Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software engineering safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Autonomous Flight Safety System September 27, 2005, Aircraft Test

This report describes the first aircraft test of the Autonomous Flight Safety System (AFSS). The test was conducted on September 27, 2005, near Kennedy Space Center (KSC) using a privately-owned single-engine plane and evaluated the performance of several basic flight safety rules using real-time data onboard a moving aerial vehicle. This test follows the first road test of AFSS conducted in February 2005 at KSC. AFSS is a joint KSC and Wallops Flight Facility (WEF) project that is in its third phase of development. AFSS is an independent subsystem intended for use with Expendable Launch Vehicles that uses tracking data from redundant onboard sensors to autonomously make flight termination decisions using software-based rules implemented on redundant flight processors. The goals of this project are to increase capabilities by allowing launches from locations that do not have or cannot afford extensive ground-based range safety assets, to decrease range costs, and to decrease reaction time for special situations. The mission rules are configured for each operation by the responsible Range Safety authorities and can be loosely categorized in four major categories: Parameter Threshold Violations, Physical Boundary Violations present position and instantaneous impact point (TIP), Gate Rules static and dynamic, and a Green-Time Rule. Examples of each of these rules were evaluated during this aircraft test.

Simpson, James C.↗

Development of Autonomous Aerobraking (Phase 1)

The NASA Engineering and Safety Center received a request from Mr. Daniel Murri (NASA Technical Fellow for Flight Mechanics) to develop an autonomous aerobraking capability. An initial evaluation for all phases of this assessment was approved to proceed at the NESC Review Board meeting. The purpose of phase 1 of this study was to provide an assessment of the feasibility of autonomous aerobraking. During this phase, atmospheric, aerodynamic, and thermal models for a representative spacecraft were developed for both the onboard algorithm known as Autonomous Aerobraking Development Software, and a ground-based "truth" simulation developed for testing purposes. The results of the phase 1 assessment are included in this report.

Murri, Daniel G.↗

From Bridges and Rockets, Lessons for Software Systems

Although differences exist between building software systems and building physical structures such as bridges and rockets, enough similarities exist that software engineers can learn lessons from failures in traditional engineering disciplines. This paper draws lessons from two well-known failures the collapse of the Tacoma Narrows Bridge in 1940 and the destruction of the space shuttle Challenger in 1986 and applies these lessons to software system development. The following specific applications are made: (1) the verification and validation of a software system should not be based on a single method, or a single style of methods; (2) the tendency to embrace the latest fad should be overcome; and (3) the introduction of software control into safety-critical systems should be done cautiously.

Holloway, C. Michael↗

Implementation of Human System Integration Workshop at NASA for Human Spaceflight

The human is a key element in the complex system of systems underlying space exploration missions. As a critical system, its operating bands and requirements need to be characterized and integrated with other systems. Optimal integration of the human system with hardware and software elements has an impact on multiple aspects of mission execution, including human health and performance, risk mitigation, effective design and functionality, enhanced safety, and reduced lifecycle costs. The field of Human Systems Integration (HSI) represents an interdisciplinary and comprehensive cross-cutting approach encompassing technical and management processes for integrating human as a system consideration and objective within and across all other system components and multiple domains. In addition to human activities, HSI covers training, operations and support dimensions. Moreover, HSI is an essential enabler to systems engineering practice, emphasizing human system aspects toward optimizing fully integrated system of systems performance while systematically infusing the needs of all users during the earliest stages of development. Consistent with the National Space Exploration Campaign, NASA is developing the Gateway, a lunar orbiting platform that will serve as astronaut habitat, support transit to deep space, validate new technologies and systems, and function as a science laboratory and communications hub, among other uses. It is an essential element of a phase that will extend human exploration into deep space through evolvable infrastructure and advanced technology, supporting assembly and logistics of other exploration architecture elements. In an effort to explore the current status and forward plan of HSI implementation in the mission (system of systems) lifecycle, the HSI Employee Resource Group conducted an HSI workshop using the Gateway Program as a case study. It revealed how different organizations at the Johnson Space Center incorporate HSI in their processes in preparation for the development and operation of the Gateway. The workshop focused on HSI methodology for implementation of the six NASA HSI domains: Human Factors Engineering, Operations Resources, Habitability and Environment, Maintainability and Supportability, Safety, and Training. Results from the workshop are reported on this paper, as well as some historical background of HSI at NASA, and the success in using an Employee Resource Group to promote technical knowledge. The authors hope that this information can be used to disseminate best practices for translational applications to other space exploration systems.

Silva-Martinez, Jackelynne↗

Implementation of Human System Integration Workshop at NASA for Human Spaceflight

The human is a key element in the complex system of systems underlying space exploration missions. As a critical system, its operating bands and requirements need to be characterized and integrated with other systems. Optimal integration of the human system with hardware and software elements has an impact on multiple aspects of mission execution, including human health and performance, risk mitigation, effective design and functionality, enhanced safety, and reduced lifecycle costs. The field of Human Systems Integration (HSI) represents an interdisciplinary and comprehensive cross-cutting approach encompassing technical and management processes for integrating human as a system consideration and objective within and across all other system components and multiple domains. In addition to human activities, HSI covers training, operations and support dimensions. Moreover, HSI is an essential enabler to systems engineering practice, emphasizing human system aspects toward optimizing fully integrated system of systems performance while systematically infusing the needs of all users during the earliest stages of development. Consistent with the National Space Exploration Campaign, NASA is developing the Gateway, a lunar orbiting platform that will serve as astronaut habitat, support transit to deep space, validate new technologies and systems, and function as a science laboratory and communications hub, among other uses. It is an essential element of a phase that will extend human exploration into deep space through evolvable infrastructure and advanced technology, supporting assembly and logistics of other exploration architecture elements. In an effort to explore the current status and forward plan of HSI implementation in the mission (system of systems) lifecycle, the HSI Employee Resource Group conducted an HSI workshop using the Gateway Program as a case study. It revealed how different organizations at the Johnson Space Center incorporate HSI in their processes in preparation for the development and operation of the Gateway. The workshop focused on HSI methodology for implementation of the six NASA HSI domains: Human Factors Engineering, Operations Resources, Habitability and Environment, Maintainability and Supportability, Safety, and Training. Results from the workshop are reported on this paper, as well as some historical background of HSI at NASA, and the success in using an Employee Resource Group to promote technical knowledge. The authors hope that this information can be used to disseminate best practices for translational applications to other space exploration systems.

Silva-Martinez, Jackelynne↗

NASA Engineering and Safety Center Technical Bulletins 2007-2023

An NESC Technical Bulletin captures critical knowledge in the form of new engineering information or best practices in a one-page format that have resulted from NESC independent testing, analysis, and assessments. This document contains all NESC Technical Bulletins from 2007 through 2023.

additive manufacturing, battery, braycote, capacit↗

A case study of a system engineered for control by humans

Alternatives to the traditional concepts for real time health and safety operations were examined. The pitfalls of the conventional contingency planning for health and safety are highlighted. The Solar Maximum Mission (SMM) contingency planning and operations provides the evolution from the conventional people intensive health and safety operation, toward a night watchman mode of operations. The SMM spacecraft health and safety operations were budget constrained to the point that one operator was responsible for the health and safety of the entire spacecraft one week after launch. The spacecraft was a protoflight with brand new subsystem configurations, software and procedures. To manage the risks associated with this one man SMM health and safety operation, the real time contingency planning and operations centered around unambiguously identifying a system level problem, and reactively safing components susceptible to unrecoverable damage. The methodology applied to both analyzing and implementing this approach of SMM is shown.

Rothenberg, J.↗

Concurrent engineering research center

The projects undertaken by The Concurrent Engineering Research Center (CERC) at West Virginia University are reported and summarized. CERC's participation in the Department of Defense's Defense Advanced Research Project relating to technology needed to improve the product development process is described, particularly in the area of advanced weapon systems. The efforts committed to improving collaboration among the diverse and distributed health care providers are reported, along with the research activities for NASA in Independent Software Verification and Validation. CERC also takes part in the electronic respirator certification initiated by The National Institute for Occupational Safety and Health, as well as in the efforts to find a solution to the problem of producing environment-friendly end-products for product developers worldwide. The 3M Fiber Metal Matrix Composite Model Factory Program is discussed. CERC technologies, facilities,and personnel-related issues are described, along with its library and technical services and recent publications.

Callahan, John R.↗

Team Expo: A State-of-the-Art JSC Advanced Design Team

In concert with the NASA-wide Intelligent Synthesis Environment Program, the Exploration Office at the Johnson Space Center has assembled an Advanced Design Team. The purpose of this team is two-fold. The first is to identify, use, and develop software applications, tools, and design processes that streamline and enhance a collaborative engineering environment. The second is to use this collaborative engineering environment to produce conceptual, system-level-of-detail designs in a relatively short turnaround time, using a standing team of systems and integration experts. This includes running rapid trade studies on varying mission architectures, as well as producing vehicle and/or subsystem designs. The standing core team is made up of experts from all of the relevant engineering divisions (e.g. Power, Thermal, Structures, etc.) as well as representatives from Risk and Safety, Mission Operations, and Crew Life Sciences among others. The Team works together during 2- hour sessions in the same specially enhanced room to ensure real-time integration/identification of cross-disciplinary issues and solutions. All subsystem designs are collectively reviewed and approved during these same sessions. In addition there is an Information sub-team that captures and formats all data and makes it accessible for use by the following day. The result is Team Expo: an Advanced Design Team that is leading the change from a philosophy of "over the fence" design to one of collaborative engineering that pushes the envelope to achieve the next-generation analysis and design environment.

Tripathi, Abhishek↗

Results from NASA Agile Teams Study

In order to meet the demands of the current global economy, a study of agile teams at NASA was conducted by the NASA Engineering and Safety Center (NESC) to explore how the Agency can become more adaptable and flexible due to several influences, including the maturity and availability of digital tools and NASA’s increased reliance on commercial providers. NESC Technical Discipline Teams (TDTs) perform annual studies to understand the needs of their stakeholders, establish a state of the discipline, and inform strategic planning efforts. As part of the 2022 interview series, the Systems Engineering TDT utilized the dissertation work of Dr. Jackelynne Silva-Martinez that focused on NASA agile teams. The Systems Engineering TDT partnered with the Software and Human Factors TDTs on the formulation of interview questions and subsequent solicitation of customer inputs, which helped attract diverse agile teams across the Agency. 34 participants were interviewed, including civil servants and contractors, with open-ended questions related to their teams’ adoption and transition to agile. Participants were also questioned about their perceptions of the implementation of agile approaches across the Agency. Results showed a consistent framing of agile as incremental knowledge growth, a way of showing progress, and as the incorporation of frequent customer feedback. However, participants emphasized a lack of a common understanding of agile across the Agency, which sometimes caused managers and engineers to be reluctant to accept and support them. Results also showed the most successful agile teams had formal training with over five years of agile experience, used retrospectives, and tailored their agile processes for their specific situation and needs. This paper provides details of the interview responses gathered in the study and suggests actions for NASA to become more agile.

NASA↗

Alternative Metrics for Evaluating the Resilence of Advanced Life Support Systems

Ensuring the safety of the crew is a key performance requirement of a life support system. However, a number of conceptual and practical difficulties arise when devising metrics to concretely measure the ability of a life support system to maintain critical functions in the presence of anticipated and unanticipated faults. Resilience is a dynamic property of a life support system that depends on the complex interactions between faults, controls and system hardware. We review some of the approaches to understanding the robustness or resilience of complex systems being developed in diverse fields such as ecology, software engineering and cell biology and discuss their applicability to regenerative life support systems. We also consider how approaches to measuring resilience vary depending on system design choices such as the definition and choice of the nominal operating regime. Finally, we explore data collection and implementation issues such as the key differences between the instantaneous or conditional and average or overall measures of resilience. Extensive simulation of a hybrid computational model of a water revitalization subsystem (WRS) with probabilistic, component-level faults provides data about off-nominal behavior of the system. The data are used to consider alternative measures of resilience as predictors of the system's ability to recover from component-level faults.

Bell, Ann Maria↗

Synthesis of Correct Digital Controller Models from Specifications by Model Transformation (21-0320)

The design of high consequence controllers (in weapons systems, autonomy, etc.) that do what they are supposed to do is a significant challenge. Testing simply does not come close to meeting the requirements for assurance. Today circuit designers at Sandia (and elsewhere) typically capture the core behavior of their components using state models in tools such as STATEFLOW. They then check that their models meet certain requirements (e.g. “The system bus must not deadlock” or “both traffic lights at an intersection must not be green at the same time”) using tools called model checkers. If the model checker returns “yes” then the property is guaranteed to be satisfied by the model. However, there are several drawbacks to this industry practice: (1) there is a lot of detail to get right, this is particularly challenging when there are multiple components requiring complex coordination (2) any errors returned by the model checker have to be traced back through the design and fixed, necessitating rework, (3) there are severe scalability problems with this approach, particularly when dealing with concurrency. All this places high demands on the designers who now face not only an accelerated schedule but also controllers of increasing complexity. This report describes a new and fundamentally different approach to the construction of safety-critical digital controllers. Instead of directly constructing a complete model and then trying to verify it, the designer can start with an initial abstract (think “sketch”) model plus the requirements, from which a correct concrete model is automatically synthesized. There is no need for post-hoc verification of required functional properties. Having tool to carry this out will significantly impact the nation’s ability to ensure the safety of high-consequence digital systems. The approach has been implemented in a prototype tool, along with a suite of examples, including ones that reflect actual problems faced by designers. Our approach operates on a variant of Statecharts developed at Sandia called Qspecs. Statecharts are a widely used formalism for developing concurrent reactive systems, supporting scalability through allowing state models containing composite states, which are the serial or parallel composition of substates which can themselves contain statecharts. Statecharts enable an incremental style of development, in which states are progressively refined to incorporate greater detail in an incremental model of software development. Our approach formulates a set of constraints from the structure of the models and the requirements and propagates these constraints to a fixpoint. The solution to the constraints is an inductive invariant along with guards on the transitions. We also show how our approach extends to implementation refinement, decomposition, composition, and elaboration. We currently handle safety requirements written in LTL (Linear Temporal Logic)

42 ENGINEERING↗

Launch Commit Criteria Monitoring Agent

The Spaceport Processing Systems Branch at NASA Kennedy Space Center has developed and deployed a software agent to monitor the Space Shuttle's ground processing telemetry stream. The application, the Launch Commit Criteria Monitoring Agent, increases situational awareness for system and hardware engineers during Shuttle launch countdown. The agent provides autonomous monitoring of the telemetry stream, automatically alerts system engineers when predefined criteria have been met, identifies limit warnings and violations of launch commit criteria, aids Shuttle engineers through troubleshooting procedures, and provides additional insight to verify appropriate troubleshooting of problems by contractors. The agent has successfully detected launch commit criteria warnings and violations on a simulated playback data stream. Efficiency and safety are improved through increased automation.

Semmel, Glenn S.↗

NEO Test Stand Analysis

A project within SwampWorks is building a test stand to hold regolith to study how dust is ejected when exposed to the hot exhaust plume of a rocket engine. The test stand needs to be analyzed, finalized, and fabrication drawings generated to move forward. Modifications of the test stand assembly were made with Creo 2 modeling software. Structural analysis calculations were developed by hand to confirm if the structure will hold the expected loads while optimizing support positions. These calculations when iterated through MatLab demonstrated the optimized position of the vertical support to be 98'' from the far end of the stand. All remaining deflections were shown to be under the 0.6'' requirement and internal stresses to meet NASA Ground Support Equipment (GSE) Safety Standards. Though at the time of writing, fabrication drawings have yet to be generated, but are expected shortly after.

Internship↗

Initial Development of Fusion Magnet Simulation Capabilities for Performance and Safety Evaluation Using the MOOSE Framework

Fusion energy holds the promise of being a transformative technology as a carbon-neutral, sustainable source of energy. Whole device modeling and the development of fusion digital twins will be increasingly important for emerging fusion device concepts at both national laboratories and within the commercial fusion industry. However, meeting the challenge of whole device modeling of fusion energy devices requires robust, multiphysics, multiscale modeling and simulation technologies capable of running on large-scale supercomputers. Detailed analysis of individual systems at-scale is also required to ensure safe and efficient operation as well as provide the safety basis for future device designs and licensing activities. In a tokamak, toroidal and poloidal magnets confine and shape the fusion plasma to promote the fusion reaction. High plasma temperatures and high magnetic field requirements in modern design concepts (leading to high amounts of energy stored within each magnet) impose electrical, thermal, and mechanical loads on the magnet components, which in turn impacts the safety considerations of the magnet and their supporting systems. Idaho National Laboratory (INL) has a history of working in this space, including development and benchmarking of the Magnetic System Circuitry Analysis Program (MSCAP) and Magnet Arcing (MAGARC) codes to study magnet quench events; notably, MAGARC was used to study quenching during the ITER Engineering Design Activity. However, these legacy codes and capabilities are not parallel and scalable, and new tools are required for future advances in this area, which leads to the INL-developed Multiphysics Object-Oriented Simulation Environment (MOOSE) framework. Developed originally for fission reactor systems under United States Department of Energy, Office of Nuclear Energy modeling and simulation programs, the MOOSE framework has been well-suited to multiscale, multiphysics modeling and simulation needs for nuclear systems. The framework is open-source, well-tested, under continuous development and deployment, and developed to a Nuclear Quality Assurance, Level 1 software quality standard. MOOSE has also been used in the fusion space previously in several projects: INL’s Tritium Migration Analysis Program, Version 8 (TMAP8) for tritium migration, UK Atomic Energy Authority’s A Unified Resource for OpenMC (fusion) Reactor Applications (AURORA) code for fusion thermo-mechanical and neutronics analysis, and Argonne National Laboratory’s Cardinal for high-fidelity computational fluid dynamics and neutronics. However, to model superconducting magnets, several MOOSE enhancements are required: additions to the current MOOSE electromagnetic capabilities, new material libraries for superconductors of interest (such as YBCO), as well as fusion-specific models for thermo-mechanics. This talk will discuss initial development activities to build these capabilities in MOOSE, focusing on initial validation and benchmarking activities. Proposed coupling workflows and future work to support the simulation of fusion magnets and magnet structural assemblies for performance and safety evaluation in MOOSE will also be discussed.

70 - PLASMA PHYSICS AND FUSION TECHNOLOGY↗

Measurement and Controls Data Acquisition System

Measurement and Controls Data Acquisition System (MCDAS) is an application program that integrates the functions of two stand-alone programs: one for acquisition of data, the other for controls. MCDAS facilitates and improves testing of complex engineering systems by helping to perform calibration and setup of test systems and acquisition, dissemination, and processing of data. Features of MCDAS include an intuitive, user-friendly graphical user interface, a capability for acquiring data at rates greater than previously possible, cooperation between the data-acquisition software subsystem and alarm-checking and analytical components of the control software subsystem, and a capability for dissemination of data through fiber optics and virtual and wide-area networks, including networks that contain hand-held display units. The integration of the data acquisition and control software offers a safety advantage by making alarm information available to the control software in a more timely manner. By enabling the use of hand-held devices, MCDAS reduces the time spent by technicians asking for screen updates to determine effects of setup actions. Previously recorded data can be processed without interruption to current acquisition of data. Analysts can continue to view test parameters while test-data files are being generated.

Hall, Rick↗

Final Report of the NASA Office of Safety and Mission Assurance Agile Benchmarking Team

To ensure that the NASA Safety and Mission Assurance (SMA) community remains in a position to perform reliable Software Assurance (SA) on NASAs critical software (SW) systems with the software industry rapidly transitioning from waterfall to Agile processes, Terry Wilcutt, Chief, Safety and Mission Assurance, Office of Safety and Mission Assurance (OSMA) established the Agile Benchmarking Team (ABT). The Team's tasks were: 1. Research background literature on current Agile processes, 2. Perform benchmark activities with other organizations that are involved in software Agile processes to determine best practices, 3. Collect information on Agile-developed systems to enable improvements to the current NASA standards and processes to enhance their ability to perform reliable software assurance on NASA Agile-developed systems, 4. Suggest additional guidance and recommendations for updates to those standards and processes, as needed. The ABT's findings and recommendations for software management, engineering and software assurance are addressed herein.

Software Assurance↗

NASA's Space Launch System Program Update

Hardware and software for the world's most powerful launch vehicle for exploration is being welded, assembled, and tested today in high bays, clean rooms and test stands across the United States. NASA's Space Launch System (SLS) continued to make significant progress in 2014 with more planned for 2015, including firing tests of both main propulsion elements and the program Critical Design Review (CDR). Developed with the goals of safety, affordability, and sustainability, SLS will still deliver unmatched capability for human and robotic exploration. The initial Block 1 configuration will deliver more than 70 metric tons of payload to low Earth orbit (LEO). The evolved Block 2 design will deliver some 130 metric tons to LEO. Both designs offer enormous opportunity and flexibility for larger payloads, simplifying payload design as well as ground and on-orbit operations, shortening interplanetary transit times, and decreasing overall mission risk. Over the past year, every vehicle element has manufactured or tested hardware. An RS-25 liquid propellant engine was hotfire-tested at NASA's Stennis Space Center, Miss. for the first time since 2009 exercising and validating the new engine controller, the renovated A-1 test stand, and the test teams. Four RS-25s will power the SLS core stage. A qualification five-segment solid rocket motor incorporating several design, material, and process changes was scheduled to be test-fired in March at the prime contractor's facility in Utah. The booster also successfully completed its Critical Design Review (CDR) validating the planned design. All six major manufacturing tools for the core stage are in place at the Michoud Assembly Facility in Louisiana, and have been used to build numerous pieces of confidence, qualification, and even flight hardware, including barrel sections, domes and rings used to assemble the world's largest rocket stage. SLS Systems Engineering accomplished several key tasks including vehicle avionics software and hardware build and testing, scale model acoustic and base heating tests. Construction of the Interim Cryogenic Propulsion Stage (ICPS) began. Advanced development provided a look into the future of SLS. Shell buckling knockdown factor testing refined decades-old design margins that added thousands of pounds to rocket payloads. Adaptive manufacturing and structured light scanning development promised to cut the cost and time associated with manufacturing and testing. This paper will provide an overview of the progress made over the past year and provide a glimpse of 2015 milestones and beyond on the way to the first launch in 2018.

May, Todd↗