Search NASA⌕ Search

SEARCH · Search NASA

Results for “probability risk analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Prioritizing Uncertainties in Hydrogen Contribution to Risk in Post-Crash Outcomes for Rail

This report presents analysis from Sandia National Laboratories predicting contributions to risk associated with the use of hydrogen technology for rail. Event sequence diagrams are used to describe possible accident scenarios and progressions. Initiating event frequencies and branch event probabilities for each scenario are quantified with uncertainty using distributions fit to Federal Railroad Administration and U.S. Department of Transportation Pipeline and Hazardous Materials Safety Administration data on applicable accidents from 2000 to 2020. Uncertainty is propagated through the event sequence diagram to estimate the frequency and conditional probability of accident end states. The analysis identifies four scenarios with significant contributions to risk from hydrogen that are predicted to occur relatively frequently, which may inform priorities for reducing uncertainty. These scenarios are 1) overpressure events resulting from collisions with hydrogen release due to mechanical damage and delayed ignition, 2) jet fire events resulting from collisions with hydrogen release due to mechanical damage and immediate ignition, 3) jet fires resulting from fire or explosion initiating events involving the hydrogen tank and correct operation of the thermally-activated pressure relief device (TPRD) subsequent to the thermal insult, and 4) pressure burst resulting from fire or explosion initiating events involving the hydrogen tank and failure of the TPRD. Delayed and immediate hydrogen ignition probabilities are identified as being highly uncertain and potential candidates for reducing conservatism in the predicted frequencies for these two scenarios.

08 HYDROGEN↗

Wallops Ship Surveillance System

Approved as a Wallops control center backup system, the Wallops Ship Surveillance Software is a day-of-launch risk analysis tool for spaceport activities. The system calculates impact probabilities and displays ship locations relative to boundary lines. It enables rapid analysis of possible flight paths to preclude the need to cancel launches and allow execution of launches in a timely manner. Its design is based on low-cost, large-customer- base elements including personal computers, the Windows operating system, C/C++ object-oriented software, and network interfaces. In conformance with the NASA software safety standard, the system is designed to ensure that it does not falsely report a safe-for-launch condition. To improve the current ship surveillance method, the system is designed to prevent delay of launch under a safe-for-launch condition. A single workstation is designated the controller of the official ship information and the official risk analysis. Copies of this information are shared with other networked workstations. The program design is divided into five subsystems areas: 1. Communication Link -- threads that control the networking of workstations; 2. Contact List -- a thread that controls a list of protected item (ocean vessel) information; 3. Hazard List -- threads that control a list of hazardous item (debris) information and associated risk calculation information; 4. Display -- threads that control operator inputs and screen display outputs; and 5. Archive -- a thread that controls archive file read and write access. Currently, most of the hazard list thread and parts of other threads are being reused as part of a new ship surveillance system, under the SureTrak project.

Smith, Donna C.↗

Orbital debris risk analysis and survivability enhancement for Freedom Station manned modules

This paper briefly reviews how 'probability of penetration' analyses are currently performed at NASA, and discusses extension of this procedure to a 'probability of loss' analysis through identifying penetration hazards and failure modes. It goes on to discuss alternatives for increasing crew safety through redesign and/or augmentation of interior manned module systems, and describes an elementary analysis maximizing crew safety considering one identified penetration-induced failure mode (depressurization) and one interior design factor (number of hatches open).

Williamsen, Joel E.↗

A Prognostic Launch Vehicle Probability of Failure Assessment Methodology for Conceptual Systems Predicated on Human Causal Factors

Create an improved method to calculate reliability of a conceptual launch vehicle system prior to fabrication by using historic data of actual root causes of failures. While failures have unique "proximate causes", there are typically a finite amount of common "root causes". Heretofore launch vehicle reliability evaluation typically hardware-centric statistical analyses, while most root causes of failures are been shown to be human-centric. A method based on human-centric root causes can be used to quantify reliability assessments and focus proposed actions to mitigate problems. Existing methods have been optimistic in their projections of launch vehicle reliability compared to actuals. Hypothesis: reliability of a conceptual launch vehicle can be more accurately evaluated based on a rational, probabilistic approach using past failure assessment teams' findings predicated on human-centric causes."Human Reliability Analysis Methods Selection Guidance for NASA"Chandler F.T., et al., NASA HQ/OSMA study group, July 2006. Outside HRA experts from academia, other federal labs, and the private sector. 50 system reliability methods considered, fourteen selected for further study, four finally selected as best suited for human spaceflight. Probabilistic Risk Analysis (PRA) + Human Reliability Analysis (HRA) enabled incorporating effects and probabilities of human errors. While four down-selected methods deemed appropriate for failure assessment, it did not appear that these methods could be concisely applied to perform major system-wide assessment of probability of failure of a conceptual design without becoming unwieldy."Engineering a Safer World", Detailed, comprehensive study external to NASA Leveson N. G., MIT, 2011.Systems-Theoretic Accident Model and Processes (STAMP). All-encompassing accident model based on systems theory analyzed accidents after they occurred and created approaches to prevent occurrence in developing systems not focused on failure prevention per se, but rather reducing hazards by influencing human behavior through use of constraints, hierarchical control structures, and process models to improve system safetySystem Theoretic Process Analysis (STPA) addresses predictive part of problem (a "hazard analysis"). Includes all causal factors identified in STAMP: "...design errors, software flaws, component interaction accidents, cognitively complex human decision-making errors, and social organizational and management factors contributing to accidents" can guide design process rather than require it to exist before-hand did not appear capable of concise application for system-wide assessment of probability of failure of a conceptual design without becoming unwieldy.

Williams, Craig H.↗

Probabilistic structural analysis of aerospace components using NESSUS

Probabilistic structural analysis of a Space Shuttle main engine turbopump blade is conducted using the computer code NESSUS (numerical evaluation of stochastic structures under stress). The goal of the analysis is to derive probabilistic characteristics of blade response given probabilistic descriptions of uncertainties in blade geometry, material properties, and temperature and pressure distributions. Probability densities are derived for critical blade responses. Risk assessment and failure life analysis is conducted assuming different failure models.

Shiao, Michael C.↗

Probabilistic structural analysis of aerospace components using NESSUS

Probabilistic structural analysis of a Space Shuttle main engine turbopump blade is conducted using the computer code NESSUS (numerical evaluation of stochastic structures under stress). The goal of the analysis is to derive probabilistic characteristics of blade response given probabilistic descriptions of uncertainties in blade geometry, material properties, and temperature and pressure distributions. Probability densities are derived for critical blade responses. Risk assessment and failure life analysis is conducted assuming different failure models.

Shiao, Michael C.↗

Carbon/graphite fiber risk analysis and assessment study: Assessment of risk to the Lockheed Model L-1011 commercial transport aircraft

The risk associated with the accidental release of carbon/graphite fibers (CF) from fires on commercial transport aircraft incorporating composite materials was assessed. Data are developed to evaluate the potential for CF damage to electrical and electronic equipment, assess the cost risk, and evaluate the hazard to continued operation. The subjects covered include identification of susceptible equipments, determination of infiltration transfer functions, analysis of airport operations, calculation of probabilities of equipment failures, assessment of the cost risk, and evaluation of the hazard to continued operation. The results show the risks associated with CF contamination are negligible through 1993.

Daniledes, J.↗

Correlation Between Weather Alerts and Grid Component Failures for Grid Alert

Weather events cause most grid failures. Often, we even get notifications on our phones to take cover or be prepared for an imminent event. If electric grid utilities had a similar warning that also included probable scenarios and the equipment involved, they could prepare and minimize the effects. Recent research at Idaho National Laboratory into electric grid risk analysis methods resulted in a tool that allows for the development of the most likely scenarios given failure probabilities of grid components. INL has a project with the U.S. Department of Energy’s Cybersecurity, Energy Security, and Emergency Response (CESER) program to develop a Grid Alert application that receives messages from the existing emergency alert system, filters and determines components possibly affected by the emergency event, calculates probable scenarios uses MASTERRI and then notifies the utility if there is significant risk. Historical failure data of elements that comprise the U.S. electric grid have been compiled by utilities and organizations such as the international regulatory body North American Electric Reliability Corporation (NERC). Nominal failure rates are obtained from this data. To make this tool possible, estimated failure rates are needed for different component types given the alert type, severity, and location. Historic weather-related grid element failures are correlated with historic weather events from Integrated Public Alert & Warning System (IPAWS). These correlated events and failures are used along with Bayesian updates from the historical norms to provide a modified failure rate for grid elements in the alert areas and calculate probable scenarios. This discusses the Grid Alert project plan but focuses on the data gathered and process used in determining failure rates for possible grid failure scenarios.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Tile-Failure Analysis

Tile Failure Probability Model (TFPM) program originally developed to quantitatively assess risk of tile loss of thermal-protection tile from Space Shuttle Orbiter. TFPM is fairly specific to orbiter, but basic technique is applied in other structural design situations where anticipated loads and material strength have significantly variable probability distributions.

Ohern, E. A.↗

Reliability Analysis in the Presence of Aleatory Uncertainty

This paper proposes a method for modeling a system’s response using data. In contrast to approaches that identify a limit state function, we focus on the case in which not all uncertain parameters affecting the response are observable and the measured response is corrupted by noise. To this end, the system response is not characterized by a limit state function but instead by a Random Predictor Model (RPM) having a nonparametric structure. Consequently, the resulting failure probability is not a scalar but a random variable. This variable accounts for the aleatory contributions of the model-form uncertainty and the measurement noise into the response. Furthermore, we propose a framework that enables trading off the predicted range of failure probabilities resulting from such an analysis with a measure of risk. In this context, risk is the percentage of all predicted outcomes the analyst is willing to ignore. The reliability analysis of an aeroelastic structure subject to flutter is used to illustrate the ideas proposed.

Crespo, L. G.↗

The Challenger disaster was caused by an Apollo decision

NASA’s view of risk changed between early Apollo and the Space Shuttle. Risk was a known serious problem at the beginning of Apollo and the risk estimates were disturbingly high. To avoid public concern, risk analysis was discontinued. Risk analysis was avoided in Shuttle, leading to an unnecessarily risky design. The immediate cause of the Challenger tragedy was the mistaken decision to launch in cold weather. The fundamental cause was the high risk of the Shuttle design. Before Challenger, management thought and testified that the probability of an accident was 1 in 100,000. After Challenger, Probabilistic Risk Analysis (PRA) found a roughly 1 in 100 chance of a Shuttle failure. The recent Orion design uses the safer Apollo approach, with a hardened capsule, launch abort escape, and the crew placed above the rocket tanks and engines. During Apollo it was estimated that, “assuming all elements from propulsion to rendezvous and life support were done as well or better than ever before, that 30 astronauts would be lost before 3 were returned safely to the Earth.” The chance of astronaut survival was only 10%. After the Apollo 1 tragedy, the awareness of risk led to an intense focus on achieving safety. “The only possible explanation for the astonishing success – no losses in space and on time – was that every participant at every level in every area far exceeded the norm of human capabilities.” During Apollo, a NASA PRA found that the chance of success was “less than 5 percent.” The NASA Administrator felt that “the numbers could do irreparable harm,” and discontinued numerical risk assessment.

Harry W Jones↗

The Challenger tragedy was caused by an Apollo mistake, terminating risk analysis

NASA’s view of risk changed between early Apollo and the Space Shuttle. Risk was a known serious problem at the beginning of Apollo and the risk estimates were disturbingly high. To avoid public concern, risk analysis was discontinued. Risk analysis was avoided in Shuttle, leading to an unnecessarily risky design. The immediate cause of the Challenger tragedy was the mistaken decision to launch in cold weather. The fundamental cause was the high risk of the Shuttle design. Before Challenger, management thought and testified that the probability of an accident was 1 in 100,000. After Challenger, Probabilistic Risk Analysis (PRA) found a roughly 1 in 100 chance of a Shuttle failure. The recent Orion design uses the safer Apollo approach, with a hardened capsule, launch abort escape, and the crew placed above the rocket tanks and engines. During Apollo it was estimated that, “assuming all elements from propulsion to rendezvous and life support were done as well or better than ever before, that 30 astronauts would be lost before 3 were returned safely to the Earth.” The chance of astronaut survival was only 10%. After the Apollo 1 tragedy, the awareness of risk led to an intense focus on achieving safety. “The only possible explanation for the astonishing success – no losses in space and on time – was that every participant at every level in every area far exceeded the norm of human capabilities.” During Apollo, a NASA PRA found that the chance of success was “less than 5 percent.” The NASA Administrator felt that “the numbers could do irreparable harm,” and discontinued numerical risk assessment. This led to decreasing understanding of risk. The head of Apollo reliability and safety decided, “Statistics don’t count for anything,” and that risk is reduced by “attention taken in design.” The great and initially unexpected success of Apollo appeared to validate the neglect of PRA. Continuing to neglect the mathematical estimation of risk led Shuttle into a high risk design that produced tragic results. The initial design of the Shuttle emphasized increasing capability and reducing cost without analysis or even mention of risk. A retired NASA official stated, “some NASA people began to confuse desire with reality. … One result was to assess risk in terms of what was thought acceptable without regard for verifying the assessment. … Note that under such circumstances real risk management is shut out.” Not computing risk led to removing launch abort, removing crew escape, selecting less reliable Solid Rocket Boosters, placing the crew compartment next to the rocket boosters, and accepting more stressed shielding tile designs. Accepting these specific risks directly caused the shuttle disasters. The Challenger tragedy is frequently taught as a case of management failure. The focus is on the Challenger launch decision hours before, which is a dramatic example of bad management. However, the true cause of the Challenger disaster occurred decades earlier in the Apollo era. When the easily predictable failures occurred, failure investigations focused on how they might have been avoided. The Shuttle was cancelled after the space station was completed because of its high risk. The ultimate cause of the Shuttle tragedies was the choice by the Apollo-era NASA administrator to avoid a negative public reaction to realistic risk analysis.

Harry W. Jones↗

Development of a New Data Tool for Computing Launch and Landing Availability with Respect to Surface Weather

The Marshall Space Flight Center Natural Environments Branch has a long history of expertise in the modeling and computation of statistical launch availabilities with respect to weather conditions. Their existing data analysis product, the Atmospheric Parametric Risk Assessment (APRA) tool, computes launch availability given an input set of vehicle hardware and/or operational weather constraints by calculating the climatological probability of exceeding the specified constraint limits, APRA has been used extensively to provide the Space Shuttle program the ability to estimate impacts that various proposed design modifications would have to overall launch availability. The model accounts for both seasonal and diurnal variability at a single geographic location and provides output probabilities for a single arbitrary launch attempt. Recently, the Shuttle program has shown interest in having additional capabilities added to the APRA model, including analysis of humidity parameters, inclusion of landing site weather to produce landing availability, and concurrent analysis of multiple sites, to assist in operational landing site selection. In addition, the Constellation program has also expressed interest in the APRA tool, and has requested several additional capabilities to address some Constellation-specific issues, both in the specification and verification of design requirements and in the development of operations concepts. The combined scope of the requested capability enhancements suggests an evolution of the model beyond a simple revision process. Development has begun for a new data analysis tool that will satisfy the requests of both programs. This new tool, Probabilities of Atmospheric Conditions and Environmental Risk (PACER), will provide greater flexibility and significantly enhanced functionality compared to the currently existing tool.

Burns, K. Lee↗

Operational Implementation of a Pc Uncertainty Construct for Conjunction Assessment Risk Analysis

Earlier this year the NASA Conjunction Assessment and Risk Analysis (CARA) project presented the theoretical and algorithmic aspects of a method to include the uncertainties in the calculation inputs when computing the probability of collision (Pc) between two space objects, principally uncertainties in the covariances and the hard-body radius. The output of this calculation approach is to produce rather than a single Pc value an entire probability density function that will represent the range of possible Pc values given the uncertainties in the inputs and bring CA risk analysis methodologies more in line with modern risk management theory. The present study provides results from the exercise of this method against an extended dataset of satellite conjunctions in order to determine the effect of its use on the evaluation of conjunction assessment (CA) event risk posture. The effects are found to be considerable: a good number of events are downgraded from or upgraded to a serious risk designation on the basis of consideration of the Pc uncertainty. The findings counsel the integration of the developed methods into NASA CA operations.

assessment↗

Approaches to Evaluating Probability of Collision Uncertainty

While the two-dimensional probability of collision (Pc) calculation has served as the main input to conjunction analysis risk assessment for over a decade, it has done this mostly as a point estimate, with relatively little effort made to produce confidence intervals on the Pc value based on the uncertainties in the inputs. The present effort seeks to try to carry these uncertainties through the calculation in order to generate a probability density of Pc results rather than a single average value. Methods for assessing uncertainty in the primary and secondary objects' physical sizes and state estimate covariances, as well as a resampling approach to reveal the natural variability in the calculation, are presented; and an initial proposal for operationally-useful display and interpretation of these data for a particular conjunction is given.

PROBABILITY↗

Modeling the Risk of Fire/Explosion Due to Oxidizer/Fuel Leaks in the Ares I Interstage

A significant flight hazard associated with liquid propellants, such as those used in the upper stage of NASA's new Ares I launch vehicle, is the possibility of leakage of hazardous fluids resulting in a catastrophic fire/explosion. The enclosed and vented interstage of the Ares I contains numerous oxidizer and fuel supply lines as well as ignition sources. The potential for fire/explosion due to leaks during ascent depends on the relative concentrations of hazardous and inert fluids within the interstage along with other variables such as pressure, temperature, leak rates, and fluid outgasing rates. This analysis improves on previous NASA Probabilistic Risk Assessment (PRA) estimates of the probability of deflagration, in which many of the variables pertinent to the problem were not explicitly modeled as a function of time. This paper presents the modeling methodology developed to analyze these risks.

Ring, Robert W.↗

Space Radiation Cancer, Circulatory Disease and CNS Risks for Near Earth Asteroid and Mars Missions: Uncertainty Estimates for Never-Smokers

The uncertainties in estimating the health risks from galactic cosmic rays (GCR) and solar particle events (SPE) are a major limitation to the length of space missions and the evaluation of potential risk mitigation approaches. NASA limits astronaut exposures to a 3% risk of exposure induced cancer death (REID), and protects against uncertainties in risks projections using an assessment of 95% confidence intervals after propagating the error from all model factors (environment and organ exposure, risk coefficients, dose-rate modifiers, and quality factors). Because there are potentially significant late mortality risks from diseases of the circulatory system and central nervous system (CNS) which are less well defined than cancer risks, the cancer REID limit is not necessarily conservative. In this report, we discuss estimates of lifetime risks from space radiation and new estimates of model uncertainties are described. The key updates to the NASA risk projection model are: 1) Revised values for low LET risk coefficients for tissue specific cancer incidence, with incidence rates transported to an average U.S. population to estimate the probability of Risk of Exposure Induced Cancer (REIC) and REID. 2) An analysis of smoking attributable cancer risks for never-smokers that shows significantly reduced lung cancer risk as well as overall cancer risks from radiation compared to risk estimated for the average U.S. population. 3) Derivation of track structure based quality functions depends on particle fluence, charge number, Z and kinetic energy, E. 4) The assignment of a smaller maximum in quality function for leukemia than for solid cancers. 5) The use of the ICRP tissue weights is shown to over-estimate cancer risks from SPEs by a factor of 2 or more. Summing cancer risks for each tissue is recommended as a more accurate approach to estimate SPE cancer risks. 6) Additional considerations on circulatory and CNS disease risks. Our analysis shows that an individual s history of smoking exposure has a larger impact on GCR risk estimates than amounts of radiation shielding or age at exposure (amongst adults). Risks for never-smokers compared to the average U.S. population are estimated to be reduced between 30% and 60% dependent on model assumptions. Lung cancer is the major contributor to the reduction for never-smokers, with additional contributions from circulatory diseases and cancers of the stomach, liver, bladder, oral cavity and esophagus, and leukemia. The relative contribution of CNS risks to the overall space radiation detriment is potentially increased for never-smokers such as most astronauts. Problems in estimating risks for former smokers and the influence of second-hand smoke are discussed. Compared to the LET approximation, the new track structure derived radiation quality functions lead to a reduced risk for relativistic energy particles and increased risks for intermediate energy particles. Revised estimates for the number of safe days in space at solar minimum for heavy shielding conditions are described for never-smokers and the average U.S. population. Results show that missions to near Earth asteroids (NEA) or Mars violate NASA's radiation safety standards with the current levels of uncertainties. Greater improvements in risk estimates for never-smokers are possible, and would be dependent on improved understanding of risk transfer models, and elucidating the role of space radiation on the various stages of disease formation (e.g. initiation, promotion, and progression).

Cucinotta, Francis A.↗

Reliability analysis in the Office of Safety, Environmental, and Mission Assurance (OSEMA)

The technical personnel in the SEMA office are working to provide the highest degree of value-added activities to their support of the NASA Langley Research Center mission. Management perceives that reliability analysis tools and an understanding of a comprehensive systems approach to reliability will be a foundation of this change process. Since the office is involved in a broad range of activities supporting space mission projects and operating activities (such as wind tunnels and facilities), it was not clear what reliability tools the office should be familiar with and how these tools could serve as a flexible knowledge base for organizational growth. Interviews and discussions with the office personnel (both technicians and engineers) revealed that job responsibilities ranged from incoming inspection to component or system analysis to safety and risk. It was apparent that a broad base in applied probability and reliability along with tools for practical application was required by the office. A series of ten class sessions with a duration of two hours each was organized and scheduled. Hand-out materials were developed and practical examples based on the type of work performed by the office personnel were included. Topics covered were: Reliability Systems - a broad system oriented approach to reliability; Probability Distributions - discrete and continuous distributions; Sampling and Confidence Intervals - random sampling and sampling plans; Data Analysis and Estimation - Model selection and parameter estimates; and Reliability Tools - block diagrams, fault trees, event trees, FMEA. In the future, this information will be used to review and assess existing equipment and processes from a reliability system perspective. An analysis of incoming materials sampling plans was also completed. This study looked at the issues associated with Mil Std 105 and changes for a zero defect acceptance sampling plan.

Kauffmann, Paul J.↗