Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Analyses”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Cryo-GCMS Outgassing Screening: Thermal Filler Materials

A study was conducted to investigate the outgassing characteristics of four thermal filler materials. The purpose of this screening was to identify any outgassing products that might be considered reactive, specifically compounds that could result in corrosion in the systems where these materials are used. A range of compounds was observed in the sample headspaces, though most do not stand out as being known reactive species of concern. However, several halogenated compounds and sulfurous compounds- classes compounds known to facilitate corrosion reactions under certain conditions- were observed in low concentrations. The TFLEX 760 exhibited the highest total outgassing, while the GR130 had the lowest. Therm-a-Gap75 and the Si thermal grease exhibited very similar outgassing profiles. It is difficult to predict the extent to which any given compound observed in an analysis of this type might pose a risk in an actual system; factors such as temperature, system geometry, concentration, and gas conductance all play a role in the kinetics governing chemical reactions. It is recommended that the results of these analyses are shared with pertinent materials SMEs familiar with the system(s) in question to evaluate potential risks.

36 MATERIALS SCIENCE↗

Risk of natural environment changes after Space Shuttle deorbit decision

The purpose of the present paper is to point out the risk of change of certain natural environment events that may be of concern in Space Shuttle landing analyses and deorbit decisions. These events are: precipitation, except light rain showers; thunderstorms with ceilings below 4000 ft; runway crosswinds above 20 knots peak at 33 ft; and thunderstorms in the descending glide path. Risk calculations showed that for deorbit decisions made one hour before landing, the maximum risk of change from favorable to unfavorable natural environment conditions is approximately 12 percent, the risk existing for only a few hours in midafternoon. Thunderstorms in the glide path account for more than three fourths of the total risk.

Brown, S. C.↗

How Can We Efficiently Build A Spacecraft That Has Longevity? Experiences From the GSFC Perspective to Inform Lunar Exploration and Science Orbiter’s Architecture

Recent successes in NASA planetary science missions has shown that long-lived missions can yield significant science return. These missions, despite their longevity, were not planned to operate beyond their deign life. For example, the Lunar Reconnaissance Orbiter has a design life of 2-3 years, and yet we are entering its 14th year on orbit. Spacecraft longevity in practice has been related to: 1) mission class; 2) did we test it long enough and resolve all the anomalies to be beyond the early failure curve; 3) consumables budgets, and 4) how components are de-signed and tested. Mission class has been perceived as one of the primary ways to drive longevity. But higher mission class is a significant cost and mission driver. Parts selection only from the limited military standard parts and extensive parts qualification adds to development time and cost. Largely redundant (often erroneously interpreted as fully redundant) adds to launch mass and increases testing complexity (which may reduce the amount of testing in the nominal con-figuration). Lower Risk Posture (reflected in a higher mission class) drives significant additional processes and quality assurance analyses. Higher mission class also drives significantly greater sparing and life testing costs. This discussion focuses on whether this is indeed the best way to achieve longevity efficiently or whether there are more efficient ways to achieve longevity. Empirical evidence shows that lower mission classes that implement effective risk reduction and selective redundancy generally results in long life at a lower Spacecraft bus cost. By evaluating redundancy careful-ly, spacecraft cost can be lowered which can enable a more capable payload. Risk of the mission is highly dependent on the complexity of the mission and is only loosely dependent on Class of Mission. High complexity missions can have many single point failures and require the development of new technology, while lower class mission can have lower risk by baselining or incorporating: (selective) redundancy, fault-tolerant design, design for minimum risk, ability to reset, and/or design for graceful degradation. The team met with Goddard Space Flight Center Space Systems Mission Operations leaders to discuss which avionics have proven in flight to be the most reliable and which have had lifetime issues. The paper proposes a list of components to focus on for redundancy for a long-lived lunar mission. Reliability numbers are presented for both single string and dual string missions. The history of life-time performance versus planned mission life according to mission class is presented. A mission with well thought out selective redundancy and effective on the ground test program, can be expected to last well beyond its mission lifetime and provided enhanced return for the community. This approach minimizes project expenditures that do not retire significant risk and allows the project to focus risk mitigation efforts on those risks that will have a significant likelihood of threatening mission success. This is aided by keeping the amount of technology maturation and mission complexity low, while focusing effort on ensuring all component stress-ing parameters well within the bounds of their capabilities.

Lessons Learned↗

Mass and power modeling of communication satellites

Analytic estimating relationships for the mass and power requirements for major satellite subsystems are described. The model for each subsystem is keyed to the performance drivers and system requirements that influence their selection and use. Guidelines are also given for choosing among alternative technologies which accounts for other significant variables such as cost, risk, schedule, operations, heritage, and life requirements. These models are intended for application to first order systems analyses, where resources do not warrant detailed development of a communications system scenario. Given this ground rule, the models are simplified to 'smoothed' representation of reality. Therefore, the user is cautioned that cost, schedule, and risk may be significantly impacted where interpolations are sufficiently different from existing hardware as to warrant development of new devices.

Price, Kent M.↗

Analysis of the Honeywell Uncertified Research Engine (HURE) with Ice Crystal Cloud Ingestion at Simulated Altitudes: Public Version

The Honeywell Uncertified Research Engine (HURE), a research version of a turbofan engine that never entered production, was tested in the NASA Propulsion System Laboratory (PSL), an altitude test facility at the NASA Glenn Research Center. The PSL is a facility that is equipped with water spray bars capable of producing an ice cloud consisting of ice particles, having a controlled particle diameter and concentration in the air flow. In preparation for testing of the HURE, numerical analysis of flow and ice particle thermodynamics was performed on the compression system of the turbofan engine to predict operating conditions that could potentially result in a risk of ice accretion due to ice crystal ingestion. The results of those analyses formed the basis of the test matrix. The goal of the test matrix was to have ice accrete in two regions of the compression system: region one, which consists of the fan-stator through the inlet guide vane (IGV), and region two which is the first stator within the high pressure compressor. The predictive analyses were performed with the mean line compressor flow modeling code (COMDES-MELT) which includes an ice particle model. Together these comprise a one-dimensional icing tool. The HURE engine was tested in PSL with the ice cloud over the range of operating conditions of altitude, ambient temperature, simulated flight Mach number, and fan speed with guidance from the analytical predictions. The engine was fitted with video cameras at strategic locations within the engine compression system flow path where ice was predicted to accrete, in order to visually confirm ice accretion when it occurred. In addition, traditional compressor instrumentation such as total pressure and temperature probes, static pressure taps, and metal temperature thermocouples were installed in targeted areas where the risk of ice accretion was expected. The current research focuses on the analysis of the data that was obtained after testing the HURE engine in PSL with ice crystal ingestion. The computational method was enhanced by computing key parameters through the fan-stator at multiple spanwise locations, in order to increase the fidelity with the current mean-line method. In addition, other sources of heat (non-adiabatic walls) were suspected to be the cause of accretion near the splitter-lip and shroud. Since there were no thermocouples near the splitter, a simple order of magnitude heat transfer model was implemented to estimate the wall temperature. Future analyses will require a higher fidelity thermal analysis of the compression system metal walls to accurately calculate the total heat flux to the ice particle. For many data points analyzed, there were differences between the thermodynamic system model and the measured test data that may partially be responsible for uncertainties with the results of the current analyses.

Turbomachinery↗

Rocket engine system reliability analyses using probabilistic and fuzzy logic techniques

The reliability of rocket engine systems was analyzed by using probabilistic and fuzzy logic techniques. Fault trees were developed for integrated modular engine (IME) and discrete engine systems, and then were used with the two techniques to quantify reliability. The IRRAS (Integrated Reliability and Risk Analysis System) computer code, developed for the U.S. Nuclear Regulatory Commission, was used for the probabilistic analyses, and FUZZYFTA (Fuzzy Fault Tree Analysis), a code developed at NASA Lewis Research Center, was used for the fuzzy logic analyses. Although both techniques provided estimates of the reliability of the IME and discrete systems, probabilistic techniques emphasized uncertainty resulting from randomness in the system whereas fuzzy logic techniques emphasized uncertainty resulting from vagueness in the system. Because uncertainty can have both random and vague components, both techniques were found to be useful tools in the analysis of rocket engine system reliability.

Hardy, Terry L.↗

Optimizing Information Automation Using a New Method Based on System-Theoretic Process Analysis: Tool Development and Method Evaluation

This report is an update to a prior report that describes progress and findings for a program of research supporting the design and optimization of information automation systems for nuclear power plants. Much of the domestic nuclear fleet is currently focused on modernizing technologies and processes, including transitioning toward digitalization in the control room and throughout the plant, along with a greater interest in the use of automation, artificial intelligence, robotics, and other emerging technologies. While there are significant opportunities to apply these technologies toward greater plant safety, efficiency, and overall cost-effectiveness, optimizing their design and avoiding potential safety and performance risks depends on ensuring that human performance-related organizational and technical design issues are identified and addressed early in the design process. This report describes modeling tools and techniques, based on sociotechnical systems theory, to support these design goals and their application in the current research effort. The report is primarily intended for senior nuclear energy stakeholders, including regulators, corporate management, and senior plant management. We have developed and employed a method to design an optimized information automation ecosystem (IAE) based on the systems-theoretic constructs underlying sociotechnical systems theory in general and the Systems-Theoretic Accident Modeling and Processes (STAMP) approach in particular. We argue that an IAE can be modeled as an interactive information control system whose behavior can be understood in terms of dynamic control, feedback, and communication relationships amongst the system’s technical and organizational components. We have employed two STAMP-based tools in this effort. The first is Causal Analysis based on STAMP (CAST), an accident and incident analysis technique that was used to examine a performance- and safety-related incident at an industry partner’s plant involving the unintentional activation of an emergency diesel generator. This analysis provided insight into the behavior of the plant’s current information control structure within the context of a specific, significant event. The second tool is Systems Theoretic Process Analysis (STPA) which is a proactive risk analysis tool used to examine existing and potential, planned sociotechnical systems. STPA was used to identify risk factors in the current design of a generic nuclear power plant (NPP) preventive maintenance system. Our analyses focused on identifying near-term system improvements and longer-term design requirements for an optimized IAE system. CAST analysis findings indicate an important underlying contributor to the incident under investigation, and a significant risk to information automation system performance, was perceived time and schedule pressure, which exposed weaknesses in interdepartmental coordination between and within responsible plant organizations and challenged the resilience of established plant processes, until a human caused the eventual event. These findings are discussed in terms of their risk to overall system performance and their implications for information automation system resilience and brittleness. STPA findings exposed several areas of concern in the design of current preventive maintenance systems. We also present two preliminary information automation models. The proactive issue resolution (PIR) model is a test case of an information automation concept with significant near-term potential for application and subsequent reduction in significant plant events. The IAE model is a more general representation of a broader, plantwide information automation system and represents an end-state vision for our work. From our results, we have generated an initial set of preliminary system-level requirements and safety constraints for these models. We have also focused on early development of easy to learn, easy to use “transportable” tools for sociotechnical systems analysis. We intend these to be used by NPP personnel as a means of gaining reliable and relatively quick insight into (1) sociotechnical systems factors impacting incidents and accidents, (2) potential sociotechnical risk factors in existing or planned system designs, and (3) potential weaknesses in a system’s safety and/or information control structure. We conclude the report with a set of summary recommendations, a discussion of planned and potential follow-on research and development, and a draft list of system-level requirements and safety constraints for optimized information automation systems.

99 GENERAL AND MISCELLANEOUS↗

Spacecraft survivability in the meteoroid and debris environment

A number of methods for providing adequate protection from meteoroid and orbital debris impact are available to space vehicle designers. Several techniques to reduce the risks from meteoroid and debris (M&D) impact are presented and assessed in the context of Space Station Freedom (SSF) applications. Evaluations of these options were made using BUMPER, a computer program to perform M&D analyses. M&D survivability can be improved by conducting an in-depth analysis of spacecraft penetration risks to reveal weak areas of the design and to determine optimal distribution of shielding and/or protection capability around the space vehicle. This paper compares enhanced hypervelocity impact shielding techniques that are more weight efficient than conventional shielding approaches. Other design and operational strategies to reduce meteoroid and debris risks are also discussed.

Christiansen, Eric L.↗

Application of Constellation's best estimate alternate source term methodology

Safety analyses for a nuclear power plants need to consider postulated accidents that results in a risk of accidental release of radiation. The regulations require plant specific safety analysis reports to include an evaluation of the requirements of 10CFR50.67. Such a safety analysis report mandates limits such that calculated radiological consequences at certain locations do not exceed established limits in 10CFR50.67 following a postulated release of radioactivity. Analyses should demonstrate, with reasonable assurance, that these prescribed limits are complied with. Conventional methodologies utilize conservative approaches to address lack of uncertainty quantification in the utilized approaches, methods, and/or inputs. These built-in excess conservatisms often result in with compounding effects and hence overly conservative results in the estimated radiological consequences, which leads to inaccurate margin evaluation for operation and accident mitigation. Therefore, evaluating accurate dose consequences is needed for both operational and safety reasons. This paper illustrates the use of the best estimate source term (BEAST) methodology to the case of the loss of coolant accident (LOCA) dose analysis.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Modeling Logistics and Supportability for Crewed Missions Beyond Low Earth Orbit

NASA’s future missions aim to establish a sustained human presence on the lunar surface and send humans to Mars. These missions will send crews farther from home than previous missions, limiting the opportunities for resupply missions. Additionally, the use of multiple launches and reusable elements will increase mission and campaign complexity. Logistics and supportability analysis evaluates the link between mission and system characteristics and key metrics such as logistics and spares mass and volume, crew time, and risk. As missions become increasingly complex and crews are logistically isolated for longer periods of time, logistics and supportability will become more powerful drivers of risk and cost and, therefore, more important considerations during system and mission development. When logistics and supportability are considered from the beginning of system and mission development, opportunities arise to create more efficient, lower-risk systems. Design choices made without detailed consideration of logistics and supportability have the potential to result in greater risks and increased costs as all options may not have been analyzed. This paper provides an overview of a methodology used for space mission logistics and supportability analysis, including key metrics, assumptions, and required inputs. Example applications of this methodology to explore the impacts of system architecture, dormancy, and synergies between lunar and Mars missions are also presented. Conducting these holistic analyses enables informed decision-making for mission planning and system design, which can help mitigate the risk of loss of mission, vehicle, or crew. Using the knowledge of historical missions, experiences gained on the lunar surface, and logistics and supportability analyses, NASA can examine and optimize supportability characteristics for safer and more effective operations for future lunar and Mars missions.

Supportability↗

Modeling Logistics and Supportability for Crewed Missions Beyond Low Earth Orbit

NASA’s future missions aim to establish a sustained human presence on the lunar surface and send humans to Mars. These missions will send crews farther from home than previous missions, limiting the opportunities for resupply missions. Additionally, the use of multiple launches and reusable elements will increase mission and campaign complexity. Logistics and supportability analysis evaluates the link between mission and system characteristics and key metrics such as logistics and spares mass and volume, crew time, and risk. As missions become increasingly complex and crews are logistically isolated for longer periods of time, logistics and supportability will become more powerful drivers of risk and cost and, therefore, more important considerations during system and mission development. When logistics and supportability are considered from the beginning of system and mission development, opportunities arise to create more efficient, lower-risk systems. Design choices made without detailed consideration of logistics and supportability have the potential to result in greater risks and increased costs as all options may not have been analyzed. This paper provides an overview of a methodology used for space mission logistics and supportability analysis, including key metrics, assumptions, and required inputs. Example applications of this methodology to explore the impacts of system architecture, dormancy, and synergies between lunar and Mars missions are also presented. Conducting these holistic analyses enables informed decision-making for mission planning and system design, which can help mitigate the risk of loss of mission, vehicle, or crew. Using the knowledge of historical missions, experiences gained on the lunar surface, and logistics and supportability analyses, NASA can examine and optimize supportability characteristics for safer and more effective operations for future lunar and Mars missions.

Supportability↗

Advancing process-based flood frequency analysis for assessing flood hazard and population flood exposure

Recent studies have showcased the use of process-based hydrological models with Stochastic Storm Transposition (SST) techniques to conduct Flood Frequency Analysis (FFA). This framework, referred hereby FFA-SST, has proved to be a robust strategy to estimate peak flows of specific annual exceedance probability (e.g., 100-year peak flow) that can reflect natural and anthropogenic disturbances, including changes in land use and meteorological patterns. With the objective of advancing the FFA-SST framework, this study presents for the first time the use of an Integrated Surface-Subsurface Hydrological Model (ISSHM) to conduct FFA-SST by extending the analysis from peak flow responses to flood extent, enabling a unique view and analysis of flood hazard and population flood exposure at the basin scale. As a proof-of-concept, we used the ISSHM, Advanced Terrestrial Simulator (Amanzi-ATS) model, and the SST model, RainyDay, to conduct FFA-SST by simulating the flood response to 5,000 annual synthetic storm events in a 2,227 $km^2$ Southeast Texas watershed. We demonstrate that ATS, without site-specific calibration, provides a robust process-based representation of peak flows, flood extent, streamflow, evapotranspiration, soil moisture content, and water storage changes. Our results and analyses, covering frequency curves up to a 500-year return period for peak flows, basin inundation fractions, and the number of people exposed to flooding, offer a unique perspective to analyze flood impacts across spatial scales. Overall, this study provides critical insights for flood risk management by extending the FFA-SST framework to include both flood hazard and population flood exposure analyses at the basin scale. Such an approach will empower stakeholders and disaster emergency agencies with a more comprehensive understanding of flood impacts across the entire basin domain, facilitating informed decision-making for flood risk assessment and management.

58 GEOSCIENCES↗

Species Transport Framework Development in SAM for System-Level Tritium Source Term Analysis

The SAM code is under development as a modern system-level modeling and simulation tool for advanced non–light water reactor safety analyses, with recent efforts to add capabilities to evaluate radiological source term risks in these novel reactor concepts. By leveraging the established system-level multiphysics thermal-hydraulic models in SAM, a framework for tightly coupled species transport modeling has been integrated into the code for engineering-scale source term evaluation. This species transport framework was first applied to the simulation of tritium, which is a well-known source term in conventional light water reactors. Tritium poses a unique risk in salt-cooled reactors, especially those with lithium-bearing salts such as the fluoride salt–cooled high-temperature reactor (FHR) concept, as tritium is generated in the salt coolant in significant quantities due to neutron interactions. A compounding factor is the increased mobility of tritium at high temperatures, which is able to permeate through metals while also potentially being retained in graphite pebbles and structures. Engineering-scale models for the tritium transport pathways in a FHR have been developed using the new species transport framework in SAM. The capabilities are assessed through analytical verification problems and validated with data from a graphite retention experiment. In conclusion, the system-level model is demonstrated by performing an initial estimate of baseline tritium generation and flows in a generic reference SAM FHR model, setting a foundation for future studies of source term transient analysis with the potential for further multiscale and multiphysics integration.

SAM↗

AUTOMATIC GENERATION OF EVENT TREES AND FAULT TREES: A MODEL-BASED APPROACH

In the past few decades, increasing complexity in modern engineering systems has been driven by the integration of a large number of components and by the fact that the system operations involve many disciplines (e.g., thermal-hydraulics, plant operations, cyber-security). Current safety/reliability modeling approaches to such systems are labor intensive, difficult to learn, and rely heavily on simplistic Boolean logic to depict failure propagation and accident progression. While these methods serve well for simple systems (i.e., linear causal systems with limited small inter- and intra-system interactions), their results are difficult to verify when modeling complex systems (typically performed through the extensive use of modeling assumptions). The development of new methods is addressed to meet these challenges through a model-based system engineering (MBSE) lens. Under MBSE philosophy, every aspect of the system (form or function) is represented by a model that completely characterizes its architecture or behavior. MBSE approach greatly improves the management of design, analysis and verification of complex systems. An integration of Dynamic Probabilistic Risk Assessment (DPRA) methods with MBSE models is proposed to perform safety/reliability analyses of engineering systems. In particular, MBSE representation of the system (performed using Systems Modeling Language [SysML]) is coupled with DPRA methods to automatically generate event trees and fault trees.

97 - MATHEMATICS AND COMPUTING↗

Failure Analysis–Informed Risk Assessment Framework for Geological Carbon Storage Using Numerical Simulation and Machine Learning

Geological carbon storage (GCS) is recognized as a critical technology for achieving large-scale reductions in anthropogenic carbon dioxide (CO 2 ) emissions. Ensuring long-term containment and safety requires robust risk assessment frameworks that account for geological uncertainty and identify potential failure scenarios. Among various indicators, the area of review (AoR) serves as a key metric for evaluating storage performance, regulatory compliance, and monitoring design, as it delineates the spatial extent impacted by pressure buildup and plume migration. However, conventional AoR-based risk assessments typically perturb parameters within narrow uncertainty bounds, potentially overlooking rare but high-impact events arising from extreme geological conditions. In this study, we present a failure analysis–informed risk assessment framework for large-scale GCS projects to improve site prescreening and monitoring design. A suite of 300 numerical simulations was generated using stochastic geological models that vary five key parameters: net-to-gross ratio, anisotropy azimuth, porosity multiplier, permeability multiplier, and vertical-to-horizontal permeability ratio. Among these, 200 realizations represent normal geological uncertainty, while 100 additional cases explore extreme yet plausible conditions for failure-case analysis. The AoR was simulated and computed from pressure and CO 2 saturation fields, where the baseline AoR boundary, representing the extent predicted under typical geological uncertainty, was defined as the union of 200 normal-range simulations, and failure was identified when extreme-range cases exceeded this baseline. Results show that incorporating broader parameter uncertainty produces significantly larger AoR extents, underscoring the potential underestimation of risk under conventional uncertainty ranges. Furthermore, spatial probability maps derived from failure-induced AoR exceedance identify regions requiring enhanced monitoring attention. Various machine learning (ML)–based classifiers were developed to predict failure occurrence from geological parameters, with the random forest model achieving the highest performance (F1-score of 0.986). Consistent findings from correlation coefficient, feature importance, and Sobol sensitivity analyses reveal that low net-to-gross ratios and permeability multipliers are the dominant risk drivers, reflecting reduced reservoir connectivity and limited pressure dissipation. Altogether, these results provide a novel framework for risk-informed site prescreening and monitoring design that explicitly considers rare but high-impact geological scenarios in GCS projects.

25 ENERGY STORAGE↗

IMPACT, a Tool Suite for Crew Health and Performance System Trade Analyses and Decision Support - Status of Development

Mission planners, systems engineers, and clinicians that support crew health and performance face very difficult choices on upcoming exploration missions. Given that there will be a heavily constrained mass and volume allocation for a medical system on these missions, what medical capability should be manifested to minimize both medical risk and mission risk? Given that not all promising research and technology proposals can be funded, how can proposals be prioritized so that those funded research investments produce the maximum benefit in reducing overall medical risk? The Informing Mission Planning via Analysis of Complex Tradespaces (IMPACT) project seeks to answer these kinds of questions and others to support upcoming exploration missions. IMPACT enables risk-informed and evidence-based trade space analysis for future space vehicles, missions, and systems. This presentation will discuss the long-term HRP and ExMC vision for the larger ecosystem of tools, which include an updated medical database, consisting of an Evidence Library for medical conditions and a medical item database (MedID) for medical resources, dynamic Probabilistic Risk Assessment (PRA) capabilities, System Modeling Language (SysML) models, and contextual data visualizations of output data. IMPACT is the result of a multi-center collaborative effort. The trade space analyses performed by IMPACT can directly inform mission, vehicle, and habitat development by quantifying medical risk, given a design reference mission, crew attributes and a set of medical capabilities. This presentation will update the audience on the development status of the tool suite as it nears its System Acceptance Review (SAR). It will review IMPACT’s constituent parts, briefly discuss typical outputs and outline the plans for transitioning to operations, currently scheduled for later in FY23. Recent development successes on the IMPACT project include the integration of the Medical Extensible Dynamic Probabilistic Risk Assessment Tool (MEDPRAT) v2.0 to accommodate segmented missions with multiple carriers and medical systems, full onboarding of the IMPACT Medical Database (IMPACT-MD), clustering medical resources and skills into medical capabilities and mutually-dependent bundles, and the ability to perform trade analyses on different medical sets, different design reference missions (DRM), with different crew complements and extra-vehicular activity (EVA) schedule.

IMPACT↗

A Risk-Based Approach for Aerothermal/TPS Analysis and Testing

The current status of aerothermal and thermal protection system modeling for civilian entry missions is reviewed. For most such missions, the accuracy of our simulations is limited not by the tools and processes currently employed, but rather by reducible deficiencies in the underlying physical models. Improving the accuracy of and reducing the uncertainties in these models will enable a greater understanding of the system level impacts of a particular thermal protection system and of the system operation and risk over the operational life of the system. A strategic plan will be laid out by which key modeling deficiencies can be identified via mission-specific gap analysis. Once these gaps have been identified, the driving component uncertainties are determined via sensitivity analyses. A Monte-Carlo based methodology is presented for physics-based probabilistic uncertainty analysis of aerothermodynamics and thermal protection system material response modeling. These data are then used to advocate for and plan focused testing aimed at reducing key uncertainties. The results of these tests are used to validate or modify existing physical models. Concurrently, a testing methodology is outlined for thermal protection materials. The proposed approach is based on using the results of uncertainty/sensitivity analyses discussed above to tailor ground testing so as to best identify and quantify system performance and risk drivers. A key component of this testing is understanding the relationship between the test and flight environments. No existing ground test facility can simultaneously replicate all aspects of the flight environment, and therefore good models for traceability to flight are critical to ensure a low risk, high reliability thermal protection system design. Finally, the role of flight testing in the overall thermal protection system development strategy is discussed.

Wright, Michael J.↗

The Systems Engineering Process for Human Support Technology Development

Systems engineering is designing and optimizing systems. This paper reviews the systems engineering process and indicates how it can be applied in the development of advanced human support systems. Systems engineering develops the performance requirements, subsystem specifications, and detailed designs needed to construct a desired system. Systems design is difficult, requiring both art and science and balancing human and technical considerations. The essential systems engineering activity is trading off and compromising between competing objectives such as performance and cost, schedule and risk. Systems engineering is not a complete independent process. It usually supports a system development project. This review emphasizes the NASA project management process as described in NASA Procedural Requirement (NPR) 7120.5B. The process is a top down phased approach that includes the most fundamental activities of systems engineering - requirements definition, systems analysis, and design. NPR 7120.5B also requires projects to perform the engineering analyses needed to ensure that the system will operate correctly with regard to reliability, safety, risk, cost, and human factors. We review the system development project process, the standard systems engineering design methodology, and some of the specialized systems analysis techniques. We will discuss how they could apply to advanced human support systems development. The purpose of advanced systems development is not directly to supply human space flight hardware, but rather to provide superior candidate systems that will be selected for implementation by future missions. The most direct application of systems engineering is in guiding the development of prototype and flight experiment hardware. However, anticipatory systems engineering of possible future flight systems would be useful in identifying the most promising development projects.

Jones, Harry↗