Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 415 records · Page 23

MOD-OA 200 kW wind turbine generator engineeringing

Engineering drawings and the detailed mechanical and electrical design of a horizontal-axis wind turbine designed for DOE at the NASA Lewis Research Center and installed in Clayton, New Mexico are discussed. The drawings show the hub, pitch change mechanism, drive train, nacelle equipment, yaw drive system, tower, foundation, electrical power systems, and the control and safety systems.

Andersen, T. S.↗

Electrical safety requirements: Implications for the module designer

Commercial photovoltaic array installations, which include residential and intermediate applications, are subject to building and electrical codes and to product safety standards. The National Electrical Code (NEC) Article 690, titled Solar Photovoltaic Systems, contains provisions defining acceptable levels of system safety and emphasizes the system design and its installation. The Underwriters Laboratories, Inc. (UL), document titled: Proposed First Edition of the Standard for Flat Plate Photovoltaic Modules and Panels, UL-1703, identifies module and panel construction requirements that ensure product safety. Together these documents describe requirements intended to minimize hazards such as shock and fire. Although initial focus of these requirements is on single crystal silicon modules, they are generic in nature, and are equally applicable to high voltage ( 30 Vdc), multikilowatt, thin film systems. A major safety concern is insulation breakdown within the module or array wiring system, or discontinuities within the electrical conductors. These failures can result in ground faults, in circuit arcs, or exposure to hazardous electrical parts. Safeguards are discussed.

Sugimura, R. S.↗

Quantifying Pilot Contribution to Flight Safety During an In-Flight Airspeed Failure

Accident statistics cite the flight crew as a causal factor in over 60% of large transport fatal accidents. Yet a well-trained and well-qualified crew is acknowledged as the critical center point of aircraft systems safety and an integral component of the entire commercial aviation system. A human-in-the-loop test was conducted using a Level D certified Boeing 737-800 simulator to evaluate the pilot's contribution to safety-of-flight during routine air carrier flight operations and in response to system failures. To quantify the human's contribution, crew complement was used as an independent variable in a between-subjects design. This paper details the crew's actions and responses while dealing with an in-flight airspeed failure. Accident statistics often cite flight crew error (Baker, 2001) as the primary contributor in accidents and incidents in transport category aircraft. However, the Air Line Pilots Association (2011) suggests "a well-trained and well-qualified pilot is acknowledged as the critical center point of the aircraft systems safety and an integral safety component of the entire commercial aviation system." This is generally acknowledged but cannot be verified because little or no quantitative data exists on how or how many accidents/incidents are averted by crew actions. Anecdotal evidence suggest crews handle failures on a daily basis and Aviation Safety Action Program data generally supports this assertion, even if the data is not released to the public. However without hard evidence, the contribution and means by which pilots achieve safety of flight is difficult to define. Thus, ways to improve the human ability to contribute or overcome deficiencies are ill-defined.

Etherington, Timothy J.↗

Assumption Generation for the Verification of Learning-Enabled Autonomous Systems

Providing safety guarantees for autonomous systems is difficultas these systems operate in complex environments that require the use of learning-enabled components, such as deep neural networks (DNNs) for visual perception. DNNs are hard to analyze due to their size (they can have thousands or millions of parameters), lack of formal specifications (DNNs are typically learnt from labeled data, in the absence of any formal or informal requirements), and sensitivity to small changes in the environment. We present an assume-guarantee style compositional approach for the formal verification of system-level safety properties of such autonomous systems. Our insight is that we can analyze the system in the absence of the DNN perception components by automatically synthesizing assumptions on the DNN behaviour that guarantee the satisfaction of the required safety properties. The synthesized assumptions are the weakest in the sense that they characterize the output sequences of all the possible DNNs that, plugged into the autonomous system, guarantee the required safety properties. The assumptions can be leveraged as run-time monitors over a deployed DNN to guarantee the safety of the overall system; they can also be mined to extract local specifications for use during training and testing of DNNs. We illustrate our approach on a case study taken from the autonomous airplanes domain that uses a complex DNN for perception

Autonomous systems↗

An Assessment of Reduced Crew and Single Pilot Operations in Commercial Transport Aircraft Operations

Future reduced crew operations or even single pilot operations for commercial airline and on-demand mobility applications are an active area of research. These changes would reduce the human element and thus, threaten the precept that "a well-trained and well-qualified pilot is the critical center point of aircraft systems safety and an integral safety component of the entire commercial aviation system." NASA recently completed a pilot-in-the-loop high fidelity motion simulation study in partnership with the Federal Aviation Administration (FAA) attempting to quantify the pilot's contribution to flight safety during normal flight and in response to aircraft system failures. Crew complement was used as the experiment independent variable in a between-subjects design. These data show significant increases in workload for single pilot operations, compared to two-crew, with subjective assessments of safety and performance being significantly degraded as well. Nonetheless, in all cases, the pilots were able to overcome the failure mode effects in all crew configurations. These data reflect current-day flight deck equipage and help identify the technologies that may improve two-crew operations and/or possibly enable future reduced crew and/or single pilot operations.

Bailey, Randall E.↗

Survey of Advanced Booster Options for Potential Shuttle Derivative Vehicles

A never-ending major goal for the Space Shuttle program is to continually improve flight safety, as long as this launch system remains in operational service. One of the options to improve system safety and to enhance vehicle performance as well, that has been seriously studied over the past several decades, is to replace the existing strap-on four segment solid rocket boosters (SRB's) with more capable units. A number of booster upgrade options have been studied in some detail, ranging from five segment solids through hybrids and a wide variety of liquid strap-ons (both pressure and pump fed with various propellants); all the way to a completely reusable liquid fly back booster (complete with air breathing engines for controlled landing and return). All of these possibilities appear to offer improvements in varying degrees; and each has their strengths and weaknesses from both programmatic and technical points of view. The most beneficial booster upgrade/design, if the shuttle program were to continue long enough to justify the required investment, would be an approach that greatly increased both vehicle and crew safety. This would be accomplished by increasing the minimum range/minimum altitude envelope that would readily allow abort to orbit (ATO), possibly even to zero/zero, and possibly reduce or eliminate the Return to Launch Site (RTLS) and even the Trans Atlantic Landing (TAL) abort mode requirements. This paper will briefly survey and discuss all of the various booster'upgrade options studied previously, and compare their relative attributes. The survey will explicitly discuss, in summary comparative form, options that include: five segment solids; several hybrid possibilities; pressure and/or pump-fed liquids using either LO2/kerosene, H2O/kerosene and LO2/J2, any of which could be either fully expendable, partly or fully reusable; and finally a fully reusable liquid fly back booster system, with a number of propellant and propulsion system options. Performance and configuration comparison illustrations and tables will be included to provide a comprehensive survey for the paper.

Sackheim, Robert L.↗

A realistic TRACE PWR LOCA model with application to high-burnup analysis

This paper presents a TRACE model of a postulated large-break loss-of-coolant accident (LBLOCA) event in a four-loop pressurized water reactor (PWR). The input files have been made publicly available and serve as a starting point for researchers to improve upon or apply to their purposes. The model, based on a legacy PWR model, contains numerous improvements and modifications consistent with US Nuclear Regulatory Commission LBLOCA analysis guidelines. The model is applied to analyze high-burnup (>62 GWD/MTU) fuel behavior during LBLOCA, improving on previous work to provide realistic thermal hydraulic predictions for future fuel performance analyses and experiments related to fission fragment, relocation, and dispersal (FFRD). Sensitivity studies are presented to quantify the impact of the vessel-modeling approach, core radial discretization, and other phenomena. In conclusion, the model is intended for research purposes and contains sufficient plant geometric, operational, and safety system details to represent the main physical phenomena pertaining to LBLOCA.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Design, characterization, and control of the NASA three degree of freedom reaction compensation platform

Increasing research is being done into industrial uses for the microgravity environment aboard orbiting space vehicles. However, there is some concern over the effects of reaction forces produced by moving objects, especially motors, robotic actuators, and astronauts. Reaction forces produced by the movement of these objects may manifest themselves as undesirable accelerations in the space vehicle making the vehicle unusable for microgravity applications. It is desirable to provide compensation for such forces using active means. This paper presents the design and experimental evaluation of the NASA three degree of freedom reaction compensation platform, a system designed to be a testbed for the feasibility of active attenuation of reaction forces caused by moving objects in a microgravity environment. Unique 'linear motors,' which convert electrical current directly into rectilinear force, are used in the platform design. The linear motors induce accelerations of the displacer inertias. These accelerations create reaction forces that may be controlled to counteract disturbance forces introduced to the platform. The stated project goal is to reduce reaction forces by 90 percent, or -20 dB. Description of the system hardware, characterization of the actuators and the composite system, and design of the software safety system and control software are included.

Birkhimer, Craig↗

Autonomous Coordinated Airspace Services for Terminal and Enroute Operations with Wind Errors

As novel uses of the airspace continue to multiply, there is increasing demand for access to high-density terminal areas around major airports. Since the predicted demand for urban-air-mobility and urban-package-delivery is very high, and the interactions between these different types of aircraft and missions will be extremely complex, increasingly autonomous systems will be required to manage safety and efficiency. This paper presents the current status of an autonomous safety system designed to ensure safe and efficient trajectories for aircraft in terminal airspace, the Terminal Advanced Airspace Concept. Previous papers have demonstrated the efficacy of this algorithm for handling commercial arrivals into a complex metroplex when there is no uncertainty present. This study extends that work to demonstrate the performance of the algorithm under high levels of uncertainty.

terminal operations↗

Autonomous Coordinated Airspace Services for Terminal and Enroute Operations with Wind Errors

As novel uses of the airspace continue to multiply, there is increasing demand for access to high-density terminal areas around major airports. Since the predicted demand for urban-air-mobility and urban-package-delivery is very high, and the interactions between these different types of aircraft and missions will be extremely complex, increasingly autonomous systems will be required to manage safety and efficiency. This paper presents the current status of an autonomous safety system designed to ensure safe and efficient trajectories for aircraft in terminal airspace, the Terminal Advanced Airspace Concept. Previous papers have demonstrated the efficacy of this algorithm for handling commercial arrivals into a complex metroplex when there is no uncertainty present. This study extends that work to demonstrate the performance of the algorithm under high levels of uncertainty.

terminal operations↗

A Modeling Approach for Handling Qualities and Controls Safety Analysis of Electric Air Taxi Vehicles

The combination of modern advances in electric propulsion, fly-by-wire controls, autonomy, and increasing demand for short range air taxi operations, is currently producing an outburst of vehicle designs more diverse than ever before. Advanced software tools are needed to support the rapid and safe introduction of any design into the airspace, including the safety of the deployed flight control system and vehicle handling qualities. This paper presents a methodology for building air taxi vehicle models with distributed electric propulsion for use in analyzing flight control system safety at the conceptual design level.The approach builds on existing software tools capable of outputting aeromechanics-based linear perturbation models for Vertical Take-off and Landing vehicles with multiple rotors. Rotor torque inputs are then converted into equivalent voltage control inputs, and the linear state and input dynamics matrices are modified to include electric motor dynamics with common parameters for direct-current electric motors. The linear perturbation dynamics are then stitched across multiple operating points into a quasi-Linear Parameter Varying model that covers the full flight envelope. A Model Predictive Controller is developed for use with the full envelope model, and a tradeoff analysis between handling quality and motor requirements is demonstrated using a six passenger NASA air taxi reference design.

Urban Air Mobility↗

High Fidelity Simulations of Air-Cooled Reactor Cavity Cooling System

High Temperature Gas Reactor (HTGR) designs incorporate passive safety systems (e.g., the Reactor Cavity Cooling System [RCCS]) that utilize natural principles to manage heat dissipation from the reactor pressure vessel (RPV) during accidents or routine shutdowns. The industry community is experiencing a pressing need for advanced simulation tools that can accurately assess the performance of these types of systems. In the literature, a knowledge gap exists concerning high-fidelity data for the RCCS, and this gap is one of the areas of focus of the present study. This research focuses on a specific RCCS designed for General Atomics' Modular High-Temperature Gas Reactor (GA-MHTGR). Experimental studies on a scaled version (can be seen in Figure 1) of the air-cooled RCCS used in GA-MHTGR were conducted by the University of Wisconsin-Madison (UW-Madison). This work contributes to a broader initiative aimed at establishing a numerical benchmark based on the UW-Madison experiments.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Expanding AirSTAR Capability for Flight Research in an Existing Avionics Design

The NASA Airborne Subscale Transport Aircraft Research (AirSTAR) project is an Unmanned Aerial Systems (UAS) test bed for experimental flight control laws and vehicle dynamics research. During its development, the test bed has gone through a number of system permutations, each meant to add functionality to the concept of operations of the system. This enabled the build-up of not only the system itself, but also the support infrastructure and processes necessary to support flight operations. These permutations were grouped into project phases and the move from Phase-III to Phase-IV was marked by a significant increase in research capability and necessary safety systems due to the integration of an Internal Pilot into the control system chain already established for the External Pilot. The major system changes in Phase-IV operations necessitated a new safety and failsafe system to properly integrate both the Internal and External Pilots and to meet acceptable project safety margins. This work involved retrofitting an existing data system into the evolved concept of operations. Moving from the first Phase-IV aircraft to the dynamically scaled aircraft further involved restructuring the system to better guard against electromagnetic interference (EMI), and the entire avionics wiring harness was redesigned in order to facilitate better maintenance and access to onboard electronics. This retrofit and harness re-design will be explored and how it integrates with the evolved Phase-IV operations.

Laughter, Sean A.↗

Querying Safety Cases

Querying a safety case to show how the various stakeholders' concerns about system safety are addressed has been put forth as one of the benefits of argument-based assurance (in a recent study by the Health Foundation, UK, which reviewed the use of safety cases in safety-critical industries). However, neither the literature nor current practice offer much guidance on querying mechanisms appropriate for, or available within, a safety case paradigm. This paper presents a preliminary approach that uses a formal basis for querying safety cases, specifically Goal Structuring Notation (GSN) argument structures. Our approach semantically enriches GSN arguments with domain-specific metadata that the query language leverages, along with its inherent structure, to produce views. We have implemented the approach in our toolset AdvoCATE, and illustrate it by application to a fragment of the safety argument for an Unmanned Aircraft System (UAS) being developed at NASA Ames. We also discuss the potential practical utility of our query mechanism within the context of the existing framework for UAS safety assurance.

Safety Case↗

Problems in Machine Learning-Based Systems for Safety-Critical Avionics

To explore, discover, and understand the impact on safety of growing complexity introduced by modernization aimed at improving the efficiency of flight, the access to airspace, and/or the expansion of services provided by air vehicles. To develop and demonstrate innovative solutions that enable this modernization and the aviation transformation envisioned by ARMD through proactive mitigation of risks in accordance with target levels of safety.

Safety Critical Systems↗