate the procedure. The algorithm for constructing interfaces can be automated, and a preliminary software system for its implementation has been developed.

Heymann, Michael

Formal verification of human-automation interaction

This paper discusses a formal and rigorous approach to the analysis of operator interaction with machines. It addresses the acute problem of detecting design errors in human-machine interaction and focuses on verifying the correctness of the interaction in complex and automated control systems. The paper describes a systematic methodology for evaluating whether the interface provides the necessary information about the machine to enable the operator to perform a specified task successfully and unambiguously. It also addresses the adequacy of information provided to the user via training material (e.g., user manual) about the machine's behavior. The essentials of the methodology, which can be automated and applied to the verification of large systems, are illustrated by several examples and through a case study of pilot interaction with an autopilot aboard a modern commercial aircraft. The expected application of this methodology is an augmentation and enhancement, by formal verification, of human-automation interfaces.

Aviation

Hybrid Verification of an Interface for an Automatic Landing

Modern commercial aircraft have extensive automation which helps the pilot by performing computations, obtaining data, and completing procedural tasks. The pilot display must contain enough information so that the pilot can correctly predict the aircraft's behavior, while not overloading the pilot with unnecessary information. Human-automation interaction is currently evaluated through extensive simulation. In this paper, using both hybrid and discrete-event system techniques, we show how one could mathematically verify that an interface contains enough information for the pilot to safely and unambiguously complete a desired maneuver. We first develop a nonlinear, hybrid model for the longitudinal dynamics of a large civil jet aircraft in an autoland/go-around maneuver. We find the largest controlled subset of the aircraft's flight envelope for which we can guarantee both safe landing and safe go-around. We abstract a discrete procedural model using this result, and verify a discrete formulation of the pilot display against it. An interface which fails this verification could result in nondeterministic or unpredictable behavior from the pilot's point of view.

Oishi, Meeko

On Abstractions and Simplifications in the Design of Human-Automation Interfaces

This report addresses the design of human-automation interaction from a formal perspective that focuses on the information content of the interface, rather than the design of the graphical user interface. It also addresses the, issue of the information provided to the user (e.g., user-manuals, training material, and all other resources). In this report, we propose a formal procedure for generating interfaces and user-manuals. The procedure is guided by two criteria: First, the interface must be correct, i.e., that with the given interface the user will be able to perform the specified tasks correctly. Second, the interface should be as succinct as possible. The report discusses the underlying concepts and the formal methods for this approach. Several examples are used to illustrate the procedure. The algorithm for constructing interfaces can be automated, and a preliminary software system for its implementation has been developed.

Heymann, Michael

Methodology for Examining the Operator and the System Concurrently: Pilot Interaction with Automation

Complex system description is problematic when considering operator task activities interacting with system dynamics. Engineering languages have matured sufficiently to allow machine system description at various levels of depth and breadth but without operator synergy. Concurrently, Task Analysis methods have evolved along diverse lines enabling a description of the operator in the system from various paradigms but not describing the system. A void exists when attempting to view the system and the operator in the same plane. We propose a methodology employing descriptive languages from different domains viewed in a single dimension. Finite Automata (FA) languages describe the machine system in the proposed approach. Operator task specifications, a form of task analysis output, examine the operator activities within the system. Operator task specifications were then selected for discrete task activities and overlaid on the system description to examine operator inputs and subsequently view system responses. Unexpected (surprise) and undesirable system behavior was expected to emerge from this analysis. In this paper we shall first describe the methodology and show how the two perspectives, machine model and operator task specifications are integrated. Following we describe the process of doing such analysis using an example from cockpit automation. The methodology was employed in the analysis of a new function that was added to an existing automatic flight control system. We begin by defining a flight scenario involving all aspects of pilot interaction with the new function. Then, we proceed to develop a basic model of the machine behavior, in the context of pilot actions. Finally we superimpose the operator task specification on the machine model and perform the analysis. The proposed methodology may have broad appeal to system designers and human factors specialists. A common language for engineers of diverse domains is a strong point of this approach. Systems engineers may not fully understand operational considerations and human limitations, and human factors specialists may not be exposed to the full extent of system behavior. We hope the proposed methodology is adopted by both disciplines and in the process each assimilates a common language to address potential shortcomings of either approach separately.

Austin, David

Formal Analysis of Human Automation Interaction: The Problem of Display Correctness

This presentation attempted to develop a quantitative method for evaluating the effectiveness of autoflight displays. Researchers sought to develop a methodology for evaluation of display correctness and develop a methodology for display synthesis. Topics covered included: mode awareness, industry/research contributions, human-machine interface analysis, research objectives, modeling, flight guidance project and evaluation.

Degani, Asaf

A Formal Approach for Designing and Evaluating Procedures

Operator interaction with modern control systems is a topic of great concern in high-risk industries such as nuclear power and commercial aviation. The issues associated with such systems focus on the ability of the operators (e.g., pilots) to achieve mission goals safely while containing failures. Operators must be able to interact safely and reliably with highly automatic and complex systems across the full spectrum of possible operating conditions, including normal, abnormal, and emergency situations. In environments such as commercial aviation, operator interaction with the machine is specified through a set of standard operating procedures (SOP). A procedure represents a collective agreement on the 'best' way to perform a given task. The intent of this paper is to suggest a formal methodology, for designing and evaluating procedures, that is both reliable and systematic. Our approach involves two major elements: a model of the machine and a list of the operator's task specifications (goals). We use formal modeling paradigms for describing the system and super-imposing on it the operator's tasks. Such paradigms, based on recent frameworks such as Statecharts and Hierarchical Hybrid Machines appear to be adequate methods for analyzing operator interaction with modern control systems. To illustrate this methodology, we model and analyze the sequence of actions for an emergency procedure. The procedure, Irregular Engine Start, for a medium-range aircraft, specifies the sequence of immediate actions that must be performed by the crew to avoid an uncontrolled rise in engine temperature during start-up. A model of engine behavior during a hot start is constructed. It also describes the various actions that can be taken by the crew and the resulting outcomes. The model is then opened up as a tree of all possible action sequences. This action tree allows us to trace the correct sequences necessary to achieve the desired end-goal (secure and shut down of the engine). In conclusion, we argue that the current process of designing and evaluating procedures can be improved. We discuss the implications of this approach for designing and evaluating this and other types of procedures. We conclude with insights about the benefits and limitation of this methodology, and offer suggestions for future research.

Degani, Asaf

Formal Aspects of Human-Automation Interaction

While new versions of automated control systems such as flight guidance systems are introduced at a rapid pace, it is widely recognized that user interaction with these machines is increasingly problematic. One cause for this difficulty that is commonly cited in the literature, is the discrepancy between the machine's behavior and the operator's (e.g., pilot) expectations. This paper discusses a formal approach to the analysis of operator's interaction with complex automated control systems. We focus attention on the issue of interface correctness; that is, on the question whether the display provides adequate information about the machine's configurations (states, modes, and associated parameters) and transitions, so as to enable the operator to successfully perform the specified set of tasks. To perform the analysis several assumptions are made: (1) A complete formal model of the machine's behavior is available (e.g., as a state transition system, or as a hybrid-machine); (2) A specification of operator's tasks is available and can be formally described (e.g., the reliable and predictable transition between activities involved in executing a climb to a new altitude); (3) The pilot is well trained and has a correct 'mental' model of the machine's response-map. By 'comparing' the machine's model with the set of operator's tasks we formally (i.e., mathematically) evaluate two questions: 1) does the machine's output interface (display) enable the operator to determine, unambiguously, what the current configuration (e.g., mode) of the machine is, and 2) does the display enable the operator to determine, unambiguously, what the next configuration of the machine will be, in response to a specified interaction by the operator (e.g., engaging a mode or changing a parameter such as a speed or target altitude). This paper describes a methodology for conducting such an evaluation using examples from automated flight control systems of modem 'glass cockpit' jetliners. Taxonomy of the different types of discrepancies that lead to pilot inability to resolve the current and next configuration of the machine is suggested. Data from incident reports involving 'mode confusion' is used to corroborate these discrepancies. Finally, means for compensating, either by augmenting the display and/or the operator's 'mental model' are briefly mentioned.

Degani, Asaf

Some Formal Aspects of Human-Machine Interaction

While automated control systems such as autopilots and medical devices are introduced at a rapid pace, it is widely recognized that user interaction with these machines is problematic (Abbott, Slotte, & Stimson, 1996). One factor commonly cited in the literature is the discrepancy between the machine's behavior and the user's expectations. Design guidelines to reduce this discrepancy focus on two elements: (1) improvement of the "feedback" about what the automation is actually doing, and (2) improvement of the user's "mental model" of the automation (Norman, 1990; Sarter and Woods, 1995). This presentation describes a methodology for investigating these two elements via a formal (Le., mathematical) approach. The method involves two representations: (1) a finite state model of the machine's behavior (2) a finite state model of the user's knowledge and expectations about the machine's behavior. In the analysis phase we compare these two models and identify discrepancies. Such discrepancies can be compensated by augmenting the display and/or the user's model. A taxonomy of these discrepancies will be discussed using examples from automated Eight control systems of modern "glass cockpit" jetliners.

Degani, Asaf

Mode Transitions in Glass Cockpit Aircraft: Results of a Field Study

One consequence of increased levels of automation in complex control systems is the presence of modes. A mode is a particular configuration of a control system that defines how human command inputs are interpreted. In complex systems, modes also often determine a specific allocation of control authority between the human and automated systems. Even in simple static devices (e.g., electronic watches, word processors), the presence of modes has been found to cause problems in either-the acquisition or production of skilled performance. Many of these problems arise due to the fact that the selection of a mode causes device behavior to be mediated by hidden internal state information. For these simple systems, many of these interaction problems can be solved by the design of appropriate feedback to communicate internal state information to the human operator. In complex dynamic systems, however, the design issues associated with modes seem to trancend the problem of merely communicating internal state information via displayed feedback. In complex supervisory control systems (e.g., aircraft, spacecraft, military command and control), a key function of modes is the selection of a particular configuration of control authority between the human operator and automated control systems. One mode may result in full manual control, another may result in a mix of manual and automatic control, while a third may result in full automatic control over the entire system. The human operator selects an appropriate mode as a function of current goals, operating conditions, and operating procedures. Thus, the operator is put in a position of essentially trying to control two coupled dynamic systems: the target system itself, and also a highly complex suite of automation controlling the target system. From a historical perspective, it should probably not come as a surprise that very little information is available to guide the design of mode-oriented control systems. The topic of function allocation (i.e., the proper division of control authority among human and computer) has a long history in human-machine systems research. Although this research has produced some relevant guidelines, a design approach capable of defining appropriate allocations of control function between the human and automation is not yet available. As a result, the function allocation decision itself has been allocated to the operator, to be performed in real-time, in the operation of mode-oriented control systems. A variety of documented aircraft accidents and incidents suggest that the real-time selection and monitoring of control modes is a weak link in the effective operation of complex supervisory control systems. Research in human-machine systems and human-computer interaction has barely scraped the surface of the problem of understanding how operators manage this task.The purpose of this paper is to present the results of a field study which examined how operators manage mode selection in a complex supervisory control system. Data on mode engagements using the Boeing B757/767 auto-flight system were collected during approach and descent into four major airports in the East Coast of the United States. Protocols documenting mode selection, automatic mode changes, pilot actions, quantitative records of flight-path variables, and verbal reports during and after mode engagements were collected by an observer from the jumpseat. Observations were conducted on two typical trips between three airports. Each trip was be replicated 11 times, which yielded a total of 22 trips and 66 legs on which data were collected. All data collected concerned the same flight numbers, and therefore, the same time of day, same type of aircraft, and identical operational environments (e.g., ATC facilities, weather patterns, traffic flow etc.)

Degani, Asaf

Designing Flight-Deck Procedures

A complex human-machine system consists of more than merely one or more human operators and a collection of hardware components. In order to operate a complex system successfully, the human-machine system must be supported by an organizational infrastructure of operating concepts, rules, guidelines, and documents. The coherency of such operating concepts, in terms of consistency and logic, is vitally important for the efficiency and safety of any complex system. In high-risk endeavors such as aircraft operations, space flight, nuclear power production, manufacturing process control, and military operations, it is essential that such support be flawless, as the price of operational error can be high. When operating rules are not adhered to, or the rules are inadequate for the task at hand, not only will the system's goals be thwarted, but there may also be tragic human and material consequences. To ensure safe and predictable operations, support to the operators, in this case flight crews, often comes in the form of standard operating procedures. These provide the crew with step-by-step guidance for carrying out their operations. Standard procedures do indeed promote uniformity, but they do so at the risk of reducing the role of human operators to a lower level. Management, however, must recognize the danger of over-procedurization, which fails to exploit one of the most valuable assets in the system, the intelligent operator who is "on the scene." The alert system designer and operations manager recognize that there cannot be a procedure for everything, and the time will come in which the operators of a complex system will face a situation for which there is no written procedure. Procedures, whether executed by humans or machines, have their place, but so does human cognition.

Degani, Asaf

Task Analytic Models to Guide Analysis and Design: Use of the Operator Function Model to Represent Pilot-Autoflight System Mode Problems

Task-analytic models structure essential information about operator interaction with complex systems, in this case pilot interaction with the autoflight system. Such models serve two purposes: (1) they allow researchers and practitioners to understand pilots' actions; and (2) they provide a compact, computational representation needed to design 'intelligent' aids, e.g., displays, assistants, and training systems. This paper demonstrates the use of the operator function model to trace the process of mode engagements while a pilot is controlling an aircraft via the, autoflight system. The operator function model is a normative and nondeterministic model of how a well-trained, well-motivated operator manages multiple concurrent activities for effective real-time control. For each function, the model links the pilot's actions with the required information. Using the operator function model, this paper describes several mode engagement scenarios. These scenarios were observed and documented during a field study that focused on mode engagements and mode transitions during normal line operations. Data including time, ATC clearances, altitude, system states, and active modes and sub-modes, engagement of modes, were recorded during sixty-six flights. Using these data, seven prototypical mode engagement scenarios were extracted. One scenario details the decision of the crew to disengage a fully automatic mode in favor of a semi-automatic mode, and the consequences of this action. Another describes a mode error involving updating aircraft speed following the engagement of a speed submode. Other scenarios detail mode confusion at various phases of the flight. This analysis uses the operator function model to identify three aspects of mode engagement: (1) the progress of pilot-aircraft-autoflight system interaction; (2) control/display information required to perform mode management activities; and (3) the potential cause(s) of mode confusion. The goal of this paper is twofold: (1) to demonstrate the use of the operator functio model methodology to describe pilot-system interaction while engaging modes And monitoring the system, and (2) to initiate a discussion of how task-analytic models might inform design processes. While the operator function model is only one type of task-analytic representation, the hypothesis of this paper is that some type of task analytic structure is a prerequisite for the design of effective human-automation interaction.

Degani, Asaf

Modes in Supervisory Control Systems: Structure and Transitions

Mode confusion is becoming a major drawback in operator interaction with systems that allow for multiple levels of automation. This drawback has manifested itself in several mode related accidents and incidents in commercial aviation, military control systems, as well as high technology medical systems. In the domain of commercial aviation, there have been four recent airline accidents, all involving highly automated aircraft, in which mode related problems were present. Mode problems, we argue, stem from three principal factors: (1) mis-identification of the current mode, (2) difficulty in apprehending current mode behavior; and (3) difficulty in predicting the consequences of the next mode transition. This combination of factors may lead to mode confusion and possibly unwanted results. We define in this paper a mode as the system's manner of behavior. Any given system or machine, may have several ways of behaving. A controller, either human or machine, provides the input that triggers the transition from one mode of behavior to another. At any point in time, a machine may be in one mode or another modes are mutually exclusive. Complex systems are typically comprised of several subsystems, or components, each one with its own set of modes. Therefore, the status of the system at any point in time can be described as a vector of all the active modes.

Degani, Asaf