Search NASA⌕ Search

SEARCH · Search NASA

Results for “Critical Function Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Cascade Distillation System Design for Safety and Mission Assurance

Per the NASA Human Health, Life Support and Habitation System Technology Area 06 report "crewed missions venturing beyond Low-Earth Orbit (LEO) will require technologies with improved reliability, reduced mass, self-sufficiency, and minimal logistical needs as an emergency or quick-return option will not be feasible." To meet this need, the development team of the second generation Cascade Distillation System (CDS 2.0) opted a development approach that explicitely incorporate consideration of safety, mission assurance, and autonomy. The CDS 2.0 prelimnary design focused on establishing a functional baseline that meets the CDS core capabilities and performance. The critical design phase is now focused on incorporating features through a deliberative process of establishing the systems failure modes and effects, identifying mitigative strategies, and evaluating the merit of the proposed actions through analysis and test. This paper details results of this effort on the CDS 2.0 design.

Sargusingh, Miriam J.↗

Cascade Distillation System Design for Safety and Mission Assurance

Per the NASA Human Health, Life Support and Habitation System Technology Area 06 report "crewed missions venturing beyond Low-Earth Orbit (LEO) will require technologies with improved reliability, reduced mass, self-sufficiency, and minimal logistical needs as an emergency or quick-return option will not be feasible".1 To meet this need, the development team of the second generation Cascade Distillation System (CDS 2.0) chose a development approach that explicitly incorporate consideration of safety, mission assurance, and autonomy. The CDS 2.0 preliminary design focused on establishing a functional baseline that meets the CDS core capabilities and performance. The critical design phase is now focused on incorporating features through a deliberative process of establishing the systems failure modes and effects, identifying mitigation strategies, and evaluating the merit of the proposed actions through analysis and test. This paper details results of this effort on the CDS 2.0 design.

Sarguisingh, Miriam↗

Rapid Analysis, Self-Calibrating Array for Air Monitoring

Human space missions have critical needs for monitoring and control for life support systems. These systems have monitoring needs that include feedback for closed loop processes and quality control for environmental factors. Sensors and monitoring technologies assure that the air environment and water supply for the astronaut crew habitat fall within acceptable limits, and that the life support system is functioning properly and efficiently. The longer the flight duration and the more distant the destination, the more critical it becomes to have carefully monitored and automated control systems for life support. Past experiments with the JPL ENose have demonstrated a lifetime of the sensor array, with the software, of around 18 months. The lifetime of the calibration, for some analytes, was as long as 24 months. We are working on a sensor array and new algorithms that will include sensor response time in the analysis. The preliminary array analysis for two analytes shows that the analysis time, of an event, can be dropped from 45 minutes to less than10 minutes and array training time can be cut substantially. We will describe the lifetime testing of an array and show lifetime data on individual sensors. This progress will lead to more rapid identification of analytes, and faster training time of the array.

Self Calibrating↗

Assurance Issues in Developing AI/ML Components (and their Standards) for Civil Aviation

Standards development activities require a keen and deep understanding of the problem being solved by the standard as well as the technologies being deployed in any reference implementation of the solution. It is important to understand the mechanisms and limits of the fundamental, underlying science of implementation and verification technologies used to realize and assure systems. We need to understand the limits of what current process and metrics can provide with respect to new technologies. US leadership is important in this endeavor, and it is vital that we have a measured approach that yields sound results. We wish to start with simple, well-defined, non-safety critical applications and then progress to functions which have (1) clearly defined requirements, (2) means of checking the answer/output, and (3) means of intervention and mitigation of incorrect answers/outputs.

Aviation Safety↗

Formal Methods in the Development of Highly Assured Software for Unmanned Aircraft Systems

In traditional software development methodologies, operational and functional requirements of systems are often specified in structured natural language notations. These restricted notations provide good documentation support, but only provide limited support for semantic analysis. These notations are generally not rich enough to unambiguously specify the requirements of safety-critical systems that, for example, involve complex numerical computations or that interact with the physical environment. Examples of these safety-critical systems are autonomous vehicles such as unmanned aircraft systems. This talk advocates the use of expressive formal logics, such as higher-order logic, to specify the operational and functional requirement of unmanned systems and to prove the correctness of these requirements. Semantic analysis of requirements written in higher-order logic is supported through the use of interactive theorem provers. Formal models serve as ideal reference implementations of functional requirements. Hence, formal logics enable software validation techniques where software implementations can be checked against functional requirements in a mechanical way. The Formal Methods group in the Safety-Critical Avionics Systems Branch at NASA Langley Research Center has conducted research on the development and application of formal verification techniques to safety-critical applications of interest to NASA for more than 30 years. This talk illustrates the use of formal methods in the development of highly-assured autonomous unmanned aircraft systems.

Formal Methods↗

What Reliability Engineers Should Know about Space Radiation Effects

Space radiation in space systems present unique failure modes and considerations for reliability engineers. Radiation effects is not a one size fits all field. Threat conditions that must be addressed for a given mission depend on the mission orbital profile, the technologies of parts used in critical functions and on application considerations, such as supply voltages, temperature, duty cycle, and redundancy. In general, the threats that must be addressed are of two types-the cumulative degradation mechanisms of total ionizing dose (TID) and displacement damage (DD). and the prompt responses of components to ionizing particles (protons and heavy ions) falling under the heading of single-event effects. Generally degradation mechanisms behave like wear-out mechanisms on any active components in a system: Total Ionizing Dose (TID) and Displacement Damage: (1) TID affects all active devices over time. Devices can fail either because of parametric shifts that prevent the device from fulfilling its application or due to device failures where the device stops functioning altogether. Since this failure mode varies from part to part and lot to lot, lot qualification testing with sufficient statistics is vital. Displacement damage failures are caused by the displacement of semiconductor atoms from their lattice positions. As with TID, failures can be either parametric or catastrophic, although parametric degradation is more common for displacement damage. Lot testing is critical not just to assure proper device fi.mctionality throughout the mission. It can also suggest remediation strategies when a device fails. This paper will look at these effects on a variety of devices in a variety of applications. This paper will look at these effects on a variety of devices in a variety of applications. (2) On the NEAR mission a functional failure was traced to a PIN diode failure caused by TID induced high leakage currents. NEAR was able to recover from the failure by reversing the current of a nearby Thermal Electric Cooler (turning the TEC into a heater). The elevated temperature caused the PIN diode to anneal and the device to recover. It was by lot qualification testing that NEAR knew the diode would recover when annealed. This paper will look at these effects on a variety of devices in a variety of applications. Single Event Effects (SEE): (1) In contrast to TID and displacement damage, Single Event Effects (SEE) resemble random failures. SEE modes can range from changes in device logic (single-event upset, or SEU). temporary disturbances (single-event transient) to catastrophic effects such as the destructive SEE modes, single-event latchup (SEL). single-event gate rupture (SEGR) and single-event burnout (SEB) (2) The consequences of nondestructive SEE modes such as SEU and SET depend critically on their application--and may range from trivial nuisance errors to catastrophic loss of mission. It is critical not just to ensure that potentially susceptible devices are well characterized for their susceptibility, but also to work with design engineers to understand the implications of each error mode. -For destructive SEE, the predominant risk mitigation strategy is to avoid susceptible parts, or if that is not possible. to avoid conditions under which the part may be susceptible. Destructive SEE mechanisms are often not well understood, and testing is slow and expensive, making rate prediction very challenging. (3) Because the consequences of radiation failure and degradation modes depend so critically on the application as well as the component technology, it is essential that radiation, component. design and system engineers work togetherpreferably starting early in the program to ensure critical applications are addressed in time to optimize the probability of mission success.

DiBari, Rebecca↗

Leveraging ASTM Industry Standard F3269-17 for Providing Safe Operations of a Highly Autonomous Aircraft

This paper expands upon the ASTM industry standard F3269-17 to outline a run-time assurance (RTA) network architecture for use in ensuring safe flight operations of a highly autonomous aircraft. An RTA network architecture is proposed and critical features discussed to implement functions where automation is primarily responsible for the safety of the aircraft instead of a pilot. This shift in responsibility, made possible by the proposed architecture, is key to highly resilient automation and is a core enabler for future “pilotless” transportation concepts. The findings in this paper stem from the researcher’s experiences with ASTM in the generation of the standard and some seven years of RTA system development on various flight programs leveraging the RTA concepts outlined in the ASTM standard.

autonomous systems↗

Implementing Software Safety in the NASA Environment

Until recently, NASA did not consider allowing computers total control of flight systems. Human operators, via hardware, have constituted the ultimate safety control. In an attempt to reduce costs, NASA has come to rely more and more heavily on computers and software to control space missions. (For example. software is now planned to control most of the operational functions of the International Space Station.) Thus the need for systematic software safety programs has become crucial for mission success. Concurrent engineering principles dictate that safety should be designed into software up front, not tested into the software after the fact. 'Cost of Quality' studies have statistics and metrics to prove the value of building quality and safety into the development cycle. Unfortunately, most software engineers are not familiar with designing for safety, and most safety engineers are not software experts. Software written to specifications which have not been safety analyzed is a major source of computer related accidents. Safer software is achieved step by step throughout the system and software life cycle. It is a process that includes requirements definition, hazard analyses, formal software inspections, safety analyses, testing, and maintenance. The greatest emphasis is placed on clearly and completely defining system and software requirements, including safety and reliability requirements. Unfortunately, development and review of requirements are the weakest link in the process. While some of the more academic methods, e.g. mathematical models, may help bring about safer software, this paper proposes the use of currently approved software methodologies, and sound software and assurance practices to show how, to a large degree, safety can be designed into software from the start. NASA's approach today is to first conduct a preliminary system hazard analysis (PHA) during the concept and planning phase of a project. This determines the overall hazard potential of the system to be built. Shortly thereafter, as the system requirements are being defined, the second iteration of hazard analyses takes place, the systems hazard analysis (SHA). During the systems requirements phase, decisions are made as to what functions of the system will be the responsibility of software. This is the most critical time to affect the safety of the software. From this point, software safety analyses as well as software engineering practices are the main focus for assuring safe software. While many of the steps proposed in this paper seem like just sound engineering practices, they are the best technical and most cost effective means to assure safe software within a safe system.

Wetherholt, Martha S.↗

Toward Certification of Machine-Learning Systems for Low Criticality Airborne Applications

The exceptional progress in the field of machine learning (ML) in recent years has attracted a lot of interest in using this technology in aviation. Possible airborne applications of ML include safety-critical functions, which must be developed in compliance with rigorous certification standards of the aviation industry. Current certification standards for the aviation industry were developed prior to the ML renaissance without taking specifics of ML technology into account. There are some fundamental incompatibilities between traditional design assurance approaches and certain aspects of ML-based systems. In this paper, we analyze the current airborne certification standards and show that all objectives of the standards can be achieved for a low-criticality ML-based system if certain assumptions about ML development workflow are applied.

Avionics↗

Analysis of Traffic Conflicts in a Mixed-Airspace Evaluation of Airborne Separation Assurance

A pair of human-in-the-loop simulation evaluations of a distributed air/ground separation assurance system have been conducted to investigate the function allocation between humans and automation systems as well as ground-based and airborne agents in the Next Generation Air Transportation System and beyond. This paper focuses on an analysis of certain critical conflicts observed between self-separating aircraft and ground-managed traffic in the same airspace. The principal cause of each conflict is identified and potential mitigations are discussed, such as: the sharing of trajectory intent information between the ground and the air; more cautious trajectory planning by the self-separating aircraft; and more equitable rules-of-the-road between the self-separating aircraft and ground-managed aircraft. This analysis will inform the ongoing design of an airborne separation assurance automation tool.

Lewis, Timothy A.↗

Technical Excellence and Communication: The Cornerstones for Successful Safety and Mission Assurance Programs

The paper describes the role of technical excellence and communication in the development and maintenance of safety and mission assurance programs. The Marshall Space Flight Center (MSFC) Safety and Mission Assurance (S&MA) organization is used to illustrate philosophies and techniques that strengthen safety and mission assurance efforts and that contribute to healthy and effective organizational cultures. The events and conditions leading to the development of the MSFC S&MA organization are reviewed. Historic issues and concerns are identified. The adverse effects of resource limitations and risk assessment roles are discussed. The structure and functions of the core safety, reliability, and quality assurance functions are presented. The current organization s mission and vision commitments serve as the starting points for the description of the current organization. The goals and objectives are presented that address the criticisms of the predecessor organizations. Additional improvements are presented that address the development of technical excellence and the steps taken to improve communication within the Center, with program customers, and with other Agency S&MA organizations.

Malone, Roy W.↗

Unmanned Aircraft Systems (UAS) Integration in the National Airspace System (NAS) Project KDP-C Review

The topics discussed are the UAS-NAS project life-cycle and ARMD thrust flow down, as well as the UAS environments and how we operate in those environments. NASA's Armstrong Flight Research Center at Edwards, CA, is leading a project designed to help integrate unmanned air vehicles into the world around us. The Unmanned Aircraft Systems Integration in the National Airspace System project, or UAS in the NAS, will contribute capabilities designed to reduce technical barriers related to safety and operational challenges associated with enabling routine UAS access to the NAS. The project falls under the Integrated Systems Research Program office managed at NASA Headquarters by the agency's Aeronautics Research Mission Directorate. NASA's four aeronautics research centers - Armstrong, Ames Research Center, Langley Research Center, and Glenn Research Center - are part of the technology development project. With the use and diversity of unmanned aircraft growing rapidly, new uses for these vehicles are constantly being considered. Unmanned aircraft promise new ways of increasing efficiency, reducing costs, enhancing safety and saving lives 460265main_ED10-0132-16_full.jpg Unmanned aircraft systems such as NASA's Global Hawks (above) and Predator B named Ikhana (below), along with numerous other unmanned aircraft systems large and small, are the prime focus of the UAS in the NAS effort to integrate them into the national airspace. Credits: NASA Photos 710580main_ED07-0243-37_full.jpg The UAS in the NAS project envisions performance-based routine access to all segments of the national airspace for all unmanned aircraft system classes, once all safety-related and technical barriers are overcome. The project will provide critical data to such key stakeholders and customers as the Federal Aviation Administration and RTCA Special Committee 203 (formerly the Radio Technical Commission for Aeronautics) by conducting integrated, relevant system-level tests to adequately address safety and operational challenges of national airspace access by unmanned aircraft systems, or UAS. In the process, the project will work with other key stakeholders to define necessary deliverables and products to help enable such access. Within the project, NASA is focusing on five sub-projects. These five focus areas include assurance of safe separation of unmanned aircraft from manned aircraft when flying in the national airspace; safety-critical command and control systems and radio frequencies to enable safe operation of UAS; human factors issues for ground control stations; airworthiness certification standards for UAS avionics and integrated tests and evaluation designed to determine the viability of emerging UAS technology. Five Focus Areas of the UAS Integration in the NAS Project Separation Assurance Provide an assessment of how planned Next Generation Air Transportation System (NextGen) separation assurance systems, with different functional allocations, perform for UAS in mixed operations with manned aircraft Assess the applicability to UAS and the performance of NASA NextGen separation assurance systems in flight tests with realistic latencies and uncertain trajectories Assess functional allocations ranging from today's ground-based, controller-provided aircraft separation to fully autonomous airborne self-separation Communications Develop data and rationale to obtain appropriate frequency spectrum allocations to enable safe and efficient operation of UAS in the NAS Develop and validate candidate secure safety-critical command and control system/subsystem test equipment for UAS that complies with UAS international/national frequency regulations, standards and recommended practices and minimum operational and aviation system performance standards for UAS Perform analysis to support recommendations for integration of safety-critical command and control systems and air traffic control communications to ensure safe and efficient operation of UAS in the NAS Human Systems Integration Develop a research test bed and database to provide data and proof of concept for GCS - ground control station - operations in the NAS Coordinate with standards organizations to develop human-factors guidelines for GCS operation in the NAS Certification Define a UAS classification scheme and approach to determining Federal Aviation Regulation airworthiness requirements applicable to all UAS digital avionics Provide hazard and risk-related data to support development of type design criteria and best development practices Integrated Tests and Evaluation Integrate and test mature concepts from technical elements to demonstrate and test viability Evaluate the performance of technology development in a relevant environment (full-mission, human-in-the-loop simulations and flight tests)

outreach↗

Hubble Space Telescope: SRM/QA observations and lessons learned

The Hubble Space Telescope (HST) Optical Systems Board of Investigation was established on July 2, 1990 to review, analyze, and evaluate the facts and circumstances regarding the manufacture, development, and testing of the HST Optical Telescope Assembly (OTA). Specifically, the board was tasked to ascertain what caused the spherical aberration and how it escaped notice until on-orbit operation. The error that caused the on-orbit spherical aberration in the primary mirror was traced to the assembly process of the Reflective Null Corrector, one of the three Null Correctors developed as special test equipment (STE) to measure and test the primary mirror. Therefore, the safety, reliability, maintainability, and quality assurance (SRM&QA) investigation covers the events and the overall product assurance environment during the manufacturing phase of the primary mirror and Null Correctors (from 1978 through 1981). The SRM&QA issues that were identified during the HST investigation are summarized. The crucial product assurance requirements (including nonconformance processing) for the HST are examined. The history of Quality Assurance (QA) practices at Perkin-Elmer (P-E) for the period under investigation are reviewed. The importance of the information management function is discussed relative to data retention/control issues. Metrology and other critical technical issues also are discussed. The SRM&QA lessons learned from the investigation are presented along with specific recommendations. Appendix A provides the MSFC SRM&QA report. Appendix B provides supplemental reference materials. Appendix C presents the findings of the independent optical consultants, Optical Research Associates (ORA). Appendix D provides further details of the fault-tree analysis portion of the investigation process.

Rodney, George A.↗

Verification and Validation of Safety-Critical Aircraft Systems Operating under Off-Nominal, Contingency, and Emergency Conditions

Verification and validation (V&V) of safety-critical technologies developed for loss of control (LOC) prevention and recovery and other aviation safety concerns pose significant challenges. Aircraft LOC can result from a wide spectrum of hazards, often occurring in combination, which cannot be fully replicated during evaluation. Technologies developed for LOC prevention and recovery must therefore be effective under a wide variety of hazardous and uncertain conditions, and the verification and validation of these technologies must provide some measure of assurance that the new vehicle safety technologies do no harm (i.e., that they themselves do not introduce new safety risks). V&V technologies must also enable the identification of system limitations and constraints, as well as enable the identification of safe and unsafe operating conditions (and their boundaries). Additionally, the V&V of complex, increasingly autonomous systems is a fundamental concern. Scalable, reproducible and cost-effective techniques for the assurance of safety critical systems during their design and operation is a key barrier to fielding new systems or updating current systems. Moreover, these techniques need to provide artifacts that enable a comprehensive evidence-based approach to certification. This briefing summarizes research performed under NASA’s Aviation Safety Program and follow-on research for the V&V of safety-critical aircraft system technologies developed for LOC prevention and recovery and increasingly autonomous systems, and for a broad assurance capability in both current and emerging aviation applications. Note that, in this briefing, the term “validation” refers to a confirmation that the system implementation (e.g., algorithms etc.) is performing the intended function(s), as well as an affirmation of effectiveness in these functions. “Verification” refers to a confirmation that the system implementation in the software and hardware meets its (hopefully validated) specifications (e.g., correctly executes algorithms as designed).

Validation↗

Service offerings and interfaces for the ACTS network of earth stations

The NASA Advanced Communications Technology Satellite (ACTS) will use a network of about 20 earth stations to operate as a Mode 1 network. This network will support two ACTS program objectives: to verify the technical performance of ACTS Mode 1 operation in GEO and to demonstrate the types and quality of services that can be provided by an ACTS Mode 1 communications system. The terrestrial interface design is a critical element in assuring that these network earth stations will meet the objectives. In this paper, the applicable terrestrial interface design requirements, the resulting interface specifications, and the associated terrestrial input/output hardware are discussed. A functional block diagram of a network earth station is shown.

Coney, T. A.↗

Forecast of the general aviation air traffic control environment for the 1980's

The critical information required for the design of a reliable, low cost, advanced avionics system which would enhance the safety and utility of general aviation is stipulated. Sufficient data is accumulated upon which industry can base the design of a reasonably priced system having the capability required by general aviation in and beyond the 1980's. The key features of the Air Traffic Control (ATC) system are: a discrete address beacon system, a separation assurance system, area navigation, a microwave landing system, upgraded ATC automation, airport surface traffic control, a wake vortex avoidance system, flight service stations, and aeronautical satellites. The critical parameters that are necessary for component design are identified. The four primary functions of ATC (control, surveillance, navigation, and communication) and their impact on the onboard avionics system design are assessed.

Hoffman, W. C.↗

Strategic Employee Development in The Government Sector

As with many other U.S. agencies, succession planning is becoming a critical need for NASA. The primary drivers include (a) NASA's higher-than-average aged workforce with approximately 50% of employees eligible for retirement within 5 years; and (b) employees who need better developmental conversations to increase morale and retention. This problem is particularly concerning for Safety & Mission Assurance (S&MA) organizations since they traditionally rely on more experienced engineers and specialists to perform their organizations' functions. In response to this challenge, the Kennedy Space Center (KSC) S&MA organization created the Strategic Employee Development (SED) program. The SED program's goal is to provide a proactive method to counter the primary drivers by creating a deeper "bench strength" and providing a more comprehensive developmental feedback experience for the employee. The SED is a new succession planning framework that enables customization to any organization, and in this case, specifically for an S&MA organization. This is accomplished via the identification of key positions, the corresponding critical competencies, and a process to help managers have relevant and meaningful development conversations with the workforce. As a result of the SED, several tools and products were created that allows management to make better strategic workforce decisions. Although there are opportunities for improvement for the SED program, the most important impact has been on the quality of developmental discussions for employees.

Nguyen, Johnny↗

Validation of the F-18 high alpha research vehicle flight control and avionics systems modifications

The verification and validation process is a critical portion of the development of a flight system. Verification, the steps taken to assure the system meets the design specification, has become a reasonably understood and straightforward process. Validation is the method used to ensure that the system design meets the needs of the project. As systems become more integrated and more critical in their functions, the validation process becomes more complex and important. The tests, tools, and techniques which are being used for the validation of the high alpha research vehicle (HARV) turning vane control system (TVCS) are discussed and the problems and their solutions are documented. The emphasis of this paper is on the validation of integrated system.

Chacon, Vince↗