Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Analyses”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

COMPASS-FME Terrestrial Ecosystem Manipulation to Probe the Effects of Storm Treatments (TEMPEST) Experiment Level 2 Sensor Data v2-1

This is the version v2-1 Level 2 (L2) data release for COMPASS-FME environmental sensors located at our Terrestrial Ecosystem Manipulation to Probe the Effects of Storm Treatments (TEMPEST) experimental site. This manipulative, ecosystem-scale TEMPEST experiment addresses the potential for freshwater and estuarine-water disturbance events to alter tree function, species composition, and ecosystem processes in a deciduous coastal forest in MD, USA. The experiment uses a large-unit (2000 m2), un-replicated experimental design, with three 50 m × 40 m plots serving as control, freshwater, and estuarine-water treatments. Level 2 (L2) data consist of sensor observations from the COMPASS-FME synoptic sites, TEMPEST, and DELUGE. Compared to the L1 data, these are more consistent (always 15-minute timestamps for the entire year); better QA/QC’d (out of bounds, out of service, and extreme outlier values are removed); and more complete, with a gap-filled time series available alongside the main observations, and additional derived (calculated) variables. L2 data are intended to be rapidly and easily usable in analyses and simulations. However, algorithmic outlier identification always carries the risk of removing valid data, and Level 1 data may be more suitable for analyses that focus on variability or extreme events. This dataset includes: - An overall dataset README file that describes the current version, gives citation and contact information, etc. - Site- and year-specific folders, each holding variable-specific Parquet (a high performance, space efficient format; see https://parquet.apache.org) data files for each site and plot in that year. - Metadata files within each site-year folder provide full information on data units, expected ranges, contact information, detailed flood times, as well as a general description of the site. - Environmental sensor types that appear in the data files include weather (ClimaVUE50, CS, RM Young, and LI instruments in the graphs below); soil conditions (TEROS12); soil redox state (Redox); groundwater variables (AquaTROLL200 and AquaTROLL600); open water sondes (Exo); tree sap velocity (Sapflow); and system voltage and state (Datalogger). Data are reported every 15 minutes. Please see v2-1 TEMPEST L2 Sensor Package Quick Start.pdf for detailed information on data package structure, temporal coverage, and versioning. Data files are in Apache Parquet, a high performance, space efficient format for tabular data. These files can be read using R's `arrow` package (https://arrow.apache.org/docs/r/), with similar tools available in other languages. The TEMPEST flood events occurred on the following dates. They lasted for ~10 hours each day and delivered ~80,000 gallons to each plot; many data streams are available at 1 or 5 minute frequency during these periods. * Tests: Aug 25 (fresh plot) and Sep 9 (salt plot), 2021 * TEMPEST 1: June 22, 2022 * TEMPEST 2: June 6-7, 2023 * TEMPEST 3: June 11-13, 2024

EARTH SCIENCE > ATMOSPHERE > ATMOSPHERIC TEMPERATU↗

COMPASS-FME Synoptic Sites Level 2 Sensor Data v2-1

This is the version 2-1 Level 2 (L2) data release for COMPASS-FME environmental sensors located at our synoptic field sites. COMPASS-FME is studying sites in two distinct regions, the Chesapeake Bay and the Western Lake Erie Basin. We established the network at seven "synoptic" (observational) sites along the Chesapeake Bay and Lake Erie coastlines, collectively generating over three million observations per month, to track and comprehend environmental changes where land and water intersect. Additionally, the two regions provide an interesting contrast of saltwater and freshwater coasts that allow us to differentiate the impacts of inundation and coastal water chemistries in two nationally important coastal systems. Level 2 (L2) data consist of sensor observations from the COMPASS-FME synoptic sites, TEMPEST, and DELUGE. Compared to the L1 data, these are more consistent (always 15-minute timestamps for the entire year); better QA/QC’d (out of bounds, out of service, and extreme outlier values are removed); and more complete, with a gap-filled time series available alongside the main observations, and additional derived (calculated) variables. L2 data are intended to be rapidly and easily usable in analyses and simulations. However, algorithmic outlier identification always carries the risk of removing valid data, and Level 1 data may be more suitable for analyses that focus on variability or extreme events. This dataset includes: - An overall dataset README file that describes the current version, gives citation and contact information, etc. - Site- and year-specific folders, each holding variable-specific Parquet (a high performance, space efficient format; see https://parquet.apache.org) data files for each site and plot in that year. - Metadata files within each site-year folder provide full information on data units, expected ranges, contact information, detailed flood times, as well as a general description of the site. - Environmental sensor types that appear in the data files include weather (ClimaVUE50, CS, RM Young, and LI instruments in the graphs below); soil conditions (TEROS12); soil redox state (Redox); groundwater variables (AquaTROLL200 and AquaTROLL600); open water sondes (Exo); tree sap velocity (Sapflow); and system voltage and state (Datalogger). Data are reported every 15 minutes. Data files are in Apache Parquet, a high performance, space efficient format for tabular data. These files can be read using R's `arrow` package (https://arrow.apache.org/docs/r/), with similar tools available in other languages. Please see v2-1 L2 Sensor Package QStart.pdf for detailed information on data package structure, temporal coverage, and versioning.

EARTH SCIENCE > ATMOSPHERE > ATMOSPHERIC TEMPERATU↗

Post-Combat-Injury Opioid Prescription and Alcohol Use Disorder in the Military

Previous studies have identified combat exposure and combat traumatic experience as problematic drinking risk factors. Increasing evidence suggests that opioid use increases the risk of alcohol use disorder. This study investigated the association between opioid prescription use after injury and (1) alcohol use disorder and (2) severity of alcohol use disorder among deployed military servicemembers. Deidentified health records data of 9,029 deployed servicemembers from a retrospective cohort study were analyzed. Data were randomly selected from the Department of Defense Trauma Registry and included servicemembers with combat injuries during deployment in Iraq or Afghanistan (2002–2016). Pharmacy records and International Classification of Diseases, Ninth and Tenth Revision diagnosis codes were used. Three groups were identified (no opioid prescription use, nonpersistent opioid prescription use, and persistent opioid prescription use) and were compared on the basis of alcohol use disorder risk using Cox proportional hazard models. Data analyses were performed in 2021. Of the 9,029 servicemembers with combat injury, 2,262 developed alcohol use disorder (1,322 developed severe alcohol use disorder). Compared with no opioid prescription use, increased alcohol use disorder risk was associated with persistent opioid prescription use, with a hazard ratio of 1.13 (95% CI=1.02, 1.26). After covariate adjustment, increased risk remained statistically significant (hazards ratio=1.24; 95% CI=1.10, 1.39). There was no significant difference in alcohol use disorder risk between no opioid prescription use and nonpersistent opioid prescription use. The risk of severe alcohol use disorder did not vary by opioid use among servicemembers with alcohol use disorder diagnosis. Furthermore, the findings of the study suggest that the incidence of alcohol use disorder was higher among injured servicemembers with persistent opioid prescription use than among those without opioid use. If replicated in prospective studies, the findings highlight the need for clinicians to consider the current and history of alcohol use of patients in initiating treatment involving opioids.

60 APPLIED LIFE SCIENCES↗

Recent developments in deployment analysis simulation using a multi-body computer code

Deployment is a candidate mode for construction of structural space systems components. By its very nature, deployment is a dynamic event, often involving large angle unfolding of flexible beam members. Validation of proposed designs and conceptual deployment mechanisms is enhanced through analysis. Analysis may be used to determine member loads thus helping to establish deployment rates and deployment control requirements for a given concept. Futhermore, member flexibility, joint free-play, manufacturing tolerances, and imperfections can affect the reliability of deployment. Analyses which include these effects can aid in reducing risks associated with a particular concept. Ground tests which can play a similar role to that of analyses are difficult and expensive to perform. Suspension systems just for vibration ground tests of large space structures in a 1 g environment present many challenges. Suspension of a structure which spatially expands is even more challenging. Analysis validation through experimental confirmation on relatively small simple models would permit analytical extrapolation to larger more complex space structures.

Housner, Jerrold M.↗

Precise relative magnitude measurement improves fracture characterization during hydraulic fracturing

SUMMARY Microseismic monitoring is an important technique to obtain detailed knowledge of in-situ fracture size and orientation during stimulation to maximize fluid flow throughout the rock volume and optimize production. Furthermore, considering that the frequency of earthquake magnitudes empirically follows a power law (i.e. Gutenberg–Richter), the accuracy of microseismic event magnitude distributions is potentially crucial for seismic risk management. In this study, we analyse microseismicity observed during four hydraulic fracture treatments of the legacy Cotton Valley experiment in 1997 at the Carthage gas field of East Texas, where fractures were activated at the base of the sand-shale Upper Cotton Valley formation. We perform waveform cross-correlation to detect similar event clusters, measure relative amplitude from aligned waveform pairs with a principal component analysis, then measure precise relative magnitudes. The new magnitudes significantly reduce the deviations between magnitude differences and relative amplitudes of event pairs. This subsequently reduces the magnitude differences between clusters located at different depths. Reduction in magnitude differences between clusters suggests that some attenuation-related biases could be effectively mitigated with relative magnitude measurements. The maximum likelihood method is applied to understand the magnitude frequency distributions and quantify the seismogenic index of the clusters. Statistical analyses with new magnitudes suggest that fractures that are more favourably oriented for shear failure have lower b-value and higher seismogenic index, suggesting higher potential for relatively larger earthquakes, rather than fractures subparallel to maximum horizontal principal stress orientation.

58 GEOSCIENCES↗

Thermal-Mechanical Analysis of an Additive Manufacturing Ceramic Heat Exchanger for High-Temperature Recuperator in a sCO2 Power System

Supercritical CO2 (sCO2) Brayton power cycle can be configured in a closed-loop power system and has a potentially high cycle efficiency. Compactness and high efficiency of a sCO2 power block make the sCO2 Brayton cycle a versatile power cycle in broad applications. While many heat sources are of sufficient intensity to produce high temperature working fluids to achieve high cycle efficiency, the thermal-mechanical stability of traditional materials (e.g., steels and nickel-based superalloys) used in construction of heat exchangers and turbine components limits the operating conditions and thus thermodynamic efficiency of the system. This effort seeks to establish the viability of ceramic heat exchanger technologies for the most extreme operating conditions envisioned for power generation and other high temperature processes. Heat exchangers constructed from ultra-high temperature ceramics, a class of extreme environment materials featuring melting points (Tmp.) above 3000 degrees C, is particularly appealing for sCO2 Brayton cycles given their ultra-low creep rates and very high retained strength at low homologous temperatures (i.e., T < 0.5 Tmp., or at least 1500 degrees C). To translate these materials properties to ultra-high temperature heat exchangers, innovations are required in ceramic manufacturing techniques to realize the complex architectures featured in compact heat exchangers with high power density. With appropriate processing, ZrB2-SiC based compositions can be sintered to near full density and shaped into complex topologies via ceramic additive manufacturing methods. This paper analyzes heat exchanger designs and explores thermal-mechanical implications of the operating environment. Thermal flow, heat transfer, and conjugate mechanical analyses provide insights into benefits and risks associated with the design approach.

additive manufacturing↗

Utilization of the LMP Methodology in Support of the VTR Conceptual Safety Design Report

The Versatile Test Reactor (VTR) is a fast spectrum test reactor currently being developed in the United States under the direction of the US Department of Energy (DOE), Office of Nuclear Energy. The VTR is utilizing a risk-informed performance-based (RIPB) approach for design support and authorization by the DOE, derived from recent efforts by the US industry led Licensing Modernization Project (LMP). This document contains an overview of the implementation of the LMP approach in support of the VTR Conceptual Safety Design Report (CSDR). The work reported here is the result of studies supporting a VTR conceptual design, cost, and schedule estimate for DOE-NE to make a decision on procurement. As such, it is preliminary. The VTR RIPB authorization approach utilizes information from the probabilistic risk assessment (PRA), coupled with deterministic analyses, to aid in decision-making regarding the identification and categorization of safety basis events (SBEs), the classification of structures, systems, and components (SSCs), and the evaluation of defense-in-depth (DID) adequacy. As part of initial reactor design efforts, a VTR conceptual design PRA was developed to support the RIPB process, which focused on at-power internal events, with scoping analyses for seismic and sodium fire hazards. In addition to supporting numerous design studies, preliminary results from the RIPB approach and the VTR conceptual design PRA were utilized as the basis of the VTR CSDR. The initial identification and categorization of SBEs, SSC classification, and DID evaluation were contained within the CSDR, which was submitted to DOE in 2019 as part of the CD-1 submittal package. Following review, DOE approved the CSDR in April 2020 and the CD-1 package in late 2020. Valuable experience was gained through the implementation of the RIPB approach for design and authorization during the VTR conceptual design phase, which is summarized in this document. To the extent possible, this experience has been shared with the advanced reactor industry, through publications and participation in licensing tabletops, in addition to informing DOE:NE advanced reactor regulatory development efforts. Furthermore, the approval of the CSDR by the DOE as part of CD-1 represents a significant milestone in the use of RIPB approaches for advanced reactor licensing.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Curating Carbon Storage Data for Reuse: Enabling Research and Modeling from Earth’s Surface to Subsurface

The volume of public geologic carbon storage (GCS) data resources has continued to increase in recent years as the result of an increase in funding from government, industry, and academia towards national, basin, regional and field scale studies to ensure carbon capture and storage becomes a commercially viable operation. Despite the increasing volume of data, GCS data applied towards analyses such as geologic, cost, and risk modeling continues to be multi-sourced and often disparate in nature, published across government agencies, websites, data repositories and buried in derivative reports and documents. Much of the time preparing for an analysis and derivative product development is spent collecting, aggregating, transforming and preparing input data. There have been significant efforts within the DOE National Energy Technology Laboratory’s Carbon Storage Program to optimize multi-source, multi-scale subsurface geologic data curation and aggregation to support data discovery, interoperability, and reuse. Methods include the use of artificial intelligence, machine learning, and data science techniques. This talk will discuss the workflows, best practices, and processes developed to support the aggregation and curation of data through the whole system – surface to subsurface data - that support multi-scale, multi-purpose analysis for carbon storage research.

Morkner, Paige↗

Improvements to the Ionizing Radiation Risk Assessment Program for NASA Astronauts

To perform dosimetry and risk assessment, NASA collects astronaut ionizing radiation exposure data from space flight, medical imaging and therapy, aviation training activities and prior occupational exposure histories. Career risk of exposure induced death (REID) from radiation is limited to 3 percent at a 95 percent confidence level. The Radiation Health Office at Johnson Space Center (JSC) is implementing a program to integrate the gathering, storage, analysis and reporting of astronaut ionizing radiation dose and risk data and records. This work has several motivations, including more efficient analyses and greater flexibility in testing and adopting new methods for evaluating risks. The foundation for these improvements is a set of software tools called the Astronaut Radiation Exposure Analysis System (AREAS). AREAS is a series of MATLAB(Registered TradeMark)-based dose and risk analysis modules that interface with an enterprise level SQL Server database by means of a secure web service. It communicates with other JSC medical and space weather databases to maintain data integrity and consistency across systems. AREAS is part of a larger NASA Space Medicine effort, the Mission Medical Integration Strategy, with the goal of collecting accurate, high-quality and detailed astronaut health data, and then securely, timely and reliably presenting it to medical support personnel. The modular approach to the AREAS design accommodates past, current, and future sources of data from active and passive detectors, space radiation transport algorithms, computational phantoms and cancer risk models. Revisions of the cancer risk model, new radiation detection equipment and improved anthropomorphic computational phantoms can be incorporated. Notable hardware updates include the Radiation Environment Monitor (which uses Medipix technology to report real-time, on-board dosimetry measurements), an updated Tissue-Equivalent Proportional Counter, and the Southwest Research Institute Radiation Assessment Detector. Also, the University of Florida hybrid phantoms, which are flexible in morphometry and positioning, are being explored as alternatives to the current NASA computational phantoms.

Semones, E. J.↗

Understanding Competing Risks

Highlights: • Clinicians and researchers need to be cognizant of competing risks (ie, the occurrence of an event that precludes future development of the outcome of interest). • Censoring is appropriate when a patient being censored at a particular time (eg, owing to loss to follow-up) is deemed to have approximately the same future risk of developing the outcome of interest as patients still being followed, and when the reason for censoring is not related to events of interest. • Censoring is not appropriate in many scenarios; for example, a dead patient can never develop a future cancer recurrence or late effect. • Kaplan-Meier (KM) analysis is commonly used for a time-to-event analysis when the primary outcome (eg, overall survival) has no meaningful competing risk and censoring is appropriate. Cox proportional hazards modeling can be used for multivariable analysis to examine the association between covariates and the primary outcome. • In the presence of competing events, incorrect use of the KM analysis will likely lead to an overestimation of the risk of the outcome of interest and biased estimates from both univariable and multivariable analyses. Therefore, KM usually should not be used to determine local recurrence risk because humanity is always at risk for dying, which is a competing risk. • A competing risk analysis is therefore most appropriate when there are competing events to the primary outcome of interest. The most commonly used multivariable model in these situations is the Fine-Gray model. • Many fundamental questions in radiation oncology—local and regional recurrence, treatment-related toxicity—are best addressed using competing risk methodologies.

62 RADIOLOGY AND NUCLEAR MEDICINE↗

Application of Accelerometer Data to Mars Odyssey Aerobraking and Atmospheric Modeling

Aerobraking was an enabling technology for the Mars Odyssey mission even though it involved risk due primarily to the variability of the Mars upper atmosphere. Consequently, numerous analyses based on various data types were performed during operations to reduce these risk and among these data were measurements from spacecraft accelerometers. This paper reports on the use of accelerometer data for determining atmospheric density during Odyssey aerobraking operations. Acceleration was measured along three orthogonal axes, although only data from the component along the axis nominally into the flow was used during operations. For a one second count time, the RMS noise level varied from 0.07 to 0.5 mm/s2 permitting density recovery to between 0.15 and 1.1 kg per cu km or about 2% of the mean density at periapsis during aerobraking. Accelerometer data were analyzed in near real time to provide estimates of density at periapsis, maximum density, density scale height, latitudinal gradient, longitudinal wave variations and location of the polar vortex. Summaries are given of the aerobraking phase of the mission, the accelerometer data analysis methods and operational procedures, some applications to determining thermospheric properties, and some remaining issues on interpretation of the data. Pre-flight estimates of natural variability based on Mars Global Surveyor accelerometer measurements proved reliable in the mid-latitudes, but overestimated the variability inside the polar vortex.

Tolson, R. H.↗

Finite Element Analysis and Test Correlation of a 10-Meter Inflation-Deployed Solar Sail

Under the direction of the NASA In-Space Propulsion Technology Office, the team of L Garde, NASA Jet Propulsion Laboratory, Ball Aerospace, and NASA Langley Research Center has been developing a scalable solar sail configuration to address NASA's future space propulsion needs. Prior to a flight experiment of a full-scale solar sail, a comprehensive phased test plan is currently being implemented to advance the technology readiness level of the solar sail design. These tests consist of solar sail component, subsystem, and sub-scale system ground tests that simulate the vacuum and thermal conditions of the space environment. Recently, two solar sail test articles, a 7.4-m beam assembly subsystem test article and a 10-m four-quadrant solar sail system test article, were tested in vacuum conditions with a gravity-offload system to mitigate the effects of gravity. This paper presents the structural analyses simulating the ground tests and the correlation of the analyses with the test results. For programmatic risk reduction, a two-prong analysis approach was undertaken in which two separate teams independently developed computational models of the solar sail test articles using the finite element analysis software packages: NEiNastran and ABAQUS. This paper compares the pre-test and post-test analysis predictions from both software packages with the test data including load-deflection curves from static load tests, and vibration frequencies and mode shapes from vibration tests. The analysis predictions were in reasonable agreement with the test data. Factors that precluded better correlation of the analyses and the tests were uncertainties in the material properties, test conditions, and modeling assumptions used in the analyses.

Sleight, David W.↗

Structural Analysis of an Inflation-Deployed Solar Sail With Experimental Validation

Under the direction of the NASA In-Space Propulsion Technology Office, the team of L Garde, NASA Jet Propulsion Laboratory, Ball Aerospace, and NASA Langley Research Center has been developing a scalable solar sail configuration to address NASA s future space propulsion needs. Prior to a flight experiment of a full-scale solar sail, a comprehensive phased test plan is currently being implemented to advance the technology readiness level of the solar sail design. These tests consist of solar sail component, subsystem, and sub-scale system ground tests that simulate the vacuum and thermal conditions of the space environment. Recently, two solar sail test articles, a 7.4-m beam assembly subsystem test article and a 10-m four-quadrant solar sail system test article, were tested in vacuum conditions with a gravity-offload system to mitigate the effects of gravity. This paper presents the structural analyses simulating the ground tests and the correlation of the analyses with the test results. For programmatic risk reduction, a two-prong analysis approach was undertaken in which two separate teams independently developed computational models of the solar sail test articles using the finite element analysis software packages: NEiNastran and ABAQUS. This paper compares the pre-test and post-test analysis predictions from both software packages with the test data including load-deflection curves from static load tests, and vibration frequencies and mode shapes from structural dynamics tests. The analysis predictions were in reasonable agreement with the test data. Factors that precluded better correlation of the analyses and the tests were uncertainties in the material properties, test conditions, and modeling assumptions used in the analyses.

Sleight, David W.↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗

Usability of Pre-Flight Planning Interfaces for Supplemental Data Service Provider Tools to Support Uncrewed Aircraft System Traffic Management

Small uncrewed aircraft systems (sUASs) operate in low-altitude, uncontrolled airspace – where support services for their operators (UASOs) are not currently provided. NASA’s System-Wide Safety (SWS) project is identifying the potential risks and hazards to sUAS operations to provide, inform, and improve the designs of In-time Aviation Safety Management Systems (IASMS). The IASMS will include a suite of data-driven tools that compile and analyze data collected from aviation systems and environmental sources to predict hazards, and provide information to allow operators to mitigate these risks (Young et al., 2020). These risk and hazard services can be run and displayed to operators on graphical user interfaces (GUIs), as they relate to a vehicle(s)’ route of flight. These interfaces offer both a means to present hazard service output and offer an opportunity to test user understanding of the information, user decision making, and the best ways to present such data to an operator. Based on these future technologies and intended missions, it is important to investigate interface requirements and evaluate how operators might use these tools. Presenting salient and meaningful risk assessment information to operators is necessary to increase situation awareness and ultimately safety. Building on previous research (Feldman et al., 2022), a usability study comparing two GUIs was conducted to explore how individuals interacted with different styles of information displays. A series of pre-flight hazard and risk-assessment tasks were developed to evaluate participant performance using the Supplemental Data Service Provider Consolidated Dashboard and the Human Automation Team Interface System interfaces. Participants were trained to use both GUIs and their performance was analysed across different scenarios involving multiple sUASs. Performance on simple tasks and the System Usability Scale scores were reported by Feldman et al., 2023. Additional analyses and evaluations on more complex tasks (e.g., risk assessment, prioritization), workload and response times are examined in this paper.

sUAV interfaces↗

Usability of Pre-flight Planning Interfaces for Supplemental Data Service Provider Tools to Support Uncrewed Aircraft System Traffic Management

Small uncrewed aircraft systems (sUASs) operate in low-altitude, uncontrolled airspace – where support services for their operators (UASOs) are not currently provided. NASA’s System-Wide Safety (SWS) project is identifying the potential risks and hazards to sUAS operations to provide, inform, and improve the designs of In-time Aviation Safety Management Systems (IASMS). The IASMS will include a suite of data-driven tools that compile and analyze data collected from aviation systems and environmental sources to predict hazards, and provide information to allow operators to mitigate these risks (Young et al., 2020). These risk and hazard services can be run and displayed to operators on graphical user interfaces (GUIs), as they relate to a vehicle(s)’ route of flight. These interfaces offer both a means to present hazard service output and offer an opportunity to test user understanding of the information, user decision making, and the best ways to present such data to an operator. Based on these future technologies and intended missions, it is important to investigate interface requirements and evaluate how operators might use these tools. Presenting salient and meaningful risk assessment information to operators is necessary to increase situation awareness and ultimately safety. Building on previous research (Feldman et al., 2022), a usability study comparing two GUIs was conducted to explore how individuals interacted with different styles of information displays. A series of pre-flight hazard and risk-assessment tasks were developed to evaluate participant performance using the Supplemental Data Service Provider Consolidated Dashboard and the Human Automation Team Interface System interfaces. Participants were trained to use both GUIs and their performance was analysed across different scenarios involving multiple sUASs. Performance on simple tasks and the System Usability Scale scores were reported by Feldman et al., 2023. Additional analyses and evaluations on more complex tasks (e.g., risk assessment, prioritization), workload and response times are examined in this paper.

sUAV interfaces↗

Microbial Anomalies Encountered on the International Space Station

Microorganisms in our living environments are unavoidable. A community of microbes arrived in space with the delivery of the first element of the International Space Station (ISS), attached to hardware and on the bodies of the humans tasked with the initial assembly missions. The risk that microorganisms could cause adverse effects in the health of both the human occupants of the ISS as well as the physical integrity of the station environment and life support systems has been both a driver and a function of engineering and operational controls. Scientists and engineers at NASA have gone to extensive measures to control microbial growth at levels safe for the crewmembers and the spacecraft environment. Many of these measures were initiated with the design of the spacecraft and its systems. Materials used in the ISS were tested for resistance to fungi, such as mold and a paint with a fungus-killing chemical was also used. Controlling the humidity of the air in the Station is also an effective way of discouraging microbe growth. The breathing air is reconditioned by the Environmental Control Life Support System (ECLSS) prior to distribution, utilizing High Efficiency Particulate Air (HEPA) filtration. Requirements restricting the accumulation of water condensate in the air handlers and habitable volume of the ISS were other safeguards added. Water for drinking and food rehydration is disinfected or filtered. A robust in-flight housekeeping regimen for the ISS significantly reduces inappropriate growth of microorganisms and includes a regular cleaning of accessible surfaces with disinfectant wipes. Most of these requirements were suggested by microbiologists to mitigate and possibly prevent many microbiological risks. In addition to these controls, before flight monitoring and analyses of the cabin air, exposed surfaces, water and food, consumables, and crew members are conducted to mitigate microbial risk to the crew and spacecraft. Many microbial risks are much easier to identify and resolve before launch than during space flight. Although the focus has been on prevention of microbiologically related, not all problems can be anticipated. A number of microbial anomalies have occurred on ISS. This paper will discuss the occurrences, root-cause investigations, and mitigation steps taken to remediate the contamination.

Bruce, Rebekah J.↗

Quantitative Risk Assessment for Hydrogen-Powered Locomotive Refueling

Hydrogen powered locomotives are being explored to reduce emissions in rail applications. The risks of operations like refueling should be understood to ensure safe environments for workers and members of the public. Sensitivity analyses were conducted using HyRAM+ to identify major drivers of risk and compare effects of system parameters on individual risk. The consequences of jet fires from full-bore leaks dominated the risk, compared to explosions or smaller leaks. Pipe size, leak detection capability, and leak frequencies of system components greatly affected risk while overpressure modeling parameters and ambient conditions had little effect. The effects of personal protective equipment (PPE) materials on individual risk were quantified by reducing the individual’s exposure time or absorbed thermal dose. PPE only showed a risk reduction in low-risk cases. This study highlighted target areas for risk mitigation, including leak detection equipment and component maintenance, and indicated that the minimal effects of other parameters on risk may not justify prescriptive requirements for refueling operators.

08 HYDROGEN↗