Search NASASearch

Engineering topics

Johnson, C. W.

Publications and source records attributed to Johnson, C. W..

At least 19 records

Safety Arguments for Next Generation, Location Aware Computing

Concerns over accuracy, availability, integrity, and continuity have limited the integration of Global Positioning System (GPS) and Global Navigation Satellite System (GLONASS) for safety-critical applications. More recent augmentation systems, such as the European Geostationary Navigation Overlay Service (EGNOS) and the North American Wide Area Augmentation System (WAAS) have begun to address these concerns. Augmentation architectures build on the existing GPS/GLONASS infrastructures to support location based services in Safety of Life (SoL) applications. Much of the technical development has been directed by air traffic management requirements, in anticipation of the more extensive support to be offered by GPS III and Galileo. WAAS has already been approved to provide vertical guidance for aviation applications. During the next twelve months, the full certification of EGNOS for SoL applications is expected. This paper discusses similarities and differences between the safety assessment techniques used in Europe and North America.

Johnson, C. W.

A Safety Conundrum Illustrated: Logic, Mathematics, and Science Are Not Enough

In an ideal world, conversations about whether a particular system is safe, or whether a particular method or tool enhances safety, would be emotion-free discussions concentrating on the level of safety required, available evidence, and coherent logical, mathematical, or scientific arguments based on that evidence. In the real world, discussions about safety are often not emotion-free. Political and economic arguments may play a bigger role than logical, mathematical, and scientific arguments, and psychological factors may be as important, or even more important, than purely technical factors. This paper illustrates the conundrum that can result from this clash of the ideal and the real by means of an imagined conversation among a collection of fictional characters representing various types of people who may be participating in a safety discussion.

Holloway, C. M.

How Past Loss of Control Accidents May Inform Safety Cases for Advanced Control Systems on Commercial Aircraft

This paper describes five loss of control accidents involving commercial aircraft, and derives from those accidents three principles to consider when developing a potential safety case for an advanced flight control system for commercial aircraft. One, among the foundational evidence needed to support a safety case is the availability to the control system of accurate and timely information about the status and health of relevant systems and components. Two, an essential argument to be sustained in the safety case is that pilots are provided with adequate information about the control system to enable them to understand the capabilities that it provides. Three, another essential argument is that the advanced control system will not perform less safely than a good pilot.

Holloway, C. M.

The Dangers of Failure Masking in Fault-Tolerant Software: Aspects of a Recent In-Flight Upset Event

On 1 August 2005, a Boeing Company 777-200 aircraft, operating on an international passenger flight from Australia to Malaysia, was involved in a significant upset event while flying on autopilot. The Australian Transport Safety Bureau's investigation into the event discovered that an anomaly existed in the component software hierarchy that allowed inputs from a known faulty accelerometer to be processed by the air data inertial reference unit (ADIRU) and used by the primary flight computer, autopilot and other aircraft systems. This anomaly had existed in original ADIRU software, and had not been detected in the testing and certification process for the unit. This paper describes the software aspects of the incident in detail, and suggests possible implications concerning complex, safety-critical, fault-tolerant software.

Johnson, C. W.

A Look at Aircraft Accident Analysis in the Early Days: Do Early 20th Century Accident Investigation Techniques Have Any Lessons for Today?

In the early years of powered flight, the National Advisory Committee on Aeronautics in the United States produced three reports describing a method of analysis of aircraft accidents. The first report was published in 1928; the second, which was a revision of the first, was published in 1930; and the third, which was a revision and update of the second, was published in 1936. This paper describes the contents of these reports, and compares the method of analysis proposed therein to the methods used today.

Holloway, C. M.

A Longitudinal Analysis of the Causal Factors in Major Maritime Accidents in the USA and Canada (1996-2006)

Accident reports provide important insights into the causes and contributory factors leading to particular adverse events. In contrast, this paper provides an analysis that extends across the findings presented over ten years investigations into maritime accidents by both the US National Transportation Safety Board (NTSB) and Canadian Transportation Safety Board (TSB). The purpose of the study was to assess the comparative frequency of a range of causal factors in the reporting of adverse events. In order to communicate our findings, we introduce J-H graphs as a means of representing the proportion of causes and contributory factors associated with human error, equipment failure and other high level classifications in longitudinal studies of accident reports. Our results suggest the proportion of causal and contributory factors attributable to direct human error may be very much smaller than has been suggested elsewhere in the human factors literature. In contrast, more attention should be paid to wider systemic issues, including the managerial and regulatory context of maritime operations.

Johnson, C. W.

Why System Safety Professionals Should Read Accident Reports

System safety professionals, both researchers and practitioners, who regularly read accident reports reap important benefits. These benefits include an improved ability to separate myths from reality, including both myths about specific accidents and ones concerning accidents in general; an increased understanding of the consequences of unlikely events, which can help inform future designs; a greater recognition of the limits of mathematical models; and guidance on potentially relevant research directions that may contribute to safety improvements in future systems.

Holloway, C. M.

Questioning the Role of Requirements Engineering in the Causes of Safety-Critical Software Failures

Many software failures stem from inadequate requirements engineering. This view has been supported both by detailed accident investigations and by a number of empirical studies; however, such investigations can be misleading. It is often difficult to distinguish between failures in requirements engineering and problems elsewhere in the software development lifecycle. Further pitfalls arise from the assumption that inadequate requirements engineering is a cause of all software related accidents for which the system fails to meet its requirements. This paper identifies some of the problems that have arisen from an undue focus on the role of requirements engineering in the causes of major accidents. The intention is to provoke further debate within the emerging field of forensic software engineering.

Johnson, C. W.

A Technique for Showing Causal Arguments in Accident Reports

In the prototypical accident report, specific findings, particularly those related to causes and contributing factors, are usually written out explicitly and clearly. Also, the evidence upon which these findings are based is typically explained in detail. Often lacking, however, is any explicit discussion, description, or depiction of the arguments that connect the findings and the evidence. That is, the reports do not make clear why the investigators believe that the specific evidence they found necessarily leads to the particular findings they enumerated. This paper shows how graphical techniques can be used to depict relevant arguments supporting alternate positions on the causes of a complex road-traffic accident.

Holloway, C. M.

Distribution of Causes in Selected US Aviation Accident Reports Between 1996 and 2003

This paper describes the results of an independent analysis of the probable and contributory causes of selected aviation accidents in the United States between 1996 and 2003. The purpose of the study was to assess the comparative frequency of a variety of causal factors in the reporting of these adverse events. Although our results show that more of these high consequence accidents were attributed to human error than to any other single factor, a large number of reports also mentioned wider systemic issues, including the managerial and regulatory context of aviation operations. These wider issues are more likely to appear as contributory rather than primary causes in this set of accident reports.

Holloway, C. M.

'Systemic Failures' and 'Human Error' in Canadian TSB Aviation Reports Between 1996 and 2002

This paper describes the results of an independent analysis of the primary and contributory causes of aviation accidents in Canada between 1996 and 2003. The purpose of the study was to assess the comparative frequency of a range of causal factors in the reporting of these adverse events. Our results suggest that the majority of these high consequence accidents were attributed to human error. A large number of reports also mentioned wider systemic issues, including the managerial and regulatory context of aviation operations. These issues are more likely to appear as contributory rather than primary causes in this set of accident reports.

Holloway, C. M.

The Strengths and Weaknesses of Logic Formalisms to Support Mishap Analysis

The increasing complexity of many safety critical systems poses new problems for mishap analysis. Techniques developed in the sixties and seventies cannot easily scale-up to analyze incidents involving tightly integrated software and hardware components. Similarly, the realization that many failures have systemic causes has widened the scope of many mishap investigations. Organizations, including NASA and the NTSB, have responded by starting research and training initiatives to ensure that their personnel are well equipped to meet these challenges. One strand of research has identified a range of mathematically based techniques that can be used to reason about the causes of complex, adverse events. The proponents of these techniques have argued that they can be used to formally prove that certain events created the necessary and sufficient causes for a mishap to occur. Mathematical proofs can reduce the bias that is often perceived to effect the interpretation of adverse events. Others have opposed the introduction of these techniques by identifying social and political aspects to incident investigation that cannot easily be reconciled with a logic-based approach. Traditional theorem proving mechanisms cannot accurately capture the wealth of inductive, deductive and statistical forms of inference that investigators routinely use in their analysis of adverse events. This paper summarizes some of the benefits that logics provide, describes their weaknesses, and proposes a number of directions for future research.

Johnson, C. W.

Modeling Tools for Propulsion Analysis and Computational Fluid Dynamics on the Internet

The existing RocketWeb(TradeMark) Internet Analysis System (httr)://www.iohnsonrockets.com/rocketweb) provides an integrated set of advanced analysis tools that can be securely accessed over the Internet. Since these tools consist of both batch and interactive analysis codes, the system includes convenient methods for creating input files and evaluating the resulting data. The RocketWeb(TradeMark) system also contains many features that permit data sharing which, when further developed, will facilitate real-time, geographically diverse, collaborative engineering within a designated work group. Adding work group management functionality while simultaneously extending and integrating the system's set of design and analysis tools will create a system providing rigorous, controlled design development, reducing design cycle time and cost.

Muss, J. A.

User's manual for rocket combustor interactive design (ROCCID) and analysis computer program. Volume 1: User's manual

The user's manual for the rocket combustor interactive design (ROCCID) computer program is presented. The program, written in Fortran 77, provides a standardized methodology using state of the art codes and procedures for the analysis of a liquid rocket engine combustor's steady state combustion performance and combustion stability. The ROCCID is currently capable of analyzing mixed element injector patterns containing impinging like doublet or unlike triplet, showerhead, shear coaxial, and swirl coaxial elements as long as only one element type exists in each injector core, baffle, or barrier zone. Real propellant properties of oxygen, hydrogen, methane, propane, and RP-1 are included in ROCCID. The properties of other propellants can easily be added. The analysis model in ROCCID can account for the influence of acoustic cavities, helmholtz resonators, and radial thrust chamber baffles on combustion stability. ROCCID also contains the logic to interactively create a combustor design which meets input performance and stability goals. A preliminary design results from the application of historical correlations to the input design requirements. The steady state performance and combustion stability of this design is evaluated using the analysis models, and ROCCID guides the user as to the design changes required to satisfy the user's performance and stability goals, including the design of stability aids. Output from ROCCID includes a formatted input file for the standardized JANNAF engine performance prediction procedure.

Muss, J. A.

User's manual for rocket combustor interactive design (ROCCID) and analysis computer program. Volume 2: Appendixes A-K

The appendices A-K to the user's manual for the rocket combustor interactive design (ROCCID) computer program are presented. This includes installation instructions, flow charts, subroutine model documentation, and sample output files. The ROCCID program, written in Fortran 77, provides a standardized methodology using state of the art codes and procedures for the analysis of a liquid rocket engine combustor's steady state combustion performance and combustion stability. The ROCCID is currently capable of analyzing mixed element injector patterns containing impinging like doublet or unlike triplet, showerhead, shear coaxial and swirl coaxial elements as long as only one element type exists in each injector core, baffle, or barrier zone. Real propellant properties of oxygen, hydrogen, methane, propane, and RP-1 are included in ROCCID. The properties of other propellants can be easily added. The analysis models in ROCCID can account for the influences of acoustic cavities, helmholtz resonators, and radial thrust chamber baffles on combustion stability. ROCCID also contains the logic to interactively create a combustor design which meets input performance and stability goals. A preliminary design results from the application of historical correlations to the input design requirements. The steady state performance and combustion stability of this design is evaluated using the analysis models, and ROCCID guides the user as to the design changes required to satisfy the user's performance and stability goals, including the design of stability aids. Output from ROCCID includes a formatted input file for the standardized JANNAF engine performance prediction procedure.

Muss, J. A.

Producibility of fibrous refractory composite insulation, FRCI 40-20

Fibrous Refractory Composite Insulation (FRCI) is a NASA-developed, second generation, reusable heat-shield material that comprises a mixture of aluminoborosilicate fibers, silica fibers, and silicon carbide. Under NASA contract, a program was conducted to demonstrate the capability for manufacturing FRCI 40-20 billets. A detailed fabrication procedure was written and validated by testing specimens from the first two billets. The material conformed to NASA requirements for density, tensile strength, modulus of rupture, thermal expansion, cristobalite content, and uniformity. Twenty-four billets were prepared to provide 20 deliverable articles. Production billets were checked for density, modulus of rupture, cristobalite content, and uniformity. Billet density ranged from 309.48 to 332.22 kg/cu m (19.32 to 20.74 lb/cu ft) and modulus of rupture from 4690 to 10,140 kPa (680 to 1470 psi). Cristobalite content was less than 1 percent. A Weibull analysis of modulus-of-rupture data indicated a 1.5 percent probability for failure below the specified strength of 4480 kPa (650 psi).

Strauss, E. L.

The Lageos satellite

The fundamental concept of Lageos is a long-lived, dense, electrically and mechanically inert spherical satellite with its surface speckled with retroreflecting cube corners, designed such that range measurements between duly equipped laser ground stations and the satellite are possible with an ultimate accuracy of 2 cm when data from a single satellite pass are appropriately averaged. The Lageos concept requires that the satellite be placed in an orbit for which an ephemeris can be determined ultimately to 5 cm rms uncertainty for a 24-hour arc. These required satellite characteristics should allow the several geodynamic motions experienced by ground stations to be determined typically with 2 cm accuracy.

Johnson, C. W.