Search NASA⌕ Search

SEARCH · Search NASA

Results for “Documented Safety Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Root Cause Correlation Analysis of Software Failures via Orthogonal Defect Classification and Natural Language Processing

Systems theoretic process analysis (STPA) is becoming an increasingly popular technique to assess how complex digital software systems can fail. Rather than defining failures by their observable failure events, which may be sparse especially for safety rated nuclear digital instrumentation and control systems (DI&C), failures are defined as postulated unsafe actions under specific contextual conditions. This permits a top-down analysis of system hazards and identifies whether imposed constraints and requirements can sufficiently address undesirable hazards. However, STPA is a qualitative approach at identifying inadequacies in the development process and cannot currently be used to quantify unsafe action likelihoods for probabilistic risk assessment. Therefore, in this work, we examine the root causes of software failure and explore whether a consistent correlation can be linked to specific unsafe action classes. We implement Lbl2Vec, an unsupervised document classification and retrieval algorithm, on a database of 4,096 software defect reports acquired from various open-source software systems. By analyzing sentence structure, embedded labels, and word vectors, we show that certain defect types positively correlate to specific unsafe action classes over others. The correlations developed can be used to estimate the failure probability of safety intended DI&C systems which provides a licensing basis for nuclear plant modernization efforts.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Range Flight Safety Requirements

The purpose of this NASA Technical Standard is to provide the technical requirements for the NPR 8715.5, Range Flight Safety Program, in regards to protection of the public, the NASA workforce, and property as it pertains to risk analysis, Flight Safety Systems (FSS), and range flight operations. This standard is approved for use by NASA Headquarters and NASA Centers, including Component Facilities and Technical and Service Support Centers, and may be cited in contract, program, and other Agency documents as a technical requirement. This standard may also apply to the Jet Propulsion Laboratory or to other contractors, grant recipients, or parties to agreements to the extent specified or referenced in their contracts, grants, or agreements, when these organizations conduct or participate in missions that involve range flight operations as defined by NPR 8715.5.1.2.2 In this standard, all mandatory actions (i.e., requirements) are denoted by statements containing the term “shall.”1.3 TailoringTailoring of this standard for application to a specific program or project shall be formally documented as part of program or project requirements and approved by the responsible Technical Authority in accordance with NPR 8715.3, NASA General Safety Program Requirements.

Flight↗

Root Cause Correlation Analysis of Software Failures via Orthogonal Defect Classification and Natural Language Processing

Systems theoretic process analysis (STPA) is becoming an increasingly popular technique to assess how complex digital software systems can fail. Rather than defining failures by their observable failure events, which may be sparse especially for safety rated nuclear digital instrumentation and control systems (DI&C), failures are defined as postulated unsafe actions under specific contextual conditions. This permits a top-down analysis of system hazards and identifies whether imposed constraints and requirements can sufficiently address undesirable hazards. However, STPA is a qualitative approach at identifying inadequacies in the development process and cannot currently be used to quantify unsafe action likelihoods for probabilistic risk assessment. Therefore, in this work, we examine the root causes of software failure and explore whether a consistent correlation can be linked to specific unsafe action classes. We implement Lbl2Vec, an unsupervised document classification and retrieval algorithm, on a database of 4,096 software defect reports acquired from various open-source software systems. By analyzing sentence structure, embedded labels, and word vectors, we show that certain defect types positively correlate to specific unsafe action classes over others. The correlations developed can be used to estimate the failure probability of safety intended DI&C systems which provides a licensing basis for nuclear plant modernization efforts.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Updated Commercial Aviation Non-Airport Crash Density Values Using Data Obtained from the U.S. National Transportation Safety Board for 2000 through 2019

This report documents the calculation of the commercial aviation (CA) non-airport crash density for Air Route Traffic Control Center (ARTCC) area associated with the Contiguous United States (CONUS) using the methodology outlined in the Department of Energy (DOE) Standard 3014-2006, Accident Analysis for Aircraft Crash Into Hazardous Facilities. For analytical purposes, the CA aircraft fleet is comprised of aircraft engaged in operations under Title 14 of the Code of Federal Regulations (CFR) Part 121 (i.e., Air Carrier) and Part 135 (i.e., Air Taxi).

99 GENERAL AND MISCELLANEOUS↗

Safer Liquid Natural Gas

After the disaster of Staten Island in 1973 where 40 people were killed repairing a liquid natural gas storage tank, the New York Fire Commissioner requested NASA's help in drawing up a comprehensive plan to cover the design, construction, and operation of liquid natural gas facilities. Two programs are underway. The first transfers comprehensive risk management techniques and procedures which take the form of an instruction document that includes determining liquid-gas risks through engineering analysis and tests, controlling these risks by setting up redundant fail safe techniques, and establishing criteria calling for decisions that eliminate or accept certain risks. The second program prepares a liquid gas safety manual (the first of its kind).

Source record↗

Analysis of Phoenix Anomalies and IV & V Findings Applied to the GRAIL Mission

NASA IV&V was established in 1993 to improve safety and cost-effectiveness of mission critical software. Since its inception the tools and strategies employed by IV&V have evolved. This paper examines how lessons learned from the Phoenix project were developed and applied to the GRAIL project. Shortly after selection, the GRAIL project initiated a review of the issues documented by IV&V for Phoenix. The motivation was twofold: the learn as much as possible about the types of issues that arose from the flight software product line slated for use on GRAIL, and to identify opportunities for improving the effectiveness of IV&V on GRAIL. The IV&V Facility provided a database dump containing 893 issues. These were categorized into 16 bins, and then analyzed according to whether the project responded by changing the affected artifacts or using as-is. The results of this analysis were compared to a similar assessment of post-launch anomalies documented by the project. Results of the analysis were discussed with the IV&V team assigned to GRAIL. These discussions led to changes in the way both the project and IV&V approached the IV&V task, and improved the efficiency of the activity.

Larson, Steve↗

NASA Fastener Procurement, Receiving Inspection, and Storage Practices for NASA Mission Hardware

This document establishes minimum requirements for supply chain risk management, procurement, receiving inspection, testing, traceability management, and storage practices for fasteners used in NASA mission hardware. This document does not contain fastener requirements pertaining to design or design analysis; design and design analysis requirements are contained in NASA-STD-5020, Requirements for Threaded Fastening Systems in Spaceflight Hardware.

Safety and Mission Assurance↗

System Guidelines for EMC Safety-Critical Circuits: Design, Selection, and Margin Demonstration

Demonstration of required safety margins on critical electrical/electronic circuits in large complex systems has become an implementation and cost problem. These margins are the difference between the activation level of the circuit and the electrical noise on the circuit in the actual operating environment. This document discusses the origin of the requirement and gives a detailed process flow for the identification of the system electromagnetic compatibility (EMC) critical circuit list. The process flow discusses the roles of engineering disciplines such as systems engineering, safety, and EMC. Design and analysis guidelines are provided to assist the designer in assuring the system design has a high probability of meeting the margin requirements. Examples of approaches used on actual programs (Skylab and Space Shuttle Solid Rocket Booster) are provided to show how variations of the approach can be used successfully.

Lawton, R. M.↗

TPSAS-NF1676L-32920-DND

In June 2019, a full-scale crash test of a Fokker F28 Fellowship aircraft will be conducted at NASA Langley Research Center?s Landing and Impact Research (LandIR) Facility. The F28 is a high-performance twin-turbo fan narrow-body aircraft with seating in a 3+2 configuration. The MK4000 variant, used in this test, is capable of carrying up to 85 passengers on medium range routes. The F28 was first type certified by the Federal Aviation Administration (FAA) in 1969 and now the majority of the F28 fleet has retired from service in the United States. In 2016, the FAA and NASA Langley Research Center (LaRC) signed an interagency agreement for conducting a research program to obtain test data that will support the development of airframe level crash requirements for transport category airplanes [1]. The objectives of the full-scale crash test can be divided into six categories: (1) To compare and contrast responses in identical aircraft undergoing vertical only to combined vertical and horizontal loading conditions, (2) To examine the effects of horizontal loading on aircraft structure during a crash event, (3) To generate data for the use in calibration of computer modelling efforts, (4) To generate data from onboard Anthropomorphic Test Devices (ATDs) for the evaluation of injury, (5) To obtain data from experimental seats, and (6) To obtain data from new and novel ATD designs including Warrior Injury Assessment MANikin (WIAMan) [2], Test device for Human Occupant Response (THOR), and other newly developed child ATDs. The focus of this presentation will be to document finite element model development of the full-scale F28 aircraft and to present preliminary test-analysis predictions. NASA obtained the full-scale F28 aircraft, plus three fuselage sections and two sets of wings with funding through the NASA Aviation Safety Program in 1998. In addition to the hardware, NASA purchased a full NASTRAN model of the airframe that had been developed by the Dutch manufacturer, Fokker. Beginning in 2016, the NASTRAN model was converted to LS-DYNA? [4, 5] format and modified by combining parts, adding missing parts of internal structure, and including ballast for loading weights, etc. It contains: 89,223 nodes; 24,065 beam elements; 55,404 shell elements; 29,044 solid elements; 740 parts; 80 material definitions; and, 46 Constrained Nodal Rigid Bodies (CNRBs). The aircraft model will be executed in LSDYNA to simulate the test article impact onto a 2-ft.-high bed of soil under combined velocity conditions of 70-ft/s forward and 30-ft/s vertical velocity. Pre-test simulation predictions will be generated and correlated with test data.

Karen E Jackson↗

HEU Metal Delayed Critical Experiments with 10 to 19 Inch Thick Graphite Reflectors

Approximately 100 graphite-reflected highly enriched uranium (HEU, 93.14 wt % 235 U) metal annular and cylindrical critical experiments were performed in the early 1960s at the Oak Ridge Critical Experiments Facility (ORCEF). This report presents details from experiment logbooks, experimental data sheets and the author's memory for 44 HEU metal (93.14 wt % 235 U) critical assemblies with graphite reflectors varying from 10 to 19 in. thick, outside diameters varying from 7 to 15 in., inside diameters varying from 7 to 13 in. and critical HEU metal masses varying from 20.4 to 69.0 kg. The data from the 44 experiments described in this report are acceptable for use as criticality safety benchmark experiments for the International Criticality Safety Evaluation Program (ICSBEP) once the uncertainty analysis on the measured k eff is completed. Based on previous ICSBEP benchmarks with this HEU metal at ORCEF, the uncertainties in the measured k eff are expected to be as low as ±0.0004. Preparation of this report is part of an effort at Oak Ridge National Laboratory (ORNL) to document more than 15 undocumented series of critical and subcritical experiments enumerated in Critical and Subcritical NEA Benchmark Possibilities for Measurements at ORCEF and Other US DOE Facilities (Mihalzo, ORNL/TM-2019/1188, 2019) and performed by ORNL at ORCEF and other US Department of Energy critical experiments facilities. More than 500 operational days of critical facility time were used, not including setup and dismantlement time. This documentation for a part of one series of graphite reflected highly enriched uranium metal critical experiments, that used 50 operational days of ORCEF time, was performed using funding received from the DOE Office of Nuclear Energy’s Nuclear Energy University Programs at the University of Tennessee Nuclear Engineering Department. This documentation was also supported by the Nuclear Criticality, Radiation Transport, and Safety programs at ORNL.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Milestone 4: Test plan for Reusable Hydrogen Composite Tank System (RHCTS). Task 3: Composite tank materials

This document is the detailed test plan for the series of tests enumerated in the preceding section. The purpose of this plan is to present the test objectives, test parameters and procedures, expected performance and data analysis plans, criteria for success, test schedules, and related safety provisions and to describe the test articles, test instrumentation, and test facility requirements. Initial testing will be performed to screen four composite materials for suitability for SSTO LH2 tank loads and environmental conditions. The laminates for this testing will be fabricated by fiber placement, which is the manufacturing approach identified as baseline for the tank wall. Even though hand layup will be involved in fabricating many of the internal structural members of the tank, no hand-layup laminates will be evaluated in the screening or subsequent characterization testing. This decision is based on the understanding that mechanical properties measured for hand-layup material should be at least equivalent to properties measured for fiber-placed material, so that the latter should provide no less than a conservative approximation of the former. A single material will be downselected from these screening tests. This material will be subsequently characterized for impact-damage tolerance and durability under conditions of mechanical and thermal cycling, and to establish a preliminary design database to support ongoing analysis. Next, testing will be performed on critical structural elements fabricated from the selected material. Finally, the 8-foot diameter tank article, containing the critical structural features of the full-scale tank, will be fabricated by fiber placement and tested to verify its structural integrity and LH2 containment.

Greenberg, H. S.↗

Review of Exploration Systems Development (ESD) Integrated Hazard Development Process: Appendices - Volume 1

The Chief Engineer of the Exploration Systems Development (ESD) Office requested that the NASA Engineering and Safety Center (NESC) perform an independent assessment of the ESD's integrated hazard development process. The focus of the assessment was to review the integrated hazard analysis (IHA) process and identify any gaps/improvements in the process (e.g., missed causes, cause tree completeness, missed hazards). This document contains the outcome of the NESC assessment.

Smiles, Michael D.↗

Review of Exploration Systems Development (ESD) Integrated Hazard Development Process: Volume 2 - Appendices

The Chief Engineer of the Exploration Systems Development (ESD) Office requested that the NASA Engineering and Safety Center (NESC) perform an independent assessment of the ESD's integrated hazard development process. The focus of the assessment was to review the integrated hazard analysis (IHA) process and identify any gaps/improvements in the process (e.g. missed causes, cause tree completeness, missed hazards). This document contains the outcome of the NESC assessment.

Smiles, Michael D.↗

Recommended techniques for effective maintainability. A continuous improvement initiative of the NASA Reliability and Maintainability Steering Committee

This manual presents a series of recommended techniques that can increase overall operational effectiveness of both flight and ground based NASA systems. It provides a set of tools that minimizes risk associated with: (1) restoring failed functions (both ground and flight based); (2) conducting complex and highly visible maintenance operations; and (3) sustaining a technical capability to support the NASA mission using aging equipment or facilities. It considers (1) program management - key elements of an effective maintainability effort; (2) design and development - techniques that have benefited previous programs; (3) analysis and test - quantitative and qualitative analysis processes and testing techniques; and (4) operations and operational design techniques that address NASA field experience. This document is a valuable resource for continuous improvement ideas in executing the systems development process in accordance with the NASA 'better, faster, smaller, and cheaper' goal without compromising safety.

Source record↗

Probabilistic Survivability Versus Time Modeling

This technical paper documents Kennedy Space Centers Independent Assessment team work completed on three assessments for the Ground Systems Development and Operations (GSDO) Program to assist the Chief Safety and Mission Assurance Officer (CSO) and GSDO management during key programmatic reviews. The assessments provided the GSDO Program with an analysis of how egress time affects the likelihood of astronaut and worker survival during an emergency. For each assessment, the team developed probability distributions for hazard scenarios to address statistical uncertainty, resulting in survivability plots over time. The first assessment developed a mathematical model of probabilistic survivability versus time to reach a safe location using an ideal Emergency Egress System at Launch Complex 39B (LC-39B); the second used the first model to evaluate and compare various egress systems under consideration at LC-39B. The third used a modified LC-39B model to determine if a specific hazard decreased survivability more rapidly than other events during flight hardware processing in Kennedys Vehicle Assembly Building (VAB).Based on the composite survivability versus time graphs from the first two assessments, there was a soft knee in the Figure of Merit graphs at eight minutes (ten minutes after egress ordered). Thus, the graphs illustrated to the decision makers that the final emergency egress design selected should have the capability of transporting the flight crew from the top of LC 39B to a safe location in eight minutes or less. Results for the third assessment were dominated by hazards that were classified as instantaneous in nature (e.g. stacking mishaps) and therefore had no effect on survivability vs time to egress the VAB. VAB emergency scenarios that degraded over time (e.g. fire) produced survivability vs time graphs that were line with aerospace industry norms.

Joyner, James J., Sr.↗

The NASA Jitter Handbook Development Activity: A Multidisciplinary Collaborative Effort

Spaceflight missions hosting high-performance vibration-sensitive optical sensor payloads with stringent pointing stability requirements are especially challenged in the areas of predicting, managing, controlling, and testing spacecraft line-of-sight (LoS) jitter. The community recognizes that this is a formidable multidisciplinary engineering task. However, while some textbooks and references in the aerospace literature may touch on the subject of jitter, important details of specific flight proven methodologies and techniques used by today’s jitter engineering practitioners are not readily accessible. There is no know engineering reference document with guidelines and best practices for managing and mitigating space-craft jitter. To fill this knowledge gap the NASA Engineering and Safety Center (NESC) has undertaken the task of developing a NASA Jitter Handbook which would include lessons learned and best practices for design, analysis, and test, along with operational guidelines to mitigate jitter. In this paper the plan for this handbook development will be described along with the envisioned handbook framework, key NASA stakeholders, and potential envisioned jitter engineering case studies. Opportunities exist technical collaboration on this handbook with NASA-external organizations.

Christopher D'Souza↗

Space-Shielding Radiation Dosage Code Evaluation Phase 2: SHIELDOSE-2 Radiation-Assessment Code

Radiation-transport codes or radiation-analysis tools are used in the spacecraft-design community to define and assess the local radiation levels. Among various radiation-transport/analysis tools available, SHIELDOSE-2 is commonly used in the early spacecraft-design phases because it has been established that it provides reasonably reliable results with relatively rapid computation time. The NASA Engineering and Safety Center initiated a two-phased study: (1) to better understand and document the SHIELDOSE-2 code capabilities and limitations, and (2) to identify alternative tools to use for cases where SHIELDOSE-2 is not applicable. This report provides a summary of the Phase 2 study.

SHIELDOSE-2↗

Space Transportation System Liftoff Debris Mitigation Process Overview

Liftoff debris is a top risk to the Space Shuttle Vehicle. To manage the Liftoff debris risk, the Space Shuttle Program created a team with in the Propulsion Systems Engineering & Integration Office. The Shutt le Liftoff Debris Team harnesses the Systems Engineering process to i dentify, assess, mitigate, and communicate the Liftoff debris risk. T he Liftoff Debris Team leverages off the technical knowledge and expe rtise of engineering groups across multiple NASA centers to integrate total system solutions. These solutions connect the hardware and ana lyses to identify and characterize debris sources and zones contribut ing to the Liftoff debris risk. The solutions incorporate analyses sp anning: the definition and modeling of natural and induced environmen ts; material characterizations; statistical trending analyses, imager y based trajectory analyses; debris transport analyses, and risk asse ssments. The verification and validation of these analyses are bound by conservative assumptions and anchored by testing and flight data. The Liftoff debris risk mitigation is managed through vigilant collab orative work between the Liftoff Debris Team and Launch Pad Operation s personnel and through the management of requirements, interfaces, r isk documentation, configurations, and technical data. Furthermore, o n day of launch, decision analysis is used to apply the wealth of ana lyses to case specific identified risks. This presentation describes how the Liftoff Debris Team applies Systems Engineering in their proce sses to mitigate risk and improve the safety of the Space Shuttle Veh icle.

Mitchell, Michael↗