Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety Critical Systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Close out the Critical Commitment for System Wide Safety’s Technical Challenge 3 (TC 3)

- Deliver validated methods and recommended practices to reduce certification costs for ground and onboard vehicle guidance and control systems through expanded acceptability of analysis as evidence for certification FY 2022. - Communicate results to maximize public awareness of the research and transfer capabilities via a set of on-demand training seminars and supporting materials including reports, publications and open source software codes where applicable.

Joseph C Coughlan↗

Integrated Systems Health Management for Space Exploration

Integrated Systems Health Management (ISHM) is a system engineering discipline that addresses the design, development, operation, and lifecycle management of components, subsystems, vehicles, and other operational systems with the purpose of maintaining nominal system behavior and function and assuring mission safety and effectiveness under off-nominal conditions. NASA missions are often conducted in extreme, unfamiliar environments of space, using unique experimental spacecraft. In these environments, off-nominal conditions can develop with the potential to rapidly escalate into mission- or life-threatening situations. Further, the high visibility of NASA missions means they are always characterized by extraordinary attention to safety. ISHM is a critical element of risk mitigation, mission safety, and mission assurance for exploration. ISHM enables: In-space maintenance and repair; a) Autonomous (and automated) launch abort and crew escape capability; b) Efficient testing and checkout of ground and flight systems; c) Monitoring and trending of ground and flight system operations and performance; d) Enhanced situational awareness and control for ground personnel and crew; e) Vehicle autonomy (self-sufficiency) in responding to off-nominal conditions during long-duration and distant exploration missions; f) In-space maintenance and repair; and g) Efficient ground processing of reusable systems. ISHM concepts and technologies may be applied to any complex engineered system such as transportation systems, orbital or planetary habitats, observatories, command and control systems, life support systems, safety-critical software, and even the health of flight crews. As an overarching design and operational principle implemented at the system-of-systems level, ISHM holds substantial promise in terms of affordability, safety, reliability, and effectiveness of space exploration missions.

Uckun, Serdar↗

A design and implementation methodology for diagnostic systems

A methodology for design and implementation of diagnostic systems is presented. Also discussed are the advantages of embedding a diagnostic system in a host system environment. The methodology utilizes an architecture for diagnostic system development that is hierarchical and makes use of object-oriented representation techniques. Additionally, qualitative models are used to describe the host system components and their behavior. The methodology architecture includes a diagnostic engine that utilizes a combination of heuristic knowledge to control the sequence of diagnostic reasoning. The methodology provides an integrated approach to development of diagnostic system requirements that is more rigorous than standard systems engineering techniques. The advantages of using this methodology during various life cycle phases of the host systems (e.g., National Aerospace Plane (NASP)) include: the capability to analyze diagnostic instrumentation requirements during the host system design phase, a ready software architecture for implementation of diagnostics in the host system, and the opportunity to analyze instrumentation for failure coverage in safety critical host system operations.

Williams, Linda J. F.↗

System Guidelines for EMC Safety-Critical Circuits: Design, Selection, and Margin Demonstration

Demonstration of safety margins for critical points (circuits) has traditionally been required since it first became a part of systems-level Electromagnetic Compatibility (EMC) requirements of MIL-E-6051C. The goal of this document is to present cost-effective guidelines for ensuring adequate Electromagnetic Effects (EME) safety margins on spacecraft critical circuits. It is for the use of NASA and other government agencies and their contractors to prevent loss of life, loss of spacecraft, or unacceptable degradation. This document provides practical definition and treatment guidance to contain costs within affordable limits.

Lawton, R. M.↗

Application of an Empirical Density Law via Python for Aqueous Plutonium Chloride Systems for MCNP6

Criticality safety models for aqueous plutonium chloride systems often contain a significant bias due to assumptions in material compositions. These systems are currently modeled as a fictitious metal-water mixture because little is known about the true solution density. Furthermore, no predictive density tools or capabilities for modeling aqueous plutonium chloride systems are approved for use at Los Alamos National Laboratory. Recent density measurements of this ternary system (PuCl 3 -HCl-H 2 O) have allowed for the development of a more realistic density law, which is applied in this work via an empirical method based in Python. This tool, entitled PuCS (Plutonium Chloride Solution tool) may be used to determine solution density and composition based on the plutonium content, acid content, and temperature for MCNP6 inputs. PuCS has been found to predict density within 2% of experimental data. In conclusion, MCNP6 calculations have found that crediting minimal amounts of free acid (0.5 M) may correspond to a ~12% decrease in peak reactivity in comparison to current modeling methods.

42 ENGINEERING↗

The Application of V&V within Reuse-Based Software Engineering

Verification and Validation (V&V) is performed during application development for many systems, especially safety-critical and mission-critical systems. The V&V process is intended to discover errors as early as possible during the development process. Early discovery is important in order to minimize the cost and other impacts of correcting these errors. In reuse-based software engineering, decisions on the requirements, design and even implementation of domain assets can can be made prior to beginning development of a specific system. in order to bring the effectiveness of V&V to bear within reuse-based software engineering. V&V must be incorporated within the domain engineering process.

Addy, Edward↗

A Framework for Performing V&V within Reuse-Based Software Engineering

Verification and validation (V&V) is performed during application development for many systems, especially safety-critical and mission-critical systems. The V&V process is intended to discover errors, especially errors related to critical processing, as early as possible during the development process. Early discovery is important in order to minimize the cost and other impacts of correcting these errors. In order to provide early detection of errors, V&V is conducted in parallel with system development, often beginning with the concept phase. In reuse-based software engineering, however, decisions on the requirements, design and even implementation of domain assets can be made prior to beginning development of a specific system. In this case, V&V must be performed during domain engineering in order to have an impact on system development. This paper describes a framework for performing V&V within architecture-centric, reuse-based software engineering. This framework includes the activities of traditional application-level V&V, and extends these activities into domain engineering and into the transition between domain engineering and application engineering. The framework includes descriptions of the types of activities to be performed during each of the life-cycle phases, and provides motivation for the activities.

Addy, Edward A.↗

The Need for V&V in Reuse-Based Software Engineering

V&V is currently performed during application development for many systems, especially safety-critical and mission-critical systems. The V&V process is intended to discover errors, especially errors related to entire' domain or product line rather than a critical processing, as early as possible during the development process. The system application provides the context under which the software artifacts are validated. engineering. This paper describes a framework that extends V&V from an individual application system to a product line of systems that are developed within an architecture-based software engineering environment. This framework includes the activities of traditional application-level V&V, and extends these activities into the transition between domain engineering and application engineering. The framework includes descriptions of the types of activities to be performed during each of the life-cycle phases, and provides motivation for activities.

Addy, Edward A.↗

The Integrated Safety-Critical Advanced Avionics Communication and Control (ISAACC) System Concept: Infrastructure for ISHM

Integrated System Health Management (ISHM) architectures for spacecraft will include hard real-time, critical subsystems and soft real-time monitoring subsystems. Interaction between these subsystems will be necessary and an architecture supporting multiple criticality levels will be required. Demonstration hardware for the Integrated Safety-Critical Advanced Avionics Communication & Control (ISAACC) system has been developed at NASA Marshall Space Flight Center. It is a modular system using a commercially available time-triggered protocol, ?Tp/C, that supports hard real-time distributed control systems independent of the data transmission medium. The protocol is implemented in hardware and provides guaranteed low-latency messaging with inherent fault-tolerance and fault-containment. Interoperability between modules and systems of modules using the TTP/C is guaranteed through definition of messages and the precise message schedule implemented by the master-less Time Division Multiple Access (TDMA) communications protocol. "Plug-and-play" capability for sensors and actuators provides automatically configurable modules supporting sensor recalibration and control algorithm re-tuning without software modification. Modular components of controlled physical system(s) critical to control algorithm tuning, such as pumps or valve components in an engine, can be replaced or upgraded as "plug and play" components without modification to the ISAACC module hardware or software. ISAACC modules can communicate with other vehicle subsystems through time-triggered protocols or other communications protocols implemented over Ethernet, MIL-STD- 1553 and RS-485/422. Other communication bus physical layers and protocols can be included as required. In this way, the ISAACC modules can be part of a system-of-systems in a vehicle with multi-tier subsystems of varying criticality. The goal of the ISAACC architecture development is control and monitoring of safety critical systems of a manned spacecraft. These systems include spacecraft navigation and attitude control, propulsion, automated docking, vehicle health management and life support. ISAACC can integrate local critical subsystem health management with subsystems performing long term health monitoring. The ISAACC system and its relationship to ISHM will be presented.

Gwaltney, David A.↗

Verification and Validation in a Rapid Software Development Process

The high cost of software production is driving development organizations to adopt more automated design and analysis methods such as rapid prototyping, computer-aided software engineering (CASE) tools, and high-level code generators. Even developers of safety-critical software system have adopted many of these new methods while striving to achieve high levels Of quality and reliability. While these new methods may enhance productivity and quality in many cases, we examine some of the risks involved in the use of new methods in safety-critical contexts. We examine a case study involving the use of a CASE tool that automatically generates code from high-level system designs. We show that while high-level testing on the system structure is highly desirable, significant risks exist in the automatically generated code and in re-validating releases of the generated code after subsequent design changes. We identify these risks and suggest process improvements that retain the advantages of rapid, automated development methods within the quality and reliability contexts of safety-critical projects.

Callahan, John R.↗

Reliability Requirements and Research Strategies for Urban Air Mobility Propulsion

An emerging new mission for aeronautics is Urban Air Mobility (UAM), a concept for air transportation around metropolitan areas with passenger-carrying operations. UAM vehicles must be capable of vertical take-off and landing, and this requirement presents unique technical challenges for electric and hybrid-based vertical take-off and landing (eVTOL). A critical challenge for UAM market growth is to gain public acceptance for being as safe as - or safer than - commercial air travel and automotive transportation. There is a lack of data for propulsion systems, components, and the associated thermal management systems for UAM eVTOL propulsion systems. The new mission, new propulsion system concepts, safety criticality of propulsion component performance during vertical take-off and lift operations, and lack of data presents many research challenges and opportunities. NASA has developed and published UAM vehicle concept studies. For a subset of the said concept vehicles, NASA has contracted for a study to identify failure modes and hazards associated with the propulsion systems of the concept vehicles and to perform functional hazard analyses (FHA) and failure modes and effects criticality analyses (FMECA) for each. From the completed study results, it was recommended for NASA to support research toward developing electric/hybrid-electric propulsion components with improved reliability and to explore powertrain architectures that can take advantage of higher reliability components to achieve inherent air-vehicle safety. NASA has started a research effort for UAM propulsion with a focus toward improving safety and reliability. Recent results and research strategy will be discussed toward the goals by means of: 1) improving individual component reliability through advanced materials and design methods, 2) improving the thermal management system, and 3) designing propulsion system architectures to provide inherent UAM vehicle safety.

Krantz, Timothy↗

Speech-Enhanced and Context Dependent Alerts: Future Implications for Spacecraft Design Abstract

In the future, NASA missions will involve many different space vehicles, habitats, and surface assets working together to provide safe and productive living and working environments for crew. Because these systems will be provided by multiple commercial companies working with NASA, it will be very different from missions of the past, bringing new challenges. One of the challenges is related to whether NASA should move beyond simple tone annunciation alerting systems, to more advanced systems that include speech. The other is related to determining the level of consistency required of safety-critical alert systems across spacecraft. Two studies were completed to address these important issues. The first study investigated the advantages and disadvantages of a tone+speech alert relative to the traditional tone-only alert. Results indicate that speech-enhanced alerts initially take longer to silence (the default action to which NASA personnel are trained), due to the need to listen to the entire message, but ultimately provided for faster understanding of the alert situation. Speech-enhanced alerts were also preferred by a large majority of crew-like study participants. An unexpected finding from this first study was that participants took longer to respond to tone-only alerts when they were mixed with speech- enhanced alerts. Participants waited to hear the speech message even for alerts they were trained to know did not contain speech components. This performance error is believed to be due to negative transfer of training. A second study focused on task and alert performance using a common set of tones across two contexts (“vehicles”) versus performance with a different set of tones for each context (“vehicle”). Participants were able to manage two different alert sets successfully; results indicate that discriminability of the two alert sets played a major role in their success. Implications for the design of spacecraft alerts are discussed and future areas of research are identified.

alerts↗

Speech-Enhanced and Context Dependent Alerts: Future Implications for Spacecraft Design

In the future, NASA missions will involve many different space vehicles, habitats, and surface assets working together to provide safe, productive environments for crew. Because these systems will be provided by multiple commercial companies working with NASA, it will be very different from missions of the past, bringing new challenges. One of the challenges is related to whether NASA should move beyond simple tone annunciation alerting systems, to more advanced systems that include speech. The other is related to determining the level of consistency required of safety-critical alert systems across spacecraft. Two studies were completed to address these important issues. The first study investigated the advantages and disadvantages of a tone+speech alert relative to the traditional tone-only alert. Results indicate that speech-enhanced alerts initially take longer to silence (the default action to which NASA personnel are trained), due to the need to listen to the entire message, but ultimately provided for faster understanding of the alert situation. Speech-enhanced alerts were also preferred by a large majority of crew-like study participants. An unexpected finding was that participants took longer to respond to tone-only alerts that were heard in the same session as speech-enhanced alerts. Participants waited to hear a speech message even for alerts they were trained to know did not contain speech components. This performance error is believed to be due to negative transfer of training. A second study focused on task and alert performance using a common set of tones across two contexts (e.g., vehicles, habitats, suits) versus performance with a different set of tones for each context. Participants were able to manage two different alert sets successfully; results indicate that discriminability of the two alert sets played a major role in their success. Implications for the design of spacecraft alerts are discussed, and future areas of research are identified.

alerts↗

A Markov model reduction technique for fault tolerant processor reliability analysis

A fault tolerant processor (FTP) plays a key role in many high performance, safety-critical control system applications. Realistic modeling of an FTP is crucial to gaining a high degree of confidence in the reliability and safety analysis of such a system. While fidelity is clearly a major consideration, a practical model must also be kept to a moderate size to allow its incorporation into the overall system model. This paper presents a systematic reduction technique that starts from a complex, detailed model of a triple, redundant FTP and produces a low order approximation of very high accuracy. The existence of two distinct time scales represents the key to the success of the technique. No eigenvalue solution or coordinate transformation are needed. The reduced model captures all the important features of the detailed model, is amenable to an analytical solution and provides insight into the reconfiguration behavior of an FTP.

Schor, Andrei L.↗

Applying formal methods and object-oriented analysis to existing flight software

Correctness is paramount for safety-critical software control systems. Critical software failures in medical radiation treatment, communications, and defense are familiar to the public. The significant quantity of software malfunctions regularly reported to the software engineering community, the laws concerning liability, and a recent NRC Aeronautics and Space Engineering Board report additionally motivate the use of error-reducing and defect detection software development techniques. The benefits of formal methods in requirements driven software development ('forward engineering') is well documented. One advantage of rigorously engineering software is that formal notations are precise, verifiable, and facilitate automated processing. This paper describes the application of formal methods to reverse engineering, where formal specifications are developed for a portion of the shuttle on-orbit digital autopilot (DAP). Three objectives of the project were to: demonstrate the use of formal methods on a shuttle application, facilitate the incorporation and validation of new requirements for the system, and verify the safety-critical properties to be exhibited by the software.

Cheng, Betty H. C.↗

The role of reliability graph models in assuring dependable operation of complex hardware/software systems

The complexity of computer systems currently being designed for critical applications in the scientific, commercial, and military arenas requires the development of new techniques for utilizing models of system behavior in order to assure 'ultra-dependability'. The complexity of these systems, such as Space Station Freedom and the Air Traffic Control System, stems from their highly integrated designs containing both hardware and software as critical components. Reliability graph models, such as fault trees and digraphs, are used frequently to model hardware systems. Their applicability for software systems has also been demonstrated for software safety analysis and the analysis of software fault tolerance. This paper discusses further uses of graph models in the design and implementation of fault management systems for safety critical applications.

Patterson-Hine, F. A.↗