Search NASA⌕ Search

SEARCH · Search NASA

Results for “probability risk analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Sensitivity Analysis of Launch Vehicle Debris Risk Model

As part of an analysis of the loss of crew risk associated with an ascent abort system for a manned launch vehicle, a model was developed to predict the impact risk of the debris resulting from an explosion of the launch vehicle on the crew module. The model consisted of a debris catalog describing the number, size and imparted velocity of each piece of debris, a method to compute the trajectories of the debris and a method to calculate the impact risk given the abort trajectory of the crew module. The model provided a point estimate of the strike probability as a function of the debris catalog, the time of abort and the delay time between the abort and destruction of the launch vehicle. A study was conducted to determine the sensitivity of the strike probability to the various model input parameters and to develop a response surface model for use in the sensitivity analysis of the overall ascent abort risk model. The results of the sensitivity analysis and the response surface model are presented in this paper.

Gee, Ken↗

Optimizing fluvial flood mitigation strategies: A multi-objective approach for cost-effective and socially-aware infrastructure feasibility analysis

Effective levee planning must balance capital cost, risk reduction, and community priorities. These objectives are rarely optimized together. This study presents a feasibility phase, simulationin-the-loop framework that couples terrain-based flood modeling with a socially aware multiobjective optimizer. Flood risk is measured as Expected Annual Exposed Population (EAEP), obtained by integrating exposure over Annual Exceedance Probability (AEP) nodes, mirroring the Hydrologic Engineering Center's Flood Damage Reduction Analysis (HEC-FDA) expected-annual formulation but with people rather than dollars. Exposure per scenario is computed by overlaying binary inundation masks with a population surface at the tract level. Distributional fairness is encoded through a Group Benefit Share (GBS) constraint that requires high-SVI tracts to receive at least a baseline share of annualized benefits. Capital cost is represented by a height-dependent unit-cost model suitable for screening. This study addresses the two-objective problem, minimize cost and expected annual exposure subject to the GBS constraint, using Non-Dominated Sorting Genetic Algorithm II (NSGA-II) and leveraging Pareto front for feasibility phase decision making. Implemented with terrain-based flood modeling, GeoFlood, for rapid scenario evaluation, the framework is demonstrated in Southeast Texas. The results reveal clear trade-offs among cost, risk, and social benefits and identify non-dominated levee height configurations that satisfy the benefit-share floor. The contributions are a scalable decision support method that operationalizes expected annual population-based risk, embeds enforceable benefit-sharing guarantees, and uses lightweight simulation to explore large design spaces before higher fidelity design stages.

Flood mitigation↗

First Stage Solid Propellant Multiply Debris Thermal Analysis

Destruction of a solid rocket stage of a launch vehicle can create a thermal radiation hazard for an aborting crew module. This hazard was assessed for the Constellation Program (Cx) crew and launch vehicle concept. For this concept, if an abort was initiated in first stage flight, the Crew Module (CM) will separate and be pulled away from the malfunctioning launch vehicle via a Launch Abort System (LAS). Having aborted the mission, the launch vehicle will likely be destroyed via a Flight Termination System (FTS) in order to prevent it from errantly traversing back over land and posing a risk to the public. The resulting launch vehicle debris field, composed primarily of first stage solid propellant, poses a threat to the CM. The harsh radiative thermal environment, caused by surrounding burning propellant debris, may lead to CM parachute failure. A methodology, detailed herein, has been developed to address this concern and to quantify the risk of first stage propellant debris leading to the thermal demise of the CM parachutes. Utilizing basic thermal radiation principles, a software program was developed to calculate parachute temperature as a function of time for a given abort trajectory and debris piece trajectory set. Two test cases, considered worst case aborts with regard to launch vehicle debris environments, were analyzed using the simulation: an abort declared at Mach 1 and an abort declared at maximum dynamic pressure (Max Q). For both cases, the resulting temperature profiles indicated that thermal limits for the parachutes were not exceeded. However, short duration close encounters by single debris pieces did have a significant effect on parachute temperature. Therefore while these two test cases did not indicate exceedance of thermal limits, in order to quantify the risk of parachute failure due to radiative effects from the abort environment, a more thorough probability-based analysis using the methodology demonstrated herein must be performed.

Toleman, Benjamin M.↗

First Stage Solid Propellant Multi Debris Thermal Analysis

The crew launch vehicle considered for the Constellation (Cx) Program utilizes a first stage solid rocket motor. If an abort is initiated in first stage flight the Crew Module (CM) will separate and be pulled away from the launch vehicle via a Launch Abort System (LAS) in order to safely and quickly carry the crew away from the malfunction launch vehicle. Having aborted the mission, the launch vehicle will likely be destroyed via a Flight Termination System (FTS) in order to prevent it from errantly traversing back over land and posing a risk to the public. The resulting launch vehicle debris field, composed primarily of first stage solid propellant, poses a threat to the CM. The harsh radiative thermal environment induced by surrounding burning propellant debris may lead to CM parachute failure. A methodology, detailed herein, has been developed to address this concern and quantify the risk of first stage propellant debris leading to radiative thermal demise of the CM parachutes. Utilizing basic thermal radiation principles, a software program was developed to calculate parachute temperature as a function of time for a given abort trajectory and debris piece trajectory set. Two test cases, considered worst-case aborts with regard to launch vehicle debris environments, were analyzed using the simulation: an abort declared at Mach 1 and an abort declared at maximum dynamic pressure (Max Q). For both cases, the resulting temperature profiles indicated that thermal limits for the parachutes were not exceeded. However, short duration close encounters by single debris pieces did have a significant effect on parachute temperature, with magnitudes on the order of 10 s of degrees Fahrenheit. Therefore while these two test cases did not indicate exceedance of thermal limits, in order to quantify the risk of parachute failure due to radiative effects from the abort environment, a more thorough probability-based analysis using the methodology demonstrated herein must be performed.

Toleman, Benjamin M.↗

Reliability and Probabilistic Risk Assessment - How They Play Together

PRA methodology is one of the probabilistic analysis methods that NASA brought from the nuclear industry to assess the risk of LOM, LOV and LOC for launch vehicles. PRA is a system scenario based risk assessment that uses a combination of fault trees, event trees, event sequence diagrams, and probability and statistical data to analyze the risk of a system, a process, or an activity. It is a process designed to answer three basic questions: What can go wrong? How likely is it? What is the severity of the degradation? Since 1986, NASA, along with industry partners, has conducted a number of PRA studies to predict the overall launch vehicles risks. Planning Research Corporation conducted the first of these studies in 1988. In 1995, Science Applications International Corporation (SAIC) conducted a comprehensive PRA study. In July 1996, NASA conducted a two-year study (October 1996 - September 1998) to develop a model that provided the overall Space Shuttle risk and estimates of risk changes due to proposed Space Shuttle upgrades. After the Columbia accident, NASA conducted a PRA on the Shuttle External Tank (ET) foam. This study was the most focused and extensive risk assessment that NASA has conducted in recent years. It used a dynamic, physics-based, integrated system analysis approach to understand the integrated system risk due to ET foam loss in flight. Most recently, a PRA for Ares I launch vehicle has been performed in support of the Constellation program. Reliability, on the other hand, addresses the loss of functions. In a broader sense, reliability engineering is a discipline that involves the application of engineering principles to the design and processing of products, both hardware and software, for meeting product reliability requirements or goals. It is a very broad design-support discipline. It has important interfaces with many other engineering disciplines. Reliability as a figure of merit (i.e. the metric) is the probability that an item will perform its intended function(s) for a specified mission profile. In general, the reliability metric can be calculated through the analyses using reliability demonstration and reliability prediction methodologies. Reliability analysis is very critical for understanding component failure mechanisms and in identifying reliability critical design and process drivers. The following sections discuss the PRA process and reliability engineering in detail and provide an application where reliability analysis and PRA were jointly used in a complementary manner to support a Space Shuttle flight risk assessment.

Safie, Fayssal M.↗

Micrometeoroid and Orbital Debris (MMOD) Shield Ballistic Limit Analysis Program

This software implements penetration limit equations for common micrometeoroid and orbital debris (MMOD) shield configurations, windows, and thermal protection systems. Allowable MMOD risk is formulated in terms of the probability of penetration (PNP) of the spacecraft pressure hull. For calculating the risk, spacecraft geometry models, mission profiles, debris environment models, and penetration limit equations for installed shielding configurations are required. Risk assessment software such as NASA's BUMPERII is used to calculate mission PNP; however, they are unsuitable for use in shield design and preliminary analysis studies. The software defines a single equation for the design and performance evaluation of common MMOD shielding configurations, windows, and thermal protection systems, along with a description of their validity range and guidelines for their application. Recommendations are based on preliminary reviews of fundamental assumptions, and accuracy in predicting experimental impact test results. The software is programmed in Visual Basic for Applications for installation as a simple add-in for Microsoft Excel. The user is directed to a graphical user interface (GUI) that requires user inputs and provides solutions directly in Microsoft Excel workbooks.

Ryan, Shannon↗

Polymer Matrix Composite Material Oxygen Compatibility

Carbon fiber/polymer matrix composite materials look promising as a material to construct liquid oxygen (LOX) tanks. Based on mechanical impact tests the risk will be greater than aluminum, however, the risk can probably be managed to an acceptable level. Proper tank design and operation can minimize risk. A risk assessment (hazard analysis) will be used to determine the overall acceptability for using polymer matrix composite materials.

Owens, Tom↗

Combined EDL-Mobility Planning for Planetary Missions

This paper presents an analysis framework for planetary missions that have coupled mobility and EDL (Entry-Descent-Landing) systems. Traditional systems engineering approaches to mobility missions such as MERs (Mars Exploration Rovers) and MSL (Mars Science Laboratory) independently study the EDL system and the mobility system, and does not perform explicit trade-off between them or risk minimization of the overall system. A major challenge is that EDL operation is inherently uncertain and its analysis results such as landing footprint are described using PDF (Probability Density Function). The proposed approach first builds a mobility cost-to-go map that encodes the driving cost of any point on the map to a science target location. The cost could include variety of metrics such as traverse distance, time, wheel rotation on soft soil, and closeness to hazards. It then convolves the mobility cost-to-go map with the landing PDF given by the EDL system, which provides a histogram of driving cost, which can be used to evaluate the overall risk of the mission. By capturing the coupling between EDL and mobility explicitly, this analysis framework enables quantitative tradeoff between EDL and mobility system performance, as well as the characterization of risks in a statistical way. The simulation results are presented with a realistic Mars terrain data

mission analysis↗

Estimating the Contributions to Human Error Probability from the Convolution of the Distribution of Time Available and Time Required

As part of their duties, Human Reliability Analysis must often evaluate if crews in nuclear power plants (NPPs) can complete tasks associated with a human-failure event within time limits. For example, the time required in NPP scenarios is determined by systematic and structured walkthroughs, feasibility studies, recorded times from training exercises, and interviews with experienced operators and experts. Typically, a point estimate is derived for the estimate (mean, maximum, or 95th percentile of time required). Using point-estimate values can mask the risk associated with variability among crews, plant conditions and set-up, environmental conditions, and other impact factors under which these actions are executed. While point estimates for time required and time available have served the industry well, without considering the uncertainty they could lead to biased understanding about the risk. The Integrated Human Event Analysis System - General Methodology (IDHEAS-G) model (developed by the US Nuclear Regulatory Commission, NRC) for human error probability calculates human error probability by summing two probabilities: insufficient time and cognitive error. As such, the model takes a more holistic approach by considering the full distributions for time required and time available to calculate the human error probability because the time available to complete the task is insufficient. In this study, we expand on the work of the NRC and discuss methods for estimating these time considerations. For example, for the time required, the impact of Performance Influencing Factors (PIFs) on the distribution was divided into impacts that are aleatory in nature, such as crew-to-crew variability, and those that are epistemic (i.e., the PIFs). Starting with the factors that introduce aleatory uncertainty, a first-order distribution was developed from a large set of time required (i.e., NPP task completion times) data for the range of operator actions that occur in the NPP control room under simulated accident conditions. The first-order distribution can then be adjusted to account for epistemic uncertainty using research associated with the impact of applicable PIFs on the time required. We also develop guidance for analysts to address the probability distributions for the time available. The guidance we developed on how to estimate time required and time available distributions is based on the identification of pertinent research and data, data analyses, and expert knowledge elicitation.

human error probability, human performance, time e↗

Evaluating Faulty State Occurrence in Wildfire UAS Missions Using Markov Chains

As autonomous technology advances, unmanned aircraft systems are increasingly integrated into emergency response missions, such as wildfire response. These systems must be be safe with less risk than non-autonomous counter parts, yet quantifying the risk associated with present-day and future systems conventionally relies solely on expert opinion and little data. Instead, combining narrative mishap reports with probabilistic analysis can provide a method for evolutionary and timely risk analysis. In this paper, we present a framework for a data-driven probabilistic risk assessment style analysis, where hazard events and rates originate from documented UAS mishaps. The framework is applied to a UAS mapping mission in wildfire response, including a fault tree analysis, event tree analysis, and probabilistic analysis using Markov Chains. The analysis provides an enumeration of hazards in the system, hazard events that can lead to faults, the probability of a mission experiencing any fault, the probability of experiencing a specific fault, and the expected time spent until faulty states occur in present-day operations.

risk analysis↗

Risk and value analysis of SETI

This paper attempts to apply a traditional risk and value analysis to the Search for Extraterrestrial Intelligence--SETI. In view of the difficulties of assessing the probability of success, a comparison is made between SETI and a previous search for extraterrestrial life, the biological component of Project Viking. Our application of simple Utility Theory, given some reasonable assumptions, suggests that SETI is at least as worthwhile as the biological experiment on Viking.

NASA Program Exobiology↗

Mars Exploration Rover Heat Shield Recontact Analysis

The twin Mars Exploration Rover missions landed successfully on Mars surface in January of 2004. Both missions used a parachute system to slow the rover s descent rate from supersonic to subsonic speeds. Shortly after parachute deployment, the heat shield, which protected the rover during the hypersonic entry phase of the mission, was jettisoned using push-off springs. Mission designers were concerned about the heat shield recontacting the lander after separation, so a separation analysis was conducted to quantify risks. This analysis was used to choose a proper heat shield ballast mass to ensure successful separation with low probability of recontact. This paper presents the details of such an analysis, its assumptions, and the results. During both landings, the radar was able to lock on to the heat shield, measuring its distance, as it descended away from the lander. This data is presented and is used to validate the heat shield separation/recontact analysis.

Raiszadeh, Behzad↗

ENRE 655 Class Project. Development of the Initial Main Parachute Failure Probability for the Constellation Program (CxP) Orion Crew Exploration Vehicle (CEV) Parachute Assembly System (CPAS)

Loss of Crew (LOC) and Loss of Mission (LOM) are two key requirements the Constellation Program (CxP) measure against. To date, one of the top risk drivers for both LOC and LOM has been Orion's Crew Exploration Vehicle (CEV) Parachute Assembly System (CPAS). Even though the Orion CPAS is one of the top risk drivers of CxP, it has been very difficult to obtain any relevant data to accurately quantify the risk. At first glance, it would seem that a parachute system would be very reliable given the track record of Apollo and Soyuz. Given the success of those two programs, the amount of data is considered to be statistically insignificant. However, due to CxP having LOC/LOM as key design requirements, it was necessary for Orion to generate a valid prior to begin the Risk Informed Design process. To do so, the Safety & Mission Assurance (S&MA) Space Shuttle & Exploration Analysis Section generated an initial failure probability for Orion to use in preparation for the Orion Systems Requirements Review (SRR).

Fuqua, Bryan C.↗

Evidence-Based Approach to the Analysis of Serious Decompression Sickness with Application to EVA Astronauts

It is important to understand the risk of serious hypobaric decompression sickness (DCS) in order to develop procedures and treatment responses to mitigate the risk. Since it is not ethical to conduct prospective tests about serious DCS with humans, the necessary information was gathered from 73 published reports. We hypothesize that a 4-hr 100% oxygen (O2) prebreathe results in a very low risk of serious DCS, and test this through analysis. We evaluated 258 tests containing information from 79,366 exposures in attitude chambers. Serious DCS was documented in 918 men during the tests. Serious DCS are signs and symptoms broadly classified as Type II DCS. A risk function analysis with maximum likelihood optimization was performed to identify significant explanatory variables, and to create a predictive model for the probability of serious DCS [P(serious DCS)]. Useful variables were Tissue Ratio, the planned time spent at altitude (T(sub alt)), and whether or not repetitive exercise was performed at altitude. Tissue Ratio is P1N2/P2, where P1N2 is calculated nitrogen (N2) pressure in a compartment with a 180-min half-time for N2 pressure just before ascent, and P2 is ambient pressure after ascent. A prebreathe and decompression profile Shuttle astronauts use for extravehicular activity (EVA) includes a 4-hr prebreathe with 100% O2, an ascent to P2 = 4.3 lb per sq. in. absolute, and a T(sub alt) = 6 hr. The P(serious DCS) is: 0.0014 (0.00096 - 0.00196, 95% confidence interval) with exercise and 0.00025 (0.00016 - 0.00035) without exercise. Given 100 Shuttle EVAs to date and no report of serious DCS, the true risk is less than 0.03 with 95% confidence (Binomial Theorem). It is problematic to estimate the risk of serious DCS since it appears infrequently, even if the estimate is based on thousands of altitude chamber exposures. The true risk to astronauts may lie between the extremes of the confidence intervals (0.00016 - 0.00196) since the contribution of other factors, particularly exercise, to the risk of serious DCS during EVA is unknown. A simple model that only accounts for four important variables in retrospective data is still helpful to increase our understanding about the risk of serious DCS.

Conkin, Johnny↗

Probabilistic Risk Assessment Procedures Guide for NASA Managers and Practitioners (Second Edition)

Probabilistic Risk Assessment (PRA) is a comprehensive, structured, and logical analysis method aimed at identifying and assessing risks in complex technological systems for the purpose of cost-effectively improving their safety and performance. NASA's objective is to better understand and effectively manage risk, and thus more effectively ensure mission and programmatic success, and to achieve and maintain high safety standards at NASA. NASA intends to use risk assessment in its programs and projects to support optimal management decision making for the improvement of safety and program performance. In addition to using quantitative/probabilistic risk assessment to improve safety and enhance the safety decision process, NASA has incorporated quantitative risk assessment into its system safety assessment process, which until now has relied primarily on a qualitative representation of risk. Also, NASA has recently adopted the Risk-Informed Decision Making (RIDM) process [1-1] as a valuable addition to supplement existing deterministic and experience-based engineering methods and tools. Over the years, NASA has been a leader in most of the technologies it has employed in its programs. One would think that PRA should be no exception. In fact, it would be natural for NASA to be a leader in PRA because, as a technology pioneer, NASA uses risk assessment and management implicitly or explicitly on a daily basis. NASA has probabilistic safety requirements (thresholds and goals) for crew transportation system missions to the International Space Station (ISS) [1-2]. NASA intends to have probabilistic requirements for any new human spaceflight transportation system acquisition. Methods to perform risk and reliability assessment in the early 1960s originated in U.S. aerospace and missile programs. Fault tree analysis (FTA) is an example. It would have been a reasonable extrapolation to expect that NASA would also become the world leader in the application of PRA. That was, however, not to happen. Early in the Apollo program, estimates of the probability for a successful roundtrip human mission to the moon yielded disappointingly low (and suspect) values and NASA became discouraged from further performing quantitative risk analyses until some two decades later when the methods were more refined, rigorous, and repeatable. Instead, NASA decided to rely primarily on the Hazard Analysis (HA) and Failure Modes and Effects Analysis (FMEA) methods for system safety assessment.

Stamatelatos,Michael↗

Evaluating Faulty State Occurrence in Wildfire UAS Missions Using Markov Chains

As autonomous technology advances, unmanned aircraft systems are increasingly integrated into emergency response missions, such as wildfire response. These systems must be be safe with less risk than non-autonomous counter parts, yet quantifying the risk associated with present-day and future systems conventionally relies solely on expert opinion and little data. Instead, combining narrative mishap reports with probabilistic analysis can provide a method for evolutionary and timely risk analysis. In this paper, we present a framework for a data-driven probabilistic risk assessment style analysis, where hazard events and rates originate from documented UAS mishaps. The framework is applied to a UAS mapping mission in wildfire response, including a fault tree analysis, event tree analysis, and probabilistic analysis using Markov Chains. The analysis provides an enumeration of hazards in the system, hazard events that can lead to faults, the probability of a mission experiencing any fault, the probability of experiencing a specific fault, and the expected time spent until faulty states occur in present-day operations.

risk analysis↗

Turbine Damage Probability

Damage probability maps for offshore wind turbines exposed to tropical cyclones (TCs) under both historical and future climate scenarios along the U.S. Atlantic and Gulf Coasts are presented in this dataset. TCs are generated using the Risk Analysis Framework for Tropical Cyclones (RAFT), forced by CMIP6 historical and future global climate simulations. Maximum wind speeds for 20- and 50-year TCs are processed through a fragility function specific to offshore wind (OSW) turbines in order to estimate the probability of damage – specifically yielding and buckling – based on wind speed intensity.

17 WIND ENERGY↗