Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 451 records · Page 25

LAMP Technical Readiness Evaluation Report

An internal preliminary evaluation of Critical Technology Elements (CTEs) for the LANSCE Modernization Project (LAMP) was completed in 2023. This included determining corresponding Technical Readiness Levels (TRLs) for all subsystems using the criteria of DOE G 413.3-4A, Technical Readiness Assessment Guide. This revised report includes a summary of the recent design modifications required to meet the project Key Performance Requirements (KPPs), some of which may reduce technical risk to the project. These recent design modifications include: • Further optimization of the low-energy and medium-energy beam transport regions (LEBT and MEBT, respectively), including relocation of various functional elements (ie choppers, kickers, and bunchers). • An additional H - ion source to separate ion-source function based on beam delivery requirements. • A high-repetition-rate pulsed kicker magnet to select/merge the two H ion beams into a common low-energy beam transport. • Modification and further optimization to a more conventional RFQ design. Performance of the RFQ has been optimized to deliver the required three types of beams while meeting the project KPPs. • The addition of a second chopper in the medium-energy beam transport (MEBT) line to reduce the required pulser voltages. The scope of the evaluation was limited to the project Work Breakdown Structure (WBS) elements as defined for the RFQ Injector and Drift Tube Linac (DTL) systems only. Integration of Instrumentation and Controls (I&C) and Safety Systems was not considered, although specific technologies as related to the RFQ and DTL systems were included. Other elements of the project such as Shielding, System Design, Technical Management, and additional facility integration needed to enable off-line testing and pre-installation commissioning were also not evaluated. Each technical subsystem element was evaluated for technical readiness, however, not all were found to meet the criteria for a CTE. Three subsystem elements were determined to meet the CTE criteria. Their associated TRLs are summarized in the table below. These subsystem elements of the project have the lowest technical readiness due to either being new, novel or modified, requiring additional R&D before being capable of meeting the project Key Performance Parameters (KPPs) and subsystem requirements, or present technology exists but has not yet been demonstrated in a relevant environment. All other subsystems were determined to have a TRL of 8, indicating that actual operating systems exist having similar performance requirements as needed for LAMP. Details of the technical readiness evaluation for each subsystem is given in the following sections of this report.

43 PARTICLE ACCELERATORS↗

Helicopter technology benefits and needs. Volume 2: Appendices

Vehicle design, avionics and flight systems; safety and reliability; navigation, guidance and flight control; propulsion; auxiliary systems; human factors; and monitoring and diagnostic systems are the technology areas involved in solving operational and technical problems related to the use of helicopters. Tables show the problems encountered and the proposed research and technology for helicopter use for search and rescue; emergency medical services; law enforcement; environmental control; fire fighting; and resource management.

Zuk, J.↗

Oxygen/hydrogen Space Station propulsion system concept definition for IOC

The potential for the reduction in propulsion system life cycle costs through the use of on-board water electrolysis to generate oxygen and hydrogen propellants, as well as the potential advantages of improved system safety and contamination impact, led to a study to evaluate candidate oxygen-/hydrogen-based propulsion systems. In this study a representative set of propulsion system requirements were compiled and candidate oxygen/hydrogen-based propulsion systems synthesized. These candidate concepts were screened and a systems evaluation was performed on the remaining eight candidate concepts. Detailed system schematics were prepared. Operational design conditions were determined and system weight, volume, energy requirements, and costs were calculated. Evaluation results indicated that the oxygen/hydrogen propulsion systems can provide simple, low cost, and viable systems for the IOC Space Station. Based on these data, a relative concept evaluation was conducted using as selection criteria reliability, safety, cost, technical risk, contamination, operational utility, growth potential, and integration potential. Top ranked candidate systems were recommended to NASA/MSFC for consideration for the IOC Space Station.

Shoji, J. M.↗

Recovery of Space Shuttle Columbia and Return to Flight of Space Shuttle Discovery

NASA has come a long way in our journey to reduce the risks of operating the Spse Shuttle system. The External Tank bipod Thermal Protection System has been redesigned to eliminate the proximate cause of the Columbia accident. In all areas, we have applied the collective knowledge and capabilities of our Nation to comply with the Columbia Accident Investigation Board recommendations and to raise the bar beyond that. We have taken prudent technical action on potential threats to review and verify the material condition of all critical areas where failure could result in catastrophic loss of the crew and vehicle. We are satisfied that critical systems and elements should operate as intended-safely and reliably. While we will never eliminate all the risks from our human space flight programs, we have eliminated those we can and reduced, controlled, and/or mitigated others. The remaining identified risks will be evaluated for acceptance. Our risk reduction approach has its roots in the system safety engineering hierarchy for hazard abatement long employed in aerospace systems engineering. The components of the hierarchy are, in order of precedence, to: design/redesign; eliminate the hazard/risk; reduce the hazard/risk; and control the hazard/risk and/or mitigate the consequence of the remaining hazard/risk through warning devices, special procedures/capabilities, and/or training. This proven approach to risk reduction has been applied to potential hazards and risks in all critical areas of the Space Shuttle and has guided us through the technical challenges, failures, and successes present in return to flight endeavors. This approach provides the structured deliberation process required to verify and form the foundation for accepting any residual risk across the entire Space Shuttle Program by NASA leadership.

Rudolphi, Michael U.↗

Investigation of HZETRN 2010 as a Tool for Single Event Effect Qualification of Avionics Systems

NASA's future missions are focused on long-duration deep space missions for human exploration which offers no options for a quick emergency return to Earth. The combination of long mission duration with no quick emergency return option leads to unprecedented spacecraft system safety and reliability requirements. It is important that spacecraft avionics systems for human deep space missions are not susceptible to Single Event Effect (SEE) failures caused by space radiation (primarily the continuous galactic cosmic ray background and the occasional solar particle event) interactions with electronic components and systems. SEE effects are typically managed during the design, development, and test (DD&T) phase of spacecraft development by using heritage hardware (if possible) and through extensive component level testing, followed by system level failure analysis tasks that are both time consuming and costly. The ultimate product of the SEE DD&T program is a prediction of spacecraft avionics reliability in the flight environment produced using various nuclear reaction and transport codes in combination with the component and subsystem level radiation test data. Previous work by Koontz, et al.1 utilized FLUKA, a Monte Carlo nuclear reaction and transport code, to calculate SEE and single event upset (SEU) rates. This code was then validated against in-flight data for a variety of spacecraft and space flight environments. However, FLUKA has a long run-time (on the order of days). CREME962, an easy to use deterministic code offering short run times, was also compared with FLUKA predictions and in-flight data. CREME96, though fast and easy to use, has not been updated in several years and underestimates secondary particle shower effects in spacecraft structural shielding mass. Thus, this paper will investigate the use of HZETRN 20103, a fast and easy to use deterministic transport code, similar to CREME96, that was developed at NASA Langley Research Center primarily for flight crew ionizing radiation dose assessments. HZETRN 2010 includes updates to address secondary particle shower effects more accurately, and might be used as another tool to verify spacecraft avionics system reliability in space flight SEE environments.

Rojdev, Kristina↗

Quantifying Pilot Contribution to Flight Safety During Dual Generator Failure

Accident statistics cite flight crew error in over 60% of accidents involving transport category aircraft. Yet, a well-trained and well-qualified pilot is acknowledged as the critical center point of aircraft systems safety and an integral safety component of the entire commercial aviation system. No data currently exists that quantifies the contribution of the flight crew in this role. Neither does data exist for how often the flight crew handles non-normal procedures or system failures on a daily basis in the National Airspace System. A pilot-in-the-loop high fidelity motion simulation study was conducted by the NASA Langley Research Center in partnership with the Federal Aviation Administration (FAA) to evaluate the pilot's contribution to flight safety during normal flight and in response to aircraft system failures. Eighteen crews flew various normal and non-normal procedures over a two-day period and their actions were recorded in response to failures. To quantify the human's contribution, crew complement was used as the experiment independent variable in a between-subjects design. Pilot actions and performance when one of the flight crew was unavailable were also recorded for comparison against the nominal two-crew operations. This paper details diversion decisions, perceived safety of flight, workload, time to complete pertinent checklists, and approach and landing results while dealing with a complete loss of electrical generators. Loss of electrical power requires pilots to complete the flight without automation support of autopilots, flight directors, or auto throttles. For reduced crew complements, the additional workload and perceived safety of flight was considered unacceptable.

Etherington, Timothy J.↗

Quantifying Pilot Contribution to Flight Safety during Drive Shaft Failure

Accident statistics cite the flight crew as a causal factor in over 60% of large transport aircraft fatal accidents. Yet, a well-trained and well-qualified pilot is acknowledged as the critical center point of aircraft systems safety and an integral safety component of the entire commercial aviation system. The latter statement, while generally accepted, cannot be verified because little or no quantitative data exists on how and how many accidents/incidents are averted by crew actions. A joint NASA/FAA high-fidelity motion-base simulation experiment specifically addressed this void by collecting data to quantify the human (pilot) contribution to safety-of-flight and the methods they use in today's National Airspace System. A human-in-the-loop test was conducted using the FAA's Oklahoma City Flight Simulation Branch Level D-certified B-737-800 simulator to evaluate the pilot's contribution to safety-of-flight during routine air carrier flight operations and in response to aircraft system failures. These data are fundamental to and critical for the design and development of future increasingly autonomous systems that can better support the human in the cockpit. Eighteen U.S. airline crews flew various normal and non-normal procedures over a two-day period and their actions were recorded in response to failures. To quantify the human's contribution to safety of flight, crew complement was used as the experiment independent variable in a between-subjects design. Pilot actions and performance during single pilot and reduced crew operations were measured for comparison against the normal two-crew complement during normal and non-normal situations. This paper details the crew's actions, including decision-making, and responses while dealing with a drive shaft failure - one of 6 non-normal events that were simulated in this experiment.

Kramer, Lynda J.↗

My Summer Experience as an Administrative Officer Assistant

The motto of the Safety and Assurance Directorate (SAAD) at NASA Glenn Research Center is "mission success starts with safety." SAAD has the functions of providing reliability, quality assurance, and system safety management to all GRC projects, programs and offices. Product assurance personnel within SAAD supervise the product assurance efforts by contractors on major contracts within GRC. The directorate includes five division offices and the Plum brook Decommissioning Office. SAAD oversees Glenn's Emergency Preparedness Program which handles security, hazmat, and disaster response and supervision.

Jones, Janelle C.↗

Growing the NASA Safety and Mission Assurance (SMA) Workforce of Tomorrow

The NASA Safety Center (NSC) was established in2006 in response to Columbia Accident Investigation Board (CAIB) recommendations to strengthen NASA’s safety program. The NSC supports all NASA centers and facilities. The NSC fosters world-class Safety and Mission Assurance (SMA) support for NASA programs and projects through professional development activities and the advancement of the following SMA technical disciplines: - Aviation Safety - Operational Safety - Quality Engineering - Reliability and Maintainability - SMA Technical Leadership - Software Assurance - System Safety The NSC’s Technical Excellence Office (TEO) is charged with encouraging technical excellence in NASA’s SMA community primarily through professional development products and services. TEO’s first initiative was the SMA Technical Excellence Program (STEP). STEP is a career-oriented, professional development roadmap for safety professionals, which is designed for the employee to learn specific knowledge and skills to improve performance in their current role.

Safety and Mission Assurance↗

A real-time robot arm collision detection system

A data structure and update algorithm are presented for a prototype real time collision detection safety system for a multi-robot environment. The data structure is a variant of the octree, which serves as a spatial index. An octree recursively decomposes 3-D space into eight equal cubic octants until each octant meets some decomposition criteria. The octree stores cylspheres (cylinders with spheres on each end) and rectangular solids as primitives (other primitives can easily be added as required). These primitives make up the two seven degrees-of-freedom robot arms and environment modeled by the system. Octree nodes containing more than a predetermined number N of primitives are decomposed. This rule keeps the octree small, as the entire environment for the application can be modeled using a few dozen primitives. As robot arms move, the octree is updated to reflect their changed positions. During most update cycles, any given primitive does not change which octree nodes it is in. Thus, modification to the octree is rarely required. Incidents in which one robot arm comes too close to another arm or an object are reported. Cycle time for interpreting current joint angles, updating the octree, and detecting/reporting imminent collisions averages 30 milliseconds on an Intel 80386 processor running at 20 MHz.

Shaffer, Clifford A.↗

COLD-SAT feasibility study safety analysis

The Cryogenic On-orbit Liquid Depot-Storage, Acquisition, and Transfer (COLD-SAT) satellite presents some unique safety issues. The feasibility study conducted at NASA-Lewis desired a systems safety program that would be involved from the initial design in order to eliminate and/or control the inherent hazards. Because of this, a hazards analysis method was needed that: (1) identified issues that needed to be addressed for a feasibility assessment; and (2) identified all potential hazards that would need to be controlled and/or eliminated during the detailed design phases. The developed analysis method is presented as well as the results generated for the COLD-SAT system.

Mchenry, Steven T.↗

A real-time robot arm collision avoidance system

A data structure and update algorithm are presented for a prototype real-time collision avoidance safety system simulating a multirobot workspace. The data structure is a variant of the octree, which serves as a spatial index. An octree recursively decomposes 3D space into eight equal cubic octants until each octant meets some decomposition criteria. The N-objects octree, which indexes a collection of 3D primitive solids is used. These primitives make up the two (seven-degrees-of-freedom) robot arms and workspace modeled by the system. As robot arms move, the octree is updated to reflect their changed positions. During most update cycles, any given primitive does not change which octree nodes it is in. Thus, modification to the octree is rarely required. Cycle time for interpreting current arm joint angles, updating the octree to reflect new positions, and detecting/reporting imminent collisions averages 30 ms on an Intel 80386 processor running at 20 MHz.

Shaffer, Clifford A.↗

Pressure control and analysis report: Hydrogen Thermal Test Article (HTTA)

Tasks accomplished during the HTTA Program study period included: (1) performance of a literature review to provide system guidelines; (2) development of analytical procedures needed to predict system performance; (3) design and analysis of the HTTA pressurization system considering (a) future utilization of results in the design of a spacecraft maneuvering system propellant package, (b) ease of control and operation, (c) system safety, and (d) hardware cost; and (4) making conclusions and recommendations for systems design.

Source record↗

Multi-KW dc distribution system technology research study

The Multi-KW DC Distribution System Technology Research Study is the third phase of the NASA/MSFC study program. The purpose of this contract was to complete the design of the integrated technology test facility, provide test planning, support test operations and evaluate test results. The subjet of this study is a continuation of this contract. The purpose of this continuation is to study and analyze high voltage system safety, to determine optimum voltage levels versus power, to identify power distribution system components which require development for higher voltage systems and finally to determine what modifications must be made to the Power Distribution System Simulator (PDSS) to demonstrate 300 Vdc distribution capability.

Dawson, S. G.↗

Operations and Range Technology Development

The Operations and Range Technology Project is responsible for the development of key technologies as part of the KSC Spaceport Technology Center Initiative to substantially reduce vehicle launch and processing operations costs and improve the systems safety and reliability. The topics include: 1) Spaceport Technology Areas; 2) Umbilical Systems Development; 3) Automated Payload Handling Systems; 4) Command, Control and Monitor Systems; 5) Intelligent Synthesis Environment; 6) Low TRL Development; 7) Second Generation Project Organization; and 8) ASTP (3rd Generation) Project Organization. This paper is presented in viewgraph form.

Taylor, Dave↗

Towards Designing Graceful Degradation into Trajectory Based Operations: A Human-Systems Integration Approach

One of the most fundamental changes to the air traffic management system in NextGen is the concept of trajectory based operations (TBO). With the introduction of such change, system safety and resilience is a critical concern, in particular, the ability of systems to gracefully degrade. In order to design graceful degradation into a TBO envrionment, knowledge of the potential causes of degradation, and appropriate solutions, is required. In addition, previous research has predominantly explored the technological contribution to graceful degradation, frequently neglecting to consider the role of the human operator, specifically, air traffic controllers (ATCOs). This is out of step with real-world operations, and potentially limits an ecologically valid understanding of achieving graceful degradation in an air traffic control (ATC) environment. The following literature review aims to identify and summarize the literature to date on the potential causes of degradation in ATC and the solutions that may be applied within a TBO context, with a specific focus on the contribution of the air traffic controller. A framework of graceful degradation, developed from the literature, is presented. It is argued that in order to achieve graceful degradation within TBO, a human-system integration approach must be applied.

human-system integration↗

Towards Designing Graceful Degradation into Trajectory Based Operations: A Human-Machine System Integration Approach

One of the most fundamental changes to the air traffic management system in NextGen is the concept of trajectory based operations (TBO). With the introduction of such change, system safety and resilience is a critical concern, in particular, the ability of systems to gracefully degrade. In order to design graceful degradation into a TBO envrionment, knowledge of the potential causes of degradation, and appropriate solutions, is required. In addition, previous research has predominantly explored the technological contribution to graceful degradation, frequently neglecting to consider the role of the human operator, specifically, air traffic controllers (ATCOs). This is out of step with real-world operations, and potentially limits an ecologically valid understanding of achieving graceful degradation in an air traffic control (ATC) environment. The following literature review aims to identify and summarize the literature to date on the potential causes of degradation in ATC and the solutions that may be applied within a TBO context, with a specific focus on the contribution of the air traffic controller. A framework of graceful degradation, developed from the literature, is presented. It is argued that in order to achieve graceful degradation within TBO, a human-system integration approach must be applied.

human-system integration↗

Runtime Assurance Protection for Advanced Turbofan Engine Control

This paper describes technical progress made in the application of run time assurance (RTA) methods to turbofan engines with advanced propulsion control algorithms that are employed to improve engine performance. It is assumed that the advanced algorithms cannot be fully certified using current verification and validation approaches and therefore need to be continually monitored by an RTA system that ensures safe operation. However, current turbofan engine control systems utilize engine protection logic for safe combustion dynamics and stable airflow through the engine. It was determined that the engine protection logic should continue to be used to provide system safety and should be considered as a part of the overall RTA system. The additional function that an RTA system provides is to perform diagnostics on anomalous conditions to determine if these conditions are being caused by errors in the advanced controller. If this is the case, the RTA system switches operation to a trusted reversionary controller. Initial studies were performed to demonstrate this benefit. The other focus was to improve the performance of the engine protection logic, which was deemed too conservative and reduced engine performance during transient operations. It was determined that the conservative response was due to poor tuning of one of the controller channels within the protection logic. An automatic tuning algorithm was implemented to optimize the protection logic control gains based on minimizing tracking error. Improved tracking responses were observed with no change to the existing protection logic control architecture.

runtime monitoring↗