Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Advanced Air Mobility and Safety Management Systems

Our current air transportation system has underserved markets, including local, regional, intraregional, and urban transportation of both people and cargo. Recent advances in aviation technology such as small highly-automated vehicles, electric aircraft, and automated air traffic are enabling business opportunities in these markets. Advanced Air Mobility, or AAM, refers to a community effort to overcome the gaps in operational rules, safety analysis, and overall acceptance, so that these new operations will be possible. For full details, please see: https://www.nasa.gov/aam As we think about how we can safely introduce these new operations, fundamental questions about how the structure of Safety Management Systems can be applied to AAM, and how that structure can be used to help us overcome the necessary technical and societal obstacles arise. Two of these questions are: • How do we tailor the requirements and desired level of monitoring and assessment to achieve safety given the breadth of possible operations and the associated risk of those operations? • How do we aid innovation by rapidly evaluating the safety of novel operations without losing associated rigor? We assume that a Safety Management System that enables these future systems will incorporate knowledge of the acceptable level of risk, and will utilize data science to automate the core monitor, assess and mitigate functions that will allow us to respond to risks and hazards in time to prevent safety incidents. In 2018, the National Academies proposed an In-Time Aviation Safety Management System (IASMS) that would advance these goals. (https://www.nap.edu/catalog/24962/in-time-aviation-safety-management-challenges-and-research-for-an) The National Academies made a clear distinction between in-time systems, in which hazards could be identified and risks mitigated in time to prevent incidents, and real-time systems, since many hazards and risks do not need real-time data and analysis to detect and mitigate.

In-Time Aviation Safety Management System↗

Human Factors Research Needs for In-Time Aviation Safety Management Systems (IASMS) Design: Enabling the NASA “Sky for All” Future Airspace Vision

Integrated safety management will be paramount for safely enabling the envisioned transformations of the future National Airspace System. Addressing the increasing need for advanced data analytics and fusion of aviation safety data, managed by human decision-makers, is essential for realizing the vision. The proposal, if accepted, will discuss safety management system challenges and how the concept of In-time Aviation Safety Management Systems addresses the need. It will also discuss human factors challenges involved in future integrated safety management, including trust, over-reliance, human-optimized data visualization, human-autonomy teaming, training, communication and dissemination of data, situation awareness, task load, and accountability.

Lawrence J Prinzel III↗

Validation and Verification of Future Integrated Safety-Critical Systems Operating under Off-Nominal Conditions

Loss of control remains one of the largest contributors to aircraft fatal accidents worldwide. Aircraft loss-of-control accidents are highly complex in that they can result from numerous causal and contributing factors acting alone or (more often) in combination. Hence, there is no single intervention strategy to prevent these accidents and reducing them will require a holistic integrated intervention capability. Future onboard integrated system technologies developed for preventing loss of vehicle control accidents must be able to assure safe operation under the associated off-nominal conditions. The transition of these technologies into the commercial fleet will require their extensive validation and verification (V and V) and ultimate certification. The V and V of complex integrated systems poses major nontrivial technical challenges particularly for safety-critical operation under highly off-nominal conditions associated with aircraft loss-of-control events. This paper summarizes the V and V problem and presents a proposed process that could be applied to complex integrated safety-critical systems developed for preventing aircraft loss-of-control accidents. A summary of recent research accomplishments in this effort is also provided.

Belcastro, Christine M.↗

The NASA Aviation Safety Reporting System

This is the fourteenth in a series of reports based on safety-related incidents submitted to the NASA Aviation Safety Reporting System by pilots, controllers, and, occasionally, other participants in the National Aviation System (refs. 1-13). ASRS operates under a memorandum of agreement between the National Aviation and Space Administration and the Federal Aviation Administration. The report contains, first, a special study prepared by the ASRS Office Staff, of pilot- and controller-submitted reports related to the perceived operation of the ATC system since the 1981 walkout of the controllers' labor organization. Next is a research paper analyzing incidents occurring while single-pilot crews were conducting IFR flights. A third section presents a selection of Alert Bulletins issued by ASRS, with the responses they have elicited from FAA and others concerned. Finally, the report contains a list of publications produced by ASRS with instructions for obtaining them.

Source record↗

EMS helicopter incidents reported to the NASA Aviation Safety Reporting System

The objectives of this evaluation were to: Identify the types of safety-related incidents reported to the Aviation Safety Reporting System (ASRS) in Emergency Medical Service (EMS) helicopter operations; Describe the operational conditions surrounding these incidents, such as weather, airspace, flight phase, time of day; and Assess the contribution to these incidents of selected human factors considerations, such as communication, distraction, time pressure, workload, and flight/duty impact.

Connell, Linda J.↗

Adaptive Stress Testing: Using Reinforcement Learning to Find Failures in Safety-Critical Systems

Emerging applications in artificial intelligence, such as driverless cars and autonomous aircraft promise to be more efficient, cheaper to operate, and always available. However, ensuring the safety of these systems remains a major challenge to their certification and adoption. These autonomous systems are expected to routinely make safety-critical decisions where failures can have serious consequences including loss of life and property. Testing and validation techniques aim to identify and diagnose potential failures before the system is deployed. However, finding failure scenarios in autonomous systems can be very challenging due to high-dimensional and continuous state spaces, interaction with large environments over many time steps, and the rarity of failures. This talk presents Adaptive Stress Testing (AST), a simulation-based testing framework for finding the most likely path to a failure event of a safety-critical system. The key idea of AST is that stress testing can be formulated as a Partially Observable Markov Decision Process (POMDP), which enables reinforcement learning techniques to be used for finding failure events. Reinforcement learning algorithms can efficiently explore the search space and have been shown to scale to very large systems. We present applications of AST to find failures in various safety-critical systems including the aircraft collision avoidance systems, autonomous cars, and small unmanned aerial vehicles.

autonomous vehicles↗

Concept of Operations for an In-time Aviation Safety Management System (IASMS) for Upper E Airspace

The National Airspace System undergoes continuous change including in the Upper Class E airspace involving increasingly complex operations and a widening diversity of vehicles. To secure a safe future system, the National Academies recommended an In-time Aviation Safety Management System (IASMS) that is extensible to Upper E. Current Air Traffic Management is not cost-effective to scale for future Upper E operations and diversity of vehicles so the Federal Aviation Administration developed an Upper E Traffic Management ConOps to safely integrate the diverse operations and vehicles having different performance characteristics and flight missions without disrupting current operations including space launch and reentry, suborbital flights, supersonic and hypersonic flights, slow moving or stationary unmanned balloons, and long endurance fixed wing vehicles that are slow, stationary, or high speed. IASMS integrates state-of-the-art predictive modeling with reactive and proactive analytics to detect hazards and mitigate risk precursors for Upper E operators. IASMS identifies emergent safety risks exposed by transformation of the NAS with new and increasingly complex operations. Safety intelligence will also expand the data available and offer insight to new approaches for implementing safety improvements to mitigate risk with more seamless “in-time” integration across the policy, risk management, safety assurance, and promotion pillars of SMS.

K Ellis↗

Psychophysiological Research Methods to Assess Airline Flight Crew Resilient Performance in High-Fidelity Flight Simulation Scenarios

New concepts in aviation system safety thinking have emerged to consider not only what may go wrong, but also what can be learned when things go right. This approach forms a more comprehensive approach to system safety thinking. A need exists for methods to enable a better understanding of human contributions to aviation safety and how they may inform Safety Management Systems (SMS). A high-fidelity 737-800 simulation study was conducted to study how current type-rated commercial airline flight crews anticipate, monitor, respond to, and learn from expected and unexpected disturbances during line operations. A number of dependent measures were collected that included traditional SMS data types, but also non-traditional safety data to include multiple psychophysiological metrics. This paper describes the psychophysiological measures results that evinced the capability of measures to help identify resilient flight crews. Implications for future research and design of future In-time Aviation Safety Management Systems are discussed.

Psychophysiology↗

Work Practice Simulation of Complex Human-Automation Systems in Safety Critical Situations: The Brahms Generalized berlingen Model

The transition from the current air traffic system to the next generation air traffic system will require the introduction of new automated systems, including transferring some functions from air traffic controllers to on­-board automation. This report describes a new design verification and validation (V&V) methodology for assessing aviation safety. The approach involves a detailed computer simulation of work practices that includes people interacting with flight-critical systems. The research is part of an effort to develop new modeling and verification methodologies that can assess the safety of flight-critical systems, system configurations, and operational concepts. The 2002 Ueberlingen mid-air collision was chosen for analysis and modeling because one of the main causes of the accident was one crew's response to a conflict between the instructions of the air traffic controller and the instructions of TCAS, an automated Traffic Alert and Collision Avoidance System on-board warning system. It thus furnishes an example of the problem of authority versus autonomy. It provides a starting point for exploring authority/autonomy conflict in the larger system of organization, tools, and practices in which the participants' moment-by-moment actions take place. We have developed a general air traffic system model (not a specific simulation of Überlingen events), called the Brahms Generalized Ueberlingen Model (Brahms-GUeM). Brahms is a multi-agent simulation system that models people, tools, facilities/vehicles, and geography to simulate the current air transportation system as a collection of distributed, interactive subsystems (e.g., airports, air-traffic control towers and personnel, aircraft, automated flight systems and air-traffic tools, instruments, crew). Brahms-GUeM can be configured in different ways, called scenarios, such that anomalous events that contributed to the Überlingen accident can be modeled as functioning according to requirements or in an anomalous condition, as occurred during the accident. Brahms-GUeM thus implicitly defines a class of scenarios, which include as an instance what occurred at Überlingen. Brahms-GUeM is a modeling framework enabling "what if" analysis of alternative work system configurations and thus facilitating design of alternative operations concepts. It enables subsequent adaption (reusing simulation components) for modeling and simulating NextGen scenarios. This project demonstrates that BRAHMS provides the capacity to model the complexity of air transportation systems, going beyond idealized and simple flights to include for example the interaction of pilots and ATCOs. The research shows clearly that verification and validation must include the entire work system, on the one hand to check that mechanisms exist to handle failures of communication and alerting subsystems and/or failures of people to notice, comprehend, or communicate problematic (unsafe) situations; but also to understand how people must use their own judgment in relating fallible systems like TCAS to other sources of information and thus to evaluate how the unreliability of automation affects system safety. The simulation shows in particular that distributed agents (people and automated systems) acting without knowledge of each others' actions can create a complex, dynamic system whose interactive behavior is unexpected and is changing too quickly to comprehend and control.

complex systems↗

Psychophysiological Research Methods to Assess Airline Flight Crew Resilient Performance in High-Fidelity Flight Simulation Scenarios

New concepts in aviation system safety thinking have emerged to consider not only what may go wrong, but also what can be learned when things go right. This approach forms a more comprehensive approach to system safety thinking. A need exists for methods to enable a better understanding of human contributions to aviation safety and how they may inform Safety Management Systems (SMS). A high-fidelity 737-800 simulation study was conducted to study how current type-rated commercial airline flight crews anticipate, monitor, respond to, and learn from expected and unexpected disturbances during line operations. A number of dependent measures were collected that included traditional SMS data types, but also non-traditional safety data to include multiple psychophysiological metrics. This paper describes the psychophysiological measures results that evinced the capability of measures to help identify resilient flight crews. Implications for future research and design of future In-time Aviation Safety Management Systems are discussed.

Psychophysiology↗

NASA System Wide Safety Project Safety Metrics Research

This is a short set of PPT slides that we will use when we visit several US airlines to provide an introduction to a data collection task supporting the System Wide Safety Project. The goal is to gain an understanding of what airline dispatchers and other airline personnel see as hazards affecting the safety of flight. We want to list the hazards and how they are evaluated as safety metrics. This may eventually lead to an ability to monitor safety metrics in the National Airspace System and identify and predict possible unsafe situations.

Aviation safety↗

Chance-Constrained System Identification of Nonlinear Discrete Systems with Safety and Stability Guarantees

This paper presents a discrete-time nonlinear system identification method while satisfying the stability and safety properties of the system with high probability. An Extreme Learning Machine (ELM) is used with a Gaussian assumption on the function reconstruction error. A quadratically constrained quadratic program (QCQP) is developed with probabilistic safety and stability constraints that are only required to be satisfied at sampled points inside the invariant region. The proposed method is validated using two simulation examples: a two degrees-of-freedom (DoF) robot manipulator with constraints on joint angles whose trajectories are guaranteed to remain inside a safe set and on motion trajectories data of a hand-drawn shape.

Iman Salehi↗

Collaborative Approaches in Developing Environmental and Safety Management Systems for Commercial Space Transportation

The Federal Aviation Administration (FAA), Office of Commercial Space Transportation (AST) licenses and permits U.S. commercial space launch and reentry activities, and licenses the operation of non-federal launch and reentry sites. ASTs mission is to ensure the protection of the public, property, and the national security and foreign policy interests of the United States during commercial space transportation activities and to encourage, facilitate, and promote U.S. commercial space transportation. AST faces unique challenges of ensuring the protection of public health and safety while facilitating and promoting U.S. commercial space transportation. AST has developed an Environmental Management System (EMS) and a Safety Management System (SMS) to help meet its mission. Although the EMS and SMS were developed independently, the systems share similar elements. Both systems follow a Plan-Do-Act-Check model in identifying potential environmental aspects or public safety hazards, assessing significance in terms of severity and likelihood of occurrence, developing approaches to reduce risk, and verifying that the risk is reduced. This paper will describe the similarities between ASTs EMS and SMS elements and how AST is building a collaborative approach in environmental and safety management to reduce impacts to the environment and risks to the public.

Federal Aviation Administration (FAA)↗

Extracting Lessons of Human Performance and Resilience Management from a Study of Weather-Related Safety Risks and Incidents Reported to NASA's Aviation Safety Reporting System (ASRS)

We present a study of weather-related incident reports submitted to NASA’s Aviation Safety Reporting System (ASRS) by air carrier pilots and air traffic controllers in the US. Using specific examples, we examine the weather-related risks reported and the relevant aspects of human performance and resilience management exhibited during these incidents. We describe our methods of lesson extraction to maximize learning, including the use of advance algorithms, and we conclude with a review of the weather-related risks encountered and the resilient practices employed to mitigate them.

resilience↗

Some Challenges in the Design of Human-Automation Interaction for Safety-Critical Systems

Increasing amounts of automation are being introduced to safety-critical domains. While the introduction of automation has led to an overall increase in reliability and improved safety, it has also introduced a class of failure modes, and new challenges in risk assessment for the new systems, particularly in the assessment of rare events resulting from complex inter-related factors. Designing successful human-automation systems is challenging, and the challenges go beyond good interface development (e.g., Roth, Malin, & Schreckenghost 1997; Christoffersen & Woods, 2002). Human-automation design is particularly challenging when the underlying automation technology generates behavior that is difficult for the user to anticipate or understand. These challenges have been recognized in several safety-critical domains, and have resulted in increased efforts to develop training, procedures, regulations and guidance material (CAST, 2008, IAEA, 2001, FAA, 2013, ICAO, 2012). This paper points to the continuing need for new methods to describe and characterize the operational environment within which new automation concepts are being presented. We will describe challenges to the successful development and evaluation of human-automation systems in safety-critical domains, and describe some approaches that could be used to address these challenges. We will draw from experience with the aviation, spaceflight and nuclear power domains.

systems engineering↗

An Ontological Approach to Integrate Commercial Space Operations with an In-time Aviation Safety Management System (IASMS)

The emergence of commercial space operations (CSO) is one of many Advanced Air Mobility domains that pose major challenges to in-time safety assurance because of the different architectures used by the operators and other agents. The National Academies recognized the need to improve integration of disparate architectures and recommended that an In-time Aviation Safety Management System(IASMS) be developed to provide seamless connectivity across interacting architectures and enable in-time safety assurance. An ontological approach to integrating CSO with IASMS involves in-time Services, Functions, and Capabilities design to manage operational risks and inform changes to design. The resulting integrated architecture provides a common basis for risk management and in-time safety assurance.

K Ellis↗

Resilient Space Habitat Design Using Safety Controls

Space habitats will involve a complex and tightly coupled combination of hardware, software, and humans, while operating in challenging environments that pose many risks, both known and unknown. It will not be possible to design habitats that are immune to failure, nor will it be possible to foresee all possible failures. Rather than aiming for designs where ―failure is not an option,‖ habitats must be resilient to disruptions. We propose an approach to resilient design for space habitats based on the concept of safety controls from system safety engineering. We model disruptions using a state-and-trigger approach, where the space habitat is in one of three distinct states at each time instance: nominal, hazardous, or accident. We use safety controls as ways of preventing a system from entering or remaining in a hazardous or accident state. We develop a safety control option space for the habitat, from which designers can select the set of safety controls that best meet resilience, performance, and other system goals. The safety control option space is likely to be large, accordingly, we design a database that links safety controls to the applicable states and triggers. We demonstrate our approach on the early design stage of a Martian space habitat.

Safety↗