Search NASA⌕ Search

SEARCH · Search NASA

Results for “Documented Safety Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Reliability and quality assurance on the MOD 2 wind system

The Safety, Reliability, and Quality Assurance (R&QA) approach developed for the largest wind turbine generator, the Mod 2, is described. The R&QA approach assures that the machine is not hazardous to the public or to the operating personnel, is operated unattended on a utility grid, demonstrates reliable operation, and helps establish the quality assurance and maintainability requirements for future wind turbine projects. The significant guideline consisted of a failure modes and effects analysis (FMEA) during the design phase, hardware inspections during parts fabrication, and three simple documents to control activities during machine construction and operation.

Mason, W. E. B.↗

A model to assess Zircaloy’s mechanical property changes following a transient beyond critical heat flux

Maintaining the integrity of nuclear fuel rods is essential for ensuring public health and safety in nuclear power generation. During reactor operation, this integrity is confirmed by demonstrating compliance with established regulatory acceptance criteria. For moderate-frequency events, such as limiting transients and anticipated operational occurrences (AOOs), the current fuel integrity criterion is based on preventing boiling transition. This criterion assumes that prevention of boiling transition will prevent excessive cladding heating and, thus, fuel failure during normal operations. While conservative, this approach places significant constraints on core design, fuel cycle economics, and a plant’s ability to perform major power uprates, leading to suboptimal fuel utilization and inefficient carbon-free energy production. A more efficient approach could be achieved by revising the failure criterion to a material-specific limit rather than strictly preventing the boiling transition, since boiling transition per se is not a cause of fuel cladding failure. Here, as a result, a new licensing framework based on material properties, termed time-at-temperature (t@T), is needed. This approach would allow for brief periods of post–critical heat flux operation during an AOO without compromising safety. Implementing the t@T licensing strategy requires a robust technical foundation in material properties, which must be established through comprehensive data collection on both unirradiated and irradiated fuel and cladding materials. This foundation would enable the development of a safety basis that ensures safe operation while providing greater flexibility and efficiency for reactor operation. This paper documents a thorough review of the available data to establish a baseline knowledge that can inform the development of cladding mechanical models, as well as identify experimental data gaps that need to be addressed in future research. Machine learning and data informatics were utilized to extract the importance of parameters on the t@T parameter. Industry tools were used to perform baseline analyses to define the relevant transient conditions for data analysis. The subsequent review successfully identified applicable experimental data, as well as sufficient data to evaluate changes in cladding mechanical properties following an AOO transient. Rather than developing new models, this work coupled existing irradiation annealing and recrystallization models to calculate changes in hardness, yield stress, and ultimate tensile stress following an AOO event. The findings from this review were summarized to highlight the experimental data needs required to fill remaining gaps and support the development of future t@T licensing methodologies.

Cladding performance↗

Design of P-3 Nadir Port

This project details the design and analysis of a structure to replace the interface of the P-3B nadir port with an optimized interface for science installations. A new nadir port plug has been designed to replace the OEM (Original Equipment Manufacturer) plug (Lockheed PN 910169) currently used in Nadir ports 1 and 2 on the NASA P-3B aircraft. The plug consists of a milled frame that can be outfitted with customizable flat plates to meet a broad range of science needs. The frame slides into place using the existing P-3B rail system using a lever and tie-rod assembly. The seal interface will contact the Fuselage skin of the aircraft and consists of a bulb E-seal that is riveted around the perimeter of the frame. The flat plate (20 inches x 31 inches) provides a large profile that can be outfitted based on science mission goals and requirements to attach multiple instruments. This is a significant increase to the aircraft capability. Previously, the OEM plug had to be modified to hold very small plates, windows, or instruments limiting the use of the ports.There were several challenges for this project that included a constrained schedule, lack of historical references, and reverse engineering. The unusually tight schedule for design, manufacture, and install limited potential approaches. In addition, design of a new interface to replace the existing plug, on an aircraft designed in the 1960's by Lockheed for the Navy with little to no documentation, required substantial reverse engineering. In order to accomplish this, a suitable method to determine interface requirements with the aircraft had to be solved. After several iterations, the solution was to implement laser scanning techniques to scan the aircraft and the OEM plug and generate a 3D model to capture the design envelope. The structure is designed to maintain a positive margin of safety when subjected to the inertial, pressure, and aerodynamic load requirements for an external installation on the P-3B, as described in the Wallops' P-3B Design Requirements 548-RQMT-0001 Rev. A . A finite element model is created in FEMAP (Finite Element Modeling And Postprocessing) and is run through NX Nastran solver to analyze the structure. After several iterations of analysis, the structure was enveloped to hold 115 pounds evenly distributed on the plate.

Chance, Monica↗

SAS4A/SASSYS-1 Verification Testing for Sodium Fast Reactor Application: Acceptance Testing Report

AS4A/SASSYS-1 (SAS) is a simulation tool used to perform deterministic analyses of anticipated events as well as design basis and beyond design basis accidents for advanced liquid-metal-cooled nuclear reactors. With its origin as SAS1A in the late 1960s, the SAS series of codes has been under continuous use and development for over sixty years and represents a critical investment in safety analysis capabilities for the U.S. Department of Energy. To support the dedication effort, this report has been generated to provide a detailed description of the available verification testing. The verification testing presented in this report captures functionality testing, focusing mainly on the testing of specific functions and algorithms for accuracy and precision of output, and interface testing, focusing mainly on the testing of critical input parameters and their valid ranges. Although SAS was developed to support the analysis of any liquid-metal-cooled nuclear reactor, the testing described in this document primarily focuses on the verification of SAS capabilities as they relate to a generic pool-type Sodium Fast Reactor (SFR).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Capability Building Progression of an Insider Threat Mitigation Program at an International Research Reactor

The nuclear industry recognizes the difficulties involved in developing effective managerial and leadership skills in a highly technical and proficient workforce such as that found in nuclear facilities. Implementing an insider threat mitigation program (ITMP) within the nuclear industry is a complex and ongoing process that demands a comprehensive understanding of human behavior, an organization’s security culture, and rigorous regulatory requirements yet also accounts for facility characteristics, physical security, material flow, and activities involving nuclear material. Given the high-consequence nature of research reactor operations, even minor lapses can lead to safety, security, and reputational risks. An effective ITMP requires a defense-in-depth approach that incorporates behavioral analysis, robust vetting procedures, continuous monitoring, and cross-disciplinary coordination. It must also promote a culture of vigilance and accountability at all levels up to and including executive leadership but be flexible enough to adapt to evolving global threats and technological advances. Insider threat mitigation is not a one-time effort but rather a sustained commitment to excellence in safety and security. Establishing a culture in which personnel proactively report incidents and issues that could affect nuclear safety and security is vital to maintaining a safe and secure operational environment. This document was developed to guide senior management and research reactor organizations in creating comprehensive programs to effectively manage and mitigate insider threat behaviors and actions. It focuses on the key pillars of an effective ITMP, including the national legal framework, security culture, preventive and protective measures, cyber security, and performance evaluation. By using a systematic approach during implementation, facilities can foster environments conducive to insider threat detection and support long-term program sustainability. The document also provides strategies for improving communication across all levels of an organization, helping to eliminate barriers that hinder the development of robust ITMPs and enhance overall security culture. In today’s organizations, the concept of leveraging safety and security culture lessons to facilitate knowledge transfer is rapidly evolving to expedite insider threat management and security culture improvements. This document outlines the rationale for evaluating an ITMP based on national customs, culture, and stakeholders. The elements are all germane to reliability and trustworthiness and relate to security concerns that states may encounter. The document focuses not only on individual perceptions regarding security issues and capability building but also on team building and how to resolve concerns. The implementers of a facility’s ITMP may zero in on indicators of insider threats within their enterprise. This material will benefit organizations when it is applied using a systematic and structured approach as demonstrated throughout the document.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Augmented Reality Technologies for Radiation Safety Training: A Systematic Review of Sensor Integration and Visualization Approaches

This paper presents a comprehensive systematic review examining the application of augmented reality (AR) and sensor technologies for visualizing ionizing radiation in virtual training environments. The review methodology involved systematic identification and analysis of the relevant literature based on predetermined criteria including publication type, year of publication, application domain, and technological approach. The literature search encompassed publications from 2011 to 2021 across four major academic databases: Web of Science, Google Scholar, IEEE Xplore, and Scopus. Through rigorous screening following PRISMA 2020 guidelines, 23 research articles met the inclusion criteria for detailed analysis. From 404 initial database records, 360 were excluded during title/abstract screening (primarily for lacking AR components, radiation focus, or training applications) and 4 during full-text assessment (all for lacking sensor integration). The findings reveal that AR-based ionizing radiation visualization has been successfully implemented across diverse domains, including nuclear facility operations, medical procedures, CERN research activities, and educational and monitoring applications. The analysis identified multiple dimensions of impact, encompassing distinct benefits, emerging opportunities, and implementation challenges associated with AR deployment for ionizing radiation training. Each of these dimensions is comprehensively examined and documented within this review. Additionally, this study identifies critical research gaps that currently limit the full potential of AR technology in supporting ionizing radiation training programs. These gaps are systematically analyzed and discussed to establish clear directions for future research endeavors in this emerging field.

61 - RADIATION PROTECTION AND DOSIMETRY↗

SAM Theory Manual

The System Analysis Module (SAM) is an advanced and modern system analysis tool under development at Argonne National Laboratory for advanced non-LWR reactor safety analysis. It aims to provide fast-running, modest-fidelity, whole-plant transient analyses capabilities, which are essential for fast turnaround design scoping and engineering analyses of advanced reactor concepts. While SAM is being developed as a system-level modeling and simulation tool, advanced modeling techniques being implemented include a reduced-order three-dimensional module, pseudo 3-D conjugate heat transfer modeling in reactor core, flexible and multi-scale modeling of heat transfer between fluid and structures, in addition to the advances in software environments and design, and numerical methods. SAM aims to be a generic system-level safety analysis tool for advanced non-LWRs, including Liquid-Metal-cooled fast Reactors (LMR), Molten Salt Reactors (MSR), Fluoride-salt-cooled High-temperature Reactors (FHR), and High-Temperature Gas-cooled Reactors (HTGR). SAM takes advantage of advances in physical modeling, numerical methods, and software engineering to enhance its user experience and usability. It utilizes an object-oriented computational framework (MOOSE), and its underlying meshing and finite-element library and linear and non-linear solvers, to leverage the modern advanced software environments and numerical methods. This document provides the theoretical and technical basis of the code to help users understand the underlying physical models (such as governing equations, closure models, and component models), system modeling approaches, numerical discretization and solution methods, and the overall capabilities in SAM. As new code capabilities and features are added, the SAM Theory Manual will be updated periodically to keep it consistent with the state of the development.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Online and Offline Analytical Techniques to Quantify Chloride Salts

This report serves as the deliverable for Milestone- M3FT-26AN080502017: Summary of Accomplishments for Online and Offline Analytical Qualification of Chloride Fuel Salts. The qualification of chloride fuel salts is a critical challenge for the development and deployment of molten salt reactors (MSRs), requiring precise control and verification of chemical and isotopic composition to ensure predictable neutronics, manageable radiological behavior, and safe plant operation. Currently, there is no universally accepted standard for fuel salt qualification, particularly for chloride-based systems, which underscores the need for robust, science-based analytical methodologies. This report presents a comprehensive evaluation of both online and offline techniques for quantifying chloride fuel salts, including multielectrode array voltammetry, differential thermal analysis (DTA) probes, inert gas fusion (IGF) analyzers, and gamma spectrometry using the Mirion NAIS-2x2 NaI(Tl) detector. The integration of these methods enables real-time monitoring of actinide concentrations, redox state, and thermophysical properties, as well as high-precision measurement of impurities and isotopic composition. The acquisition of advanced instruments such as the Bruker Leonardo G6 for IGF and the Mirion NaI detector enhances analytical capabilities, supporting the establishment of operational envelopes and impurity thresholds. These approaches provide essential data for neutronic impact evaluation, feedstock documentation, and compliance with nuclear safety standards. The methodologies developed and validated in this report lay the groundwork for future standardized protocols, bridging the gap between laboratory research and commercial reactor operation, and advancing the safe and efficient deployment of chloride-fueled MSRs.

Polke, Amber↗

NASA Lewis Wind Tunnel Model Systems Criteria

This report describes criteria for the design, analysis, quality assurance, and documentation of models or test articles that are to be tested in the aeropropulsion facilities at the NASA Lewis Research Center. The report presents three methods for computing model allowable stresses on the basis of the yield stress or ultimate stress, and it gives quality assurance criteria for models tested in Lewis' aeropropulsion facilities. Both customer-furnished model systems and in-house model systems are discussed. The functions of the facility manager, project engineer, operations engineer, research engineer, and facility electrical engineer are defined. The format for pretest meetings, prerun safety meetings, and the model criteria review are outlined Then, the format for the model systems report (a requirement for each model that is to be tested at NASA Lewis) is described, the engineers that are responsible for developing the model systems report are listed, and the time table for its delivery to the facility manager is given.

Soeder, Ronald H.↗

Review of Significant Incidents and Close Calls in Human Spaceflight from a Human Factors Perspective

This project aims to identify poor human factors design decisions that led to error-prone systems, or did not facilitate the flight crew making the right choices; and to verify that NASA is effectively preventing similar incidents from occurring again. This analysis was performed by reviewing significant incidents and close calls in human spaceflight identified by the NASA Johnson Space Center Safety and Mission Assurance Flight Safety Office. The review of incidents shows whether the identified human errors were due to the operational phase (flight crew and ground control) or if they initiated at the design phase (includes manufacturing and test). This classification was performed with the aid of the NASA Human Systems Integration domains. This in-depth analysis resulted in a tool that helps with the human factors classification of significant incidents and close calls in human spaceflight, which can be used to identify human errors at the operational level, and how they were or should be minimized. Current governing documents on human systems integration for both government and commercial crew were reviewed to see if current requirements, processes, training, and standard operating procedures protect the crew and ground control against these issues occurring in the future. Based on the findings, recommendations to target those areas are provided.

Silva-Martinez, Jackelynne↗

Bayesian Inference for NASA Probabilistic Risk and Reliability Analysis

This document, Bayesian Inference for NASA Probabilistic Risk and Reliability Analysis, is intended to provide guidelines for the collection and evaluation of risk and reliability-related data. It is aimed at scientists and engineers familiar with risk and reliability methods and provides a hands-on approach to the investigation and application of a variety of risk and reliability data assessment methods, tools, and techniques. This document provides both: A broad perspective on data analysis collection and evaluation issues. A narrow focus on the methods to implement a comprehensive information repository. The topics addressed herein cover the fundamentals of how data and information are to be used in risk and reliability analysis models and their potential role in decision making. Understanding these topics is essential to attaining a risk informed decision making environment that is being sought by NASA requirements and procedures such as 8000.4 (Agency Risk Management Procedural Requirements), NPR 8705.05 (Probabilistic Risk Assessment Procedures for NASA Programs and Projects), and the System Safety requirements of NPR 8715.3 (NASA General Safety Program Requirements).

Dezfuli, Homayoon↗

Automation for System Safety Analysis

This presentation describes work to integrate a set of tools to support early model-based analysis of failures and hazards due to system-software interactions. The tools perform and assist analysts in the following tasks: 1) extract model parts from text for architecture and safety/hazard models; 2) combine the parts with library information to develop the models for visualization and analysis; 3) perform graph analysis and simulation to identify and evaluate possible paths from hazard sources to vulnerable entities and functions, in nominal and anomalous system-software configurations and scenarios; and 4) identify resulting candidate scenarios for software integration testing. There has been significant technical progress in model extraction from Orion program text sources, architecture model derivation (components and connections) and documentation of extraction sources. Models have been derived from Internal Interface Requirements Documents (IIRDs) and FMEA documents. Linguistic text processing is used to extract model parts and relationships, and the Aerospace Ontology also aids automated model development from the extracted information. Visualizations of these models assist analysts in requirements overview and in checking consistency and completeness.

Malin, Jane T.↗

Supporting Crew Autonomy in Deep Space Exploration: Preliminary Onboard Capability Requirements and Proposed Research Questions. Technical Report of the Autonomous Crew Operations Technical Interchange Meeting

Communication delays are a critical challenge posed by long duration deep space exploration. Space missions historically have relied on an ever-present Mission Control Center (MCC) to direct operations in near real-time. As unanticipated anomalies that defeat fault detection and resolution systems do arise, the lack of real-time communication will significantly weaken what the MCC support represents: a reliable safety net for the flight crew through its deep and diverse areas of expertise and investigative resources. As a consequence, future space vehicles and habitats need to be equipped with capabilities to support the flight crew to operate with little or no ground support. Considerations must be given to vehicle and mission designs that will fortify the traditionally ground-centered safety net and forge new support systems, when communication delays exist. In August 2018, NASA’s Human Research Program, through its Human Factors and Behavioral Performance Element, convened a Technical Interchange Meeting (TIM) on Autonomous Crew Operations at NASA Ames Research Center. The goal of the meeting was to gather input from NASA centers, industry, academia, and branches of the Department of Defense (DoD) to address how intelligent technologies can be applied to augment onboard capabilities to support crew anomaly response. The TIM featured 24 presentations by 29 speakers and hosted a total of 59 attendees, including 43 from 5 NASA centers (Ames, Johnson, Langley, Marshall, and Jet Propulsion Lab) and 4 from the DoD (3 from Army Research Lab and 1 from Naval Postgraduate School), with remaining attendees from academia (e.g., UC Davis, CMU) and industry (e.g., IBM, Siemens). Discussions were centered around three themes: standards and guidelines, lessons learned in analog environments, and technologies. To help provide a framework for discussion, a concept matrix describing anomaly response processes was created prior to the TIM (Figure 1, page 6). The matrix captures the steps involved (monitoring and detection, diagnosis, solution development and evaluation, solution implementation and verification, resolution documentation) as well as the resources and capabilities required to support these steps (data, knowledge, analysis, synthesis, resource management). A wallpaper size printout of the matrix was utilized at the TIM to solicit attendee inputs along the three themes; the activity garnered 108 submissions of ideas. Overall, what emerged from TIM discussions was a picture of mismatch between crew anomaly response needs and support that can be provided by existing intelligent technologies. The needs are broad, spanning multiple steps and processes/resources, with many of which lacking support from existing technologies, such as knowledge management throughout the steps of problem solving (especially in resolution documentation) and manpower management. The solutions provided by existing intelligent technologies are specific to the steps/processes that they are designed to support and constrained to solving only problems similar to those that have occurred before. What is lacking from technologies is typically made up by humans, specifically their complex critical thinking, creative problem solving, and domain expertise. In the end, the TIM highlighted the pressing need to support responses to onboard anomalies during autonomous crew operations, particularly those that have eluded the system tests, inspection, and other assurance processes. Such anomalies can potentially threaten crew and vehicle safety, as well as significantly impact overall operations with additional workload. These fairly rare events are difficult to anticipate and prepare for, given the state-of-the-art in intelligent technologies. This is true even for anomalies that stem from “unknown knowns”—cases in which there is sufficient external information to characterize the problem but the overall pattern fails to be recognized by the problem solver, or in which the internal knowledge needed to solve a problem is held tacitly and potentially accessible by the problem solver but not articulated. It follows that the ability to tackle anomalies lies not only with the availability of relevant information and knowledge but also their accessibility in times of need. To that end, we propose research questions along the following three broad themes: • How intelligent technologies can help make relevant knowledge and information available? • How intelligent technologies can help make relevant knowledge and information accessible? • How intelligent technologies can help support the crew operating as a team in anomaly response processes?

autonomous crew operations↗

Development of a Bayesian Belief Network Runway Incursion and Excursion Model

In a previous work, a statistical analysis of runway incursion (RI) event data was conducted to ascertain the relevance of this data to the top ten Technical Challenges (TC) of the National Aeronautics and Space Administration (NASA) Aviation Safety Program (AvSP). The study revealed connections to several of the AvSP top ten TC and identified numerous primary causes and contributing factors of RI events. The statistical analysis served as the basis for developing a system-level Bayesian Belief Network (BBN) model for RI events, also previously reported. Through literature searches and data analysis, this RI event network has now been extended to also model runway excursion (RE) events. These RI and RE event networks have been further modified and vetted by a Subject Matter Expert (SME) panel. The combined system-level BBN model will allow NASA to generically model the causes of RI and RE events and to assess the effectiveness of technology products being developed under NASA funding. These products are intended to reduce the frequency of runway safety incidents/accidents, and to improve runway safety in general. The development and structure of the BBN for both RI and RE events are documented in this paper.

Green, Lawrence L.↗

Evaluating Faulty State Occurrence in Wildfire UAS Missions Using Markov Chains

As autonomous technology advances, unmanned aircraft systems are increasingly integrated into emergency response missions, such as wildfire response. These systems must be be safe with less risk than non-autonomous counter parts, yet quantifying the risk associated with present-day and future systems conventionally relies solely on expert opinion and little data. Instead, combining narrative mishap reports with probabilistic analysis can provide a method for evolutionary and timely risk analysis. In this paper, we present a framework for a data-driven probabilistic risk assessment style analysis, where hazard events and rates originate from documented UAS mishaps. The framework is applied to a UAS mapping mission in wildfire response, including a fault tree analysis, event tree analysis, and probabilistic analysis using Markov Chains. The analysis provides an enumeration of hazards in the system, hazard events that can lead to faults, the probability of a mission experiencing any fault, the probability of experiencing a specific fault, and the expected time spent until faulty states occur in present-day operations.

risk analysis↗

SAM User's Guide

The System Analysis Module (SAM) is a modern system analysis tool being developed at Argonne National Laboratory for advanced non-LWR safety analysis. It aims to provide fast-running, whole-plant transient analyses capability with improved-fidelity for Sodium-cooled Fast Reactors (SFR), Lead-cooled Fast Reactors (LFR), and Molten Salt Reactors (MSR) or Fluoride-cooled High-temperature Reactors (FHR). SAM takes advantage of advances in physical modeling, numerical methods, and software engineering to enhance its user experience and usability. It utilizes an object-oriented application framework (MOOSE), and its underlying meshing and finite-element library (libMesh) and linear and non-linear solvers (PETSc), to leverage the modern advanced software environments and numerical methods. This document provides a user’s guide, which will help users understand the input description and core capabilities of the SAM code. A brief overview of the code is presented, as well as how to obtain and run it. The input syntax for various parts of the code is provided. Additionally, a number of example problems, starting with simple unit component problems to problems with increasing complexity, are provided. Because the code is still under active development, this SAM User’s Guide will evolve with periodic updates.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

U.S. Efforts in Support of Examinations at Fukushima Daiichi - September 2024 Meeting Notes

Information obtained from Fukushima Daiichi Nuclear Power Station (Daiichi) is required to inform future Decontamination and Decommissioning (D&D) activities, improving the ability of the Tokyo Electric Power Company Holdings, Incorporated (TEPCO Holdings) to characterize potential hazards and to ensure the safety of workers involved with cleanup activities. This information also has important implications for the safety and operation of U.S. Commercial nuclear power plants. A collaborative U.S. and Japanese effort was initiated in 2014 by the Department of Energy Office of Nuclear Energy to identify Daiichi examination needs and evaluate recent Daiichi examination data to address these needs. This document summarizes information presented at and findings, action items, and recommendations by U.S. and Japanese experts in reactor safety and plant operations during the September 2024 Forensics Effort meeting. Significant safety insights were obtained in several areas: system and component performance, radionuclide surveys and sampling, debris end-state location, combustible gas effects, and plant operations and maintenance. In addition to reducing uncertainties and knowledge gaps in severe accident modeling progression, these insights continue to be used to assess whether additional updates are needed in guidance for severe accident prevention, mitigation, and emergency planning. Furthermore, Daiichi-related activities, such as code modeling improvements and analysis, testing, and new technology deployment efforts, have the potential to offer additional safety and economic benefits to the operating fleet and new light water reactor (LWR) and non-LWR designs.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Information Extraction for System-Software Safety Analysis: Calendar Year 2008 Year-End Report

This annual report describes work to integrate a set of tools to support early model-based analysis of failures and hazards due to system-software interactions. The tools perform and assist analysts in the following tasks: 1) extract model parts from text for architecture and safety/hazard models; 2) combine the parts with library information to develop the models for visualization and analysis; 3) perform graph analysis and simulation to identify and evaluate possible paths from hazard sources to vulnerable entities and functions, in nominal and anomalous system-software configurations and scenarios; and 4) identify resulting candidate scenarios for software integration testing. There has been significant technical progress in model extraction from Orion program text sources, architecture model derivation (components and connections) and documentation of extraction sources. Models have been derived from Internal Interface Requirements Documents (IIRDs) and FMEA documents. Linguistic text processing is used to extract model parts and relationships, and the Aerospace Ontology also aids automated model development from the extracted information. Visualizations of these models assist analysts in requirements overview and in checking consistency and completeness.

Malin, Jane T.↗