Search NASA⌕ Search

SEARCH · Search NASA

Results for “Critical Function Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Validation of the F-18 high alpha research vehicle flight control and avionics systems modifications

The verification and validation process is a critical portion of the development of a flight system. Verification, the steps taken to assure the system meets the design specification, has become a reasonably understood and straightforward process. Validation is the method used to ensure that the system design meets the needs of the project. As systems become more integrated and more critical in their functions, the validation process becomes more complex and important. The tests, tools, and techniques which are being used for the validation of the high alpha research vehicle (HARV) turning vane control system (TVCS) are discussed and the problems and their solutions are documented. The emphasis of this paper is on the validation of integrated system.

Chacon, Vince↗

Validation of the F-18 high alpha research vehicle flight control and avionics systems modifications

The verification and validation process is a critical portion of the development of a flight system. Verification, the steps taken to assure the system meets the design specification, has become a reasonably understood and straightforward process. Validation is the method used to ensure that the system design meets the needs of the project. As systems become more integrated and more critical in their functions, the validation process becomes more complex and important. The tests, tools, and techniques which are being used for the validation of the high alpha research vehicle (HARV) turning valve control system (TVCS) are discussed, and their solutions are documented. The emphasis of this paper is on the validation of integrated systems.

Chacon, Vince↗

Gyro Evaluation for the Mission to Jupiter

As an important component in NASA's New Frontiers Program, the Jupiter Polar Orbiter (Juno) mission is designed to investigate in-depth physical properties of Jupiter. It will include the giant planet's ice-rock core and atmospheric studies as well as exploration of its polar magnetosphere. It will also provide the opportunity to understand the origin of the Jovian magnetic field. Due to severe radiation environment of the Jovian system, this mission inherently presents a significant technical challenge to Attitude Control System (ACS) design since the ACS sensors must survive and function properly to reliably maneuver the spacecraft throughout the mission. Different gyro technologies and their critical performance characteristics are discussed, compared and evaluated to facilitate a choice of appropriate gyro-based inertial measurement unit to operate in a harsh Jovian environment to assure mission success.

physical properties↗

Solar Electric Propulsion System Integration Technology (SEPSIT). Volume 1: Technical summary

The use of solar electric propulsion as a means of exploring space beyond the reach of ballistic missions was investigated. The method used was to study the application of this new propulsion technology to a future flight project. A 1980 Encke rendezvous mission was chosen because a design successful for Encke could be used for less difficult, but scientifically rewarding, missions. Design points for the mission and for the thrust subsystem were specified. The baseline-vehicle design was defined. A preliminary functional description document for the thrust subsystem was originated. Analyses were performed in support of the design point selection for the SEP-module thrust subsystem to specify parameters, to clarify and optimize the interface requirements, and to assure feasibility of some of the more critical technological aspects of SEP application.

Gardner, J. A.↗

Report on Alternative Devices to Pyrotechnics on Spacecraft

Pyrotechnics accomplish many functions on today's spacecraft, possessing minimum volume/weight, providing instantaneous operation on demand, and requiring little input energy. However, functional shock, safety, and overall system cost issues, combined with emergence and availability of new technologies question their continued use on space missions. Upon request from the National Aeronautics and Space Administration's (NASA) Program Management Council (PMC), Langley Research Center (LaRC) conducted a survey to identify and evaluate state-of-the-art non-explosively actuated (NEA) alternatives to pyrotechnics, identify NEA devices planned for NASA use, and investigate potential interagency cooperative efforts. In this study, over 135 organizations were contacted, including NASA field centers, Department of Defense (DOD) and other government laboratories, universities, and American and European industrial sources resulting in further detailed discussions with over half, and 18 face-to-face briefings. Unlike their single use pyrotechnic predecessors, NEA mechanisms are typically reusable or refurbishable, allowing flight of actual tested units. NEAs surveyed include spool-based devices, thermal knife, Fast Acting Shockless Separation Nut (FASSN), paraffin actuators, and shape memory alloy (SMA) devices (e.g., Frangibolt). The electro-mechanical spool, paraffin actuator and thermal knife are mature, flight proven technologies, while SMA devices have a limited flight history. There is a relationship between shock, input energy requirements, and mechanism functioning rate. Some devices (e.g., Frangibolt and spool based mechanisms) produce significant levels of functional shock. Paraffin, thermal knife, and SMA devices can provide gentle, shock-free release but cannot perform critically timed, simultaneous functions. The FASSN flywheel-nut release device possesses significant potential for reducing functional shock while activating nearly instantaneously. Specific study recommendations include: (1) development of NEA standards, specifically in areas of material characterization, functioning rates, and test methods; (2) a systems level approach to assure successful NEA technology application; and (3) further investigations into user needs, along with industry/government system-level real spacecraft cost benefit trade studies to determine NEA application foci and performance requirements. Additional survey observations reveal an industry and government desire to establish partnerships to investigate remaining unknowns and formulate NEA standards, specifically those driven by SMAs. Finally, there is increased interest and need to investigate alternative devices for such functions as stage/shroud separation and high pressure valving. This paper summarizes results of the NASA-LaRC survey of pyrotechnic alternatives. State of-the-art devices with their associated weight and cost savings are presented. Additionally, a comparison of functional shock characteristics of several devices are shown, and potentially related technology developments are highlighted.

Lucy, M. H.↗

SE and I system testability: The key to space system FDIR and verification testing

The key to implementing self-diagnosing design is a systems engineering task focused on design for testability concurrent with design for functionality. The design for testability process described here is the product of several years of DOD study and experience. Its application to the space station has begun on Work Package II under NASA and McDonnell direction. Other work package teams are being briefed by Harris Corporation with the hope of convincing them to embrace the process. For the purpose of this discussion the term testability is used to describe the systems engineering process by which designers can assure themselves and their reviewers that their designs are TESTABLE, that is they will support the downstream process of determining their functionality. Due to the complexity and density of present-day state-of-the-art designs, such as pipeline processors and high-speed integrated circuit technology, testability feature design is a critical requirement of the functional design process. A systematic approach to Space systems test and checkout as well as fault detection fault isolation reconfiguration (FDFIR) will minimize operational costs and maximize operational efficiency. An effective design for the testability program must be implemented by all contractors to insure meeting this objective. The process is well understood and technology is here to support it.

Barry, Thomas↗

Defining Collaborative Control Interactions Using Systems Theory

Human teams collaborate by establishing roles, changing functional authorities, maintaining team cognition, coordinating, and mutually helping one another close control loops. These complex inter-actions are inspiring novel concepts to improve human-machine and multi-machine collaboration. However, these new systems face engineering gaps in modeling, analysis, design, and assurance. As such, few have been fielded in safety-critical domains like aerospace. To analyze safety, this paper introduces a system-theoretic framework to describe interactions that are—or are planned to be—used in multi-controller systems. It outlines a taxonomy of seven structural dimensions that influence controller interactions and nine dynamics observed in collaborative control that are defined using Systems Theory. An analyzed set of 101 controller interactions in aerospace systems demonstrates how to apply the framework and that designers are trying to create more sophisticated systems. This framework provides the foundation to extend system-theoretic hazard analysis techniques to systematically find collabora-tive-control causal factors.

Human machine teaming↗

Enhanced UAS Availability via Vehicle to Vehicle Routing Scaled Experiments

The safe integration of modern unmanned aerial systems into the national airspace requires the ability to be able to confirm that the vehicles are working as planned. This means the availability of the vehicle and latency of the communication is critical. These requirements, along with a complex and multifaceted environment as well as the unmanned air traffic management framework, present a unique optimization problem. In this paper, we articulate our envisioned problem space and create a scaled-down version to test the functional feasibility of utilizing the vehicle to vehicle communication as a secondary communication assurance mechanism. We present our framework, experimental approach, and some lessons learned through the process.

Nicholas B Cramer↗

Overview of environmental test plans for Space Station Freedom work package 4

The generation and distribution of electric power for Space Station Freedom (SSF) is critical to the station's success. Work Package 4 (WP-04) has the responsibility for the design, development, test, and delivery of the Electric Power System (EPS) for the SSF. During launch, assembly, and operation, the EPS will be subjected to various environments. A test and verification approach has been developed to assure that the EPS will function in these environments. An overview of that test program is presented with emphasis on environmental testing of hardware. Two key areas of the test program are highlighted in the overview. One area is the verification of the Solar Power Module (SPM) and associated cargo element hardware. This area includes detailing the plans for development and qualification testing of the SPM hardware. One series of tests, including modal and acoustic, has been completed on a development cargo element. Another area highlighted is the acceptance testing of high-power Orbital Replacement Units (ORU). The environmental test equipment plans are presented and reviewed in light of an aggressive production rate, which delivers ORU's to the WP-04 and other Space Station Work Packages. Through implementing the test program as outlined, the EPS hardware will be certified for flight and operation on the Space Station Freedom.

Peterson, Tom J.↗

Solid Rocket Booster (SRB) - Evolution and Lessons Learned During the Shuttle Program

The Solid Rocket Booster (SRB) element integrates all the subsystems needed for ascent flight, entry, and recovery of the combined Booster and Motor system. These include the structures, avionics, thrust vector control, pyrotechnic, range safety, deceleration, thermal protection, and retrieval systems. This represents the only human-rated, recoverable and refurbishable solid rocket ever developed and flown. Challenges included subsystem integration, thermal environments and severe loads (including water impact), sometimes resulting in hardware attrition. Several of the subsystems evolved during the program through design changes. These included the thermal protection system, range safety system, parachute/recovery system, and others. Obsolescence issues occasionally required component recertification. Because the system was recovered, the SRB was ideal for data and imagery acquisition, which proved essential for understanding loads and system response. The three main parachutes that lower the SRBs to the ocean are the largest parachutes ever designed, and the SRBs are the largest structures ever to be lowered by parachutes. SRB recovery from the ocean was a unique process and represented a significant operational challenge; requiring personnel, facilities, transportation, and ground support equipment. The SRB element achieved reliability via extensive system testing and checkout, redundancy management, and a thorough postflight assessment process. Assembly and integration of the booster subsystems was a unique process and acceptance testing of reused hardware components was required for each build. Extensive testing was done to assure hardware functionality at each level of stage integration. Because the booster element is recoverable, subsystems were available for inspection and testing postflight, unique to the Shuttle launch vehicle. Problems were noted and corrective actions were implemented as needed. The postflight assessment process was quite detailed and a significant portion of flight operations. The SRBs provided fully redundant critical systems including thrust vector control, mission critical pyrotechnics, avionics, and parachute recovery system. The design intent was to lift off with full redundancy. On occasion, the redundancy management scheme was needed during flight operations. This paper describes some of the design challenges, how the design evolved with time, and key areas where hardware reusability contributed to improved system level understanding.

Kanner, Howard S.↗

Solid Rocket Booster (SRB) Flight System Integration at Its Best

The Solid Rocket Booster (SRB) element integrates all the subsystems needed for ascent flight, entry, and recovery of the combined Booster and Motor system. These include the structures, avionics, thrust vector control, pyrotechnic, range safety, deceleration, thermal protection, and retrieval systems. This represents the only human-rated, recoverable and refurbishable solid rocket ever developed and flown. Challenges included subsystem integration, thermal environments and severe loads (including water impact), sometimes resulting in hardware attrition. Several of the subsystems evolved during the program through design changes. These included the thermal protection system, range safety system, parachute/recovery system, and others. Because the system was recovered, the SRB was ideal for data and imagery acquisition, which proved essential for understanding loads, environments and system response. The three main parachutes that lower the SRBs to the ocean are the largest parachutes ever designed, and the SRBs are the largest structures ever to be lowered by parachutes. SRB recovery from the ocean was a unique process and represented a significant operational challenge; requiring personnel, facilities, transportation, and ground support equipment. The SRB element achieved reliability via extensive system testing and checkout, redundancy management, and a thorough postflight assessment process. However, the in-flight data and postflight assessment process revealed the hardware was affected much more strongly than originally anticipated. Assembly and integration of the booster subsystems required acceptance testing of reused hardware components for each build. Extensive testing was done to assure hardware functionality at each level of stage integration. Because the booster element is recoverable, subsystems were available for inspection and testing postflight, unique to the Shuttle launch vehicle. Problems were noted and corrective actions were implemented as needed. The postflight assessment process was quite detailed and a significant portion of flight operations. The SRBs provided fully redundant critical systems including thrust vector control, mission critical pyrotechnics, avionics, and parachute recovery system. The design intent was to lift off with full redundancy. On occasion, the redundancy management scheme was needed during flight operations. This paper describes some of the design challenges and technical issues, how the design evolved with time, and key areas where hardware reusability contributed to improved system level understanding.

Wood, T. David↗

Vulcan Test Platform: Demonstrating the Data Center as a Flexible Grid Asset

Explosive data center demand is outpacing grid infrastructure development. AI workloads and hyperscale cloud growth are creating unprecedented power requirements, while traditional grid expansion faces multi-year development timelines, regulatory hurdles, and decarbonization challenges. Sidewalk Infrastructure Partners recognized this impending crisis years ago and founded Verrus to develop an innovative solution: data centers that function as grid assets rather than passive loads. The Verrus approach integrates proprietary grid-aware controls with battery energy storage systems (BESS) in a medium-voltage architecture that delivers three critical capabilities: Fast-responding demand flexibility that can service requests from the utility within 10 seconds, Uninterrupted transition to islanded operation during grid disturbances, Continuous uptime assurance while maintaining all customer service level commitments Through Verrus' strategic partnership with the National Renewable Energy Laboratory (NREL), we validated these capabilities on Vulcan, a 70 MW utility-scale test platform powered by NREL's ARIES Virtual Emulation Environment. This deployment-ready technology has successfully demonstrated that Verrus data centers can deliver meaningful grid services while maintaining mission-critical reliability. This technical report outlines the design, methodology, and results of this emulated deployment, demonstrating that data centers can play a pivotal role in enhancing grid flexibility and reliability, without sacrificing service level guarantees.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Implementation of Programmatic Quality and the Impact on Safety

The purpose of this paper is to discuss the implementation of a programmatic quality assurance discipline within the International Space Station Program and the resulting impact on safety. NASA culture has continued to stress safety at the expense of quality when both are extremely important and both can equally influence the success or failure of a Program or Mission. Although safety was heavily criticized in the media after Col~imbiaa, strong case can be made that it was the failure of quality processes and quality assurance in all processes that eventually led to the Columbia accident. Consequently, it is possible to have good quality processes without safety, but it is impossible to have good safety processes without quality. The ISS Program quality assurance function was analyzed as representative of the long-term manned missions that are consistent with the President s Vision for Space Exploration. Background topics are as follows: The quality assurance organizational structure within the ISS Program and the interrelationships between various internal and external organizations. ISS Program quality roles and responsibilities with respect to internal Program Offices and other external organizations such as the Shuttle Program, JSC Directorates, NASA Headquarters, NASA Contractors, other NASA Centers, and International Partner/participants will be addressed. A detailed analysis of implemented quality assurance responsibilities and functions with respect to NASA Headquarters, the JSC S&MA Directorate, and the ISS Program will be presented. Discussions topics are as follows: A comparison of quality and safety resources in terms of staffing, training, experience, and certifications. A benchmark assessment of the lessons learned from the Columbia Accident Investigation (CAB) Report (and follow-up reports and assessments), NASA Benchmarking, and traditional quality assurance activities against ISS quality procedures and practices. The lack of a coherent operational and sustaining quality assurance strategy for long-term manned space flight. An analysis of the ISS waiver processes and the Problem Reporting and Corrective Action (PRACA) process implemented as quality functions. Impact of current ISS Program procedures and practices with regards to operational safety and risk A discussion regarding a "defense-in-depth" approach to quality functions will be provided to address the issue of "integration vs independence" with respect to the roles of Programs, NASA Centers, and NASA Headquarters. Generic recommendations are offered to address the inadequacies identified in the implementation of ISS quality assurance. A reassessment by the NASA community regarding the importance of a "quality culture" as a component within a larger "safety culture" will generate a more effective and value-added functionality that will ultimately enhance safety.

Huls, Dale Thomas↗

Standards for AI/ML and Emerging Technologies

Standards development activities require a keen and deep understanding of the problem being solved by the standard as well as the technologies being deployed in any reference implementation of the solution. It is important to understand the mechanisms and limits of the fundamental, underlying science of implementation and verification technologies used to realize and assure systems. We need to understand the limits of what current process and metrics can provide with respect to new technologies. US leadership is important in this endeavor, and it is vital that we have a measured approach that yields sound results. We wish to start with simple, well-defined, non-safety critical applications and then progress to functions which have (1) clearly defined requirements, (2) means of checking the answer/output, and (3) means of intervention and mitigation of incorrect answers/outputs.

Standards Development↗

Application of quantitative risk assessment to address stakeholder questions in geologic carbon storage

Ambitious international greenhouse gas emissions reduction targets demand a rapid transformation to a low-carbon economy. This transformation includes the accelerated adoption of carbon dioxide (CO2) capture and storage (CCS) technology. However, as with any large-scale engineering enterprise, the widespread commercial-scale deployment of geologic carbon storage (GCS) raises important questions about technology and cost-effectiveness, safety, environmental risk, and long-term liability. Effectively assessing and managing risks and liability associated with GCS projects is a key technical need throughout the project life cycle-from site selection and permitting to monitoring design, operational risk management, and post-operational site closure. This presentation highlights recent advancements in tools for quantitative risk assessment, being developed by the National Risk Assessment Partnership (NRAP). NRAP is a multi-year, multinational laboratory research collaboration sponsored by the U.S. Department of Energy's Office of Fossil Energy and Carbon Management. Our focus will be on these tools' applications in addressing critical stakeholder questions related to supporting permitting to ensure secure and environmentally protective storage; designing effective and efficient monitoring plans; evaluating the effectiveness of remedial actions and risk management alternatives; and informing liability assessment and investment decisions. This paper will detail the key functionality of NRAP’s Open-Source Integrated Assessment Model (NRAP-Open-IAM), a computational framework for assessing leakage risk and containment assurance. This model features streamlined workflows for calculating leakage risk profiles, delineating risk-based area of review, and assessing contingency plans and post-injection site care requirements. ORION is an open-source, observation-based ensemble forecasting toolkit to help operators assess the seismic hazard at a carbon storage site. The State of Stress Analysis Tool (SOSAT), designed to assess subsurface stress conditions and evaluate geomechanical risk resulting from CO2 injection in an area of interest will also be presented. We will also introduce a prototype model to evaluate storage project costs and liability associated with risk management. The Technoeconomic and Liability Evaluation for Storage (TALES) model uses results from forecasts of leakage and induced seismicity risk to estimate the lifecycle cost of managing risk. Finally, a preliminary example of how the NRAP Risk-based Adaptive Monitoring Plan (RAMP) tool can be used to design efficient and effective site monitoring plans and estimate the detectability of fluid leakage will be provided. The relevance of these tools for addressing key stakeholder questions amidst uncertainty will be emphasized.

decision support↗

Reliability inputs to Mariner 9 data explosion

This paper describes the prelaunch and post-launch reliability functions which contributed to the success of the Mariner 9 spacecraft. Examples are included to illustrate how each reliability activity was a vital part of each phase of the project. Prelaunch reliability functions included: (1) establishing, negotiating, and monitoring system and subsystem requirements, (2) participating in spacecraft system and subsystem design/hardware reviews, (3) monitoring preparation of failure mode effects and criticality analyses (FMECA), (4) establishing and managing a problem failure reporting (PFR) system for the spacecraft and its support equipment, (5) monitoring electronic parts activities, and (6) participating in spacecraft reviews. Particular emphasis is placed on mission operations reliability assurance activities, which included: (1) spacecraft problem/failure reporting, (2) managing an integrating failure reporting system which covered all mission operations activities, (3) real-time analysis of spacecraft anomalies, and (4) risk assessment.

Macgregor, D. S.↗

Considerations in Assuring Safety of Increasingly Autonomous Systems

Recent technological advances have accelerated the development and application of increasingly autonomous (IA) systems in civil and military aviation. IA systems can provide automation of complex mission tasks-ranging across reduced crew operations, air-traffic management, and unmanned, autonomous aircraft-with most applications calling for collaboration and teaming among humans and IA agents. IA systems are expected to provide benefits in terms of safety, reliability, efficiency, affordability, and previously unattainable mission capability. There is also a potential for improving safety by removal of human errors. There are, however, several challenges in the safety assurance of these systems due to the highly adaptive and non-deterministic behavior of these systems, and vulnerabilities due to potential divergence of airplane state awareness between the IA system and humans. These systems must deal with external sensors and actuators, and they must respond in time commensurate with the activities of the system in its environment. One of the main challenges is that safety assurance, currently relying upon authority transfer from an autonomous function to a human to mitigate safety concerns, will need to address their mitigation by automation in a collaborative dynamic context. These challenges have a fundamental, multidimensional impact on the safety assurance methods, system architecture, and V&V capabilities to be employed. The goal of this report is to identify relevant issues to be addressed in these areas, the potential gaps in the current safety assurance techniques, and critical questions that would need to be answered to assure safety of IA systems. We focus on a scenario of reduced crew operation when an IA system is employed which reduces, changes or eliminates a human's role in transition from two-pilot operations.

Alves, Erin E.↗

Integrated Systems Health Management for Space Exploration

Integrated Systems Health Management (ISHM) is a system engineering discipline that addresses the design, development, operation, and lifecycle management of components, subsystems, vehicles, and other operational systems with the purpose of maintaining nominal system behavior and function and assuring mission safety and effectiveness under off-nominal conditions. NASA missions are often conducted in extreme, unfamiliar environments of space, using unique experimental spacecraft. In these environments, off-nominal conditions can develop with the potential to rapidly escalate into mission- or life-threatening situations. Further, the high visibility of NASA missions means they are always characterized by extraordinary attention to safety. ISHM is a critical element of risk mitigation, mission safety, and mission assurance for exploration. ISHM enables: In-space maintenance and repair; a) Autonomous (and automated) launch abort and crew escape capability; b) Efficient testing and checkout of ground and flight systems; c) Monitoring and trending of ground and flight system operations and performance; d) Enhanced situational awareness and control for ground personnel and crew; e) Vehicle autonomy (self-sufficiency) in responding to off-nominal conditions during long-duration and distant exploration missions; f) In-space maintenance and repair; and g) Efficient ground processing of reusable systems. ISHM concepts and technologies may be applied to any complex engineered system such as transportation systems, orbital or planetary habitats, observatories, command and control systems, life support systems, safety-critical software, and even the health of flight crews. As an overarching design and operational principle implemented at the system-of-systems level, ISHM holds substantial promise in terms of affordability, safety, reliability, and effectiveness of space exploration missions.

Uckun, Serdar↗