Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Wide Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Improving system reliability through formal analysis and use of checks in software

Software is playing increasingly important roles in avionics systems. It is widely used in navigation and, in some cases, in control loops that maintain aircraft stability. To guarantee the safety of flight systems, the FAA requires that critical components have a probability of failure no greater than 10(exp -9) per hour of flight. Software is being used to diagnose system components for failure. SIFT (Software Implemented Fault Tolerance) was a computer system developed to study the use of software to check for failure and manage processor reconfiguration. To guarantee that software satisfies its specifications, formal verification can be used. With this a program and its specification are viewed as mathematical objects, and a mathematical proof is used to show that the program and its specification are equivalent. In previous research, a theory of checking was developed to offer assistance in analyzing specifications and designing run-time checks. In the theory, checking is considered abstractly in terms of n-ary relations much like those of relational database theory. Within the theory check are categorized, checks on input and checks on results are considered, and formal attention is given to the minimization and logical combination of checks. The focus is upon input checks and the obstacles in checking input to critical systems. A central concern is with a property referred to as independence. The concern is with circumstances under which it is possible to apply isolated, independent checks to separate sensor inputs and be assure that all illegal input will be properly detected. Presently, independence is being investigated and checked in the context of the GCS (Guidance and Control System). The GCS simulator is intended for testing software that implements control laws for landing spacecraft. The large number of inputs and their complex interrelationships provide an exciting context in which to investigate independence and the difficulties of supplying input checks.

Staknis, Mark E.↗

Safety Arguments for Next Generation, Location Aware Computing

Concerns over accuracy, availability, integrity, and continuity have limited the integration of Global Positioning System (GPS) and Global Navigation Satellite System (GLONASS) for safety-critical applications. More recent augmentation systems, such as the European Geostationary Navigation Overlay Service (EGNOS) and the North American Wide Area Augmentation System (WAAS) have begun to address these concerns. Augmentation architectures build on the existing GPS/GLONASS infrastructures to support location based services in Safety of Life (SoL) applications. Much of the technical development has been directed by air traffic management requirements, in anticipation of the more extensive support to be offered by GPS III and Galileo. WAAS has already been approved to provide vertical guidance for aviation applications. During the next twelve months, the full certification of EGNOS for SoL applications is expected. This paper discusses similarities and differences between the safety assessment techniques used in Europe and North America.

Johnson, C. W.↗

Validation of Safety-Critical Systems for Aircraft Loss-of-Control Prevention and Recovery

Validation of technologies developed for loss of control (LOC) prevention and recovery poses significant challenges. Aircraft LOC can result from a wide spectrum of hazards, often occurring in combination, which cannot be fully replicated during evaluation. Technologies developed for LOC prevention and recovery must therefore be effective under a wide variety of hazardous and uncertain conditions, and the validation framework must provide some measure of assurance that the new vehicle safety technologies do no harm (i.e., that they themselves do not introduce new safety risks). This paper summarizes a proposed validation framework for safety-critical systems, provides an overview of validation methods and tools developed by NASA to date within the Vehicle Systems Safety Project, and develops a preliminary set of test scenarios for the validation of technologies for LOC prevention and recovery

Belcastro, Christine M.↗

Structural Requirements for the Space Propulsion Engine Systems

In January 2004, the National Aeronautics and Space Administration (NASA) was given a vision for Space Exploration by President Bush, setting our sight on a bold new path to go back to the Moon, then to Mars and beyond. As NASA gets ready to meet the vision set by President Bush, failures are not an option. Reliability of the propulsion engine systems will play an important role in establishing an overall safe and reliable operation of these new space systems. A new standard, NASA-STD-5012, Strength and Life Assessment for Space Propulsion System Engines, has been developed to provide structural requirements for assessment of the propulsion systems engine. This standard is a complement to the current NASA-wide standard NASA-STD-5001, Structural Design and Test Factors of Safety for Spaceflight Hardware, which excluded the requirement for the engine systems (rotatory structures) along with pressure vessels. As developed, this document builds on the heritage of the multiple industrial standards related to strength and life assessment of the structures. For assuring a safe and reliable operation of a product and/or mission, establishing a set of structural assessment requirements is a key ingredient. Hence, a concentrated effort was made to improve the requirements where there are known lessons learned during the design, test, and operation phases of the Space Shuttle Main Engine (SSME) and other engine development programs. Requirements delineated in this standard are also applicable for the reusable and/or human missions. It shall be noted that "reliability of a system cannot be tested and inspected but can only be achieved if it is first designed into a system." Hence, these strength and life assessment requirements for the space propulsion system engines shall be used along with other good engineering practices, requirements, and policies.

Aggarwal, Pravin K.↗

Airspace Safety Threshold Study: NAS-Wide Encounter Rate Evaluation Using Historical Radar Data and ACES

Realization of the expected proliferation of Unmanned Aircraft System (UAS) operations in the National Airspace System (NAS) depends on the development and validation of performance standards for UAS Detect and Avoid (DAA) Systems. The RTCA Special Committee 228 (SC-228) is charged with leading the development of draft Minimum Operational Performance Standards (MOPS) for UAS DAA Systems. NASA, as a participating member of RTCA SC-228 is committed to supporting the development and validation of draft requirements as well as the safety substantiation and end-to-end assessment of DAA system performance. With regard to the safety aspect being studied by the SC-228 DAA Safety sub-group, NASA has conducted a study using the ACES (Airspace Concept Evaluation System) simulation capability to determine: 1) the rate at which IFR aircraft encounter other IFR and VFR aircraft, and 2) the rate at which UAS aircraft encounter VFR aircraft as well as the corresponding encounter geometries. Five different separation thresholds were used (two for encounter and one each for well-clear, near mid-air collision, and closest point of approach). The results will be used by the SC-228 DAA Safety sub-group to inform decisions about the safety aspect of UAS DAA systems and future requirements development and validation efforts.

encounter geometry↗

The NASA Aviation Safety Program: Overview

In 1997, the United States set a national goal to reduce the fatal accident rate for aviation by 80% within ten years based on the recommendations by the Presidential Commission on Aviation Safety and Security. Achieving this goal will require the combined efforts of government, industry, and academia in the areas of technology research and development, implementation, and operations. To respond to the national goal, the National Aeronautics and Space Administration (NASA) has developed a program that will focus resources over a five year period on performing research and developing technologies that will enable improvements in many areas of aviation safety. The NASA Aviation Safety Program (AvSP) is organized into six research areas: Aviation System Modeling and Monitoring, System Wide Accident Prevention, Single Aircraft Accident Prevention, Weather Accident Prevention, Accident Mitigation, and Synthetic Vision. Specific project areas include Turbulence Detection and Mitigation, Aviation Weather Information, Weather Information Communications, Propulsion Systems Health Management, Control Upset Management, Human Error Modeling, Maintenance Human Factors, Fire Prevention, and Synthetic Vision Systems for Commercial, Business, and General Aviation aircraft. Research will be performed at all four NASA aeronautics centers and will be closely coordinated with Federal Aviation Administration (FAA) and other government agencies, industry, academia, as well as the aviation user community. This paper provides an overview of the NASA Aviation Safety Program goals, structure, and integration with the rest of the aviation community.

Shin, Jaiwon↗

Summary of NASA Aerospace Flight Battery Systems Program activities

A summary of NASA Aerospace Flight Battery Systems Program Activities is presented. The NASA Aerospace Flight Battery Systems Program represents a unified NASA wide effort with the overall objective of providing NASA with the policy and posture which will increase the safety, performance, and reliability of space power systems. The specific objectives of the program are to: enhance cell/battery safety and reliability; maintain current battery technology; increase fundamental understanding of primary and secondary cells; provide a means to bring forth advanced technology for flight use; assist flight programs in minimizing battery technology related flight risks; and ensure that safe, reliable batteries are available for NASA's future missions.

Manzo, Michelle↗

A 20 kiloHertz space station power system

The space station represents the next major U.S. commitment in space. The efficient delivery of power to multiple user loads is key to that success. In 1969, NASA Lewis Research Center began a series of studies with component and circuit developments that led to the high frequency, bi-directional, four quadrant resonant driven converter. Additional studies and subsequent developments into the early 1980's have shown how the high frequency ac power system could provide overall advantages to many aerospace power systems. Because of its wide versatility, it also has outstanding advantages for the Space Station Program and its wide range of users. High frequency ac power provides higher efficiency, lower cost, and improved safety. The 20 kHz power system has exceptional flexibility, is inherently user friendly, and is compatible with all types of energy sources - photovoltaic, solar dynamic, rotating machines or nuclear. Lewis has recently completed development under contract a 25 kW, 20 kHz ac power distribution system testbed. The testbed demonstrates flexibility, versatility, and transparency to user technology as well as high efficiency, low mass, and reduced volume.

Hansen, I. G.↗

20 kHz Space Station power system

The Space Station represents the next major U.S. commitment in space. The efficient delivery of power to multiple user loads is key to that success. In 1969, NASA Lewis Research Center began a series of studies with component and circuit developments that led to the high frequency bi-directional, four quadrant resonant driven converter. Additional studies and subsequent developments into the early 1980's have shown how the high frequency ac power system could provide overall advantages to many aerospace power systems. Because of its wide versatility, it also has outstanding advantages for the Space Station Program and its wide range of users. High frequency ac power provides higher efficiency, lower cost, and improved safety. The 20 kHz power system has exceptional flexibility, is inherently user friendly, and is compatible with all types of energy sources - photovoltaic, solar dynamic, rotating machines or nuclear Lewis distribution system testbed. The testbed demonstrates flexibility, versatility, and transparency to user technology as well as high efficiency, low mass, and reduced volume.

Hansen, Irving G.↗

Prototype Development for MBSE-Driven Digital Environment at Fermilab

Complex projects like Fermilab s accelerators and detectors involve thousands of interdependent components and requirements, making traditional documentation hard to keep consistent and often causing rework. Model-Based Systems Engineering (MBSE) tackles this by representing the system as a digital, queryable model. While widely used in aerospace and safety-critical industries, MBSE adoption has been limited elsewhere due to steep learning curves and high costs. This project investigates how a web-first, low-code MBSE stack can reduce those barriers and offer an accessible, unified source of truth for engineers and physicists.

Valle, Diego Pedro (ORCID:0009000865900663)↗

Advanced rechargeable sodium batteries with novel cathodes

Various high energy density rechargeable batteries are being considered for future space applications. Of these, the sodium-sulfur battery is one of the leading candidates. The primary advantage is the high energy density (760 Wh/kg theoretical). Energy densities in excess of 180 Wh/kg were realized in practical batteries. Other technological advantages include its chemical simplicity, absence of self-discharge, and long cycle life possibility. More recently, other high temperature sodium batteries have come into the spotlight. These systems can be described as follow: Na/Beta Double Prime-Al2O3/NaAlCl4/Metal Dichloride Sodium/metal dichloride systems are colloquially known as the zebra system and are currently being developed for traction and load leveling applications. The sodium-metal dichloride systems appear to offer many of the same advantages of the Na/S system, especially in terms of energy density and chemical simplicity. The metal dichloride systems offer increased safety and good resistance to overcharge and operate over a wide range of temperatures from 150 to 400 C with less corrosion problems.

Distefano, S.↗

Formalization of the Integral Calculus in the PVS Theorem Prover

The PVS Theorem prover is a widely used formal verification tool used for the analysis of safety-critical systems. The PVS prover, though fully equipped to support deduction in a very general logic framework, namely higher-order logic, it must nevertheless, be augmented with the definitions and associated theorems for every branch of mathematics and Computer Science that is used in a verification. This is a formidable task, ultimately requiring the contributions of researchers and developers all over the world. This paper reports on the formalization of the integral calculus in the PVS theorem prover. All of the basic definitions and theorems covered in a first course on integral calculus have been completed.The theory and proofs were based on Rosenlicht's classic text on real analysis and follow the traditional epsilon-delta method. The goal of this work was to provide a practical set of PVS theories that could be used for verification of hybrid systems that arise in air traffic management systems and other aerospace applications. All of the basic linearity, integrability, boundedness, and continuity properties of the integral calculus were proved. The work culminated in the proof of the Fundamental Theorem Of Calculus. There is a brief discussion about why mechanically checked proofs are so much longer than standard mathematics textbook proofs.

Butler, Ricky W.↗

NASA's Software Safety Standard

NASA relies more and more on software to control, monitor, and verify its safety critical systems, facilities and operations. Since the 1960's there has hardly been a spacecraft launched that does not have a computer on board that will provide command and control services. There have been recent incidents where software has played a role in high-profile mission failures and hazardous incidents. For example, the Mars Orbiter, Mars Polar Lander, the DART (Demonstration of Autonomous Rendezvous Technology), and MER (Mars Exploration Rover) Spirit anomalies were all caused or contributed to by software. The Mission Control Centers for the Shuttle, ISS, and unmanned programs are highly dependant on software for data displays, analysis, and mission planning. Despite this growing dependence on software control and monitoring, there has been little to no consistent application of software safety practices and methodology to NASA's projects with safety critical software. Meanwhile, academia and private industry have been stepping forward with procedures and standards for safety critical systems and software, for example Dr. Nancy Leveson's book Safeware: System Safety and Computers. The NASA Software Safety Standard, originally published in 1997, was widely ignored due to its complexity and poor organization. It also focused on concepts rather than definite procedural requirements organized around a software project lifecycle. Led by NASA Headquarters Office of Safety and Mission Assurance, the NASA Software Safety Standard has recently undergone a significant update. This new standard provides the procedures and guidelines for evaluating a project for safety criticality and then lays out the minimum project lifecycle requirements to assure the software is created, operated, and maintained in the safest possible manner. This update of the standard clearly delineates the minimum set of software safety requirements for a project without detailing the implementation for those requirements. This allows the projects leeway to meet these requirements in many forms that best suit a particular project's needs and safety risk. In other words, it tells the project what to do, not how to do it. This update also incorporated advances in the state of the practice of software safety from academia and private industry. It addresses some of the more common issues now facing software developers in the NASA environment such as the use of Commercial-Off-the-Shelf Software (COTS), Modified OTS (MOTS), Government OTS (GOTS), and reused software. A team from across NASA developed the update and it has had both NASA-wide internal reviews by software engineering, quality, safety, and project management. It has also had expert external review. This presentation and paper will discuss the new NASA Software Safety Standard, its organization, and key features. It will start with a brief discussion of some NASA mission failures and incidents that had software as one of their root causes. It will then give a brief overview of the NASA Software Safety Process. This will include an overview of the key personnel responsibilities and functions that must be performed for safety-critical software.

Ramsay, Christopher M.↗

The Role and Quality of Software Safety in the NASA Constellation Program

In this study, we examine software safety risk in the early design phase of the NASA Constellation spaceflight program. Obtaining an accurate, program-wide picture of software safety risk is difficult across multiple, independently-developing systems. We leverage one source of safety information, hazard analysis, to provide NASA quality assurance managers with information regarding the ongoing state of software safety across the program. The goal of this research is two-fold: 1) to quantify the relative importance of software with respect to system safety; and 2) to quantify the level of risk presented by software in the hazard analysis. We examined 154 hazard reports created during the preliminary design phase of three major flight hardware systems within the Constellation program. To quantify the importance of software, we collected metrics based on the number of software-related causes and controls of hazardous conditions. To quantify the level of risk presented by software, we created a metric scheme to measure the specificity of these software causes. We found that from 49-70% of hazardous conditions in the three systems could be caused by software or software was involved in the prevention of the hazardous condition. We also found that 12-17% of the 2013 hazard causes involved software, and that 23-29% of all causes had a software control. Furthermore, 10-12% of all controls were software-based. There is potential for inaccuracy in these counts, however, as software causes are not consistently scoped, and the presence of software in a cause or control is not always clear. The application of our software specificity metrics also identified risks in the hazard reporting process. In particular, we found a number of traceability risks in the hazard reports may impede verification of software and system safety.

Layman, Lucas↗

Correlated Topics in a Scalable Multidimensional Text Cube: Algorithms and Aviation Safety Case Study

As world-wide air traffic continues to grow even at a modest pace, the overall complexity of the system will increase significantly. This increased complexity can lead to a larger number of fatalities per year even if the extremely low fatality rate that we currently enjoy is maintained. One important source of information about the safety of the aviation system is in Aviation Safety Text Reports which are written by members of the flight crew, air traffic controllers, and other parties involved with the aviation system. These anonymized narrative reports contain fixed-field contextual information about the flight but also contain free-form narratives that describe, in the author s own words, the nature of the safety incident and, in many cases, the contributing factors that led to the safety incident. Several thousand such reports are filed each month, each of which is read and analyzed by highly trained experts. However, it is possible that there are emerging safety issues due to the fact that they may be reported very infrequently and in different contexts with different descriptions. The goal of this research paper is to develop correlated topic models which uncover correlations in the subspaces defined by the intersection of numerous fixed fields and discovered correlated topics. This task requires the discovery of latent topics in the text reports and the creation of a topic cube. Furthermore, because the number of potential cells in the topic cube is very large, we discuss novel methods of pruning the search space in the topic cells, thereby making the analysis feasible. We demonstrate the new algorithms on an analysis of pilot fatigue and its contributing factors, as well as the safety incidents that are correlated with this phenomenon.

Zhao, Bo↗

Spot: A Programming Language for Verified Flight Software

The C programming language is widely used for programming space flight software and other safety-critical real time systems. C, however, is far from ideal for this purpose: as is well known, it is both low-level and unsafe. This paper describes Spot, a language derived from C for programming space flight systems. Spot aims to maintain compatibility with existing C code while improving the language and supporting verification with the SPIN model checker. The major features of Spot include actor-based concurrency, distributed state with message passing and transactional updates, and annotations for testing and verification. Spot also supports domain-specific annotations for managing spacecraft state, e.g., communicating telemetry information to the ground. We describe the motivation and design rationale for Spot, give an overview of the design, provide examples of Spot's capabilities, and discuss the current status of the implementation.

validation↗

Prognostics As-A-Service: A Scalable Cloud Architecture for Prognostics

Comprehensive aircraft system health-state awareness is critical for maintaining safe, efficient growth in global operations, enabling higher levels of autonomy, and facilitating new forms of aviation. Maintainers, vehicle operators, air traffic controllers, dispatchers, pilots, autonomous systems, and other decision-makers must have reliable real-time knowledge of the vehicle health, the health of its critical composite systems, predictions of how health changes with time, and forecasts of how its capabilities change with health degradation to preserve safety and efficiency. Providing this information in a reliable manner in computationally constrained environments and across a wide range of vehicles and systems continues to be a challenge. This challenge can be partially resolved through cloud computing, where the execution of prognostic and diagnostic algorithms is performed on a network of remote servers hosted on the internet. NASA is developing a cloud computing service, Prognostics As-A-Service (PaaS), that explores the feasibility and challenges of cloud-enhanced prognostics. Though such a system has broad applicability, this research effort is focused on aviation applications.

Prognostics↗

Application of System Identification to Parachute Modeling

Parachute models are used in numerous flight simulation tools to predict a wide range of parachute flight performance characteristics (e.g., parachute inflation loads, parachute stability and dynamics, vehicle touchdown conditions, and, ultimately, the safety and survivability of the system using the parachute). The current state of the art in developing parachute models is to initially estimate the parachute characteristics based on the parachute geometry and historical data and then add increased model fidelity based on data from wind tunnel and/or flight tests. This approach, however, can be deficient in identifying which parachute states (e.g., angle of attack, sideslip, angular rates, flyout angles, descent rate, dynamic pressure, proximity to other parachutes) are responsible for the parachute motion, and the relationship between those states and the forces on the parachute.

Murri, Daniel G.↗