Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “source term estimation”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 271 records · Page 15

Enabling Scalable VQE Simulation on Leading HPC Systems

Large-scale simulations of quantum circuits pose significant challenges, especially in the context of quantum chemistry, due to the number of qubits, circuit depth, and the number of circuits needed per problem. High-performance computing (HPC) systems offer massive computational capabilities that could help overcome these obstacles. We developed a high-performance quantum circuit simulator, called NWQ-Sim, and demonstrate its capability to simulate large quantum chemistry problems on NERSC's Perlmutter supercomputer. Integrating NWQ-Sim with XACC, we have executed QPE and VQE algorithms for downfolded quantum chemistry systems at unprecedented scales. Our work demonstrates the potential of leveraging HPC resources to advance quantum chemistry and other applications of near-term quantum devices.

Wang, Meng↗

Update of the Nuclear Criticality Slide Rule: Review of the Estimation of the Number of Fissions

IRSN (France), LLNL (USA) and ORNL (USA) began a long-term collaboration effort in 2015 to update the nuclear criticality Slide Rule (https://ncsp.llnl.gov/analytical-methods/criticality-sliderule) for the emergency response to a nuclear criticality accident. The Slide Rule permits the estimation of neutron and gamma dose rates and integrated doses based upon estimated fission yields, as a function of distance from the fission source, and time after criticality accidents for different critical systems. This paper presents the review of the section “estimation of the number of fissions”, named “fission yield” in the Slide Rule document. This estimation is important because the other information provided by the Slide Rule is directly proportional to the number of fissions. The previous models, based on Hansen and Barbry formulae, will be presented with their associated assumptions and limitations. Then, new proposals will be presented with a comparison to past criticality accidents and experimental data. The new formulae, based on the heat energy equation, cover many types of criticality accidents (solution, dry or low-moderated powder, rods/assemblies in water and dry metal) and require limited information in an emergency situation.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Improved Estimate of Phobos Secular Acceleration from MOLA Observations

We report on new observations of the orbital position of Phobos, and use them to obtain a new and improved estimate of the rate of secular acceleration in longitude due to tidal dissipation within Mars. Phobos is the inner-most natural satellite of Mars, and one of the few natural satellites in the solar system with orbital period shorter than the rotation period of its primary. As a result, any departure from a perfect elastic response by Mars in the tides raised on it by Phobos will cause a transfer of angular momentum from the orbit of Phobos to the spin of Mars. Since its discovery in 1877, Phobos has completed over 145,500 orbits, and has one of the best studied orbits in the solar system, with over 6000 earth-based astrometric observations, and over 300 spacecraft observations. As early as 1945, Sharpless noted that there is a secular acceleration in mean longitude, with rate (1.88 + 0.25) 10(exp -3) degrees per square year. In preparation for the 1989 Russian spacecraft mission to Phobos, considerable work was done compiling past observations, and refining the orbital model. All of the published estimates from that era are in good agreement. A typical solution (Jacobson et al., 1989) yields (1.249 + 0.018) 10(exp -3) degrees per square year. The MOLA instrument on MGS is a laser altimeter, and was designed to measure the topography of Mars. However, it has also been used to make observations of the position of Phobos. In 1998, a direct range measurement was made, which indicated that Phobos was slightly ahead of the predicted position. The MOLA detector views the surface of Mars in a narrow field of view, at 1064 nanometer wavelength, and can detect shadows cast by Phobos on the surface of Mars. We have found 15 such serendipitous shadow transit events over the interval from xx to xx, and all of them show Phobos to be ahead of schedule, and getting progressively farther ahead of the predicted position. In contrast, the cross-track positions are quite close to the predicted values. Assuming that the along-track discrepancy is small enough that we can linearize the corrections, we model the mean orbital longitude as a quadratic function of time, and solve for corrections to the constant, linear, and quadratic terms. The time span of the recent observations is insufficient to properly resolve this issue alone, but when the 127 years of prior observations are added, we find a solution which reduces misfit to the new observations considerably, and makes no significant change to the fit to earlier observations. Our estimate for the secular acceleration term is (1.367 + 0.006) degrees per square year. The corresponding rate of energy dissipation is 3.34 MW. From a geophysical perspective, a more interesting parameter than the secular acceleration itself is the tidal lag angle, or tidal quality factor Q, for Mars. Unfortunately, the limiting error source in that determination is remaining uncertainty in the tidal Love numbers at harmonic degrees 2,3, and even 4. Until those parameters are better constrained, improvement in the orbital model of Phobos will not provide corresponding benefits for understanding the interior of Mars.

Bills, Bruce↗

Quantifying Uncertainties in Nighttime Light Retrievals From Suomi-NPP and NOAA-20 VIIRS Day/Night Band Data

Satellite observations of nighttime lights (NTL) from Suomi-NPP and NOAA-20 VIIRS Day/Night Band data have been widely used to estimate human activities. Long-term changes such as urban development and abrupt short-term changes such as power outages have been monitored from temporal NTL acquired by satellites. While high temporal NTL variation has been found across NTL data of varying temporal scale (e.g., daily, monthly, and annual composites), the sources of measurement error and uncertainty are poorly understood. This paper quantifies the sources of VIIRS-derived NTL uncertainty due to view-illumination geometry, surface Bidirectional Reflectance Distribution Function (BRDF)/albedo, and the effects of snow cover, lunar irradiance, aerosol loading, cloud mask, vegetation, geometry, and ephemeral artifacts (e.g., the Aurora Borealis). Based on this current assessment of NASA Black Marble retrievals (VNP46, Collection V001), we found that angular and atmospheric effects dominate retrieval uncertainty. Errors introduced by upstream data inputs (e.g., a coarser nighttime snow cover flag and misclassification errors in the existing VIIRS nighttime cloud mask) were also found to impact retrieval quality. Despite these challenges, a consistent daily NTL time series record can be routinely generated from top-of-atmosphere VNP46 radiances. Key recommendations include: (1) the use of lunar-BRDF adjusted and atmospherically corrected NTL (i.e., as identified as high-quality retrievals in the VNP46 QA fields), (2) development and improvement to the VIIRS snow cover and cloud masks algorithms to accurately reflect NTL retrieval conditions, (3) characterizing seasonal variations in NTL due to vegetation and snow, (4) reducing geometric effects due to the spatial mismatch of gridded pixel and observation footprint, (5) employing angularly-consistent NTL observations from multiple VIIRS instruments (i.e., Suomi-NPP and NOAA-20) to reduce pixel-based uncertainties and address persistent data gaps, and (6) being mindful of surface-reflected radiance from aurora events at mid-to-high latitudes.

Zhuosen Wang↗

Regional-scale estimates of surface moisture availability and thermal inertia using remote thermal measurements

A review is presented of numerical models which were developed to interpret thermal IR data and to identify the governing parameters and surface energy fluxes recorded in the images. Analytic, predictive, diagnostic and empirical models are described. The limitations of each type of modeling approach are explored in terms of the error sources and inherent constraints due to theoretical or measurement limitations. Sample results of regional-scale soil moisture or evaporation patterns derived from the Heat Capacity Mapping Mission and GOES satellite data through application of the predictive model devised by Carlson (1981) are discussed. The analysis indicates that pattern recognition will probably be highest when data are collected over flat, arid, sparsely vegetated terrain. The soil moisture data then obtained may be accurate to within 10-20 percent.

Carlson, T. N.↗

A radiometric Bode's Law: Predictions for Uranus

The magnetospheres of three planets, Earth, Jupiter, and Saturn, are known to be sources of intense, nonthermal radio bursts. The emissions from these sources undergo pronounced long term intensity fluctuations that are caused by the solar wind interaction with the magnetosphere of each planet. Determinations by spacecraft of the low frequency radio spectra and radiation beam geometry now permit a reliable assessment of the overall efficiency of the solar wind in stimulating these emissions. Earlier estimates of how magnetospheric radio output scales with the solar wind energy input must be revised greatly, with the result that, while the efficiency is much lower than previously thought, it is remarkably uniform from planet to planet. The formulation of a radiometric Bode's Law from which a planet's magnetic moment is estimated from its radio emission output is presented. Applying the radiometric scaling law to Uranus, the low-frequency radio power is likely to be measured by the Voyager 2 spacecraft as it approaches this planet.

Desch, M. D.↗

Large-volume lava flow fields on Venus: Dimensions and morphology

Of all the volcanic features identified in Magellan images, by far the most extensive and really important are lava flow fields. Neglecting the widespread lava plains themselves, practically every C1-MIDR produced so far contains several or many discrete lava flow fields. These range in size from a few hundred square kilometers in area (like those fields associated with small volcanic edifices for example), through all sizes up to several hundred thousand square kilometers in extent (such as many rift related fields). Most of these are related to small, intermediate, or large-scale volcanic edifices, coronae, arachnoids, calderas, fields of small shields, and rift zones. An initial survey of 40 well-defined flow fields with areas greater than 50,000 sq km (an arbitrary bound) has been undertaken. Following Columbia River Basalt terminology, these have been termed great flow fields. This represents a working set of flow fields, chosen to cover a variety of morphologies, sources, locations, and characteristics. The initial survey is intended to highlight representative flow fields, and does not represent a statistical set. For each flow field, the location, total area, flow length, flow widths, estimated flow thicknesses, estimated volumes, topographic slope, altitude, backscatter, emissivity, morphology, and source has been noted. The flow fields range from about 50,000 sq km to over 2,500,000 sq km in area, with most being several hundred square kilometers in extent. Flow lengths measure between 140 and 2840 km, with the majority of flows being several hundred kilometers long. A few basic morphological types have been identified.

Lancaster, M. G.↗

The Arctic Ocean ice balance - A Kalman smoother estimate

The methodology of Kalman filtering and smoothing is used to integrate a 7-year time series of buoy-derived ice motion fields and satellite passive microwave observations. The result is a record of the concentrations of open water, first-year ice, and multiyear ice that we believe is better than the estimates based on the microwave data alone. The Kalman procedure interprets the evolution of the ice cover in terms of advection, melt, growth, ridging, and aging of first-year into multiyear ice. Generally, the regions along the coasts of Alaska and Siberia and the area just north of Fram Strait are sources of first-year ice, with the rest of the Arctic Ocean acting as a sink for first-year ice via ridging and aging. All the Arctic Ocean except for the Beaufort and Chukchi seas is a source of multiyear ice, with the Chukchi being the only internal multiyear ice sink. Export through Fram Strait is a major ice sink, but we find only about two-thirds the export and greater interannual variation than found in previous studies. There is no discernible trend in the area of multiyear ice in the Arctic Ocean during the 7 years.

Thomas, D. R.↗

WBS 1.2.3.405 - Life Cycle Assessment of Storage Technologies

Recent commitments by the Biden administration have established targets to achieve a net-zero energy system by 2050. Meeting these targets will spur a rapid transition to clean energy technologies and a commensurate need to develop and deploy energy storage technologies at scale. Pumped Storage Hydro (PSH) is expected to be part of this solution because its ability to provide grid flexibility and stability and enable the dispatching of disparate variable renewable energy technologies. Despite PSH being a mature technology with a history of deployment dating back several decades, there is very little information on the greenhouse gas (GHG) implications of PSH as compared to other storage technologies. The objective of this project is to perform a full lifecycle assessment (LCA) of new PSH projects in the U.S. This LCA includes all project phases (resource extraction, construction, operation, maintenance, end-of-life). The functional unit for this study is 1 kWh electricity delivered by system to grid substation connection point and the estimated lifetime for our base case is 80 years. Data used in this study are based on over 30 potential PSH projects that are in preliminary planning phases and are represent a wide range of potential closed-loop PSH systems in terms of location, technology, and capacity. The project approach, data sources, and modeling assumptions have been informed by a technical review committee of stakeholders that include experts from academia, national and international government, industry, and utilities. The GHGs and energy return on investment (EROI) from PSH will be compared to other storage technologies (e.g., stationary battery storage). Results from this project will improve the PSH community's understanding of the environmental impacts and sustainability of new PSH projects and how PSH compares to other storage technologies. The approach used in this project relies on open-source programming. The analysis framework (source code and data) and will be made publicly available at the end of the project. In addition to reporting results for the base case, we will perform rigorous sensitivity analysis to identify the major drivers, understand impacts of different configurations, and future energy markets. Results from this project will be published in a suitable journal.

ENERGY PLANNING, POLICY, AND ECONOMY,HYDRO ENERGY↗

Extrapolation of the Rainflow-Counted Load Ranges for Fatigue Assessment of the Wind Turbine's Blades

Wind turbine design standards recommend the use of statistical modeling coupled with extrapolation of the short-term load data to long-term periods for fatigue reliability assessment. However, statistical error and computational expense can limit the accuracy of such approaches. In the case of wind turbine blades, the errors are more significant because of the high material fatigue exponent that makes the damage estimations more sensitive to variations. In addition, due to different excitation sources, the flapwise load range histogram is not unimodal, and thus its statistical modeling is complex. In the present work, we provide three methods for statistical modeling of the flapwise bending moment ranges including a novel approach based on frequency-based separation of the modes. The first two methods are simplified approaches for modeling the most crucial load ranges using unimodal distributions and the third method involves multimodal distribution fitting. The research is based on 3600 10-minute aeroelastic simulations of DTU 10MW case study wind turbine from which a benchmark damage equivalent load (DEL) is calculated. The DEL calculated by each of the three proposed methods is compared to this reference. The results show that the conventional approach based on using 6 seeds as well as using mixture models fitted on the limited data lead to under-conservative results with errors up to 23%. On the other hand, the simplified unimodal approaches provided in this work can provide conservative estimations of the fatigue damage with mean values 5% and 12% higher than the benchmark. However, the variability of the DEL estimates is higher when using unimodal extrapolation of the load ranges, and the data can be conservative by 17.5%. The proposed unimodal fits suggested for modeling and extrapolation of the blade's load ranges provide less errors relatively and most importantly conservative DEL estimations while maintaining computational efficiency.

blade fatigue↗

Velocity dispersions in galaxies. IV - The nucleus of NGC 1068

A high-resolution spectrum of the Seyfert galaxy NGC 1068, obtained with an integrating television system, is compared with the spectrum of a KO III star (delta Tau) to derive the line-of-sight velocity dispersion of the stars in the galactic nucleus. An Fe I absorption line observed at 4059.7 A yields a velocity dispersion of 150 (plus or minus 50) km/sec. An upper limit for the nuclear mass is derived in terms of this velocity dispersion, an estimated nuclear radius of 136 pc, and a Hubble constant of 50 km/sec per Mpc. The results, 14 (+10, -8) by 10 to the 8th power solar masses, is shown to be consistent with a number of quasar models scaled down in luminosity to provide the energy source for a Seyfert nucleus. Strong H and K interstellar absorption lines superposed on the spectrum of NGC 1068 are analyzed.-

Richstone, D. O.↗

Multi-tracer intensity mapping: cross-correlations, line noise & decorrelation

Line intensity mapping (LIM) is a rapidly emerging technique for constraining cosmology and galaxy formation using multi-frequency, low angular resolution maps. Many LIM applications crucially rely on cross-correlations of two line intensity maps, or of intensity maps with galaxy surveys or galaxy/CMB lensing. We present a consistent halo model to predict all these cross-correlations and enable joint analyses, in 3D redshift-space and for 2D projected maps. We extend the conditional luminosity function formalism to the multi-line case, to consistently account for correlated scatter between multiple galaxy line luminosities. This allows us to model the scale-dependent decorrelation between two line intensity maps, a key input for foreground rejection and for approaches that estimate auto-spectra from cross-spectra. This also enables LIM cross-correlations to reveal astrophysical properties of the interstellar medium inacessible with LIM auto-spectra. We expose the different sources of luminosity scatter or "line noise" in LIM, and clarify their effects on the 1-halo and galaxy shot noise terms. In particular, we show that the effective number density of halos can in some cases exceed that of galaxies, counterintuitively. Using observational and simulation input, we implement this halo model for the Hα, [Oiii], Lyman-α, CO and [Cii] lines. Here, we encourage observers and simulators to measure galaxy luminosity correlation coefficients for pairs of lines whenever possible. Our code is publicly available at https://github.com/EmmanuelSchaan/HaloGen/tree/LIM. In a companion paper, we use this halo model formalism and code to highlight the degeneracies between cosmology and astrophysics in LIM, and to compare the LIM observables to galaxy detection for a number of surveys.

79 ASTRONOMY AND ASTROPHYSICS↗

Using an Atom Interferometer to Infer Gravitational Entanglement Generation

If gravitational perturbations are quantized into gravitons in analogy with the electromagnetic field and photons, the resulting graviton interactions should lead to an entangling interaction between massive objects. We suggest a test of this prediction. To do this, we introduce the concept of interactive quantum information sensing. This novel sensing protocol is tailored to provable verification of weak dynamical entanglement generation between a pair of systems. We show that this protocol is highly robust to typical thermal noise sources. The sensitivity can moreover be increased both using an initial thermal state and/or an initial phase of entangling via a non-gravitational interaction. We outline a concrete implementation testing the ability of the gravitational field to generate entanglement between an atomic interferometer and mechanical oscillator. Preliminary numerical estimates suggest that near-term devices could feasibly be used to perform the experiment.

72 PHYSICS OF ELEMENTARY PARTICLES AND FIELDS↗

The Energy Budget of the Polar Atmosphere in MERRA

Components of the atmospheric energy budget from the Modern Era Retrospective-analysis for Research and Applications (MERRA) are evaluated in polar regions for the period 1979-2005 and compared with previous estimates, in situ observations, and contemporary reanalyses. Closure of the energy budget is reflected by the analysis increments term, which results from virtual enthalpy and latent heating contributions and averages -11 W/sq m over the north polar cap and -22 W/sq m over the south polar cap. Total energy tendency and energy convergence terms from MERRA agree closely with previous study for northern high latitudes but convergence exceeds previous estimates for the south polar cap by 46 percent. Discrepancies with the Southern Hemisphere transport are largest in autumn and may be related to differences in topography with earlier reanalyses. For the Arctic, differences between MERRA and other sources in TOA and surface radiative fluxes maximize in May. These differences are concurrent with the largest discrepancies between MERRA parameterized and observed surface albedo. For May, in situ observations of the upwelling shortwave flux in the Arctic are 80 W/sq m larger than MERRA, while the MERRA downwelling longwave flux is underestimated by 12 W/sq m throughout the year. Over grounded ice sheets, the annual mean net surface energy flux in MERRA is erroneously non-zero. Contemporary reanalyses from the Climate Forecast Center (CFSR) and the Interim Re-Analyses of the European Centre for Medium Range Weather Forecasts (ERA-I) are found to have better surface parameterizations, however these collections are also found to have significant discrepancies with observed surface and TOA energy fluxes. Discrepancies among available reanalyses underscore the challenge of reproducing credible estimates of the atmospheric energy budget in polar regions.

Cullather, Richard I.↗

Aircraft System Noise of the NASA D8 Subsonic Transport Concept

A vehicle-level noise assessment has been performed for the NASA D8 (ND8) concept aircraft in the NASA Advanced Air Transport Technology Project portfolio. The NASA research-level Aircraft Noise Prediction Program was used to predict the noise from each source component on the ND8 to build up a noise estimate for the full aircraft. The propulsion airframe aeroacoustic effects of the ND8 (namely, boundary-layer ingestion, with its influence on fan noise; and the noise shielding, reflection, and diffraction mechanisms of the unconventional airframe) were empirically modeled using experimental data. Far-term noise reduction technology concepts were modeled and added to the noise prediction to evaluate the low-noise potential of the ND8 in the far-term timeframe. Results indicate that the increase in fan noise due to boundary-layer ingestion, as well as the lack of aft shielding, prevents the aircraft from approaching NASA’s noise goals for either the midterm or far term. The aircraft achieves margins to Stage 4 of only 9.4 and 17.3 effective perceived noise in decibels (EPNdB) in the midterm and far-term configurations, respectively, compared with goals of 32–42 EPNdB in the midterm and 42-52 EPNdB in the far term.

aircraft system noise↗

Baseline Vector Repeatability at the Sub-Millimeter Level Enabled by Radio Interferometer Phase Delays of Intra-Site Baselines

We report the results of position ties for short baselines at eight geodetic sites based on phase delays that are extracted from global geodetic very-long-baseline interferometry (VLBI) observations rather than dedicated short-baseline experiments. An analysis of phase delay observables at X band from two antennas at the Geodetic Observatory Wettzell, Germany, extracted from 107 global 24-hr VLBI sessions since 2019 yields weighted root-mean-square scatters about the mean baseline vector of 0.3, 0.3, and 0.8 mm in the east, north, and up directions, respectively. Position ties are also obtained for other short baselines between legacy antennas and nearby, newly built antennas. They are critical for maintaining a consistent continuation of the realization of the terrestrial reference frame, especially when including the new VGOS network. The phase delays of the baseline WETTZ13N–WETTZELL enable an investigation of sources of error at the sub-millimeter level. We found that a systematic variation of larger than 1 mm can be introduced to the Up estimates of this baseline vector when atmospheric delays were estimated. Although the sub-millimeter repeatability has been achieved for the baseline vector WETTZ13N–WETTZELL, we conclude that long term monitoring should be conducted for more short baselines to assess the instrumental effects, in particular the systematic differences between phase delays and group delays, and to find common solutions for reducing them. This will be an important step toward the goal of global geodesy at the 1 mm level.

geodetic VLBI↗

Techno-Economic Analysis of Lithium Extraction from Geothermal Brines

The United States has a large, domestic source of lithium in geothermal fluids, especially at the Salton Sea region of southern California, where estimates of lithium pass-through at geothermal plants exceed 24,000 metric tons per year, based on 2019 geothermal plant operations. Lithium extraction from geothermal brines offers the potential to provide the United States with a secure, domestic supply of lithium to meet the increasing demands of electric vehicles, grid energy storage, portable electronics, and other end-use applications. Additionally, the use of direct extraction technologies allows for a more sustainable lithium supply relative to current evaporative brine and hardrock mining operations in terms of land use, water use, time to market with lithium products, and carbon intensity of operations. This report is part of an effort to assess geothermal brines as a source of commercial lithium supply for the United States. In this study, the National Renewable Energy Laboratory (NREL) reviews and summarizes public technoeconomic analyses of lithium extraction technologies. The work was coordinated with the Critical Minerals Institute at the Colorado School of Mines who focused on supply chain analysis of lithium.

15 GEOTHERMAL ENERGY↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗