Search NASA⌕ Search

SEARCH · Search NASA

Results for “Functional Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Moving from Information Assurance to Functional Assurance with Engineered Controls

Cyber threats to operational technology demand more than traditional IT defenses—they require full-spectrum mission assurance. Cyber-Informed Engineering (CIE) is an approach that embeds engineered controls into system design to ensure critical functions remain safe and reliable, even under attack. Unlike conventional cybersecurity tools, engineered controls act directly on physical processes to prevent unacceptable outcomes such as equipment damage or mission failure. This session will outline the CIE framework and share examples of consequence-based design that deliver true resilience, not just fail-safe behaviors. Attendees will learn how to integrate these principles into the engineering lifecycle to support resilient-by-design architectures and inform emerging standards. This talk sets the stage for the panel discussion on advancing CIE across sectors as digital and physical systems converge.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

CRITICAL FUNCTION ASSURANCE: Understanding Critical Function and Critical Function Delivery is Foundational for Meaningful ICS Security Improvement and Policy Efforts

Modern life is enabled by a complex and interdependent web of critical functions, including energy, communications, transportation, food, and water. Automation has significantly reduced or replaced human interactions in the delivery of these functions, resulting in a web of goods and services that are made available 24/7 only through unique and intentional deployments of microprocessors, software, and firmware technologies. The prospect of cyber-enabled sabotage of these processes disrupts traditional risk determination models. Critical Function Assurance (CFA) is a foundational approach to identifying, prioritizing, and mitigating the risk that is inherent in the delivery of critical functions that depend on digital technology. It provides rapid focus to what matters most and illuminates elements and areas of risk that otherwise are often overlooked. This focus enables effective application of available security resources and optimizes security strategy and policy efforts. This paper introduces CFA to decision makers and risk executives (including CEOs, COOs, CFOs, and CISOs) whose organizations support and deliver the critical functions that underpin national defense, societal health and safety, and a vibrant economy.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cyber-Enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering

Cyber-enabled Sabotage, Critical Function Assurance, and Cyber-Informed Engineering: This discussion will introduce the idea of cyber-enabled sabotage, and the role engineering plays in the cyber defense of critical functions with a focus on electric power systems. It will outline how and why engineering practice must be used to apply cybersecurity principles to establish safe and reliable operations even in the face of determined and skilled adversaries, and give an overview of INL’s Consequence-Driven Cyber-Informed Engineering methodology to apply these principles. There will be an opportunity for audience questions and answers at the end of the session.

42 ENGINEERING↗

Management of government quality assurance functions for NASA contracts

This handbook sets forth requirements for NASA direction and management of government quality assurance functions performed for NASA contracts and is applicable to all NASA installations. These requirements will standardize management to provide the minimum oversight and effective use of resources. This handbook implements Federal Acquisition Regulation (FAR) Part 46, NASA FAR Supplement 18-46, Quality Assurance, and NMI 7410.1. Achievement of established quality and reliability goals at all levels is essential to the success of NASA programs. Active participation by NASA and other agency quality assurance personnel in all phases of contract operations, including precontract activity, will assist in the economic and timely achievement of program results. This involves broad participation in design, development, procurement, inspection, testing, and preventive and corrective actions. Consequently, government, as well as industry, must place strong emphasis on the accomplishment of all functions having a significant bearing on quality and reliability from program initiation through end-use of supplies and services produced. For purposes of implementing NASA and other agency agreements, and to provide for uniformity and consistency, the terminology and definitions prescribed herein and in a future handbook shall be utilized for all NASA quality assurance delegations and subsequent redelegations.

Source record↗

Function Allocation between Automation and Human Pilot for Airborne Separation Assurance

Maintaining safe separation between aircraft is a key determinant of the airspace capacity to handle air transportation. With the advent of satellite-based surveillance, aircraft equipped with the needed technologies are now capable of maintaining awareness of their location in the airspace and sharing it with their surrounding traffic. As a result, concepts and cockpit automation are emerging to enable delegating the responsibility of maintaining safe separation from traffic to the pilot; thus increasing the airspace capacity by alleviating the limitation of the current non-scalable centralized ground-based system. In this paper, an analysis of allocating separation assurance functions to the human pilot and cockpit automation is presented to support the design of these concepts and technologies. A task analysis was conducted with the help of Petri nets to identify the main separation assurance functions and their interactions. Each function was characterized by three behavior levels that may be needed to perform the task: skill, rule and knowledge based levels. Then recommendations are made for allocating each function to an automation scale based on their behavior level characterization and with the help of Subject matter experts.

Idris, Husni↗

Concept of Operation for Tactical Separation Assurance in Super-Density Operations

The Airspace Systems Program is committed to supporting the Next Generation Air Transportation System through research and development in select areas. One such area, referred to as Super Density Operations, is conducting research to develop technologies that will safely increase the throughput in busy terminal area environments. The purpose of this document is to develop a Concept of Operations for the Tactical Separation Assurance function, one of the functions included in Super Density Operations. A functional description of the technologies required for Super Density Operations is presented followed by a more detail description of the Tactical Separation Assurance function. Two story boards are presented to illustrate the operational use of the Tactical Separation Assurance function under different situations. The last section proposes a pathway to implementing the Tactical Separation Assurance function.

Denery, Dallas G.↗

Model Based Mission Assurance: Emerging Opportunities for Robotic Systems

The emergence of Model Based Systems Engineering (MBSE) in a Model Based Engineering framework has created new opportunities to improve effectiveness and efficiencies across the assurance functions. The MBSE environment supports not only system architecture development, but provides for support of Systems Safety, Reliability and Risk Analysis concurrently in the same framework. Linking to detailed design will further improve assurance capabilities to support failures avoidance and mitigation in flight systems. This also is leading new assurance functions including model assurance and management of uncertainty in the modeling environment. Further, the assurance cases, a structured hierarchal argument or model, are emerging as a basis for supporting a comprehensive viewpoint in which to support Model Based Mission Assurance (MBMA).

Mission Assurance↗

A Complexity Metric for Automated Separation

A metric is proposed to characterize airspace complexity with respect to an automated separation assurance function. The Maneuver Option metric is a function of the number of conflict-free trajectory change options the automated separation assurance function is able to identify for each aircraft in the airspace at a given time. By aggregating the metric for all aircraft in a region of airspace, a measure of the instantaneous complexity of the airspace is produced. A six-hour simulation of Fort Worth Center air traffic was conducted to assess the metric. Results showed aircraft were twice as likely to be constrained in the vertical dimension than the horizontal one. By application of this metric, situations found to be most complex were those where level overflights and descending arrivals passed through or merged into an arrival stream. The metric identified high complexity regions that correlate well with current air traffic control operations. The Maneuver Option metric did not correlate with traffic count alone, a result consistent with complexity metrics for human-controlled airspace.

Aweiss, Arwa↗

Gateway Program Safety and Mission Assurance Integration - the Future of Safe Deep Space Human Exploration

As a foundational element of the National Aeronautics and Space Administration (NASA) Artemis Campaign, the Gateway is an incrementally built cislunar spacecraft that will serve as a platform for deep space human exploration, science, and technology demonstration. The Gateway will be a unifying catalyst for international partners around the world to establish sustained deep space scientific investigations, lunar surface access, and missions to Mars. As human exploration moves farther away from Earth, spacecraft designs must prioritize and optimize mass and volume allocations, while minimizing human and spacecraft risk. To accomplish this objective, the Gateway Program Safety and Mission Assurance functions develop, implement, and ensure compliance with requirements, in concert with the accurate characterization and transparent communication of residual hazard risks, for integrated safety, reliability and maintainability and quality assurance. Safety and Mission Assurance was a key contributor during Gateway program pre-formulation and formulation activities where safety and reliability analysis was embedded in the Gateway Systems Engineering and Integration team. During these early program stages, a preliminary Gateway Integrated Hazard Analysis and Preliminary Gateway Probabilistic Risk Assessment assisted in Gateway architectural and operational definition as part of a risk-informed design process. As the deep space architecture has matured, the integrated Safety and Mission Assurance analyses have matured, new safety review processes have been developed, and requirements have been refined to ensure compliance with integrated safety and mission assurance objectives. The Gateway Program is currently concluding the preliminary design review informed milestone, where the primary objectives included: - Ensured completeness and consistency of the preliminary design, including the meeting of all requirements within appropriate margins and acceptable risk posture. - Identification of any major issues moving forward to the Critical Design phase. At this milestone, Safety and Mission Assurance provided numerous products, including Gateway Top Risks and Risk Mitigation Plans, updated integrated hazard analyses, updated probabilistic risk assessment, Crew Survival Analysis Report, and updated Safety and Mission Assurance Requirements and Plans. These products provide a many-faceted perspective on the inherent risk and available mitigations involved in flying the current proposed vehicle design and anticipated stack configurations. In addition, Safety and Mission Assurance identified top technical, process and workforce concerns to be addressed as the program progresses toward the critical design phase. This paper will detail the evolution of the Gateway Program Safety and Mission Assurance integration functions, provide its current status and lessons learned for future human spaceflight programs. Throughout this paper the key tenets of the Gateway Program Safety and Mission Assurance will be discussed: - Application of a risk-informed approach to identify and mitigate areas of highest risk. - Leverage of valuable processes and lessons learned from earlier spaceflight programs. - Development of Safety and Mission Assurance products to inform design risk trades. - Utilization of common Safety and Mission Assurance practices to identify safety risks for multiple perspectives: top-down, bottom-up, and across lines of integration. - Approval of safety hazards at the appropriate level of authority, keeping most deliberation closest to design expertise and elevating risks of greatest concern for program-level consideration. - Championing of Safety and Mission Assurance processes and forums to foster a pervasive safety culture that is transparent, inclusive, and collaborative between all partners. These tenets have allowed the Gateway Safety and Mission Assurance function to play a key role in optimized vehicle design evolution, and early identification and mitigation of Gateway program and Artemis mission risk.

Helen Vaccaro↗

Pilot education and safety awareness programs

Guidelines necessary for the implementation of safety awareness programs for commuter airlines are discussed. A safety office can be viewed as fulfilling either an education and training function or a quality assurance function. Issues such as management structure, motivation, and cost limitations are discussed.

Shearer, M.↗

Functional Allocation Approach for Separation Assurance for Remotely Piloted Aircraft

A functional analysis framework is employed with the objective of exploring the separation assurance function for the remotely piloted aircraft system. The architecture of the remotely piloted aircraft system—highlighting several of the component systems and the functions resident onboard the remotely piloted aircraft and in the ground control station—is described to provide the context for understanding the complexity of the said system for a detailed functional analysis. The interactions between the agents of the separation assurance function belonging to the air traffic service provider, remotely piloted aircraft system operator and remotely piloted aircraft are described. Separation assurance by air traffic control, remain well clear by the remotely piloted aircraft system and collision avoidance onboard the remotely piloted aircraft are briefly discussed. The functional analysis framework is illustrated by relating the agents to the actions of (a) acquiring the surveillance information, (b) checking for conflicts, (c) creating the solutions for resolving conflicts and (d) implementing the conflict resolution solutions. This example is offered as a template by which a more detailed functional analysis of this and other functions could be developed. The architecture of the remotely piloted aircraft system is described to aid this process.

functional analysis↗

Functional Allocation Approach for Separation Assurance for Remotely Piloted Aircraft

A functional analysis framework is employed with the objective of exploring the separation assurance function for the remotely piloted aircraft system. The architecture of the remotely piloted aircraft system—highlighting several of the component systems and the functions resident onboard the remotely piloted aircraft and in the ground control station—is described to provide the context for understanding the complexity of the said system for a detailed functional analysis. The interactions between the agents of the separation assurance function belonging to the air traffic service provider, remotely piloted aircraft system operator and remotely piloted aircraft are described. Separation assurance by air traffic control, remain well clear by the remotely piloted aircraft system and collision avoidance onboard the remotely piloted aircraft are briefly discussed. The functional analysis framework is illustrated by relating the agents to the actions of (a) acquiring the surveillance information, (b) checking for conflicts, (c) creating the solutions for resolving conflicts and (d) implementing the conflict resolution solutions. This example is offered as a template by which a more detailed functional analysis of this and other functions could be developed. The architecture of the remotely piloted aircraft system is described to aid this process.

Functional analysis↗

Implementation of Programmatic Quality and the Impact on Safety

The purpose of this paper is to discuss the implementation of a programmatic quality assurance discipline within the International Space Station Program and the resulting impact on safety. NASA culture has continued to stress safety at the expense of quality when both are extremely important and both can equally influence the success or failure of a Program or Mission. Although safety was heavily criticized in the media after Col~imbiaa, strong case can be made that it was the failure of quality processes and quality assurance in all processes that eventually led to the Columbia accident. Consequently, it is possible to have good quality processes without safety, but it is impossible to have good safety processes without quality. The ISS Program quality assurance function was analyzed as representative of the long-term manned missions that are consistent with the President s Vision for Space Exploration. Background topics are as follows: The quality assurance organizational structure within the ISS Program and the interrelationships between various internal and external organizations. ISS Program quality roles and responsibilities with respect to internal Program Offices and other external organizations such as the Shuttle Program, JSC Directorates, NASA Headquarters, NASA Contractors, other NASA Centers, and International Partner/participants will be addressed. A detailed analysis of implemented quality assurance responsibilities and functions with respect to NASA Headquarters, the JSC S&MA Directorate, and the ISS Program will be presented. Discussions topics are as follows: A comparison of quality and safety resources in terms of staffing, training, experience, and certifications. A benchmark assessment of the lessons learned from the Columbia Accident Investigation (CAB) Report (and follow-up reports and assessments), NASA Benchmarking, and traditional quality assurance activities against ISS quality procedures and practices. The lack of a coherent operational and sustaining quality assurance strategy for long-term manned space flight. An analysis of the ISS waiver processes and the Problem Reporting and Corrective Action (PRACA) process implemented as quality functions. Impact of current ISS Program procedures and practices with regards to operational safety and risk A discussion regarding a "defense-in-depth" approach to quality functions will be provided to address the issue of "integration vs independence" with respect to the roles of Programs, NASA Centers, and NASA Headquarters. Generic recommendations are offered to address the inadequacies identified in the implementation of ISS quality assurance. A reassessment by the NASA community regarding the importance of a "quality culture" as a component within a larger "safety culture" will generate a more effective and value-added functionality that will ultimately enhance safety.

Huls, Dale Thomas↗

Pilot and Controller Evaluations of Separation Function Allocation in Air Traffic Management

Two human-in-the-loop simulation experiments were conducted in coordinated fashion to investigate the allocation of separation assurance functions between ground and air and between humans and automation. The experiments modeled a mixed-operations concept in which aircraft receiving ground-based separation services shared the airspace with aircraft providing their own separation service (i.e., self-separation). Ground-based separation was provided by air traffic controllers without automation tools, with tools, or by ground-based automation with controllers in a managing role. Airborne self-separation was provided by airline pilots using self-separation automation enabled by airborne surveillance technology. The two experiments, one pilot-focused and the other controller-focused, addressed selected key issues of mixed operations, assuming the starting point of current-day operations and modeling an emergence of NextGen technologies and procedures. In the controller-focused experiment, the impact of mixed operations on controller performance was assessed at four stages of NextGen implementation. In the pilot-focused experiment, the limits to which pilots with automation tools could take full responsibility for separation from ground-controlled aircraft were tested. Results indicate that the presence of self-separating aircraft had little impact on the controllers' ability to provide separation services for ground-controlled aircraft. Overall performance was best in the most automated environment in which all aircraft were data communications equipped, ground-based separation was highly automated, and self-separating aircraft had access to trajectory intent information for all aircraft. In this environment, safe, efficient, and highly acceptable operations could be achieved for twice today's peak airspace throughput. In less automated environments, reduced trajectory intent exchange and manual air traffic control limited the safely achievable airspace throughput and negatively impacted the maneuver efficiency of self-separating aircraft through high-density airspace. In a test of scripted conflicts with ground-managed aircraft, flight crews of self-separating aircraft prevented separation loss in all conflicts with detection time greater than one minute. In debrief, pilots indicated a preference for at least five minute's alerting notice and trajectory intent information on all aircraft. When intent information on ground-managed aircraft was available, self-separating aircraft benefited from fewer conflict alerts and fewer required deviations from trajectory-based operations.

Wing, David↗

Pilot Subjective Assessments During an Investigation of Separation Function Allocation Using a Human-In-The-Loop Simulation

Two human-in-the-loop simulation experiments were conducted to investigate allocation of separation assurance functions between ground and air and between humans and automation. The experiments modeled a mixed-operations concept in which aircraft receiving ground-based separation services shared the airspace with aircraft providing their own separation service (i.e., self-separation). The two experiments, one pilot-focused and the other controller-focused, addressed selected key issues of mixed operations and modeling an emergence of NextGen technologies and procedures. This paper focuses on the results of the subjective assessments of pilots collected during the pilot-focused human-in-the-loop simulation, specifically workload and situation awareness. Generally the results revealed that across all conditions, pilots' perceived workload was low to medium, with the highest reported levels of workload occurring when the pilots experienced a loss of separation during the scenario. Furthermore, the results from the workload data and situation awareness data were complimentary such that when pilots reported lower levels of workload they also experienced higher levels of situation awareness.

Burke, Kelly A.↗

Spacelab Data Processing Facility (SLDPF) quality assurance expert systems development

The Spacelab Data Processing Facility (SLDPF) is an integral part of the Space Shuttle data network for missions that involve attached scientific payloads. Expert system prototypes were developed to aid in the performance of the quality assurance function of the Spacelab and/or Attached Shuttle Payloads processed telemetry data. The Spacelab Input Processing System (SIPS) and the Spacelab Output Processing System (SOPS), two expert systems, were developed to determine their feasibility and potential in the quality assurance of processed telemetry data. The capabilities and performance of these systems are discussed.

Basile, Lisa R.↗

Mission Operations Assurance

Integrate the mission operations assurance function into the flight team providing: (1) value added support in identifying, mitigating, and communicating the project's risks and, (2) being an essential member of the team during the test activities, training exercises and critical flight operations.

project tracking↗

Explosive Fracturing of an F-16 Canopy for Through-Canopy Crew Egress

Through-canopy crew egress, such as in the Harrier (AV-8B) aircraft, expands escape envelopes by reducing seat ejection delays in waiting for canopy jettison. Adverse aircraft attitude and reduced forward flight speed can further increase the times for canopy jettison. However, the advent of heavy, high-strength polycarbonate canopies for bird-strike resistance has not only increased jettison times, but has made seat penetration impossible. The goal of the effort described in this paper was to demonstrate a method of explosively fracturing the F-16 polycarbonate canopy to allow through-canopy crew ejection. The objectives of this effort were to: 1. Mount the explosive materials on the exterior of the canopy within the mold line, 2. Minimize visual obstructions, 3. Minimize internal debris on explosive activation, 4. Operate within less than 10 ms, 5. Maintain the shape of the canopy after functioning to prevent major pieces from entering the cockpit, and 6. Minimize the resistance of the canopy to seat penetration. All goals and objectives were met in a full-scale test demonstration. In addition to expanding crew escape envelopes, this canopy fracture approach offers the potential for reducing system complexity, weight and cost, while increasing overall reliability, compared to current canopy jettison approaches. To comply with International Traffic in Arms Regulations (ITAR) and permit public disclosure, this document addresses only the principles of explosive fracturing of the F-16 canopy materials and the end result. ITAR regulations restrict information on improving the performance of weapon systems. Therefore, details on the explosive loads and final assembly of this canopy fracture approach, necessary to assure functional performance, are not included.

Bement, Laurence J.↗