Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety System”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

System safety in manned spaceflight

System safety in manned spaceflight is discussed with attention to the organization of the NASA safety effort, hazard identification and resolution, safety program integration, risk management visibility, and space transportation system payload safety. Key ingredients of the safety program, including concepts such as a distinct and appropriate level of responsibility for safety, and comprehensive and appropriate safety requirements from the policy level to the system level, are summarized. Program safety interrelationships are indicated.

Hammack, J. B.↗

Why system safety programs can fail

Factors that cause system safety programs to fail are discussed from the viewpoint that in general these programs have not achieved their intended aims. The one item which is considered to contribute most to failure of a system safety program is a poor statement of work which consists of ambiguity, lack of clear definition, use of obsolete requirements, and pure typographical errors. It is pointed out that unless safety requirements are stated clearly, and where they are readily apparent as firm requirements, some of them will be overlooked by designers and contractors. The lack of clarity is stated as being a major contributing factor in system safety program failure and usually evidenced in: (1) lack of clear requirements by the procuring activity, (2) lack of clear understanding of system safety by other managers, and (3) lack of clear methodology to be employed by system safety engineers.

Willie Hammer↗

The Art World's Concept of Negative Space Applied to System Safety Management

Tools from several different disciplines can improve system safety management. This paper relates the Art World with our system safety world, showing useful art schools of thought applied to system safety management, developing an art theory-system safety bridge. This bridge is then used to demonstrate relations with risk management, the legal system, personnel management and basic management (establishing priorities). One goal of this presentation/paper is simply to be a fun diversion from the many technical topics presented during the conference.

Goodin, James Ronald (Ronnie)↗

Issues in Software System Safety: Polly Ann Smith Co. versus Ned I. Ludd

This paper is a work of fiction, but it is fiction with a very real purpose: to stimulate careful thought and friendly discussion about some questions for which thought is often careless and discussion is often unfriendly. To accomplish this purpose, the paper creates a fictional legal case. The most important issue in this fictional case is whether certain proffered expert testimony about software engineering for safety critical systems should be admitted. Resolving this issue requires deciding the extent to which current practices and research in software engineering, especially for safety-critical systems, can rightly be considered based on knowledge, rather than opinion.

Holloway, C. Michael↗

An Autonomous Flight Safety System

The Autonomous Flight Safety System (AFSS) being developed by NASA s Goddard Space Flight Center s Wallops Flight Facility and Kennedy Space Center has completed two successful developmental flights and is preparing for a third. AFSS has been demonstrated to be a viable architecture for implementation of a completely vehicle based system capable of protecting life and property in event of an errant vehicle by terminating the flight or initiating other actions. It is capable of replacing current human-in-the-loop systems or acting in parallel with them. AFSS is configured prior to flight in accordance with a specific rule set agreed upon by the range safety authority and the user to protect the public and assure mission success. This paper discusses the motivation for the project, describes the method of development, and presents an overview of the evolving architecture and the current status.

Bull, James B.↗

Autonomous Flight Safety System

The Autonomous Flight Safety System (AFSS) is an independent self-contained subsystem mounted onboard a launch vehicle. AFSS has been developed by and is owned by the US Government. Autonomously makes flight termination/destruct decisions using configurable software-based rules implemented on redundant flight processors using data from redundant GPS/IMU navigation sensors. AFSS implements rules determined by the appropriate Range Safety officials.

Simpson, James↗

Comprehensive Lifecycle for Assuring System Safety

CLASS is a novel approach to the enhancement of system safety in which the system safety case becomes the focus of safety engineering throughout the system lifecycle. CLASS also expands the role of the safety case across all phases of the system's lifetime, from concept formation to decommissioning. As CLASS has been developed, the concept has been generalized to a more comprehensive notion of assurance becoming the driving goal, where safety is an important special case. This report summarizes major aspects of CLASS and contains a bibliography of papers that provide additional details.

Knight, John C.↗

The NASA System Safety Program

NASA aerospace system safety program implementation and supporting organization with emphasis on background, concepts, constraints, methods and results

Harris, R. E.↗

Lunar module program system safety

The application of system safety principles to the Lunar Module Program is summarized. Objectives of the program include elimination or reduction of risk to personnel, material, and facilities resulting from failures or malfunctions in hardware or procedures. Data also cover design, production, and test activity.

William E. Scarborough↗

Range Safety Systems

The high kinetic and potential energy of a launch vehicle mandates there be a mechanism to minimize possible damage to provide adequate safety for the launch facilities, range, and, most importantly, the general public. The Range Safety System, sometimes called the Flight Termination System or Flight Safety System, provides the required level of safety. The Range Safety System section of the Avionics chapter will attempt to describe how adequate safety is provided, the system's design, operation, and it's interface with the rest of the launch vehicle.

Schrock, Kenneth W.↗

Informing New Concepts for UAS and Autonomous System Safety Management using Disaster Management and First Responder Scenarios

As emerging flight operations become more prevalent and increasingly automated and distributed, the capabilities for managing safety of vehicles and operations will also need to evolve. To address this challenge, the National Academies has envisioned an In-Time Aviation Safety Management System (IASMS) capability for a wide range of aviation operations including current commercial operations as well as new entrants envisioned with advanced air mobility (AAM). The suite of IASMS services, functions, and capabilities (SFCs) would be implemented in a federated approach and would address trends as well as individual operations. Through predictive modeling and data analysis, IASMS is envisioned to identify arising risks so that they can be mitigated, in-time, before a safety incident occurs. IASMS and its requisite set of SFCs must leverage a wide range of information to perform. To better understand these new needs, FSF worked with the aviation and humanitarian communities to develop and validate scenarios that include traditional aviation operations and UAS operations intermingled as they are deployed for disaster management and first responder (DMFR) situations. The three scenarios developed include: • Post Natural disaster response, such as a hurricane, involving multiple parties utilizing traditional aviation and UAS to support rescue operations, surveil damage, and locate survivors needing assistance. • Wildfire fighting in remote locations with traditional aircraft for transport and fire-retardant delivery combined with UAS for surveillance of fire locations as well as to track individual firefighter locations. • Medical Operations and AAM in Urban Environments including passenger-carrying helicopters and AAM vehicles, medical missions (such as transport of radio-pharmaceuticals), and other UAS delivery operations (such as the delivery of defibrillators). Each scenario was developed and validated by representatives with expertise in humanitarian operations, urban and rural emergency response, air traffic management, UAS operations, and traditional flight operations. The scenario definitions address roles and responsibilities of individual actors, the appropriate utilization of UAS, and the actions taken by those actors to appropriately manage risks associated with the mission and environment. The risks to aviation traffic and to people on the ground explored included potential risks arising from incompatibilities in calculating reference altitudes (eg, differing uses of AGL, MSL, barometric, or GPS-derived values), loss of command and control (C2) communications, rapid changes in weather and winds, and physical interference. For each risk, IASMS SFCs were postulated in the context of monitoring services, risk assessment capabilities, and identifying appropriate mitigation strategies. The identified SFC capabilities were envisioned from known services postulated for IASMS and for UTM. For these unique environments, IASMS SFCs are needed to address conditions such as hazardous payloads, micro-climates and urban canyons, and the need to keep uninvolved air traffic out of the area where DMFR operations are being conducted. The second phase of analysis focused on inferring the specific information needs and the SFCs for IASMS, utilizing a structure of 16 information classes to organize requirements. For each of the risks identified in the workshops, it was postulated what data sources would be necessary to monitor critical aspects of the risk (eg, surrounding air traffic, ground population, terrain, etc). to be directly measured as well as data that would be derived, which implies additional SFCs for different actors to understand what information would likely be exchanged between parties. For an IASMS to be effective, additional research is needed to develop the advanced algorithms that can address the increasingly autonomous and complex operations in differing environments and to develop means of identifying unknown risks. Looking at these scenarios highlighted a number of research issues. These include the ability to quickly "cordon off" airspace thru temporary flight restrictions (TFRs) or other means, developing clear definitions to enable automation-based algorithms for prioritizing operations, defining airspace density metrics, standardization of altitude reporting, and establishing a basis for safety data metrics definition and collection. This paper seeks to outline the development of an IASMS in the context of the DMFR scenarios and resulting demonstrations. Utilizing this contextual approach, NASA will generate recommendations for an assured safety framework for AAM operations that enables AAM operations to safely access the NAS.

In Time Aviation Safety Management System↗

System safety education focused on flight safety

The measures necessary for achieving higher levels of system safety are analyzed with an eye toward maintaining the combat capability of the Air Force. Several education courses were provided for personnel involved in safety management. Data include: (1) Flight Safety Officer Course, (2) Advanced Safety Program Management, (3) Fundamentals of System Safety, and (4) Quantitative Methods of Safety Analysis.

Eugene Holt↗

The procedure safety system

Telerobotic operations, whether under autonomous or teleoperated control, require a much more sophisticated safety system than that needed for most industrial applications. Industrial robots generally perform very repetitive tasks in a controlled, static environment. The safety system in that case can be as simple as shutting down the robot if a human enters the work area, or even simply building a cage around the work space. Telerobotic operations, however, will take place in a dynamic, sometimes unpredictable environment, and will involve complicated and perhaps unrehearsed manipulations. This creates a much greater potential for damage to the robot or objects in its vicinity. The Procedural Safety System (PSS) collects data from external sensors and the robot, then processes it through an expert system shell to determine whether an unsafe condition or potential unsafe condition exists. Unsafe conditions could include exceeding velocity, acceleration, torque, or joint limits, imminent collision, exceeding temperature limits, and robot or sensor component failure. If a threat to safety exists, the operator is warned. If the threat is serious enough, the robot is halted. The PSS, therefore, uses expert system technology to enhance safety thus reducing operator work load, allowing him/her to focus on performing the task at hand without the distraction of worrying about violating safety criteria.

Obrien, Maureen E.↗

Why System Safety Professionals Should Read Accident Reports

System safety professionals, both researchers and practitioners, who regularly read accident reports reap important benefits. These benefits include an improved ability to separate myths from reality, including both myths about specific accidents and ones concerning accidents in general; an increased understanding of the consequences of unlikely events, which can help inform future designs; a greater recognition of the limits of mathematical models; and guidance on potentially relevant research directions that may contribute to safety improvements in future systems.

Holloway, C. M.↗

WTEC monograph on instrumentation, control and safety systems of Canadian nuclear facilities

This report updates a 1989-90 survey of advanced instrumentation and controls (I&C) technologies and associated human factors issues in the U.S. and Canadian nuclear industries carried out by a team from Oak Ridge National Laboratory (Carter and Uhrig 1990). The authors found that the most advanced I&C systems are in the Canadian CANDU plants, where the newest plant (Darlington) has digital systems in almost 100 percent of its control systems and in over 70 percent of its plant protection system. Increased emphasis on human factors and cognitive science in modern control rooms has resulted in a reduced workload for the operators and the elimination of many human errors. Automation implemented through digital instrumentation and control is effectively changing the role of the operator to that of a systems manager. The hypothesis that properly introducing digital systems increases safety is supported by the Canadian experience. The performance of these digital systems has been achieved using appropriate quality assurance programs for both hardware and software development. Recent regulatory authority review of the development of safety-critical software has resulted in the creation of isolated software modules with well defined interfaces and more formal structure in the software generation. The ability of digital systems to detect impending failures and initiate a fail-safe action is a significant safety issue that should be of special interest to nuclear utilities and regulatory authorities around the world.

Uhrig, Robert E.↗

ESSAA: Embedded system safety analysis assistant

The Embedded System Safety Analysis Assistant (ESSAA) is a knowledge-based tool that can assist in identifying disaster scenarios. Imbedded software issues hazardous control commands to the surrounding hardware. ESSAA is intended to work from outputs to inputs, as a complement to simulation and verification methods. Rather than treating the software in isolation, it examines the context in which the software is to be deployed. Given a specified disasterous outcome, ESSAA works from a qualitative, abstract model of the complete system to infer sets of environmental conditions and/or failures that could cause a disasterous outcome. The scenarios can then be examined in depth for plausibility using existing techniques.

Wallace, Peter↗