Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety Case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Assess/Mitigate Risk through the Use of Computer-Aided Software Engineering (CASE) Tools

The NASA Engineering and Safety Center (NESC) was requested to perform an independent assessment of the mitigation of the Constellation Program (CxP) Risk 4421 through the use of computer-aided software engineering (CASE) tools. With the cancellation of the CxP, the assessment goals were modified to capture lessons learned and best practices in the use of CASE tools. The assessment goal was to prepare the next program for the use of these CASE tools. The outcome of the assessment is contained in this document.

Aguilar, Michael L.↗

Safety Risk Knowledge Elicitation in Support of Aeronautical R and D Portfolio Management: A Case Study

Aviation is a problem domain characterized by a high level of system complexity and uncertainty. Safety risk analysis in such a domain is especially challenging given the multitude of operations and diverse stakeholders. The Federal Aviation Administration (FAA) projects that by 2025 air traffic will increase by more than 50 percent with 1.1 billion passengers a year and more than 85,000 flights every 24 hours contributing to further delays and congestion in the sky (Circelli, 2011). This increased system complexity necessitates the application of structured safety risk analysis methods to understand and eliminate where possible, reduce, and/or mitigate risk factors. The use of expert judgments for probabilistic safety analysis in such a complex domain is necessary especially when evaluating the projected impact of future technologies, capabilities, and procedures for which current operational data may be scarce. Management of an R&D product portfolio in such a dynamic domain needs a systematic process to elicit these expert judgments, process modeling results, perform sensitivity analyses, and efficiently communicate the modeling results to decision makers. In this paper a case study focusing on the application of an R&D portfolio of aeronautical products intended to mitigate aircraft Loss of Control (LOC) accidents is presented. In particular, the knowledge elicitation process with three subject matter experts who contributed to the safety risk model is emphasized. The application and refinement of a verbal-numerical scale for conditional probability elicitation in a Bayesian Belief Network (BBN) is discussed. The preliminary findings from this initial step of a three-part elicitation are important to project management practitioners as they illustrate the vital contribution of systematic knowledge elicitation in complex domains.

Shih, Ann T.↗

Perform Design Support with MCNP for New Measurements

This report incorporates our work carried out during our 5-month internship at LANL under an internship agreement with EAMEA (École des Applications Militaires de l’Énergie Atomique). After outlining the context in which we worked, we present our work as aid to modeling and predicting the neutronic behavior of nuclear systems, with a view to carrying out criticality experiments qualifying the MCNP code as part of innovative projects. Fourth generation reactors will enable to tackle a lot of issues such as environmental crisis, affordable energy access, and nuclear waste management. They seem to be one of the keys for a sustainable future. Most of the projects that emerge nowadays include the use of HALEU (high assay low enriched uranium) or MOX recycled fuels. Our projects are part of this dynamic and addresses concrete scientific research issues in the nuclear field. Studies of HALEU package are essential to anticipate the need, therefore the Optimus L (OPTImal Modular Universal Shipping cask technology) designed by NAC (Nuclear Assurance Corporation) international but filled with 20 % enriched uranium dioxide (UO 2 ) will be studied to support safe transportation. However, it seems there is no benchmark with a high correlation with the combination of this fuel and this package to validate MCNP simulations. As such, the study will focus on the development of new criticality safety benchmarks for this case. On the other hand, there is a great need for critical benchmarks in the intermediate energy range with MOX fuel. An IER (Integral Experiment Request) has then be requested to answer it through a partnership between French institution IRSN and U.S. Department of Energy's Nuclear Criticality Safety Program (NCSP). This experience planned for 2025 requires to gather calculated data through a MCNP model to be realized safely. Finally, a presentation of our one-week experience at the DAF as part of our discovery of criticality experiments will be introduced in Appendix 1: Week at the DAF (Device Assembly Facility)

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

A Hybrid Method of Assurance Cases and Testing for Improved Confidence in Autonomous Space Systems

Autonomous systems react intelligently to their environments, making them capable of handling many possible conditions, but challenging to test. We are investigating a new test development method that aims to maximize the confidence to be achieved by combining Assurance Cases with High Throughput Testing (HTT). Assurance Cases, developed for safety-critical systems, are a rigorous argument that the system satisfies a property (e.g., the Mars rover will not tip over during a traverse). They integrate testing, analysis, and environmental and operational assumptions, from which the set of conditions that testing must cover is determined. In our method, information from the Assurance Case is used to determine the test coverage needed, and then input to HTT to generate the minimal test suites needed to provide that coverage.

Huntsberger, Terry↗

The procedure safety system

Telerobotic operations, whether under autonomous or teleoperated control, require a much more sophisticated safety system than that needed for most industrial applications. Industrial robots generally perform very repetitive tasks in a controlled, static environment. The safety system in that case can be as simple as shutting down the robot if a human enters the work area, or even simply building a cage around the work space. Telerobotic operations, however, will take place in a dynamic, sometimes unpredictable environment, and will involve complicated and perhaps unrehearsed manipulations. This creates a much greater potential for damage to the robot or objects in its vicinity. The Procedural Safety System (PSS) collects data from external sensors and the robot, then processes it through an expert system shell to determine whether an unsafe condition or potential unsafe condition exists. Unsafe conditions could include exceeding velocity, acceleration, torque, or joint limits, imminent collision, exceeding temperature limits, and robot or sensor component failure. If a threat to safety exists, the operator is warned. If the threat is serious enough, the robot is halted. The PSS, therefore, uses expert system technology to enhance safety thus reducing operator work load, allowing him/her to focus on performing the task at hand without the distraction of worrying about violating safety criteria.

Obrien, Maureen E.↗

Flight Test Safety Considerations for Airborne Science Aircraft

Most of the scientific community that require scientific data or scientific measurements from aircraft do not understand the full implications of putting certain equipment on board high performance aircraft. It is the duty of the NASA Flight Operations personnel to ensure that all Principal Investigators who are given space on NASA flight research aircraft, comply with stringent safety requirements. The attitude of the experienced Flight operations personnel given this duty has been and remains one of insuring that the PI's experiment is allowed to be placed on the aircraft (facility) and can be operated in a manner that will obtain the expected data. This is sometimes a challenge. The success that NASA has in this regard is due to the fact that it is its own authority under public law, to certify its aircraft as airworthy. Airworthiness, fitness for flight, is a complex issue which pulls together all aspects of configuration management, engineering, quality, and flight safety. It is often the case at each NASA Center that is conducting airborne research, that unique solutions to some challenging safety issues are required. These solutions permit NASA to do things that would not be permitted by the Department of Transportation. This paper will use examples of various flight research configurations to show the necessity of a disciplined process leading up to flight test and mission implementation. All new configurations required engineering flight test but many, as noted in this paper, require that the modifications be flight tested to insure that they do not negatively impact on any part of the aircraft operational profiles. The success of these processes has been demonstrated over many years and NASA has accommodated experimental packages that cannot be flown on any other aircraft.

Reynolds, Randolph S.↗

Safety Assessment of a Machine Learning-Based Aircraft Emergency Braking System: A Case Study

Machine Learning (ML) is revolutionizing many technological fields, but its use in aviation remains restricted due to stringent certification requirements. Efforts by the aviation community to establish standards for certifying ML-based systems are progressing, yet challenges persist, particularly with safety assessment methods for ML-based systems. This research addresses these challenges through a case study of an autonomous emergency braking system utilizing a computer vision deep neural network (DNN). We demonstrate a safety assessment process tailored to ML-specific concerns, such as low integrity and performance variability in quantitative safety analysis. This study can serve as an illustrative example to facilitate the discussion and convergence on certification aspects for ML-based systems within the aviation community.

Safety certification↗

Gear-tooth fatigue-strength estimates

Method helps to determine fatigue damage and safety margins for case-hardened gear teeth. It can help designers determine rapidly these important factors.

Brinkley, W.↗

Development and validation of techniques for improving software dependability

A collection of document abstracts are presented on the topic of improving software dependability through NASA grant NAG-1-1123. Specific topics include: modeling of error detection; software inspection; test cases; Magnetic Stereotaxis System safety specifications and fault trees; and injection of synthetic faults into software.

Knight, John C.↗

Structural design considerations for the Space Infrared Telescope Facility

To assess the design feasibility of the Space Infrared Telescope Facility (SIRTF) and to identify parameters that might impose constraints on performance such as frequencies of vibration, structural concepts for both the telescope and spacecraft are developed and evaluated. Trade studies of key design features are carried out using FEM and analysis. In most cases, the margin of safety was greater than 0.50. An example of stress in the octagonal equipment bus panels is shown. The strap-supported mass is predicted to deflect 6 mm relative to the outer shell when subjected to 8.0 G in the X direction, and to deflect about 5 mm in the Y and Z directions when subjected to 10.0 G. Deflections for the top of the solar panel are predicted to be about 35 mm when subjected to the 10.0 G quasi-static load in the Z direction. The liquid helium tank, thermal isolation, and primary mirror and mount are discussed.

Macneal, Paul D.↗

Closing the Certification Gaps in Adaptive Flight Control Software

Over the last five decades, extensive research has been performed to design and develop adaptive control systems for aerospace systems and other applications where the capability to change controller behavior at different operating conditions is highly desirable. Although adaptive flight control has been partially implemented through the use of gain-scheduled control, truly adaptive control systems using learning algorithms and on-line system identification methods have not seen commercial deployment. The reason is that the certification process for adaptive flight control software for use in national air space has not yet been decided. The purpose of this paper is to examine the gaps between the state-of-the-art methodologies used to certify conventional (i.e., non-adaptive) flight control system software and what will likely to be needed to satisfy FAA airworthiness requirements. These gaps include the lack of a certification plan or process guide, the need to develop verification and validation tools and methodologies to analyze adaptive controller stability and convergence, as well as the development of metrics to evaluate adaptive controller performance at off-nominal flight conditions. This paper presents the major certification gap areas, a description of the current state of the verification methodologies, and what further research efforts will likely be needed to close the gaps remaining in current certification practices. It is envisioned that closing the gap will require certain advances in simulation methods, comprehensive methods to determine learning algorithm stability and convergence rates, the development of performance metrics for adaptive controllers, the application of formal software assurance methods, the application of on-line software monitoring tools for adaptive controller health assessment, and the development of a certification case for adaptive system safety of flight.

Jacklin, Stephen A.↗

Space Shuttle Orbiter Drag Chute Summary

This paper summarizes the development history and technical highlights of the Space Shuttle Orbiter Drag Chute Program. Data and references are given on the design, development, and testing of the system, plus several interesting operational issues and solutions. The last Shuttle flight was completed in 2011 and all the Orbiters have now become museum pieces. Before all the data from system development and the 86 Orbiter Drag Chute (ODC) operational landings is lost or forgotten, it may be useful to summarize it here and to identify data sources for future reference. Much has been written about various aspects of the program, and this summary has attempted to cite many such references to make available more detailed information. The ODC program was a high-visibility NASA program that afforded the opportunity to thoroughly engineer and test the chute system, far beyond so many of today s tight-budget programs. So the ODC program was extremely informative--it provided a wide scope of information including protective door jettison issues and solutions, wind tunnel data and analyses on chute stability and drag behind a huge and rather blunt forebody, component and system reuse, and chute cleaning methods. Technology and data created have aided several current and past parachute programs, and will continue to do so in the future. The original Orbiter preliminary design included a drag parachute-- it was deleted early to save weight. But after the 1987 Challenger accident and during the program redefinition phase that followed, Astronaut John Young presented a strong case for enhancing landing safety by adding nosegear steering, brake improvements, and reviving the drag chute.

Lowry, Charles H.↗

Concept of Operations for a Prospective "Proving Ground" in the Lunar Vicinity

NASA is studying a "Proving Ground" near the Moon to conduct human space exploration missions in preparation for future flights to Mars. This paper describes a concept of operations ("conops") for activities in the Proving Ground, focusing on the construction and use of a mobile Cislunar Transit Habitat capable of months-long excursions within and beyond the Earth-Moon system. Key elements in the conops include the Orion spacecraft (with mission kits for docking and other specialized operations) and the Space Launch System heavy-lift rocket. Potential additions include commercial launch vehicles and logistics carriers, solar electric propulsion stages to move elements between different orbits and eventually take them on excursions to deep space, a node module with multiple docking ports, habitation and life support blocks, and international robotic and piloted lunar landers. The landers might include reusable ascent modules which could remain docked to in-space elements between lunar sorties. The architecture will include infrastructure for launch preparation, communication, mission control, and range safety. The conops describes "case studies" of notional missions chosen to guide the design of the architecture and its elements. One such mission is the delivery of a ~10-ton pressurized element, co-manifested with an Orion on a Block 1B Space Launch System rocket, to the Proving Ground. With a large solar electric propulsion stage, the architecture could enable a year-long mission to land humans on a near-Earth asteroid. In the last case, after returning to near-lunar space, two of the asteroid explorers could join two crewmembers freshly arrived from Earth for a Moon landing, helping to safely quantify the risk of landing deconditioned crews on Mars. The conops also discusses aborts and contingency operations. Early return to Earth may be difficult, especially during later Proving Ground missions. While adding risk, limited-abort conditions provide needed practice for Mars, from which early return is likely to be impossible.

Love, Stanley G.↗

The Cognitive Challenges of Flying a Remotely Piloted Aircraft

A large variety of Remotely Piloted Aircraft (RPA) designs are currently in production or in development. These aircraft range from small electric quadcopters that are flown close to the ground within visual range of the operator, to larger systems capable of extended flight in airspace shared with conventional aircraft. Before RPA can operate routinely and safely in civilian airspace, we need to understand the unique human factors associated with these aircraft. The task of flying an RPA in civilian airspace involves challenges common to the operation of other highly-automated systems, but also introduces new considerations for pilot perception, decision-making, and action execution. RPA pilots participated in focus groups where they were asked to recall critical incidents that either presented a threat to safety, or highlighted a case where the pilot contributed to system resilience or mission success. Ninety incidents were gathered from focus-groups. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies. Some of these concerns have received significant attention in the literature, or are analogous to human factors of manned aircraft. The presentation will focus on issues that are poorly understood, and have not yet been the subject of extensive human factors study. Although many of the reported incidents were related to pilot error, the participants also provided examples of the positive contribution that humans make to the operation of highly-automated systems.

remote pilot station↗

The Human Challenges of Remotely Piloted Aircraft Systems

Remotely Piloted Aircraft (RPA) range from small electric quadcopters that are flown close to the ground within visual range of the operator, to larger systems capable of extended flight in airspace shared with conventional aircraft. Before RPA can operate routinely and safely in civilian airspace, we need to understand the unique human factors associated with these aircraft. RPA pilots participated in focus groups where they were asked to recall critical incidents that either presented a threat to safety, or highlighted a case where the pilot contributed to system resilience or mission success. Ninety incidents were gathered from focus-groups. Human factor issues included the impact of reduced sensory cues, traffic separation in the absence of an out-the-window view, control latencies, vigilance during monotonous and ultra-long endurance flights, control station design considerations, transfer of control between control stations, the management of lost link procedures, and decision-making during emergencies. Some of these concerns have received significant attention in the literature, or are analogous to human factors of manned aircraft. Although many of the reported incidents were related to pilot error, the participants also provided examples of the positive contribution that humans make to the operation of highly-automated systems.

Hobbs, Alan↗

Detection and Tracking of Aircraft in the Far-Field from Small Unmanned Aerial Systems

Onboard far-field aircraft detection is needed for safe non-cooperative traffic mitigation in autonomous small Unmanned Aerial System (sUAS) operations. Machine vision systems, based on standard optics and visible light detectors, possess the ideal size, weight, and power (SWaP) requirements for sUAS. This work presents the design and analysis of a novel aircraft detection and tracking pipeline based on optical sensing alone. Key contributions of the work include a refined range inequality model based on sensing and detection with FAA well-clear separation assurance distances between aircraft in mind, a detector fusion method to maximize the benefit of two image detectors, and a comparative analysis of Linear Kalman-filtering and Extended Kalman-filtering to seek optimal tracking performance. The pipeline is evaluated offline against multiple intruder platforms, using two types of flight encounters: multirotor sUAS vs. fixed-wing sUAS and multirotor sUAS vs. general aviation(GA)plane. Analysis is restricted to the rate-limiting head-on and departing collision volume cases vertically separated for safety. Results indicate that it is feasible to use the proposed optical spatial-temporal tracking algorithm to provide adequate alerting time to prevent penetration of well-clear separation volumes for both sUAS and GA aircraft.

Unmanned Aerial System↗

A postprocessor system for the data reduction and post analysis of NASTRAN results

NASTRAN analysis results are scanned to determine maximum and minimum displacements, forces and stresses. Allowables and margins of safety are computed, and in the case of multiple loading conditions, envelopes for displacements, forces, stresses and margins of safety are also produced for specified element sets. Graphical plots of the reduced or the regular NASTRAN results may be obtained superimposed either of a developed fuselage strip or on a projection of any specified part of the finite element model. The use of the data reduction, post analysis and graphical plotting capabilities provide the analyst with a fast and convenient tool for the study of NASTRAN analysis results and their presentation for project documentation.

Raibstein, A. I.↗