Search NASA⌕ Search

SEARCH · Search NASA

Results for “software risk”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

BioSentinel Avionics Design Approach with COTS Parts

This presentation focuses on ARC's avionics design approach using Commercial Off-The-Shelf (COTS) parts for high-risk, high-reward missions. Examples of ARC's past missions in small spacecraft, nano-satellites, and Class D payloads are highlighted, emphasizing the benefits of COTS, such as wider selections, faster development schedules, and lower costs. The challenges and limitations of traditional Qualified Parts List (QPL) approaches are discussed, along with observations from ARC missions, which show that design and workmanship issues are more significant than component failures. Mitigations for radiation risks associated with COTS are proposed, emphasizing risk awareness, proper software and hardware design, and careful parts selection. The success of ARC's 30+ projects using COTS over the past 17 years underscores its viability for high-risk missions.

BioSentinel↗

Vehicle Shield Optimization and Risk Assessment of Future NEO Missions

Future human space missions target far destinations such as Near Earth Objects (NEO) or Mars that require extended stay in hostile radiation environments in deep space. The continuous assessment of exploration vehicles is needed to iteratively optimize the designs for shielding protection and calculating the risks associated with such long missions. We use a predictive software capability that calculates the risks to humans inside a spacecraft. The software uses the CAD software Pro/Engineer and Fishbowl tool kit to quantify the radiation shielding properties of the spacecraft geometry by calculating the areal density seen at a certain point, dose point, inside the spacecraft. The shielding results are used by NASA-developed software, BRYNTRN, to quantify the organ doses received in a human body located in the vehicle in a possible solar particle events (SPE) during such prolonged space missions. The organ doses are used to quantify the risks posed on the astronauts' health and life using NASA Space Cancer Model software. An illustration of the shielding optimization and risk calculation on an exploration vehicle design suitable for a NEO mission is provided in this study. The vehicle capsule is made of aluminum shell, airlock with hydrogen-rich carbon composite material end caps. The capsule contains sets of racks that surround a working and living area. A water shelter is provided in the middle of the vehicle to enhance the shielding in case of SPE. The mass distribution is optimized to minimize radiation hotspots and an assessment of the risks associated with a NEO mission is calculated.

Nounu, Hatem, N.↗

Lessons Learned from Seven Space Shuttle Missions

Much can be learned from well-written descriptions of the technical and organizational factors that lead to an accident. Subsequent analysis by third parties of investigation reports and associated evidence collected during the investigations can lead to additional insight. Much can also be learned from documented close calls that do not result in loss of life or a spacecraft, such as the Mars Exploration Rover Spirit software anomaly, the SOHO mission interruption, and the NEAR burn anomaly. Seven space shuttle incidents fall into the latter category: Rendezvous Target Failure On STS-41B; Rendezvous Radar Anomaly and Trajectory Dispersion-STS-32 ;Rendezvous Lambert Targeting Anomaly-STS-49; Rendezvous Lambert Targeting Anomaly-STS-51; Zero Doppler Steering Maneuver Anomaly-STS-59; Excessive Propellant Consumption During Rendezvous-STS-69; Global Positioning System Receiver and Associated Shuttle Flight Software Anomalies-STS-91 Procedural work-arounds or software changes prevented them from threatening mission success. Extensive investigations, which included the independent recreation of the anomalies by multiple Shuttle Program organizations, were the key to determining the cause, accurately assessing risk, and identifying software and software process improvements. Lessons learned from these incidents not only validated long-standing operational best practices, but serve to promote discussion and mentoring among Program personnel and are applicable to future space flight programs.

Goodman, John↗

Software reliability through fault-avoidance and fault-tolerance

Strategies and tools for the testing, risk assessment and risk control of dependable software-based systems were developed. Part of this project consists of studies to enable the transfer of technology to industry, for example the risk management techniques for safety-concious systems. Theoretical investigations of Boolean and Relational Operator (BRO) testing strategy were conducted for condition-based testing. The Basic Graph Generation and Analysis tool (BGG) was extended to fully incorporate several variants of the BRO metric. Single- and multi-phase risk, coverage and time-based models are being developed to provide additional theoretical and empirical basis for estimation of the reliability and availability of large, highly dependable software. A model for software process and risk management was developed. The use of cause-effect graphing for software specification and validation was investigated. Lastly, advanced software fault-tolerance models were studied to provide alternatives and improvements in situations where simple software fault-tolerance strategies break down.

Vouk, Mladen A.↗

Projected Impact of Compositional Verification on Current and Future Aviation Safety Risk

The projected impact of compositional verification research conducted by the National Aeronautic and Space Administration System-Wide Safety and Assurance Technologies on aviation safety risk was assessed. Software and compositional verification was described. Traditional verification techniques have two major problems: testing at the prototype stage where error discovery can be quite costly and the inability to test for all potential interactions leaving some errors undetected until used by the end user. Increasingly complex and nondeterministic aviation systems are becoming too large for these tools to check and verify. Compositional verification is a "divide and conquer" solution to addressing increasingly larger and more complex systems. A review of compositional verification research being conducted by academia, industry, and Government agencies is provided. Forty-four aviation safety risks in the Biennial NextGen Safety Issues Survey were identified that could be impacted by compositional verification and grouped into five categories: automation design; system complexity; software, flight control, or equipment failure or malfunction; new technology or operations; and verification and validation. One capability, 1 research action, 5 operational improvements, and 13 enablers within the Federal Aviation Administration Joint Planning and Development Office Integrated Work Plan that could be addressed by compositional verification were identified.

Reveley, Mary S.↗

Risk analysis and management

Present software development accomplishments are indicative of the emerging interest in and increasing efforts to provide risk assessment backbone tools in the manned spacecraft engineering community. There are indications that similar efforts are underway in the chemical processes industry and are probably being planned for other high risk ground base environments. It appears that complex flight systems intended for extended manned planetary exploration will drive this technology.

Smith, H. E.↗

Human System Risk Communication: Directed Acyclic Graphs

- The Human System Risk Board (HSRB) is responsible for the management of a portfolio of 30 human system risks that NASA tracks and configuration manages to mitigate for future crewed exploration missions. - The HSRB has been exploring the concept of causal diagrams (in the form of Directed Acyclic Graphs or DAGs) as an approach to creating knowledge graphs for each risk to enable shared mental models of causal flow from spaceflight hazards to mission outcomes among HSRB Stakeholders. - These diagrams are intended to improve insight and communication of risk across the myriad subject matter experts and management interested in human system risk reduction. This includes program managers, systems engineers, and operators in addition to the Human Health and Performance Directorate. - The DAG project was intended to create the foundation for composition of the 30 baselined DAGs into a single risk network and software is being developed in parallel to enable this forward work.

directed acrylic graph↗

Space Shuttle Main Engine Quantitative Risk Assessment: Illustrating Modeling of a Complex System with a New QRA Software Package

During 1997, a team from Hernandez Engineering, MSFC, Rocketdyne, Thiokol, Pratt & Whitney, and USBI completed the first phase of a two year Quantitative Risk Assessment (QRA) of the Space Shuttle. The models for the Shuttle systems were entered and analyzed by a new QRA software package. This system, termed the Quantitative Risk Assessment System(QRAS), was designed by NASA and programmed by the University of Maryland. The software is a groundbreaking PC-based risk assessment package that allows the user to model complex systems in a hierarchical fashion. Features of the software include the ability to easily select quantifications of failure modes, draw Event Sequence Diagrams(ESDs) interactively, perform uncertainty and sensitivity analysis, and document the modeling. This paper illustrates both the approach used in modeling and the particular features of the software package. The software is general and can be used in a QRA of any complex engineered system. The author is the project lead for the modeling of the Space Shuttle Main Engines (SSMEs), and this paper focuses on the modeling completed for the SSMEs during 1997. In particular, the groundrules for the study, the databases used, the way in which ESDs were used to model catastrophic failure of the SSMES, the methods used to quantify the failure rates, and how QRAS was used in the modeling effort are discussed. Groundrules were necessary to limit the scope of such a complex study, especially with regard to a liquid rocket engine such as the SSME, which can be shut down after ignition either on the pad or in flight. The SSME was divided into its constituent components and subsystems. These were ranked on the basis of the possibility of being upgraded and risk of catastrophic failure. Once this was done the Shuttle program Hazard Analysis and Failure Modes and Effects Analysis (FMEA) were used to create a list of potential failure modes to be modeled. The groundrules and other criteria were used to screen out the many failure modes that did not contribute significantly to the catastrophic risk. The Hazard Analysis and FMEA for the SSME were also used to build ESDs that show the chain of events leading from the failure mode occurence to one of the following end states: catastrophic failure, engine shutdown, or siccessful operation( successful with respect to the failure mode under consideration).

Smart, Christian↗

The ILLIAC IV memory system: Current status and future possibilities

The future needs of researchers who will use the Illiac were examined and the requirements they will place on the memory system were evaluated. Various alternatives to replacing critical memory components were considered with regard to cost, risk, system impact, software requirements, and implementation schedules. The current system, its performance and status, and the limitations it places on possible enhancements are discussed as well as the planned enhancements to the Illiac processor. After a brief technology survey, different implementations are presented for each system memory component. Three different memory systems are proposed to meet the identified needs of the Illiac user community. These three alternatives differ considerably with respect to storage capacity and accessing capabilities, but they all offer significant improvements over the current system. The proposed systems and their relative merits are analyzed.

Stevenson, D. K.↗

Aerobraking mission design - Mission domain and mass performance

The work reported comprises part of an Aerobraking Study that sought to establish a 'feasible mission design, navigation design, and MOS design and to show the desirability of aerobraking for the Venus Orbiting Imaging Radar (VOIR) mission by assessing mission performance, cost, and risk'. The developed software assesses accurately the mass performance of aerobraking and chemical missions that place a spacecraft in orbit about another planet. All injection date/arrival data combinations that provide a trajectory with adequate mass performance are available for further study. The considered analysis has been applied to the Type I trajectories from earth to Venus in 1988. The analysis can easily be applied to missions to Mars and to Titan. The intersection of the determined mass performance domain with the stable orbit domain provides an adequate mission domain for VOIR 1988.

Kerridge, S. J.↗

Ares I Avionics Introduction

The Ares I is the next generation human-rated launcher for the United States Constellation program. This system is required to provide single fault tolerance within defined crew safety and mission reliability limits. As part of the effort to achieve those safety goals, Ares I includes an avionics subsystem built as a multistring, voting architecture. The avionics design draws upon experience gained from building fly-by-wire systems for Shuttle, X- 38, and Seawolf. Architectural drivers for the avionics design include using proven technologies with existing suppliers of space rated parts for critical functions (to reduce overall development risk), easing the software development effort by using an off-theshelf, DO-178B certifiable, ARINC-653 operating system in the main flight computers, minimizing mutual data and power connections that might lead to a common-mode hardware failure of the redundant avionics strings, and centralizing overall Ares I command & control within the Upper Stage.

Marchant, Christopher C.↗

Ground System Harmonization Efforts at NASA's Goddard Space Flight Center

This slide presentation reviews the efforts made at Goddard Space Flight Center in harmonizing the ground systems to assist in collaboration in space ventures. The key elements of this effort are: (1) Moving to a Common Framework (2) Use of Consultative Committee for Space Data Systems (CCSDS) Standards (3) Collaboration Across NASA Centers (4) Collaboration Across Industry and other Space Organizations. These efforts are working to bring into harmony the GSFC systems with CCSDS standards to allow for common software, use of Commercial Off the Shelf Software and low risk development and operations and also to work toward harmonization with other NASA centers

Smith, Dan↗

Driving Curiosity: Mars Rover Mobility Trends During the First Seven Years

NASA’s Mars Science Laboratory (MSL) mission landed the Curiosity rover on Mars on August 6, 2012. As of August 6, 2019 (sol 2488), Curiosity has driven 21,318.5 meters over a variety of terrain types and slopes, employing multiple drive modes with varying amounts of onboard autonomy. Curiosity’s drive distances each sol have ranged from its shortest drive of 2.6 centimeters to its longest drive of 142.5 meters, with an average drive distance of 28.9 meters. Real-time human intervention during Curiosity drives on Mars is not possible due to the latency in uplinking commands and downlinking telemetry, so the operations team relies on the rover’s flight software to prevent an unsafe state during driving. Over the first seven years of the mission, Curiosity has attempted 738 drives. While 622 drives have completed successfully, 116 drives were prevented or stopped early by the rover’s fault protection software. The primary risks to mobility success have been wheel wear, wheel entrapment, progressive wheel sinkage (which can lead to rover embedding), and terrain interactions or hardware or cabling failures that result in an inability to command one or more steer or drive actuators. In this paper, we describe mobility trends over the first 21.3km of the mission, operational aspects of the mobility fault protection, and risk mitigation strategies that will support continued mobility success for the remainder of the mission.

Rankin, Arturo↗

Risk Management Implementation Tool

Continuous Risk Management (CM) is a software engineering practice with processes, methods, and tools for managing risk in a project. It provides a controlled environment for practical decision making, in order to assess continually what could go wrong, determine which risk are important to deal with, implement strategies to deal with those risk and assure the measure effectiveness of the implemented strategies. Continuous Risk Management provides many training workshops and courses to teach the staff how to implement risk management to their various experiments and projects. The steps of the CRM process are identification, analysis, planning, tracking, and control. These steps and the various methods and tools that go along with them, identification, and dealing with risk is clear-cut. The office that I worked in was the Risk Management Office (RMO). The RMO at NASA works hard to uphold NASA s mission of exploration and advancement of scientific knowledge and technology by defining and reducing program risk. The RMO is one of the divisions that fall under the Safety and Assurance Directorate (SAAD). I worked under Cynthia Calhoun, Flight Software Systems Engineer. My task was to develop a help screen for the Continuous Risk Management Implementation Tool (RMIT). The Risk Management Implementation Tool will be used by many NASA managers to identify, analyze, track, control, and communicate risks in their programs and projects. The RMIT will provide a means for NASA to continuously assess risks. The goals and purposes for this tool is to provide a simple means to manage risks, be used by program and project managers throughout NASA for managing risk, and to take an aggressive approach to advertise and advocate the use of RMIT at each NASA center.

Wright, Shayla L.↗

Assurance of Fault Management: Risk-Significant Adverse Condition Awareness

Fault Management (FM) systems are ranked high in risk-based assessment of criticality within flight software, emphasizing the importance of establishing highly competent domain expertise to provide assurance for NASA projects, especially as spaceflight systems continue to increase in complexity. Insight into specific characteristics of FM architectures seen embedded within safety- and mission-critical software systems analyzed by the NASA Independent Verification Validation (IVV) Program has been enhanced with an FM Technical Reference (TR) suite. Benefits are aimed beyond the IVV community to those that seek ways to efficiently and effectively provide software assurance to reduce the FM risk posture of NASA and other space missions. The identification of particular FM architectures, visibility, and associated IVV techniques provides a TR suite that enables greater assurance that critical software systems will adequately protect against faults and respond to adverse conditions. The role FM has with regard to overall asset protection of flight software systems is being addressed with the development of an adverse condition (AC) database encompassing flight software vulnerabilities.Identification of potential off-nominal conditions and analysis to determine how a system responds to these conditions are important aspects of hazard analysis and fault management. Understanding what ACs the mission may face, and ensuring they are prevented or addressed is the responsibility of the assurance team, which necessarily should have insight into ACs beyond those defined by the project itself. Research efforts sponsored by NASAs Office of Safety and Mission Assurance defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs, and allowing queries based on project, mission type, domain component, causal fault, and other key characteristics. The repository has a firm structure, initial collection of data, and an interface established for informational queries, with plans for integration within the Enterprise Architecture at NASA IVV, enabling support and accessibility across the Agency. The development of an improved workflow process for adaptive, risk-informed FM assurance is currently underway.

Software Verification & Validation↗

Visualization support for risk-informed decision making when planning and managing software developments

Key decisions are made in the early stages of planning and management of software developments. The information basis for these decisions is often a mix of analogy with past developments, and the best judgments of domain experts. Visualization of this information can support to such decision making by clarifying the status of the information and yielding insights into the ramifications of that information vis-a-vis decision alternatives.

technology infusion↗