Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 433 records · Page 24

Problems in Machine Learning-Based Systems for Safety-Critical Avionics

To explore, discover, and understand the impact on safety of growing complexity introduced by modernization aimed at improving the efficiency of flight, the access to airspace, and/or the expansion of services provided by air vehicles. To develop and demonstrate innovative solutions that enable this modernization and the aviation transformation envisioned by ARMD through proactive mitigation of risks in accordance with target levels of safety.

Safety Critical Systems↗

Skylab Medical Experiments Altitude Test /SMEAT/ facility design and operation.

This paper presents the design approaches and test facility operation methods used to successfully accomplish a 56-day test for Skylab to permit evaluation of selected Skylab medical experiments in a ground test simulation of the Skylab environment with an astronaut crew. The systems designed for this test include the two-gas environmental control system, the fire suppression and detection system, equipment transfer lock, ground support equipment, safety systems, potable water system, waste management system, lighting and power system, television monitoring, communications and recreation systems, and food freezer.

Hinners, A. H., Jr.↗

Implementation of the Enhanced Flight Termination System at National Aeronautics and Space Administration Dryden Flight Research Center

This paper discusses the methodology, requirements, tests, and results of the implementation of the current operating capability for the Enhanced Flight Termination System (EFTS) at the National Aeronautics and Space Administration (NASA) Dryden Flight Research Center (DFRC). The implementation involves the development of the EFTS at NASA DFRC starting from the requirements to system safety review to full end to end system testing, and concluding with the acceptance of the system as an operational system. The paper discusses the first operational usage and subsequent flight utilizing EFTS successfully.

Tow, David↗

Psychophysiological Methods to Assess Pilot Productive Safety Behaviors

The NASA System-Wide Safety (SWS) Project is focused on developing new technologies and operational concepts for the aviation industry to meet the increasing global demand while maintaining the current ultra-safe system safety levels. To achieve this, the SWS Project is developing research priorities, including In-time System-wide Safety Assurance (ISSA) and In-time Aviation Safety Management System (IASMS; Ellis et al., 2019). A critical component of the IASMS is the human as pilot and in other roles in aviation operations as demonstrated by SWS human factors research on rare occurrences of human error and the far more prevalent human safety producing behaviors (e.g., Hollnagel, 2016). The talk presented by Chad Stephens of NASA Langley Research Center and NASA SWS Project will describe the history of human factors research involving psychophysiological and biocybernetics methods supporting aviation safety conducted at NASA. Specific examples of recent NASA crew state monitoring research focused on a psychophysiological assessment method and system to enable Training for Attention Management will be demonstrated. Current SWS research including the SWS Operations and Technologies for Enabling Resilient In-Time Assurance (SOTERIA) flight simulation study and a data testbed created to enable study of Human Contributions to Safety (HC2S) will be presented. Ongoing collaborative research efforts with Boeing researchers will be highlighted and opportunities for further collaboration will be discussed.

psychophysiology↗

Analysis of AP1000 Small-Break Loss-of-Coolant Accident Using Reactor Transient Simulator

The Westinghouse Electric Company’s Advanced Passive Reactor (AP1000) is characterized by the incorporation of passive safety systems (PSSs) designed to ensure core cooling during transient events. The assessment of PSSs requires evaluation of their performance through a combination of experiments and simulations employing various thermal-hydraulic codes. In addition, detailed evaluation of PSSs for a specific reactor system transient analysis such as loss-of-coolant-accident analysis supports understanding representative integral effects test facility development and the further evolution model development and assessment process. Developing a reactor system code is a complex and time-consuming process that requires significant engineering expertise and effort. It can take several months to even years to complete in the early stages of reactor system design and analysis. However, this process can be expedited through the use of transient simulator models for similar reactor systems, which can be used for lesson learning and training purposes. This study uses the Personal Computer Transient Analyzer (PCTRAN) code. The main advantage of PCTRAN is its ease of use and ability to run faster than real time. This study presents the results obtained for a small-break loss-of-coolant accident (SBLOCA) for two breaks using the full version (licensed) of PCTRAN. The purpose of this investigation is to evaluate the overall system behavior during the postulated SBLOCA event as well as assess the capability of the PCTRAN code to reproduce the system response during transient events. The obtained results were compared with the Westinghouse NOTRUMP system code. The PCTRAN code proved to be reliable in predicting the qualitative behavior of the system in both transient cases. As for the system response, it was found that it is contingent on the activation time of the PSSs. The differences in reactor coolant system pressure between the two codes were attributed to the critical flow model and simplification of mass and energy balance. Despite PCTRAN’s limitations, it can still provide a reasonable prediction of various reactor parameters such as pressure, mass flow rate, and void fraction during a SBLOCA scenario. It is worth noting that PCTRAN currently employs a bulk approach similar to that of the Modular Accident Analysis Program (MAAP) and MELCOR codes. However, the upcoming version of PCTRAN will include an artificial intelligence–based detection and accident prevention system, as well as different models for different reactor components. Consequently, PCTRAN has the potential to be upgraded to match the system thermal-hydraulic codes of the U.S. Nuclear Regulatory Commission and become more widely used in cybersecurity to safeguard nuclear power plants from cyberattacks.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Range Flight Safety Requirements

The purpose of this NASA Technical Standard is to provide the technical requirements for the NPR 8715.5, Range Flight Safety Program, in regards to protection of the public, the NASA workforce, and property as it pertains to risk analysis, Flight Safety Systems (FSS), and range flight operations. This standard is approved for use by NASA Headquarters and NASA Centers, including Component Facilities and Technical and Service Support Centers, and may be cited in contract, program, and other Agency documents as a technical requirement. This standard may also apply to the Jet Propulsion Laboratory or to other contractors, grant recipients, or parties to agreements to the extent specified or referenced in their contracts, grants, or agreements, when these organizations conduct or participate in missions that involve range flight operations as defined by NPR 8715.5.1.2.2 In this standard, all mandatory actions (i.e., requirements) are denoted by statements containing the term “shall.”1.3 TailoringTailoring of this standard for application to a specific program or project shall be formally documented as part of program or project requirements and approved by the responsible Technical Authority in accordance with NPR 8715.3, NASA General Safety Program Requirements.

Flight↗

Autonomous Hydrogen Fueling Station

This project “Autonomous Hydrogen Fueling Station” covered the autonomous refueling with both gaseous hydrogen and liquid hydrogen. The part on gaseous hydrogen focused on the development of an autonomous robotic fueling arm that would couple to a fuel cell engine for hydrogen refueling without guidance from the forklift operator and budget period. Research was also covered for the robotic fueling with a commercial vehicle. The second phase of the project created the baseline for an autonomous liquid hydrogen transfer system that would minimize boil off losses by operating at thermodynamically efficient state points. For the development of the robotic fueling arm, testing was conducted to establish a baseline measurement of the accuracy and repeatability of a human operator positioning a lift truck in front of a dispenser. The goal was to establish the range of motion required for an autonomous fueling mechanism to mate a hydrogen nozzle with a receptacle on a fuel cell system installed in a forklift. The final design comprised a selective compliance articulated robot arm (SCARA)-type mechanism with two arms for horizontal motion and a ball screw for vertical movement and color and LIDAR cameras were used for marker identification and proximity awareness to guide the robotic arm to its target receptacle. Initial tests resulted in 199 out of 200 successful attempts at autonomous coupling of the dispensing coupler and a fuel cell engine, without hydrogen. The dispenser prototype was modified to include tubing for both hydrogen fuel and air purge lines, but subsequent tests were confounded by the shoulder motor over current errors which limited the robot from getting to the fully inserted position to achieve a positive latch. Robotic hydrogen refueling was successfully demonstrated over 1.5 hours of testing, Plug completed 29 successful latches with an average number of 4 sequential latches before failure. However, a robot capable of placing the nozzle with more force is required for higher reliability. For budget period two, a small scale (10 kg / transfer) automated control system was designed that would operate valves to control pressure and flow of liquid nitrogen between a source and receiving tank with an aim to minimize boil off losses by operating at the most thermodynamically efficient state points. Control system logic flow and a P&ID were developed prior to system safety characterization via HAZOP. A control narrative and system state points were defined. Delays in approval for a change of project objective and procurement issues precluded the construction and test of the final prototype system.

08 HYDROGEN↗

EVA and telerobot interaction

We are about to enter into a new era - that of astronauts working hand in hand with telerobots in space. This has been done to some degree with astronauts and the Space Station Shuttle's Remote Manipulator Arm. However, for the Space Station Freedom, not only will astronauts be working with the RMS type system but also with smaller, more dexterous systems such as the Flight Telerobotic Servicer (FTS). Because EVA time is a premium resource, the most effective use of the astronauts and the telerobot will be required. There may be some tasks for which it is most efficient to have both the EVA astronaut and the telerobot working together. This type of close integration has not occurred before and brings up many issues. Most of these issues are related to technology: communication must be infallible, new control systems and devices may be required, enhanced telerobot safety systems may be necessary. IVA operations may also be affected by the combined EVA telerobot tasks. There is also the issue of how the EVA astronaut and the telerobot work on separate tasks but at the same time. For both situations, research and development of at least some new technology is required; enhanced communication both by voice and data, sophisticated collision detection systems, more responsive controls and displays. These new systems or system enhancements may require knowledge base systems for their operation. Some of the important issues, types of tasks, the FTS capabilities, the technology that is needed to address those issues, and the possible impact on Space Station Freedom are reviewed.

Willshire, Kelli F.↗

Reliability-Based Design of a Safety-Critical Automation System: A Case Study

In 1986, NASA funded a project to modernize the NASA Ames Research Center Unitary Plan Wind Tunnels, including the replacement of obsolescent controls with a modern, automated distributed control system (DCS). The project effort on this system included an independent safety analysis (ISA) of the automation system. The purpose of the ISA was to evaluate the completeness of the hazard analyses which had already been performed on the Modernization Project. The ISA approach followed a tailoring of the risk assessment approach widely used on existing nuclear power plants. The tailoring of the nuclear industry oriented risk assessment approach to the automation system and its role in reliability-based design of the automation system is the subject of this paper.

Carroll, Carol W.↗

Discrete Abstractions of Hybrid Systems: Verification of Safety and Application to User-Interface Design

Human interaction with a complex control system involves the user, the automation’s discrete mode logic, and the underlying continuous dynamics of the physical system. The user-interface of such systems always displays a reduced set of information about the entire system. Designing interfaces such that all the pertinent information is available and assuring that this information is correct is important for any user-interface, but especially so for safety-critical systems such as automotive systems and autopilots. Here we describe a methodology for the analysis of hybrid control systems that incorporate user interaction, with the goal of assuring that the information provided to the user is correct. That is, the user-interface must contain all information necessary to safely complete a desired procedure or task. We begin with a hybrid system model which incorporates discrete mode logic as well as nonlinear continuous dynamics. Using a hybrid computational tool for reachability, we find the largest region of the state-space in which we can guarantee the state of the system can always remain – this is the safe region of operation. By implementing a controller for safety which arises from this computation, we mathematically guarantee that this safe region is invariant, meaning that the system will always remain within the safe region if the determined controller is used on the boundary of the safe region. Verification within a hybrid framework allows us to account for the continuous dynamics underlying the discrete representations displayed to the user. Using the computed invariant regions as discrete states, we can abstract a discrete event system from this hybrid system with safety restrictions. This abstraction can be used to determine what information must be provided on the display. Furthermore, in cases in which an interface already exists, the abstraction provides the necessary input into existing interface verification methods. We provide two examples: a car traveling through a yellow light at an intersection and an aircraft autopilot in an automatic landing/go-around maneuver. The examples demonstrate the applicability of this methodology to hybrid systems that have operational constraints we can pose in terms of safety. This methodology differs from existing work in hybrid system verification in that we directly account for the user’s interactions with the system.

Meeko Oishi↗

Remote Diagnosis of the International Space Station Utilizing Telemetry Data

Modern systems such as fly-by-wire aircraft, nuclear power plants, manufacturing facilities, battlefields, etc., are all examples of highly connected network enabled systems. Many of these systems are also mission critical and need to be monitored round the clock. Such systems typically consist of embedded sensors in networked subsystems that can transmit data to central (or remote) monitoring stations. Moreover, many legacy are safety systems were originally not designed for real-time onboard diagnosis, but a critical and would benefit from such a solution. Embedding additional software or hardware in such systems is often considered too intrusive and introduces flight safety and validation concerns. Such systems can be equipped to transmit the sensor data to a remote-processing center for continuous health monitoring. At Qualtech Systems, we are developing a Remote Diagnosis Server (RDS) that can support multiple simultaneous diagnostic sessions from a variety of remote subsystems.

Deb, Somnath↗

Analyzing Software Requirements Errors in Safety-Critical, Embedded Systems

This paper analyzes the root causes of safety-related software errors in safety-critical, embedded systems. The results show that software errors identified as potentially hazardous to the system tend to be produced by different error mechanisms than non- safety-related software errors. Safety-related software errors are shown to arise most commonly from (1) discrepancies between the documented requirements specifications and the requirements needed for correct functioning of the system and (2) misunderstandings of the software's interface with the rest of the system. The paper uses these results to identify methods by which requirements errors can be prevented. The goal is to reduce safety-related software errors and to enhance the safety of complex, embedded systems.

Lutz, Robyn R.↗

The jumbo jet and public safety.

Safety of jumbo jet aircraft, accident reduction, traffic control, systems safety engineering, landing approach, midair collision prevention and crash survival

Lederer, J.↗

Fact Sheets of CTAS and NASA Decision-Support Tools and Concepts

Distributed Air/Ground (DAG) Traffic Management (TM) is an integrated operational concept in which flight deck crews, air traffic service providers and aeronautical operational control personnel use distributed decision-making to enable user preferences and increase system capacity, while meeting air traffic management (ATM) requirements. It is a possible operational mode under the Free Flight concept outlined by the RTCA Task Force 3. The goal of DAG-TM is to enhance user flexibility/efficiency and increase system capacity, without adversely affecting system safety or restricting user accessibility to the National Airspace System (NAS). DAG-TM will be accomplished with a human-centered operational paradigm enabled by procedural and technological innovations. These innovations include automation aids, information sharing and Communication, Navigation, and Surveillance (CNS) / ATM technologies. The DAG-TM concept is intended to eliminate static restrictions to the maximum extent possible. In this paradigm, users may plan and operate according to their preferences - as the rule rather than the exception - with deviations occumng eyond the year 2015. Out of a total of 15 concept elements, 4 have been selected for initial sutidies (see Key Elements in sidebar). DAG-TM research is being performed at Ames, Glenn, and Langley Research Centers.

Lee, Katharine↗

Mechanical Systems

The presentation provides an overview of requirement and interpretation letters, mechanical systems safety interpretation letter, design and verification provisions, and mechanical systems verification plan.

Davis, Robert E.↗

CATS-based Agents That Err

This report describes preliminary research on intelligent agents that make errors. Such agents are crucial to the development of novel agent-based techniques for assessing system safety. The agents extend an agent architecture derived from the Crew Activity Tracking System that has been used as the basis for air traffic controller agents. The report first reviews several error taxonomies. Next, it presents an overview of the air traffic controller agents, then details several mechanisms for causing the agents to err in realistic ways. The report presents a performance assessment of the error-generating agents, and identifies directions for further research. The research was supported by the System-Wide Accident Prevention element of the FAA/NASA Aviation Safety Program.

Callantine, Todd J.↗

Decentralized Control Synthesis for Air Traffic Management in Urban Air Mobility

Urban air mobility (UAM) refers to air transportation services within an urban area, often in an on-demand fashion. We study air traffic management (ATM) for vehicles in a UAM fleet, while guaranteeing system safety requirements such as traffic separation. Existing ATM methods for unmanned aerial systems, such as UAS traffic management, utilize alternative approaches which do not provide strict safety guarantees. No established infrastructure exists for providing ATM at scale for UAM. We provide a decentralized, hierarchical approach for UAM ATM that allows for scalability to high traffic densities as well as providing theoretical guarantees of correctness with respect to user-provided safety specifications. Our main contributions are two-fold. First, we propose a novel UAM ATM architecture that divides the control authority between vertihubs that are each in charge of all UAM vehicles in their local airspace. Each vertihub also contains a number of vertiports that are in charge of UAM vehicle takeoffs and landings. The resulting architecture is decentralized and hierarchical, which not only enables scalability, but also robustness in the event of any individual vertihub or vertiport no longer being operational. Second, we provide a contract-based correct-by-construction reactive synthesis approach that provably guarantees safety properties with respect to user-provided specifications in linear temporal logic. We demonstrate the approach on large-volume UAM air traffic data.

Urban Air Mobility↗