Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “explosives safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Application of Fault Management Theory to the Quantitative Selection of a Launch Vehicle Abort Trigger Suite

The theory of System Health Management (SHM) and of its operational subset Fault Management (FM) states that FM is implemented as a "meta" control loop, known as an FM Control Loop (FMCL). The FMCL detects that all or part of a system is now failed, or in the future will fail (that is, cannot be controlled within acceptable limits to achieve its objectives), and takes a control action (a response) to return the system to a controllable state. In terms of control theory, the effectiveness of each FMCL is estimated based on its ability to correctly estimate the system state, and on the speed of its response to the current or impending failure effects. This paper describes how this theory has been successfully applied on the National Aeronautics and Space Administration's (NASA) Space Launch System (SLS) Program to quantitatively estimate the effectiveness of proposed abort triggers so as to select the most effective suite to protect the astronauts from catastrophic failure of the SLS. The premise behind this process is to be able to quantitatively provide the value versus risk trade‐off for any given abort trigger, allowing decision makers to make more informed decisions. All current and planned crewed launch vehicles have some form of vehicle health management system integrated with an emergency launch abort system to ensure crew safety. While the design can vary, the underlying principle is the same: detect imminent catastrophic vehicle failure, initiate launch abort, and extract the crew to safety. Abort triggers are the detection mechanisms that identify that a catastrophic launch vehicle failure is occurring or is imminent and cause the initiation of a notification to the crew vehicle that the escape system must be activated. While ensuring that the abort triggers provide this function, designers must also ensure that the abort triggers do not signal that a catastrophic failure is imminent when in fact the launch vehicle can successfully achieve orbit. That is, the abort triggers must have low false negative rates to be sure that real crew‐threatening failures are detected, and also low false positive rates to ensure that the crew does not abort from non‐crew‐threatening launch vehicle behaviors. The analysis process described in this paper is a compilation of over six years of lessons learned and refinements from experiences developing abort triggers for NASA's Constellation Program (Ares I Project) and the SLS Program, as well as the simultaneous development of SHM/FM theory. The paper will describe the abort analysis concepts and process, developed in conjunction with SLS Safety and Mission Assurance (S&MA) to define a common set of mission phase, failure scenario, and Loss of Mission Environment (LOME) combinations upon which the SLS Loss of Mission (LOM) Probabilistic Risk Assessment (PRA) models are built. This abort analysis also requires strong coordination with the Multi‐Purpose Crew Vehicle (MPCV) and SLS Structures and Environments (STE) to formulate a series of abortability tables that encapsulate explosion dynamics over the ascent mission phase. The design and assessment of abort conditions and triggers to estimate their Loss of Crew (LOC) Benefits also requires in‐depth integration with other groups, including Avionics, Guidance, Navigation and Control(GN&C), the Crew Office, Mission Operations, and Ground Systems. The outputs of this analysis are a critical input to SLS S&MA's LOC PRA models. The process described here may well be the first full quantitative application of SHM/FM theory to the selection of a sensor suite for any aerospace system.

Lo, Yunnhon↗

Color Changing Hydrogen Sensors

During the Space Shuttle Program, one of the most hazardous operation that occurred was the loading of liquid hydrogen (LH2) during fueling operations of the spacecraft. Due to hydrogen's low explosive limit, any amount leaked could lead to catastrophic event. Hydrogen's chemical properties make it ideal as a rocket fuel; however, the fuel is deemed unsafe for most commercial use because of the inability to easily detect the gas leaking. The increased use of hydrogen over traditional fossil fuels would reduce greenhouse gases and America's dependency on foreign oil. Therefore a technology that would improve safety at NASA and in the commercial sector while creating a new economic sector would have a huge impact to NASA's mission. The Chemochromic Detector for sensing hydrogen gas leakage is a color-changing detector that is useful in any application where it is important to know not only the presence but also the location of the hydrogen gas leak. This technology utilizes a chemochromicpigment and polymer matrix that can be molded or spun into rigid or pliable shapes useable in variable temperature environments including atmospheres of inert gas, hydrogen gas, or mixtures of gases. A change in color of the detector material indicates where gaseous hydrogen leaks are occurring. The irreversible sensor has a dramatic color change from beige to dark grey and remains dark grey after exposure. A reversible pigment changes from white to blue in the presence of hydrogen and reverts back to white in the presence of oxygen. Both versions of the sensor's pigments were comprised of a mixture of a metal oxide substrate and a hydro-chromic compound (i.e., the compound that changed color in the presence of hydrogen) and immediately notified the operator of the presence of low levels of hydrogen. The detector can be used in a variety of formats including paint, tape, caulking, injection molded parts, textiles and fabrics, composites, and films. This technology brings numerous benefits over the traditional hydrogen sensors: The technology has excellent temperature stability (4K to 373 K), it can be used in cryogenic fluid applications, it is easy to apply and remove; it requires no power to operate; it has a quick response time; the leak points can be detected visually or electronically; it is nonhazardous, thus environmentally friendly; it can be reversible or irreversible; it does not require on-site monitoring; has a long shelf life; the detector is very durable; and the technology is inexpensive to manufacture.

Chemochromic sensor↗

Fault tree safety analysis of a large Li/SOCl(sub)2 spacecraft battery

The results of the safety fault tree analysis on the eight module, 576 F cell Li/SOCl2 battery on the spacecraft and in the integration and test environment prior to launch on the ground are presented. The analysis showed that with the right combination of blocking diodes, electrical fuses, thermal fuses, thermal switches, cell balance, cell vents, and battery module vents the probability of a single cell or a 72 cell module exploding can be reduced to .000001, essentially the probability due to explosion for unexplained reasons.

Uy, O. Manuel↗

Requirements for an Integrated UAS CNS Architecture

The National Aeronautics and Space Administration (NASA) Glenn Research Center (GRC) is investigating revolutionary and advanced universal, reliable, always available, cyber secure and affordable Communication, Navigation, Surveillance (CNS) options for all altitudes of UAS operations. In Spring 2015, NASA issued a Call for Proposals under NASA Research Announcements (NRA) NNH15ZEA001N, Amendment 7 Subtopic 2.4. Boeing was selected to conduct a study with the objective to determine the most promising candidate technologies for Unmanned Air Systems (UAS) air-to-air and air-to-ground data exchange and analyze their suitability in a post-NextGen NAS environment. The overall objectives are to develop UAS CNS requirements and then develop architectures that satisfy the requirements for UAS in both controlled and uncontrolled air space. This contract is funded under NASAs Aeronautics Research Mission Directorates (ARMD) Aviation Operations and Safety Program (AOSP) Safe Autonomous Systems Operations (SASO) project and proposes technologies for the Unmanned Air Systems Traffic Management (UTM) service. Communications, Navigation and Surveillance (CNS) requirements must be developed in order to establish a CNS architecture supporting Unmanned Air Systems integration in the National Air Space (UAS in the NAS). These requirements must address cybersecurity, future communications, satellite-based navigation APNT, and scalable surveillance and situational awareness. CNS integration, consolidation and miniaturization requirements are also important to support the explosive growth in small UAS deployment. Air Traffic Management (ATM) must also be accommodated to support critical Command and Control (C2) for Air Traffic Controllers (ATC). This document therefore presents UAS CNS requirements that will guide the architecture.

Templin, Fred↗

Quantitative Risk Assessment for Fuel Cell Electric Bus Hydrogen Storage and Refueling Facility

It is necessary to understand the safety implications and risk mitigation options for fuel cell electric bus fleet deployment, especially for related facilities responsible for operations such as production, storage, compression, and dispensing of hydrogen for use by the buses. In this report, we present a quantitative risk assessment for a potential fuel cell electric bus fleet that was motivated by efforts to improve resilience at the Portland International Airport but can be applicable to a range of hydrogen case studies and use cases. We estimated risk for a facility that produces, stores, compresses, and dispenses hydrogen for the fleet of buses, with a focus on individual risk to people in terms of annual frequency of fatality. We considered the frequency of hydrogen leaks that could result in harmful physical outcomes like jet fires or explosions, and the consequences of those outcomes for people. We created customized fault trees to calculate the frequencies of different sizes of leaks and event sequence diagrams to calculate ignition probabilities for the various leak sizes. We also leveraged the HyRAM+ toolkit to use these inputs to calculate overall risk for the facility, which we separated into one section responsible for producing, storing, and compressing hydrogen, and one section responsible for dispensing the hydrogen to the buses. We found that the dispensing area seemed to have a higher risk than the production/storage/compression area of the facility, largely because of the inclusion of a component with a high leak frequency (the heat exchanger used to cool the hydrogen before entering the vehicle, to prevent overheating and expansion of hydrogen in the onboard tank). For the example production and refueling facility we evaluated and the data we used for the analysis, the leak frequency had a larger impact on the risk differences between the two sections on the facility, compared to the physical outcome consequence, which was slightly different due to the varying fuel conditions, but not substantially different. Actions can be taken to prevent these hazards (e.g., lowering leak frequencies in system components) or to mitigate the consequences if they do occur (e.g., installing barriers to protect people if ignition events occur). The choice of which actions to take depends not only on safety considerations but also on space, time, staffing, feasibility, and financial constraints. Therefore, the quantitative risk assessment approach can help understand relative risk contributions from different components, leak sizes, consequences, and human actions, to prioritize risk reduction strategies and balance these parameters. The outcomes of this report may be useful for a variety of stakeholders working in the hydrogen, transportation, vehicle, and aviation sector, including those responsible for aspects like facility design, operations, and regulations. There is not a single value of risk that determines whether a hypothetical system is “safe” or not. The insights about risk mitigations may be leveraged, and the quantitative risk assessment approach can be applied to other case studies to understand risk priorities and contributions specific to different FCEB and hydrogen facility uses.

08 HYDROGEN↗

Safety Standard for Hydrogen and Hydrogen Systems: Guidelines for Hydrogen System Design, Materials Selection, Operations, Storage and Transportation

The NASA Safety Standard, which establishes a uniform process for hydrogen system design, materials selection, operation, storage, and transportation, is presented. The guidelines include suggestions for safely storing, handling, and using hydrogen in gaseous (GH2), liquid (LH2), or slush (SLH2) form whether used as a propellant or non-propellant. The handbook contains 9 chapters detailing properties and hazards, facility design, design of components, materials compatibility, detection, and transportation. Chapter 10 serves as a reference and the appendices contained therein include: assessment examples; scaling laws, explosions, blast effects, and fragmentation; codes, standards, and NASA directives; and relief devices along with a list of tables and figures, abbreviations, a glossary and an index for ease of use. The intent of the handbook is to provide enough information that it can be used alone, but at the same time, reference data sources that can provide much more detail if required.

Source record↗

Development and first flight of a sounding rocket payload to investigate the phenomena of rapidly varying space plasma

NASA Goddard Space Flight Center, Wallops Flight Facility has developed, flown, and recovered a unique plasma physics payload. This sounding rocket payload was developed to measure varying aspects of Alfven's critical velocity effect in a space plasma by using conical-shaped barium explosives. These measurements could possibly duplicate conditions that existed in the early solar system. This paper provides details of the payload and subpayload development, with specific emphasis on the extensive dynamic analysis of the barium release modules. Other key elements which are expanded on in the paper are: (1) design, development, and testing acceptance for the science/inertia booms using a viscous damping system for high spin rate deployment; (2) vehicle dynamic analysis; (3) apogee and impact dispersion analysis to satisfy the science and NASA safety requirements; (4) a comparison of predicted versus actual flight events.

Buchanan, R. P.↗

Evaluation of Hydrogen Storage Quantity Limits for Safety Requirements

As hydrogen storage facilities increase in size and capacity, it may be necessary to evaluate codes and standards that regulate hydrogen, especially in relation to allowable aggregate quantities. Existing regulations for other substances with comparable hazards such as oxygen, natural gas, and petroleum were reviewed; most fuels do not have aggregate quantity limits despite sometimes having individual tank capacity restrictions or limits for certain non-industrial, indoor, or small-scale applications. This precedent suggests that specifying a hydrogen quantity limit may not be necessary. Several possible methods for identifying an appropriate limit are presented to illustrate different approaches for a limit basis. These methods are based on overall risk, or the specific consequences inflicted by a jet fire or an explosion on people and infrastructure. However, these example metrics tend to require assumptions about potential leak sizes, suggesting that a general aggregate quantity limit would be difficult to justify without more system-specific requirements.

08 HYDROGEN↗

Flat H Frangible Joint Evolution

Space vehicle staging and separation events require pyrotechnic devices. They are single-use mechanisms that cannot be tested, nor can failure-tolerant performance be demonstrated in actual flight articles prior to flight use. This necessitates the implementation of a robust design and test approach coupled with a fully redundant, failure-tolerant explosive mechanism to ensure that the system functions even in the event of a single failure. Historically, NASA has followed the single failure-tolerant (SFT) design philosophy for all human-rated spacecraft, including the Space Shuttle Program. Following the end of this program, aerospace companies proposed building the next generation human-rated vehicles with off-the-shelf, non-redundant, zero-failure-tolerant (ZFT) separation systems. Currently, spacecraft and launch vehicle providers for both the Orion and Commercial Crew Programs (CCPs) plan to deviate from the heritage safety approach and NASA's SFT human rating requirements. Both programs' partners have base-lined ZFT frangible joints for vehicle staging and fairing separation. These joints are commercially available from pyrotechnic vendors. Non-human-rated missions have flown them numerous times. The joints are relatively easy to integrate structurally within the spacecraft. In addition, the separation event is debris free, and the resultant pyro shock is lower than that of other design solutions. It is, however, a serious deficiency to lack failure tolerance. When used for critical applications on human-rated vehicles, a single failure could potentially lead to loss of crew (LOC) or loss of mission (LOM)). The Engineering and Safety & Mission Assurance directorates within the NASA Johnson Space Center took action to address this safety issue by initiating a project to develop a fully redundant, SFT frangible joint design, known as the Flat H. Critical to the ability to retrofit on launch vehicles being developed, the SFT mechanisms must fit within the same three-dimensional envelope as current designs as well as meet structural loads requirements. There is increased mass associated with the redundant design, and the goal is to minimize the weight impact as much as possible. These requirements presented significant challenges, both technically and financially; these challenges will be explored in this paper. Perhaps greater than the technical issues confronted during this design process, were the financial considerations. These were a significant part of the story of this design and development plan. Insufficient financial and labor resources were formidable barriers to completing this project. Nevertheless, JSC personnel successfully conducted several test series at JSC with very useful results. The many lessons learned drove design improvements, performance efficiency, and increased functional reliability. This paper examines the significant technical and financial challenges that these requirements posed to the project team. It discusses the evolution of the SFT frangible joint design, including optimization, testing, and successful partnering of the Johnson Space Center (JSC) engineering and JSC safety organizations, to enhance the flight safety margin for America's next generation of human-rated space vehicles.

Diegelman, Thomas E.↗

The 2019 Raikoke volcanic eruption -Part 2: Particle-phase dispersion and concurrent wildfire smoke emissions

Between 27 June and 14 July 2019 aerosol layers were observed by the United Kingdom (UK) Raman lidar network in the upper troposphere and lower stratosphere. The arrival of these aerosol layers in late June caused some concern within the London Volcanic Ash Advisory Centre (VAAC) as according to dispersion simulations the volcanic plume from the 21 June 2019 eruption of Raikoke was not expected over the UK until early July. Using dispersion simulations from the Met Office Numerical Atmospheric-dispersion Modelling Environment (NAME), and supporting evidence from satellite and in situ aircraft observations, we show that the early arrival of the stratospheric layers was not due to aerosols from the explosive eruption of the Raikoke volcano but due to biomass burning smoke aerosols associated with intense forest fires in Alberta, Canada, that occurred 4 d prior to the Raikoke eruption. We use the observations and model simulations to describe the dispersion of both the volcanic and forest fire aerosol clouds and estimate that the initial Raikoke ash aerosol cloud contained around 15 Tg of volcanic ash and that the forest fires produced around 0.2 Tg of biomass burning aerosol. The operational monitoring of volcanic aerosol clouds is a vital capability in terms of aviation safety and the synergy of NAME dispersion simulations, and lidar data with depolarising capabilities allowed scientists at the Met Office to interpret the various aerosol layers over the UK and attribute the material to their sources. The use of NAME allowed the identification of the observed stratospheric layers that reached the UK on 27 June as biomass burning aerosol, characterised by a particle linear depolarisation ratio of 9 %, whereas with the lidar alone the latter could have been identified as the early arrival of a volcanic ash–sulfate mixed aerosol cloud. In the case under study, given the low concentration estimates, the exact identification of the aerosol layers would have made little substantive difference to the decision-making process within the London VAAC. However, our work shows how the use of dispersion modelling together with multiple observation sources enabled us to create a more complete description of atmospheric aerosol loading.

Martin J Osborne↗

Soot formation and radiation in turbulent jet diffusion flames under normal and reduced gravity conditions

Most practical combustion processes, as well as fires and explosions, exhibit some characteristics of turbulent diffusion flames. For hydrocarbon fuels, the presence of soot particles significantly increases the level of radiative heat transfer from flames. In some cases, flame radiation can reach up to 75 percent of the heat release by combustion. Laminar diffusion flame results show that radiation becomes stronger under reduced gravity conditions. Therefore, detailed soot formation and radiation must be included in the flame structure analysis. A study of sooting turbulent diffusion flames under reduced-gravity conditions will not only provide necessary information for such practical issues as spacecraft fire safety, but also develop better understanding of fundamentals for diffusion combustion. In this paper, a summary of the work to date and of future plans is reported.

Ku, Jerry C.↗

Evaluation of the SSRCT engine with a hydrazine as a fuel, phase 1

The performance parameters for the space shuttle reaction control thruster (SSRCT) when the fuel is changed from monomethylhydrazine to hydrazine were predicted. Potential problems are higher chamber wall temperature during steady state operation and explosive events during pulse mode operation. Solutions to the problems are suggested. To conduct the analysis, a more realistic film cooling model was devised which considers that hydrazine based fuels are reactive when used as a film coolant on the walls of the combustion chamber. Hydrazine based fuels can decompose exothermally as a monopropellant and also enter into bipropellant reactions with any excess oxidizer in the combustion chamber. It is concluded that the conversion of the thruster from MMH to hydrazine fuel is feasible but that a number of changes would be required to achieve the same safety margins as the monomethylhydrazine-fueled thruster.

Minton, S. J.↗

Thermal Insulation Strips Conserve Energy

Launching the space shuttle involves an interesting paradox: While the temperatures inside the shuttle s main engines climb higher than 6,000 F hot enough to boil iron for fuel, the engines use liquid hydrogen, the second coldest liquid on Earth after liquid helium. Maintained below 20 K (-423 F), the liquid hydrogen is contained in the shuttle s rust-colored external tank. The external tank also contains liquid oxygen (kept below a somewhat less chilly 90 K or -297 F) that combines with the hydrogen to create an explosive mixture that along with the shuttle s two, powdered aluminum-fueled solid rocket boosters allows the shuttle to escape Earth s gravity. The cryogenic temperatures of the main engines liquid fuel can cause ice, frost, or liquefied air to build up on the external tank and other parts of the numerous launch fueling systems, posing a possible debris risk when the ice breaks off during launch and causing difficulties in the transfer and control of these cryogenic liquid propellants. Keeping the fuel at the necessary ultra-cold temperatures while minimizing ice buildup and other safety hazards, as well as reducing the operational maintenance costs, has required NASA to explore innovative ways for providing superior thermal insulation systems. To address the challenge, the Agency turned to an insulating technology so effective that, even though it is mostly air, a thin sheet can prevent a blowtorch from igniting a match. Aerogels were invented in 1931 and demonstrate properties that make them the most extraordinary insulating materials known; a 1-inch-thick piece of aerogel provides the same insulation as layering 15 panes of glass with air pockets in between. Derived from silica, aluminum oxide, or carbon gels using a supercritical drying process - resulting in a composition of almost 99-percent air - aerogels are the world s lightest solid (among 15 other titles they hold in the Guinness World Records), can float indefinitely on water if treated to be hydrophobic, and can withstand extremely hot temperatures (from 1,100 F to 3,000 F depending on the type of aerogel) down to cryogenic levels, making this "frozen smoke" ideal for use in space. Because of its low weight and ability to withstand temperature extremes, an aerogel was even used as the space-based catcher s mitt to trap comet particles and space dust for NASA s Stardust mission, launched in 1999. All of this remarkable technology s characteristics were ideal for NASA s purposes except one: The aerogels were extremely brittle. Through a long-term partnership between Kennedy Space Center and Aspen Aerogels Inc., of Northborough, Massachusetts, researchers developed a flexible, durable form of aerogel that NASA has since used as cryogenic insulation for space shuttle launch systems. Through Aspen Aerogels, the technology has made oil pipeline insulation, extreme weather clothing, and infrared shielding for combat helicopters.

Source record↗

Prioritizing Uncertainties in Hydrogen Contribution to Risk in Post-Crash Outcomes for Rail

This report presents analysis from Sandia National Laboratories predicting contributions to risk associated with the use of hydrogen technology for rail. Event sequence diagrams are used to describe possible accident scenarios and progressions. Initiating event frequencies and branch event probabilities for each scenario are quantified with uncertainty using distributions fit to Federal Railroad Administration and U.S. Department of Transportation Pipeline and Hazardous Materials Safety Administration data on applicable accidents from 2000 to 2020. Uncertainty is propagated through the event sequence diagram to estimate the frequency and conditional probability of accident end states. The analysis identifies four scenarios with significant contributions to risk from hydrogen that are predicted to occur relatively frequently, which may inform priorities for reducing uncertainty. These scenarios are 1) overpressure events resulting from collisions with hydrogen release due to mechanical damage and delayed ignition, 2) jet fire events resulting from collisions with hydrogen release due to mechanical damage and immediate ignition, 3) jet fires resulting from fire or explosion initiating events involving the hydrogen tank and correct operation of the thermally-activated pressure relief device (TPRD) subsequent to the thermal insult, and 4) pressure burst resulting from fire or explosion initiating events involving the hydrogen tank and failure of the TPRD. Delayed and immediate hydrogen ignition probabilities are identified as being highly uncertain and potential candidates for reducing conservatism in the predicted frequencies for these two scenarios.

08 HYDROGEN↗

Demonstrating damage tolerance of composite airframes

Commercial transport aircraft operating in the United States are certified by the Federal Aviation Authority to be damage tolerant. On 28 April 1988, Aloha Airlines Flight 243, a Boeing 727-200 airplane, suffered an explosive decompression of the fuselage but landed safely. This event provides very strong justification for the damage tolerant design criteria. The likely cause of the explosive decompression was the linkup of numerous small fatigue cracks that initiated at adjacent fastener holes in the lap splice joint at the side of the body. Actually, the design should have limited the damage size to less than two frame spacings (about 40 inches), but this type of 'multi-site damage' was not originally taken into account. This cracking pattern developed only in the high-time airplanes (many flights). After discovery in the fleet, a stringent inspection program using eddy current techniques was inaugurated to discover these cracks before they linked up. Because of concerns about safety and the maintenance burden, the lap-splice joints of these high-time airplanes are being modified to remove cracks and prevent new cracking; newer designs account for 'multi-site damage'.

Poe, Clarence C., Jr.↗

NASA Tech Briefs, August 2003

Topics covered include: Stable, Thermally Conductive Fillers for Bolted Joints; Connecting to Thermocouples with Fewer Lead Wires; Zipper Connectors for Flexible Electronic Circuits; Safety Interlock for Angularly Misdirected Power Tool; Modular, Parallel Pulse-Shaping Filter Architectures; High-Fidelity Piezoelectric Audio Device; Photovoltaic Power Station with Ultracapacitors for Storage; Time Analyzer for Time Synchronization and Monitor of the Deep Space Network; Program for Computing Albedo; Integrated Software for Analyzing Designs of Launch Vehicles; Abstract-Reasoning Software for Coordinating Multiple Agents; Software Searches for Better Spacecraft-Navigation Models; Software for Partly Automated Recognition of Targets; Antistatic Polycarbonate/Copper Oxide Composite; Better VPS Fabrication of Crucibles and Furnace Cartridges; Burn-Resistant, Strong Metal-Matrix Composites; Self-Deployable Spring-Strip Booms; Explosion Welding for Hermetic Containerization; Improved Process for Fabricating Carbon Nanotube Probes; Automated Serial Sectioning for 3D Reconstruction; and Parallel Subconvolution Filtering Architectures.

Source record↗

Linear Aerospike SR-71 Experiment (LASRE): Aerospace Propulsion Hazard Mitigation Systems

A major hazard posed by the propulsion system of hypersonic and space vehicles is the possibility of fire or explosion in the vehicle environment. The hazard is mitigated by minimizing or detecting, in the vehicle environment, the three ingredients essential to producing fire: fuel, oxidizer, and an ignition source. The Linear Aerospike SR-71 Experiment (LASRE) consisted of a linear aerospike rocket engine integrated into one-half of an X-33-like lifting body shape, carried on top of an SR-71 aircraft. Gaseous hydrogen and liquid oxygen were used as propellants. Although LASRE is a one-of-a-kind experimental system, it must be rated for piloted flight, so this test presented a unique challenge. To help meet safety requirements, the following propulsion hazard mitigation systems were incorporated into the experiment: pod inert purge, oxygen sensors, a hydrogen leak detection algorithm, hydrogen sensors, fire detection and pod temperature thermocouples, water misting, and control room displays. These systems are described, and their development discussed. Analyses, ground test, and flight test results are presented, as are findings and lessons learned.

Mizukami, Masashi↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗