Search NASA⌕ Search

SEARCH · Search NASA

Results for “risk informed design”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Risk Informed Design as Part of the Systems Engineering Process

This slide presentation reviews the importance of Risk Informed Design (RID) as an important feature of the systems engineering process. RID is based on the principle that risk is a design commodity such as mass, volume, cost or power. It also reviews Probabilistic Risk Assessment (PRA) as it is used in the product life cycle in the development of NASA's Constellation Program.

Deckert, George↗

An Example of Risk Informed Design

NASA Engineering requested a Probabilistic Risk Assessment (PRA) to compare the difference in the risk of Loss of Crew (LOC) and Loss of Mission (LOM) between different designs of a fluid assembly. They were concerned that the configuration favored by the design team was more susceptible to leakage than a second proposed design, but realized that a quantitative analysis to compare the risks between the two designs might strengthen their argument. The analysis showed that while the second design did help improve the probability of LOC, it did not help from a probability of LOM perspective. This drove the analysis team to propose a minor design change that would drive the probability of LOM down considerably. The analysis also demonstrated that there was another major risk driver that was not immediately obvious from a typical engineering study of the design and was therefore unexpected. None of the proposed alternatives were addressing this risk. This type of trade study demonstrates the importance of performing a PRA in order to completely understand a system's design. It allows managers to use risk as another one of the commodities (e.g., mass, cost, schedule, fault tolerance) that can be traded early in the design of a new system.

Banke, Rick↗

Gateway Program Safety and Mission Assurance Integration - the Future of Safe Deep Space Human Exploration

As a foundational element of the National Aeronautics and Space Administration (NASA) Artemis Campaign, the Gateway is an incrementally built cislunar spacecraft that will serve as a platform for deep space human exploration, science, and technology demonstration. The Gateway will be a unifying catalyst for international partners around the world to establish sustained deep space scientific investigations, lunar surface access, and missions to Mars. As human exploration moves farther away from Earth, spacecraft designs must prioritize and optimize mass and volume allocations, while minimizing human and spacecraft risk. To accomplish this objective, the Gateway Program Safety and Mission Assurance functions develop, implement, and ensure compliance with requirements, in concert with the accurate characterization and transparent communication of residual hazard risks, for integrated safety, reliability and maintainability and quality assurance. Safety and Mission Assurance was a key contributor during Gateway program pre-formulation and formulation activities where safety and reliability analysis was embedded in the Gateway Systems Engineering and Integration team. During these early program stages, a preliminary Gateway Integrated Hazard Analysis and Preliminary Gateway Probabilistic Risk Assessment assisted in Gateway architectural and operational definition as part of a risk-informed design process. As the deep space architecture has matured, the integrated Safety and Mission Assurance analyses have matured, new safety review processes have been developed, and requirements have been refined to ensure compliance with integrated safety and mission assurance objectives. The Gateway Program is currently concluding the preliminary design review informed milestone, where the primary objectives included: - Ensured completeness and consistency of the preliminary design, including the meeting of all requirements within appropriate margins and acceptable risk posture. - Identification of any major issues moving forward to the Critical Design phase. At this milestone, Safety and Mission Assurance provided numerous products, including Gateway Top Risks and Risk Mitigation Plans, updated integrated hazard analyses, updated probabilistic risk assessment, Crew Survival Analysis Report, and updated Safety and Mission Assurance Requirements and Plans. These products provide a many-faceted perspective on the inherent risk and available mitigations involved in flying the current proposed vehicle design and anticipated stack configurations. In addition, Safety and Mission Assurance identified top technical, process and workforce concerns to be addressed as the program progresses toward the critical design phase. This paper will detail the evolution of the Gateway Program Safety and Mission Assurance integration functions, provide its current status and lessons learned for future human spaceflight programs. Throughout this paper the key tenets of the Gateway Program Safety and Mission Assurance will be discussed: - Application of a risk-informed approach to identify and mitigate areas of highest risk. - Leverage of valuable processes and lessons learned from earlier spaceflight programs. - Development of Safety and Mission Assurance products to inform design risk trades. - Utilization of common Safety and Mission Assurance practices to identify safety risks for multiple perspectives: top-down, bottom-up, and across lines of integration. - Approval of safety hazards at the appropriate level of authority, keeping most deliberation closest to design expertise and elevating risks of greatest concern for program-level consideration. - Championing of Safety and Mission Assurance processes and forums to foster a pervasive safety culture that is transparent, inclusive, and collaborative between all partners. These tenets have allowed the Gateway Safety and Mission Assurance function to play a key role in optimized vehicle design evolution, and early identification and mitigation of Gateway program and Artemis mission risk.

Helen Vaccaro↗

Comparative Analysis of Static and Dynamic Probabilistic Risk Assessment

Implementation of risk-informed design allows the design team to thoroughly explore the risks of a system while iterating the operations concept, design, and requirements until the system meets mission objects and is achievable within constraints. To arrive at a space system design that is likely to meet all constraints placed upon mass, cost, performance and risk, the system requirements must be understood and traded against each other as early as the conceptual design phase. Depending on the project phase and the goals of the risk analysis, various PRA methodologies could be used to produce quantitative risk estimates to enable such a process. In order to better understand the applicability, advantages, and limitations of various PRA methodologies, a comparative analysis of three bottom-up, component-based PRA approaches was performed. The three methods examined are a traditional static fault tree, a fault tree hybrid, and a dynamic Monte Carlo simulation. Each approach was used to assess a generic reaction control system (RCS) thruster pod and mission. The methods are assessed in terms of the process of modeling a system, the actionable information produced for the design team, and the overall fidelity of the quantitative risk evaluation generated. The paper also discusses the applicability of each methodology to the different phases of system development.

Probablistic↗

An Integrated Reliability and Physics-Based Risk Modeling Approach for Assessing Human Spaceflight Systems

This paper presents an integrated reliability and physics-based risk modeling approach for assessing human spaceflight systems. The approach is demonstrated using an example, end-to-end risk assessment of a generic-crewed space transportation system during a reference mission to the International Space Station. The behavior of the system is modeled using analysis techniques from multiple disciplines in order to properly capture the dynamic time- and state- dependent consequences of failures encountered in different mission phases. We discuss how to combine traditional reliability analyses with Monte Carlo simulation methods and physics-based engineering models to produce loss-of- mission and loss-of-crew risk estimates supporting risk-based decision-making and requirement verification. This approach facilitates risk-informed design by providing more realistic representation of system failures and interactions; identifying key risk-driving sensitivities, dependencies, and assumptions; and tracking multiple figures of merit within a single, responsive assessment framework that can readily incorporate evolving design information throughout system development.

Risk assessment↗

ENRE 655 Class Project. Development of the Initial Main Parachute Failure Probability for the Constellation Program (CxP) Orion Crew Exploration Vehicle (CEV) Parachute Assembly System (CPAS)

Loss of Crew (LOC) and Loss of Mission (LOM) are two key requirements the Constellation Program (CxP) measure against. To date, one of the top risk drivers for both LOC and LOM has been Orion's Crew Exploration Vehicle (CEV) Parachute Assembly System (CPAS). Even though the Orion CPAS is one of the top risk drivers of CxP, it has been very difficult to obtain any relevant data to accurately quantify the risk. At first glance, it would seem that a parachute system would be very reliable given the track record of Apollo and Soyuz. Given the success of those two programs, the amount of data is considered to be statistically insignificant. However, due to CxP having LOC/LOM as key design requirements, it was necessary for Orion to generate a valid prior to begin the Risk Informed Design process. To do so, the Safety & Mission Assurance (S&MA) Space Shuttle & Exploration Analysis Section generated an initial failure probability for Orion to use in preparation for the Orion Systems Requirements Review (SRR).

Fuqua, Bryan C.↗

Altair Lunar Lander Development Status: Enabling Human Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a minimum functionality approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicles safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to begin Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. A blended NASA-industry team will continue to refine the lander configuration and mature the vehicle design over the next few years. This paper will update the international community on the status of the Altair Project as it addresses the challenges of project formulation, including optimizing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

Altair Lunar Lander Development Status: Enabling Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a "minimum functionality" approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicle's safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to began Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. NASA intends to continue to seek industry involvement in project formulation activities. This paper will update the international coimmunity on the status of the Altair Project as it addresses the challenges of project formulation, including optinuzing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

An Altair Overview: Designing a Lunar Lander for 21st Century Human Space Exploration

Altair, the lunar lander element of NASA's Constellation program, was conducted in a different design environment than many other NASA projects of similar scope. Because of this relatively unique approach, there are a number of significant success stories that should be considered during the development of any future lunar landers or human spacecraft. This paper is divided into two separate themes; the first is the approach used during the conceptual design studies, including the systematic analysis cycles and the decision making process associated with each: and the second is a summary of the resulting lessons learned that were compiled after looking back at the lifetime of the Project. Altair was terminated before entering Phase B of its design, and was often criticized for being a very heavy and very large vehicle. While there was specific rationale for all of the decisions that led up to that configuration, future design cycles were specifically planned to re-address the mass challenge. Had the project continued, the deliberate, stepwise design process would have converged on an optimized lander design that balanced mass, risk, cost and capabilities. Some of the specific items that will be addressed in this paper include project development strategy, organizational approach and team dynamics, risk-informed design process, mission architecture constraints, mission key driving requirements, model-based systems engineering process, configuration studies, contingency considerations, subsystem overviews and key trade studies. The paper will conclude with a summary of the lessons identified during the Altair project and make suggestions for application to future studies.

Brown, Kendall K.↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗

NASA Hazard Analysis Process

This viewgraph presentation reviews The NASA Hazard Analysis process. The contents include: 1) Significant Incidents and Close Calls in Human Spaceflight; 2) Subsystem Safety Engineering Through the Project Life Cycle; 3) The Risk Informed Design Process; 4) Types of NASA Hazard Analysis; 5) Preliminary Hazard Analysis (PHA); 6) Hazard Analysis Process; 7) Identify Hazardous Conditions; 8) Consider All Interfaces; 9) Work a Preliminary Hazard List; 10) NASA Generic Hazards List; and 11) Final Thoughts

Deckert, George↗

An Analysis of Risk and Function Information in Early Stage Design

The concept of function offers a high potential for thinking and reasoning about designs as well as providing a common thread for relating together other design information. This paper focuses specifically on the relation between function and risk by examining how this information is addressed for a design team conducting early stage design for space missions. Risk information is decomposed into a set of key attributes which are then used to scrutinize the risk information using three approaches from the pragmatics sub-field of linguistics: i) Gricean, ii) Relevance Theory, and Functional Analysis. Results of this linguistics-based approach descriptively account for the context of designer communication with respect to function and risk, and offer prescriptive guidelines for improving designer communication.

Barrientos, Francesca↗

Exploration Medical Capability - Advancing Medical System Design and Risk-Informed Decision Making for Deep Space Exploration

BACKGROUND: Within NASA’s Human Research Program, the Exploration Medical Capability (ExMC) Element has three primary focus areas: clinical and scientific research, systems engineering and trade space analysis, and technology development and demonstrations. These focus areas feed into the overarching goal of enabling progressively Earth-Independent Medical Operations (EIMO), a new paradigm that will be necessary for future Artemis and Mars medical and vehicle systems. This EIMO end state aligns with NASA’s Moon to Mars Objectives, which clearly outline the need for NASA deep space exploration missions to reduce their reliance upon Earth and become increasingly autonomous, in preparation for the first human Mars mission. OVERVIEW: To advance exploration medical systems and ultimately, integrated crew health and performance systems, ExMC’s portfolio includes: funding ground development & testing of novel medical capabilities; creation of new approaches for the development of medical protocols and procedures; deployment of innovative technologies into analog environments; technology demonstrations in spaceflight; and eventual transition to operations of new capabilities for deep space exploration missions. The portfolio also includes: pharmaceutical research targeting stability, pharmacokinetics, and pharmacodynamics; integrated data architectures and clinical decision support tools; and systems engineering and trade space analysis tools to assist NASA in the development of future medical system models as well as the medical system requirements that can serve as a foundation for deep space exploration missions. All of these investments are done in a collaborative and coordinated fashion with other NASA stakeholders, such as the Environmental Control and Life Support Systems – Crew Health and Performance System Capability Leadership Team and the Health and Medical Technical Authority. DISCUSSION: In this presentation, ExMC will provide an overview of our work from across our portfolio, all of which will inform future EIMO efforts at NASA. ExMC’s research and development investments are targeted to reduce the human system risks associated with deep space exploration to the Moon and Mars.

Kris Lehnhardt↗

An Approach for Identifying IASMS Services, Functions, and Capabilities From Data Sources

Assuring safety in the NAS with the inclusion of new entrants that are part of Advanced Air Mobility (AAM) will require overcoming unique safety challenges that result from combining innovative technologies with novel airspace concepts for moving people and cargo using semi-autonomous/autonomous vehicles. Overcoming these AAM safety assurance challenges is the focus of the In-time Aviation Safety Management System (IASMS). The IASMS Concept of Operations (ConOps) describes an interconnected set of services, functions, and capabilities (SFCs)designed to manage operational risks, identify unknown risks, and inform system design to mitigate risk. This paper describes a broad approach for identifying SFCs involving technology trends in research, assessment of known and unknown risks in safety reports, and causal and contributing factors in aviation accidents and incidents. This approach leverages these sources to identify potential SFCs that enable the Monitor, Assess, and Mitigate (M-A-M)functionality that represents the enabling framework of the IASMS.

Kyle Ellis↗

An Approach for Defining IASMS Services, Functions, and Capabilities

Assuring safety in the NAS with the inclusion of new entrants, such as Advanced Air Mobility (AAM), will require overcoming unique safety challenges that result from combining innovative technologies with novel airspace concepts for moving people and cargo using autonomous vehicles. The focus of the In-time Aviation Safety Management System (IASMS) is to overcome AAM’s safety assurance challenges. The IASMS Concept of Operations (ConOps) describes an interconnected set of services, functions, and capabilities (SFCs) designed to manage operational risks, identify unknown risks, and inform system designs. This paper describes an approach for defining SFCs based on technology trends in research, assessment of known and unknown risks in voluntary safety reports, and causal and contributing factors in aviation accidents and incidents. This approach would identify potential SFCs that further expand the Monitor, Assess, and Mitigate (M-A-M) functionality that represents the enabling framework of the IASMS. Safety implications that will result from integration of AAM in the transformation of the National Airspace System (NAS) were addressed in National Academies committees reports on AAM and IASMS. Development of a ConOps for IASMS was a top recommendation and can be represented as a reframing of safety assurance that builds on real-time alerting such as the Traffic Alert and Collision Avoidance System, and adds the more encompassing in-time temporal parameter in recognition of the different timelines for collecting and assessing safety data for risk mitigations. For example, mining for safety trends from data sources such as the Aviation Safety Information Analysis and Sharing system occurs over a longer time period. Research on AAM operations poses that SFCs can be designed to monitor the safety margin appropriate for AAM including with regards to the distance between current flight parameters and nominal ideal conditions. These in-time comparisons will become more complex as the density of operations increases at least in certain areas and can include planned and actual 4D trajectory, and in-time comparisons having implications on conflict modeling and prediction including expected and actual departure time, fix/waypoint crossing times, and arrival time. These comparisons would be integrated as part of SFCs that redefine and inform new safety margin. An increased safety margin improves management of operational risks while reducing the potential for anomalies. An increased safety margin also has implications for operator confidence in the certainty of its operations and trust in automation. Technology trends in research could be used to refine existing SFCs and define needs for additional SFCs that provide safety improvements to the design and operation of vehicles, airspace design, and operator performance requirements. NASA is developing innovative approaches to safeguard against major accidents and incidents that have occurred in the NAS and those anticipated with the inclusion of envisioned AAM operations. The innovations use operational performance data to monitor, detect, and predict flight variations exceeding safe nominal patterns, such as would be caused by navigational error, severe weather complications, or hijacking of UAS controls. These innovative approaches have high potential to prevent accidents and incidents in the new AAM era. It is anticipated that elements of the innovations will evolve into SFCs for the IASMS. Voluntary safety reports can be monitored to identify anomalies related to design or operational performance risks. Reports could be periodically monitored and assessed for specific topics. Reports might serve as weak signals or precursors indicative of emergent risk such as when combined with other safety information. The architecture could include SFCs that are based on voluntary safety reports recognizing the periodic temporal nature of data analysis. As previously mentioned, aviation accidents with their causal and contributing precursors can inform the need for SFCs in the IASMS. Accidents and incidents at San Francisco International Airport such as Asiana 214 and Air Canada 759 illustrate how combinations of different factors lead to increased risk. These types of precursors and different factors have implications on the types of SFCs that could be needed to monitor and manage different sources and types of design and operational risk. Continuing to assure the safety of AAM as designs and operations gain in complexity can be accompanied by defining SFCs that also increase in complexity. These SFCs can leverage information from findings and recommendations synthesized across on-going research, voluntary safety reports, and accident and incident reports. These SFCs can serve to refine accuracy of algorithms and resolve limitations with current practices. The IASMS architecture represents the framework for the SFCs and their critical role in safety assurance.

In-Time Aviation Safety Management System↗