Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety Boundary”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Bayesian Statistics and Uncertainty Quantification for Safety Boundary Analysis in Complex Systems

The analysis of a safety-critical system often requires detailed knowledge of safe regions and their highdimensional non-linear boundaries. We present a statistical approach to iteratively detect and characterize the boundaries, which are provided as parameterized shape candidates. Using methods from uncertainty quantification and active learning, we incrementally construct a statistical model from only few simulation runs and obtain statistically sound estimates of the shape parameters for safety boundaries.

Active Learning↗

Online Dectection and Modeling of Safety Boundaries for Aerospace Application Using Bayesian Statistics

The behavior of complex aerospace systems is governed by numerous parameters. For safety analysis it is important to understand how the system behaves with respect to these parameter values. In particular, understanding the boundaries between safe and unsafe regions is of major importance. In this paper, we describe a hierarchical Bayesian statistical modeling approach for the online detection and characterization of such boundaries. Our method for classification with active learning uses a particle filter-based model and a boundary-aware metric for best performance. From a library of candidate shapes incorporated with domain expert knowledge, the location and parameters of the boundaries are estimated using advanced Bayesian modeling techniques. The results of our boundary analysis are then provided in a form understandable by the domain expert. We illustrate our approach using a simulation model of a NASA neuro-adaptive flight control system, as well as a system for the detection of separation violations in the terminal airspace.

Statistics↗

Commercial Crew Program Crew Safety Strategy

The purpose of this presentation is to explain to our international partners (ESA and JAXA) how NASA is implementing crew safety onto our commercial partners under the Commercial Crew Program. It will show them the overall strategy of 1) how crew safety boundaries have been established; 2) how Human Rating requirements have been flown down into programmatic requirements and over into contracts and partner requirements; 3) how CCP SMA has assessed CCP Certification and CoFR strategies against Shuttle baselines; 4) Discuss how Risk Based Assessment (RBA) and Shared Assurance is used to accomplish these strategies.

Crew Safety↗

MARGInS: Model-Based Analysis of Realizable Goals in Systems

Under NASAs Constellation effort, the Exploration Technology Development Program funded research toward a system validation capability that applied machine learning and test-case generation techniques to the analysis of black-box system behavior. The behavior analysis capability scaled to spaces of hundreds of input parameters and tens of thousands of test cases. Aerospace systems at the vehicle level, especially those systems which contain some level of autonomy, are best described by hybrid and non-linear mathematics. Even simplified models of such systems need parameter dimensionalities in the hundreds or thousands of parameters in order to capture sufficient fidelity. The System Safety Assessments (such as those described in the SAE ARP 4761A Safety Assessment Process guidelines) for these systems are prone to errorinteractions between the vehicles subsystems are complex, and can display emergent behaviors. NASA captured this new analysis in the Model-based Analysis of Realizable Goals in Systems (MARGInS) tool and applied it to the Pad Abort 1 (PA-1) simulation as part of the independent validation and verification cycle before the PA-1 flight test in May of 2010. MARGInS evaluated the adherence of the high-fidelity simulation to its requirements, and deter- mined the margins to failure from the expected nominal input conditions. Following the PA-1 test, the capabilities within the MARGInS framework have been extended with sophisticated statistical and white-box test case generation techniques and applied to other NASA missions. The frame- work now includes a critical factors analysis that was applied to NASAs Orion simulation and design. NASAs Aeronautics Research Mission Directorate (ARMD) leveraged the existing MARGInS framework for work on aviation safety for civil transport vehicles and for research on autonomy issues. The NASA ARMD effort created a time series output prediction capability that has been used to characterize trajectories for a plane with an adaptive control system, and a safety boundary detection capability that has been applied to an air traffic control concept of operation for the Federal Aviation Administration. The statistical and machine- learning based techniques within MARGInS have been successfully combined with concolic execution to improve the coverage of a critical unit by driving system-level inputs. The use case driving the concolic execution and MARGInS integration was inspired by the Air France 447 disaster in which the loss of a critical functionality (the airspeed calculation from the pitot tubes) led to loss of the entire plane with the people aboard. To illustrate capabilities and limitations, we will highlight the analyses for the applications listed above. We will then discuss the future plans for MARGInS and its interfaces with other tools.

Validation↗

Validating an Air Traffic Management Concept of Operation Using Statistical Modeling

Validating a concept of operation for a complex, safety-critical system (like the National Airspace System) is challenging because of the high dimensionality of the controllable parameters and the infinite number of states of the system. In this paper, we use statistical modeling techniques to explore the behavior of a conflict detection and resolution algorithm designed for the terminal airspace. These techniques predict the robustness of the system simulation to both nominal and off-nominal behaviors within the overall airspace. They also can be used to evaluate the output of the simulation against recorded airspace data. Additionally, the techniques carry with them a mathematical value of the worth of each prediction-a statistical uncertainty for any robustness estimate. Uncertainty Quantification (UQ) is the process of quantitative characterization and ultimately a reduction of uncertainties in complex systems. UQ is important for understanding the influence of uncertainties on the behavior of a system and therefore is valuable for design, analysis, and verification and validation. In this paper, we apply advanced statistical modeling methodologies and techniques on an advanced air traffic management system, namely the Terminal Tactical Separation Assured Flight Environment (T-TSAFE). We show initial results for a parameter analysis and safety boundary (envelope) detection in the high-dimensional parameter space. For our boundary analysis, we developed a new sequential approach based upon the design of computer experiments, allowing us to incorporate knowledge from domain experts into our modeling and to determine the most likely boundary shapes and its parameters. We carried out the analysis on system parameters and describe an initial approach that will allow us to include time-series inputs, such as the radar track data, into the analysis

Statistical emulation↗

ACES M and S: Unmitigated Factorial Encounter Study on DAA/TCAS Interoperability

Realization of the expected proliferation of Unmanned Aircraft System (UAS) operations in the National Airspace System (NAS) depends on the development and validation of standards for UAS Detect and Avoid (DAA) Systems. The RTCA Special Committee 228 is charged with leading the development of draft Minimum Operational Performance Standards (MOPS) for UAS DAA Systems. NASA, as a participating member of RTCA SC-228 is committed to supporting the development and validation of draft requirements for DAA alerting and guidance systems. This presentation contains the results of two combinatorial encounter analysis studies using NASA's SAA Control fast-time simulation capability for this purpose. In these studies, encounters between two aircraft were simulated one at a time for the full factorial combination of encounter geometries (e.g., encounter angle, CPA offset) and aircraft performance (e.g., ownership and intruder ground speeds and vertical rates). The first study analyzes the relationships (e.g., timeline) between the different alerting-safety regions in the SC-228 MOPS (in order of increasing severity): 1) DAA warning alert, 2) well clear recovery (WCR) guidance, 3) DAA-Collision Avoidance (CA), and 4) TCAS RA. This study will focus primarily on encounter situations in which TCAS RA occurs prior to any of the other alerting-safety boundaries. In particular, this study will investigate whether using vertical distance or vertical distance at closest point of approach (i.e., vertical miss distance or VMD) is more appropriate for the definition of the DAA-CA region. In addition, cases where transitions between different regions skip an intermediate region will be analyzed. The second study in this presentation explores a proposal to use an altitude rate error threshold to determine if vertical maneuvers are acceptable for DAA WCR guidance against non-cooperative intruders. This study incorporates the radar from the Honeywell sensor model and examines a series of pairwise encounters between a non-cooperative intruder and a UAS ownship, with different combinations of intruder states and ownship performance levels. The study uses SAA Control as a simulation platform and pilot model, and Omnibands to provide DWC recovery guidance. Two simulation sets, one that allows vertical DWC recovery guidance and one that does not, are compared to determine if encounters with altitude rate errors above 250 feet-per-minute are more likely to have more severe losses of well clear, as determined by the Loss of Well-Clear Severity metric.

SaaControl↗

MARGInS Model-Based Analysis of Realizable Goals in Systems

The high complexity of modern aircraft and spacecraft requires elaborate Verification and Validation (V&V) approaches to make sure that such complex systems work properly and reliably. MARGInS is a framework for the analysis, understanding, and prediction of the behavior of a complex, hybrid system. MARGInS contains a set of machine learning and statistical algorithms for multivariate clustering, treatment learning, critical factor determination, time-series analysis, event prediction, and safety-boundary detection and characterization. The framework supports system testing and can be configured to find novel features in test suites, determine classes of behavior, propose new experiments that can efficiently explore and characterize the boundaries between classes of system behavior, and to create visualizations and reports.

He, Yuning↗

An assessment of ocean alkalinity enhancement using aqueous hydroxides: kinetics, efficiency, and precipitation thresholds

Abstract. Ocean alkalinity enhancement (OAE) is a promising approach to marine carbon dioxide removal (mCDR) that leverages the large surface area and carbon storage capacity of the oceans to sequester atmospheric CO2 as dissolved bicarbonate (HCO3-). One OAE method involves the conversion of salt in seawater into aqueous alkalinity (NaOH), which is returned to the ocean. The resulting increase in seawater pH and alkalinity causes a shift in dissolved inorganic carbon (DIC) speciation toward carbonate and a decrease in the surface ocean pCO2. The shift in the pCO2 results in enhanced uptake of atmospheric CO2 by the seawater due to gas exchange. In this study, we systematically test the efficiency of CO2 uptake in seawater treated with NaOH at aquarium (15 L) and tank (6000 L) scales to establish operational boundaries for safety and efficiency in advance of scaling up to field experiments. CO2 equilibration occurred on the order of weeks to months, depending on circulation, air forcing, and air bubbling conditions within the test tanks. An increase of ∼0.7–0.9 mol DIC per mol added alkalinity (in the form of NaOH) was observed through analysis of seawater bottle samples and pH sensor data, consistent with the value expected given the values of the carbonate system equilibrium calculations for the range of salinities and temperatures tested. Mineral precipitation occurred when the bulk seawater pH exceeded 10.0 and Ωaragonite exceeded 30.0. This precipitation was dominated by Mg(OH)2 over hours to 1 d before shifting to CaCO3,aragonite precipitation. These data, combined with models of the dilution and advection of alkaline plumes, will allow the estimation of the amount of carbon dioxide removal expected from OAE pilot studies. Future experiments should better approximate field conditions including sediment interactions, biological activity, ocean circulation, air–sea gas exchange rates, and mixing zone dynamics.

Ringham, Mallory C. (ORCID:0000000348020185)↗

Colossal Tooling Design: 3D Simulation for Ergonomic Analysis

The application of high-level 3D simulation software to the design phase of colossal mandrel tooling for composite aerospace fuel tanks was accomplished to discover and resolve safety and human engineering problems. The analyses were conducted to determine safety, ergonomic and human engineering aspects of the disassembly process of the fuel tank composite shell mandrel. Three-dimensional graphics high-level software, incorporating various ergonomic analysis algorithms, was utilized to determine if the process was within safety and health boundaries for the workers carrying out these tasks. In addition, the graphical software was extremely helpful in the identification of material handling equipment and devices for the mandrel tooling assembly/disassembly process.

Hunter, Steve L.↗

Statistical learning framework for safety and failure analysis of a DNN-based autonomous aircraft system

Deep Neural Networks (DNNs) and Machine Learning technology is increasingly used for safety-critical applications in the Aerospace domain. To ensure safe operations, the DNN and the system must undergo rigorous verification and validation, including advanced statistical analyses. Performance and safety of the DNN and system behavior must not only be analyzed for the nominal case, but under numerous off-nominal and failure cases. In this paper we will describe how our statistical learning framework SYSAI can efficiently perform such analyses using the tool’s unique combination of advanced learning modeling and statistical analysis techniques. SYSAI can effectively explore the high-dimensional state and failure space of the system under test; geometrical shape detection of safety regions and boundaries support explainability of the results to the designer. In this paper, we report experiments and results obtained with a vision-based DNN control system (ACT) that is capable of autonomously steering an aircraft down a runway.

Yuning He↗

Exploring the Early Lightning Notification of an Electric Field Mill at the Savannah River Site

At the Savannah River Site (SRS), employees receive automated broadcast notification about lightning only after three strikes have already occurred near the site boundary. To increase employee safety, it is preferential to give employees lead time before lightning strikes occur. We compared measurements from an on-site electric field mill to lightning detection data from the National Lightning Detection Network and the Geostationary Lightning Mapper. Using a difference threshold, we determined that the electric field mill provided a lead time greater than 6 minutes for 95% of lightning events from 2009-2020, with an average lead time of 56 minutes. Detection of events were limited to a 7-mile radius around the field mill. We also identified that the field mill threshold generated many false detections not clearly identified. False detections and detections from only precipitation can be reduced by using a second threshold without creating too many missed detections (Type II errors). The two thresholds used together provide the best information about rapidly changing electric fields and aid in advanced detection necessary to improve the lightning warning system used at SRS.

42 ENGINEERING↗

STS-114: Discovery Flight Day 7 Post MMT Meeting

Wayne Hale Space Shuttle Deputy Program Manager, and Chuck Campbell Subsystem Engineer in Aerothermodynamics are seen in this post mission management teem briefing on this seventh day of space flight. Wayne Hale begins with talking about how the International Space Station has been resupplied with its necessities, and that the Control Moment Gyroscope (CSG) has been replaced. Hale expresses his concern about the health of the Space Shuttle Discovery with the two protruding gap fillers present, and the aerothermodynamics surrounding the gap fillers. These concerns led to the conclusion to have spacewalker Stephen Robinson remove the gap fillers during EVA-3. Campbell shows a video of the protruding gap filler aft of Nose Landing Gear Door (NLGD). Campbell and Hale answer questions from the news media about the risks of performing this spacewalk, boundary layer transitions, flight safety, inspections, and temperature concerns.

Source record↗

Wind tunnel results of the low-speed NLF(1)-0414F airfoil

The large performance gains predicted for the Natural Laminar Flow (NLF)(1)-0414F airfoil were demonstrated in two-dimensional airfoil tests and in wind tunnel tests conducted with a full scale modified Cessna 210. The performance gains result from maintaining extensive areas of natural laminar flow, and were verified by flight tests conducted with the modified Cessna. The lift, stability, and control characteristics of the Cessna were found to be essentially unchanged when boundary layer transition was fixed near the wing leading edge. These characteristics are very desirable from a safety and certification view where premature boundary layer transition (due to insect contamination, etc.) must be considered. The leading edge modifications were found to enhance the roll damping of the Cessna at the stall, and were therefore considered effective in improving the stall/departure resistance. Also, the modifications were found to be responsible for only minor performance penalties.

Murri, Daniel G.↗

Safe and Optimal Techniques Enabling Recovery, Integrity, and Assurance

There is a trend in the aviation industry to go from federated to integrated computing systems. Combining a number of traditional stand-alone federated systems into an integrated common platform (called Integrated Modular Avionics, IMA) has the benefit of increased power efficiency, reduced support hardware, and reduced cabling. However, changing from federated to integrated has a significant impact on the system architecture and hence the process of how avionic systems are to be analyzed. Traditional approaches to safety analysis become inefficient when functional boundaries can no longer be assumed for failure independence and fault isolation. In this report, we describe a tool that we developed to accelerate the safety engineer's ability to perform safety analysis of IMA systems through modeling, as well as optimize the system engineer's ability to develop a system through architecture synthesis. This work was the result of a three-year research effort called SOTERIA (Safe and Optimal Techniques Enabling Recovery, Integrity, and Assurance). We developed a compositional modeling language that supports rapid development, modification, and evaluation of architectures. The modeling language is structured such that the end-user defines a library of components with information on component reliability, connectivity, and fault propagation logic. The system model is built by instantiating the components from the library, connecting the components, and identifying the top-level faults of interest. Our tool is compositional in that the end-user only needs to define safety aspects at the component level. The tool takes the model and automatically synthesizes both the qualitative and quantitative safety analyses. We go further by allowing users to describe system information such as components to use in an architecture and their connection compatibility and automatically synthesize an architecture that meets the top-level probability target adhering to end-user specified constraints. This capability allows users to rapidly explore a design space..

Siu, Kit Y.↗

Safer Systems: A NextGen Aviation Safety Strategic Goal

The Joint Planning and Development Office (JPDO), is charged by Congress with developing the concepts and plans for the Next Generation Air Transportation System (NextGen). The National Aviation Safety Strategic Plan (NASSP), developed by the Safety Working Group of the JPDO, focuses on establishing the goals, objectives, and strategies needed to realize the safety objectives of the NextGen Integrated Plan. The three goal areas of the NASSP are Safer Practices, Safer Systems, and Safer Worldwide. Safer Practices emphasizes an integrated, systematic approach to safety risk management through implementation of formalized Safety Management Systems (SMS) that incorporate safety data analysis processes, and the enhancement of methods for ensuring safety is an inherent characteristic of NextGen. Safer Systems emphasizes implementation of safety-enhancing technologies, which will improve safety for human-centered interfaces and enhance the safety of airborne and ground-based systems. Safer Worldwide encourages coordinating the adoption of the safer practices and safer systems technologies, policies and procedures worldwide, such that the maximum level of safety is achieved across air transportation system boundaries. This paper introduces the NASSP and its development, and focuses on the Safer Systems elements of the NASSP, which incorporates three objectives for NextGen systems: 1) provide risk reducing system interfaces, 2) provide safety enhancements for airborne systems, and 3) provide safety enhancements for ground-based systems. The goal of this paper is to expose avionics and air traffic management system developers to NASSP objectives and Safer Systems strategies.

Darr, Stephen T.↗

Addressing Unison and Uniqueness of Reliability and Safety for Better Integration

For a long time, both in theory and in practice, safety and reliability have not been clearly differentiated, which leads to confusion, inefficiency, and sometime counter-productive practices in executing each of these two disciplines. It is imperative to address the uniqueness and the unison of these two disciplines to help both disciplines become more effective and to promote a better integration of the two for enhancing safety and reliability in our products as an overall objective. There are two purposes of this paper. First, it will investigate the uniqueness and unison of each discipline and discuss the interrelationship between the two for awareness and clarification. Second, after clearly understanding the unique roles and interrelationship between the two in a product design and development life cycle, we offer suggestions to enhance the disciplines with distinguished and focused roles, to better integrate the two, and to improve unique sets of skills and tools of reliability and safety processes. From the uniqueness aspect, the paper identifies and discusses the respective uniqueness of reliability and safety from their roles, accountability, nature of requirements, technical scopes, detailed technical approaches, and analysis boundaries. It is misleading to equate unreliable to unsafe, since a safety hazard may or may not be related to the component, sub-system, or system functions, which are primarily what reliability addresses. Similarly, failing-to-function may or may not lead to hazard events. Examples will be given in the paper from aerospace, defense, and consumer products to illustrate the uniqueness and differences between reliability and safety. From the unison aspect, the paper discusses what the commonalities between reliability and safety are, and how these two disciplines are linked, integrated, and supplemented with each other to accomplish the customer requirements and product goals. In addition to understanding the uniqueness in reliability and safety, a better understanding of unison and commonalities will further help in understanding the interaction between reliability and safety. This paper discusses the unison and uniqueness of reliability and safety. It presents some suggestions for better integration of the two disciplines in terms of technical approaches, tools, techniques, and skills to enhance the role of reliability and safety in supporting a product design and development life cycle. The paper also discusses eliminating the redundant effort and minimizing the overlap of reliability and safety analyses for an efficient implementation of the two disciplines.

Huang, Zhaofeng↗

An Executable Choreography Framework for Dynamic Service-Oriented Architectures

Interoperability and loose coupling requirements are pushing the next generation of distributed applications towards more decentralized and more dynamic interaction schemes, which the classic requestJresponse communication paradigm can hardly accommodate. Hence, sound foundations and mechanisms for the establishment of unmticiptitteb peer-to-peer interactions across organizational boundaries are of significant importance to upcoming middleware platforms. The Executable Choreography Framework (ECF) is a middleware-level framework that targets dynamic and decentralized service compositions. The ECF combines transparent context propagation with aspect-oriented software composition techniques to dynamically refine the default control and data flow of service invocations. The framework provides a ground for experimentation with dynamic and distributed workflows, and a base to assess their safety and applicability when depioyed across organizational boundaries.

Akkawi, Faisal↗

The Key Role of Grain Boundary Dynamics in Revolutionizing the Potential of Solid Electrolytes

Solid electrolytes (SEs) have the potential to enhance the safety and performance of Li-metal batteries. However, the existence of grain boundaries in polycrystalline SEs presents a significant challenge for both ionic and electronic migration, promoting the propagation of detrimental lithium dendrites. This study compares the roles of grain boundaries in electrical properties of three distinct SEs including garnet-type Li 6.5 La 3 Zr 1.5 Ta 0.5 O 12 (LLZO), argyrodite-type Li 6 PS 5 Cl (LPSC), and NASICON-type Li 1+x+y Al x (Ti,Ge) 2-x Si y P 3-y O 12 (LATP). Results demonstrate that the electronic and ionic conductivities of solid-state electrolytes are affected differently by grain boundaries, depending on the specific type of electrolyte. For instance, LLZO and LATP experience dielectric breakdown at 3.7 and 5.3 V, respectively, while LPSC does not exhibit such behavior. Here, a new chemical modification is proposed that simultaneously alters the composition of both the surface and grain boundaries of SEs, ultimately reducing electronic conductivity for the LLZO SEs. Consequently, the proposed LLZO exhibits unprecedented dendrite-free cycling stability, achieving a remarkable 12 000-h lifetime at room temperature, surpassing conventional strategies such as surface coatings in dendrite mitigation. This study highlights the significance of modifying grain boundaries to design safe and durable Li-metal batteries. It provides new insights for developing SEs that are highly resistant to dendrite formation.

36 MATERIALS SCIENCE↗