Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Risk analysis of an RTG on the Space Shuttle

As part of the effort to review the Ulysses Final Safety Analysis Report and to understand the risk of plutonium release from the Ulysses spacecraft General Purpose Heat Source-Radioisotope Thermal Generator (GPHS-RTG), the Interagency Nuclear Safety Review Panel (INSRP) and the author performed an integrated, quantitative analysis of the uncertainties of the calculated risk of plutonium release from Ulysses. Using state-of-the-art probabilistic risk assessment technology, the uncertainty analysis accounted for both variability and uncertainty of the key parameters of the risk analysis. The results show tht INSRP had high confidence that risk of fatal cancers from potential plutonium release associated with calculated launch and deployment accident scenarios is low.

Frank, Michael V.↗

L-Band Digital Aeronautical Communications System Engineering - Initial Safety and Security Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract NNC05CA85C, Task 7: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed L-band (960 to 1164 MHz) terrestrial en route communications system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents a preliminary safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the L-band communication system after the technology is chosen and system rollout timing is determined. The security risk analysis resulted in identifying main security threats to the proposed system as well as noting additional threats recommended for a future security analysis conducted at a later stage in the system development process. The document discusses various security controls, including those suggested in the COCR Version 2.0.

Zelkin, Natalie↗

MBSE (SysML) and Digital Twin Integration to Support Engineering Analysis & Design

Problem Statement: The complexity of Gateway systems and of managing the integrated safety analysis have made traditional methods of engineering analysis and design increasingly challenging. To address these challenges, a prototype that integrate Model-Based Systems Engineering (MBSE) with Digital Twin technology has been developed to demonstrate the utilities and functions. Project Goal: Develop a prototype of a Digital Twin Of Gateway ECLSS IMV system to enhance fault management analysis through collaboration, visualization, and simulation. Overall Project Results / Accomplishments: - Developed extension to streamline the integration of SysML models with the Digital Twin platform - Demonstrated the capability to aggregate any relevant information and provide simulation integration within the DT prototype. - Generated digital twin simulation using SysML Activity Diagrams - Implemented a complex trade study use case based on the integrated SysML-Digital Twin infrastructure

MBSE↗

Developing a safe on-orbit cryogenic depot

New U.S. space initiatives will require technology to realize planned programs such as piloted lunar and Mars missions. Key to the optimal execution of such missions are high performance orbit transfer vehicles and propellant storage facilities. Large amounts of liquid hydrogen and oxygen demand a uniquely designed on-orbit cryogenic propellant depot. Because of the inherent dangers in propellant storage and handling, a comprehensive system safety program must be established. This paper shows how the myriad and complex hazards demonstrate the need for an integrated safety effort to be applied from program conception through operational use. Even though the cryogenic depot is still in the conceptual stage, many of the hazards have been identified, including fatigue due to heavy thermal loading from environmental and operating temperature extremes, micrometeoroid and/or depot ancillary equipment impact (this is an important problem due to the large surface area needed to house the large quantities of propellant), docking and maintenance hazards, and hazards associated with extended extravehicular activity. Various safety analysis techniques were presented for each program phase. Specific system safety implementation steps were also listed. Enhanced risk assessment was demonstrated through the incorporation of these methods.

Bahr, Nicholas J.↗

A Markov model reduction technique for fault tolerant processor reliability analysis

A fault tolerant processor (FTP) plays a key role in many high performance, safety-critical control system applications. Realistic modeling of an FTP is crucial to gaining a high degree of confidence in the reliability and safety analysis of such a system. While fidelity is clearly a major consideration, a practical model must also be kept to a moderate size to allow its incorporation into the overall system model. This paper presents a systematic reduction technique that starts from a complex, detailed model of a triple, redundant FTP and produces a low order approximation of very high accuracy. The existence of two distinct time scales represents the key to the success of the technique. No eigenvalue solution or coordinate transformation are needed. The reduced model captures all the important features of the detailed model, is amenable to an analytical solution and provides insight into the reconfiguration behavior of an FTP.

Schor, Andrei L.↗

"Source Term Modeling for Advanced Gas Micro-Reactors"

Maintaining the safety of the public, environment, and operating personnel is the most important factor in designing, operating, maintaining, and decommissioning nuclear reactors. In recent years, there has been a growing interest in the development of micro-reactors employing TRi-structural ISOtropic (TRISO)-coated particle fuel. In gas reactors, TRISO fuel plays an important role in the safety case for high temperature reactors because of the fission product retention properties of the fuel. This ability enables the use of a functional containment strategy for the reactor where multiple barriers are used to prevent fission product release to the environment. Part of the safety analysis of these advanced reactors is the assessment of radionuclide releases under normal and accident conditions through the multiple credited safety barriers. Using conservative assumptions, a mechanistic analysis can be performed to quantify these releases that combines the probabilistic assessment of failure with analytic solutions to radionuclide transport equations. Source term modeling for TRISO fuel has been performed for previous reactor designs; however, these models are outdated, in many cases proprietary, and need updates to be applied to the current state of TRISO fuel technology and alternative gas reactor core configurations [1]. Currently, the only publicly available source term assessment for gas reactors is an expert-based Monte Carlo simulation based on the effectiveness of the fuel kernel, coating layers, and graphite block in a modular high temperature gas reactor [2]. Thus, there is a need to develop a simple, versatile, and mechanistic model of fission product release and transport in gas reactor cores that could be applied to a variety of reactors through user inputs and reactor-specific radionuclide inventories. The release is calculated by the diffusion of the key safety important fission products through the kernel, silicon carbide (SiC), graphite for both intact and defective TRISO particles based on fuel and graphite temperatures in the reactor under normal operation. These releases from the fuel enter the coolant where they can plate-out on cooler surfaces. A clean-up model is included for designs with a coolant purification system to remove fission gases. This initial distribution of fission products in the reactor serves as an initial condition for potential releases under postulated accident conditions. The model then can calculate the fission product release for any transient temperature profile and fission product releases can then be used to assess radiological dose to the workers and the public using conventional dose tools. Data on the diffusion of fission products is based on historic German TRISO experiments and the more current Department of Energy (DOE) Advanced Gas Reactor (AGR) TRISO fuel development program. The model is coded in python with inputs and outputs in excel spreadsheets, as well as python plotting utilities to aid in the interpretation of the results. References: [1] INL, NGNP Mechanistic Source Term White Paper, INL-10-17997, July 2010. [2] David A. Petti, Richard R. Hobbins, Peter Lowry, Hans Gougar, “Representative Source Terms and The Influence of Reactor Attributes on Functional Containment in Modular High Temperature Gas-cooled Reactors,” Nuclear Technology, Vol. 184, p. 181-197, Nov. 2013.

07 ISOTOPE AND RADIATION SOURCES↗

An Assessment of Civil Tiltrotor Concept of Operations in the Next Generation Air Transportation System

Based on a previous Civil Tiltrotor (CTR) National Airspace System (NAS) performance analysis study, CTR operations were evaluated over selected routes and terminal airspace configurations assuming noninterference operations (NIO) and runway-independent operations (RIO). This assessment aims to further identify issues associated with these concepts of operations (ConOps), and their dependency on the airspace configuration and interaction with conventional fixed-wing traffic. Safety analysis following a traditional Safety Management System (SMS) methodology was applied to CTR-unique departure and arrival failures in the selected airspace to identify any operational and certification issues. Additional CTR operational cases were then developed to get a broader understanding of issues and gaps that will need to be addressed in future CTR operational studies. Finally, needed enhancements to National Airspace System performance analysis tools were reviewed, and recommendations were made on improvements in these tools that are likely to be required to support future progress toward CTR fleet operations in the Next Generation Air Transportation System (NextGen).

Chung, William W.↗

SAM User's Guide

The System Analysis Module (SAM) is a modern system analysis tool being developed at Argonne National Laboratory for advanced non-LWR safety analysis. It aims to provide fast-running, whole-plant transient analyses capability with improved-fidelity for Sodium-cooled Fast Reactors (SFR), Lead-cooled Fast Reactors (LFR), and Molten Salt Reactors (MSR) or Fluoride-cooled High-temperature Reactors (FHR). SAM takes advantage of advances in physical modeling, numerical methods, and software engineering to enhance its user experience and usability. It utilizes an object-oriented application framework (MOOSE), and its underlying meshing and finite-element library (libMesh) and linear and non-linear solvers (PETSc), to leverage the modern advanced software environments and numerical methods. This document provides a user’s guide, which will help users understand the input description and core capabilities of the SAM code. A brief overview of the code is presented, as well as how to obtain and run it. The input syntax for various parts of the code is provided. Additionally, a number of example problems, starting with simple unit component problems to problems with increasing complexity, are provided. Because the code is still under active development, this SAM User’s Guide will evolve with periodic updates.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Software safety - A user's practical perspective

Software safety assurance philosophy and practices at the NASA Ames are discussed. It is shown that, to be safe, software must be error-free. Software developments on two digital flight control systems and two ground facility systems are examined, including the overall system and software organization and function, the software-safety issues, and their resolution. The effectiveness of safety assurance methods is discussed, including conventional life-cycle practices, verification and validation testing, software safety analysis, and formal design methods. It is concluded (1) that a practical software safety technology does not yet exist, (2) that it is unlikely that a set of general-purpose analytical techniques can be developed for proving that software is safe, and (3) that successful software safety-assurance practices will have to take into account the detailed design processes employed and show that the software will execute correctly under all possible conditions.

Dunn, William R.↗

Stall Recovery Guidance Using Fast Model Predictive Control

Based on a detailed analysis of recent loss-of-control events, the Aircraft State Awareness Joint Safety Analysis Team has identified the need to develop algorithms and display strategies to provide control guidance for recovery from approach-to-stall or stall. In order to be effective, such guidance should enhance the pilots ability to execute the Federal Aviation Administrations recommended stall recovery procedure. This paper explores the use of a fast model predictive control algorithm that determines near optimal recovery guidance, which quantifies the aircraft configuration and situation dependent recovery information required to maximize the effectiveness of the recovery. This information includes the magnitude of the initial pitch down maneuver, the specific amount of airspeed and thrust needed before pulling out of the recovery dive, as well as the maximum pitch-up rate that can be sustained without causing a secondary stall. The algorithm was integrated and tested with an in-house desktop simulator that implements the General Transport Aircraft model and the associated stall aircraft dynamics. Preliminary results are presented to demonstrate the use of the proposed approach as a recovery aid for pilots.

predictive control↗

Space Shuttle 2 Advanced Space Transportation System. Volume 1: Executive Summary

An investigation into the feasibility of establishing a second generation space transportation system is summarized. Incorporating successful systems from the Space Shuttle and technological advances made since its conception, the second generation shuttle was designed to be a lower-cost, reliable system which would guarantee access to space well into the next century. A fully reusable, all-liquid propellant booster/orbiter combination using parallel burn was selected as the base configuration. Vehicle characteristics were determined from NASA ground rules and optimization evaluations. The launch profile was constructed from particulars of the vehicle design and known orbital requirements. A stability and control analysis was performed for the landing phase of the orbiter's flight. Finally, a preliminary safety analysis was performed to indicate possible failure modes and consequences.

Adinaro, James N.↗

Gas-Cooled High-Temperature Pebble-Bed Reactor Reference Plant Model Updates

This work presents the latest improvements to, and investigations performed with, the pebble-bed high-temperature gas-cooled reactor (PB-HTGR) reference plant models for the United States Nuclear Regulatory Commission. These models serve as the foundation for the future development of detailed design evaluation models based on license applications. The reference plant models have been developed with the Comprehensive Reactor Analysis Bundle, or BlueCRAB, which is the code suite proposed for non-light-water reactor systems safety analysis. It incorporates various simulation tools developed by the Nuclear Energy Advanced Modeling and Simulation program, including the Griffin code for reactor physics, the Pronghorn and SAM codes for core thermal fluids, the BISON code for solid conduction and fuel performance, and the SAM code for system analysis. The primary objective of the work that was performed was to assess BlueCRAB’s level of readiness for modeling a PB-HTGR. To do so, we first developed numerical models in BlueCRAB that include the key physics for this technology to ensure an adequate level of fidelity for modeling PB-HTGR core performance and for performing multiphysics simulations for equilibrium core conditions and different accident scenarios. Then we simulated transient scenarios, including depressurized and pressurized loss of forced cooling accidents, over-cooling, and control rod withdrawal events with delayed and prompt supercritical reactivity insertions. The analysis in this report includes comparisons of the 2D thermal fluid porous media models in Pronghorn and SAM, and comparisons of coupled SAM/Griffin/SAM and coupled Pronghorn/Griffin for depressurized and pressurized loss of forced cooling, over-cooling, and control rod withdrawal events. In addition, we compare 3D, 2D, and 0D/PKE neutronic models for the two control rod withdrawal scenarios with coupled Pronghorn/Griffin. The comparisons show that the BlueCRAB models lead to physically intuitive solutions for the scenarios examined. The changes in the various scalar and vector fields, such as neutron flux, power, temperature, density, pressure, and velocity, are within the expected ranges, and their distributions can be explained by the system response of the transients and the geometric and material variations. Several comparisons suggest that the porous media models in Pronghorn and SAM can lead to similar solutions, even though they are based on different methodologies. This work further highlights the need for flexible tools with various levels of fidelity to cover the breadth and depth of needs that may arise in future technical evaluations of the PB-HTGR. We believe that the BlueCRAB capabilities will be a significant asset for confirmatory analyses in order to resolve important safety questions.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Ares I-X Range Safety Analyses Overview

Ares I-X was the first test flight of NASA's Constellation Program's Ares I Crew Launch Vehicle designed to provide manned access to low Earth orbit. As a one-time test flight, the Air Force's 45th Space Wing required a series of Range Safety analysis data products to be developed for the specified launch date and mission trajectory prior to granting flight approval on the Eastern Range. The range safety data package is required to ensure that the public, launch area, and launch complex personnel and resources are provided with an acceptable level of safety and that all aspects of prelaunch and launch operations adhere to applicable public laws. The analysis data products, defined in the Air Force Space Command Manual 91-710, Volume 2, consisted of a nominal trajectory, three sigma trajectory envelopes, stage impact footprints, acoustic intensity contours, trajectory turn angles resulting from potential vehicle malfunctions (including flight software failures), characterization of potential debris, and debris impact footprints. These data products were developed under the auspices of the Constellation's Program Launch Constellation Range Safety Panel and its Range Safety Trajectory Working Group with the intent of beginning the framework for the operational vehicle data products and providing programmatic review and oversight. A multi-center NASA team in conjunction with the 45th Space Wing, collaborated within the Trajectory Working Group forum to define the data product development processes, performed the analyses necessary to generate the data products, and performed independent verification and validation of the data products. This paper outlines the Range Safety data requirements and provides an overview of the processes established to develop both the data products and the individual analyses used to develop the data products, and it summarizes the results of the analyses required for the Ares I-X launch.

Starr, Brett R.↗

New Safety Feedback Control Design to Guarantee Adequate Frequency Performance in Microgrids

Safety analysis of power systems is concerned with the system's ability to maintain critical variables within specified limits following a disturbance. Frequency control adequacy has become increasingly important as the system inertia decreases due to the increase in renewable energy penetration. Various controllers for inverters have been proposed to improve the system frequency response and few are capable to ensure the safety of the response. In this article, a diesel-wind energy system is considered and modeled as a switching system between normal, faulted, and post-fault modes. Further, a safety feedback controller is designed as a supplementary signal for a wind turbine generator such that the speed of the diesel generator stays within a permissible range in the presence of a finite energy disturbance. Numerical results on the modified 33-bus microgrid system obtained of the proposed novel approach indicate that the suggested control configuration can guarantee adequate frequency response without excessive conservativeness.

barrier function↗

Automated Mixed Traffic Vehicle (AMTV) technology and safety study

Technology and safety related to the implementation of an Automated Mixed Traffic Vehicle (AMTV) system are discussed. System concepts and technology status were reviewed and areas where further development is needed are identified. Failure and hazard modes were also analyzed and methods for prevention were suggested. The results presented are intended as a guide for further efforts in AMTV system design and technology development for both near term and long term applications. The AMTV systems discussed include a low speed system, and a hybrid system consisting of low speed sections and high speed sections operating in a semi-guideway. The safety analysis identified hazards that may arise in a properly functioning AMTV system, as well as hardware failure modes. Safety related failure modes were emphasized. A risk assessment was performed in order to create a priority order and significant hazards and failure modes were summarized. Corrective measures were proposed for each hazard.

Johnston, A. R.↗

Wake-Induced Aerodynamics on a Trailing Aircraft

NASA conducted flight tests to measure the exhaust products from alternative fuels using a DC-8 transport aircraft and a Falcon business jet. An independent analysis of the maximum vortex-induced loads on the Falcon in the DC-8 wake was conducted for pre-flight safety analysis and to define safe trail distances for the flight tests. Static and dynamic vortex-induced aerodynamic loads on the Falcon were predicted at a matrix of locations aft of the DC-8 under flight-test conditions, and the maximum loads were compared with design limit loads to assess aircraft safety. Trajectory simulations for the Falcon during close encounters with the DC-8 wake were made to study the vortex-induced loads during traverses of the DC-8 primary trailing vortex. A parametric study of flight traverses through the trailing vortex was conducted to assess Falcon flight behavior and motion characteristics.

Mendenhall, Michael R.↗

SAS4A/SASSYS-1 Modeling Improvements for the Transition to Natural Circulation

SAS4A/SASSYS-1 (SAS) is a simulation tool used to perform deterministic analyses of anticipated events as well as design basis and beyond design basis accidents for advanced liquid-metal-cooled nuclear reactors. With its origin as SAS1A in the late 1960s, the SAS series of codes has been under continuous use and development for over fifty years and represents a critical investment in safety analysis capabilities for the U.S. Department of Energy. In recent years, SAS has undergone a number of improvements to enable improved safety analyses that meet end users’ modernized needs while complying with the current regulatory environment. Improvements made in versions 5.6 and 5.7 released within the last year include the development of anisotropic Reynolds number dependent loss coefficients throughout the core and heat transport systems, the ability to distinguish the transition friction factor from the fully developed laminar and turbulent friction factors, and timedependent direct coolant and wall heating for pipe-like elements in the heat transport systems. While it was possible to capture loss coefficients, friction factors, and heat transfer from an element to a heat sink within SAS in previous versions of the code, users were required to end the simulation and restart it to adjust the input to account for any significant changes to the values during the transient. With these improvements, users can better capture flow reversal, pump heating, and the transition from forced to natural circulation without being limited to constant orifice coefficients, constant heat sinks, or the need to restart the simulation and modify input. In order to demonstrate the application of these improvements, a loss of flow transient is simulated for the Advanced Burner Test Reactor (ABTR).

SAS4A/SASSYS-1↗

Safety assessment for EPS electron-proton spectrometer

A safety analysis was conducted to identify the efforts required to assure relatively hazard free operation of the EPS and to meet the safety requirements of the program. Safety engineering criteria, principles, and techniques in applicable disciplines are stressed in the performance of the system and subsystem studies; in test planning; in the design, development, test, evaluation, and checkout of the equipment; and the operating procedures for the EPS program.

Gleeson, P.↗