Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “firmware analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Memory forensic analysis of a programmable logic controller in industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLCs) are used to automate physical processes such as nuclear plants and power grid stations, and are often subject to cyber attacks. As in conventional IT domain, the memory analysis of the PLCs can help answer important forensic questions about the attack, such as the presence of malicious firmware, injection of modified control logic (the program running on the PLC), and manipulation of I/O devices (e.g., sensors and actuators). Unlike conventional IT domain, PLCs have heterogeneous hardware architecture, proprietary firmware and control software, making it challenging to employ a unified framework for their memory forensics. For merely extracting artifacts of forensic importance, reverse-engineering the firmware is a tedious task, and the effort needs to be repeated for every PLC model. As a community, a step-wise approach to tackle this challenge is to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. Our work is a step forward in this direction. By following a methodology that focuses on the functional layer of PLCs instead of reverse engineering the firmware, we analyze the digital forensic artifacts available in a common PLC, Allen-Bradley ControlLogix 1756-L61. Before diving into the memory dump, we analyze the PLC control software to create a list of important artifacts that are sure to exist in the PLC memory dump. The approach employs a setup where PLC control software RSLogix-5000 is connected to the PLC, and the memory dump can be obtained as and when needed. We create test cases that sequentially highlight each category of artifacts, followed by an examination of the resultant impact on memory. After attaining the listed artifacts, we employ conventional string and known data searches to extract interesting information present in this PLC's memory. The memory analysis profile, presented as a Python library and shared with the community, can help a forensic investigator to readily extract forensic artifacts from the same model's controller. The adopted approach may help researchers in creating memory profile of other PLCs, and ultimately formulating a generic PLC memory analysis framework.

Rais, Muhammad Haris↗

ARCADE (Advanced Reactor Cyber Analysis and Development Environment)

SAND2025-11780O ARCADE (Advanced Reactor Cyber Analysis and Development Environment) software performs cybersecurity experiments on Defensive Cyber Security Architectures (DCSA) for Distributed Control Systems (DCSs). The application is integrated into a cohesive environment that performs cyber risk analyses and reduces costs. ARCADE can investigate the entire cyber-attack surface of a DCS from the physics of control, down to the firmware of individual components with automated efficiency. ARCADE has five major functional components: the Data Broker system, the virtualization environment, the cyber-attack simulator, the cyber-physical analysis system, and the physics simulator. Sandia National Laboratories is a multimission laboratory managed and operated by National Technology & Engineering Solutions of Sandia, LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy’s National Nuclear Security Administration under contract DE-NA0003525.

Valme, Romuald↗

Fault Management Algorithm Risk Assessment for the NASA Space Launch System

This presentation describes the false positive (FP) and false negative (FN) risk assessment process currently being conducted for the Space Launch System (SLS) Artemis II Fault Management (FM) detection functions. The analysis scope, general assumptions and guide rules, and key modeling concepts were discussed to establish the basis of the risk assessments conducted. Initial analyses indicated a dominance in the total risk by software and firmware failures. This paper presents efforts applied to refine the software risks and the overall impact of implementing those modifications. Current analyses conducted on the detection functions implemented for the SLS Artemis II mission indicate primary risk drivers for the individual FM detection functions are flight software failures, firmware design failures, and hardware Common Cause Failures (CCFs). There still remains issues of how to account for time and redundancy in the software risk estimations.

probability risk analysis↗

Fault Management Algorithm Risk Assessment for the NASA Space Launch System

This paper presents the false positive (FP) and false negative (FN) risk assessment process currently being conducted for the Space Launch System (SLS) Artemis II Fault Management (FM) detection functions. The analysis scope, general assumptions and guide rules, and key modeling concepts were discussed to establish the basis of the risk assessments conducted. Initial analyses indicated a dominance in the total risk by software and firmware failures. This paper presents efforts applied to refine the software risks and the overall impact of implementing those modifications. Current analyses conducted on the detection functions implemented for the SLS Artemis II mission indicate primary risk drivers for the individual FM detection functions are flight software failures, firmware design failures, and hardware Common Cause Failures (CCFs). There still remains issues of how to account for time and redundancy in the software risk estimations.

probability risk analysis↗

A program downloader and other utility software for the DATAC bus monitor unit

A set or programs designed to facilitate software testing on the DATAC Bus Monitor is described. By providing a means to simplify program loading, firmware generation, and subsequent testing of programs, the overhead involved in software evaluation is reduced and that time is used more productively in performance, analysis and improvement of current software.

Novacki, Stanley M., III↗

Testing Results of the X-38 Crew Return Vehicle GPS Receiver

The X-38 Crew Return Vehicle (CRV) utilizes a Space Integrated GPS/INS (SIGI) sensor to obtain navigation and attitude knowledge. Testing and analysis at the NASA Goddard Space Flight Center Guidance, Navigation, and Control's GPS Lab was conducted in order to validate the development of SIGI GPS receiver attitude firmware. The modifications to the International Space Station (ISS) SIGI receiver that were completed to meet the CRV requirements will be presented. The CRV is designed to be used as a life-boat in case of an emergency evacuation from the ISS. The need to return the ISS crew in a timely manner places challenging performance requirements on the SIGI sensor. This paper will summarize the performance of the SIGI GPS receiver for the CRV. The ability to track the GPS signals at any initial attitude and the performance of the SIGI GPS-only solution during reentry are detailed in this paper. A discussion regarding the use of the Global Satellite Systems GPS Signal Generator in testing the SIGI sensor will provide insight into the GPS validation process used at NASA Goddard.

Simpson, James↗

Advanced Signal Conditioners for Data-Acquisition Systems

Signal conditioners embodying advanced concepts in analog and digital electronic circuitry and software have been developed for use in data-acquisition systems that are required to be compact and lightweight, to utilize electric energy efficiently, and to operate with high reliability, high accuracy, and high power efficiency, without intervention by human technicians. These signal conditioners were originally intended for use aboard spacecraft. There are also numerous potential terrestrial uses - especially in the fields of aeronautics and medicine, wherein it is necessary to monitor critical functions. Going beyond the usual analog and digital signal-processing functions of prior signal conditioners, the new signal conditioner performs the following additional functions: It continuously diagnoses its own electronic circuitry, so that it can detect failures and repair itself (as described below) within seconds. It continuously calibrates itself on the basis of a highly accurate and stable voltage reference, so that it can continue to generate accurate measurement data, even under extreme environmental conditions. It repairs itself in the sense that it contains a micro-controller that reroutes signals among redundant components as needed to maintain the ability to perform accurate and stable measurements. It detects deterioration of components, predicts future failures, and/or detects imminent failures by means of a real-time analysis in which, among other things, data on its present state are continuously compared with locally stored historical data. It minimizes unnecessary consumption of electric energy. The design architecture divides the signal conditioner into three main sections: an analog signal section, a digital module, and a power-management section. The design of the analog signal section does not follow the traditional approach of ensuring reliability through total redundancy of hardware: Instead, following an approach called spare parts tool box, the reliability of each component is assessed in terms of such considerations as risks of damage, mean times between failures, and the effects of certain failures on the performance of the signal conditioner as a whole system. Then, fewer or more spares are assigned for each affected component, pursuant to the results of this analysis, in order to obtain the required degree of reliability of the signal conditioner as a whole system. The digital module comprises one or more processors and field-programmable gate arrays, the number of each depending on the results of the aforementioned analysis. The digital module provides redundant control, monitoring, and processing of several analog signals. It is designed to minimize unnecessary consumption of electric energy, including, when possible, going into a low-power "sleep" mode that is implemented in firmware. The digital module communicates with external equipment via a personal-computer serial port. The digital module monitors the "health" of the rest of the signal conditioner by processing defined measurements and/or trends. It automatically makes adjustments to respond to channel failures, compensate for effects of temperature, and maintain calibration.

Lucena, Angel↗

Equipment Assessment Guide: A Technical Inspection and Hardening Guide for Devices in Power Grid Operations

This Equipment Assessment Guide, developed by Idaho National Laboratory (INL), provides a comprehensive framework designed to enhance the security of operational technology (OT) devices within power grid operations. The guide outlines essential steps for asset owners to conduct technical inspections and harden vulnerable hardware and firmware components commonly found in embedded systems. It focuses on components frequently targeted by cyber threats, offering valuable identification techniques for locating and recognizing critical components on devices. Additionally, the guide presents recommended secure configurations aimed at minimizing exposure and reinforcing defenses, along with impact analysis that highlights the potential consequences for grid operations if components are compromised. By implementing the recommendations outlined in this guide, asset owners can significantly enhance their cybersecurity posture, reduce the attack surface of field-deployed devices, and improve the resilience of grid services against emerging cyber threats.

42 - ENGINEERING↗

Report on ISR-1 High-Altitude Balloon Flight

To test small technologies at lower cost for space science applications, LANL has developed a small high altitude balloon payload that could, in the future, be regularly and inexpensively launched from LANL. A neutron detector, NEMO, was integrated to evaluate its performance in a space-like mixed-radiation environment and collect neutron data in the atmosphere. In collaboration with EES-14, a high-altitude balloon payload was launched from LANL Technical Area 51 on February 27, 2023 and April 17, 2023. For real-time geolocation, a SAM-M8Q M8 GNSS module was used to get position and time, and an Iridium RockBLOCK 9603 was used to communicate with the ground using the Iridium satellite fleet. These modules were all controlled using an Iteaduino Mega microcontroller board. Finally, a High Altitude Science Eagle Flight Computer with a temperature pressure sensor ran independently, writing data to an SD card. All of these modules were powered by a 5 mAh lithium polymer battery. The battery was attached to the bottom of the payload while the remaining electronics were embedded in the underside of the top of the payload. These modules were wired as seen in Figure 1-2. The Iteaduino Mega microcontroller board was programmed to use the RockBLOCK to send a message once every 10 minutes containing neutron and GPS data read off the NEMO and SAM M8Q, respectively. Once the message send attempt finished, the RockBLOCK would be slept for the rest of the 10 minute interval. The Eagle Flight Computer ran continuously throughout the flight, taking data every 6 seconds. The RockBLOCK message data was set up to be delivered from the Iridium satellite fleet to a website, where it was stored and parsed to create live maps and plots for analysis and balloon retrieval. The RockBLOCK message data was additionally configured to be sent to an email as a fail-safe. The payload was ground-tested successfully for over 50 hours, with multiple revisions occurring to best prepare for conditions at altitude and improve the software and firmware to fix any issues that cropped up with the data pipeline. Additional to the balloon payload, the flight had an attached iMet-4 radiosonde and Garmin T5 GPS Dog Collar. The radiosonde provided GPS and meteorological data. The T5 dog collar is used along with a Garmin Astro 430 to track the balloon at a range of up to 9 miles for retrieval. The balloon itself was initially a 1600 g meteorological balloon with an attached High Altitude Science parachute, both of which can be seen in Figure 1-3. After the first flight, the EES team swapped to a Rocketman parachute.

42 ENGINEERING↗

Space Telecommunications Radio System Software Architecture Concepts and Analysis

The Space Telecommunications Radio System (STRS) project investigated various Software Defined Radio (SDR) architectures for Space. An STRS architecture has been selected that separates the STRS operating environment from its various waveforms and also abstracts any specialized hardware to limit its effect on the operating environment. The design supports software evolution where new functionality is incorporated into the radio. Radio hardware functionality has been moving from hardware based ASICs into firmware and software based processors such as FPGAs, DSPs and General Purpose Processors (GPPs). Use cases capture the requirements of a system by describing how the system should interact with the users or other systems (the actors) to achieve a specific goal. The Unified Modeling Language (UML) is used to illustrate the Use Cases in a variety of ways. The Top Level Use Case diagram shows groupings of the use cases and how the actors are involved. The state diagrams depict the various states that a system or object may be in and the transitions between those states. The sequence diagrams show the main flow of activity as described in the use cases.

Handler, Louis M.↗

Towards a New Supply Chain Cybersecurity Risk Analysis Technique

Supply chain cyber-attacks, such as the SolarWinds Orion attack, are occurring with greater frequency. These attacks compromise a digital device before it is sent to customers, bypassing traditional security controls to remain persistent and undetected in operational environments. While supply chain attacks are prevalent, methods for analyzing the risk of these attacks are currently unavailable. This paper proposes new supply chain cyber-attack difficulty and risk metrics to evaluate the relative risk of an attack throughout the supply chain lifecycle. Difficulty metrics for each stakeholder in a digital device’s supply chain (e.g., hardware manufacturing, firmware development, software development, storage, and distribution entities) are calculated using scores from cybersecurity maturity questionnaires in a Bayesian Network leaky Noisy-MAX model. These difficulty metrics are then used to calculate an overall supply chain cyber-attack risk. Vulnerability and recoverability metrics are also proposed to evaluate the relative stakeholder influence in the attack risk. These proposed relative risk metrics enable continuous supply chain monitoring, provide decision-makers with information necessary for improved supplier selection, and help drive improvements in the cybersecurity posture of the stakeholders in their supply chain.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Commissioning of the Mu2e tracker DAQ, planning for the Vertical Slice Test and pre-pattern recognition studies

The primary objective of the Mu2e experiment at Fermilab is to search for the neutrino-less coherent $\mu \rightarrow e$ conversion in the field of an aluminum nucleus ($\mu^- \text{Al} \rightarrow e^- \text{Al}$). The signature of this process is a monochromatic Conversion Electron (CE) with an energy of approximately 104.97 MeV \cite{bartoszek2015mu2e}. Within the Standard Model (SM), the branching ratio for this process, including neutrino masses and oscillation, is expected to be less than $\mathcal{O}(10^{-50})$. This value is far beyond current experimental capabilities. However, models of physics beyond the SM predict much higher relative rates, approaching an observable level. The SINDRUM II experiment set an upper limit on muon conversion at $7 \times 10^{-13}$ (90\% CL) on Au target \cite{SINDRUMII:2006dvw}, and the Mu2e collaboration aims to improve this limit by four orders of magnitude. Observing this process would provide a clear evidence of physics beyond the Standard Model. A brief discussion of the theoretical and experimental aspects is provided in Chapter \ref{intr}. Mu2e adopts a sophisticated experimental setup to achieve its goals, further described in Chapter \ref{mu2echapter}. The central part of the Mu2e detector is the tracker, that consists of 18 tracking stations. The tracker must provide excellent momentum resolution, approximately 1 MeV/c, to distinguish the monochromatic CE signal from the background. To minimize the energy losses, a straw tube tracker will be used \cite{bobbb}. Chapter \ref{chaptertrk} provides an overview of the straw tracker design and its working principles. This Thesis presents a comprehensive study of the Mu2e tracker, covering complementary aspects from initial commissioning to optimization and first steps of the calibration processes. My work at Fermilab has been focused on the complete Data Acquisition (DAQ) testing from both hardware and software perspectives. I was involved in the commissioning of the Mu2e DAQ system and the Vertical Slice Test (VST) of the tracker. The VST encompasses the entire testing chain, from the straws to the readout, and to processed data on disk. I was also focused on the offline analysis, especially on pre-pattern recognition studies, to explore the best methods for identifying $\delta$-electrons during the data taking. Chapter \ref{commissioning} details the commissioning of the tracker DAQ system, emphasizing the importance of understanding of the readout process before the data acquisition. This includes validating the readout logic and firmware through Monte Carlo simulations to confirm functionality and buffering, monitoring the quality of the data from the tracker preamplifiers and front-end electronics, and assessing overall DAQ performance to ensure reliability during future calibration and data-taking. Chapter \ref{planning} discusses the initial steps towards the tracker calibration. The ultimate goal is to perform a time calibration of the first assembled station of the tracker using cosmic muons, aiming for a longitudinal hit position resolution better than 4 cm. This involves determining the signal propagation times and channel-to-channel delays. I performed a Monte Carlo study to determine the impact of the station orientation on the quality of the calibration, in particular on the cosmic track reconstruction, focusing on potential biases that could arise. These studies provide essential insights into the operation, optimization, and calibration of the Mu2e tracker system. Given the high data volume expected during Mu2e operations, estimated at approximately 7 PBytes per year, optimizing memory usage and minimizing CPU consumption are critical. A significant challenge lies in effectively flagging $\delta$-electron hits, which are the primary source of hits in the tracker, without compromising the efficiency of CE hit detection and track reconstruction. A detailed study of pre-pattern recognition and a thorough comparison of two $\delta$-electron flagging algorithms is provided in Chapter \ref{delta}. In Chapter \ref{conclusions}, the findings are concisely summarized, offering a comprehensive synthesis of the research and emphasizing the key insights derived from this study.

43 PARTICLE ACCELERATORS↗

Field and data analysis studies related to the atmospheric environment

This report summarizes work on a broad array of projects including: (1) applications of meteorological and/or oceanographic satellites; (2) improvement of the current set of NASA/USAF lightning related launch commit criteria rules; (3) the design, building, testing and deployment of a set of cylindrical field mills for aircraft use; (4) the study of marginal electrification storm conditions in relationship to the current launch commit rules for the space shuttle and various other launch vehicles using an instrumented aircraft; (5) support of the DC-8 and ER-2 lightning instrument package as part of both the Tropical Ocean - Global Atmospheric/Coupled Ocean-Atmospheric Response Experiment and the Convection and Moisture Experiment; (6) design of electronic circuitry and microprocessor firmware for the NASA Advanced Ground Based Field Mill; (7) design and testing of electronic and computer instrumentation for atmospheric electricity measurements; (8) simulating observations from a lightning imaging sensor on the Tropical Rainfall Measuring satellite; and (9) supporting scientific visualization and the development of computer software tools.

Kidder, Stanley↗

Flight Performance Evaluation of Three GPS Receivers for Sounding Rocket Tracking

In preparation for the European Space Agency Maxus-4 mission, a sounding rocket test flight was carried out at Esrange, near Kiruna, Sweden on February 19, 2001 to validate existing ground facilities and range safety installations. Due to the absence of a dedicated scientific payload, the flight offered the opportunity to test multiple GPS receivers and assess their performance for the tracking of sounding rockets. The receivers included an Ashtech G12 HDMA receiver, a BAE (Canadian Marconi) Allstar receiver and a Mitel Orion receiver. All of them provide C/A code tracking on the L1 frequency to determine the user position and make use of Doppler measurements to derive the instantaneous velocity. Among the receivers, the G12 has been optimized for use under highly dynamic conditions and has earlier been flown successfully on NASA sounding rockets. The Allstar is representative of common single frequency receivers for terrestrial applications and received no particular modification, except for the disabling of the common altitude and velocity constraints that would otherwise inhibit its use for space application. The Orion receiver, finally, employs the same Mitel chipset as the Allstar, but has received various firmware modifications by DLR to safeguard it against signal losses and improve its tracking performance. While the two NASA receivers were driven by a common wrap-around antenna, the DLR experiment made use of a switchable antenna system comprising a helical antenna in the tip of the rocket and two blade antennas attached to the body of the vehicle. During the boost a peak acceleration of roughly l7g's was achieved which resulted in a velocity of about 1100 m/s at the end of the burn. At apogee, the rocket reached an altitude of over 80 km. A detailed analysis of the attained flight data is given together with a evaluation of different receiver designs and antenna concepts.

Bull, Barton↗

Nanosecond Gated CMOS Camera (NSGCC) ICD (Rev. 2.1)

The Ultra-Fast X-ray Imager (UXI) program is an ongoing effort at Sandia National Laboratories to create high speed, multi-frame, time-gated Read Out Integrated Circuits (ROICs), and a corresponding suite of photodetectors to image a wide variety of High Energy Density (HED) physics experiments on both Sandia’s Z-Machine and LLNL’s National Ignition Facility (NIF). Several cameras have been designed over the length of the program; one of the most recent is the Icarus, which is an improvement on past imagers (Furi and Hippogriff). A second sensor that can be connected is the Daedalus sensor. The Icarus is a 1024 × 512-pixel array with either 25 μm or 8 µm spatial resolution containing four frames of storage per pixel and has improved timing generation and distribution components while achieved 2 ns time gating. The Daedalus sensor is also a 1024 x 512-pixel array with 25 µm special resolution containing three frames of storage per pixel and has an increased set of features for a wider variety of applications from interlacing of rows in each frame to configurability of all shutters. See Section 14 for details regarding the Icarus implementation of the firmware and Section 15 for details regarding the Daedalus implementation. Due to the unique test environments UXI sensors are targeted for, full custom hardware was required to physically mount an Icarus or Daedalus sensor, manage its various functions, and read out pixel data for transfer to a host computer. Beyond experimental functionality, the hardware also needed to accommodate sensor characterization requirements. Lawrence Livermore National Laboratory’s ‘Version 4.0 Board’ was the result of these efforts. It mounts all the components required to fully utilize the Icarus and Daedalus sensors including analog to digital converters to convert pixel data and various system voltages to digital form for readout and analysis, DAC channels for remote configuration of critical bias voltages, static random-access memories to buffer pixel data, RS422 and Gigabit Ethernet communications for remote access, and an FPGA to tie these components together. This document describes the FPGA electrical interfaces in detail to allow the reader a greater understanding of the device, and to facilitate implementation of custom software to control and manage it. The Version 4.0 Board is a continuation of the Nano-second Gated CMOS hardware design that retains much of the functionality of the Version 1.0 Board while adding features including a DAC instead of digital potentiometers, as well as sensors for pressure and radiation. The Version 4.0 board is intended for applications requiring tight form-factor enclosures. It is composed of two stacking boards; one holds the FPGA and regulators to power the various components of the board while the other contains the mating connector to the sensor, image-readoff ADCs, the DAC, and other components.

42 ENGINEERING↗

Flight Performance Evaluation of Three GPS Receivers for Sounding Rocket Tracking

In preparation for the European Space Agency Maxus-4 mission, a sounding rocket test flight was carried out at Esrange,, near Kiruna, Sweden on February 19, 2001 to validate existing ground facilities and range safety installations. Due to the absence of a dedicated scientific payload, the flight offered the opportunity to test multiple GPS receivers and assess their performance for the tracking of sounding rockets. The receivers included an Ashtech G12 HDMA receiver, a BAE (Canadian Marconi) Allstar receiver and a Mitel Orion receiver. All of them provide CIA code tracking on the L1 frequency to determine the user position and make use of Doppler measurements to derive the instantaneous velocity. Among the receivers, the G12 has been optimized for use under highly dynamic conditions and has earlier been flown successfully on NASA sounding rockets [Bull, ION-GPS-2000]. The Allstar is representative of common single frequency receivers for terrestrial applications and received no particular modification, except for the disabling of the common altitude and velocity constraints that would otherwise inhibit its use for space application. The Orion receiver, finally, employs the same Mitel chipset as the Allstar, but has received various firmware modifications by DLR to safeguard it against signal losses and improve its tracking performance [Montenbruck et al., ION-GPS-2000]. While the two NASA receivers were driven by a common wrap-around antenna, the DLR experiment made use of a switchable antenna system comprising a helical antenna in the tip of the rocket and two blade antennas attached to the body of the vehicle. During the boost a peak acceleration of roughly 17g's was achieved which resulted in a velocity of about 1100 m/s at the end of the burn. At apogee, the rocket reached a maximum altitude of over 80 km. A detailed analysis of the attained flight data will be given in the paper together with a evaluation of different receiver designs and antenna concepts.

Bull, Barton↗

Scheduling and Operations of the ECOSTRESS Mission

This paper describes the development and use of an automated scheduling system for the National Aeronautics and Space Administration’s (NASA) ECOsystem Spaceborne Thermal Radiometer Experiment on Space Station (ECOSTRESS) mission. Key to the success of the ECOSTRESS mission has been the use of automated scheduling in mission analysis pre-launch, and in successful operations where automated scheduling was deployed to address several operational challenges. ECOSTRESS uses an adaptation of the Compressed Large-scale Activity Scheduling and Planning (CLASP) system to automatically select science observations respecting area and point target priorities as well as visibility, illumination, onboard storage, and radiation constraints to satisfy high-level prioritized science campaigns. The ECOSTRESS scheduler was used pre-launch to predict the effectiveness of alternative formulations of science campaign definitions accounting for the impact of data volume, keepout, and orbit/illumination/visibility constraints to derive the initial operational science campaign definitions and priorities. The scheduler was then used after instrument checkout for operations. ECOSTRESS has faced multiple operational challenges relating to instrument firmware and hardware, and the scheduler has been updated several times to address these challenges. The instrument Mass Storage Units (MSUs) had operational issues, requiring the scheduler to plan for and schedule commands to handle intricacies of data management. After many months of operations, both MSUs on the instrument became non-functioning and the firmware of the instrument was updated to bypass the MSUs. A further update to the ECOSTRESS scheduler enabled the scheduler to operate in this new operations mode. The ECOSTRESS scheduler has also been updated to improve handling of along-track uncertainty inherent in International Space Station operations. The flexibility and ease of updating of the automated scheduler has been a significant contributor to successful operations of the ECOSTRESS mission.

Padams, Jordan↗

Dynamic Probabilistic Safety Assessment Studies for Advanced Reactor Using RAVEN

Probabilistic Safety Assessment (PSA) is used extensively to evaluate the risks associated with complex engineering systems like Nuclear Power Plants (NPPs). Current PSA models are based on the Event-Tree/Fault-Tree (ET/FT) methodology. ET and FT models are static and are based on Boolean logic approaches. In the past, concerns have been raised in the literature regarding the capability of the traditional static modelling approaches to adequately account for the impact of process, hardware, software, firmware and human interactions on the stochastic system behaviour. To overcome the limitations of the traditional approach to PSA, several dynamic PSA methodologies have been proposed. One of the dynamic PSA methodologies used for dynamic evaluations is Dynamic Event Tree (DET) framework which can be used to assess the impact of the parameter variability and scenario dynamics on the PSA model for the initiating event. The DET framework couples the stochastic model (number of component/trains that start on demand, operator action timing, etc.) with a Thermal-Hydraulic (TH) model of the plant. This paper explores the use of DET along with a case study on advanced reactor. The initiating event selected for the study was Class IV power supply failure event. The TH analysis considering uncertainty in various parameters was performed using RELAP5 and Reactor Analysis and Virtual control ENvironment (RAVEN) tool. Based on the uncertainty analysis, it is concluded that the peak clad temperatures (PCT) are within the limits in all the code runs implying a high-degree of safety margin. However, variation in time to reach the PCT was observed among the code runs and the mean time to reach the PCT was found to be around 8590sec (approximately 2.4 hours). Hence, sufficient time margin is available for human intervention and the operator might have a relatively stress-free state during such an accident scenario. Due to the static nature of the traditional PSA models, the safety margin available was lesser, whereas, with the help of dynamic PSA models, one can demonstrate that the actual available safety margin is more in the present case study and is valuable input from the design point of view.

99 GENERAL AND MISCELLANEOUS↗