Search NASA⌕ Search

SEARCH · Search NASA

Results for “probability risk analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Analysis of Launch Vehicle Liftoff Debris: Historical Perspective from Space Shuttle and Application to Artemis I

Human exploration-class launch vehicles are inherently prone to debris due to the extreme environments generated during pre-launch operations, liftoff, and flight. The use of cryogenic propellants often requires thermal protection system (TPS) coatings, typically foam, to maintain the propellant conditions in the tank and prevent an accumulation ice on the external surface of the vehicle. Some ice growth is to be expected at umbilical interfaces, vents, flanges, or brackets where it is difficult to apply TPS. This ice may come loose at any time due to wind on the launch pad, structural vibration and acoustics after rocket ignition, or aerodynamic forces during flight. This phenomena is especially apparent on vehicles with no TPS, such as the Saturn V rockets used in the Apollo Program, see Figure 1. During propellant tanking, the thermal contraction of the underlying substrate may generate cracks in the TPS (Figure 1). Chunks of TPS can release due to the expansion of ingested gas from cryopumping or from aerodynamic forces if the crack creates an offset surface. Most foams will also have a certain amount of “popcorning” where small pieces of foam will pop off during flight because of the differential between the static surface pressure and the pressure of the gas trapped in the foam cell structure. There are a number of other coating or closeout materials that may be shed from the vehicle and become debris. During pre-launch operations and liftoff, the vehicle may also be exposed to debris originating from the launch pad or ground support equipment. This debris is separate from foreign object debris, or FOD, which is not intended to be present and is strictly controlled through operations and maintenance procedures. In this case, debris is generated from hardware and materials that are necessary for launch and are subject to the intense vibration, acoustics, and direct plume impingement of the launch environment. Examples include ice from umbilicals, tape and tie wraps that protect cables, and rust or corrosion from the launch platform. While NASA has historically been aware of debris as a potential issue that could cause a failure resulting in loss of mission, loss of vehicle, or loss of crew, the likelihood and severity of that risk was not always well understood or given sufficient weight in program and flight decisions. After the Space Shuttle Columbia accident (STS-107), the investigation found that foam TPS debris shed from the external tank was the proximate cause of the damage to the orbiter wing. Six previous observations of debris released from the foam ramp that covered the bipod connecting the forward end of the orbiter to the external tank resulted in minor changes or were determined to be accepted flight risks. Two occurrences of bipod ramp foam loss were not identified until the STS-107 investigation. Despite the damage inflicted by these debris strikes, the Shuttle Program Requirements Control Board deemed the vehicle safe to fly. During the Return to Flight effort following the Columbia disaster, NASA Engineering developed a process for the assessment of debris transport, impact, and damage tolerance to support independent assessments of risk by NASA Safety and Mission Assurance (S&MA). Under this system, each element (vehicle or ground system) defines a catalog of all expected debris based on launch history, component testing, or analysis. Debris transport analysis (DTA) is conducted using the debris catalog characteristics and potential flow transport mechanisms (e.g., vehicle aerodynamics, gravity, wind, plume-driven). The predicted debris impact locations and velocities are provided to the hardware owners, who use available test data and analysis to determine whether each component can withstand the impacts. In cases where the element hardware may be severely damaged or fail, the options are to mitigate the debris source through some change in design or operation, or to work with S&MA to try to characterize the probability of the impact and damage for program risk acceptance. Because of the differences in debris characteristics and transport, the DTA has been divided between the Liftoff and Ascent regimes. The development and application of Liftoff DTA methodology from the Shuttle Program to the current Artemis Program is the subject of this paper. Liftoff DTA covers the time from the start of pre-launch operations at the launch pad, up until the vehicle clears the launch tower and there is no longer any interaction with ground systems. Debris transport during this period is broadly classified as either gravity, wind, and plume-entrained (GWPE) or plume driven (PD). GWPE debris is generally lower speed, travelling in a forward-to-aft direction. PD transport includes flow features from the rocket ignition transient, as well as plume impingement and recirculation that occur as the vehicle lifts off the launch platform. In these cases, the debris typically moves in an aft-to-forward direction at higher speeds. The applicable transport mechanisms must be considered for each piece of debris depending on the material, and release location and time. For example, rust or metallic debris from the tower could fall (GWPE) and impact the vehicle before landing on the launch platform deck where it could be also be transported by plume impingement (PD). However, falling ice (GWPE) from an umbilical is unlikely to survive impact with the vehicle or launch platform and be available for PD transport. Modeling of debris transport is accomplished using a set of DTA tools which simulate debris trajectories subject to a reference frame acceleration (i.e., gravity) and aerodynamic drag. Where the trajectory encounters a solid surface, the debris is allowed to rebound with a specified coefficient of restitution. The drag is calculated by interpolating the fluid state at each point in the debris trajectory from high-fidelity computational fluid dynamics (CFD) simulations of the launch vehicle and pad. The CFD data may either be static (steady state or time averaged), typically for GWPE transport, or dynamic (time-accurate) for PD flow features like the ignition transient. Examples of the CFD flow field solutions for the Space Launch System (SLS) rocket and launch pad are shown in Figure 2. Typical SLS debris trajectory predictions from DTA are illustrated in Figure 3. The final version of this paper will include a more detailed examination of the Liftoff DTA process developed during the Shuttle Program, and how it has been augmented and applied to the SLS rocket under the Artemis Program. Comparisons with debris observations from the Artemis I launch will demonstrate validation of the tools and methodology.

Debris↗

Systems Analysis of In-Space Manufacturing Applications for the International Space Station and the Evolvable Mars Campaign

Maintenance logistics support is a significant challenge for extended human operations in space, especially for missions beyond Low Earth Orbit (LEO). For missions to Mars (such as NASA's Evolvable Mars Campaign (EMC)), where timely resupply or abort in the event of emergency will not be possible, maintenance logistics mass is directly linked to the Probability of Loss of Crew (P(LoC)), and the cost of driving down risk is an exponential increase in mass requirements. The logistics support strategies that have maintained human operations in LEO will not be effective for these deep space missions. In-Space Manufacturing (ISM) is a promising technological solution that could reduce logistics requirements, mitigate risks, and augment operational capabilities, enabling Earth- independent human spaceflight. This paper reviews maintenance logistics challenges for spaceflight operations in LEO and beyond, and presents a summary of selected results from a systems analysis of potential ISM applications for the ISS and EMC. A quantitative modeling framework and sample assessment of maintenance logistics and risk reduction potential of this new technology is also presented and discussed.

Owens, Andrew C.↗

Second Cancers After Fractionated Radiotherapy: Stochastic Population Dynamics Effects

When ionizing radiation is used in cancer therapy it can induce second cancers in nearby organs. Mainly due to longer patient survival times, these second cancers have become of increasing concern. Estimating the risk of solid second cancers involves modeling: because of long latency times, available data is usually for older, obsolescent treatment regimens. Moreover, modeling second cancers gives unique insights into human carcinogenesis, since the therapy involves administering well characterized doses of a well studied carcinogen, followed by long-term monitoring. In addition to putative radiation initiation that produces pre-malignant cells, inactivation (i.e. cell killing), and subsequent cell repopulation by proliferation can be important at the doses relevant to second cancer situations. A recent initiation/inactivation/proliferation (IIP) model characterized quantitatively the observed occurrence of second breast and lung cancers, using a deterministic cell population dynamics approach. To analyze ifradiation-initiated pre-malignant clones become extinct before full repopulation can occur, we here give a stochastic version of this I I model. Combining Monte Carlo simulations with standard solutions for time-inhomogeneous birth-death equations, we show that repeated cycles of inactivation and repopulation, as occur during fractionated radiation therapy, can lead to distributions of pre-malignant cells per patient with variance >> mean, even when pre-malignant clones are Poisson-distributed. Thus fewer patients would be affected, but with a higher probability, than a deterministic model, tracking average pre-malignant cell numbers, would predict. Our results are applied to data on breast cancers after radiotherapy for Hodgkin disease. The stochastic IIP analysis, unlike the deterministic one, indicates: a) initiated, pre-malignant cells can have a growth advantage during repopulation, not just during the longer tumor latency period that follows; b) weekend treatment gaps during radiotherapy, apart from decreasing the probability of eradicating the primary cancer, substantially increase the risk of later second cancers.

Sachs, Rainer K.↗

Determining the Most Influencing Medical Conditions in MEDPRAT’s SIN Directed Graph

INTRODUCTION: The Susceptibility Inference Network (SIN) is a network of medical conditions, part of the Medical Extensible Probabilistic Risk Assessment Tool (MEDPRAT) developed by NASA to assess human health and medical risk to space exploration missions. The SIN is subject matter expert informed and acts as a prototype that provides relationships and dependencies between events modeled by MEDPRAT. Each vertex in the SIN has a weight which evaluates the severity of having the condition regardless of the progression from or to that condition. In this presentation, we consider two statistics to measure that stand alone risk: Quality Time Lost (QTL) and Loss of Crew Life (LOCL). Our goal is to identify the medical conditions that contribute the most to crew members QTL and LOCL risks due to progression of conditions in the network. We investigate how different computation parameters result in different condition rankings and address the choice of parameters that allows appropriate interventions to ensure space mission success. METHODS: The Katz score, one of many centrality measures created for ranking purposes in network analysis, takes into account all possible walks through the network, penalizing each additional step in a walk by a factor α called the Katz parameter. The literature does not provide specific values for the choice of α. We derive an analytical relationship between α and the maximum path length which has influence on the Katz score and ranking. Based on the probability of progression of each condition in the SIN, we identify that maximum path length of interest and calculate α that is then used in the Katz formula to rank the conditions in the SIN. RESULTS AND CONCLUSION: The effective probabilities of the SIN matrix generally fall below 10−6, which is below the level of the least influencing condition in the set. This corresponds to the probability of at most six consecutive progressions of a condition. Consequently, we calculate the Katz Parameter α and get 0.32. We rank the medical conditions and find that Acute Radiation Symptom is the condition the most prone to contribute to quality time loss due to progression.

risk analysis↗

Modeling the effects of exercise during 100% oxygen prebreathe on the risk of hypobaric decompression sickness

BACKGROUND: Several previous studies indicated that exercise during prebreathe with 100% O2 decreased the incidence of hypobaric decompression sickness (DCS). We report a meta-analysis of these investigations combined with a new study in our laboratory to develop a statistical model as a predictive tool for DCS. HYPOTHESIS: Exercise during prebreathe increases N2 elimination in a theoretical 360-min half-time compartment decreasing the incidence of DCS. METHODS: A dose-response probability tissue ratio (TR) model with 95% confidence limits was created for two groups, prebreathe with exercise (n = 113) and resting prebreathe (n = 113), using nonlinear regression analysis with maximum likelihood optimization. RESULTS: The model predicted that prebreathe exercise would reduce the residual N2 in a 360-min half-time compartment to a level analogous to that in a 180-min compartment. This finding supported the hypothesis. The incidence of DCS for the exercise prebreathe group was significantly decreased (Chi-Square = 17.1, p < 0.0001) from the resting prebreathe group. CONCLUSIONS: The results suggested that exercise during prebreathe increases tissue perfusion and N2 elimination approximately 2-fold and markedly lowers the risk of DCS. Based on the model, the prebreathe duration may be reduced from 240 min to a predicted 91 min for the protocol in our study, but this remains to be verified. The model provides a useful planning tool to develop and test appropriate prebreathe exercise protocols and to predict DCS risks for astronauts.

NASA Program Environmental Health↗

On Space Exploration and Human Error: A Paper on Reliability and Safety

NASA space exploration should largely address a problem class in reliability and risk management stemming primarily from human error, system risk and multi-objective trade-off analysis, by conducting research into system complexity, risk characterization and modeling, and system reasoning. In general, in every mission we can distinguish risk in three possible ways: a) known-known, b) known-unknown, and c) unknown-unknown. It is probably almost certain that space exploration will partially experience similar known or unknown risks embedded in the Apollo missions, Shuttle or Station unless something alters how NASA will perceive and manage safety and reliability

Bell, David G.↗

Risk Presentation Using the Three Dimensions of Likelihood, Severity, and Level of Control

Traditional hazard analysis techniques utilize a two-dimensional representation of the results determined by relative likelihood and severity of the residual risk. These matrices present a quick-look at the Likelihood (Y-axis) and Severity (X-axis) of the probable outcome of a hazardous event. A three-dimensional method, described herein, utilizes the traditional X and Y axes, while adding a new, third dimension, shown as the Z-axis, and referred to as the Level of Control. The elements of the Z-axis are modifications of the Hazard Elimination and Control steps (also known as the Hazard Reduction Precedence Sequence). These steps are: 1. Eliminate risk through design. 2. Substitute less risky materials for more hazardous materials. 3. Install safety devices. 4. Install caution and warning devices. 5. Develop administrative controls (to include special procedures and training.) 6. Provide protective clothing and equipment. When added to the two-dimensional models, the level of control adds a visual representation of the risk associated with the hazardous condition, creating a tall-pole for the leastwell-controlled failure while establishing the relative likelihood and severity of all causes and effects for an identified hazard. Computer modeling of the analytical results, using spreadsheets and three-dimensional charting gives a visual confirmation of the relationship between causes and their controls.

Watson, Clifford↗

Root Cause Correlation Analysis of Software Failures via Orthogonal Defect Classification and Natural Language Processing

Systems theoretic process analysis (STPA) is becoming an increasingly popular technique to assess how complex digital software systems can fail. Rather than defining failures by their observable failure events, which may be sparse especially for safety rated nuclear digital instrumentation and control systems (DI&C), failures are defined as postulated unsafe actions under specific contextual conditions. This permits a top-down analysis of system hazards and identifies whether imposed constraints and requirements can sufficiently address undesirable hazards. However, STPA is a qualitative approach at identifying inadequacies in the development process and cannot currently be used to quantify unsafe action likelihoods for probabilistic risk assessment. Therefore, in this work, we examine the root causes of software failure and explore whether a consistent correlation can be linked to specific unsafe action classes. We implement Lbl2Vec, an unsupervised document classification and retrieval algorithm, on a database of 4,096 software defect reports acquired from various open-source software systems. By analyzing sentence structure, embedded labels, and word vectors, we show that certain defect types positively correlate to specific unsafe action classes over others. The correlations developed can be used to estimate the failure probability of safety intended DI&C systems which provides a licensing basis for nuclear plant modernization efforts.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

A Prognostic Launch Vehicle Probability of Failure Assessment Methodology for Conceptual Systems Predicated on Human Causal Factors

Lessons learned from past failures of launch vehicle developments and operations were used to create a new method to predict the probability of failure of conceptual systems. Existing methods such as Probabilistic Risk Assessments and Human Risk Assessments were considered but found to be too cumbersome for this type of system-wide application for yet-to-be-flown vehicles. The basis for this methodology were historic databases of past failures, where it was determined that various faulty human-interactions were the predominant root causes of failure rather than deficient component reliabilities evaluated through statistical analysis. This methodology contains an expert scoring part which can be used in either a qualitative or a quantitative mode. The method produces two products: a numerical score of the probability of failure and guidance to program management on critical areas in need of increased focus to improve the probability of success. In order to evaluate the effectiveness of this new method, data from a concluded vehicle program (USAF's Titan IV with the Centaur G-Prime upper stage) was used as a test case. The theoretical vs. actual probability of failure was found to be 4.46% vs. 6.67% respectively. Recommendations are made for future applications of this method to ongoing launch vehicle development programs.

Launch Vehicle↗

Prognostic Launch Vehicle Probability of Failure Assessment Methodology for Conceptual Systems Predicated on Human Causal Factors

Lessons learned from past failures of launch vehicle developments and operations were used to create a new method to predict the probability of failure of conceptual systems. Existing methods such as Probabilistic Risk Assessments and Human Risk Assessments were considered but found to be too cumbersome for this type of system-wide application for yet-to-be-flown vehicles. The basis for this methodology were historic databases of past failures, where it was determined that various faulty human-interactions were the predominant root causes of failure rather than deficient component reliabilities evaluated through statistical analysis. This methodology contains an expert scoring part which can be used in either a qualitative or a quantitative mode. The method produces two products: a numerical score of the probability of failure or guidance to program management on critical areas in need of increased focus to improve the probability of success. In order to evaluate the effectiveness of this new method, data from a concluded vehicle program (USAF's Titan IV with the Centaur G-Prime upper stage) was used as a test case. Although the theoretical vs. actual probability of failure was found to be in reasonable agreement (4.46% vs. 6.67% respectively) the underlying sub-root cause scoring had significant disparities attributable to significant organizational changes and acquisitions. Recommendations are made for future applications of this method to ongoing launch vehicle development programs.

Craig H Williams↗

Solar Array Mast Imagery Discussion for ISIW

SAW Mast inspection background: In 2012, NASA's Flight Safety Office requested the Micro Meteoroid and Orbital Debris (MMOD) office determine the probability of damage to the Solar Array Wing (SAW) mast based on the exposure over the life time of the ISS program. As part of the risk mitigation of the potential MMOD strikes. ISS Program office along with the Image Science and Analysis Group (ISAG) began developing methods for imaging the structural components of the Mast.

Kilgo, Gary↗

Decision Support Tool for Risk Assessment & Maneuver Planning in Collision Avoidance

As the quantity of orbital debris continues to grow, so too does the rate of conjunction messages that suggest possible collisions between high value payloads and debris. The abundance of these conjunction messages, and eventual misses, has led to a culture of ignored alerts, and an increase in satellite operation costs as a result of the frequent need to plan resources for maneuver planning and execution. The loss of “trust” in conjunction alerts is due to the poorly characterized evolution in probability of collision (Pc) as time approaches the time of closest approach (TCA) between two objects, as well as the interpretation of Pc in the context of maneuver planning. To address these problems, and in collaboration with the NASA Conjunction Assessment Risk Analysis (CARA) program, the Industrial Sciences Group has developed a novel Maneuver Decision Support System (MDSS) to assist satellite operations in conjunction assessment and Maneuver planning. It provides a meaningful and intuitive Urgency metric for actionable maneuver decisions, based on the physical dynamics of conjunctions. It is based on a forecast of the evolution of Pc over time and represents an advance over current methods that are in use for satellite conjunction monitoring and planning. The result is to give satellite operators a validated decision support systems to plan for maneuver execution or mitigation or monitoring up to 3 days before TCA.

Decision Support Tool↗

A comparison of reliability and conventional estimation of safe fatigue life and safe inspection intervals

Both the conventional and reliability analyses for determining safe fatigue life are predicted on a population having a specified (usually log normal) distribution of life to collapse under a fatigue test load. Under a random service load spectrum, random occurrences of load larger than the fatigue test load may confront and cause collapse of structures which are weakened, though not yet to the fatigue test load. These collapses are included in reliability but excluded in conventional analysis. The theory of risk determination by each method is given, and several reasonably typical examples have been worked out, in which it transpires that if one excludes collapse through exceedance of the uncracked strength, the reliability and conventional analyses gave virtually identical probabilities of failure or survival.

Hooke, F. H.↗

Guidance, Navigation, and Control System Design in a Mass Reduction Exercise

Early Orion GN&C system designs optimized for robustness, simplicity, and utilization of commercially available components. During the System Definition Review (SDR), all subsystems on Orion were asked to re-optimize with component mass and steady state power as primary design metrics. The objective was to create a mass reserve in the Orion point of departure vehicle design prior to beginning the PDR analysis cycle. The Orion GN&C subsystem team transitioned from a philosophy of absolute 2 fault tolerance for crew safety and 1 fault tolerance for mission success to an approach of 1 fault tolerance for crew safety and risk based redundancy to meet probability allocations of loss of mission and loss of crew. This paper will discuss the analyses, rationale, and end results of this activity regarding Orion navigation sensor hardware, control effectors, and trajectory design.

Crain, Timothy↗

SMART: A Propositional Logic-Based Trade Analysis and Risk Assessment Tool for a Complex Mission

This paper introduces a new trade analysis software called the Space Mission Architecture and Risk Analysis Tool (SMART). This tool supports a high-level system trade study on a complex mission, such as a potential Mars Sample Return (MSR) mission, in an intuitive and quantitative manner. In a complex mission, a common approach to increase the probability of success is to have redundancy and prepare backups. Quantitatively evaluating the utility of adding redundancy to a system is important but not straightforward, particularly when the failure of parallel subsystems are correlated.

Ono, Masahiro↗

Space Propulsion Hazards Analysis Manual (SPHAM), volume 1

The Space Propulsion Hazards Analysis Manual (SPHAM) is a compilation of methods and data directed at hazards analysis and safety for space propulsion and associated vehicles, but broadly applicable to other environments and systems. Methods are described of compiling relevant regulatory documentation, deriving design requirements and specifications, modeling accident scenarios in formal risk assessments, and correlation real-time data to risk probability modeling. Also, SPHAM provides methods for predicting post-accident blast, fragmentation, thermal, and environmental damage. Included in the appendices are an exhaustive bibliography, hazardous properties information on selected space propulsion commodities, and system descriptions of various launch vehicles, upper stages, and spacecrafts.

Becker, Dorothy L.↗

A Single Conjunction Risk Assessment Metric: the F-Value

The Conjunction Assessment Team at NASA Goddard Space Flight Center provides conjunction risk assessment for many NASA robotic missions. These risk assessments are based on several figures of merit, such as miss distance, probability of collision, and orbit determination solution quality. However, these individual metrics do not singly capture the overall risk associated with a conjunction, making it difficult for someone without this complete understanding to take action, such as an avoidance maneuver. The goal of this analysis is to introduce a single risk index metric that can easily convey the level of risk without all of the technical details. The proposed index is called the conjunction "F-value." This paper presents the concept of the F-value and the tuning of the metric for use in routine Conjunction Assessment operations.

Frigm, Ryan Clayton↗

Root Cause Correlation Analysis of Software Failures via Orthogonal Defect Classification and Natural Language Processing

Systems theoretic process analysis (STPA) is becoming an increasingly popular technique to assess how complex digital software systems can fail. Rather than defining failures by their observable failure events, which may be sparse especially for safety rated nuclear digital instrumentation and control systems (DI&C), failures are defined as postulated unsafe actions under specific contextual conditions. This permits a top-down analysis of system hazards and identifies whether imposed constraints and requirements can sufficiently address undesirable hazards. However, STPA is a qualitative approach at identifying inadequacies in the development process and cannot currently be used to quantify unsafe action likelihoods for probabilistic risk assessment. Therefore, in this work, we examine the root causes of software failure and explore whether a consistent correlation can be linked to specific unsafe action classes. We implement Lbl2Vec, an unsupervised document classification and retrieval algorithm, on a database of 4,096 software defect reports acquired from various open-source software systems. By analyzing sentence structure, embedded labels, and word vectors, we show that certain defect types positively correlate to specific unsafe action classes over others. The correlations developed can be used to estimate the failure probability of safety intended DI&C systems which provides a licensing basis for nuclear plant modernization efforts.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗