Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 307 records · Page 17

Validation and Verification (V&V) of Safety-Critical Systems Operating Under Off-Nominal Conditions

Loss of control (LOC) remains one of the largest contributors to aircraft fatal accidents worldwide. Aircraft LOC accidents are highly complex in that they can result from numerous causal and contributing factors acting alone or more often in combination. Hence, there is no single intervention strategy to prevent these accidents. Research is underway at the National Aeronautics and Space Administration (NASA) in the development of advanced onboard system technologies for preventing or recovering from loss of vehicle control and for assuring safe operation under off-nominal conditions associated with aircraft LOC accidents. The transition of these technologies into the commercial fleet will require their extensive validation and verification (V&V) and ultimate certification. The V&V of complex integrated systems poses highly significant technical challenges and is the subject of a parallel research effort at NASA. This chapter summarizes the V&V problem and presents a proposed process that could be applied to complex integrated safety-critical systems developed for preventing aircraft LOC accidents. A summary of recent research accomplishments in this effort is referenced.

Belcastro, Christine M.↗

Tactical Separation and Safety Alerting System for Terminal Airspace

Provision of tactical alerts to aid air traffic controllers in providing separation assurance in terminal airspace is hindered by the complexity of the airspace, its operations, and flight procedures. A prototype automation system is studied that provides controllers with both separation and safety alerts based on or derived from the separation standard for terminal airspace. The system models flight trajectories heuristically, with use of merged intent information from readily available sources: area navigation departure procedures, flight-plan routes, and arrival nominal interior routes used in terminal automation systems. Flight vertical intent is modeled according to standard procedural restrictions except when superseded by controller-issued altitude clearances. Importantly, flight trajectories are modeled for all aircraft, including those conducting visual approaches. New safety-alert thresholds for aircraft conducting visual approaches are studied. Performance of the system is evaluated through fast-time playback of recorded air traffic data from high-fidelity Human-In-The-Loop simulations and real-world operations in two Terminal Radar Approach Control facilities. The prototype system is found to produce a false-alert rate of 8% for separation alerts. The number and validity of safety alerts are studied by comparing with the current Conflict Alert system, showing that the false alerts of Conflict Alert are at 85% and they are avoided in the prototype system.

Air Traffic Management↗

Forming Human-Robot Teams Across Time and Space

NASA pushes telerobotics to distances that span the Solar System. At this scale, time of flight for communication is limited by the speed of light, inducing long time delays, narrow bandwidth and the real risk of data disruption. NASA also supports missions where humans are in direct contact with robots during extravehicular activity (EVA), giving a range of zero to hundreds of millions of miles for NASA s definition of "tele". . Another temporal variable is mission phasing. NASA missions are now being considered that combine early robotic phases with later human arrival, then transition back to robot only operations. Robots can preposition, scout, sample or construct in advance of human teammates, transition to assistant roles when the crew are present, and then become care-takers when the crew returns to Earth. This paper will describe advances in robot safety and command interaction approaches developed to form effective human-robot teams, overcoming challenges of time delay and adapting as the team transitions from robot only to robots and crew. The work is predicated on the idea that when robots are alone in space, they are still part of a human-robot team acting as surrogates for people back on Earth or in other distant locations. Software, interaction modes and control methods will be described that can operate robots in all these conditions. A novel control mode for operating robots across time delay was developed using a graphical simulation on the human side of the communication, allowing a remote supervisor to drive and command a robot in simulation with no time delay, then monitor progress of the actual robot as data returns from the round trip to and from the robot. Since the robot must be responsible for safety out to at least the round trip time period, the authors developed a multi layer safety system able to detect and protect the robot and people in its workspace. This safety system is also running when humans are in direct contact with the robot, so it involves both internal fault detection as well as force sensing for unintended external contacts. The designs for the supervisory command mode and the redundant safety system will be described. Specific implementations were developed and test results will be reported. Experiments were conducted using terrestrial analogs for deep space missions, where time delays were artificially added to emulate the longer distances found in space.

Hambuchen, Kimberly↗

System and Safety Analysis with SysAI A Statistical Learning Framework

This is a tutorial on how to use the SYSAI (System Analysis using Statistical AI), a flexible statistical learning framework for the V&V and analysis of complex and high-dimensional Aerospace systems with DNN and AI components. SYSAI provides functionality for a variety of analyses and V&V tasks, including statistical data analysis, high dimensional safety-envelope and time-series analysis, property checking, as well as intelligent test-case generation. The tutorial will demonstrate SYSAI with our industrial partner’s Autonomous Centerline Tracking system, which uses a DNN to enable autonomous aircraft taxiing as an example. Video & Tutorial

Statistical V&V for Complex safety-critical system↗

Robonaut 2 - IVA Experiments On-Board ISS and Development Towards EVA Capability

Robonaut 2 (R2) has completed its fixed base activities on-board the ISS and is scheduled to receive its climbing legs in early 2014. In its continuing line of firsts, the R2 torso finished up its on-orbit activities on its stanchion with the manipulation of space blanket materials and performed multiple tasks under teleoperation control by IVA astronauts. The successful completion of these two IVA experiments is a key step in Robonaut's progression towards an EVA capability. Integration with the legs and climbing inside the ISS will provide another important part of the experience that R2 will need prior to performing tasks on the outside of ISS. In support of these on-orbit activities, R2 has been traversing across handrails in simulated zero-g environments and working with EVA tools and equipment on the ground to determine manipulation strategies for an EVA Robonaut. R2 made significant advances in robotic manipulation of deformable materials in space while working with its softgoods task panel. This panel features quarter turn latches that secure a space blanket to the task panel structure. The space blanket covers two cloth cubes that are attached with Velcro to the structure. R2 was able to open and close the latches, pull back the blanket, and remove the cube underneath. R2 simulated cleaning up an EVA worksite as well, by replacing the cube and reattaching the blanket. In order to interact with the softgoods panel, R2 has both autonomously and with a human in the loop identified and localized these deformable objects. Using stereo color cameras, R2 identified characteristic elements on the softgoods panel then extracted the location and orientation of the object in its field of view using stereo disparity and kinematic transforms. R2 used both vision processing and supervisory control to successfully accomplish this important task. Teleoperation is a key capability for Robonaut's effectiveness as an EVA system. To build proficiency, crewmembers have attempted increasingly difficult tasks using R2 inside the Station. After donning motion capture equipment and a virtual reality visor, Expedition 34/35 flight engineer Tom Marshburn began operations with simple hand movements. Having gained confidence, Marshburn guided R2's arms in a leader-follower exercise with crewmate Chris Cassidy. He was also able to use the hand to grab a tumbling roll of tape, a task only demonstrable in microgravity. Later efforts saw Cassidy handle softgoods through shared control with ground operators, mimicking an activity previously achieved using only autonomy. Robotic climbing through the ISS on handrails requires both precision motion and compliant grasps in order to both position grippers on handrails/seat track and prevent large internal forces. R2 climbs using actively controlled compliance and torque limiting to meet both the precision and softness requirements. During a step, the attached leg is controlled to be strong and stiff in order to maintain precision trajectory tracking. The swing leg is controlled to be stiff but weak to minimize unintentional impact forces while maintaining precision. During a simulated dual limb grasp (as shown in Figure 1), the R2 controller maintains one limb rigid and one limb soft to prevent large internal forces from building up. R2's grippers also use a form of force control to limit grip force while not fully closed on either a handrail or seat track thus limiting unintentional forces on cables/objects that may be present in R2's translational path. The on-board torso R2 safety system relies on a single end-effector velocity limit to prevent potential impact forces from exceeding Station maximum load requirements. R2's mobile configuration required modifications to the velocity limiting safety function due to its large, dynamic inertia. R2's legs maneuver the robot's mass creating configuration dependent, joint-relative inertias. A single all-encompassing velocity limit to cover worst case inertia is prohibitively low. The upgraded R2 control and safety systems solve this problem using momentum limiting, momentum control, and kinetic energy minimization. Momentum and kinetic energy take the robot mass into account relieving low velocity restrictions on low inertia end-effectors while ensuring that the overall mass of R2 is limited from hazardous velocities. The momentum of R2's five safety nodes (each of the four end-effectors and the body) is monitored and compared to a single momentum limit. If any of the five nodes exceeds the safety limit, the motor power is removed and the robot comes to a stop. Momentum control/limiting also provides a simple, reliable method to integrate hand held tools into the safety system by providing the tool mass to the control system thus automatically reducing the allowable velocity of the end-effector with the tool. Work on the ground continues to build the skill set for an EVA Robonaut. Recent experiments (Figure 2) demonstrate how a teleoperator can use R2 to manipulate a tether hook, an important safety precaution on spacewalks. Another task displayed Robonaut's ability to pull back a protective jacket over a hose and search for damage, as well as inspect a quick-disconnect fitting for debris. Demonstrations such as these are indicative of EVA work done on ISS, specifically seen during a series of spacewalks over 2012 and 2013 where astronauts searched for an ammonia leak in one of the external cooling loops. Through experiments both on ISS and on the ground, R2 is evolving and providing the information needed to plan out the upgrades that will make an EVA Robonaut an effective tool. With the addition of legs, R2 will start climbing inside the space station and supply invaluable information on how the climbing strategies and task stabilization techniques must be refined. Ground R2 systems will continue to work with additional EVA tools and equipment in preparation for onboard IVA testing and future EVA applications.

Diftler, Myron↗

(ODIN): An Open Source, Low-Latency Data Integration & Visualization Framework for the NASA System Wide Safety Project's Disaster Response Safety Demonstration Series

The Open Data Integration Framework (ODIN) is an open source, low latency data integration and visualization framework (https://github.com/NASARace/race-odin) developed under NASA’s System WideSafety Program to demonstrate new safety capabilities designed to improve US airspace operations. Safety demonstrations are a set of increasingly complex (from public safety perspective) disaster response scenarios under which air systems must operate with increased capacity and include: 1) Wildland fire response, 2) Hurricane relief and recovery, 4) Emergency medical delivery via UAS and 4) Urban disaster relief. To accommodate disaster response, ODIN is field deployable and can scale on one or more multi-core, commodity laptops operating with full to limited or intermittent internet connectivity, conditions likely encountered during operations. ODIN runs as webserver with local, persistent data storage to serve either public or a secured, ad hoc network (e.g., an incident command post). The current released ODIN, ODIN-Fire is tailored for wildland fire management incorporating information on satellite overpasses with links to the near real-time data and imagery from the respective agencies. Included are winds data, an important variable for emergency responders and airspace operations, and high-resolution wind forecasts generated by super-computing resources and ingested into ODIN. As an open-source project, ODIN has attracted interest from multiple entities. We will show how 1) a commercial field instrument and data provider uses ODIN to help users visualize, publish and integrate their in-situ sensor network data and 2) ODIN’s capabilities to ingest, integrate and display near-real time satellite data with air traffic and a USFS winds forecast model used in fire response and post-fire assessment. Within NASA ODIN demonstrated novel, near terminal airspace safety capabilities for a project close-out event and previously it monitored the national airspace in real-time to meet an agency milestone. ODIN is presently under development for the anticipated hurricane relief and response demonstration notionally scheduled for the 2025-27 time frame and is available from NASA's github at the above link.

Aeronautics↗

Safety issues of manipulator systems under computer control

An overview of the development test flight (DTF-1) mission is presented, and the system design, safety requirements, and safety features are described. The lessons that were learned during the design and early development stages are also presented. The DTF-1 mission objectives are to evaluate: the overall man-machine performance in zero G, Flight Telerobotic Service manipulator design, and workstation design, including handcontrollers and displays. The payload bay and aft flight deck elements, and computer control of the DTF-1 are described. Recommendations for developing and implementing a safety system are presented, and some design alternatives for the next space-qualified telerobotic system are suggested.

Andary, James F.↗

Applying Formal Methods to Safety-Critical Systems

How do you know a proof is correct? Traditionally, mathematical proofs are socially verified – at least one human, following a set of implicit rules of natural language and logic, determines if the proof is believable. If the proof becomes overly tedious and/or is essential to some safety- or mission-critical application, it becomes necessary to determine the soundness to a higher standard. 'Formal methods' refer to mathematically rigorous techniques and tools that enable specification, design, and verification of hardware and software systems. The specification used in formal methods are statements in a mathematical logic while the formal verifications are deductions in that logic. Formal methods can be difficult or time/resource intensive, but offer a higher level of assurance than standard verification through testing or handwritten proofs. This talk will introduce formal methods, motivated by applications of interest to NASA, including uncrewed aircraft operations in the national airspace, urban air environments, and wildfire areas. The audience will be given a crash course in mechanically verified proofs in the Prototype Verification System (PVS), an interactive theorem prover.

Formal Methods↗

Surface Movement Incidents Reported to the NASA Aviation Safety Reporting System

Increasing numbers of aircraft are operating on the surface of airports throughout the world. Airport operations are forecast to grow by more that 50%, by the year 2005. Airport surface movement traffic would therefore be expected to become increasingly congested. Safety of these surface operations will become a focus as airport capacity planning efforts proceed toward the future. Several past events highlight the prevailing risks experienced while moving aircraft during ground operations on runways, taxiways, and other areas at terminal, gates, and ramps. The 1994 St. Louis accident between a taxiing Cessna crossing an active runway and colliding with a landing MD-80 emphasizes the importance of a fail-safe system for airport operations. The following study explores reports of incidents occurring on an airport surface that did not escalate to an accident event. The Aviation Safety Reporting System has collected data on surface movement incidents since 1976. This study sampled the reporting data from June, 1993 through June, 1994. The coding of the data was accomplished in several categories. The categories include location of airport, phase of ground operation, weather /lighting conditions, ground conflicts, flight crew characteristics, human factor considerations, and airport environment. These comparisons and distributions of variables contributing to surface movement incidents can be invaluable to future airport planning, accident prevention efforts, and system-wide improvements.

Connell, Linda J.↗

Developing a safe on-orbit cryogenic depot

New U.S. space initiatives will require technology to realize planned programs such as piloted lunar and Mars missions. Key to the optimal execution of such missions are high performance orbit transfer vehicles and propellant storage facilities. Large amounts of liquid hydrogen and oxygen demand a uniquely designed on-orbit cryogenic propellant depot. Because of the inherent dangers in propellant storage and handling, a comprehensive system safety program must be established. This paper shows how the myriad and complex hazards demonstrate the need for an integrated safety effort to be applied from program conception through operational use. Even though the cryogenic depot is still in the conceptual stage, many of the hazards have been identified, including fatigue due to heavy thermal loading from environmental and operating temperature extremes, micrometeoroid and/or depot ancillary equipment impact (this is an important problem due to the large surface area needed to house the large quantities of propellant), docking and maintenance hazards, and hazards associated with extended extravehicular activity. Various safety analysis techniques were presented for each program phase. Specific system safety implementation steps were also listed. Enhanced risk assessment was demonstrated through the incorporation of these methods.

Bahr, Nicholas J.↗

Architecture of the personnel protection systems for Spallation Neutron Source Second Target Station

The Oak Ridge National Laboratory (ORNL) is implementing a major upgrade to the Spallation Neutron Source (SNS) facility, encompassing the addition of the Second Target Station (STS). Preliminary design reviews have been conducted on several STS Personnel Protection Systems (PPS). The reviews focused primarily on the integration with the existing SNS PPS, the new proton transport tunnel, and the target areas. Development of the PPS is ongoing, to ensure a coherent safety system with the mission of protecting users and workers from prompt radiation hazards while providing high beam availability to operations. The STS PPS element in the Integrated Control System (ICS) is a facility-wide system composed of multiple safety subsystems, including the Ring to Second Target (RTST) beam transport tunnel, Target, Bunker and Instruments. Personnel working in all these geographic areas are protected by modular reliable PPS solutions. The safety system enforces access controls, radiation monitoring, beam destination control, and application of critical device inhibit upon detection of abnormal condition. It uses well-documented processes, Common Industrial Protocol (CIP) safety, pulsed test, and redundancy to achieve the desired Safety Integrity Level (SIL). This paper gives an architectural overview of the STS PPS and a detailed safety plan for the SNS facility, addressing safety solutions and human factors.

Michaelides, Tommy [ORNL] (ORCID:0000000190499869)↗

The Influence of Mental Workload in Causes of System Degradation in Air Traffic Control

System safety and resilience is a critical concern in the air traffic domain. An important element of maintaining system safety and resilience is the ability of systems to ‘degrade gracefully’. However, previous research on the causes of system degradation in the air traffic domain are sporadic, and the potential interaction between the causes of degradation, and the resulting possible compound effect on the entire system, has been under-researched. An interview study was conducted with 12 retired controllers as participants. The results of a thematic analysis revealed the key causes of system degradation, and the associated impact on the ability of the controllers to prevent system degradation or recover the system. Findings have direct implications for identifying and mitigating potential risks of increasingly automated air traffic control systems.

Edwards, Tamsyn E.↗

The Influence of Mental Workload in Causes of System Degradation in Air Traffic Control

System safety and resilience is a critical concern in the air traffic domain. An important element of maintaining system safety and resilience is the ability of systems to ‘degrade gracefully'. However, previous research on the causes of system degradation in the air traffic domain are sporadic, and the potential interaction between the causes of degradation, and the resulting possible compound effect on the entire system, has been under-researched. An interview study was conducted with 12 retired controllers as participants. The results of a thematic analysis revealed the key causes of system degradation, and the associated impact on the ability of the controllers to prevent system degradation or recover the system. Findings have direct implications for identifying and mitigating potential risks of increasingly automated air traffic control systems.

Edwards, Tamsyn↗

Safety Characteristics in System Application of Software for Human Rated Exploration Missions for the 8th IAASS Conference

NASA and its industry and international partners are embarking on a bold and inspiring development effort to design and build an exploration class space system. The space system is made up of the Orion system, the Space Launch System (SLS) and the Ground Systems Development and Operations (GSDO) system. All are highly coupled together and dependent on each other for the combined safety of the space system. A key area of system safety focus needs to be in the ground and flight application software system (GFAS). In the development, certification and operations of GFAS, there are a series of safety characteristics that define the approach to ensure mission success. This paper will explore and examine the safety characteristics of the GFAS development. The GFAS system integrates the flight software packages of the Orion and SLS with the ground systems and launch countdown sequencers through the 'agile' software development process. A unique approach is needed to develop the GFAS project capabilities within this agile process. NASA has defined the software development process through a set of standards. The standards were written during the infancy of the so-called industry 'agile development' movement and must be tailored to adapt to the highly integrated environment of human exploration systems. Safety of the space systems and the eventual crew on board is paramount during the preparation of the exploration flight systems. A series of software safety characteristics have been incorporated into the development and certification efforts to ensure readiness for use and compatibility with the space systems. Three underlining factors in the exploration architecture require the GFAS system to be unique in its approach to ensure safety for the space systems, both the flight as well as the ground systems. The first are the missions themselves, which are exploration in nature, and go far beyond the comfort of low Earth orbit operations. The second is the current exploration system will launch only one mission per year even less during its developmental phases. Finally, the third is the partnered approach through the use of many different prime contractors, including commercial and international partners, to design and build the exploration systems. These three factors make the challenges to meet the mission preparations and the safety expectations extremely difficult to implement. As NASA leads a team of partners in the exploration beyond earth's influence, it is a safety imperative that the application software used to test, checkout, prepare and launch the exploration systems put safety of the hardware and mission first. Software safety characteristics are built into the design and development process to enable the human rated systems to begin their missions safely and successfully. Exploration missions beyond Earth are inherently risky, however, with solid safety approaches in both hardware and software, the boldness of these missions can be realized for all on the home planet.

capability↗

Achievements and challenges of Space Station Freedom's safety review process

The most complex space vehicle in history, Space Station Freedom, is well underway to completion, and System Safety is a vital part of the program. The purpose is to summarize and illustrate the progress that over one-hundred System Safety engineers have made in identifying, documenting, and controlling the hazards inherent in the space station. To date, Space Station Freedom has been reviewed by NASA's safety panels through the first six assembly flights, when Freedom achieves a configuration known as Man Tended Capability. During the eight weeks of safety reviews spread out over a year and a half, over 200 preliminary hazard reports were presented. Along the way NASA and its contractors faced many challenges, made much progress, and even learned a few lessons.

Robinson, David W.↗