Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “risk objectives”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Space Debris Modeling at NASA

Since the Second European Conference on Space Debris in 1997, the Orbital Debris Program Office at the NASA Johnson Space Center has undertaken a major effort to update and improve the principal software tools employed to model the space debris environment and to evaluate mission risks. NASA's orbital debris engineering model, ORDEM, represents the current and near-term Earth orbital debris population from the largest spacecraft to the smallest debris in a manner which permits spacecraft engineers and experimenters to estimate the frequency and velocity with which a satellite may be struck by debris of different sizes. Using expanded databases and a new program design, ORDEM2000 provides a more accurate environment definition combined with a much broader array of output products in comparison with its predecessor, ORDEM96. Studies of the potential long-term space debris environment are now conducted with EVOLVE 4.0, which incorporates significant advances in debris characterization and breakup modeling. An adjunct to EVOLVE 4.0, GEO EVOLVE has been created to examine debris issues near the geosynchronous orbital regime. In support of NASA Safety Standard 1740.14, which establishes debris mitigation guidelines for all NASA space programs, a set of evaluation tools called the Debris Assessment Software (DAS) is specifically designed for program offices to determine whether they are in compliance with NASA debris mitigation guidelines. DAS 1.5 has recently been released with improved WINDOWS compatibility and graphics functions. DAS 2.0 will incorporate guideline changes in a forthcoming revision to NASA Safety Standard 1740.14. Whereas DAS contains a simplified model to calculate possible risks associated with satellite reentries, NASA's higher fidelity Object Reentry Survival Analysis Tool (ORSAT) has been upgraded to Version 5.0. With the growing awareness of the potential risks posed by uncontrolled satellite reentries to people and property on Earth, the application of both DAS and ORSAT has increased markedly in the past two years.

Johnson, Nicholas L.↗

Assessment of Uncertainty-Based Screening Volumes for NASA Robotic LEO and GEO Conjunction Risk Assessment

Conjunction Assessment operations require screening assets against the space object catalog by placing a pre-determined spatial volume around each asset and predicting when another object will violate that volume. The selection of the screening volume used for each spacecraft is a trade-off between observing all conjunction events that may pose a potential risk to the primary spacecraft and the ability to analyze those predicted events. If the screening volumes are larger, then more conjunctions can be observed and therefore the probability of a missed detection of a high risk conjunction event is small; however, the amount of data which needs to be analyzed increases. This paper characterizes the sensitivity of screening volume size to capturing typical orbit uncertainties and the expected number of conjunction events observed. These sensitivities are quantified in the form of a trade space that allows for selection of appropriate screen-ing volumes to fit the desired concept of operations, system limitations, and tolerable analyst workloads. This analysis will specifically highlight the screening volume determination and selection process for use in the NASA Conjunction Assessment Risk Analysis process but will also provide a general framework for other Owner / Operators faced with similar decisions.

Narvet, Steven W.↗

Space Weather Impacts to Conjunction Assessment: A NASA Robotic Orbital Safety Perspective

National Aeronautics and Space Administration (NASA) recognizes the risk of on-orbit collisions from other satellites and debris objects and has instituted a process to identify and react to close approaches. The charter of the NASA Robotic Conjunction Assessment Risk Analysis (CARA) task is to protect NASA robotic (unmanned) assets from threats posed by other space objects. Monitoring for potential collisions requires formulating close-approach predictions a week or more in the future to determine analyze, and respond to orbital conjunction events of interest. These predictions require propagation of the latest state vector and covariance assuming a predicted atmospheric density and ballistic coefficient. Any differences between the predicted drag used for propagation and the actual drag experienced by the space objects can potentially affect the conjunction event. Therefore, the space environment itself, in particular how space weather impacts atmospheric drag, is an essential element to understand in order effectively to assess the risk of conjunction events. The focus of this research is to develop a better understanding of the impact of space weather on conjunction assessment activities: both accurately determining the current risk and assessing how that risk may change under dynamic space weather conditions. We are engaged in a data-- ]mining exercise to corroborate whether or not observed changes in a conjunction event's dynamics appear consistent with space weather changes and are interested in developing a framework to respond appropriately to uncertainty in predicted space weather. In particular, we use historical conjunction event data products to search for dynamical effects on satellite orbits from changing atmospheric drag. Increased drag is expected to lower the satellite specific energy and will result in the satellite's being 'later' than expected, which can affect satellite conjunctions in a number of ways depending on the two satellites' orbits and the geometry of the conjunction. These satellite time offsets can form the basis of a new technique under development to determine whether space weather perturbations, such as coronal mass ejections, are likely to increase, decrease, or have a neutral effect on the collision risk due to a particular close approach.

Ghrist, Richard↗

Proposed Project Selection Method for Human Support Research and Technology Development (HSR&TD)

The purpose of HSR&TD is to deliver human support technologies to the Exploration Systems Mission Directorate (ESMD) that will be selected for future missions. This requires identifying promising candidate technologies and advancing them in technology readiness until they are acceptable. HSR&TD must select an may of technology development projects, guide them, and either terminate or continue them, so as to maximize the resulting number of usable advanced human support technologies. This paper proposes an effective project scoring methodology to support managing the HSR&TD project portfolio. Researchers strongly disagree as to what are the best technology project selection methods, or even if there are any proven ones. Technology development is risky and outstanding achievements are rare and unpredictable. There is no simple formula for success. Organizations that are satisfied with their project selection approach typically use a mix of financial, strategic, and scoring methods in an open, established, explicit, formal process. This approach helps to build consensus and develop management insight. It encourages better project proposals by clarifying the desired project attributes. We propose a project scoring technique based on a method previously used in a federal laboratory and supported by recent research. Projects are ranked by their perceived relevance, risk, and return - a new 3 R's. Relevance is the degree to which the project objective supports the HSR&TD goal of developing usable advanced human support technologies. Risk is the estimated probability that the project will achieve its specific objective. Return is the reduction in mission life cycle cost obtained if the project is successful. If the project objective technology performs a new function with no current cost, its return is the estimated cash value of performing the new function. The proposed project selection scoring method includes definitions of the criteria, a project evaluation questionnaire, and a scoring formula.

Jones, Harry↗

Risk Balance: A Key Tool for Mission Operations Assurance

The Mission Operations Assurance (MOA) discipline actively participates as a project member to achieve their common objective of full mission success while also providing an independent risk assessment to the Project Manager and Office of Safety and Mission Success staff. The cornerstone element of MOA is the independent assessment of the risks the project faces in executing its mission. Especially as the project approaches critical mission events, it becomes imperative to clearly identify and assess the risks the project faces. Quite often there are competing options for the project to select from in deciding how to execute the event. An example includes choices between proven but aging hardware components and unused but unproven components. Timing of the event with respect to visual or telecommunications visibility can be a consideration in the case of Earth reentry or hazardous maneuver events. It is in such situations that MOA is called upon for a risk balance assessment or risk trade study to support their recommendation to the Project Manager for a specific option to select. In the following paragraphs we consider two such assessments, one for the Stardust capsule Earth return and the other for the choice of telecommunications system configuration for the EPOXI flyby of the comet Hartley 2. We discuss the development of the trade space for each project's scenario and characterize the risks of each possible option. The risk characterization we consider includes a determination of the severity or consequence of each risk if realized and the likelihood of its occurrence. We then examine the assessment process to arrive at a MOA recommendation. Finally we review each flight project's decision process and the outcome of their decisions.

operations↗

Nuclear Security Risks for HALEU Fuels

There is growing interest in high-assay low-enriched uranium (HALEU) for use in advanced nuclear reactors as a high-energy fuel source. The primary objectives of this report are to identify the security risks that directly result from HALEU and to identify the gaps and challenges it presents from a theft and sabotage perspective. This study focuses on HALEU security risks for the front end of the fuel cycle and includes a review of the supply chain, fuel fabrication, and transport for terrestrial reactors.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Lessons Learned from the Clementine Mission

According to BMDO, the Clementine mission achieved many of its technology objectives during its flight to the Moon in early 1994 but, because of a software error, was unable to test the autonomous tracking of a cold target. The preliminary analyses of the returned lunar data suggest that valuable scientific measurements were made on several important topics but that COMPLEX's highest-priority objectives for lunar science were not achieved. This is not surprising given that the rationale for Clementine was technological rather than scientific. COMPLEX lists below a few of the lessons that may be learned from Clementine. Although the Clementine mission was not conceived as a NASA science mission exactly like those planned for the Discovery program, many operational aspects of the two are similar. It is therefore worthwhile to understand the strengths and faults of the Clementine approach. Some elements of the Clementine operation that led to the mission's success include the following: (1) The mission's achievements were the responsibility of a single organization and its manager, which made that organization and that individual accountable for the final outcome; (2) The sponsor adopted a hands-off approach and set a minimum number of reviews (three); (3) The sponsor accepted a reasonable amount of risk and allowed the project team to make the trade-offs necessary to minimize the mission's risks while still accomplishing all its primary objectives; and (4) The development schedule was brief and the agreed-on funding (and funding profile) was adhered to. Among the operational shortcomings of Clementine were the following: (1) An overly ambitious schedule and a slightly lean budget (meaning insufficient time for software development and testing, and leading ultimately to human exhaustion); and (2) No support for data calibration, reduction, and analysis. The principal lesson to be learned in this category is that any benefits from the constructive application of higher risk for lower cost and faster schedule will be lost if the schedule does not allow adequate time for the development of all essential systems or makes no allowance for human frailties. Another lesson to be drawn is that despite its limitations, if judged strictly as a science mission, Clementine attested that significant scientific information can be gathered during a technology-demonstration mission. In the current era of limited funds, when science missions will be infrequent, the opportunity to fly scientific instruments aboard missions whose objectives might be other than science must be seized and, indeed, encouraged. During such opportunities it would be inexcusable to do second-class science. Thus the scientific community must be actively involved in such projects from their initiation.

Source record↗

Regulatory Considerations for Domestic Reprocessing Facility Physical Security

U.S. advanced non-light-water reactor vendors may pursue collocated on-site reprocessing activities. Therefore, these facilities are likely to possess formula quantities, or Category I quantities, of special nuclear material (SNM) during normal operations. The U.S. Nuclear Regulatory Commission (U.S. NRC) has yet to formally establish a regulatory framework for commercial reprocessing. While Category I requirements would explicitly not apply in this circumstance under current regulatory requirements, regulatory certainty does not exist. A novel framework should be developed to ensure public health and safety while also risk-informing the physical security requirements. This report reviews the relevant background of related rulemaking activities and proposes risk-informed physical protection requirements to satisfy these objectives. Insights from NRC security-related rulemaking activities provide a substantial technical basis to approach potential establishment of physical security requirements for reprocessing facilities. If a licensee can provide justification that the material satisfies a sufficient self-protecting radiation dose threshold, the material may not be subject to theft or diversion requirements and only potential sabotage requirements would apply. Furthermore, if the material can be justified to be moderately dilute, a set of risk-informed requirements could provide adequate protection of public health and safety. A revised performance objective for prevention of theft of moderately dilute Category I SNM may be detection to allow prompt recovery by a local law enforcement agency. However, a significant caveat to the proposed categorization scheme is the unknown integration of radiological sabotage with requirements for the protection against theft. Future licensees should consult with the NRC regarding treatment of this regulatory topic. Additionally, the self-protecting radiation dose threshold (either the existing or a proposed future threshold) would need to be considered. An integrated approach may apply graded potential requirements for protection against the design basis threat of radiological sabotage currently applicable to commercial nuclear power plants and Category I SNM facilities defined within 10 CFR 73.1(a).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Technology and Tool Development to Support Safety and Mission Assurance

The Assurance Case approach is being adopted in a number of safety-mission-critical application domains in the U.S., e.g., medical devices, defense aviation, automotive systems, and, lately, civil aviation. This paradigm refocuses traditional, process-based approaches to assurance on demonstrating explicitly stated assurance goals, emphasizing the use of structured rationale, and concrete product-based evidence as the means for providing justified confidence that systems and software are fit for purpose in safely achieving mission objectives. NASA has also been embracing assurance cases through the concepts of Risk Informed Safety Cases (RISCs), as documented in the NASA System Safety Handbook, and Objective Hierarchies (OHs) as put forth by the Agency's Office of Safety and Mission Assurance (OSMA). This talk will give an overview of the work being performed by the SGT team located at NASA Ames Research Center, in developing technologies and tools to engineer and apply assurance cases in customer projects pertaining to aviation safety. We elaborate how our Assurance Case Automation Toolset (AdvoCATE) has not only extended the state-of-the-art in assurance case research, but also demonstrated its practical utility. We have successfully developed safety assurance cases for a number of Unmanned Aircraft Systems (UAS) operations, which underwent, and passed, scrutiny both by the aviation regulator, i.e., the FAA, as well as the applicable NASA boards for airworthiness and flight safety, flight readiness, and mission readiness. We discuss our efforts in expanding AdvoCATE capabilities to support RISCs and OHs under a project recently funded by OSMA under its Software Assurance Research Program. Finally, we speculate on the applicability of our innovations beyond aviation safety to such endeavors as robotic, and human spaceflight.

Mission Assuranc↗

The Evolution of System Safety at NASA

The NASA system safety framework is in the process of change, motivated by the desire to promote an objectives-driven approach to system safety that explicitly focuses system safety efforts on system-level safety performance, and serves to unify, in a purposeful manner, safety-related activities that otherwise might be done in a way that results in gaps, redundancies, or unnecessary work. An objectives-driven approach to system safety affords more flexibility to determine, on a system-specific basis, the means by which adequate safety is achieved and verified. Such flexibility and efficiency is becoming increasingly important in the face of evolving engineering modalities and acquisition models, where, for example, NASA will increasingly rely on commercial providers for transportation services to low-earth orbit. A key element of this objectives-driven approach is the use of the risk-informed safety case (RISC): a structured argument, supported by a body of evidence, that provides a compelling, comprehensible and valid case that a system is or will be adequately safe for a given application in a given environment. The RISC addresses each of the objectives defined for the system, providing a rational basis for making informed risk acceptance decisions at relevant decision points in the system life cycle.

Dezfuli, Homayoon↗

NASA Risk Management Handbook: Version 2.0, Part 2

The purpose of this handbook is to provide an in-depth reference for the practice of risk management in NASA, updating the guidance offered in its original version, NASA/SP-2011-3422 (November 2011), and closely aligning the updated guidance with the current NASA Procedural Requirements for Agency Risk Management, NPR 8000.4, and the parent NASA Policy Directive for NASA Governance and Strategic Management, NPD 1000.0 (January 2020). NPD 1000.0 introduces with emphasis the concept of “Risk Leadership,” making it a fundamental tenet and pillar of the risk management culture that it advocates for the Agency. NPR 8000.4 applies this concept and establishes Risk Management (RM) requirements for the Agency as an integrated enterprise, as well as the RM requirements for portfolio elements within the enterprise. Such elements include the various programs and projects that contribute to the Agency’s objectives and the various institutional activities carried out by entities that contribute to mission support. The present version of the handbook also emphasizes the integration of risk management processes across activity and project life cycles and their coordination and interaction with day-to-day programmatic and organizational functions. Areas of application of risk assessment and management that were not covered with specific guidance in the preceding version are addressed in this version with in-depth examples. The handbook is structured into two parts, whose chapters are in turn organized in a sequential order intended to facilitate a gradual and progressive introduction of the reader to risk management principles and practices. Part 1 of the handbook is dedicated to the introduction of the basic foundations of the NASA integrated risk management framework, the related fundamental risk concepts, the description of the risk management and decision processes that are to be implemented within the framework, the discussion of the risk assessment techniques that should be utilized in support of such processes, and the management and organizational interactions and interfaces that should be enabled to implement an effective integration of risk management activities within the Agency. Part 2 provides self-contained, end-to-end examples of application of the processes and techniques introduced in Part 1, in the context of both programmatic (i.e., project and/or mission related) and institutional activities.

Risk Leadership↗

Generalized Separation of an Object Jettisoned from the ISS

The International Space Station (ISS) Program faces unprecedented logistics challenges in both upmass and downmass. Some items employed on the ISS exterior present significant technical issues for a controlled de-orbit on either the shuttle or an expendable supply vehicle. Such manifest problems arise due to structural degradation, insufficient containment of hazardous pressures or contents, excessive size, or some combination of all of these factors. In addition, the mounting hardware and other flight service equipment to manifest the returned equipment must itself be launched, competing with other upmass. EVA techniques and equipment to successfully contain and secure such problematic equipment result in numerous significant risks to the spacewalking crews and cost and schedule risks to the program. The ISS Program office has therefore developed a policy that advises the jettison of the most problematic objects. Such jettisoned items join a small family of nearly co-planar orbital debris objects that threaten the ISS on several timescales, besides threatening all satellites with perigee below the ISS orbit and the general human population on Earth. This analysis addresses the governing physics and the ensuing risks when an object is jettisoned. It is shown that there are four time domains which must be considered, each with its own inherent problems, and that a ballistic solution is usually possible that satsfies all constraints in all domains.

Bacon, Jack↗

Risk-Oriented PMU Placement Approach in Electric Power Systems

The objective of traditional PMU placement approaches is to use the minimal number of PMUs to cover system complete observability. Very few consider the probability and the consequence severity of observability loss. For example, following line trip, grid topology changes, which may results in observability loss and overloaded lines. As long as the overloaded lines are still observable, then we can take action in time to correct the system; and the consequence of the observability loss is not severe, although some parts of the system is not observable. Otherwise, if the overloaded lines become unobservable, then we lose the situation awareness of the system and the consequence of the observability loss is severe. To address the above points in PMU placement, this paper proposes a risk-oriented PMU placement approach. The proposed approach uses two indices, namely the probability of observability loss and its corresponding consequence of severity to design the optimal PMU placement strategy. We show that our proposed approach is able to capture the critical events while the traditional approaches fail to do so. Extensive simulation results carried out on the IEEE 39-bus and 118-bus systems demonstrate its effectiveness.

observability, risk of observability loss, PMUs pl↗

The Regulatory Treatment of Low Frequency External Events as Part of a Risk-Informed, Performance-Based Approach

To assist the developing advanced reactor industry in future licensing efforts, the U.S. Department of Energy Advanced Reactor Demonstration Program Regulatory Development area initiated a project at Argonne National Laboratory to examine the regulatory treatment of external hazards as part of a risk-informed performance-based (RIPB) licensing framework. A RIPB licensing framework for advanced reactors built on establishing an affirmative safety case offers the benefits of increased flexibility regarding key design and licensing decisions based on a detailed assessment and understanding of plant risk. Historically, reactor licensing addressed events of very low frequency primarily through the application of design margin and defense-in-depth philosophy. In contrast, RIPB approaches attempt to evaluate these scenarios at a level of detail commensurate with their risk, which often necessitates an explicit treatment of their frequency and associated consequence. While the detailed analysis of low frequency events provides insights that can help justify alternative treatments to past conservatism, the findings are dependent on the quality and confidence associated with the analyses. The assessment of external hazards presents a unique challenge, as their potential frequency of occurrence, especially of large magnitude events, is inherently uncertain given the long return periods in question. This project aims to identify the benefits and challenges of such approaches for advanced reactor vendors and aid in the development of consistent and appropriate analysis methodologies. The paper summarizes project findings and explores the application of various approaches for different external hazards. In addition, the current work also evaluates the application of the quantitative health objectives as a limit on external event risk, as they are a potential regulatory requirement under the current draft 10 CFR Part 53, which is a new technology-neutral reactor licensing pathway in the U.S.

Grabaskas, David↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗

Spacecraft Orbital Debris Reentry: Aerothermal Analysis

In the past 40 years, thousands of objects have been placed in Earth orbit and are being tracked. Space hardware reentry survivability must be evaluated to assess risks to human life and property on the ground. The objective of this paper is to present results of a study to determine altitude of demise (burn-up) or survivability of reentering objects. Two NASA/JSC computer codes - Object Reentry Survival Analysis Tool (ORSAT) and Miniature ORSAT (MORSAT) were used to determine trajectories, aerodynamic aerothermal environment, and thermal response of selected spacecraft components. The methodology of the two codes is presented, along with results of a parametric study of reentering objects modeled as spheres and cylinders. Parameters varied included mass, diameter, wall thickness, ballistic coefficient, length, type of material, and mode of tumbling/spinning. Two fragments of a spent Delta second stage undergoing orbital decay, stainless steel cylindrical propellant tank and titanium pressurization sphere, were evaluated with ORSAT and found to survive entry, as did the actual objects. Also, orbital decay reentry predictions of the Japanese Advanced Earth Observing Satellite (ADEOS) aluminum and nickel box-type components and the Russian COSMOS 954 satellite beryllium cylinders were made with MORSAT. These objects were also shown to survive reentry.

Rochelle, Wm. C.↗

NASA's International Lunar Network Anchor Nodes and Robotic Lunar Lander Project Update

NASA Marshall Space Flight Center and The Johns Hopkins University Applied Physics Laboratory have been conducting mission studies and performing risk reduction activities for NASA's robotic lunar lander flight projects. Additional mission studies have been conducted to support other objectives of the lunar science and exploration community and extensive risk reduction design and testing has been performed to advance the design of the lander system and reduce development risk for flight projects.

Cohen, Barbara A.↗

Astronaut Risk Levels During Crew Module (CM) Land Landing

The NASA Engineering Safety Center (NESC) is investigating the merits of water and land landings for the crew exploration vehicle (CEV). The merits of these two options are being studied in terms of cost and risk to the astronauts, vehicle, support personnel, and general public. The objective of the present work is to determine the astronaut dynamic response index (DRI), which measures injury risks. Risks are determined for a range of vertical and horizontal landing velocities. A structural model of the crew module (CM) is developed and computational simulations are performed using a transient dynamic simulation analysis code (LS-DYNA) to determine acceleration profiles. Landing acceleration profiles are input in a human factors model that determines astronaut risk levels. Details of the modeling approach, the resulting accelerations, and astronaut risk levels are provided.

Lawrence, Charles↗