Search NASA⌕ Search

SEARCH · Search NASA

Results for “Human Reliability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

NASA Taxonomies for Searching Problem Reports and FMEAs

Many types of hazard and risk analyses are used during the life cycle of complex systems, including Failure Modes and Effects Analysis (FMEA), Hazard Analysis, Fault Tree and Event Tree Analysis, Probabilistic Risk Assessment, Reliability Analysis and analysis of Problem Reporting and Corrective Action (PRACA) databases. The success of these methods depends on the availability of input data and the analysts knowledge. Standard nomenclature can increase the reusability of hazard, risk and problem data. When nomenclature in the source texts is not standard, taxonomies with mapping words (sets of rough synonyms) can be combined with semantic search to identify items and tag them with metadata based on a rich standard nomenclature. Semantic search uses word meanings in the context of parsed phrases to find matches. The NASA taxonomies provide the word meanings. Spacecraft taxonomies and ontologies (generalization hierarchies with attributes and relationships, based on terms meanings) are being developed for types of subsystems, functions, entities, hazards and failures. The ontologies are broad and general, covering hardware, software and human systems. Semantic search of Space Station texts was used to validate and extend the taxonomies. The taxonomies have also been used to extract system connectivity (interaction) models and functions from requirements text. Now the Reconciler semantic search tool and the taxonomies are being applied to improve search in the Space Shuttle PRACA database, to discover recurring patterns of failure. Usual methods of string search and keyword search fall short because the entries are terse and have numerous shortcuts (irregular abbreviations, nonstandard acronyms, cryptic codes) and modifier words cannot be used in sentence context to refine the search. The limited and fixed FMEA categories associated with the entries do not make the fine distinctions needed in the search. The approach assigns PRACA report titles to problem classes in the taxonomy. Each ontology class includes mapping words - near-synonyms naming different manifestations of that problem class. The mapping words for Problems, Entities and Functions are converted to a canonical form plus any of a small set of modifier words (e.g. non-uniformity NOT + UNIFORM.) The report titles are parsed as sentences if possible, or treated as a flat sequence of word tokens if parsing fails. When canonical forms in the title match mapping words, the PRACA entry is associated with the corresponding Problem, Entity or Function in the ontology. The user can search for types of failures associated with types of equipment, clustering by type of problem (e.g., all bearings found with problems of being uneven: rough, irregular, gritty ). The results could also be used for tagging PRACA report entries with rich metadata. This approach could also be applied to searching and tagging failure modes, failure effects and mitigations in FMEAs. In the pilot work, parsing 52K+ truncated titles (the test cases that were available), has resulted in identification of both a type of equipment and type of problem in about 75% of the cases. The results are displayed in a manner analogous to Google search results. The effort has also led to the enrichment of the taxonomy, adding some new categories and many new mapping words. Further work would make enhancements that have been identified for improving the clustering and further reducing the false alarm rate. (In searching for recurring problems, good clustering is more important than reducing false alarms). Searching complete PRACA reports should lead to immediate improvement.

Malin, Jane T.↗

Holodeck: Telepresence Dome Visualization System Simulations

This paper explores the simulation and consideration of different image-projection strategies for the Holodeck, a dome that will be used for highly immersive telepresence operations in future endeavors of the National Aeronautics and Space Administration (NASA). Its visualization system will include a full 360 degree projection onto the dome's interior walls in order to display video streams from both simulations and recorded video. Because humans innately trust their vision to precisely report their surroundings, the Holodeck's visualization system is crucial to its realism. This system will be rigged with an integrated hardware and software infrastructure-namely, a system of projectors that will relay with a Graphics Processing Unit (GPU) and computer to both project images onto the dome and correct warping in those projections in real-time. Using both Computer-Aided Design (CAD) and ray-tracing software, virtual models of various dome/projector geometries were created and simulated via tracking and analysis of virtual light sources, leading to the selection of two possible configurations for installation. Research into image warping and the generation of dome-ready video content was also conducted, including generation of fisheye images, distortion correction, and the generation of a reliable content-generation pipeline.

Hite, Nicolas↗

Novel Microgreen Crop Testing for Space

Long-duration missions beyond low-Earth orbit will encounter challenges in maintaining adequate nutrition and crew acceptability in the food system. In situ production of fresh produce can supplement nutrient deficiencies in the prepackaged diet. Currently, there are a relatively small number of crops that can be reliably grown in space for space crop production efforts. An intriguing area of new investigation involves novel types of microgreens that have the potential to be sources of calories, fat, carbohydrates, and protein. These sources of nutrition are not obtainable in significant quantities with current pick and eat crops. Many microgreen cultivars are also sources of nutrients of interest, such as Vitamins B1, C, and K, and elements such as potassium. Microgreens should be selected to address specific nutritional deficits, as identified by NASA’s Human Research Program, with an emphasis on having a diversity of crops to meet nutritional requirements and crew acceptability. To achieve this, the concept of Crop Readiness Level (CRL) has been developed to gauge readiness of crops for spaceflight applications. CRL includes assessing environmental compatibility, food safety considerations, relevant nutritional analysis, and sensory analysis. Recent testing at Kennedy Space Center has focused on advancing the CRL of a variety of novel microgreens. These varieties were grown under 150 µmol m -2 s -1 PPFD from LED lights, 3000 ppm CO 2 , and 23°C to simulate an ISS environment. Crops were harvested and yield was assessed. Then, baseline microbiological and nutritional analysis (Vitamins B1, C, K; mineral analysis; proximate analysis) and sensory evaluation were performed. These baseline data are essential to selecting candidate crops for future missions and assessing crop production hardware and changes in environmental conditions on future crop performance and nutritional quality.

nutrition↗

Reusable Solid Rocket Motor - Accomplishment, Lessons, and a Culture of Success

The Reusable Solid Rocket Motor (RSRM) represents the largest solid rocket motor (SRM) ever flown and the only human-rated solid motor. High reliability of the RSRM has been the result of challenges addressed and lessons learned. Advancements have resulted by applying attention to process control, testing, and postflight through timely and thorough communication in dealing with all issues. A structured and disciplined approach was taken to identify and disposition all concerns. Careful consideration and application of alternate opinions was embraced. Focus was placed on process control, ground test programs, and postflight assessment. Process control is mandatory for an SRM, because an acceptance test of the delivered product is not feasible. The RSRM maintained both full-scale and subscale test articles, which enabled continuous improvement of design and evaluation of process control and material behavior. Additionally RSRM reliability was achieved through attention to detail in post flight assessment to observe any shift in performance. The postflight analysis and inspections provided invaluable reliability data as it enables observation of actual flight performance, most of which would not be available if the motors were not recovered. RSRM reusability offered unique opportunities to learn about the hardware. NASA is moving forward with the Space Launch System that incorporates propulsion systems that takes advantage of the heritage Shuttle and Ares solid motor programs. These unique challenges, features of the RSRM, materials and manufacturing issues, and design improvements will be discussed in the paper.

Moore, D. R.↗

Regional climate change predictions from the Goddard Institute for Space Studies high resolution GCM

Model simulations of global climate change are seen as an essential component of any program aimed at understanding human impact on the global environment. A major weakness of current general circulation models (GCMs), however, is their inability to predict reliably the regional consequences of a global scale change, and it is these regional scale predictions that are necessary for studies of human/environmental response. This research is directed toward the development of a methodology for the validation of the synoptic scale climatology of GCMs. This is developed with regard to the Goddard Institute for Space Studies (GISS) GCM Model 2, with the specific objective of using the synoptic circulation form a doubles CO2 simulation to estimate regional climate change over North America, south of Hudson Bay. This progress report is specifically concerned with validating the synoptic climatology of the GISS GCM, and developing the transfer function to derive grid-point temperatures from the synoptic circulation. Principal Components Analysis is used to characterize the primary modes of the spatial and temporal variability in the observed and simulated climate, and the model validation is based on correlations between component loadings, and power spectral analysis of the component scores. The results show that the high resolution GISS model does an excellent job of simulating the synoptic circulation over the U.S., and that grid-point temperatures can be predicted with reasonable accuracy from the circulation patterns.

Crane, Robert G.↗

Characterization of microgravity effects on bone structure and strength using fractal analysis

The effect of micro-gravity on the musculoskeletal system has been well studied. Significant changes in bone and muscle have been shown after long term space flight. Similar changes have been demonstrated due to bed rest. Bone demineralization is particularly profound in weight bearing bones. Much of the current techniques to monitor bone condition use bone mass measurements. However, bone mass measurements are not reliable to distinguish Osteoporotic and Normal subjects. It has been shown that the overlap between normals and osteoporosis is found for all of the bone mass measurement technologies: single and dual photon absorptiometry, quantitative computed tomography and direct measurement of bone area/volume on biopsy as well as radiogrammetry. A similar discordance is noted in the fact that it has not been regularly possible to find the expected correlation between severity of osteoporosis and degree of bone loss. Structural parameters such as trabecular connectivity have been proposed as features for assessing bone conditions. In this report, we use fractal analysis to characterize bone structure. We show that the fractal dimension computed with MRI images and X-Ray images of the patella are the same. Preliminary experimental results show that the fractal dimension computed from MRI images of vertebrae of human subjects before bedrest is higher than during bedrest.

Acharya, Raj S.↗

On the Performance of Adaptive Data Rate over Deep Space Ka-Bank Link: Case Study Using Kepler Data

Future missions envisioned for both human and robotic exploration demand increasing communication capacity through the use of Ka-band communications. The Ka-band channel, being more sensitive to weather impairments, presents a unique trade-offs between data storage, latency, data volume and reliability. While there are many possible techniques for optimizing Ka-band operations such as adaptive modulation and coding and site-diversity, this study focus exclusively on the use of adaptive data rate (ADR) to achieve significant improvement in the data volume-availability tradeoff over a wide range of link distances for near Earth and Mars exploration. Four years of Kepler Ka-band downlink symbol signal-to-noise (SNR) data reported by the Deep Space Network were utilized to characterize the Ka-band channel statistics at each site and conduct various what-if performance analysis for different link distances. We model a notional closed-loop adaptive data rate system in which an algorithm predicts the channel condition two-way light time (TWLT) into the future using symbol SNR reported in near-real time by the ground receiver and determines the best data rate to use. Fixed and adaptive margins were used to mitigate errors in channel prediction. The performance of this closed-loop adaptive data rate approach is quantified in terms of data volume and availability and compared to the actual mission configuration and a hypothetical, optimized single rate configuration assuming full a priori channel knowledge.

Gao, Jay L.↗

Thermal Protection for Mars Sample Return Earth Entry Vehicle: A Grand Challenge for Design Methodology and Reliability Verification

Mars Sample Return is our Grand Challenge for the coming decade. TPS (Thermal Protection System) nominal performance is not the key challenge. The main difficulty for designers is the need to verify unprecedented reliability for the entry system: current guidelines for prevention of backward contamination require that the probability of spores larger than 1 micron diameter escaping into the Earth environment be lower than 1 million for the entire system, and the allocation to TPS would be more stringent than that. For reference, the reliability allocation for Orion TPS is closer to 11000, and the demonstrated reliability for previous human Earth return systems was closer to 1100. Improving reliability by more than 3 orders of magnitude is a grand challenge indeed. The TPS community must embrace the possibility of new architectures that are focused on reliability above thermal performance and mass efficiency. MSR (Mars Sample Return) EEV (Earth Entry Vehicle) will be hit with MMOD (Micrometeoroid and Orbital Debris) prior to reentry. A chute-less aero-shell design which allows for self-righting shape was baselined in prior MSR studies, with the assumption that a passive system will maximize EEV robustness. Hence the aero-shell along with the TPS has to take ground impact and not break apart. System verification will require testing to establish ablative performance and thermal failure but also testing of damage from MMOD, and structural performance at ground impact. Mission requirements will demand analysis, testing and verification that are focused on establishing reliability of the design. In this proposed talk, we will focus on the grand challenge of MSR EEV TPS and the need for innovative approaches to address challenges in modeling, testing, manufacturing and verification.

Design and Verification for Reliability↗

Situation Awareness Implications of Adaptive Automation of Air Traffic Controller Information Processing Functions

The goal of this research was to define a measure of situation awareness (SA) in an air traffic control (ATC) task and to assess the influence of adaptive automation (AA) of various information processing functions on controller perception, comprehension and projection. The measure was also to serve as a basis for defining and developing an approach to triggering dynamic control allocations, as part of AA, based on controller SA. To achieve these objectives, an enhanced version of an ATC simulation (Multitask (copyright)) was developed for use in two human factors experiments. The simulation captured the basic functions of Terminal Radar Approach Control (TRACON) and was capable of presenting to operators four different modes of control, including information acquisition, information analysis, decision making and action implementation automation, as well as a completely manual control mode. The SA measure that was developed as part of the research was based on the Situation Awareness Global Assessment Technique (SAGAT), previous goal-directed task analyses of enroute control and TRACON, and a separate cognitive task analysis on the ATC simulation. The results of the analysis on Multitask were used as a basis for formulating SA queries as part of the SAGAT-based approach to measuring controller SA, which was used in the experiments. A total of 16 subjects were recruited for both experiments. Half the subjects were used in Experiment #1, which focused on assessing the sensitivity and reliability of the SA measurement approach in the ATC simulation. Comparisons were made of manual versus automated control. The remaining subjects were used in the second experiment, which was intended to more completely describe the SA implications of AA applied to specific controller information processing functions, and to describe how the measure could ultimately serve as a trigger of dynamic function allocations in the application of AA to ATC. Comparisons were made of the sensitivity of the SA measure to automation manipulations impacting both higher-order information processing functions, such as information analysis and decision making, versus lower-order functions, including information acquisition and action implementation. All subjects were exposed to all forms of AA of the ATC task and the manual control condition. The approach to AA used in both experiments was to match operator workload, assessed using a secondary task, to dynamic control allocations in the primary task. In total, the subjects in each experiment participated in 10 trials with each lasting between 45 minutes and 1 hour. In both experiments, ATC performance was measured in terms of aircraft cleared, conflicting, and collided. Secondary task (gauge monitoring) performance was assessed in terms of a hit-to-signal ratio. As part of the SA measure, three simulation freezes were conducted during each trial to administer queries on Level 1, 2, and 3 SA.

Kaber, David B.↗

Near-Earth Phase Risk Comparison of Human Mars Campaign Architectures

A risk analysis of the launch, orbital assembly, and Earth-departure phases of human Mars exploration campaign architectures was completed as an extension of a probabilistic risk assessment (PRA) originally carried out under the NASA Constellation Program Ares V Project. The objective of the updated analysis was to study the sensitivity of loss-of-campaign risk to such architectural factors as composition of the propellant delivery portion of the launch vehicle fleet (Ares V heavy-lift launch vehicle vs. smaller/cheaper commercial launchers) and the degree of launcher or Mars-bound spacecraft element sparing. Both a static PRA analysis and a dynamic, event-based Monte Carlo simulation were developed and used to evaluate the probability of loss of campaign under different sparing options. Results showed that with no sparing, loss-of-campaign risk is strongly driven by launcher count and on-orbit loiter duration, favoring an all-Ares V launch approach. Further, the reliability of the all-Ares V architecture showed significant improvement with the addition of a single spare launcher/payload. Among architectures utilizing a mix of Ares V and commercial launchers, those that minimized the on-orbit loiter duration of Mars-bound elements were found to exceed the reliability of no spare all-Ares V campaign if unlimited commercial vehicle sparing was assumed

Manning, Ted A.↗

NASA-STD-7009 Guidance Document for Human Health and Performance Models and Simulations

Rigorous verification, validation, and credibility (VVC) processes are imperative to ensure that models and simulations (MS) are sufficiently reliable to address issues within their intended scope. The NASA standard for MS, NASA-STD-7009 (7009) [1] was a resultant outcome of the Columbia Accident Investigation Board (CAIB) to ensure MS are developed, applied, and interpreted appropriately for making decisions that may impact crew or mission safety. Because the 7009 focus is engineering systems, a NASA-STD-7009 Guidance Document is being developed to augment the 7009 and provide information, tools, and techniques applicable to the probabilistic and deterministic biological MS more prevalent in human health and performance (HHP) and space biomedical research and operations.

numerical analysis↗

A Vehicle Management End-to-End Testing and Analysis Platform for Validation of Mission and Fault Management Algorithms to Reduce Risk for NASA's Space Launch System

The engineering development of the new Space Launch System (SLS) launch vehicle requires cross discipline teams with extensive knowledge of launch vehicle subsystems, information theory, and autonomous algorithms dealing with all operations from pre-launch through on orbit operations. The characteristics of these spacecraft systems must be matched with the autonomous algorithm monitoring and mitigation capabilities for accurate control and response to abnormal conditions throughout all vehicle mission flight phases, including precipitating safing actions and crew aborts. This presents a large and complex system engineering challenge, which is being addressed in part by focusing on the specific subsystems involved in the handling of off-nominal mission and fault tolerance with response management. Using traditional model based system and software engineering design principles from the Unified Modeling Language (UML) and Systems Modeling Language (SysML), the Mission and Fault Management (M&FM) algorithms for the vehicle are crafted and vetted in specialized Integrated Development Teams (IDTs) composed of multiple development disciplines such as Systems Engineering (SE), Flight Software (FSW), Safety and Mission Assurance (S&MA) and the major subsystems and vehicle elements such as Main Propulsion Systems (MPS), boosters, avionics, Guidance, Navigation, and Control (GNC), Thrust Vector Control (TVC), and liquid engines. These model based algorithms and their development lifecycle from inception through Flight Software certification are an important focus of this development effort to further insure reliable detection and response to off-nominal vehicle states during all phases of vehicle operation from pre-launch through end of flight. NASA formed a dedicated M&FM team for addressing fault management early in the development lifecycle for the SLS initiative. As part of the development of the M&FM capabilities, this team has developed a dedicated testbed that integrates specific M&FM algorithms, specialized nominal and off-nominal test cases, and vendor-supplied physics-based launch vehicle subsystem models. Additionally, the team has developed processes for implementing and validating these algorithms for concept validation and risk reduction for the SLS program. The flexibility of the Vehicle Management End-to-end Testbed (VMET) enables thorough testing of the M&FM algorithms by providing configurable suites of both nominal and off-nominal test cases to validate the developed algorithms utilizing actual subsystem models such as MPS. The intent of VMET is to validate the M&FM algorithms and substantiate them with performance baselines for each of the target vehicle subsystems in an independent platform exterior to the flight software development infrastructure and its related testing entities. In any software development process there is inherent risk in the interpretation and implementation of concepts into software through requirements and test cases into flight software compounded with potential human errors throughout the development lifecycle. Risk reduction is addressed by the M&FM analysis group working with other organizations such as S&MA, Structures and Environments, GNC, Orion, the Crew Office, Flight Operations, and Ground Operations by assessing performance of the M&FM algorithms in terms of their ability to reduce Loss of Mission and Loss of Crew probabilities. In addition, through state machine and diagnostic modeling, analysis efforts investigate a broader suite of failure effects and associated detection and responses that can be tested in VMET to ensure that failures can be detected, and confirm that responses do not create additional risks or cause undesired states through interactive dynamic effects with other algorithms and systems. VMET further contributes to risk reduction by prototyping and exercising the M&FM algorithms early in their implementation and without any inherent hindrances such as meeting FSW processor scheduling constraints due to their target platform - ARINC 653 partitioned OS, resource limitations, and other factors related to integration with other subsystems not directly involved with M&FM such as telemetry packing and processing. The baseline plan for use of VMET encompasses testing the original M&FM algorithms coded in the same C++ language and state machine architectural concepts as that used by Flight Software. This enables the development of performance standards and test cases to characterize the M&FM algorithms and sets a benchmark from which to measure the effectiveness of M&FM algorithms performance in the FSW development and test processes.

Trevino, Luis↗

Design of evaporator of spacelab refrigerator/freezer

An Evaporator has been designed for NASA-Johnson Space Center Life Sciences to conduct experiments in Spacelab mission SLS-1 using different samples such as blood, urine, human tissues etc. Two units will fly - one as a Refrigerator (4 C) and the other as a Freezer (-22 C). The evaporator tube is dip brazed on a grooved flat plate. Aluminum heat sink is dip brazed on the other side of the plate. Freon R5O2 is pumped through the tube and air is circulated over the finned surface to transfer heat. As freon 5O2 is considered toxic, the whole freon tube is covered with an evaporator cover to contain any freon leakage to avoid exposure to crew members. This containment is under vacuum and this pressure is monitored along with the freon pressure to determine freon leakage so that necessary steps can be taken to stop contamination of the spacelab air. An stress analysis has been done and it is found to have adequate safety margin to meet the requirements of NASA safety and reliability standards.

Hye, A.↗

Project UM-HAUL: A self-unloading reusable lunar lander

The establishment of a lunar base is technologically and financially challenging. Given the necessary resources and political support, it can be done. In addition to the geopolitical obstacles, however, there are logistical problems involved in establishing such bases that can only be overcome with the acquisition of a significant transportation and communications network in the Earth-Moon spatial region. Considering the significant number of payloads that will be required in this process, the mass-specific cost of launching these payloads, and the added risk and cost of human presence in space, it is clearly desirable to automate major parts of such an operation. One very costly and time-consuming factor in this picture is the delivery of payloads to the Moon. Foreseeable payloads would include atmospheric modules, inflatable habitat kits, energy and oxygen plant elements, ground vehicles, laboratory modules, crew supplies, etc. The duration of high-risk human presence on the Moon could be greatly reduced if all such payloads were delivered to the prospective base site in advance of crew arrival. In this view, the idea of a 'Self-Unloading Reusable Lunar Lander' (SURLL) arises naturally. The general scenario depicts the lander being brought to low lunar orbit (LLO) from Earth atop a generic Orbital Transfer Vehicle (OTV). From LLO, the lander shuttles payloads down to the lunar surface, where, by means of some resident, detachable unloading device, it deploys the payloads and returns to orbit. The general goal is for the system to perform with maximum payload capability, automation, and reliability, while also minimizing environmental hazards, servicing needs, and mission costs. Our response to this demand is UM-HAUL, or the UnManned Heavy pAyload Unloader and Lander. The complete study includes a system description, along with a preliminary cost analysis and a design status assessment.

Source record↗

Engineering America's Current and Future Space Transportation Systems: 50 Years of Systems Engineering Innovation for Sustainable Exploration

Over the past 50 years, the National Aeronautics and Space Administration (NASA) has delivered space transportation solutions for America's complex missions, ranging from scientific payloads that expand knowledge, such as the Hubble Space Telescope, to astronauts and lunar rovers destined for voyages to the Moon. Currently, the venerable Space Shuttle, which has been in service since 1981, provides the United States' (U.S.) capability for both crew and heavy cargo to low-Earth orbit to' construct the International Space Station, before the Shuttle is retired in 2010. In the next decade, NASA will replace this system with a duo of launch vehicles: the Ares I Crew Launch Vehicle and the Ares V Cargo Launch Vehicle (Figure 1). The goals for this new system include increased safety and reliability coupled with lower operations costs that promote sustainable space exploration for decades to come. The Ares I will loft the Orion Crew Exploration Vehicle, while the heavy-lift Ares V will carry the Altair Lunar Lander and the equipment and supplies needed to construct a lunar outpost for a new generation of human and robotic space pioneers. This paper will provide details of the in-house systems engineering and vehicle integration work now being performed for the Ares I and planned for the Ares V. It will give an overview of the Ares I system-level test activities, such as the ground vibration testing that will be conducted in the Marshall Center's Dynamic Test Stand to verify the integrated vehicle stack's structural integrity and to validate computer modeling and simulation (Figure 2), as well as the main propulsion test article analysis to be conducted in the Static Test Stand. These activities also will help prove and refine mission concepts of operation, while supporting the spectrum of design and development work being performed by Marshall's Engineering Directorate, ranging from launch vehicles and lunar rovers to scientific spacecraft and associated experiments. Ultimately, fielding a robust space transportation solution that will carry international explorers and essential payloads will pave the way for a new century of scientific discovery beyond planet Earth.

Dmbacher, Daniel L.↗

Formal Aspects of Human-Automation Interaction

While new versions of automated control systems such as flight guidance systems are introduced at a rapid pace, it is widely recognized that user interaction with these machines is increasingly problematic. One cause for this difficulty that is commonly cited in the literature, is the discrepancy between the machine's behavior and the operator's (e.g., pilot) expectations. This paper discusses a formal approach to the analysis of operator's interaction with complex automated control systems. We focus attention on the issue of interface correctness; that is, on the question whether the display provides adequate information about the machine's configurations (states, modes, and associated parameters) and transitions, so as to enable the operator to successfully perform the specified set of tasks. To perform the analysis several assumptions are made: (1) A complete formal model of the machine's behavior is available (e.g., as a state transition system, or as a hybrid-machine); (2) A specification of operator's tasks is available and can be formally described (e.g., the reliable and predictable transition between activities involved in executing a climb to a new altitude); (3) The pilot is well trained and has a correct 'mental' model of the machine's response-map. By 'comparing' the machine's model with the set of operator's tasks we formally (i.e., mathematically) evaluate two questions: 1) does the machine's output interface (display) enable the operator to determine, unambiguously, what the current configuration (e.g., mode) of the machine is, and 2) does the display enable the operator to determine, unambiguously, what the next configuration of the machine will be, in response to a specified interaction by the operator (e.g., engaging a mode or changing a parameter such as a speed or target altitude). This paper describes a methodology for conducting such an evaluation using examples from automated flight control systems of modem 'glass cockpit' jetliners. Taxonomy of the different types of discrepancies that lead to pilot inability to resolve the current and next configuration of the machine is suggested. Data from incident reports involving 'mode confusion' is used to corroborate these discrepancies. Finally, means for compensating, either by augmenting the display and/or the operator's 'mental model' are briefly mentioned.

Degani, Asaf↗

Existing and Required Modeling Capabilities for Evaluating ATM Systems and Concepts

ATM systems throughout the world are entering a period of major transition and change. The combination of important technological developments and of the globalization of the air transportation industry has necessitated a reexamination of some of the fundamental premises of existing Air Traffic Management (ATM) concepts. New ATM concepts have to be examined, concepts that may place more emphasis on: strategic traffic management; planning and control; partial decentralization of decision-making; and added reliance on the aircraft to carry out strategic ATM plans, with ground controllers confined primarily to a monitoring and supervisory role. 'Free Flight' is a case in point. In order to study, evaluate and validate such new concepts, the ATM community will have to rely heavily on models and computer-based tools/utilities, covering a wide range of issues and metrics related to safety, capacity and efficiency. The state of the art in such modeling support is adequate in some respects, but clearly deficient in others. It is the objective of this study to assist in: (1) assessing the strengths and weaknesses of existing fast-time models and tools for the study of ATM systems and concepts and (2) identifying and prioritizing the requirements for the development of additional modeling capabilities in the near future. A three-stage process has been followed to this purpose: 1. Through the analysis of two case studies involving future ATM system scenarios, as well as through expert assessment, modeling capabilities and supporting tools needed for testing and validating future ATM systems and concepts were identified and described. 2. Existing fast-time ATM models and support tools were reviewed and assessed with regard to the degree to which they offer the capabilities identified under Step 1. 3 . The findings of 1 and 2 were combined to draw conclusions about (1) the best capabilities currently existing, (2) the types of concept testing and validation that can be carried out reliably with such existing capabilities and (3) the currently unavailable modeling capabilities that should receive high priority for near-term research and development. It should be emphasized that the study is concerned only with the class of 'fast time' analytical and simulation models. 'Real time' models, that typically involve humans-in-the-loop, comprise another extensive class which is not addressed in this report. However, the relationship between some of the fast-time models reviewed and a few well-known real-time models is identified in several parts of this report and the potential benefits from the combined use of these two classes of models-a very important subject-are discussed in chapters 4 and 7.

Odoni, Amedeo R.↗

A Satellite Mortality Study to Support Space Systems Lifetime Prediction

Estimating the operational lifetime of satellites and spacecraft is a complex process. Operational lifetime can differ from mission design lifetime for a variety of reasons. Unexpected mortality can occur due to human errors in design and fabrication, to human errors in launch and operations, to random anomalies of hardware and software or even satellite function degradation or technology change, leading to unrealized economic or mission return. This study focuses on data collection of public information using, for the first time, a large, publically available dataset, and preliminary analysis of satellite lifetimes, both operational lifetime and design lifetime. The objective of this study is the illustration of the relationship of design life to actual lifetime for some representative classes of satellites and spacecraft. First, a Weibull and Exponential lifetime analysis comparison is performed on the ratio of mission operating lifetime to design life, accounting for terminated and ongoing missions. Next a Kaplan-Meier survivor function, standard practice for clinical trials analysis, is estimated from operating lifetime. Bootstrap resampling is used to provide uncertainty estimates of selected survival probabilities. This study highlights the need for more detailed databases and engineering reliability models of satellite lifetime that include satellite systems and subsystems, operations procedures and environmental characteristics to support the design of complex, multi-generation, long-lived space systems in Earth orbit.

Fox, George↗