Enabling Autonomous Advanced Air Mobility: Human-Autonomy Teaming and In-Time System-Wide Safety Assurance
Explore the source record for details and available documents.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
This paper explains why labeling something as evidence does not make it special and proposes a systematic approach for avoiding giving the word more authority than it warrants in rational inquiry about the real world.
Explore the source record for details and available documents.
Assuring safety in the NAS with the inclusion of new entrants, such as Advanced Air Mobility (AAM), will require overcoming unique safety challenges that result from combining innovative technologies with novel airspace concepts for moving people and cargo using autonomous vehicles. The focus of the In-time Aviation Safety Management System (IASMS) is to overcome AAM’s safety assurance challenges. The IASMS Concept of Operations (ConOps) describes an interconnected set of services, functions, and capabilities (SFCs) designed to manage operational risks, identify unknown risks, and inform system designs. This paper describes an approach for defining SFCs based on technology trends in research, assessment of known and unknown risks in voluntary safety reports, and causal and contributing factors in aviation accidents and incidents. This approach would identify potential SFCs that further expand the Monitor, Assess, and Mitigate (M-A-M) functionality that represents the enabling framework of the IASMS. Safety implications that will result from integration of AAM in the transformation of the National Airspace System (NAS) were addressed in National Academies committees reports on AAM and IASMS. Development of a ConOps for IASMS was a top recommendation and can be represented as a reframing of safety assurance that builds on real-time alerting such as the Traffic Alert and Collision Avoidance System, and adds the more encompassing in-time temporal parameter in recognition of the different timelines for collecting and assessing safety data for risk mitigations. For example, mining for safety trends from data sources such as the Aviation Safety Information Analysis and Sharing system occurs over a longer time period. Research on AAM operations poses that SFCs can be designed to monitor the safety margin appropriate for AAM including with regards to the distance between current flight parameters and nominal ideal conditions. These in-time comparisons will become more complex as the density of operations increases at least in certain areas and can include planned and actual 4D trajectory, and in-time comparisons having implications on conflict modeling and prediction including expected and actual departure time, fix/waypoint crossing times, and arrival time. These comparisons would be integrated as part of SFCs that redefine and inform new safety margin. An increased safety margin improves management of operational risks while reducing the potential for anomalies. An increased safety margin also has implications for operator confidence in the certainty of its operations and trust in automation. Technology trends in research could be used to refine existing SFCs and define needs for additional SFCs that provide safety improvements to the design and operation of vehicles, airspace design, and operator performance requirements. NASA is developing innovative approaches to safeguard against major accidents and incidents that have occurred in the NAS and those anticipated with the inclusion of envisioned AAM operations. The innovations use operational performance data to monitor, detect, and predict flight variations exceeding safe nominal patterns, such as would be caused by navigational error, severe weather complications, or hijacking of UAS controls. These innovative approaches have high potential to prevent accidents and incidents in the new AAM era. It is anticipated that elements of the innovations will evolve into SFCs for the IASMS. Voluntary safety reports can be monitored to identify anomalies related to design or operational performance risks. Reports could be periodically monitored and assessed for specific topics. Reports might serve as weak signals or precursors indicative of emergent risk such as when combined with other safety information. The architecture could include SFCs that are based on voluntary safety reports recognizing the periodic temporal nature of data analysis. As previously mentioned, aviation accidents with their causal and contributing precursors can inform the need for SFCs in the IASMS. Accidents and incidents at San Francisco International Airport such as Asiana 214 and Air Canada 759 illustrate how combinations of different factors lead to increased risk. These types of precursors and different factors have implications on the types of SFCs that could be needed to monitor and manage different sources and types of design and operational risk. Continuing to assure the safety of AAM as designs and operations gain in complexity can be accompanied by defining SFCs that also increase in complexity. These SFCs can leverage information from findings and recommendations synthesized across on-going research, voluntary safety reports, and accident and incident reports. These SFCs can serve to refine accuracy of algorithms and resolve limitations with current practices. The IASMS architecture represents the framework for the SFCs and their critical role in safety assurance.
Assuring safety in the NAS with the inclusion of new entrants that are part of Advanced Air Mobility (AAM) will require overcoming unique safety challenges that result from combining innovative technologies with novel airspace concepts for moving people and cargo using semi-autonomous/autonomous vehicles. Overcoming these AAM safety assurance challenges is the focus of the In-time Aviation Safety Management System (IASMS). The IASMS Concept of Operations (ConOps) describes an interconnected set of services, functions, and capabilities (SFCs)designed to manage operational risks, identify unknown risks, and inform system design to mitigate risk. This paper describes a broad approach for identifying SFCs involving technology trends in research, assessment of known and unknown risks in safety reports, and causal and contributing factors in aviation accidents and incidents. This approach leverages these sources to identify potential SFCs that enable the Monitor, Assess, and Mitigate (M-A-M)functionality that represents the enabling framework of the IASMS.
NASA is conducting research to demonstrate and evaluate the application of Run Time Assurance (RTA) as a means to assure safety in Electric Vertical Takeoff and Landing (eVTOL) aircraft with highly automated or autonomous flight capability supervised by a single onboard pilot. The work described in this report demonstrates an application of RTA and examines the implications for design and analysis of aircraft functions and systems; aircraft safety hazards; safety assurance; development assurance; and pilot tasks and performance. This research effort also seeks to assess the efficacy of the combined application of traditional Functional Hazard Analysis (FHA) and the more modern System Theoretic Process Analysis (STPA) techniques to perform hazard analyses on aircraft with complex automated and autonomous systems and an onboard pilot. During the research effort we developed architectural designs of two alternate eVTOL aircraft, generally following the process characterized in the SAE standards ARP4754 and ARP4761. The design has focused on the control architectures of these aircraft, which are identical except that one incorporates RTA techniques to reduce the criticality of some key software components. Artifacts of this process include a taxonomy of aircraft-level functions, aircraft-level architecture diagrams, aircraft-level functional hazard assessments (AFHA), function allocations onto aircraft systems and subsystems, functional block diagrams for a select set of control-related functions, and system-level functional hazard assessments (SFHA) for those functions. This project has highlighted the notion that DAL D is something of a sweet spot for low-confidence controllers in an RTA-based design. Among the many activities described in DO-178C, the activities related to requirement verifiability, algorithmic accuracy, and test coverage can be the most challenging for the kinds of advanced control techniques that may be desirable in novel UAM designs, such as adaptive control, machine-learning, artificial intelligence, numerical search, and Monte Carlo based algorithms. Moreover, the standard requires that development teams demonstrate that errors leading to unacceptable failure conditions have been removed from the software. The RTA architecture, which cordons off the low-confidence function, makes it much easier to show this for these kinds of algorithms. With regard to the use of STPA and FHA as complementary hazard analysis techniques, our research effort led us to the conclusion that STPA should be used to derive requirements for hardware and software systems and/or components. Also, STPA is a natural complement to other processes in ARP4754A involving design studies and iteration.
The Safety and Assurance Directorate (SAAD) has a vision. The vision is to be an essential part of NASA Glenn's journey to excellence. SAAD is in charge of leading safety, security, and quality and is important to our customers. When it comes to programmatic and technical decision making and implementation, SAAD provides clear safety, reliability, maintainable, quality assurance and security. I worked on a couple different things during my internship with Sandra Hardy. I did a lot of logistics for meeting and trips. I helped run the budget for the SAAD directorate. I also worked with Rich Miller for one week and we took water samples and ran tests. We also calibrated the different equipment. There is a lot more to meetings than people see. I did one for a retirement party. I had to get work orders and set up the facilities where the event is going to take place. I also set up a trip to Plum Brook Station. I had to order vans and talk with the people up there to see when a good time was. I also had to make invitations and coordinate everything. I also help Sandy run the numbers in the budget. We use excel to do this, which makes it a lot easier. things. He is in the environmental safety office. I learned how to collaborate the equipment using alpha and beta sources. I went out with him and we took water samples and tested them for conductivity and chlorine. I have learned a lot in the short time I've been here. It has been a great experience and I have has the pleasure of meeting and working with great people.
The Aviation Safety Program (AvSP) System-Wide Safety and Assurance Technologies (SSAT) Project asked the AvSP Systems and Portfolio Analysis Team to identify SSAT-related trends. SSAT had four technical challenges: advance safety assurance to enable deployment of NextGen systems; automated discovery of precursors to aviation safety incidents; increasing safety of human-automation interaction by incorporating human performance, and prognostic algorithm design for safety assurance. This report reviews incident data from the NASA Aviation Safety Reporting System (ASRS) for system-component-failure- or-malfunction- (SCFM-) related and human-factor-related incidents for commercial or cargo air carriers (Part 121), commuter airlines (Part 135), and general aviation (Part 91). The data was analyzed by Federal Aviation Regulations (FAR) part, phase of flight, SCFM category, human factor category, and a variety of anomalies and results. There were 38 894 SCFM-related incidents and 83 478 human-factorrelated incidents analyzed between January 1993 and April 2011.
Since its initiation, the System-wide Safety Assurance Technologies (SSAT) Project has been focused on developing multidisciplinary tools and techniques that are verified and validated to ensure prevention of loss of property and life in NextGen and enable proactive risk management through predictive methods. To this end, four technical challenges have been listed to help realize the goals of SSAT, namely (i) assurance of flight critical systems, (ii) discovery of precursors to safety incidents, (iii) assuring safe human-systems integration, and (iv) prognostic algorithm design for safety assurance. The objective of this report is to provide an extensive survey of SSAT-related research accomplishments by researchers within and outside NASA to get an understanding of what the state-of-the-art is for technologies enabling each of the four technical challenges. We hope that this report will serve as a good resource for anyone interested in gaining an understanding of the SSAT technical challenges, and also be useful in the future for project planning and resource allocation for related research.
Safety cases are typically used to certify systems at design time as being approved for operation. However, systems typically undergo changes in operation. We present ongoing work extending the safety case concept to account for operational updates.
Safety, reliability and quality assurance design analysis results are presented as well as design requirements recommended for implementation in the PEP design.
NASA’s planetary protection program seeks to understand and control harmful contamination of solar systems targets of exploration by terrestrial contamination and prevent harmful biological contamination of the Earth-Moon system by extraterrestrial life, should it exist. To accomplish these objective’s NASA has developed a balanced safety and mission assurance strategy that leverages COSPAR Policy guidelines, workshops, scientific consensus, partnerships and international working groups to develop policy and implementation guidelines. Upcoming crewed missions to the Moon and Mars, as well as robotic missions to small solar system bodies, Europa, Titan and Mars are some of the driving activities of astrobiological interest that continue to emphasize the importance of planetary protection throughout the project life cycle. Development of a responsive and updated agency planetary protection policy has been a focus area in supporting upcoming mission opportunities for exploration to include Mars sample return and crewed mission concepts. An extensive update of this policy is underway which encompasses crewed and robotic procedural polices, a general technical requirements standard, and an implementation handbook. During this timeframe NASA has been working with the international community to develop scientific consensus, and to identify and fill in knowledge gaps for developing balanced policy guidelines, incorporation of risk informed decision making and quantitative technical standards. NASA has developed a planetary protection roadmap as a technology management strategy to track and monitor the development of each knowledge gaps. The Committee of Space Research (COSPAR) Policy on Planetary Protection and the National Academies of Science, Engineering, and Medicine’s Committee of Planetary Protection are used to inform updates to the planetary protection polices and guidelines. This integrated strategy for planetary protection seeks to provide a transparent, structured approach for enabling missions, providing guidance for NASA and NASA partnered missions, and being responsive to the increased interest and activities in space exploration whilst maintaining an understanding and control of harmful contamination.
NASA's planetary protection program seeks to understand and control harmful contamination of solar systems targets of exploration by terrestrial contamination and prevent harmful biological contamination of the Earth-Moon system by extraterrestrial life, should it exist. To accomplish these objective's NASA has developed a balanced safety and mission assurance strategy that leverages COSPAR Policy guidelines, workshops, scientific consensus, partnerships and international working groups to develop policy and implementation guidelines. Upcoming crewed missions to the Moon and Mars, as well as robotic missions to small solar system bodies, Europa, Titan and Mars are some of the driving activities of astrobiological interest that continue to emphasize the importance of planetary protection throughout the project life cycle.Development of a responsive and updated agency planetary protection policy has been a focus area in supporting upcoming mission opportunities for exploration to include Mars sample return and crewed mission concepts. An extensive update of this policy is underway which encompasses crewed and robotic procedural polices, a general technical requirements standard, and an implementation handbook. During this timeframe NASA has been working with the international community to develop scientific consensus, and to identify and fill in knowledge gaps for developing balanced policy guidelines, incorporation of risk informed decision making and quantitative technical standards. NASA has developed a planetary protection roadmap as a technology management strategy to track and monitor the development of each knowledge gaps. The Committee of Space Research (COSPAR) Policy on Planetary Protection and the National Academies of Science, Engineering, and Medicine's Committee of Planetary Protection are used to inform updates to the planetary protection polices and guidelines. This integrated strategy for planetary protection seeks to provide a transparent, structured approach for enabling missions, providing guidance for NASA and NASA partnered missions, and being responsive to the increased interest and activities in space exploration whilst maintaining an understanding and control of harmful contamination.
Machine learning is increasingly being used in safety-critical systems, where the public safety requires a rigorous assurance process. We shall outline how assurance processes work for conventional systems and identify the primary difficulty in applying them to machine learning enabled systems. We will then outline a path forward including identifying where considerable basic research remains
In FY 1991, the NASA Safety Division continued efforts to enhance the quality and productivity of its safety oversight function. Recent initiatives set forth in areas such as training, risk management, safety assurance, operational safety, and safety information systems have matured into viable programs contributing to the safety and success of activities throughout the Agency. Efforts continued to develop a centralized intra-agency safety training program with establishment of the NASA Safety Training Center at the Johnson Space Center (JSC). The objective is to provide quality training for NASA employees and contractors on a broad range of safety-related topics. Courses developed by the Training Center will be presented at various NASA locations to minimize travel and reach the greatest number of people at the least cost. In FY 1991, as part of the ongoing efforts to enhance the total quality of NASA's safety work force, the Safety Training Center initiated development of a Certified Safety Professional review course. This course provides a comprehensive review of the skills and knowledge that well-rounded safety professionals must possess to qualify for professional certification. FY 1992 will see the course presented to NASA and contractor employees at all installations via the NASA Video Teleconference System.
Machine learning is increasingly being used in safety-critical systems, where the public safety requires a rigorous assurance process. We shall outline how assurance processes work for conventional systems and identify the primary difficulty in applying them to machine learning enabled systems. We will then outline a path forward including identifying where considerable basic research remains.