NASA EPFD Project's Progress Towards Reducing Barrier EAP Technology and Integration Risks
Explore the source record for details and available documents.
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
When new technology, such as artificial intelligence (AI), is introduced into an existing workflow it may impact risk by mitigating some vulnerabilities and threats in the workflow while introducing others. We present a versatile methodology for assessing the vulnerabilities and threats that impact overall risk in a workflow to inform technology integration. Our method involves both qualitative and quantitative assessment of risk and includes a formula for generating a risk score to guide technology integration. We describe our methodology and demonstrate its application to a specific workflow (the Derivative Classification review process). This work was funded by the Department of Energy (DOE) Automated Classification Tools for the Identification of Classified Information (ACTICI) program.
Power-hardware-in-the-loop evaluation of IBRs has become more and more important as it provides reliable testing results to investigate the real responses of inverters with interconnected systems. A successful laboratory PHIL testing gives confidence of the hardware system to be deployed and de-risk technology integration prior to field deployment. So far, there are two important applications for PHIL evaluation: (1) test stability and functionality of large utility inverters into the system when it interconnects to the distribution systems/microgrids; and (2) test the collective grid service that inverters can provide to the grid. For the first application, the PHIL evaluation has high requirements for the stability and accuracy of the PHIL interface as the close-loop in digital real time simulator (DRTS) should replicate the actual current and voltage dynamics in the inverter. This is challenging because of the delays, sensing errors, nonlinearities of inverters, and hardware bandwidth limitations of the elements in the HIL loop. For the second application, multiple inverters will be tested resulting in multiple PCCs, which naturally causes competing dynamics and oscillations among hardware inverters if traditional PHIL interface is used. Therefore, new PHIL interface should be developed to compromise between stability and accuracy and represent the dispatched grid services for the hardware inverters. In this presentation, we will share our latest work in developing PHIL interface in these two applications to address the two key challenges.
This report documents the activities performed by Idaho National Laboratory (INL) during fiscal year (FY) 2021 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) Risk Assessment project. In FY-2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems (IRADIC technology) was proposed for this strategy, which aims to (1) provide a best-estimate risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the High Safety Significant Safety-related (HSSSR) DI&C systems, (2) develop an advanced risk assessment technology to support transition from analog to DI&C technologies for nuclear industry, (3) assure the long-term safety and reliability of vital HSSSR DI&C systems, (4) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the IRADIC technology is instructive for nuclear vendors and utilities to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify responding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the individual level, system level, and plant level, (4) providing insights and suggestions on designs to manage the risks; thus, to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). In this report, an approach for performing software CCF analysis, given limited data, is developed and demonstrated using a case study of a highly redundant digital reactor trip system. Consequence analysis is also performed based on different accident scenarios. Results indicate that plant modernization including the improvement of HSSSR DI&C systems will make great benefits to plant safety by providing more safety margins to accident management. In addition, a novel approach is proposed in this report for the quantification of software hazards when sufficient operational and testing data available. The method incorporates software development quality as well as strong analysis techniques to identify and link software defects to potential failure modes. The approach includes both semantic and test-based analysis to detect failures that can exist in different stages of the software development life cycle. This method is applied to an advanced human system interface relevant to reactor trip safety developed from the APR 1400 design.
This report documents the plus-up activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2022 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems was proposed for this strategy, which aims to (1) provide a best-estimate, risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the high safety-significant safety-related (HSSSR) DI&C systems, (2) support and supplement existing advanced risk-informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems to support system design decisions and diversity and redundancy applications, (4) assure the long-term safety and reliability of HSSSR DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the LWRS-developed framework instructs nuclear vendors and utilities on how to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). Adding diversity within system or components is the main means to eliminate and mitigate CCFs, but diversity also increases plant complexity and errors and may not address all sources of systematic failures. How to optimize the diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in HSSSR DI&C systems of NPPs and supporting relevant design optimization, the framework provides: ? An integrated best-estimate, risk-informed capability to address new technical digital issues quantitatively, accurately, and efficiently in plan modernization progress, such as software CCFs in HSSSR DI&C systems of NPPs ? A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to efficiently predict and prevent risk in the early design stage of DI&C systems ? Technical bases and risk-informed insights to assist U.S. Nuclear Regulatory Commission (NRC) and industry to address and fulfill the risk-informed alternatives for evaluation of CCFs in HSSSR DI&C systems of NPPs ? An integrated risk-informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The plus-up research and development efforts of this project in FY 2022 are focused on methodology improvement of software CCF modeling and estimation, prevention analysis, importance analysis and risk analysis of various design architectures of HSSSR DI&C systems. This work greatly enhances the capability of the LWRS-developed framework for the risk assessment and design optimization of safety-critical DI&C systems. It should be noted that all the analyses are performed for the demonstration of the LWRS-developed framework, not for the evaluation of relevant systems. Results are obtained based on very limited design information and testing data.
Digital instrumentation and control (DI&C) systems in nuclear power plants (NPPs) have many advantages over analog systems but also pose different engineering and technical challenges, such as potential threats due to common cause failures (CCFs). This paper proposes an integrated risk assessment technology for DI&C systems (IRADIC) developed by Idaho National Laboratory for dealing with potential software CCFs in DI&C systems of NPPs. The methodology development of the IRADIC technology on the quantitative evaluation of software CCFs in high safety-significant safety-related DI&C systems in NPPs is illustrated in this paper. In IRADIC, qualitative hazard analysis and quantitative reliability and consequence analysis are successively implemented to obtain quantitative risk information, compare with respective risk evaluation acceptance criteria, and provide suggestions for risk reduction and design optimization. A comprehensive case study was also performed and documented in this paper. Results show that the IRADIC technology can effectively identify potential digital-based CCFs, estimate their failure probabilities, and evaluate their impacts to system and plant safety.
BACKGROUND: Radiation, reduced gravity, distance from earth, isolation and confinement, and habitation within artificially created and controlled life support environments are hazards that present risk to human space explorers. NASA’s Human System Risk Board (HSRB) maintains a set of twenty-nine different Human System Risks with subject matter experts from across the agency providing regular updates to the estimated likelihood and consequence associated with each risk. The Human Research Program (HRP) has historically used these risk classifications as a primary basis for identifying and prioritizing human research investments aimed at characterizing and/or mitigating the respective human system risks. In many cases, technology development is required to mature and validate risk mitigation strategies, however, NASA’s primary technology development programs have not typically used Human System Risks as a basis for strategic planning. A primary function of the Environmental Control and Life Support Systems (ECLSS) – Crew Health and Performance (CHP) System Capability Leadership Team (SCLT) is to continually identify, review, and update technological capability gaps and to establish and oversee multiyear strategic roadmaps aimed at guiding NASA’s technology development priorities in these areas. These roadmaps are intended to be agency-wide and independent of any program, directorate, or other organization within NASA. DESCRIPTION: The SCLT and HRP collaborated to establish a set of Human System Capability Gaps, which establish a formal linkage between the capability gaps used to prioritize investments across much of NASA, and the Human System Risks that are primarily used to inform and prioritize human research. This set of twenty-eight gaps was developed by subject matter experts, and each gap mapped to the primary associated Human System Risks. The gaps and risk mapping were then reviewed and approved via the HSRB, thereby formally aligning the research-focused Human System Risks with the technology-focused capability gaps. DISCUSSION: This effort has enabled development of integrated roadmaps and budget coordination with research and technology development activities that are formally linked to agency-recognized capability gaps and Human System Risks. Close and ongoing coordination between the SCLT, HRP, Mars Campaign Office, and the Health & Medical Technical Authority (HMTA) is essential to ensure alignment and prioritization of CHP-related research and technology development to enable NASA’s future exploration missions.
Explore the source record for details and available documents.
Electric grid operators are adept at handling complexity and uncertainty. However, with increasing introduction of renewable generation, distributed energy resources, and more frequent severe weather events, operators will experience new workload and challenging decision scenarios. Here, this paper quantifies risks and benefits from an operator's perspective of introducing weather based forecast Dynamic Line Ratings (DLR) using variable wind conditions in addition to ambient temperature to relieve transmission congestion and facilitating more offshore wind (OSW). A concept of operations (CONOPS) applied to a forecast DLR implementation and its integration with OSW is defined. A method for evaluating tradeoffs of derating to make the rating more conservative but decreasing the benefit was developed and applied to a case study for two existing overhead transmission lines on Long Island, New York. The CONOPS uses historical day-ahead and hour-ahead High Resolution Rapid Refresh weather forecasts and weather station data to support planning and real-time operations. The analysis determines the risk of downgrades in real-time operational rating compared to the forecast and quantifies the frequency and severity of last-minute downgrades. The risk is compared against the benefits in increased capacity to provide insights on the additional amount of uncertainty DLR and OSW will add to the operator's workload.
NASA is continuing to develop and qualify a state of the art 13 kW-class Advanced Electric Propulsion System (AEPS) for NASA exploration missions through a contract with Aerojet Rocketdyne. An objective of the AEPS project is to empower the US space industry to accelerate the adoption of high power electric propulsion technologies by reducing the risk and uncertainty of integrating Solar Electric Propulsion (SEP) technologies into space flight systems. NASA and AEPS contract has recently initiated engineering hardware testing of the Hall Current Thruster (HCT), Power Processing Unit (PPU), and Xenon Flow Controller (XFC) at both the component and system levels. The successful completion of these tests will provide the required information to advance the AEPS system towards Critical Design Review. In support of the AEPS contract, NASA and JPL have been performing risk reduction activities to address specific concerns of the state of the art higher power Hall thruster propulsion system. These risk reduction activities have included long duration wear testing of the Technology Demonstration Unit (TDU) Hall thruster and cathode hardware, thermal cycling testing of TDU cathode heaters and coils, plasma plume measurements, and investigating PPU design. In addition to NASA propulsion development, the SEP project is developing the Plasma Diagnostic Package (PDP) and the SEP Testbed. The PDP is designed for use in conjunction with a high powered EP system to characterize in-space operation. The SEP Testbed system is developed for demonstration of Abstract: NASA is continuing to develop and qualify a state of the art 13 kW-class Advanced Electric Propulsion System (AEPS) for NASA exploration missions through a contract with Aerojet Rocketdyne. An objective of the AEPS project is to empower the US space industry to accelerate the adoption of high power electric propulsion technologies by reducing the risk and uncertainty of integrating Solar Electric Propulsion (SEP) technologies into space flight systems. NASA and AEPS contract has recently initiated engineering hardware testing of the Hall Current Thruster (HCT), Power Processing Unit (PPU), and Xenon Flow Controller (XFC) at both the component and system levels. The successful completion of these tests will provide the required information to advance the AEPS system towards Critical Design Review. In support of the AEPS contract, NASA and JPL have been performing risk reduction activities to address specific concerns of the state of the art higher power Hall thruster propulsion system. These risk reduction activities have included long duration wear testing of the Technology Demonstration Unit (TDU) Hall thruster and cathode hardware, thermal cycling testing of TDU cathode heaters and coils, plasma plume measurements, and investigating PPU design. In addition to NASA propulsion development, the SEP project is developing the Plasma Diagnostic Package (PDP) and the SEP Testbed. The PDP is designed for use in conjunction with a high powered EP system to characterize in-space operation. The SEP Testbed system is developed for demonstration of an integrated SEP end-to-end system performance. The paper will present an overview of the NASA and the AEPS contract activities and a summary of the associated NASA in-house activities.
This paper describes recent work on developing an extensible information grid for risk management at NASA - a RISK INFORMATION GRID. This grid is being developed by integrating information grid technology with risk management processes for a variety of risk related applications. To date, RISK GRID applications are being developed for three main NASA processes: risk management - a closed-loop iterative process for explicit risk management, program/project management - a proactive process that includes risk management, and mishap management - a feedback loop for learning from historical risks that escaped other processes. This is enabled through an architecture involving an extensible database, structuring information with XML, schemaless mapping of XML, and secure server-mediated communication using standard protocols.
In order to realize the vision of expanding human presence in space, NASA will develop new technologies that can enable future crewed spacecraft to go far beyond Earth orbit. These technologies must be matured to the point that future project managers can accept the risk of incorporating them safely and effectively within integrated spacecraft systems, to satisfy very challenging mission requirements. The technologies must also be applied and managed within an operational context that includes both on-board crew and mission support on Earth. The Advanced Exploration Systems (AES) Program is one part of the NASA strategy to identify and develop key capabilities for human spaceflight, and mature them for future use. To support this initiative, the Integrated Power Avionics and Software (iPAS) environment has been developed that allows engineers, crew, and flight operators to mature promising technologies into applicable capabilities, and to assess the value of these capabilities within a space mission context. This paper describes the development of the integration environment to support technology maturation and risk reduction, and offers examples of technology and mission demonstrations executed to date.
Emerging capabilities to integrate instruments on smallsats, airborne platforms and in situ devices into an intelligent, distributed observing strategy show great promise for measuring Earth science natural phenomena and physical processes that have not previously been characterized. To reduce the threshold for success in deploying such an intelligent, integrated observing strategy, a ground-based testbed system is proposed. Virtually all of the technologies needed for using such a tool have matured to the point of being used, individually. Virtually none of the technologies have been deployed, working together. The technologies to be deployed should be integrated into a working "breadboard" where the components can be debugged and performance and behavior characterized and tuned-up. A system of this complexity should not be expected to work without full integration and experimental characterization. Further, and perhaps more importantly, in order to successfully propose a space-based element to this strategy, teams must convince the relevant science community that the risk is low enough to warrant the investment. The main benefit of the testbed is to retire the risk of integrating these new technologies and increase the Technology Readiness Level (TRL) of each component as well as the System Readiness Level (SRL) of the integrated system.
The objective of this study is to define the functionality and evaluate the propulsion and power system benefits derived from a Solid Oxide Fuel Cell (SOFC) based Auxiliary Power Unit (APU) for a future short range commercial aircraft, and to define the technology gaps to enable such a system. United Technologies Corporation (UTC) Integrated Total Aircraft Power System (ITAPS) methodologies were used to evaluate a baseline aircraft and several SOFC architectures. The technology benefits were captured as reductions of the mission fuel burn, life cycle cost, noise and emissions. As a result of the study, it was recognized that system integration is critical to maximize benefits from the SOFC APU for aircraft application. The mission fuel burn savings for the two SOFC architectures ranged from 4.7 percent for a system with high integration to 6.7 percent for a highly integrated system with certain technological risks. The SOFC APU itself produced zero emissions. The reduction in engine fuel burn achieved with the SOFC systems also resulted in reduced emissions from the engines for both ground operations and in flight. The noise level of the baseline APU with a silencer is 78 dBA, while the SOFC APU produced a lower noise level. It is concluded that a high specific power SOFC system is needed to achieve the benefits identified in this study. Additional areas requiring further development are the processing of the fuel to remove sulfur, either on board or on the ground, and extending the heat sink capability of the fuel to allow greater waste heat recovery, resolve the transient electrical system integration issues, and identification of the impact of the location of the SOFC and its size on the aircraft.
Outline - NASA perspective on upset/stall training - Risk reduction opportunity - Simulation technology - Integrated training benefits - Future needs - Recommendations - Relevant publications
Explore the source record for details and available documents.
Upgrading the existing analog instrumentation and control (I&C) systems to state-of-the-art digital I&C (DI&C) systems will greatly benefit existing light water reactors. However, the issue of software common cause failure (CCF) remains an obstacle in terms of qualification for digital technologies. Existing analyses of CCFs in I&C systems mainly focus on hardware failures. With the application and upgrading of new DI&C systems, design flaws could cause software CCFs to become a potential threat to plant safety, considering that most redundancy designs use similar digital platforms or software in their operating and application systems. With complex multilayer redundancy designs to meet the single failure criterion, these I&C safety systems are of particular concern in U.S. Nuclear Regulatory Commission licensing procedures. In Fiscal Year 2019, the Risk-Informed Systems Analysis (RISA) Pathway of the U.S. Department of Energy’s Light Water Reactor Sustainability Program initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades and designs. An integrated risk assessment for the DI&C process was proposed for this strategy to identify potential key digital-induced failures, implement reliability analyses of related digital safety I&C systems, and evaluate the unanalyzed sequences introduced by these failures (particularly software CCFs) at the plant level. Here this paper summarizes these RISA efforts in the risk analysis of safety-related DI&C systems at Idaho National Laboratory.
This project supports the Department of Energy's Bioenergy Technology Office mission of transitioning bioenergy technologies to market by de-risking integration, developing scaling relations and modeling that de-risks scale up, and providing a feedback loop with lower TRL projects to understand process and technology fundamentals. Two objectives were pursued during this merit cycle. First, the Thermal and Catalytic Process Development Unit (TCPDU), a 0.5 ton/day pilot plant, was used to validate kinetic models developed by the Consortium for Computational Physics and Chemistry (CCPC). Validating the models accurately predict product yields and composition is a first step toward de-risking a common industry failure - taking too large of steps between scales. In addition, these models help with design and troubleshooting of new unit operations for the TCPDU. The second objective was to conduct the FY22 verification campaign around ex situ CFP. The primary challenge of this effort was the coordination of multiple national labs and projects. This was overcome by a dedicated leadership role and effective communication strategy between the projects. Currently the project is undergoing a pivot based on a stagegate decision to not conduct the verification campaign in the TCPDU and it is focused on closing out the CFP technology at a smaller scale by the end of the current fiscal year.