Search NASA⌕ Search

SEARCH · Search NASA

Results for “avoidable risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

A Structured, Model-Based Systems Engineering Methodology for Operations System Design

Two widely accepted techniques for lowering the cost and risk of developing systems are (1) the use of a defined systems engineering (SE) process or methodology and (2) the reuse of existing (previously built) system components. The first technique is represented, for example, in materials published by NASA (e.g., NASA Systems Engineering Handbook) or by professional societies such as INCOSE (International Council on Systems Engineering). Well-formed SE techniques provide value by establishing the proper scope of the system (e.g., requirements), and by identifying and resolving problems relatively early in project lifecycles, when fixes are less expensive. The second technique (reuse) is applied most commonly to hardware and software; it seeks to avoid replicating design and implementation costs while also reducing risk by placing proven capabilities into operational use. In this paper, we outline a methodology combining these two techniques and extending reuse beyond hardware and software to foundational aspects of a Mission Operation System’s (MOS) design. We describe the system design artifacts that result (e.g., requirements, design documentation), as well as the reusable patterns and elements of the design, and their interrelationships. This approach is enabled by model-based systems engineering (MBSE) techniques and tools and is currently available in SysML form as a plug-in to MagicDraw. Additionally, usage of a rigorous MBSE approach allows for training materials and tutorials to be packaged within the overall model itself. The results of such an approach include decreased cost and risk during the design phase, improved ability of the MOS development team to investigate trade spaces and identify impacts to important flight-ground trade studies. Such results extend into decreased costs and risk in later phases due to improved design, decreased need for late fixes or development of "glue-ware" or scripts to fill unanticipated gaps in functionality, and improved ability to identify and plan testing and other validation activities. Finally, lower operational costs can be expected, both due to improved quality of the MOS, increased ease of maintaining updated knowledge of system configuration, and the fact that training and procedural materials are also updated at the same time as accepted system changes.

Bindschadler, Duane L.↗

Impact of representative ground motion level on seismic PSA with the boundary between overestimation and underestimation

One commonly used approach in seismic probabilistic safety assessment (PSA) is the discrete method. This method follows the standard PSA framework and can be applied to various models, such as multi-unit models, while reducing computational costs using standard software. However, due to the inability to subdivide intervals infinitely, the discrete method approximates with a finite number of subintervals. In practice, different numbers of subintervals are applied, and the representative ground motion level is selected based on expert judgment. When employing a smaller number of subintervals, it is important to take caution to prevent underestimation. This study analyzes the impact of the representative ground motion level on seismic risk. It confirms that underestimation can occur with a small number of subintervals depending on the representative ground motion level. This study also proposes a method for determining the boundary of underestimation and overestimation. The method is demonstrated through examples, providing a mathematical foundation for selecting appropriate representative ground motion levels. By avoiding underestimation, this research helps prevent the oversight of significant risk contributors and enhances the understanding of seismic risk.

99 - GENERAL AND MISCELLANEOUS↗

Twenty‐First Century Drought Projections in the CMIP6 Forcing Scenarios

There is strong evidence climate change will increase drought risk and severity, but these conclusions depend on the regions, seasons, and drought metrics being considered. We analyze changes in drought across the hydrologic cycle (precipitation, soil moisture, and runoff) in projections from Phase Six of the Coupled Model Intercomparison Project (CMIP6). The multi‐model ensemble shows robust drying in the mean state across many regions and metrics by the end of the 21st century, even following the more aggressive mitigation pathways (SSP1‐2.6 and SSP2‐4.5). Regional hotspots with strong drying include western North America, Central America, Europe and the Mediterranean, the Amazon, southern Africa, China, Southeast Asia, and Australia. Compared to SSP3‐7.0 and SSP5‐8.5, however, the severity of drying in the lower warming scenarios is substantially reduced and further precipitation declines in many regions are avoided. Along with drying in the mean state, the risk of the historically most extreme drought events also increases with warming, by 200–300% in some regions. Soil moisture and runoff drying in CMIP6 is more robust, spatially extensive, and severe than precipitation, indicating an important role for other temperature‐sensitive drought processes, including evapotranspiration and snow. Given the similarity in drought responses between CMIP5 and CMIP6, we speculate both generations of models are subject to similar uncertainties, including vegetation processes, model representations of precipitation, and the degree to which model responses to warming are consistent with observations. These topics should be further explored to evaluate whether CMIP6 models offer reasons to have increased confidence in drought projections.

drought↗

System Risk Balancing Profiles: Software Component

The Software QA / V&V guide will be reviewed and updated based on feedback from NASA organizations and others with a vested interest in this area. Hardware, EEE Parts, Reliability, and Systems Safety are a sample of the future guides that will be developed. Cost Estimates, Lessons Learned, Probability of Failure and PACTS (Prevention, Avoidance, Control or Test) are needed to provide a more complete risk management strategy. This approach to risk management is designed to help balance the resources and program content for risk reduction for NASA's changing environment.

Kelly, John C.↗

Prediction of coronary artery disease in patients undergoing operations for mitral valve degeneration

OBJECTIVES: We sought to develop and validate a model that estimates the risk of obstructive coronary artery disease in patients undergoing operations for mitral valve degeneration and to demonstrate its potential clinical utility. METHODS: A total of 722 patients (67% men; age, 61 +/- 12 years) without a history of myocardial infarction, ischemic electrocardiographic changes, or angina who underwent routine coronary angiography before mitral valve prolapse operations between 1989 and 1996 were analyzed. A bootstrap-validated logistic regression model on the basis of clinical risk factors was developed to identify low-risk (< or =5%) patients. Obstructive coronary atherosclerosis was defined as 50% or more luminal narrowing in one or more major epicardial vessels, as determined by means of coronary angiography. RESULTS: One hundred thirty-nine (19%) patients had obstructive coronary atherosclerosis. Independent predictors of coronary artery disease include age, male sex, hypertension, diabetes mellitus,and hyperlipidemia. Two hundred twenty patients were designated as low risk according to the logistic model. Of these patients, only 3 (1.3%) had single-vessel disease, and none had multivessel disease. The model showed good discrimination, with an area under the receiver-operating characteristic curve of 0.84. Cost analysis indicated that application of this model could safely eliminate 30% of coronary angiograms, corresponding to cost savings of $430,000 per 1000 patients without missing any case of high-risk coronary artery disease. CONCLUSION: A model with standard clinical predictors can reliably estimate the prevalence of obstructive coronary atherosclerosis in patients undergoing mitral valve prolapse operations. This model can identify low-risk patients in whom routine preoperative angiography may be safely avoided.

Non-NASA Center↗

Earth Observing System (EOS) Aqua and Aura Space Weather Effects on Operational Collision Avoidance

This presentation will describe recent EOS Aqua and Aura operational collision avoidance experience during periods of solar and geomagnetic storm activity. It will highlight challenges faced by the operations team during short-notice, high-risk predicted close approaches. The presentation will highlight the evolution of the operational collision avoidance process for the EOS Aqua and Aura missions. The presentation will highlight operational challenges that have occurred, process improvements that have been implemented and identify potential future challenges.

Guit, Bill↗

Earth Observing System (EOS) Aqua & Aura Space Weather Effects on Operational Collision Avoidance

This presentation will describe recent EOS Aqua and Aura operational collision avoidance experience during periods of solar and geomagnetic storm activity. It will highlight challenges faced by the operations team during short-notice, high-risk predicted close approaches. The presentation will highlight the evolution of the operational collision avoidance process for the EOS Aqua and Aura missions. The presentation will highlight operational challenges that have occurred, process improvements that have been implemented and identify potential future challenges.

Operational collision avoidance↗

Re-Entry Survivability Risk Assessment of the Extreme Ultraviolet Explorer (EUVE)

A reentry analysis of the Extreme Ultraviolet Explorer (EUVE) spacecraft was performed using the Object Reentry Survival Analysis Tool (ORSAT) - Version 5.0. The analysis was done in response to a request by NASA Headquarters and Goddard Space Flight Center (GSFC) after a preliminary assessment using the NASA Johnson Space Center Debris Assessment Software (DAS) - Version 1.0 had shown that the EUVE reentry may produce a debris area greater than the limit set within the NASA Safety Standard 1740.14 guidelines. DAS predicted that an uncontrolled reentry of the EUVE spacecraft would result in a total casualty area of 12.41 sq m, which exceeds the 8 sq m limit set in the NASA standards and implies a potential human casualty risk of approximately 1 in 5300. The ORSAT model enabled a higher fidelity thermal analysis of the EUVE spacecraft, utilizing sophisticated material and thermal properties such as emissivity, heat of oxidation, thermal conductivity, and material thickness inputs, which provided a foundation for a more in depth analysis of the reentering objects. Due to the conservative nature of the DAS study, it was reasonable to run ORSAT for only the ten objects shown to survive in the original DAS analysis. The result of the ORSAT study was a reduced casualty area of only 5.95 sq m, well within NASA safety limits. With the risk to human life now acceptably low, NASA can avoid having to take mitigation measures and allow EUVE to reenter the Earth's atmosphere uncontrolled.

O'Hara, Robin E.↗

Quantifying Distribution System Resilience From Utility Data: Large Event Risk and Benefits of Investments

We focus on blackouts in electric distribution systems that have a large cost to customers. To quantify resilience to these events, we show how to calculate risk metrics from the historical outage data routinely collected by utilities' outage management systems. Risk is defined using a customer cost exceedance curve. The exceedance curve has a heavy tail that implies large fluctuations in large blackout costs, and this makes estimating the mean large cost in the usual way impractical. To avoid this problem, we use new resilience metrics describing the large event risk; these metrics are the probability of a large cost event, the annual log cost resilience index, and the average of the logarithm of the cost of large-cost events or the slope magnitude of the tail on a log–log exceedance curve. Resilience can be improved by planned investments to upgrade system components or speed up restoration. The benefits that these investments would have had if they had been made in the past can be quantified by “rerunning history” with the effects of the investment included, and then recalculating the large event risk to find the improvement in resilience. An example using utility data shows a 2% reduction in the probability of a large cost event due to 10% wind hardening and 6%–7% reduction due to 10% faster restoration in two different areas of a distribution utility. This new data-driven approach to quantify resilience and resilience investments is realistic and much easier to apply than complicated approaches based on modeling all the phases of resilience. Moreover, an appeal to improvements to past lived experience may well be persuasive to customers and regulators in making the case for resilience investments.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Cost-Benefit Analysis of Electricity Resilience Projects: State of the Art and Gap Analysis

Utilities and regulators must weigh the benefits of electricity resilience projects against their costs, which would be passed on to customers. Cost-benefit analysis (CBA) is an appropriate method for assessing this tradeoff. Here, in this paper we review the literature on CBA of electricity resilience projects and analyze gaps in the available methods and tools. The costs of resilience projects are typically straightforward to estimate but their benefits — particularly the avoided costs of power interruptions — are complex to quantify and monetize. A common perception among practitioners is that current CBA tools are not sufficiently mature to be adopted into real-world practice. We propose an electricity resilience CBA framework consisting of several elements: risks, physical impacts, power interruptions, economic impacts, and resilience projects. While methods for some elements are well-developed, there is a need for novel approaches to value avoided power interruptions, integrate multiple risks and benefit streams, and incorporate uncertainty.

Cost-benefit analysis↗

Considerations When Building Thermal Models that Require Conversion Between Formats

At times, it is inevitable to require conversion of thermal models from one software format to another. This most often occurs for missions with international partners where not all parties utilize the same software packages for thermal analysis. Mandating a single tool for all parties is one possible solution, but this approach can introduce problems if significant effort is required to overcome inexperience with the designated tool and may result in difficulty meeting analysis schedule requirements. Alternatively, allowing all parties to use their own familiar tools minimizes the impact to analysis schedules but does introduce the need to convert the models later to a common format for analysis at a higher level of assembly. External conversion tools and formats have been developed through the years to aid in this process, but have had limited success in fully converting models seamlessly. Having a basic familiarity with tool capabilities on both sides of the conversion process allows for models to be built in a manner to better facilitate conversion by avoiding features and capabilities which are unsupported by the destination tool or for which no workarounds exist. Also, the effort to convert a model is often neglected when developing the schedules for analysis at the higher assembly levels; delivery of models preconditioned for convertibility minimizes the schedule risk. This paper seeks to provide some guidance on modeling techniques to avoid when developing Geometrical Math Models (GMM) and Thermal Math Models (TMM) when conversion is required. The recommendations are based on GMM conversion experiences between TSS/ThermalDesktop/ESARAD and TMM conversions between SINDA-FLUINT/ESATAN.

Modeling↗

First-of-a-Kind Risk-Informed Digital Twin for Operational Decision Making

A digital twin (DT) is a digital model or a collection of models of a physical entity. DTs in the nuclear arena can be used from plant design through decommissioning. Decisions are typically a priori or made offline. Risk-informed decision making is identifying what can go wrong, its frequency, and the consequences of its failure. Ideally risk-informed decision making reflects the current state of the plant and provides a decision in real time. Traditionally, probabilistic risk assessments (PRAs) evaluate the failures of safety systems, the risk of core damage, and the offsite dose as the consequence. However, this DT evaluates the decisions on the control side rather than the protection side. It uses the same risk methods to probabilistically inform the decision-making process but in a different way. Rather than evaluating the risk of core damage, this DT evaluates the likelihood of avoiding a trip set point while maintaining plant safety. Performance-based assessments are identified via its probabilistic evaluation of operational alternatives based on system status. Because the purpose of the control system is to maintain system variables within prescribed operating ranges, upsets or challenges that can exceed a trip set point resulting in a plant transient and a challenge to plant mitigating systems based on actual plant conditions, are evaluated to safely maintain the plant within the operating ranges. The probabilistic portion of the model is autonomously and automatically adjusted, and the metric of interest (i.e. likelihood of avoiding a trip set point) is recalculated. The digital representation of the physical system (i.e. the DT) performs a deterministic performance–based assessment of the probabilistically identified alternatives identified to validate the probabilistic assessment. A decision-making algorithm selects the appropriate option based on the probabilistic and deterministic assessments and transmits a control signal to a component(s) to initiate a corrective action or informs an operator of its decision.

digital twin↗

Establishing and Monitoring an Aseptic Workspace

When are aseptic operations necessary? In order to meet certain bioburden requirements, some components must undergo dry heat microbial reduction (DHMR) or other sterilizing procedures. If sensitive surfaces must be re-exposed after DHMR, this could compromise the bioburden levels. Recontaminating sterilized surfaces could be costly both in time by requiring repeated DHMR and risk to the hardware, which may not be compatible with repeated high temperature bakes. In order to prevent recontamination of the sensitive surfaces, an aseptic environment and sterile technique must be employed. Aseptic environments mean working in a space with almost no detectable bioburden in the air or on surfaces. Ideally, DHMR happens as late as possible to avoid requiring aseptic operations, as it can be considered a high-risk operations. Preparing the cleanroom for aseptic operations Establishing an ISO (International Organization for Standardization) class 5 space to minimize airborne particles. Maintain low bioburden in the cleanroom by using biocidal cleaners. Using multiple biocidal techniques decreases the likelihood of selecting for resistant microorganisms. 70% Isopropyl Alcohol (IPA) denatures the proteins in a microorganism (note: 70% IPA is better at killing microorganisms than 100% IPA) 7% hydrogen peroxide: damages DNA and proteins through oxygen radical damage. Ultraviolet-C (UV-C) lamps: causes crosslinking in DNA which prevents replication. Monitor cleanroom regularly for bioburden trending: Standard bioassay: Swab or wipe samples of cleanroom surfaces processed for colony forming unity (viable or spore selected); Rapid bioassay: Adenosine triphosphate (ATP) or Limulus amebocyte lysate (LAL) for a bioburden snapshot. High levels can signal an immediate re-cleaning before standard bioassay samples are taken. Airborne monitoring: Active (pulling air through a filter) or passive (particle fallout) for bioburden. Verify bioburden levels just before aseptic operation. Test hardware and cleanroom surfaces and air 3 days before the planned aseptic operation. Rapid bioburden just before aseptic operation to ensure room was not re-contaminated. Preparing personnel and tools: Personnel training. Everyone in the cleanroom: Standard cleanroom certification Everyone on the team: 1 day Planetary Protection overview. Aseptic operators only: Half-day aseptic operations training. Covers sterile garmenting/gloves, Sterile handling with a focus on contact transfer risk, tool/GSE preparation, and two-operator system for opening sterilized tools/components. Tool sterilization: All tools to be used during an aseptic operation need to be identified. Compatible tools are sterilized by DHMR or Autoclave. Double wrapped so that the exterior bag can be handled by a non-sterile operator, and the sterile. Tools that are not compatible with high heat do not come in contact with sensitive surfaces: either substitutes are found, or tools are isolated by wrapping in sterile foil. During an aseptic operation. Pre-task to make sure everyone understands the operations, who is handling what, and when the most critical surfaces will be exposed. Monitoring during the operation. Bioburden: active and passive airborne bioburden sampling, glove-tip dabs onto a plate after completion of operation (3 days for results). Particles: real time particle counter constantly running, with alarm for exceeding ISO 5 conditions.

aseptic processing↗

Initial design concepts for solid boron injection in ITER

As part of ITER’s consideration to change its first wall material from beryllium to tungsten, the ITER Organization has proposed studying the feasibility of real-time solid boron injection (SBI) into the plasma to coat the walls and divertor to supplement glow discharge boronization (GDB). Boron deposits getter oxygen and reduce sputtering of tungsten from plasma facing components (PFCs). Particularly in areas with significant plasma wall interactions, boron coatings are expected to be short-lived under high performance plasma conditions. The proposed SBI system aims to maintain boron layers in these areas to avoid excessive radiation from tungsten in the plasma as a risk mitigation to ensure ITER will be able to reach and sustain Q = 10 conditions. The system will be used sparingly, as redeposition of boron can lead to significant tritium retention, which must be minimized in ITER to comply with nuclear safety concerns. SBI is proposed to limit and precisely control the amount of boron injected in real-time during plasma operation. Here, some of the design requirements and initial concepts for an SBI system in ITER are presented based on previous results carried out with SBI systems on a number of tokamaks and stellarators around the world. Previous results using SBI systems installed by PPPL have injected boron particles from 5 µm–2 mm diameter at calibrated rates of 2–200 mg/s in real-time during plasma operation on AUG, DIII-D, EAST, KSTAR, LHD, TFTR, WEST, and W7-X, leading to improved wall conditions with reduced plasma impurity concentrations and radiated power and improved plasma performance. The boron is ionized in the plasma edge and then deposited on plasma-wetted surfaces. On AUG, EAST and WEST reduced tungsten sputtering sources were observed following several discharges with SBI. Extrapolation of these SBI results are presented to estimate the amount of boron needed for wall conditioning in ITER. Real-time SBI control requirements and plasma operation scenarios for ITER are also described.

36 MATERIALS SCIENCE↗

MSAT PIM and multipactor test program

The MSAT satellite system will provide telephone, fax and low data rate communication services to mobile users throughout North America. The space segment of the MSAT system must supply high radiated power densities on the ground to allow communication with small mobile terminals. Therefore, the high power handling requirement (multipactor, PIM and thermal dissipation) are very important performance parameters for mobile satellite communication systems. Large separate transmit and receive L-Band deployable reflectors are used on MSAT to reduce the risk of PIM (passive intermodulation). In addition, PIM and multipactor avoidance were major design drivers for the L-Band high power transmit output network and antenna. This paper provides an overview of the designs selected and the extensive qualification and verification program undertaken on MSAT to meet the challenging PIM and multipactor requirements. The test campaigns at component, sub-system and system levels and the associated test results are presented. The manufacturing and assembly approaches taken to allow the PIM and Multipactor to be met are also briefly described.

Patenaude, Y.↗

Fuel-Efficient Descent and Landing Guidance Logic for a Safe Lunar Touchdown

The landing of a crewed lunar lander on the surface of the Moon will be the climax of any Moon mission. At touchdown, the landing mechanism must absorb the load imparted on the lander due to the vertical component of the lander's touchdown velocity. Also, a large horizontal velocity must be avoided because it could cause the lander to tip over, risking the life of the crew. To be conservative, the worst-case lander's touchdown velocity is always assumed in designing the landing mechanism, making it very heavy. Fuel-optimal guidance algorithms for soft planetary landing have been studied extensively. In most of these studies, the lander is constrained to touchdown with zero velocity. With bounds imposed on the magnitude of the engine thrust, the optimal control solutions typically have a "bang-bang" thrust profile: the thrust magnitude "bangs" instantaneously between its maximum and minimum magnitudes. But the descent engine might not be able to throttle between its extremes instantaneously. There is also a concern about the acceptability of "bang-bang" control to the crew. In our study, the optimal control of a lander is formulated with a cost function that penalizes both the touchdown velocity and the fuel cost of the descent engine. In this formulation, there is not a requirement to achieve a zero touchdown velocity. Only a touchdown velocity that is consistent with the capability of the landing gear design is required. Also, since the nominal throttle level for the terminal descent sub-phase is well below the peak engine thrust, no bound on the engine thrust is used in our formulated problem. Instead of bangbang type solution, the optimal thrust generated is a continuous function of time. With this formulation, we can easily derive analytical expressions for the optimal thrust vector, touchdown velocity components, and other system variables. These expressions provide insights into the "physics" of the optimal landing and terminal descent maneuver. These insights could help engineers to achieve a better "balance" between the conflicting needs of achieving a safe touchdown velocity, a low-weight landing mechanism, low engine fuel cost, and other design goals. In comparing the computed optimal control results with the preflight landing trajectory design of the Apollo-11 mission, we noted interesting similarities between the two missions.

guidance logic↗

Launch COLA Operations: An Examination of Data Products, Procedures, and Thresholds

NASA GSFC and KSC, acting in response to headquarters NASA direction, performed a year-long study of launch collision avoidance (LCOLA) operations in order to determine and recommend best risk assessment and mitigation practices. The following condenses the findings and recommendations of the study into one short summary, a more expanded version of which appears as Section 10.

Launch COLA Operations: Revision A (12 JAN 2014)↗

OSIRIS-REx Conjunction Screenings: Earth Gravity Assist and Earth Return Analysis and Results

The NASA OSIRIS-REx asteroid sample return mission performed an Earth gravity assist on September 22, 2017, and returned to Earth to drop off the sample on September 24, 2023. In each case, the NASA Conjunction Assessment Risk Analysis (CARA) team screened the OSIRIS-REx trajectories against the satellite catalog in search of high-risk close approaches. This paper describes the preparation for collision avoidance and screening results, along with lessons learned, providing a baseline for support of future missions in this category, particularly as space traffic around the Earth and in cis-lunar space continues to rapidly expand.

Dolan E. Highsmith↗