Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety architecture”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Model-Driven Development of Safety Architectures

We describe the use of model-driven development for safety assurance of a pioneering NASA flight operation involving a fleet of small unmanned aircraft systems (sUAS) flying beyond visual line of sight. The central idea is to develop a safety architecture that provides the basis for risk assessment and visualization within a safety case, the formal justification of acceptable safety required by the aviation regulatory authority. A safety architecture is composed from a collection of bow tie diagrams (BTDs), a practical approach to manage safety risk by linking the identified hazards to the appropriate mitigation measures. The safety justification for a given unmanned aircraft system (UAS) operation can have many related BTDs. In practice, however, each BTD is independently developed, which poses challenges with respect to incremental development, maintaining consistency across different safety artifacts when changes occur, and in extracting and presenting stakeholder specific information relevant for decision making. We show how a safety architecture reconciles the various BTDs of a system, and, collectively, provide an overarching picture of system safety, by considering them as views of a unified model. We also show how it enables model-driven development of BTDs, replete with validations, transformations, and a range of views. Our approach, which we have implemented in our toolset, AdvoCATE, is illustrated with a running example drawn from a real UAS safety case. The models and some of the innovations described here were instrumental in successfully obtaining regulatory flight approval.

Safety case↗

A Comparison of Bus Architectures for Safety-Critical Embedded Systems

We describe and compare the architectures of four fault-tolerant, safety-critical buses with a view to deducing principles common to all of them, the main differences in their design choices, and the tradeoffs made. Two of the buses come from an avionics heritage, and two from automobiles, though all four strive for similar levels of reliability and assurance. The avionics buses considered are the Honeywell SAFEbus (the backplane data bus used in the Boeing 777 Airplane Information Management System) and the NASA SPIDER (an architecture being developed as a demonstrator for certification under the new DO-254 guidelines); the automobile buses considered are the TTTech Time-Triggered Architecture (TTA), recently adopted by Audi for automobile applications, and by Honeywell for avionics and aircraft control functions, and FlexRay, which is being developed by a consortium of BMW, DaimlerChrysler, Motorola, and Philips.

Rushby, John↗

Robonaut 2 - Building a Robot on the International Space Station

In 2010, the Robonaut Project embarked on a multi‐phase mission to perform technology demonstrations on‐board the International Space Station (ISS), showcasing state of the art robotics technologies through the use of Robonaut 2 (R2). This phased approach implements a strategy that allows for the use of ISS as a test bed during early development to both demonstrate capability and test technology while still making advancements in the earth based laboratories for future testing and operations in space. While R2 was performing experimental trials onboard the ISS during the first phase, engineers were actively designing for Phase 2, Intra‐Vehicular Activity (IVA) Mobility, that utilizes a set of zero‐g climbing legs outfitted with grippers to grasp handrails and seat tracks. In addition to affixing the new climbing legs to the existing R2 torso, it became clear that upgrades to the torso to both physically accommodate the climbing legs and to expand processing power and capabilities of the robot were required. In addition to these upgrades, a new safety architecture was also implemented in order to account for the expanded capabilities of the robot. The IVA climbing legs not only needed to attach structurally to the R2 torso on ISS, but also required power and data connections that did not exist in the upper body. The climbing legs were outfitted with a blind mate adapter and coarse alignment guides for easy installation, but the upper body required extensive rewiring to accommodate the power and data connections. This was achieved by mounting a custom adapter plate to the torso and routing the additional wiring through the waist joint to connect to the new set of processors. In addition to the power and data channels, the integrated unit also required updated electronics boards, additional sensors and updated processors to accommodate a new operating system, software platform, and custom control system. In order to perform the unprecedented task of building a robot in space, extensive practice sessions and meticulous procedures were required. Since crew training time is at a premium, the R2 team took a skills‐based training approach to ensure the astronauts were proficient with a basic skill set while refining the detailed procedures over several practice sessions and simulations. In addition to the crew activities, meticulous ground procedures were required in order to upgrade firmware on the upper body motor drivers. The new firmware for the IVA mobility unit needed to be deployed using the old software system. This also provided an opportunity to upgrade the upper body joints with new software and allowed for limited insight into the success of the updates. Complete verification that the updated firmware was successfully loaded was not confirmed until the rewiring of the upper body torso was complete.

Diftler, Myron↗

Architectural Modeling and Analysis for Safety Engineering

Model-based development tools are increasingly being used for system-level development of safety-critical systems. Architectural and behavioral models provide important information that can be leveraged to improve the system safety analysis process. Model-based design artifacts produced in early stage development activities can be used to perform system safety analysis, reducing costs and providing accurate results throughout the system life-cycle. In this report we describe an extension to the Architecture Analysis and Design Language (AADL) that supports modeling of system behavior under failure conditions. This Safety Annex enables the independent modeling of component failures and allows safety engineers to weave various types of fault behavior into the nominal system model. The accompanying tool support uses model checking to propagate errors from their source to their effect on safety properties without the need to add separate propagation specifications. The tool also captures all minimal set of fault combinations that can cause violation of the safety properties, that can be compared to qualitative and quantitative objectives as part of the safety assessment process. We describe the Safety Annex, illustrate its use with a representative example, and discuss and demonstrate the tool support enabling an analyst to investigate the system behavior under failure conditions.

FTA↗

Selecting an Architecture for a Safety-Critical Distributed Computer System with Power, Weight and Cost Considerations

This report presents an example of the application of multi-criteria decision analysis to the selection of an architecture for a safety-critical distributed computer system. The design problem includes constraints on minimum system availability and integrity, and the decision is based on the optimal balance of power, weight and cost. The analysis process includes the generation of alternative architectures, evaluation of individual decision criteria, and the selection of an alternative based on overall value. In this example presented here, iterative application of the quantitative evaluation process made it possible to deliberately generate an alternative architecture that is superior to all others regardless of the relative importance of cost.

Torres-Pomales, Wilfredo↗

A safety-based decision making architecture for autonomous systems

Engineering systems designed specifically for space applications often exhibit a high level of autonomy in the control and decision-making architecture. As the level of autonomy increases, more emphasis must be placed on assimilating the safety functions normally executed at the hardware level or by human supervisors into the control architecture of the system. The development of a decision-making structure which utilizes information on system safety is detailed. A quantitative measure of system safety, called the safety self-information, is defined. This measure is analogous to the reliability self-information defined by McInroy and Saridis, but includes weighting of task constraints to provide a measure of both reliability and cost. An example is presented in which the safety self-information is used as a decision criterion in a mobile robot controller. The safety self-information is shown to be consistent with the entropy-based Theory of Intelligent Machines defined by Saridis.

Musto, Joseph C.↗

Sensitivity and Importance Measure Analyses for Various Design Architectures for High Safety-Significant Safety-Related Digital Instrumentation and Control Systems of Nuclear Power Plants

A transition from analog instrumentation and control (I&C) technologies to digital I&C technologies is taking place for license renewals of existing nuclear power plants and for operating licenses of new advanced reactors. This transition necessitates research on risk and economic assessments of digital I&C technologies to ensure the long-term safety and reliability of vital systems, reduce uncertainty in licensing costs in addition to timeline, support integration of digital I&C systems in the plant, and find the most efficient technology upgrades. Adding redundancy within systems or components is a common means of improving design safety; however, it can also make designs more prone to common-cause failures (CCFs). Introducing diversity into redundant systems or components is a way to mitigate and possibly eliminate CCFs, but it also increases plant complexity and may be costly. The balance between redundancy and diversity remains a challenge for digital I&C systems. This study performs sensitivity and importance analyses for four design architectures of two digital I&C systems—the reactor-trip system and the engineered safety features actuation system. For each system, two architectures are examined, including a redundant, non-diverse configuration and a redundant, diverse configuration. The sensitivity analysis will provide insights on the impact of introducing diversity to system reliability. The importance results will help identify risk-significant and risk-sensitive components and failure modes, which may be good candidates for future design improvement.

99 GENERAL AND MISCELLANEOUS↗

Risk Analysis of Various Design Architectures for High Safety-significant Safety-related Digital Instrumentation and Control Systems of Nuclear Power Plants during Accident Scenarios

This report documents the plus-up activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2022 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems was proposed for this strategy, which aims to (1) provide a best-estimate, risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the high safety-significant safety-related (HSSSR) DI&C systems, (2) support and supplement existing advanced risk-informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems to support system design decisions and diversity and redundancy applications, (4) assure the long-term safety and reliability of HSSSR DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the LWRS-developed framework instructs nuclear vendors and utilities on how to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). Adding diversity within system or components is the main means to eliminate and mitigate CCFs, but diversity also increases plant complexity and errors and may not address all sources of systematic failures. How to optimize the diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in HSSSR DI&C systems of NPPs and supporting relevant design optimization, the framework provides: ? An integrated best-estimate, risk-informed capability to address new technical digital issues quantitatively, accurately, and efficiently in plan modernization progress, such as software CCFs in HSSSR DI&C systems of NPPs ? A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to efficiently predict and prevent risk in the early design stage of DI&C systems ? Technical bases and risk-informed insights to assist U.S. Nuclear Regulatory Commission (NRC) and industry to address and fulfill the risk-informed alternatives for evaluation of CCFs in HSSSR DI&C systems of NPPs ? An integrated risk-informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The plus-up research and development efforts of this project in FY 2022 are focused on methodology improvement of software CCF modeling and estimation, prevention analysis, importance analysis and risk analysis of various design architectures of HSSSR DI&C systems. This work greatly enhances the capability of the LWRS-developed framework for the risk assessment and design optimization of safety-critical DI&C systems. It should be noted that all the analyses are performed for the demonstration of the LWRS-developed framework, not for the evaluation of relevant systems. Results are obtained based on very limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Architecting Safer Autonomous Aviation Systems

The aviation literature gives relatively little guidance to practitioners about the specifics of architecting systems for safety, particularly the impact of architecture on allocating safety requirements, or the relative ease of system assurance resulting from system or subsystem level architectural choices. As an exemplar, this paper considers common architectural patterns used within traditional aviation systems and explores their safety and safety assurance implications when applied in the context of integrating artificial intelligence (AI) and machine learning (ML) based functionality. Considering safety as an architectural property, we discuss both the allocation of safety requirements and the architectural trade-offs involved early in the design lifecycle. This approach could be extended to other assured properties, similar to safety, such as security. We conclude with a discussion of the safety considerations that emerge in the context of candidate architectural patterns that have been proposed in the recent literature for enabling autonomy capabilities by integrating AI and ML. A recommendation is made for the generation of a property-driven architectural pattern catalogue.

Architecture patterns↗

Architecting Safer Autonomous Aviation Systems

The aviation literature gives relatively little guidance to practitioners about the specifics of architecting systems for safety, particularly the impact of architecture on allocating safety requirements, or the relative ease of system assurance resulting from system or subsystem level architectural choices. As an exemplar, this paper considers common architectural patterns used within traditional aviation systems and explores their safety and safety assurance implications when applied in the context of integrating artificial intelligence (AI) and machine learning (ML) based functionality. Considering safety as an architectural property, we discuss both the allocation of safety requirements and the architectural trade-offs involved early in the design lifecycle. This approach could be extended to other assured properties, similar to safety, such as security. We conclude with a discussion of the safety considerations that emerge in the context of candidate architectural patterns that have been proposed in the recent literature for enabling autonomy capabilities by integrating AI and ML. A recommendation is made for the generation of a property-driven architectural pattern catalogue.

Architecture patterns↗

Safety-Critical Partitioned Software Architecture: A Partitioned Software Architecture for Robotic

The flight software on virtually every mission currently managed by JPL has several major flaws that make it vulnerable to potentially fatal software defects. Many of these problems can be addressed by recently developed partitioned operating systems (OS). JPL has avoided adopting a partitioned operating system on its flight missions, primarily because doing so would require significant changes in flight software design, and the risks associated with changes of that magnitude cannot be accepted by an active flight project. The choice of a partitioned OS can have a dramatic effect on the overall system and software architecture, allowing for realization of benefits far beyond the concerns typically associated with the choice of OS. Specifically, we believe that a partitioned operating system, when coupled with an appropriate architecture, can provide a strong infrastructure for developing systems for which reusability, modifiability, testability, and reliability are essential qualities. By adopting a partitioned OS, projects can gain benefits throughout the entire development lifecycle, from requirements and design, all the way to implementation, testing, and operations.

(Avionics Application Standard Software Interface ↗

In-time System-wide Safety Assurance (ISSA) Concept of Operations and Design Considerations for Urban Air Mobility (UAM)

Emerging operations involving Advanced Air Mobility (AAM), such as Urban Air Mobility (UAM), pose a challenge to safety assurance and to accessibility within the National Airspace System (NAS).In particular, the public has a low tolerance for risk in aviation and the current NAS tends to be labor-intensive with limited ability to scale up for UAM. In response to this landscape, NASA is collaborating with industry to define a Concept of Operations (ConOps) for In-time System-Wide Safety Assurance (ISSA) for scalable UAM involving a service-oriented architecture. This architecture focuses safety investments for technological solutions that can overcome safety related barriers for emerging operations. By working with industry, consensus can be reached on desirable system traits that are based on integration and fusion of data and leverage increasingly autonomous and automated systems. These complex systems can identify anomalies, precursors, and trends that together enable more proactive management of operational risks. AAM and UAM elevate the need for risk management in relation to increasing density and heterogeneity of vehicles and operations. Whereas safety in today’s NAS is built on a history of programs and technologies that react to incidents and accidents, AAM presents an opportunity to leverage that experience and its implications and proactively integrate safety into the earliest designs of vehicles and systems. In a perfect world AAM and UAM would not be inherently dangerous but until then ensuring the highest quality of safety requirements is the bridge to mitigating risks.

In-Time System-Wide Safety Assurance↗

Autonomous Surface Site Establishment to Ensure Safe Crew Arrival and Operations

Traditional human Mars missions have relied on crew to support the surface systems. However, for safety, the surface systems will likely need to be setup and capable of operating prior to the arrival of crew. To mitigate risks to the crew, a novel surface architecture has been developed that addresses risks associated with other Mars missions. This architecture relies on a reusable descent and ascent vehicle, extensive in-situ resource utilization, redundant habitation systems, and emerging autonomous capabilities. The resulting surface architecture increases safety for the crew while also providing potential to expand to support longer missions with larger populations in the future.

Jones, Christopher A.↗

Identification of Safety Metrics for Airport Surface Operations

A large fraction of safety incidents occurs on the ground during airport surface operations. Although these incidents are mostly non-fatal with a few exceptions, they are high profile incidents that remain a source of concern for the National Transportation Safety Board (NTSB), the Federal Aviation Administration (FAA), major airlines, and other stakeholders of the National Airspace System (NAS). These incidents have historically been mitigated by implementing changes to regulations, policies, and procedures over time. This approach has minimized but not eliminated the risk of occurrence of safety incidents. It is thus important to develop integrated techniques to assess, model, and prevent these incidents by analyzing the risk and likelihood of occurrence and communicating results of the analysis to decision-making personnel who can mitigate and prevent incidents in real time. The work presented in this paper builds on a previously developed architecture for safety, Real-Time Safety Monitoring (RTSM), to enable monitoring and prediction of the safety of the NAS. In the RTSM framework, hazards to flight are translated to safety metrics such as wake vortex encounters or loss of separation, that can be modeled and analyzed offline and also predicted and monitored in real time (online). The intent of this paper is to integrate predictable incidents that occur during surface and ground operations into the safety portfolio of the RTSM project by (i) identifying suitable information sources from which ground incidents can be studied, (ii) developing safety metrics correlated with surface operations, and (iii) recommending suitable data sources that can be quantified and used for the computation of pertinent safety metrics.

safety↗

ADEPT: A Pedagogical Framework for Integrating Agentic AI with Deterministic Scientific Workflows

The integration of Large Language Models (LLMs) into scientific research promises to accelerate discovery, yet a significant gap remains between the dynamic reasoning of Artificial Intelligence (AI) agents and the static, deterministic nature of canonical scientific workflows. This paper introduces ADEPT (Agentic Discovery and Exploration Platform for Tools), a reference architecture and pedagogical framework explicitly designed to bridge this gap. ADEPT's primary mission is to provide a transparent, "glass-box" environment where researchers and engineers can learn to effectively wrap established scientific software (e.g., BLAST, Nextflow pipelines) and compose it into reliable, agent-driven workflows. We describe its modular, multi-server architecture, which leverages the Model Context Protocol (MCP) for tool serving, LangGraph for robust agentic orchestration, and a secure nsjail-based sandbox for safe code execution. By prioritizing architectural clarity, safety, and modularity, ADEPT serves as an extensible blueprint for building trustworthy AI-augmented systems and fosters the collaborative development necessary to responsibly employ agentic AI for science. We provide practical examples of how to adapt and extend this framework, highlighting its utility in workforce development and AI-readiness capabilities across research and development projects.

97 MATHEMATICS AND COMPUTING↗

Technology drivers for flight telerobotic system software

Viewgraphs on technology drivers for flight telerobotic system software are included. Topics covered include: flight software lines of code; flight computer architecture; system safety; safety critical parameters; system safety - software functions.

Labaugh, Robert↗