Search NASA⌕ Search

SEARCH · Search NASA

Results for “probabilistic safety assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗

Findings of a review of spacecraft fire safety needs

Discussions from a workshop to guide UCLA and NASA investigators on the state of knowledge and perceived needs in spacecraft fire safety and its risk management are reviewed, for an introduction to an analytical and experimental project in this field. The report summarizes the workshop discussions and includes the visual aids used in the presentations. Probabilistic Safety Assessment (PSA) methods, which are currently not used, would be of great value to the designs and operation of future human-crew spacecraft. Key points in the discussions were the importance of understanding and testing smoldering as a likely fire scenario in space and the need for smoke damage modeling, since many fire-risk models ignore this mechanism and consider only heat damage.

Apostolakis, G. E.↗

Continued Discussion of Failure Mode Modeling and Overall Component Reliability: Are the Data Missing or Censored?

This paper is the continuation of a paper presented at the 13th Probabilistic Safety Assessment and Management Conference, in which a methodology of modeling failure modes of complex components was presented; see Paulos and Smith (2016). This methodology is not particularly helpful in the space industry where there is a lack of failure data, but is more helpful in industries that see a lot of component repairs and improvements, such as in the aircraft or automotive industries. The previous paper demonstrated how the typical approach of treating failure modes as being exponential in nature may yield optimistic predictions when estimating how improvements to components will perform in the future. It is more accurate to model the failure modes as a race in time; unfortunately, this does not give a closed-form solution. This paper uses simulation to solve for the model of the world, and the results compared to the standard methodology of treating the failure modes as being exponential random failures. The standard method is shown to have optimistic predictions, which will lead to prediction errors when failure modes are removed or “fixed.” The failure mode methodology presented in the first paper treated the data as being censored when the test stopped. In this paper, we will compare the results from treating the data as both censored and missing.

Smith, Curtis↗

A Decision Support System for Extravehicular Operations Under Significant Communication Latency

Within the next few decades, humanity hopes to perform extravehicular activities (EVAs) on the surface of Mars; however, several technical and operational challenges must first be overcome. Foremost among these challenges is managing a significant two-way communication latency between Earth and Mars. Current and historical paradigms of EVA operations have required near-real-time communication between the crewmember(s) performing an EVA and an Earth-based mission control. Next-generation operational paradigms for supporting deep space exploration will necessitate a distributed decision authority system, including delayed Earth-based mission control, the on-planet extravehicular crewmember(s), and intermediate mission support from intravehicular crewmember(s) within real-time communication range. This latter group is of particular interest: they must provide operations support without the plentiful resources available to mission control on Earth. For this purpose, NASA is developing the Personalized EVA Informatics and Decision Support (PersEIDS) software platform. PersEIDS is designed to bolster operator situational awareness and offload operator workload by automating the tracking and projection of consumables usage over an EVA timeline, providing real-time probabilistic safety assessments of an EVA timeline given consumables constraints, and recommending alternative EVA timeline(s) when the active timeline is not expected to be completed under consumables limits. The PersEIDS concept of operations, use cases, and models will be presented. A limited version of PersEIDS was demonstrated during a three-day-long study where each day a roughly four-hour-long simulated Martian EVA was performed in virtual reality at the NASA Johnson Space Center. The first day was a control trial without PersEIDS support; the second and third days represented different levels of decision support provided by PersEIDS to the intravehicular crewmember acting as mission control. With PersEIDS support, the IV crewmember was able to manage the mission to completion faster and with more remaining consumables; however, additional testing is required to understand confounding factors, e.g. training bias.

Mars↗

A Decision Support System for Extravehicular Operations Under Significant Communication Latency

Humanity hopes to perform extravehicular activities (EVAs) on the surface of Mars; however, several technical and operational challenges must first be overcome. Foremost among these challenges is managing a significant communication latency between Earth and Mars. Current and historical paradigms of EVA operations have required near-real-time communication between the crewmember(s) and Earth-based mission control. Nextgeneration operational paradigms for supporting deep space exploration will necessitate a distributed decision authority system, including delayed Earth-based mission control, the onplanet extravehicular crewmember(s), and intermediate mission support from intravehicular (IV) crewmember(s) within real-time communication range. This latter group is of particular interest: they must provide operations support without the plentiful resources available to mission control on Earth. Thus, NASA is developing the Personalized EVA Informatics and Decision Support (PersEIDS) software platform. PersEIDS is designed to bolster operator situational awareness and offload operator workload by automatically tracking and projecting consumables usage over an EVA timeline, providing real-time probabilistic safety assessments and recommending alternative EVA timeline(s) when the active timeline is not expected to be completed under consumables limits. The PersEIDS concept of operations, use cases, and models will be presented. A limited version of PersEIDS was demonstrated during a three-day-long study where each day a roughly four-hour-long simulated Martian EVA was performed in virtual reality at the NASA Johnson Space Center. The first day was a control trial without PersEIDS support; the second and third days represented different levels of decision support provided by PersEIDS to the IV crewmember acting as mission control. With PersEIDS support, the IV crewmember was able to manage the mission to completion faster and with more remaining consumables; however, additional testing is required to understand confounding factors, e.g., training bias.

Mars↗

PersEIDS: A Biomedical Decision Support System for Extravehicular Operations Under Significant Communication Latency

Humanity hopes to perform extravehicular activities (EVAs) on the surface of Mars; however, several technical and operational challenges must first be overcome. Foremost among these challenges is managing a significant communication latency between Earth and Mars. Current and historical paradigms of EVA operations have required near-real-time communication between the crewmember(s) and Earth-based mission control. Nextgeneration operational paradigms for supporting deep space exploration will necessitate a distributed decision authority system, including delayed Earth-based mission control, the onplanet extravehicular crewmember(s), and intermediate mission support from intravehicular (IV) crewmember(s) within real-time communication range. This latter group is of particular interest: they must provide operations support without the plentiful resources available to mission control on Earth. Thus, NASA is developing the Personalized EVA Informatics and Decision Support (PersEIDS) software platform. PersEIDS is designed to bolster operator situational awareness and offload operator workload by automatically tracking and projecting consumables usage over an EVA timeline, providing real-time probabilistic safety assessments and recommending alternative EVA timeline(s) when the active timeline is not expected to be completed under consumables limits. The PersEIDS concept of operations, use cases, and models will be presented. A limited version of PersEIDS was demonstrated during a three-day-long study where each day a roughly four-hour-long simulated Martian EVA was performed in virtual reality at the NASA Johnson Space Center. The first day was a control trial without PersEIDS support; the second and third days represented different levels of decision support provided by PersEIDS to the IV crewmember acting as mission control. With PersEIDS support, the IV crewmember was able to manage the mission to completion faster and with more remaining consumables; however, additional testing is required to understand confounding factors, e.g., training bias.

Mars↗

Risk-Informed Safety Assurance and Probabilistic Assessment of Mission-Critical Software-Intensive Systems

This report validates and documents the detailed features and practical application of the framework for software intensive digital systems risk assessment and risk-informed safety assurance presented in the NASA PRA Procedures Guide for Managers and Practitioner. This framework, called herein the "Context-based Software Risk Model" (CSRM), enables the assessment of the contribution of software and software-intensive digital systems to overall system risk, in a manner which is entirely compatible and integrated with the format of a "standard" Probabilistic Risk Assessment (PRA), as currently documented and applied for NASA missions and applications. The CSRM also provides a risk-informed path and criteria for conducting organized and systematic digital system and software testing so that, within this risk-informed paradigm, the achievement of a quantitatively defined level of safety and mission success assurance may be targeted and demonstrated. The framework is based on the concept of context-dependent software risk scenarios and on the modeling of such scenarios via the use of traditional PRA techniques - i.e., event trees and fault trees - in combination with more advanced modeling devices such as the Dynamic Flowgraph Methodology (DFM) or other dynamic logic-modeling representations. The scenarios can be synthesized and quantified in a conditional logic and probabilistic formulation. The application of the CSRM method documented in this report refers to the MiniAERCam system designed and developed by the NASA Johnson Space Center.

Guarro, Sergio B.↗

"Making Safety Happen" Through Probabilistic Risk Assessment at NASA

NASA is using Probabilistic Risk Assessment (PRA) as one of the tools in its Safety & Mission Assurance (S&MA) tool belt to identify and quantify risks associated with human spaceflight. This paper discusses some of the challenges and benefits associated with developing and using PRA for NASA human space programs. Some programs have entered operation prior to developing a PRA, while some have implemented PRA from the start of the program. It has been observed that the earlier a design change is made in the concept or design phase, the less impact it has on cost and schedule. Not finding risks until the operation phase yields much costlier design changes and major delays, which can result in discussions of just accepting the risk. Risk contributors identified by PRA are not just associated with hardware failures. They include but are not limited to crew fatality due to medical causes, the environment the vehicle and crew are exposed to, the software being used, and the reliability of the crew performing required actions. Some programs have entered operation prior to developing a PRA, and while PRA can still provide a benefit for operations and future design trades, the benefit of implementing PRA from the start of the program provides the added benefit of informing design and reducing risk early in program development. Currently, NASA’s International Space Station (ISS) program is in its 20th year of on-orbit operations around the Earth and has several new programs in the design phase preparing to enter the operation phase all of which have active (or living) PRAs. These programs incorporate PRA as part of their Risk-Informed, Decision-Making (RIDM) process. For new NASA human spaceflight programs discussion begins with mission concept, establishing requirements, forming the PRA team, and continues through the design cycles into the operational phase. Several examples of PRA related applications and observed lessons are included.

Applications↗

Probabilistic Causal Analysis for System Safety Risk Assessments in Commercial Air Transport

Aviation is one of the critical modes of our national transportation system. As such, it is essential that new technologies be continually developed to ensure that a safe mode of transportation becomes even safer in the future. The NASA Aviation Safety Program (AvSP) is managing the development of new technologies and interventions aimed at reducing the fatal aviation accident rate by a factor of 5 by year 2007 and by a factor of 10 by year 2022. A portfolio assessment is currently being conducted to determine the projected impact that the new technologies and/or interventions may have on reducing aviation safety system risk. This paper reports on advanced risk analytics that combine the use of a human error taxonomy, probabilistic Bayesian Belief Networks, and case-based scenarios to assess a relative risk intensity metric. A sample case is used for illustrative purposes.

Luxhoj, James T.↗

Probabilistic Design Analysis (PDA) Approach to Determine the Probability of Cross-System Failures for a Space Launch Vehicle

Quantifying the probability of significant launch vehicle failure scenarios for a given design, while still in the design process, is critical to mission success and to the safety of the astronauts. Probabilistic risk assessment (PRA) is chosen from many system safety and reliability tools to verify the loss of mission (LOM) and loss of crew (LOC) requirements set by the NASA Program Office. To support the integrated vehicle PRA, probabilistic design analysis (PDA) models are developed by using vehicle design and operation data to better quantify failure probabilities and to better understand the characteristics of a failure and its outcome. This PDA approach uses a physics-based model to describe the system behavior and response for a given failure scenario. Each driving parameter in the model is treated as a random variable with a distribution function. Monte Carlo simulation is used to perform probabilistic calculations to statistically obtain the failure probability. Sensitivity analyses are performed to show how input parameters affect the predicted failure probability, providing insight for potential design improvements to mitigate the risk. The paper discusses the application of the PDA approach in determining the probability of failure for two scenarios from the NASA Ares I project

Shih, Ann T.↗

Dynamic Positioning System (DPS) Risk Analysis Using Probabilistic Risk Assessment (PRA)

The National Aeronautics and Space Administration (NASA) Safety & Mission Assurance (S&MA) directorate at the Johnson Space Center (JSC) has applied its knowledge and experience with Probabilistic Risk Assessment (PRA) to projects in industries ranging from spacecraft to nuclear power plants. PRA is a comprehensive and structured process for analyzing risk in complex engineered systems and/or processes. The PRA process enables the user to identify potential risk contributors such as, hardware and software failure, human error, and external events. Recent developments in the oil and gas industry have presented opportunities for NASA to lend their PRA expertise to both ongoing and developmental projects within the industry. This paper provides an overview of the PRA process and demonstrates how this process was applied in estimating the probability that a Mobile Offshore Drilling Unit (MODU) operating in the Gulf of Mexico and equipped with a generically configured Dynamic Positioning System (DPS) loses location and needs to initiate an emergency disconnect. The PRA described in this paper is intended to be generic such that the vessel meets the general requirements of an International Maritime Organization (IMO) Maritime Safety Committee (MSC)/Circ. 645 Class 3 dynamically positioned vessel. The results of this analysis are not intended to be applied to any specific drilling vessel, although provisions were made to allow the analysis to be configured to a specific vessel if required.

Thigpen, Eric B.↗

Dynamic Positioning System (DPS) Risk Analysis Using Probabilistic Risk Assessment (PRA)

The National Aeronautics and Space Administration (NASA) Safety & Mission Assurance (S&MA) directorate at the Johnson Space Center (JSC) has applied its knowledge and experience with Probabilistic Risk Assessment (PRA) to projects in industries ranging from spacecraft to nuclear power plants. PRA is a comprehensive and structured process for analyzing risk in complex engineered systems and/or processes. The PRA process enables the user to identify potential risk contributors such as, hardware and software failure, human error, and external events. Recent developments in the oil and gas industry have presented opportunities for NASA to lend their PRA expertise to both ongoing and developmental projects within the industry. This paper provides an overview of the PRA process and demonstrates how this process was applied in estimating the probability that a Mobile Offshore Drilling Unit (MODU) operating in the Gulf of Mexico and equipped with a generically configured Dynamic Positioning System (DPS) loses location and needs to initiate an emergency disconnect. The PRA described in this paper is intended to be generic such that the vessel meets the general requirements of an International Maritime Organization (IMO) Maritime Safety Committee (MSC)/Circ. 645 Class 3 dynamically positioned vessel. The results of this analysis are not intended to be applied to any specific drilling vessel, although provisions were made to allow the analysis to be configured to a specific vessel if required.

Thigpen, Eric B.↗

Science Goals in Radiation Protection for Exploration

Space radiation presents major challenges to future missions to the Earth s moon or Mars. Health risks of concern include cancer, degenerative and performance risks to the central nervous system, heart and lens, and the acute radiation syndromes. The galactic cosmic rays (GCR) contain high energy and charge (HZE) nuclei, which have been shown to cause qualitatively distinct biological damage compared to terresterial radiation, such as X-rays or gamma-rays, causing risk estimates to be highly uncertain. The biological effects of solar particle events (SPE) are similar to terresterial radiation except for their biological dose-rate modifiers; however the onset and size of SPEs are difficult to predict. The high energies of GCR reduce the effectiveness of shielding, while SPE s can be shielded however the current gap in radiobiological knowledge hinders optimization. Methods used to project risks on Earth must be modified because of the large uncertainties in projecting health risks from space radiation, and thus impact mission requirements and costs. We describe NASA s unique approach to radiation safety that applies probabilistic risk assessments and uncertainty based criteria within the occupational health program for astronauts and to mission design. The two terrestrial criteria of a point estimate of maximum acceptable level of risk and application of the principle of As Low As Reasonably Achievable (ALARA) are supplemented by a third requirement that protects against risk projection uncertainties using the upper 95% confidence level (CL) in radiation risk projection models. Exploration science goals in radiation protection are centered on ground-based research to achieve the necessary biological knowledge, and in the development of new technologies to improve SPE monitoring and optimize shielding. Radiobiology research is centered on a ground based program investigating the radiobiology of high-energy protons and HZE nuclei at the NASA Space Radiation Laboratory (NSRL) located at DoE s Brookhaven National Laboratory in Upton, NY. We describe recent NSRL results that are closing the knowledge gap in HZE radiobiology and improving exploration risk estimates. Linking probabilistic risk assessment to research goals makes it possible to express risk management objectives in terms of quantitative metrics, which include the number of days in space without exceeding a given risk level within well defined confidence limits, and probabilistic assessments of the effectiveness of design trade spaces such as material type, mass, solar cycle, crew selection criteria, and biological countermeasures. New research in SPE alert and risk assessment, individual radiation sensitivity, and biological countermeasure development are described.

Cucinotta, Francs A.↗

Investigating Risks Due to Artemis EVA Tempo Via Probabilistic Risk Assessment

Spaceflight operations pose unique challenges to crew health, safety, and resource management. As space agencies and private companies continue to push the boundaries of human exploration, it is essential to understand the risks associated with Extravehicular Activities (EVAs) and develop strategies to mitigate them. The tempo at which EVAs are conducted – the total number and frequency of these activities – can have a profound impact on medical risks, resource consumption, and overall mission success. Probabilistic risk assessment (PRA) provides a powerful framework for evaluating complex systems and identifying potential hazards. Our work employs the Medical Extensible Dynamic Probabilistic Risk Assessment Tool (MEDPRAT) [1] to simulate mission events, occurrence and treatment of medical conditions, and track the utilization of resources. Coupled with the Evidence Library [2], a medical evidence base for exploration-class missions developed by the Exploration Medical Capability within NASA’s Human Research Program, we can estimate these risks with increased fidelity and optimize medical kit contents to meet specific mission requirements. This presentation provides a detailed examination of how EVA tempo influences medical risk estimates for a lunar surface design reference mission. A comprehensive analysis is conducted to assess the additional mass and volume burden imposed on medical kits required to maintain adequate levels of risk mitigation. Furthermore, we estimate the distribution of the number of successful EVAs completed based on the level of task impairment imposed by medical events and flight rules related to specific medical events, such as decompression sickness.

Modeling↗

NSTS Orbiter auxiliary power unit turbine wheel cracking risk assessment

The present investigation of turbine-wheel cracking problems in the hydrazine-fueled APU turbine wheel of the Space Shuttle Orbiter's Main Engines has indicated the efficacy of systematic probabilistic risk assessment in flight certification and safety resolution. Nevertheless, real crack-initiation and propagation problems do not lend themselves to purely analytical studies. The high-cycle fatigue problem is noted to generally be unsuited to probabilistic modeling, due to its extremely high degree of intrinsic scatter. In the case treated, the cracks appear to trend toward crack arrest in a low cycle fatigue mode, due to a detuning of the resonance model.

Cruse, T. A.↗

Constellation Probabilistic Risk Assessment (PRA): Design Consideration for the Crew Exploration Vehicle

Managed by NASA's Office of Safety and Mission Assurance, a pilot probabilistic risk analysis (PRA) of the NASA Crew Exploration Vehicle (CEV) was performed in early 2006. The PRA methods used follow the general guidance provided in the NASA PRA Procedures Guide for NASA Managers and Practitioners'. Phased-mission based event trees and fault trees are used to model a lunar sortie mission of the CEV - involving the following phases: launch of a cargo vessel and a crew vessel; rendezvous of these two vessels in low Earth orbit; transit to th$: moon; lunar surface activities; ascension &om the lunar surface; and return to Earth. The analysis is based upon assumptions, preliminary system diagrams, and failure data that may involve large uncertainties or may lack formal validation. Furthermore, some of the data used were based upon expert judgment or extrapolated from similar components~systemsT. his paper includes a discussion of the system-level models and provides an overview of the analysis results used to identify insights into CEV risk drivers, and trade and sensitivity studies. Lastly, the PRA model was used to determine changes in risk as the system configurations or key parameters are modified.

Prassinos, Peter G.↗