Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety Case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Automated Generation and Assessment of Autonomous Systems Test Cases

This slide presentation reviews some of the issues concerning verification and validation testing of autonomous spacecraft routinely culminates in the exploration of anomalous or faulted mission-like scenarios using the work involved during the Dawn mission's tests as examples. Prioritizing which scenarios to develop usually comes down to focusing on the most vulnerable areas and ensuring the best return on investment of test time. Rules-of-thumb strategies often come into play, such as injecting applicable anomalies prior to, during, and after system state changes; or, creating cases that ensure good safety-net algorithm coverage. Although experience and judgment in test selection can lead to high levels of confidence about the majority of a system's autonomy, it's likely that important test cases are overlooked. One method to fill in potential test coverage gaps is to automatically generate and execute test cases using algorithms that ensure desirable properties about the coverage. For example, generate cases for all possible fault monitors, and across all state change boundaries. Of course, the scope of coverage is determined by the test environment capabilities, where a faster-than-real-time, high-fidelity, software-only simulation would allow the broadest coverage. Even real-time systems that can be replicated and run in parallel, and that have reliable set-up and operations features provide an excellent resource for automated testing. Making detailed predictions for the outcome of such tests can be difficult, and when algorithmic means are employed to produce hundreds or even thousands of cases, generating predicts individually is impractical, and generating predicts with tools requires executable models of the design and environment that themselves require a complete test program. Therefore, evaluating the results of large number of mission scenario tests poses special challenges. A good approach to address this problem is to automatically score the results based on a range of metrics. Although the specific means of scoring depends highly on the application, the use of formal scoring - metrics has high value in identifying and prioritizing anomalies, and in presenting an overall picture of the state of the test program. In this paper we present a case study based on automatic generation and assessment of faulted test runs for the Dawn mission, and discuss its role in optimizing the allocation of resources for completing the test program.

Testing challenges↗

Application of Objectives-Driven Assurance Cases to System Development in an Evolving Acquisition Model

System properties such as “safety” and “dependability” cannot, in practice, be proven, and must be argued in an “assurance case” aimed at supporting risk-acceptance decisions that have to be made by system acquirers and/or regulatory authorities. The paper is concerned with applications of the “assurance case” idea early in design and development of new systems, when (apart from dedicated testing) the only available operating experience information derives from previous (non-identical) systems. Much of the discussion is based on an evolving acquisition model at the US National Aeronautics and Space Administration; previously, most major systems were developed in-house, but some major systems will now be developed by and acquired from commercial providers. Key points discussed include the following. (1) By promoting a particular kind of focused discussion between acquirers and providers, the use of assurance cases should be particularly valuable under the new acquisition model. (2) In principle, objectives-driven (sometimes called “performance-based”) approaches to assurance of performance have significant advantages in cases where they are applicable. (3) For truly novel systems, completeness of the safety analysis is a significant issue; it is important for the assurance case to include a commitment by the provider (or applicant) to seriously pursue analysis of operating experience, so that previously unrecognized hazards can be identified and addressed. (4) Inquiries into major accidents often point to deficiencies in management oversight in all parts of the life cycle; management processes need to be addressed in the formulation and the implementation of an assurance case. Under the new acquisition model, these considerations imply a serious reconsideration of the way in which the development process is managed by both providers and acquirers.

Objectives-driven↗

Software development for safety-critical medical applications

There are many computer-based medical applications in which safety and not reliability is the overriding concern. Reduced, altered, or no functionality of such systems is acceptable as long as no harm is done. A precise, formal definition of what software safety means is essential, however, before any attempt can be made to achieve it. Without this definition, it is not possible to determine whether a specific software entity is safe. A set of definitions pertaining to software safety will be presented and a case study involving an experimental medical device will be described. Some new techniques aimed at improving software safety will also be discussed.

Knight, John C.↗

Safety of hydrogen pressure gauges.

Study of the relative safety afforded an operator by various hydrogen-pressure gauge case designs. It is shown that assurance of personnel safety, should a failure occur, requires careful selection of available gauge designs, together with proper mounting. Specific gauge case features and mounting requirements are recommended.

Voth, R. O.↗

MIKA: Manager for Intelligent Knowledge Access Toolkit for Engineering Knowledge Discovery and Information Retrieval

Repositories of safety reports are often underutilized and only analyzed manually by trained experts, despite safety management systems requiring reports. These collections of documents contain a wealth of information from past projects and operations that could improve system safety and design. Advances in natural language processing techniques have improved information extraction and retrieval in consumer technology, biomedicine, and finance, for instance, but have not been applied to engineering documents on the same scale. To this end, the Manager for Intelligent Knowledge Access (MIKA) open-source toolkit has been developed for rapid knowledge discovery and information retrieval in safety engineering applications. The MIKA toolkit uses state-of-the-art natural language processing algorithms and allows a user to apply these methods to their own dataset. This paper describes the MIKA toolkit and its two primary capabilities, knowledge discovery and information retrieval, and demonstrates the toolkit via a case study on National Transportation Safety Board (NTSB) reports.

Machine Learning↗

MIKA: Manager for Intelligent Knowledge Access Toolkit for Engineering Knowledge Discovery and Information Retrieval

Repositories of safety reports are often underutilized and only analyzed manually by trained experts, despite safety management systems requiring reports. These collections of documents contain a wealth of information from past projects and operations that could improve system safety and design. Advances in natural language processing techniques have improved information extraction and retrieval in consumer technology, biomedicine, and finance, for instance, but have not been applied to engineering documents on the same scale. To this end, the Manager for Intelligent Knowledge Access (MIKA) open-source toolkit has been developed for rapid knowledge discovery and information retrieval in safety engineering applications. The MIKA toolkit uses state-of-the-art natural language processing algorithms and allows a user to apply these methods to their own dataset. This paper describes the MIKA toolkit and its two primary capabilities, knowledge discovery and information retrieval, and demonstrates the toolkit via a case study on National Transportation Safety Board (NTSB) reports.

Systems Engineering↗

Reliability, Safety, and Performance for Two Aerospace Revolutions - UAS/ODM and Commercial Deep Space

Aerospace is in the midst of a renaissance, expanding on both the air and space side into major new commercial areas including unmanned air systems (UAS), on demand mobility (ODM), personal air vehicles (PAV), and commercial deep space. These new areas require, in the initial planning, consideration of new safety, reliability, and in some cases, enabling performance approaches for viability. For example, due to their huge numbers, if current accident rates prevail, UAS/ODM/PAV aircraft could crash at an unacceptable rate, causing life and property damage. Also, if humans in commercial space activities have serious health issues and/or there are unacceptable rocket viability issues/crash rates, these new, major markets (order of 1 trillion dollars per year) could be rapidly curtailed until agreeable and effective changes are instituted, producing additional expense, delay, and reduced revenue. This report addresses such safety and reliability issues and includes: performance enhancement possibilities such as an enabling Air Traffic Control System (ATC), crash proof vehicles, increased range for aero, space debris removal, and human health for space.

Crash Proof↗

Effect of service environments on adhesively bonded joints in composite structures

The models employed in the present computational methods for evaluating severe service-environment effects on adhesively bonded joints in composites are based on composite analyses and structural mechanics, encompassing nonlinear environmental degradation. The methods are demonstrated for the case of a butt joint with a single doubler, subjected to the environmental effects as well as static and cyclic loads. The highest joint strength is noted to be required in the case of cyclic loads and hygrothermal service environments; margins of safety for adhesive material stresses decline rapidly in such cases.

Singhal, S. N.↗

Handling qualities of the High Speed Civil Transport

The low speed handling qualities of a High Speed Civil Transport class aircraft have been investigated by using data of the former Advanced Supersonic Transport (AST) 105. The operation of such vehicles in the airport terminal area is characterized by 'backside' performance. Main objectives of this research effort were: (Q) determination of the nature and magnitude of the speed instability associated with the backside of the thrust required curve; (2) confirmation of the validity of existing MIL-SPEC handling qualities criteria; (3) safety of operation of the vehicle in the event of autothrottle failure; and (4) correlation of required engine responsiveness with level of speed instability. Preliminary findings comprise the following: (1) The critical velocity for speed instability was determined to be 196 knots, well above the projected approach speed of 155 knots. This puts the vehicle far on the backside of its thrust required curve. While the aircraft can be configured to have static and dynamic stability at this trim point, a significant speed instability emerges, if a pilot or autopilot attempts flight path control with elevator and/or canard control surfaces only. This requires a properly configured autothrottle and/or variable aerodynamic drag devices which can provide speed stability; (2) An AST 105 type vehicle meets MIL-SPEC criteria only in part. While the damping criteria for phugoid and short period motion are met easily, the AST 105 falls short of the required minimum short period frequency, meaning that the HSCT is too sluggish in pitch to meet the military criteria. Obviously the military specification do not consider a vehicle with such high pitch inertia. With regard to speed stability and flight path stability criteria, the vehicle meets levels 2 and 3 of the military requirements, indicating that it would be landed safety with manual controls in case of an autothrottle failure, even though the pilot workload would be high; and (3) This requires quick thrust response to throttle adjustment, however. If the engine responsiveness is slow, the aircraft handling qualities are further deteriorated. Progress has been made in correlating required engine responses dyanmics with the given level of speed instability of the vehicle.

Solies, U. Peter↗

A Thermostructural Analysis of a Diboride Composite Leading Edge

In an effort to support the design of zirconium diboride composite leading edges for hypersonic vehicles, a finite element model (FEM) of a prototype leading edge was created and finite element analysis (FEA) was employed to assess its thermal and structural response to aerothermal boundary conditions. Unidirectional material properties for the structural components of the leading edge, a continuous fiber reinforced diboride composite, were computed with COSTAR. These properties agree well with those experimentally measured. To verify the analytical approach taken with COSMOS/M, an independent FEA of one of the leading edge assembly components was also done with COSTAR. Good agreement was obtained between the two codes. Both showed that a unidirectional lay-up had the best margin of safety for a simple loading case. Both located the maximum stress in the same region and ply. The magnitudes agreed within 4 percent. Trajectory based aerothermal heating was then applied to the leading edge assembly FEM created with COSMOS/M to determine steady state temperature response, displacement, stresses, and contact forces due to thermal expansion and thermal strains. Results show that the leading edge stagnation line temperature reached 4700 F. The maximum computed failure index for the laminated composite components peaks at 4.2, and is located at the bolt flange in layer 2 of the side bracket. The temperature gradient in the tip causes a compressive stress of 279 ksi along its width and substantial tensile stresses within its depth.

Kowalski, Tom↗

Remote Sensing of Planetary Surfaces

Our efforts have been focused on understanding the physical properties of planetary surfaces using remote sensing techniques. Specific application has been to the surfaces of the Moon and Mars. Our approach has been to use thermal-infrared emission and radar reflectance and scattering as a way of exploring the decimeter-scale structure of these surfaces. At this scale, the techniques are sensitive to physical parameters such as the average or effective particle size of surface materials, the degree of induration or physical bonding between individual regolith grains, and the abundance of rocks of different sizes resting on or admixed in to the surface. The results are relevant to understanding the geological processes that have affected the surface and, in the case of Mars, determining site safety and scientific relevance for planning upcoming lander, rover, and sample-return spacecraft missions. Specific results are discussed below, and publications that have resulted are listed at the end.

Jakosky, Bruce M.↗

2008 NASA Range Safety Annual Report

Welcome to the 2008 edition of the NASA Range Safety Annual Report. Funded by NASA Headquarters, this report provides a NASA Range Safety overview for current and potential range users. This year, along with full length articles concerning various subject areas, we have provided updates to standard subjects with links back to the 2007 original article. Additionally, we present summaries from the various NASA Range Safety Program activities that took place throughout the year, as well as information on several special projects that may have a profound impact on the way we will do business in the future. The sections include a program overview and 2008 highlights of Range Safety Training; Range Safety Policy; Independent Assessments and Common Risk Analysis Tools Development; Support to Program Operations at all ranges conducting NASA launch operations; a continuing overview of emerging Range Safety-related technologies; Special Interests Items that include recent changes in the ELV Payload Safety Program and the VAS explosive siting study; and status reports from all of the NASA Centers that have Range Safety responsibilities. As is the case each year, contributors to this report are too numerous to mention, but we thank individuals from the NASA Centers, the Department of Defense, and civilian organizations for their contributions. We have made a great effort to include the most current information available. We recommend that this report be used only for guidance and that the validity and accuracy of all articles be verified for updates. This is the third year we have utilized this web-based format for the annual report. We continually receive positive feedback on the web-based edition, and we hope you enjoy this year's product as well. It has been a very busy and productive year on many fronts as you will note as you review this report. Thank you to everyone who contributed to make this year a successful one, and I look forward to working with all of you in the years to come.

Lamoreaux, Richard W.↗

Spacecraft Charging Current Balance Model Applied to High Voltage Solar Array Operations

Spacecraft charging induced by high voltage solar arrays can result in power losses and degradation of spacecraft surfaces. In some cases, it can even present safety issues for astronauts performing extravehicular activities. An understanding of the dominant processes contributing to spacecraft charging induced by solar arrays is important to current space missions, such as the International Space Station, and to any future space missions that may employ high voltage solar arrays. A common method of analyzing the factors contributing to spacecraft charging is the current balance model. Current balance models are based on the simple idea that the spacecraft will float to a potential such that the current collecting to the surfaces equals the current lost from the surfaces. However, when solar arrays are involved, these currents are dependent on so many factors that the equation becomes quite complicated. In order for a current balance model to be applied to solar array operations, it must incorporate the time dependent nature of the charging of dielectric surfaces in the vicinity of conductors1-3. This poster will present the factors which must be considered when developing a current balance model for high voltage solar array operations and will compare results of a current balance model with data from the Floating Potential Measurement Unit4 on board the International Space Station.

Willis, Emily M.↗

Unified Analysis of Aerospace Structures through Implementation of Rapid Tools into a Stress Framework

Rapid structural analysis tools have become an important part of the design cycle for aerospace companies for the last several decades. As these tools have been developed over time, there is often little consideration for shared software infrastructure between the tools, which makes design and analysis cumbersome due to a lack of commonality in input and output data and reporting, as well as poor traceability of results. Under the Rapid Tools task of the Advanced Composites Consortium (ACC), four aerospace tools were recently implemented or enhanced in the HyperSizer stress framework and then evaluated by this consortium of industry and government organizations. The framework provides an automated software environment for executing the rapid tools for analysis and sizing, quantifying margins of safety for thousands of load cases, and generating reports in support of FAA certification. This paper describes the process by which the tools were enhanced or implemented in the stress framework under the ACC project, and the evaluation conducted by industry consortium members.

Craig S Collier↗

Damage-Tolerant, Affordable Composite Engine Cases Designed and Fabricated

An integrated team of NASA personnel, Government contractors, industry partners, and university staff have developed an innovative new technology for commercial fan cases that will substantially influence the safety and efficiency of future turbine engines. This effective team, under the direction of the NASA Glenn Research Center and with the support of the Federal Aviation Administration, has matured a new class of carbon/polymer composites and demonstrated a 30- to 50-percent improvement in specific containment capacity (blade fragment kinetic energy/containment system weight). As the heaviest engine component, the engine case/containment system greatly affects both the safety and efficiency of aircraft engines. The ballistic impact research team has developed unique test facilities and methods for screening numerous candidate material systems to replace the traditional heavy, metallic engine cases. This research has culminated in the selection of a polymer matrix composite reinforced with triaxially braided carbon fibers and technology demonstration through the fabrication of prototype engine cases for three major commercial engine manufacturing companies.

Hopkins, Dale A.↗

Miniature spectrally selective dosimeter

A miniature spectrally selective dosimeter capable of measuring selected bandwidths of radiation exposure on small mobile areas is described. This is achieved by the combination of photovoltaic detectors, electrochemical integrators (E-cells) and filters in a small compact case which can be easily attached in close proximity to and substantially parallel to the surface being measured. In one embodiment two photovoltaic detectors, two E-cells, and three filters are packaged in a small case with attaching means consisting of a safety pin. In another embodiment, two detectors, one E-cell, three filters are packaged in a small case with attaching means consisting of a clip to clip over a side piece of an eye glass frame.

Adams, R. R.↗

Technology test bed engine real-time failure control

The Real-Time Failure Control (RTFC) program involves development of a failure detection algorithm, for the Space Shuttle Main Engine (SSME). This failure detection approach is signal-based and entails monitoring SSME measurement signals based on predetermined as well as on-line computed mean and standard deviation values. Twenty-four engine measurements are monitored in the algorithm and provisions are made to add more parameters if needed. Each of the first values of every measurement signal at the algorithm start is checked against safety limits placed around a pre-computed engine-to-engine mean value (MV) with a bandwidth equal to a given multiple of the pre-computed standard deviation (SD). If several parameters are out of the bounds of these limits a failure is signaled. During the first two seconds (after algorithm start) a moving average (MA) and a SD is computed on-line in real-time. The moving average of each parameter is computed by averaging the incoming signal measurement with the four most recent previous signal measurements. The moving average is updated at every sampling interval (40 msec) and is checked against a similar safety band around the initial signal value for each parameter. If several anomalies are registered, a failure is signaled by the algorithm. At the end of the two-second interval the MA is fixed as the mean value for the rest of the algorithm operation and a safety band is placed above and below this value equal to a multiple of the computed SD. However, the safety band is adjusted by adjusting the mean value when propellant tank repressurization and venting take place. 'Influence Coefficients' are used to make the necessary adjustments to the safety limits of those parameters that are affected by repressurization and venting or valve closure and opening. The MA is, in both cases, continuously updated and checked against the safety band. Once more, if several parameters exceed the limits a failure is signaled. At the start of every scheduled power transient the algorithm is stopped. It is re-initiated after two seconds from the termination of the power transient and the process is repeated. The final report is divided into four major sections. The most encompassing of all is the discussion section that has sub-sections on: (1) RTFC algorithm development, (2) RTFC simulations; (3) RTFC current limitations; and (4) enhancements planned for.

Panossian, Hagop V.↗