Search NASASearch

SEARCH · Search NASA

Results for “Documented Safety Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Possible safety hazards associated with the operation of the 0.3-m transonic cryogenic tunnel at the NASA Langley Research Center

The 0.3 m Transonic Cryogenic Tunnel (TCT) at the NASA Langley Research Center was built in 1973 as a facility intended to be used for no more than 60 hours in order to verify the validity of the cryogenic wind tunnel concept at transonic speeds. The role of the 0.3 m TCT has gradually changed until now, after over 3000 hours of operation, it is classified as a major NASA research facility and, under the administration of the Experimental Techniques Branch, it is used extensively for the testing of airfoils at high Reynolds numbers and for the development of various technologies related to the efficient operation and use of cryogenic wind tunnels. The purpose of this report is to document the results of a recent safety analysis of the 0.3 m TCT facility. This analysis was made as part of an on going program with the Experimental Techniques Branch designed to ensure that the existing equipment and current operating procedures of the 0.3 m TCT facility are acceptable in terms of today's standards of safety for cryogenic systems.

Webster, T. J.

Sense and Avoid Safety Analysis for Remotely Operated Unmanned Aircraft in the National Airspace System. Version 5

This document describes a method to demonstrate that a UAS, operating in the NAS, can avoid collisions with an equivalent level of safety compared to a manned aircraft. The method is based on the calculation of a collision probability for a UAS , the calculation of a collision probability for a base line manned aircraft, and the calculation of a risk ratio given by: Risk Ratio = P(collision_UAS)/P(collision_manned). A UAS will achieve an equivalent level of safety for collision risk if the Risk Ratio is less than or equal to one. Calculation of the probability of collision for UAS and manned aircraft is accomplished through event/fault trees.

Carreno, Victor

Defining and Reasoning about Model-based Safety Analysis: A Review

Model-based safety analysis (MBSA) has been around for over two decades. The benefits of MBSA have been well-documented in the literature, such as tackling complexity, introducing Formal Methods to eliminate the ambiguity in the traditional safety analysis, using automation to replace the error-prone manual safety modeling process, and ensuring consistency between the design model and the safety model. However, there is still a lack of consensus on what MBSA even is. This paper provides an approach towards developing such a consensus

model-based

Certifying Auto-Generated Flight Code

Model-based design and automated code generation are being used increasingly at NASA. Many NASA projects now use MathWorks Simulink and Real-Time Workshop for at least some of their modeling and code development. However, there are substantial obstacles to more widespread adoption of code generators in safety-critical domains. Since code generators are typically not qualified, there is no guarantee that their output is correct, and consequently the generated code still needs to be fully tested and certified. Moreover, the regeneration of code can require complete recertification, which offsets many of the advantages of using a generator. Indeed, manual review of autocode can be more challenging than for hand-written code. Since the direct V&V of code generators is too laborious and complicated due to their complex (and often proprietary) nature, we have developed a generator plug-in to support the certification of the auto-generated code. Specifically, the AutoCert tool supports certification by formally verifying that the generated code is free of different safety violations, by constructing an independently verifiable certificate, and by explaining its analysis in a textual form suitable for code reviews. The generated documentation also contains substantial tracing information, allowing users to trace between model, code, documentation, and V&V artifacts. This enables missions to obtain assurance about the safety and reliability of the code without excessive manual V&V effort and, as a consequence, eases the acceptance of code generators in safety-critical contexts. The generation of explicit certificates and textual reports is particularly well-suited to supporting independent V&V. The primary contribution of this approach is the combination of human-friendly documentation with formal analysis. The key technical idea is to exploit the idiomatic nature of auto-generated code in order to automatically infer logical annotations. The annotation inference algorithm itself is generic, and parametrized with respect to a library of coding patterns that depend on the safety policies and the code generator. The patterns characterize the notions of definitions and uses that are specific to the given safety property. For example, for initialization safety, definitions correspond to variable initializations while uses are statements which read a variable, whereas for array bounds safety, definitions are the array declarations, while uses are statements which access an array variable. The inferred annotations are thus highly dependent on the actual program and the properties being proven. The annotations, themselves, need not be trusted, but are crucial to obtain the automatic formal verification of the safety properties without requiring access to the internals of the code generator. The approach has been applied to both in-house and commercial code generators, but is independent of the particular generator used. It is currently being adapted to flight code generated using MathWorks Real-Time Workshop, an automatic code generator that translates from Simulink/Stateflow models into embedded C code.

Denney, Ewen

Green Propellant Landing Demonstration at U.S. Range

The Green Propellant Loading Demonstration (GPLD) was conducted December 2015 at Wallops Flight Facility (WFF), leveraging work performed over recent years to bring lower toxicity hydrazine replacement green propellants to flight missions. The objective of this collaboration between NASA Goddard Space Flight Center (GSFC), WFF, the Swedish National Space Board (SNSB), and Ecological Advanced Propulsion Systems (ECAPS) was to successfully accept LMP-103S propellant at a U.S. Range, store the propellant, and perform a simulated flight vehicle propellant loading. NASA GSFC Propulsion (Code 597) managed all aspects of the operation, handling logistics, preparing the procedures, and implementing the demonstration. In addition to the partnership described above, Moog Inc. developed an LMP-103S propellant-compatible titanium rolling diaphragm flight development tank and loaned it to GSFC to act as the GPLD flight vessel. The flight development tank offered the GPLD an additional level of flight-like propellant handling process and procedures. Moog Inc. also provided a compatible latching isolation valve for remote propellant expulsion. The GPLD operation, in concert with Moog Inc. executed a flight development tank expulsion efficiency performance test using LMP-103S propellant. As part of the demonstration work, GSFC and WFF documented Range safety analyses and practices including all elements of shipping, storage, handling, operations, decontamination, and disposal. LMP-103S has not been previously handled at a U.S. Launch Range. Requisite for this activity was an LMP-103S Risk Analysis Report and Ground Safety Plan. GSFC and WFF safety offices jointly developed safety documentation for application into the GPLD operation. The GPLD along with the GSFC Propulsion historical hydrazine loading experiences offer direct comparison between handling green propellant versus safety intensive, highly toxic hydrazine propellant. These described motives initiated the GPLD operation in order to investigate the handling and process safety variances in project resources between LMP-103S and typical in-space propellants. The GPLD risk reduction operation proved successful for many reasons including handling the green propellant at a U.S. Range, loading and pressurizing a flight-like tank, expelling the propellant, measuring the tank expulsion efficiency, and most significantly, GSFC propulsion personnel's new insight into the LMP-103S propellant handling details.

Propellant

Green Propellant Loading Demonstration at U.S. Range

The Green Propellant Loading Demonstration (GPLD) was conducted December 2015 at Wallops Flight Facility (WFF), leveraging work performed over recent years to bring lower toxicity hydrazine replacement green propellants to flight missions. The objective of this collaboration between NASA Goddard Space Flight Center (GSFC), WFF, the Swedish National Space Board (SNSB), and Ecological Advanced Propulsion Systems (ECAPS) was to successfully accept LMP-103S propellant at a U.S. Range, store the propellant, and perform a simulated flight vehicle propellant loading. NASA GSFC Propulsion (Code 597) managed all aspects of the operation, handling logistics, preparing the procedures, and implementing the demonstration. In addition to the partnership described above, Moog Inc. developed an LMP-103S propellant-compatible titanium rolling diaphragm flight development tank and loaned it to GSFC to act as the GPLD flight vessel. The flight development tank offered the GPLD an additional level of flight-like propellant handling process and procedures. Moog Inc. also provided a compatible latching isolation valve for remote propellant expulsion. The GPLD operation, in concert with Moog Inc. executed a flight development tank expulsion efficiency performance test using LMP-103S propellant. As part of the demonstration work, GSFC and WFF documented Range safety analyses and practices including all elements of shipping, storage, handling, operations, decontamination, and disposal. LMP-103S has not been previously handled at a U.S. Launch Range. Requisite for this activity was an LMP-103S Risk Analysis Report and Ground Safety Plan. GSFC and WFF safety offices jointly developed safety documentation for application into the GPLD operation. The GPLD along with the GSFC Propulsion historical hydrazine loading experiences offer direct comparison between handling green propellant versus safety intensive, highly toxic hydrazine propellant. These described motives initiated the GPLD operation in order to investigate the handling and process safety variances in project resources between LMP-103S and typical in-space propellants. The GPLD risk reduction operation proved successful for many reasons including handling the green propellant at a U.S. Range, loading and pressurizing a flight-like tank, expelling the propellant, measuring the tank expulsion efficiency, and most significantly, GSFC propulsion personnel's new insight into the LMP-103S propellant handling details.

Green Propellant

Collision Avoidance Functional Requirements for Step 1. Revision 6

This Functional Requirements Document (FRD) describes the flow of requirements from the high level operational objectives down to the functional requirements specific to cooperative collision avoidance for high altitude, long endurance unmanned aircraft systems. These are further decomposed into performance and safety guidelines that are backed up by analysis or references to various documents or research findings. The FRD should be considered when establishing future policies, procedures, and standards pertaining to cooperative collision avoidance.

Source record

Engineering risk reduction in satellite programs

Methods developed in planning and executing system safety engineering programs for Lockheed satellite integration contracts are presented. These procedures establish the applicable safety design criteria, document design compliance and assess the residual risks where non-compliant design is proposed, and provide for hazard analysis of system level test, handling and launch preparations. Operations hazard analysis identifies product protection and product liability hazards prior to the preparation of operational procedures and provides safety requirements for inclusion in them. The method developed for documenting all residual hazards for the attention of program management assures an acceptable minimum level of risk prior to program deployment. The results are significant for persons responsible for managing or engineering the deployment and production of complex high cost equipment under current product liability law and cost/time constraints, have a responsibility to minimize the possibility of an accident, and should have documentation to provide a defense in a product liability suit.

Dean, E. S., Jr.

Engineering and Safety Partnership Enhances Safety of the Space Shuttle Program (SSP)

Project Management must use the risk assessment documents (RADs) as tools to support their decision making process. Therefore, these documents have to be initiated, developed, and evolved parallel to the life of the project. Technical preparation and safety compliance of these documents require a great deal of resources. Updating these documents after-the-fact not only requires substantial increase in resources - Project Cost -, but this task is also not useful and perhaps an unnecessary expense. Hazard Reports (HRs), Failure Modes and Effects Analysis (FMEAs), Critical Item Lists (CILs), Risk Management process are, among others, within this category. A positive action resulting from a strong partnership between interested parties is one way to get these documents and related processes and requirements, released and updated in useful time. The Space Shuttle Program (SSP) at the Marshall Space Flight Center has implemented a process which is having positive results and gaining acceptance within the Agency. A hybrid Panel, with equal interest and responsibilities for the two larger organizations, Safety and Engineering, is the focal point of this process. Called the Marshall Safety and Engineering Review Panel (MSERP), its charter (Space Shuttle Program Directive 110 F, April 15, 2005), and its Operating Control Plan emphasizes the technical and safety responsibilities over the program risk documents: HRs; FMEA/CILs; Engineering Changes; anomalies/problem resolutions and corrective action implementations, and trend analysis. The MSERP has undertaken its responsibilities with objectivity, assertiveness, dedication, has operated with focus, and has shown significant results and promising perspectives. The MSERP has been deeply involved in propulsion systems and integration, real time technical issues and other relevant reviews, since its conception. These activities have transformed the propulsion MSERP in a truly participative and value added panel, making a difference for the safety of the Space Shuttle Vehicle, its crew, and personnel. Because of the MSERP's valuable contribution to the assessment of safety risk for the SSP, this paper also proposes an enhanced Panel concept that takes this successful partnership concept to a higher level of 'true partnership'. The proposed panel is aimed to be responsible for the review and assessment of all risk relative to Safety for new and future aerospace and related programs.

Duarte, Alberto

Cooperative Conflict Avoidance Sensor Trade Study Report, Version 2

This study develops evaluation criteria for systems and technologies against the Cooperative Conflict Avoidance (CCA) requirements for unmanned flight at and above FL430 as part of Step 1 of the Access-5 program. These evaluation criteria are then applied to both current and future technologies to identify those which might be used to provide an Equivalent Level of Safety (ELOS) for CCA. This document provides the results of this analysis of various systems and technologies intended for evaluation as part of the CCA work package.

Source record

An Evaluation of The Dynamic Physical Security Risk Assessment Methodology for Fleet-Wide Applications

The requirements for U.S. nuclear power plants to maintain a large onsite physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This integrated process for physical security analysis is named Modeling and Analysis for Safety Security using Dynamic EMRALD Framework (MASS-DEF). This document provides an update on the progress in applying the MASS-DEF process to an operating commercial nuclear power plant as well as additional industry feedback regarding use of the tool for other physical security risk-informed topics. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, and integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5 or MAAP. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report is an update the progress of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report also provides an update to the procedural guidance for the MASS-DEF process and an overview of the generic models available for use by utilities. This report does not contain any plant’s sensitive information and/or safeguards information. This study’s purpose was to verify that the results achieved using generic models are similar to actual plant results and refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Hazard Analysis for Building 34 Vacuum Glove Box Assembly

One of the characteristics of an effective safety program is the recognition and control of hazards before mishaps or failures occur. Conducting potentially hazardous tests necessitates a thorough hazard analysis in order to prevent injury to personnel, and to prevent damage to facilities and equipment. The primary purpose of this hazard analysis is to define and address the potential hazards and controls associated with the Building 34 Vacuum Glove Box Assembly, and to provide the applicable team of personnel with the documented results. It is imperative that each member of the team be familiar with the hazards and controls associated with his/her particular tasks, assignments and activities while interfacing with facility test systems, equipment and hardware. In fulfillment of the stated purposes, the goal of this hazard analysis is to identify all hazards that have the potential to harm personnel, damage the facility or its test systems or equipment, test articles, Government or personal property, or the environment. This analysis may also assess the significance and risk, when applicable, of lost test objectives when substantial monetary value is involved. The hazards, causes, controls, verifications, and risk assessment codes have been documented on the hazard analysis work sheets in Appendix A of this document. The preparation and development of this report is in accordance with JPR 1700.1, "JSC Safety and Health Handbook" and JSC 17773 Rev D "Instructions for Preparation of Hazard Analysis for JSC Ground Operations".

Meginnis, Ian

Draft Feasibility Assessment for Use of AI in Preparing Transportation Safety Analysis Reports

Preparing transportation safety analysis reports for microreactors is time and labor intensive, requiring extensive cross referencing to Federal regulations, previously approved documents, and expert review comments across structural, thermal, criticality, shielding, containment, and security. These burdens are magnified by the novelty of microreactor technologies and the evolving regulatory landscape, as well as current workforce constraints. Generative AI and supporting machine learning tools present an opportunity to accelerate drafting timelines, lift generalized writing burdens, and systematically enforce regulatory adherence through retrieval augmented generation and other knowledge retrieval and mapping methods. This draft report presents a preliminary feasibility assessment of the use of AI to expedite the preparation of microreactor transportation safety analysis reports and proposes an initial methodology for doing so.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Retrospectively Documenting Satisfaction of the Overarching Properties: An Exploratory Prototype

Software-intensive aviation systems are typically developed in accordance with recognized development process, safety analysis, and software development standards such as SAE ARP4754A, SAE ARP4761, and RTCA DO-178C. Efforts to streamline assurance processes and make them flexible enough to handle future assurance challenges have produced the Overarching Properties (OPs) for airworthiness approval. Each of the three OPs is a property systems must possess to be certifiable. There is no mandated means of documenting possession of the OPs. To explore possible means, we have prepared retrospective documentation showing that a specimen software system possesses the OPs. The specimen system, Safeguard, enforces geofencing restrictions on unmanned aerial vehicles. Our OP-possession case for its airborne component comprises eight arguments in the Goal Structuring Notation (GSN): a main argument for each OP and five cross-cutting auxiliary arguments. We present this argument as an example for discussion and further research, e.g., into means of assessing OP possession.

safety case

Human Error Analysis for Human-Rated Space Systems

Humans bring unique capabilities to space systems and contribute to mission success in a manner that cannot be matched by machines. Nevertheless, from time to time, human error can present a threat to system performance, and system designers must anticipate and manage this risk. NASA’s Human-Rating Requirements for Space Systems call for program managers to conduct a human error analysis (HEA) during system development but does not specify how to do this. In 2018, NASA’s Engineering and Safety Center asked the authors to develop a guidance document on HEA. The resulting position paper outlines a suggested method for HEA and makes it clear that error analysis is about identifying and mitigating problems at a system level, and not about finding fault with individuals. Error management strategies must be directed at error-producing conditions, thereby reducing the likelihood of human error, while retaining the positive contribution that humans make to system operations.

human error human-rated space

Designing for human presence in space: An introduction to environmental control and life support systems

Human exploration and utilization of space requires habitats to provide appropriate conditions for working and living. These conditions are provided by environmental control and life support systems (ECLSS) that ensure appropriate atmosphere composition, pressure, and temperature; manage and distribute water, process waste matter, provide fire detection and suppression; and other functions as necessary. The functions that are performed by ECLSS are described and basic information necessary to design an ECLSS is provided. Technical and programmatic aspects of designing and developing ECLSS for space habitats are described including descriptions of technologies, analysis methods, test requirements, program organization, documentation requirements, and the requirements imposed by medical, mission, safety, and system needs. The design and development process is described from initial trade studies through system-level analyses to support operation. ECLSS needs for future space habitats are also described. Extensive listings of references and related works provide sources for more detailed information on each aspect of ECLSS design and development.

Wieland, Paul

External Tank Liquid Hydrogen (LH2) Prepress Regression Analysis Independent Review Technical Consultation Report

The request to conduct an independent review of regression models, developed for determining the expected Launch Commit Criteria (LCC) External Tank (ET)-04 cycle count for the Space Shuttle ET tanking process, was submitted to the NASA Engineering and Safety Center NESC on September 20, 2005. The NESC team performed an independent review of regression models documented in Prepress Regression Analysis, Tom Clark and Angela Krenn, 10/27/05. This consultation consisted of a peer review by statistical experts of the proposed regression models provided in the Prepress Regression Analysis. This document is the consultation's final report.

Parsons, Vickie s.