Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Wide Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Tracing NASA Contributions Toward Aviation Safety Stakeholder Guidance

The System-Wide Safety project at NASA is developing the concept and a subset of supporting technologies for evolving safety management from a post-accident iterative improvement on safety performed by large commercial operators only to predictive and increasingly autonomous safety functions that are performed during operations across vehicles, airports, and services. The system of interest is the In-time Aviation Safety Management System (IASMS), recommended by the National Academies for NASA to develop the concept in coordination with the broad and diverse community of stakeholders in aviation safety. Because the system context is the airspace and aviation industry, it is important to create and maintain traceability from the research work and system architecture elements developed at NASA to community-created roadmaps and aviation agency guidance.

IASMS↗

Energize the Future - Systems Engineering Processes and Methods: Tracing NASA Contributions Toward Aviation Safety Stakeholder Guidance

The System-Wide Safety project at NASA is developing the concept and a subset of supporting technologies for evolving safety management from a post-accident iterative improvement on safety performed by large commercial operators only to predictive and increasingly autonomous safety functions that are performed during operations across vehicles, airports, and services. The system of interest is the In-time Aviation Safety Management System (IASMS), recommended by the National Academies for NASA to develop the concept in coordination with the broad and diverse community of stakeholders in aviation safety. Because the system context is the airspace and aviation industry, it is important to create and maintain traceability from the research work and system architecture elements developed at NASA to community-created roadmaps and aviation agency guidance.

MBSE↗

Development of a Safety Hazards Risk Assessment Tool for Uncrewed Aircraft System Traffic Management during Preflight Planning

Tremendous growth in the uncrewed and remotely piloted vehicle market is expected in low-altitude, uncontrolled airspace, resulting in potential decreases in safety without systems that support monitoring, assessing, and mitigating risk. At NASA, the System-Wide Safety (SWS) project has been developing a suite of data-driven tools to predict hazards so that the potential risks that these hazards pose can be mitigated. Services to predict various hazards have been developed, including battery capacity, proximity to static obstacles, population risks, global positioning system signal strength, radio frequency spectrum interference risk, and vertiport congestion. These services can monitor hazards along a flight path and if any risks posed by these hazards exceed a threshold, the uncrewed aircraft system (UAS) fleet manager can be alerted to mitigate the risk by modifying the flight path, changing the scheduled departure or arrival times, and/or diverting the vehicle to an alternate vertiport. These services were originally developed to monitor and assess risks during flight, but they have been adapted to assess hazard risks prior to departure so that a fleet manager can evaluate the potential risks for a fleet of UAS along their planned flight paths. These services have been integrated into a prototype tool called the Supplemental Data Service Provider-Consolidated Dashboard (SDSP-CD), developed at NASA Ames Research Center. The tool consists of a dashboard which provides a comprehensive overview for a number of risks and a map display that shows the details of the hazards along each flight’s path. Based on the findings from three previous studies, the SDSP-CD has been updated with new design elements and functions. In this paper, we describe lessons learned from the previous studies, changes made to the interface, and the feedback received during a follow-up usability study. Overall, participants reported that there is a substantial benefit of having a fleet manager use a consolidated dashboard to assess hazards for the vehicles in their fleet and to provide situational awareness to potential risks so that they can be mitigated prior to flight. Once the SDSP-CD matures, it will need to be integrated into flight and mission planning tools. Some initial thoughts on how this integration should be accomplished are shared in this paper. Finally, the functional differences between preflight vs. in-flight risk assessment and the differences in fleet manager vs. UAS pilot roles that may require different information and user interactions are discussed.

preflight↗

An In-time Aviation Safety Management System Concept of Operations and Modernization of the National Airspace System​

The National Airspace System (NAS) is growing in complexity of aircraft, missions, and operations. In response, many organizations have published papers and concepts of operations (ConOps) for new and enhanced safety systems. The National Academies’ vision for an In-time Aviation Safety Management System (IASMS) is integral to Federal Aviation Administration (FAA) modernization efforts. The National Aeronautics and Space Administration (NASA) System-Wide Safety (SWS) project is conducting safety research, exploring solutions, and defining the safety needs of future missions, such as Advanced Air Mobility (AAM) and autonomous aircraft operating in a more connected, flexible, and dynamic airspace. IASMS enables and provides a path for bringing FAA’s operational vision to fruition through increasingly automated safety systems that integrate services, functions, and capabilities (SFCs). These SFCs provide the necessary responsiveness to monitor, assess, and mitigate known hazards and emergent risks. This paper describes how safety in today’s air transportation system will need to evolve, identifies key points regarding in-time safety, and explores the criticality of IASMS in the future NAS.

Airspace↗

Safety Demonstrator Series for an In-Time Aviation Safety Management System

NASA's Advanced Air Mobility Integration Office has coordinated a meeting with the National Research Council Canada (NRC) to have an interchange of technical area activities to evaluate merit for international partnership. Both NASA and NRC will provide a brief overview of their Advanced Air Mobility activities. Additional aeronautics projects will have an opportunity to present a few slides on current activities and plans. Topics include wildfire, vehicle automation technologies and detect and avoid, and national campaign flight initiatives. NASA's System-Wide Safety (SWS) Project will provide a high-level overview of the the safety demonstrator series. The project has scheduled operational demonstrations of an in-time aviation safety management system across a series of disaster-oriented operations. First up is a wildland fire demonstration scheduled for 2025. Opportunities for synergy will be discussed.

system-wide safety↗

SWS TechTalk: System Modeling in Support of IASMS Definition

Topic: System modeling in support of IASMS definition 1. What is system modeling? 2. What are the building blocks necessary for a formal model of the IASMS concept of operations, or “conops”, and “architectures”? 3. Scenario modeling to support safety demonstrator planning and technology integration The System Wide Safety Tech Talks will offer a great opportunity to keep up on each other’s work and accomplishments, as well as an opportunity to find areas of potential collaboration. The topics of these technical talks will cover any papers, presentations, special trips, or meetings that are a part of SWS.

IASMS↗

Assessment of Some IASMS-relevant Data Sources for Aviation Safety

An In-time Aviation Safety Management System (IASMS) [1,2] is a set of services, functions, and capabilities (SFCs) necessary for monitoring known hazards and emergent risks, assessing safety data for anomalies, precursors, and trends, mitigating hazards that reach safety thresholds, and assuring efficacy of controls in mitigating hazards. An IASMS will continually monitor the NAS to collect data on the status of aircraft, air traffic management systems, weather, and airports. Within the NASA Aeronautics Research Mission Directorate (ARMD) System-Wide Safety (SWS) project’s technical challenge called In-time Aviation Safety Management Systems (IASMS) for Commercial Aviation Operations, which we often refer to as Technical Challenge 6 (TC-6), we have performed an assessment of several aviation data sources we have found that are relevant to assessing the safety of the National Airspace System (NAS) in the context of an IASMS. This assessment includes understanding the nature of the data themselves and using some data analytics tools on these data to show how they can be used to identify potential safety issues. We also describe how the data and analytics are part of a system that can allow for other data and analytics to be performed and for the results to be visualized for use by appropriate operators to identify potential safety issues and develop mitigations. This report is a step toward the ultimate goal of TC-6, which is to develop a prototype IASMS system that demonstrates the potential of an IASMS and inspire operators to build analogous systems to make the best possible use of the significant investments that they make in collecting, storing, and managingdata related to their operations.

aviation safety↗

Projected Impact of Compositional Verification on Current and Future Aviation Safety Risk

The projected impact of compositional verification research conducted by the National Aeronautic and Space Administration System-Wide Safety and Assurance Technologies on aviation safety risk was assessed. Software and compositional verification was described. Traditional verification techniques have two major problems: testing at the prototype stage where error discovery can be quite costly and the inability to test for all potential interactions leaving some errors undetected until used by the end user. Increasingly complex and nondeterministic aviation systems are becoming too large for these tools to check and verify. Compositional verification is a "divide and conquer" solution to addressing increasingly larger and more complex systems. A review of compositional verification research being conducted by academia, industry, and Government agencies is provided. Forty-four aviation safety risks in the Biennial NextGen Safety Issues Survey were identified that could be impacted by compositional verification and grouped into five categories: automation design; system complexity; software, flight control, or equipment failure or malfunction; new technology or operations; and verification and validation. One capability, 1 research action, 5 operational improvements, and 13 enablers within the Federal Aviation Administration Joint Planning and Development Office Integrated Work Plan that could be addressed by compositional verification were identified.

Reveley, Mary S.↗

In-time Safety Management Capabilities for Wildland Fire Management Aircraft Operations - A Gap Assessment

This study assesses the in-time safety management services, functions, and capabilities (SFCs)being investigated by NASA’s System Wide Safety (SWS) project to determine applicability to the project’s planned safety demonstrator (SD-1) for wildland fire management. The purpose of this work is to evaluate how effectively existing SFCs address the different hazards presented by a safety demonstrator operating in a wildland fire management scenario. This will help inform decision makers which SFCs would provide the most cost-effective solutions to fill the hazard gaps for further research. Hazards for the safety demonstrator wildland fire management scenario were collated, and the SFCs were evaluated for each hazard based on how applicable and effective the unmodified SFCs are at addressing the hazard. The SFCs are also evaluated for the gap type that needs to be addressed to improve the SFC effectiveness for the given hazard. The key finding of this assessment is that all the existing SFCs require at least some research and development to adapt to the safety demonstrator. No single SFC fully addresses any of the safety demonstrator operation hazards. The result of this study will be used to determine the performance of current SFCs and suggest strategies to adapt existing SFCs or add new SFCs.

Patricia Revolinsky↗

The Aviation System Monitoring and Modeling (ASMM) Project: A Documentation of its History and Accomplishments: 1999-2005

The Aviation System Monitoring and Modeling (ASMM) Project was one of the projects within NASA s Aviation Safety Program from 1999 through 2005. The objective of the ASMM Project was to develop the technologies to enable the aviation industry to undertake a proactive approach to the management of its system-wide safety risks. The ASMM Project entailed four interdependent elements: (1) Data Analysis Tools Development - develop tools to convert numerical and textual data into information; (2) Intramural Monitoring - test and evaluate the data analysis tools in operational environments; (3) Extramural Monitoring - gain insight into the aviation system performance by surveying its front-line operators; and (4) Modeling and Simulations - provide reliable predictions of the system-wide hazards, their causal factors, and their operational risks that may result from the introduction of new technologies, new procedures, or new operational concepts. This report is a documentation of the history of this highly successful project and of its many accomplishments and contributions to improved safety of the aviation system.

Statler, Irving C.↗

STEReO 1.0 Overview

STEReO brings together several technologies in Unmanned Aircraft Systems (UAS) Traffic Management (UTM), Autonomy, Communications, Human Factors, and Domain Expertise & Tools, aimed at providing scalability and flexibility, as well as operational resiliency to dynamic changes during a disaster event. Some of the concepts STEReO explores are: collaborative tools to ingest remote sensing information and distribute a common mission operating picture, apply ad-hoc communication networks to facilitate timely information sharing and communication of changes, vehicle-to-vehicle and onboard autonomy technologies ensure the safety and resiliency of operations, and apply NASA’s UAS traffic management system (UTM) as a public safety UAS Service Supplier (USS) to access and coordinate use of the airspace by both manned and unmanned operations. The potential benefits of STEReO include: standardized, cross-platform communication means increased interoperability and ease of cooperation/collaboration, increased situation awareness and common operating picture allow for earlier detection and decision making, and scalable to size and complexity of environment, operations, and mission objectives. This presentation gives an informational overview of the STEReO project to attendees of the System Wide Safety (SWS) Wildland Firefighting Operations Workshop.

emergency response operations↗

Formal Foundations for Hierarchical Safety Cases

Safety cases are increasingly being required in many safety-critical domains to assure, using structured argumentation and evidence, that a system is acceptably safe. However, comprehensive system-wide safety arguments present appreciable challenges to develop, understand, evaluate, and manage, partly due to the volume of information that they aggregate, such as the results of hazard analysis, requirements analysis, testing, formal verification, and other engineering activities. Previously, we have proposed hierarchical safety cases, hicases, to aid the comprehension of safety case argument structures. In this paper, we build on a formal notion of safety case to formalise the use of hierarchy as a structuring technique, and show that hicases satisfy several desirable properties. Our aim is to provide a formal, theoretical foundation for safety cases. In particular, we believe that tools for high assurance systems should be granted similar assurance to the systems to which they are applied. To this end, we formally specify and prove the correctness of key operations for constructing and managing hicases, which gives the specification for implementing hicases in AdvoCATE, our toolset for safety case automation. We motivate and explain the theory with the help of a simple running example, extracted from a real safety case and developed using AdvoCATE.

Hierarchy↗

Assurance of Autonomy

This presentation gives an overview of the research directions taken by the System Wide Safety project (NASA ARMD) with respect to the assurance of autonomy to support certification of aviation systems for emerging markets. The talk gives an overview of the project and a quick overview of some of the research tools being developed at NASA Ames.

Brat, Guillaume↗

Supporting Hazard Analysis for Wildfire Response Using fmdtools and MIKA

The System Wide Safety (SWS) Safety Demonstrator (SD) Series drives development of an increasingly capable In-Time Aviation Safety Management System (IASMS) focusing on humanitarian applications, starting with wildfire response (SD-1). The goals of this report are to (1) provide an early hazard analysis and mitigation evaluation of wildfire response to support these efforts and (2) provide a demonstration of capabilities of the Fault Model Design Tools (fmdtools) and Manager for Intelligent Knowledge Access (MIKA) tools. fmdtools provides a modeling, simulation, and resiliency analysis framework in which a wildfire response model, the System Modeling and Analysis of Resiliency in Scalable Traffic Management for Emergency Response Operations (SMARt-STEReO), is built. MIKA is an intelligent knowledge manager with several capabilities, including assisting in hazard analysis by extracting and analyzing hazards from historical incident reports. The following topics are covered in the report: Understanding Wildfire Hazard Dynamics. We provide a description and simulated examples of how hazards occur in the SMARt-STEReO model of wildfire response and their effect on its outcome. This provides a common mental model and focuses the analysis presented in the remainder of the report. Wildfire Hazard Identification. MIKA identifies wildfire hazards from three relevant datasets: the ICS-209-PLUS, SAFECOM, and SAFENET. Hazards are manually organized into a taxonomy and MIKA analyzes each hazard’s effects, likelihood, severity, and risk. Evaluating Mitigation Strategies. The SMARt-STEReO wildfire response model built in fmdtools evaluates a subset of identified hazards. Specifically, we simulate the effect of communications faults and equipment faults on operator safety, the effect of changing winds and flammability, and a scenario with multiple ignition points and heavy smoke. Tool Limitations and Usage Considerations. We provide a discussion of appropriate tool use cases as well as limitations and considerations for usage. The tool findings are used to synthesize recommendations for wildfire response operations, which can be captured as part of an IASMS. Key recommendations are as follows: Hazards are identified from a broad spectrum of sources including aircraft subsystems, operational sources, and ground crew operations. Highest risk operational environment hazards identified are Evacuations. The highest risk manned aerial operations hazard categorized is Jumper Operations Mishap. Ground crew hazards that are highest risk are Burns, Cargo Operations Overhead, Dehydration, Entrapment, Falling Objects, Heart Attacks, Heat Exhaustion, Inadequate Training or Certification, Vehicle Breakdown, and Vehicle Collision. Modelled containment failures arise from a mismatch between the difficulty of the firefighting scenario and the capacity (e.g., speed, effectiveness, awareness) of the response. In firefighting scenarios where containment is possible (e.g., because the fire does not spread too quickly), these mismatches can occur because of a change in environmental conditions (e.g., wind, flammability, etc) or because of planning, equipment, or communications faults. Improvements to communications increase the capacity of the firefighting response by reducing the time needed to respond to the fire. While surveillance does not increase this capacity by itself, it increases operator safety by increasing state awareness, enabling firefighters to evade approaching fires. Increasing both has a synergistic effect. In general, these performance and resilience increases generalize over fault scenarios as well as unforeseen changes to circumstances (i.e., wind, aridity, etc.). However, these improvements need to be designed so as not to make the system prone to persistent large-scale communications outages, which can reduce performance.

Hazard analysis↗

A Concept of Operations (ConOps) of an In-time Aviation Safety Management System (IASMS) for Advanced Air Mobility (AAM)

The growth of new emerging operations involving Advanced Air Mobility (AAM) necessitates developing a perspective for an In-time Aviation Safety Management System (IASMS). This perspective advances from the National Academies report on IASMS and its recommendation for developing a Concept of Operations (ConOps) for IASMS. A ConOps has been developed for In-time System-Wide Safety Assurance (ISSA) from which the IASMS ConOps pivots to provide a robust scope commensurate with the broad vision defined by the National Academies. The IASMS ConOps focuses on emerging operations and spans innovations in Unmanned Aircraft System (UAS) and an increasingly complex ecosystem comprised of a widening mix of vehicles and technologies, Urban Air Mobility (UAM) with industry-federated services, traditional operations, as well as new supersonic aircraft and space launch systems.The challenge for the IASMS ConOps is to be broad to encompass innovations in the coming years and decades while agile to ensure levels of safety compatible with operational and certification requirements of the National Airspace System (NAS). The IASMS ConOps interweaves increasing complexity of operational safety capabilities and unlocking UAS Maturity Levels (UMLs). The relationships between increased complexity of automation and automated systems, fewer operators who are not as traditionally higher skilled, more complex operational environments, and aviation operations management with mixed aircraft and equipage pose a multi-dimensional space for IASMS capabilities essential for safety assurance and risk management. Instantiating IASMS capabilities and how they would be integral to AAM operations and increasing maturity of UAM could be accomplished through a series of Safety Demonstrators. These Safety Demonstrators could provide increased understanding and insight into use of controls for risk mitigation, means of compliance for certification, and operational experience with safety services such as in relation to contingency management. The IASMS capabilities can be viewed as initially residing with the vehicle, airspace, and Supplemental Data Service Provider (SDSP). For example, vehicle capabilities include communications including the command and control link, Remote Identification (ID), conflict advisory/alerting, and UAS system monitoring. These capabilities monitor and assess data such as battery health, aircraft state, and human performance. Complexity of ISAMS capabilities depends on a number of factors. These factors are intendedonly as a notional categorization with the purpose being to reflect the complexity of the AAM ecosystem that would drive up the complexity of ISSA capabilities including systems, sensors, models, standards, and controls. Factors could include the Vehicle Flight Management, Environment, Airspace, and Contingency Management. Each of these factors can be comprised of multiple sub-factors that contribute to increasing complexity. For example, Airspace at a lower level of complexity could be dedicated to UTM operations that are unmonitored, and at a higher level of complexity could involve mixed UTM and ATM operations. The IASMS concept includes safety services that provide data and information to different participants in AAM. The roles and responsibilities of participants can be defined using the Responsible-Accountable-Consulted-Informed (RACI) analysis. For example, for the safety service involving the Remote ID, the Operator would be accountable for providing the data, the Vehicle would be responsible for transmitting it, and the USS, SDSP, Vertiports, FIMS (FAA), and Public Entities such as safety services would be informed by receiving the data. The IASMS ConOps identifies the capabilities needed for risk mitigation and safety assurance in the increasingly complex national airspace. The ConOps serves as a pathway for engaging with industry to gain operational experience including through the Safety Demonstrator series, the RACI analysis, and operational complexity factors. The ConOps serves to integrate these different perspectives to build a cohesive and cogent approach to an AAM safety management system.

In-Time Aviation Safety Management System↗

A Criteria Standard for Conflict Resolution: A Vision for Guaranteeing the Safety of Self-Separation in NextGen

Distributed approaches for conflict resolution rely on analyzing the behavior of each aircraft to ensure that system-wide safety properties are maintained. This paper presents the criteria method, which increases the quality and efficiency of a safety assurance analysis for distributed air traffic concepts. The criteria standard is shown to provide two key safety properties: safe separation when only one aircraft maneuvers and safe separation when both aircraft maneuver at the same time. This approach is complemented with strong guarantees of correct operation through formal verification. To show that an algorithm is correct, i.e., that it always meets its specified safety property, one must only show that the algorithm satisfies the criteria. Once this is done, then the algorithm inherits the safety properties of the criteria. An important consequence of this approach is that there is no requirement that both aircraft execute the same conflict resolution algorithm. Therefore, the criteria approach allows different avionics manufacturers or even different airlines to use different algorithms, each optimized according to their own proprietary concerns.

Munoz, Cesar↗

RF Environment Data Analysis for UAS Operations

As the usage of radio frequency spectrum and uncrewed aircraft systems continue to grow, the radio frequency environment and its implications to flight safety should be understood. This is important to ensure control and command links as well as data collection links maintain strong communications during flight. NASA System-Wide Safety (SWS) is currently developing standards of flight safety but lacks methods for establishing confidence in the availability of radio frequency space to make a go/no-go decision for drone flights. This study examines information about the radio modules used by SWS and how they interact with the RF environment though analysis of historical spectrum data. This review studies the potential effectiveness of observing the power spread and occupancy methods as they apply to the flight system radios. It has been determined that viewing the frequency and time when the environment is greater than a threshold which indicates potential interference levels may give insight into the patterns of spectrum usage.

Radio Frequency↗