Search NASA⌕ Search

SEARCH · Search NASA

Results for “sequence diagram”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Simulated Evaluation of Strategic Conflict Management Capabilities for Urban Air Mobility Operations

Urban Air Mobility (UAM) is a new air transportation service concept to carry passengers or cargo in metropolitan areas, leveraged by innovative aircraft and automation technologies. NASA has conducted a series of simulations to evaluate the UAM concept of operations and inform the development of airspace procedures and services for UAM operations. The latest set of simulations called “X5” were conducted to test a Provider of Services for UAM (PSU) prototype that NASA developed for UAM flight planning, strategic conflict management support, and data exchange between UAM operators. In these simulations, two strategic conflict management capabilities, Demand-Capacity Balancing (DCB) and Sequencing and Scheduling (S&S), were further investigated. This paper describes the system architecture designed for the X5 simulation activities, the sequence diagram for strategic conflict management, and the simulation environment in the Dallas/Fort Worth urban area. The simulation results based on several system performance metrics for evaluation show that a sequential application of DCB and S&S effectively works to distribute traffic demand and meet sequencing and spacing criteria by assigning ground delays, compared to the DCB only and S&S only cases.

Urban Air Mobility, Strategic Conflict Management,↗

Simulated Evaluation of Strategic Conflict Management Capabilities for Urban Air Mobility Operations

Urban Air Mobility (UAM) is a new air transportation service concept to carry passengers or cargo in metropolitan areas, leveraged by innovative aircraft and automation technologies. NASA has conducted a series of simulations to evaluate the UAM concept of operations and inform the development of airspace procedures and services for UAM operations. The latest set of simulations called “X5” were conducted to test a Provider of Services for UAM (PSU) prototype that NASA developed for UAM flight planning, strategic conflict management support, and data exchange between UAM operators. In these simulations, two strategic conflict management capabilities, Demand-Capacity Balancing (DCB) and Sequencing and Scheduling (S&S), were further investigated. This paper describes the system architecture designed for the X5 simulation activities, the sequence diagram for strategic conflict management, and the simulation environment in the Dallas/Fort Worth urban area. The simulation results based on several system performance metrics for evaluation show that a sequential application of DCB and S&S effectively works to distribute traffic demand and meet sequencing and spacing criteria by assigning ground delays, compared to the DCB only and S&S only cases.

Simulation↗

X-57 Cockpit Interface Control Document (ICD-CEPT-006)

The Cockpit Interface Control Document defines the hardware interfaces between the X-57 cockpit and subsystems. It provides locational and operational information in support of ground and flight operations with details on controls and displays that include Modes of Operation, Start-Up and Shut- Down Sequence diagrams and captures the current state of the MOD II Avionics Power Architecture. There is also preliminary information of the MOD III and MOD IV configurations. Microsoft PowerPoint was chosen for the document as early development required frequent meetings with multiple customers including aircraft operators (pilots), ground operations, support contractors and power, instrumentation, and human systems integration engineers and PowerPoint enabled presentations that could be quickly modified based on customer and developer interaction. One of the driving requirements for the cockpit design was to keep the left side panel as close the stock Tecnam panel as possible to reduce the failure risk of flight critical indicators. The original annunciator panel in the left side panel was modified to alert the pilot to failures in critical X-57 subsystems and an operator audio alert capability was added for these subsystems. Power-Up switches for the aircraft low voltage 13.8 VDC systems are located at the bottom of the left side panel and center panel, the same location as the stock Tecnam 13.8 VDC switches. The switches for energizing the high voltage system were located in the overhead panel to reduce the risk of inadvertently energizing the high voltage system during the low voltage power-up sequence. The Cruise Motor ARM switches were also located in the overhead panel and correspond to the same location as the stock Tecnam ignition switches. The stock Tecnam throttle levers and prop pitch levers were retained for the X-57. The throttle levers were renamed torque levers since they controlled the commanded torque to the cruise motors. The prop pitch levers provide a commanded RPM signal to an electronic prop pitch controller. X-57 specific displays, located in the right-side panel, are driven by dedicated sensors that monitor right and left side cruise motor RPM, right and left high voltage “Traction Bus” A and B (voltage, current and power) and the Avionics Bus DC converters (A and B) voltage and current. An X-57 Multi-Function Display (MFD) located in the center panel displays CAN Bus parameters. CAN Bus architecture is not certified for flight so these displays could not be used for safety critical information but were designed to be used for test point information only.

Laura Kushner↗

Quantitative Risk Assessment for Fuel Cell Electric Bus Hydrogen Storage and Refueling Facility

It is necessary to understand the safety implications and risk mitigation options for fuel cell electric bus fleet deployment, especially for related facilities responsible for operations such as production, storage, compression, and dispensing of hydrogen for use by the buses. In this report, we present a quantitative risk assessment for a potential fuel cell electric bus fleet that was motivated by efforts to improve resilience at the Portland International Airport but can be applicable to a range of hydrogen case studies and use cases. We estimated risk for a facility that produces, stores, compresses, and dispenses hydrogen for the fleet of buses, with a focus on individual risk to people in terms of annual frequency of fatality. We considered the frequency of hydrogen leaks that could result in harmful physical outcomes like jet fires or explosions, and the consequences of those outcomes for people. We created customized fault trees to calculate the frequencies of different sizes of leaks and event sequence diagrams to calculate ignition probabilities for the various leak sizes. We also leveraged the HyRAM+ toolkit to use these inputs to calculate overall risk for the facility, which we separated into one section responsible for producing, storing, and compressing hydrogen, and one section responsible for dispensing the hydrogen to the buses. We found that the dispensing area seemed to have a higher risk than the production/storage/compression area of the facility, largely because of the inclusion of a component with a high leak frequency (the heat exchanger used to cool the hydrogen before entering the vehicle, to prevent overheating and expansion of hydrogen in the onboard tank). For the example production and refueling facility we evaluated and the data we used for the analysis, the leak frequency had a larger impact on the risk differences between the two sections on the facility, compared to the physical outcome consequence, which was slightly different due to the varying fuel conditions, but not substantially different. Actions can be taken to prevent these hazards (e.g., lowering leak frequencies in system components) or to mitigate the consequences if they do occur (e.g., installing barriers to protect people if ignition events occur). The choice of which actions to take depends not only on safety considerations but also on space, time, staffing, feasibility, and financial constraints. Therefore, the quantitative risk assessment approach can help understand relative risk contributions from different components, leak sizes, consequences, and human actions, to prioritize risk reduction strategies and balance these parameters. The outcomes of this report may be useful for a variety of stakeholders working in the hydrogen, transportation, vehicle, and aviation sector, including those responsible for aspects like facility design, operations, and regulations. There is not a single value of risk that determines whether a hypothetical system is “safe” or not. The insights about risk mitigations may be leveraged, and the quantitative risk assessment approach can be applied to other case studies to understand risk priorities and contributions specific to different FCEB and hydrogen facility uses.

08 HYDROGEN↗

Considerations for the retrofit of data link

Human factors issues related to the retrofit of data link in commercial transport aircraft are discussed. Topics that must be considered for data link implementation include, the loss of the party line, (i.e., the availability to all aircraft of information transmitted on a common voice frequency), and the scheduling of information to the flight crew. This paper focuses primarily on the human factors issues related to retrofit of Mode S. Retrofits is a difficult task because panel space accessible to flight crew members is limited. As with all cockpit equipment, data link implementation will have to comply with Federal Aviation Regulation 25.1523, which requires the manufacturer to address the conspicuity and ease of use of the data link device, and to assess the impact on crew workload. Operational sequence diagrams are provided to illustrate a methodology that can be used to decompose the flight crew body channel utilization of candidate avionics configurations in order to optimize the pilot-vehicle interface.

Corwin, William H.↗

Space Shuttle Main Engine Quantitative Risk Assessment: Illustrating Modeling of a Complex System with a New QRA Software Package

During 1997, a team from Hernandez Engineering, MSFC, Rocketdyne, Thiokol, Pratt & Whitney, and USBI completed the first phase of a two year Quantitative Risk Assessment (QRA) of the Space Shuttle. The models for the Shuttle systems were entered and analyzed by a new QRA software package. This system, termed the Quantitative Risk Assessment System(QRAS), was designed by NASA and programmed by the University of Maryland. The software is a groundbreaking PC-based risk assessment package that allows the user to model complex systems in a hierarchical fashion. Features of the software include the ability to easily select quantifications of failure modes, draw Event Sequence Diagrams(ESDs) interactively, perform uncertainty and sensitivity analysis, and document the modeling. This paper illustrates both the approach used in modeling and the particular features of the software package. The software is general and can be used in a QRA of any complex engineered system. The author is the project lead for the modeling of the Space Shuttle Main Engines (SSMEs), and this paper focuses on the modeling completed for the SSMEs during 1997. In particular, the groundrules for the study, the databases used, the way in which ESDs were used to model catastrophic failure of the SSMES, the methods used to quantify the failure rates, and how QRAS was used in the modeling effort are discussed. Groundrules were necessary to limit the scope of such a complex study, especially with regard to a liquid rocket engine such as the SSME, which can be shut down after ignition either on the pad or in flight. The SSME was divided into its constituent components and subsystems. These were ranked on the basis of the possibility of being upgraded and risk of catastrophic failure. Once this was done the Shuttle program Hazard Analysis and Failure Modes and Effects Analysis (FMEA) were used to create a list of potential failure modes to be modeled. The groundrules and other criteria were used to screen out the many failure modes that did not contribute significantly to the catastrophic risk. The Hazard Analysis and FMEA for the SSME were also used to build ESDs that show the chain of events leading from the failure mode occurence to one of the following end states: catastrophic failure, engine shutdown, or siccessful operation( successful with respect to the failure mode under consideration).

Smart, Christian↗

Derivation of Failure Rates and Probability of Failures for the International Space Station Probabilistic Risk Assessment Study

National Aeronautics and Space Administration s (NASA) International Space Station (ISS) Program uses Probabilistic Risk Assessment (PRA) as part of its Continuous Risk Management Process. It is used as a decision and management support tool to not only quantify risk for specific conditions, but more importantly comparing different operational and management options to determine the lowest risk option and provide rationale for management decisions. This paper presents the derivation of the probability distributions used to quantify the failure rates and the probability of failures of the basic events employed in the PRA model of the ISS. The paper will show how a Bayesian approach was used with different sources of data including the actual ISS on orbit failures to enhance the confidence in results of the PRA. As time progresses and more meaningful data is gathered from on orbit failures, an increasingly accurate failure rate probability distribution for the basic events of the ISS PRA model can be obtained. The ISS PRA has been developed by mapping the ISS critical systems such as propulsion, thermal control, or power generation into event sequences diagrams and fault trees. The lowest level of indenture of the fault trees was the orbital replacement units (ORU). The ORU level was chosen consistently with the level of statistically meaningful data that could be obtained from the aerospace industry and from the experts in the field. For example, data was gathered for the solenoid valves present in the propulsion system of the ISS. However valves themselves are composed of parts and the individual failure of these parts was not accounted for in the PRA model. In other words the failure of a spring within a valve was considered a failure of the valve itself.

Vitali, Roberto↗

Quantitative risk assessment system (QRAS)

A quantitative risk assessment system (QRAS) builds a risk model of a system for which risk of failure is being assessed, then analyzes the risk of the system corresponding to the risk model. The QRAS performs sensitivity analysis of the risk model by altering fundamental components and quantifications built into the risk model, then re-analyzes the risk of the system using the modifications. More particularly, the risk model is built by building a hierarchy, creating a mission timeline, quantifying failure modes, and building/editing event sequence diagrams. Multiplicities, dependencies, and redundancies of the system are included in the risk model. For analysis runs, a fixed baseline is first constructed and stored. This baseline contains the lowest level scenarios, preserved in event tree structure. The analysis runs, at any level of the hierarchy and below, access this baseline for risk quantitative computation as well as ranking of particular risks. A standalone Tool Box capability exists, allowing the user to store application programs within QRAS.

Weinstock, Robert M↗

Analyzing and Detecting Problems in Systems of Systems

Many software systems are evolving complex system of systems (SoS) for which inter-system communication is mission-critical. Evidence indicates that transmission failures and performance issues are not uncommon occurrences. In a NASA-supported Software Assurance Research Program (SARP) project, we are researching a new approach addressing such problems. In this paper, we are presenting an approach for analyzing inter-system communications with the goal to uncover both transmission errors and performance problems. Our approach consists of a visualization and an evaluation component. While the visualization of the observed communication aims to facilitate understanding, the evaluation component automatically checks the conformance of an observed communication (actual) to a desired one (planned). The actual and the planned are represented as sequence diagrams. The evaluation algorithm checks the conformance of the actual to the planned diagram. We have applied our approach to the communication of aerospace systems and were successful in detecting and resolving even subtle and long existing transmission problems.

Lindvall, Mikael↗

Towards Behavioral Reflexion Models

Software architecture has become essential in the struggle to manage today s increasingly large and complex systems. Software architecture views are created to capture important system characteristics on an abstract and, thus, comprehensible level. As the system is implemented and later maintained, it often deviates from the original design specification. Such deviations can have implication for the quality of the system, such as reliability, security, and maintainability. Software architecture compliance checking approaches, such as the reflexion model technique, have been proposed to address this issue by comparing the implementation to a model of the systems architecture design. However, architecture compliance checking approaches focus solely on structural characteristics and ignore behavioral conformance. This is especially an issue in Systems-of- Systems. Systems-of-Systems (SoS) are decompositions of large systems, into smaller systems for the sake of flexibility. Deviations of the implementation to its behavioral design often reduce the reliability of the entire SoS. An approach is needed that supports the reasoning about behavioral conformance on architecture level. In order to address this issue, we have developed an approach for comparing the implementation of a SoS to an architecture model of its behavioral design. The approach follows the idea of reflexion models and adopts it to support the compliance checking of behaviors. In this paper, we focus on sequencing properties as they play an important role in many SoS. Sequencing deviations potentially have a severe impact on the SoS correctness and qualities. The desired behavioral specification is defined in UML sequence diagram notation and behaviors are extracted from the SoS implementation. The behaviors are then mapped to the model of the desired behavior and the two are compared. Finally, a reflexion model is constructed that shows the deviations between behavioral design and implementation. This paper discusses the approach and shows how it can be applied to investigate reliability issues in SoS.

Ackermann, Christopher↗

Modeling Payload Stowage Impacts on Fire Risks On-Board the International Space Station

The purpose of this presentation is to determine the risks of fire on-board the ISS due to non-standard stowage. ISS stowage is constantly being reexamined for optimality. Non-standard stowage involves stowing items outside of rack drawers, and fire risk is a key concern and is heavily mitigated. A Methodology is needed to account for fire risk due to non-standard stowage to capture the risk. The contents include: 1) Fire Risk Background; 2) General Assumptions; 3) Modeling Techniques; 4) Event Sequence Diagram (ESD); 5) Qualitative Fire Analysis; 6) Sample Qualitative Results for Fire Risk; 7) Qualitative Stowage Analysis; 8) Sample Qualitative Results for Non-Standard Stowage; and 9) Quantitative Analysis Basic Event Data.

Anton, Kellie e.↗

Independent Verification and Validation (IV and V) - Adding Mission Assurance to NASA Flight Software

The NASA Independent Verification and Validation (IV&V) Facility objective is to identify potential defects in flight software using independent analysis techniques. This paper describes the tailored IV&V techniques that have been developed in support of critical interactions on the Mars Science Laboratory (MSL) project, scheduled to launch in November, 2011. The IV&V techniques for interface analysis use independently developed sequence diagrams of critical scenarios. The results from these analyses have had a positive impact on the requirements flow down, consistency amongst MSL requirements and identification of missing requirements. The results of these analyses and the positive impact to the MSL project are provided.

performance evaluation↗

Reliability and Probabilistic Risk Assessment - How They Play Together

Since the Space Shuttle Challenger accident in 1986, NASA has extensively used probabilistic analysis methods to assess, understand, and communicate the risk of space launch vehicles. Probabilistic Risk Assessment (PRA), used in the nuclear industry, is one of the probabilistic analysis methods NASA utilizes to assess Loss of Mission (LOM) and Loss of Crew (LOC) risk for launch vehicles. PRA is a system scenario based risk assessment that uses a combination of fault trees, event trees, event sequence diagrams, and probability distributions to analyze the risk of a system, a process, or an activity. It is a process designed to answer three basic questions: 1) what can go wrong that would lead to loss or degraded performance (i.e., scenarios involving undesired consequences of interest), 2) how likely is it (probabilities), and 3) what is the severity of the degradation (consequences). Since the Challenger accident, PRA has been used in supporting decisions regarding safety upgrades for launch vehicles. Another area that was given a lot of emphasis at NASA after the Challenger accident is reliability engineering. Reliability engineering has been a critical design function at NASA since the early Apollo days. However, after the Challenger accident, quantitative reliability analysis and reliability predictions were given more scrutiny because of their importance in understanding failure mechanism and quantifying the probability of failure, which are key elements in resolving technical issues, performing design trades, and implementing design improvements. Although PRA and reliability are both probabilistic in nature and, in some cases, use the same tools, they are two different activities. Specifically, reliability engineering is a broad design discipline that deals with loss of function and helps understand failure mechanism and improve component and system design. PRA is a system scenario based risk assessment process intended to assess the risk scenarios that could lead to a major/top undesirable system event, and to identify those scenarios that are high-risk drivers. PRA output is critical to support risk informed decisions concerning system design. This paper describes the PRA process and the reliability engineering discipline in detail. It discusses their differences and similarities and how they work together as complementary analyses to support the design and risk assessment processes. Lessons learned, applications, and case studies in both areas are also discussed in the paper to demonstrate and explain these differences and similarities.

Safie, Fayssal↗

Reliability and Probabilistic Risk Assessment - How They Play Together

PRA methodology is one of the probabilistic analysis methods that NASA brought from the nuclear industry to assess the risk of LOM, LOV and LOC for launch vehicles. PRA is a system scenario based risk assessment that uses a combination of fault trees, event trees, event sequence diagrams, and probability and statistical data to analyze the risk of a system, a process, or an activity. It is a process designed to answer three basic questions: What can go wrong? How likely is it? What is the severity of the degradation? Since 1986, NASA, along with industry partners, has conducted a number of PRA studies to predict the overall launch vehicles risks. Planning Research Corporation conducted the first of these studies in 1988. In 1995, Science Applications International Corporation (SAIC) conducted a comprehensive PRA study. In July 1996, NASA conducted a two-year study (October 1996 - September 1998) to develop a model that provided the overall Space Shuttle risk and estimates of risk changes due to proposed Space Shuttle upgrades. After the Columbia accident, NASA conducted a PRA on the Shuttle External Tank (ET) foam. This study was the most focused and extensive risk assessment that NASA has conducted in recent years. It used a dynamic, physics-based, integrated system analysis approach to understand the integrated system risk due to ET foam loss in flight. Most recently, a PRA for Ares I launch vehicle has been performed in support of the Constellation program. Reliability, on the other hand, addresses the loss of functions. In a broader sense, reliability engineering is a discipline that involves the application of engineering principles to the design and processing of products, both hardware and software, for meeting product reliability requirements or goals. It is a very broad design-support discipline. It has important interfaces with many other engineering disciplines. Reliability as a figure of merit (i.e. the metric) is the probability that an item will perform its intended function(s) for a specified mission profile. In general, the reliability metric can be calculated through the analyses using reliability demonstration and reliability prediction methodologies. Reliability analysis is very critical for understanding component failure mechanisms and in identifying reliability critical design and process drivers. The following sections discuss the PRA process and reliability engineering in detail and provide an application where reliability analysis and PRA were jointly used in a complementary manner to support a Space Shuttle flight risk assessment.

Safie, Fayssal M.↗

ISS Double-Gimbaled CMG Subsystem Simulation Using the Agile Development Method

This paper presents an evolutionary approach in simulating a cluster of 4 Control Moment Gyros (CMG) on the International Space Station (ISS) using a common sense approach (the agile development method) for concurrent mathematical modeling and simulation of the CMG subsystem. This simulation is part of Training systems for the 21st Century simulator which will provide training for crew members, instructors, and flight controllers. The basic idea of how the CMGs on the space station are used for its non-propulsive attitude control is briefly explained to set up the context for simulating a CMG subsystem. Next different reference frames and the detailed equations of motion (EOM) for multiple double-gimbal variable-speed control moment gyroscopes (DGVs) are presented. Fixing some of the terms in the EOM becomes the special case EOM for ISS's double-gimbaled fixed speed CMGs. CMG simulation development using the agile development method is presented in which customer's requirements and solutions evolve through iterative analysis, design, coding, unit testing and acceptance testing. At the end of the iteration a set of features implemented in that iteration are demonstrated to the flight controllers thus creating a short feedback loop and helping in creating adaptive development cycles. The unified modeling language (UML) tool is used in illustrating the user stories, class designs and sequence diagrams. This incremental development approach of mathematical modeling and simulating the CMG subsystem involved the development team and the customer early on, thus improving the quality of the working CMG system in each iteration and helping the team to accurately predict the cost, schedule and delivery of the software.

Inampudi, Ravi↗

An Analysis of the Role of Safety Nets in the National Airspace System

Safe operations of aircraft in the National Airspace System (NAS) may be attributed to many factors, including the application of a variety of safety nets (SNs) as a last line of defense. In preparation for the Next Generation Air Transportation System (NextGen), a review of Aviation Safety Reporting System (ASRS) reports for incidents with positive outcomes was conducted to investigate the importance of current safety nets. The examination of positive outcomes not only shows what went wrong, but also what went right to prevent accidents and “save the day.” More than 400 incident reports for 2015 from the voluntary ASRS reporting database were studied in detail to create event sequence diagrams (ESDs), illustrating the effectiveness of SNs. The developed ESDs are considered top-level, representative models and are limited with respect to being reliably quantitative because they are based on only reports from a single year. The ESDs could offer insights into human systems integration research, such as strategically using technologies as SNs without human interface or alleviating human workload with new technologies to provide resilient recovery from off-nominal conditions ensuring flight safety.

Geuther, Steven↗

IRAS colors of carbon stars - An optical spectroscopic test

Optical spectra are obtained of 57 photographic counterparts to IRAS sources not previously studied spectroscopically, and expected on the basis of their IRAS colors to be M or C type stars. Confirmed carbon stars are found only in a restricted range of 12-25 index, and constitute a striking 'vertical' sequence in the 12-25-60 micron color-color diagram. This sequence is in accord with evolutionary models for AGB stars that convert M into C stars by dredge-up, and follow loops in the color-color plane. Optically visible and optically invisible carbon stars occupy different color-color locations consistent with their representations of different evolutionary states in the life of relatively low-mass stars.

Cohen, Martin↗

Orbital resonances, unusual configurations and exotic rotation states among planetary satellites

The origin of orbital resonances is shown in the demonstration of the evolution of a pair of planetary satellites through a commensurability of the mean motions by a sequence of diagrams of constant energy curves in a two-dimensional phase space; the closed curve corresponding to the motion in each successive diagram is identified by its adiabatically conserved area. It is found that two-body resonances serve as a basis in the solution of the problem of the origin and evolution of the three-body Laplace resonance among the Galilean satellites of Jupiter. The unusual rotation state of Saturn's satellite Hyperion which is expected to tumble chaotically for an indefinite amount of time is discussed.

Peale, S. J.↗