Search NASA⌕ Search

SEARCH · Search NASA

Results for “Critical Function Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Cyber-Enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering

Cyber-enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering: This discussion will introduce the idea of cyber-enabled sabotage, and the role engineering plays in the cyber defense of critical functions with a focus on electric power systems. It will outline how and why engineering practice must be used to apply cybersecurity principles to establish safe and reliable operations even in the face of determined and skilled adversaries, and give an overview of INL’s Consequence-Driven Cyber-Informed Engineering methodology to apply these principles. There will be an opportunity for audience questions and answers at the end of the session.

42 ENGINEERING↗

Digital-Threat Bias and Psychological Distance: Barriers to Foundational Digital-Security Improvement

Modern life is held together by a web of digital dependencies that enable and provide delivery of critical services and functions—think the provision of utilities such as electricity and water, as well as our dependency on digital services for social and economic services (internet, communication, etc.). As this dependency grows, the complexity related to the delivery of these critical services increases as well. As complexity increases, the understanding of the risk and impact associated with potential disruption, degradation, or destruction—due to either malicious or non-malicious events of those digitally enabled functions—decreases. One potential explanation for the difficulty to 1) understand the risks faced and 2) address them appropriately and effectively is the abstractness and psychological distance assigned to “digital threat.” The complexity of these digitally enabled services creates a perceived complicatedness; as a result, digital threats are treated differently than similarly devasting (but more easily understood) kinetic or physical threats. How we categorize these threats also matters. Acts of cyber-enabled sabotage to critical infrastructure need to be defined as irregular warfare. By inadequately defining the threat, we compound the problem. Acknowledging this digital-threat bias is foundational to improving the ability to protect critical infrastructure. Using construal-level theory and psychological-distance concepts provides an intriguing starting point to address these issues, to reframe the challenges faced, and pursue more effective critical infrastructure security and defense policy.

29 - ENERGY PLANNING, POLICY AND ECONOMY↗

Gateway Implementation of Cybersecurity Requirements

Cyber threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is one of the critical subsystems that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfill and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Svetlana Hanson↗

Gateway Implementation of Cybersecurity Requirements

Cybersecurity threats are a constant present-day reality for any type of business -- Space exploration is not excluded from these threats either. The Gateway Program is one of NASA’s latest initiatives that extend space exploration beyond low earth orbit. Gateway allows for NASA to prove technologies and mature systems necessary to live and work on another celestial body before embarking on multi-year missions to Mars. The Gateway is a small, human-tended space station in orbit around the Moon. With the increased autonomy, distance and criticality of systems, cybersecurity is a critical discipline that touches and integrates with most if not all subsystems of the Gateway. Building a gateway to the lunar orbit is no simple task. In this presentation, we outline an approach that the Gateway team adopted in creating a cyber safe and robust vehicle to support operations and assure protection of the critical functions. Gateway Program is required to implement National Institute of Standards and Technology (NIST) guidelines to adhere to the Federal Information Security Modernization Act (FISMA). NIST provides a framework for managing and controlling cybersecurity risks by defining cybersecurity controls and methodologies for implementation. The NIST framework is based upon the system, data within the system, integrations with external systems, and risk assessments to determine impacts for each of those systems. The goals and objectives are to identify appropriate security controls that fulfil and map to the NIST 800-53 framework. The implementation process involves developing an organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. NIST Security controls are interpreted and defined within the Gateway vehicle requirements subsystems specifications. This paper details the approach, implementation, and challenges faced during the development and design phases to address cyber threats during the Gateway vehicle operations.

Cybersecurity↗

Moving from Information Assurance to Functional Assurance with Engineered Controls

Cyber threats to operational technology demand more than traditional IT defenses—they require full-spectrum mission assurance. Cyber-Informed Engineering (CIE) is an approach that embeds engineered controls into system design to ensure critical functions remain safe and reliable, even under attack. Unlike conventional cybersecurity tools, engineered controls act directly on physical processes to prevent unacceptable outcomes such as equipment damage or mission failure. This session will outline the CIE framework and share examples of consequence-based design that deliver true resilience, not just fail-safe behaviors. Attendees will learn how to integrate these principles into the engineering lifecycle to support resilient-by-design architectures and inform emerging standards. This talk sets the stage for the panel discussion on advancing CIE across sectors as digital and physical systems converge.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Developing Standards for AI/ML Systems in Civil Aviation: Challenges and Barriers

The inability to establish appropriate assurance methods for AI/ML components in safety critical systems leaves us unable to effectively manage the risks and benefits of such systems. It drives cost of development for systems with AI/ML components uneconomically high, it delays the adoption of systems with AI/ML components at scale, and it can result in catastrophic consequences in terms of the safety of systems with AI/ML components. In this presentation we will explore what constitutes sufficient scientific-based evidence to substantiate a safety claim related to an AI/ML component performing a safety-critical function.

AI/ML Standards↗

A Framework for Dynamic Architecture and Functional Allocations for Increasing Airspace Autonomy

To enable scalability of air travel for use cases such as cargo delivery, it is anticipated that future air traffic operations will involve unmanned aircraft operated by remote pilots. Of particular interest are schemes where a small number of pilots operate a large number of vehicles, mitigating high cost and pilot shortage issues. Such architectures require increased levels of automation and supervisory control modes. They also require ensuring safe operations when the command and control link to the vehicle is degraded or lost completely, rendering the vehicle autonomous. To evaluate these variable and dynamic architectures, this paper will present a framework for decomposing the functions necessary to ensure safe, orderly, and expeditious air travel, assessing the agents in the system, and classifying the levels of autonomy. Then, an example allocation to agents of roles for the function of separation assurance is presented, highlighting the dependency of the allocation on three main factors: time criticality of a potential separation violation, the ratio of pilots to vehicles, and the loss of the command and control link.

air traffic management, function allocation, auton↗

A Framework for Dynamic Architecture and Functional Allocations for Increasing Airspace Autonomy

To enable scalability of air travel for use cases such as cargo delivery, it is anticipated that future air traffic operations will involve unmanned aircraft operated by remote pilots. Of particular interest are schemes where a small number of pilots operate a large number of vehicles, mitigating high cost and pilot shortage issues. Such architectures require increased levels of automation and supervisory control modes. They also require ensuring safe operations when the command and control link to the vehicle is degraded or lost completely, rendering the vehicle autonomous. To evaluate these variable and dynamic architectures, this paper will present a framework for decomposing the functions necessary to ensure safe, orderly, and expeditious air travel, assessing the agents in the system, and classifying the levels of autonomy. Then, an example allocation to agents of roles for the function of separation assurance is presented, highlighting the dependency of the allocation on three main factors; time criticality of a potential separation violation, the ratio of pilots to vehicles, and the loss of the command and control link.

air traffic management↗

Developing stable, simplified, functional consortia from Brachypodium rhizosphere for microbial application in sustainable agriculture

The rhizosphere microbiome plays a crucial role in supporting plant productivity and ecosystem functioning by regulating nutrient cycling, soil integrity, and carbon storage. However, deciphering the intricate interplay between microbial relationships within the rhizosphere is challenging due to the overwhelming taxonomic and functional diversity. Here we present our systematic design framework built on microbial colocalization and microbial interaction, toward successful assembly of multiple rhizosphere-derived Reduced Complexity Consortia (RCC). We enriched co-localized microbes from Brachypodium roots grown in field soil with carbon substrates mimicking Brachypodium root exudates, generating 768 enrichments. By transferring the enrichments every 3 or 7 days for 10 generations, we developed both fast and slow-growing reduced complexity microbial communities. Most carbon substrates led to highly stable RCC just after a few transfers. 16S rRNA gene amplicon analysis revealed distinct community compositions based on inoculum and carbon source, with complex carbon enriching slow growing yet functionally important soil taxa like Acidobacteria and Verrucomicrobia. Network analysis showed that microbial consortia, whether differentiated by growth rate (fast vs. slow) or by succession (across generations), had significantly different network centralities. Besides, the keystone taxa identified within these networks belong to genera with plant growth-promoting traits, underscoring their critical function in shaping rhizospheric microbiome networks. Furthermore, tested consortia demonstrated high stability and reproducibility, assuring successful revival from glycerol stocks for long-term viability and use. Our study represents a significant step toward developing a framework for assembling rhizosphere consortia based on microbial colocalization and interaction, with future implications for sustainable agriculture and environmental management.

59 BASIC BIOLOGICAL SCIENCES↗

Description of the SSF PMAD dc testbed control system data acquisition function

A functional description of the various levels of the SSF power management and distribution dc test-bed control system architecture is presented, and the data acquisition function and the status of its implementation are described. The data requirements for the test-bed control system are dictated by the functionality being implemented at each level of the architecture. The test-bed control system hierarchy data acquisition function is distributed among its various levels. Fast-acting control functions that require time critical data are implemented at the lowest level. These functions require periodic data sampling to assure safe system operation and performance. Slower response control functions are implemented at the higher levels and require data to be reported at least every second. The present data acquisition function meets the requirements for a hierarchical and distributed power management and control system.

Baez, Anastacio N.↗

Architecture and Information Requirements to Assess and Predict Flight Safety Risks During Highly Autonomous Urban Flight Operations

As aviation adopts new and increasingly complex operational paradigms, vehicle types, and technologies to broaden airspace capability and efficiency, maintaining a safe system will require recognition and timely mitigation of new safety issues as they emerge and before significant consequences occur. A shift toward a more predictive risk mitigation capability becomes critical to meet this challenge. In-time safety assurance comprises monitoring, assessment, and mitigation functions that proactively reduce risk in complex operational environments where the interplay of hazards may not be known (and therefore not accounted for) during design. These functions can also help to understand and predict emergent effects caused by the increased use of automation or autonomous functions that may exhibit unexpected non-deterministic behaviors. The envisioned monitoring and assessment functions can look for precursors, anomalies, and trends (PATs) by applying model-based and data-driven methods. Outputs would then drive downstream mitigation(s) if needed to reduce risk. These mitigations may be accomplished using traditional design revision processes or via operational (and sometimes automated) mechanisms. The latter refers to the ‘in-time’ aspect of the system concept. This report comprises architecture and information requirements and considerations toward enabling such a capability within the domain of low altitude highly autonomous urban flight operations. This domain may span, for example, public-use surveillance missions flown by small unmanned aircraft (e.g., infrastructure inspection, facility management, emergency response, law enforcement, and/or security) to transportation missions flown by larger aircraft that may carry passengers or deliver products. Caveat: Any stated requirements in this report should be considered initial requirements that are intended to drive research and development (R&D). These initial requirements are likely to evolve based on R&D findings, refinement of operational concepts, industry advances, and new industry or regulatory policies or standards related to safety assurance.

Young, Steven↗

A Review of Function Allocation and En Route Separation Assurance

Today's air traffic control system has reached a limit to the number of aircraft that can be safely managed at the same time. This air traffic capacity bottleneck is a critical problem along the path to modernization for air transportation. The design of the next separation assurance system to address this problem is a cornerstone of air traffic management research today. This report reviews recent work by NASA and others in the areas of function allocation and en route separation assurance. This includes: separation assurance algorithms and technology prototypes; concepts of operations and designs for advanced separation assurance systems; and specific investigations into air-ground and human-automation function allocation.

Lewis, Timothy A.↗

Changing the S and MA [Safety and Mission Assurance] Paradigm

Objectives: 1) Optimize S&MA organization to best facilitate Shuttle transition in 2010, successfully support Ares developmental responsibilities, and minimize the impacts of the gap between last Shuttle flight and start of Ares V Project. 2) Improve leveraging of critical skills and experience between Shuttle and Ares. 3) Split technical and supervisory functions to facilitate technical penetration. 4) Create Chief Safety and Mission Assurance Officer (CSO) stand-alone position for successfully implementation of S&MA Technical Authority. 5) Minimize disruption to customers. 6) Provide early involvement of S&MA leadership team and frequent/open communications with S&MA team members and steak-holders.

Malone, Roy W., Jr.↗

Gateway Program Safety and Mission Assurance Integration - the Future of Safe Deep Space Human Exploration

As a foundational element of the National Aeronautics and Space Administration (NASA) Artemis Campaign, the Gateway is an incrementally built cislunar spacecraft that will serve as a platform for deep space human exploration, science, and technology demonstration. The Gateway will be a unifying catalyst for international partners around the world to establish sustained deep space scientific investigations, lunar surface access, and missions to Mars. As human exploration moves farther away from Earth, spacecraft designs must prioritize and optimize mass and volume allocations, while minimizing human and spacecraft risk. To accomplish this objective, the Gateway Program Safety and Mission Assurance functions develop, implement, and ensure compliance with requirements, in concert with the accurate characterization and transparent communication of residual hazard risks, for integrated safety, reliability and maintainability and quality assurance. Safety and Mission Assurance was a key contributor during Gateway program pre-formulation and formulation activities where safety and reliability analysis was embedded in the Gateway Systems Engineering and Integration team. During these early program stages, a preliminary Gateway Integrated Hazard Analysis and Preliminary Gateway Probabilistic Risk Assessment assisted in Gateway architectural and operational definition as part of a risk-informed design process. As the deep space architecture has matured, the integrated Safety and Mission Assurance analyses have matured, new safety review processes have been developed, and requirements have been refined to ensure compliance with integrated safety and mission assurance objectives. The Gateway Program is currently concluding the preliminary design review informed milestone, where the primary objectives included: - Ensured completeness and consistency of the preliminary design, including the meeting of all requirements within appropriate margins and acceptable risk posture. - Identification of any major issues moving forward to the Critical Design phase. At this milestone, Safety and Mission Assurance provided numerous products, including Gateway Top Risks and Risk Mitigation Plans, updated integrated hazard analyses, updated probabilistic risk assessment, Crew Survival Analysis Report, and updated Safety and Mission Assurance Requirements and Plans. These products provide a many-faceted perspective on the inherent risk and available mitigations involved in flying the current proposed vehicle design and anticipated stack configurations. In addition, Safety and Mission Assurance identified top technical, process and workforce concerns to be addressed as the program progresses toward the critical design phase. This paper will detail the evolution of the Gateway Program Safety and Mission Assurance integration functions, provide its current status and lessons learned for future human spaceflight programs. Throughout this paper the key tenets of the Gateway Program Safety and Mission Assurance will be discussed: - Application of a risk-informed approach to identify and mitigate areas of highest risk. - Leverage of valuable processes and lessons learned from earlier spaceflight programs. - Development of Safety and Mission Assurance products to inform design risk trades. - Utilization of common Safety and Mission Assurance practices to identify safety risks for multiple perspectives: top-down, bottom-up, and across lines of integration. - Approval of safety hazards at the appropriate level of authority, keeping most deliberation closest to design expertise and elevating risks of greatest concern for program-level consideration. - Championing of Safety and Mission Assurance processes and forums to foster a pervasive safety culture that is transparent, inclusive, and collaborative between all partners. These tenets have allowed the Gateway Safety and Mission Assurance function to play a key role in optimized vehicle design evolution, and early identification and mitigation of Gateway program and Artemis mission risk.

Helen Vaccaro↗

Organization, Management and Function of International Space Station (ISS) Multilateral Medical Operations

Long duration crews have inhabited the ISS since November of 2000. The favorable medical outcomes of its missions can be largely attributed to sustained collective efforts of all ISS Partners medical organizations. In-flight medical monitoring and support, although crucial, is just a component of the ISS system of Joint Medical Operations. The goal of this work is to review the principles, design, and function of the multilateral medical support of the ISS Program. The governing documents, which describe the relationships among all ISS partner medical organizations, were evaluated, followed by analysis of the roles, responsibilities, and decision-making processes of the ISS medical boards, panels, and working groups. The degree of integration of the medical support system was evaluated by reviewing the multiple levels of the status reviews and mission assurance activities carried out throughout the last six years. The Integrated Medical Group, consisting of physicians and other essential personnel in the mission control centers represents the front-line medical support of the ISS. Data from their day-to-day activities are presented weekly at the Space Medicine Operations Team (SMOT), where known or potential concerns are addressed by an international group of physicians. A broader status review is conducted monthly to project the state of crew health and medical support for the following month, and to determine measures to return to nominal state. Finally, a comprehensive readiness review is conducted during preparations for each ISS mission. The Multilateral Medical Policy Board (MMPB) issues medical policy decisions and oversees all health and medical matters. The Multilateral Space Medicine Board (MSMB) certifies crewmembers and visitors for training and space flight to the Station, and physicians to practice space medicine for the ISS. The Multilateral Medical Operations Panel (MMOP) develops medical requirements, defines and supervises implementation of operational countermeasures, environmental monitoring, medical care, and emergency medical services. MMOP assures the medical readiness of the Station for each subsequent mission or critical event. All boards and panels have functioned effectively and without interruptions even in various challenging circumstances. Based on the experience of the authors, consensus has prevailed as the primary nature of decisions made by all ISS medical groups, at all levels. The six first years of piloted operation have demonstrated the ability of the ISS medical authority groups and the medical infrastructure to implement medical policies and requirements, effectively interface with non-medical groups, and maintain the health and productivity of the crew in an integrated, multilaterally coordinated fashion. The medical support system appears to be mature and ready for further expansion of all Partners roles, and for the anticipated increase in the size of ISS crews.

Duncan, James M.↗

Improving the Agency's Software Acquisition Capability

External development of software has oftc n led to unsatisfactory results and great frustration for the assurE 7ce community. Contracts frequently omit critical assuranc 4 processes or the right to oversee software development activitie: At a time when NASA depends more and more on software to in plement critical system functions, combination of three factors ex; cerbate this problem: I ) the ever-increasing trend to acquire rather than develop software in-house, 2) the trend toward performance based contracts, and 3) acquisition vehicles that only state softwar 2 requirements while leaving development standards and assur! ince methodologies up to the contractor. We propose to identify specific methods at d tools that NASA projects can use to mitigate the adverse el ects of the three problems. TWO broad classes of methoddt ~ols will be explored. The first will be those that provide NASA p ojects with insight and oversight into contractors' activities. The st cond will be those that help projects objectively assess, and thus i nprwe, their software acquisition capability. Of particular interest is the Software Engineering Institute's (SEI) Software Acqt isition Capability Maturity Model (SA-CMMO).

Hankinson, Allen↗

Guiding Integration of Formal Verification in Assurance Cases

Assurance cases are being increasingly acknowledged as away to build trust in complex systems with autonomous capabilities. An assurance case is a comprehensive, defensible, and valid justification that a system will function as intended for a specific mission and operating environment. Formal verification is often reserved for the most critical components of such systems. However, formal verification tools are often complex, and their usage is subject to many constraints and contextual dependencies. This can raise challenges both for performing the verification as well as reflecting the verification results appropriately in the assurance case, especially for non-expert users of the verification tool. To address these challenges, we present a tool-supported methodology for integrating formal verification results in an assurance case by capturing key verification method information in a rigorously constructed assurance case. In particular, we capture the tool specification in terms of its inputs, outputs, and assurance constraints as assumptions over inputs and guarantees provided over its outputs. The tool specification is parametrized over the inputs and outputs to both guide the intended application of the tool, as well as to check that the tool has been applied following the stated assumptions and that the guarantees hold. We define a generic tool assurance argument pattern that enables integration of the verification results in the assurance case by allowing custom refinement and automated instantiation for each tool use. We demonstrate our methodology on two formal verification tools and their applications to the verification of neural network properties for the aircraft domain.

Assurance Cases↗

Mission Operations Assurance

Integrate the mission operations assurance function into the flight team providing: (1) value added support in identifying, mitigating, and communicating the project's risks and, (2) being an essential member of the team during the test activities, training exercises and critical flight operations.

project tracking↗