Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “proactive scheduling”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

34 records · Page 2

NASA Collaborative Approach Mitigates Environmentally-Driven Obsolescence

National Aeronautics and Space Administration (NASA) missions, like Department of Defense (DoD) organizations, require the rigorous testing and qualification of critical materials. Obsolescence supply risks created by environmental requirements can affect the cost, schedule and performance of NASA missions and the resilience of critical infrastructure. The NASA Technology Evaluation for Environmental Risk Mitigation (TEERM) Principal Center helps to identify obsolescence supply risks driven by environmental requirements and works proactively with NASA Centers and Programs, the DoD, the European Space Agency (ESA) and other agencies and partners to identify and evaluate environmentally friendly alternatives. TEERM tracks environmental regulations, identifies the potential loss of material availability and works with NASA programs and Centers to evaluate potential impacts through a risk assessment approach. TEERM collaborative projects identify, demonstrate and evaluate commercially viable alternative technologies and materials. A major focus during the Space Shuttle Program was the need to replace ozone depleting substances that were used in spray foam and cleaning applications. The potential obsolescence of coatings containing hexavalent chromium and the risks associated with lead free solder were also of concern for the Space Shuttle and present ongoing risks to new programs such as the Space Launch System. One current project teams NASA and ESA in the evaluation and testing of individual coatings and coating systems as replacements for hexavalent chromium coatings in aerospace applications. The proactive, collaborative approach used by TEERM helps reduce the cost burden on any one team partner, reduces duplication of effort, and enhances the technical quality and overall applicability of the testing and analysis.

environmentall-driven obsolescence↗

Optimizing Information Automation Using a New Method Based on System-Theoretic Process Analysis: Tool Development and Method Evaluation

This report is an update to a prior report that describes progress and findings for a program of research supporting the design and optimization of information automation systems for nuclear power plants. Much of the domestic nuclear fleet is currently focused on modernizing technologies and processes, including transitioning toward digitalization in the control room and throughout the plant, along with a greater interest in the use of automation, artificial intelligence, robotics, and other emerging technologies. While there are significant opportunities to apply these technologies toward greater plant safety, efficiency, and overall cost-effectiveness, optimizing their design and avoiding potential safety and performance risks depends on ensuring that human performance-related organizational and technical design issues are identified and addressed early in the design process. This report describes modeling tools and techniques, based on sociotechnical systems theory, to support these design goals and their application in the current research effort. The report is primarily intended for senior nuclear energy stakeholders, including regulators, corporate management, and senior plant management. We have developed and employed a method to design an optimized information automation ecosystem (IAE) based on the systems-theoretic constructs underlying sociotechnical systems theory in general and the Systems-Theoretic Accident Modeling and Processes (STAMP) approach in particular. We argue that an IAE can be modeled as an interactive information control system whose behavior can be understood in terms of dynamic control, feedback, and communication relationships amongst the system’s technical and organizational components. We have employed two STAMP-based tools in this effort. The first is Causal Analysis based on STAMP (CAST), an accident and incident analysis technique that was used to examine a performance- and safety-related incident at an industry partner’s plant involving the unintentional activation of an emergency diesel generator. This analysis provided insight into the behavior of the plant’s current information control structure within the context of a specific, significant event. The second tool is Systems Theoretic Process Analysis (STPA) which is a proactive risk analysis tool used to examine existing and potential, planned sociotechnical systems. STPA was used to identify risk factors in the current design of a generic nuclear power plant (NPP) preventive maintenance system. Our analyses focused on identifying near-term system improvements and longer-term design requirements for an optimized IAE system. CAST analysis findings indicate an important underlying contributor to the incident under investigation, and a significant risk to information automation system performance, was perceived time and schedule pressure, which exposed weaknesses in interdepartmental coordination between and within responsible plant organizations and challenged the resilience of established plant processes, until a human caused the eventual event. These findings are discussed in terms of their risk to overall system performance and their implications for information automation system resilience and brittleness. STPA findings exposed several areas of concern in the design of current preventive maintenance systems. We also present two preliminary information automation models. The proactive issue resolution (PIR) model is a test case of an information automation concept with significant near-term potential for application and subsequent reduction in significant plant events. The IAE model is a more general representation of a broader, plantwide information automation system and represents an end-state vision for our work. From our results, we have generated an initial set of preliminary system-level requirements and safety constraints for these models. We have also focused on early development of easy to learn, easy to use “transportable” tools for sociotechnical systems analysis. We intend these to be used by NPP personnel as a means of gaining reliable and relatively quick insight into (1) sociotechnical systems factors impacting incidents and accidents, (2) potential sociotechnical risk factors in existing or planned system designs, and (3) potential weaknesses in a system’s safety and/or information control structure. We conclude the report with a set of summary recommendations, a discussion of planned and potential follow-on research and development, and a draft list of system-level requirements and safety constraints for optimized information automation systems.

99 GENERAL AND MISCELLANEOUS↗

Risk-Informed Decision Making: Application to Technology Development Alternative Selection

NASA NPR 8000.4A, Agency Risk Management Procedural Requirements, defines risk management in terms of two complementary processes: Risk-informed Decision Making (RIDM) and Continuous Risk Management (CRM). The RIDM process is used to inform decision making by emphasizing proper use of risk analysis to make decisions that impact all mission execution domains (e.g., safety, technical, cost, and schedule) for program/projects and mission support organizations. The RIDM process supports the selection of an alternative prior to program commitment. The CRM process is used to manage risk associated with the implementation of the selected alternative. The two processes work together to foster proactive risk management at NASA. The Office of Safety and Mission Assurance at NASA Headquarters has developed a technical handbook to provide guidance for implementing the RIDM process in the context of NASA risk management and systems engineering. This paper summarizes the key concepts and procedures of the RIDM process as presented in the handbook, and also illustrates how the RIDM process can be applied to the selection of technology investments as NASA's new technology development programs are initiated.

Dezfuli, Homayoon↗

Emergency Preparedness for Catastrophic Events at Small and Medium Sized Airports: Lacking or Not?

The implementation of security methods and processes in general has had a decisive impact on the aviation industry. However, efforts to effectively coordinate varied aspects of security protocols between agencies and general aviation components have not been adequately addressed. Whether or not overall security issues, especially with regard to planning for catastrophic terrorist events, have been neglected at the nation's smaller airports is the main topic of this paper. For perspective, the term general aviation is generally accepted to include all flying except for military and scheduled airline operations. Genera aviation makes up more than 1 percent of the U.S. Gross Domestic Product and supports almost 1.3 mission high-skilled jobs in professional services and manufacturing and hence is an important component of the aviation industry (AOPA, n.d.). In both conceptual and practical terms, this paper argues for the proactive management of security planning and repeated security awareness training from both an individual and an organizational perspective within the general aviation venue. The results of a research project incorporating survey data from general aviation and small commercial airport managers as well as Transportation Security Administration (TSA) employees are reported. Survey findings suggest that miscommunication does take place on different organizational levels and that between TSA employees and airport management interaction can be contentious and cooperation diminished. The importance of organizational training for decreasing conflict and increasing security and preparedness is discussed as a primary implication.

Sweet, Kathleen M.↗

Light Water Sustainability Program: Optimizing Information Automation Using a New Method Based on System-Theoretic Process Analysis

This report describes the interim progress for research supporting the design and optimization of information automation systems for nuclear power plants. Much of the domestic nuclear fleet is currently focused on modernizing technologies and processes, including transitioning toward digitalization in the control room and elsewhere throughout the plant, along with a greater use of automation, artificial intelligence, robotics, and other emerging technologies. While there are significant opportunities to apply these technologies toward greater plant safety, efficiency, and overall cost-effectiveness, optimizing their design and avoiding potential safety and performance risks depends on ensuring that human-performance-related organizational and technical design issues are identified and addressed. This report describes modeling tools and techniques, based on sociotechnical system theory, to support these design goals and their application in the current research effort. The report is intended for senior nuclear energy stakeholders, including regulators, corporate management, and senior plant management. We have developed and employed a method to design an optimized information automation ecosystem (IAE) based on the systems-theoretic constructs underlying sociotechnical systems theory in general and the Systems-Theoretic Accident Modeling and Processes (STAMP) approach in particular. We argue that an IAE can be modeled as an interactive information control system whose behavior can be understood in terms of dynamic control and feedback relationships amongst the system’s technical and organizational components. Up to this point, we have employed a Causal Analysis based on STAMP (CAST) technique to examine a performance- and safety-related incident at an industry partner’s plant that involved the unintentional activation of an emergency diesel generator. This analysis provided insight into the behavior of the plant’s current information control structure within the context of a specific, significant event. Our ongoing analysis is focused on identifying near-term process improvements and longer-term design requirements for an optimized IAE system. The latter analyses will employ a second STAMP-derived technique, System-Theoretic Process Analysis (STPA). STPA is a useful modeling tool for generating and analyzing actual or potential information control structures. Finally, we have begun modeling plantwide organizational relationships and processes. Organizational system modeling will supplement our CAST and STPA findings and provide a basis for mapping out a plantwide information control architecture. CAST analysis findings indicate an important underlying contributor to the incident under investigation, and a significant risk to information automation system performance, was perceived schedule pressure, which exposed weaknesses in interdepartmental coordination between and within responsible plant organizations and challenged the resilience of established plant processes, until a human caused the initiating event. These findings are discussed in terms of their risk to overall system performance and their implications for information automation system resilience and brittleness. We present two preliminary information automation models. The proactive issue resolution model is a test case of an information automation concept with significant near-term potential for application and subsequent reduction in significant plant events. The IAE model is a more general representation of a broader, plantwide information automation system. From our results, we have generated a set of preliminary system-level requirements and safety constraints. These requirements will be further developed over the remainder of our project in collaboration with nuclear industry subject matter experts and specialists in the technical systems under consideration. Additionally, we will continue to pursue the system analyses initiated in the first part of our effort, with a particular emphasis on STPA as the main tool to identify weak or weakening control structures that affect the resilience of organizations and programs. Our intent is to broaden the scope of the analysis from an individual use case to a related set of use cases (e.g., maintenance tasks, compliance tasks) with similar human-system performance challenges. This will enable more generalized findings to refine the Proactive Issue Resolution and IAE models, as well as their system-level requirements and safety constraints. We will use organizational system modeling analyses to supplement STPA findings and model development. We conclude the report with a set of summary recommendations and an initial draft list of system-level requirements and safety constraints for optimized information automation systems.

99 GENERAL AND MISCELLANEOUS↗

Why Don't They Just Give Us Money? Project Cost Estimating and Cost Reporting

Successful projects require an integrated approach to managing cost, schedule, and risk. This is especially true for complex, multi-year projects involving multiple organizations. To explore solutions and leverage valuable lessons learned, NASA's Virtual Project Management Challenge will kick off a three-part series examining some of the challenges faced by project and program managers when it comes to managing these important elements. In this first session of the series, we will look at cost management, with an emphasis on the critical roles of cost estimating and cost reporting. By taking a proactive approach to both of these activities, project managers can better control life cycle costs, maintain stakeholder confidence, and protect other current and future projects in the organization's portfolio. Speakers will be Doug Comstock, Director of NASA's Cost Analysis Division, Kristin Van Wychen, Senior Analyst in the GAO Acquisition and Sourcing Management Team, and Mary Beth Zimmerman, Branch Chief for NASA's Portfolio Analysis Branch, Strategic Investments Division. Moderator Ramien Pierre is from NASA's Academy for Program/Project and Engineering Leadership (APPEL).

Comstock, Douglas A.↗

Evaluating and Addressing Potential Hazards of Fuel Tanks Surviving Atmospheric Reentry

In order to ensure reentering spacecraft do not pose an undue risk to the Earth's population it is important to design satellites and rocket bodies with end of life considerations in mind. In addition to considering the possible consequences of deorbiting a vehicle, consideration must also be given to the possible risks associated with a vehicle failing to become operational or reach its intended orbit. Based on recovered space debris and numerous reentry survivability analyses, fuel tanks are of particular concern in both of these considerations. Most spacecraft utilize some type of fuel tank as part of their propulsion system. These fuel tanks are most often constructed using stainless steel or titanium and are filled with potentially hazardous substances such as hydrazine and nitrogen tetroxide. For a vehicle which has reached its scheduled end of mission the contents of the tanks are typically depleted. In this scenario the use of stainless steel and titanium results in the tanks posing a risk to people and property do to the high melting point and large heat of ablation of these materials leading to likely survival of the tank during reentry. If a large portion of the fuel is not depleted prior to reentry, there is the added risk of hazardous substance being released when the tank impact the ground. This paper presents a discussion of proactive methods which have been utilized by NASA satellite projects to address the risks associated with fuel tanks reentering the atmosphere. In particular it will address the design of a demiseable fuel tank as well as the evaluation of off the shelf designs which are selected to burst during reentry.

Kelley, Robert L.↗

Risk Management for the International Space Station

The International Space Station (ISS) is an extremely complex system, both technically and programmatically. The Space Station must support a wide range of payloads and missions. It must be launched in numerous launch packages and be safely assembled and operated in the harsh environment of space. It is being designed and manufactured by many organizations, including the prime contractor, Boeing, the NASA institutions, and international partners and their contractors. Finally, the ISS has multiple customers, (e.g., the Administration, Congress, users, public, international partners, etc.) with contrasting needs and constraints. It is the ISS Risk Management Office strategy to proactively and systematically manages risks to help ensure ISS Program success. ISS program follows integrated risk management process (both quantitative and qualitative) and is integrated into ISS project management. The process and tools are simple and seamless and permeate to the lowest levels (at a level where effective management can be realized) and follows the continuous risk management methodology. The risk process assesses continually what could go wrong (risks), determine which risks need to be managed, implement strategies to deal with those risks, and measure effectiveness of the implemented strategies. The process integrates all facets of risk including cost, schedule and technical aspects. Support analysis risk tools like PRA are used to support programatic decisions and assist in analyzing risks.

Sebastian, J.↗

The New Millenium Program: Serving Earth and Space Sciences

NASA has exciting plans for space science and Earth observations during the next decade. A broad range of advanced spacecraft and measurement technologies will be needed to support these plans within the existing budget and schedule constraints. Many of these technology needs are common to both NASA's Office of Earth Science (OES) and Office of Space Sciences (OSS). Even though some breakthrough technologies have been identified to address these needs, project managers have traditionally been reluctant to incorporate them into flight programs because their inherent development risk. To accelerate the infusion of new technologies into its OES and OSS missions, NASA established the New Millennium Program (NMP). This program analyzes the capability needs of these enterprises, identifies candidate technologies to address these needs, incorporates advanced technology suites into validation flights, validates them in the relevant space environment, and then proactively infuses the validated technologies into future missions to enhance their capabilities while reducing their life cycle cost. The NMP employs a cross-enterprise Science Working Group, the NASA Enterprise science and technology roadmaps to define the capabilities needed by future Earth and Space science missions. Additional input from the science community is gathered through open workshops and peer-reviewed NASA Research Announcement (NRAs) for advanced measurement concepts. Technology development inputs from the technology organizations within NASA, other government agencies, federally funded research and development centers (FFRDC's), U.S. industry, and academia are sought to identify breakthrough technologies that might address these needs. This approach significantly extends NASA's technology infrastructure. To complement other flight test programs that develop or validate of individual components, the NMP places its highest priority on system-level validations of technology suites in the relevant space environment. This approach is not needed for all technologies, but it is usually essential to validate advanced system architectures or new measurement concepts. The NMP has recently revised its processes for defining candidate validation flights, and selecting technologies for these flights. The NMP now employs integrated project formulation teams, 'Which include scientists, technologists, and mission planners, to incorporate technology suites into candidate validation flights. These teams develop competing concepts, which can be rigorously evaluated prior to selection for flight. The technology providers for each concept are selected through an open, competitive, process during the project formulation phase. If their concept is selected for flight, they are incorporated into the Project Implementation Team, which develops, integrates, tests, launches, and operates the technology validation flight. Throughout the project implementation phase, the Implementation Team will document and disseminate their validation results to facilitate the infusion of their validated technologies into future OSS and OES science missions. The NMP has successfully launched its first two Deep Space flights for the OSS, and is currently implementing its first two Earth Orbiting flights for the OES. The next OSS and OES flights are currently being defined. Even though these flights are focused on specific Space Science and Earth Science themes, they are designed to validate a range of technologies that could benefit both enterprises, including advanced propulsion, communications, autonomous operations and navigation, multifunctional structures, microelectronics, and advanced instruments. Specific examples of these technologies will be provided in our presentation. The processes developed by the NMP also provide benefits across the Space and Earth Science enterprises. In particular, the extensive, nation-wide technology infrastructure developed by the NMP enhances the access to breakthrough technologies for both enterprises.

Li, Fuk K.↗

Connecting the Dots: An Assessment of Cyber-risks in Networked Building and Municipal Infrastructure Systems

The buildings and city streets we walk down are changing. Driven by various data-driven use cases, there is increased interest in networking and integrating lighting and other building systems (e.g., heating, ventilation, and air conditioning (HVAC), security, scheduling) that were previously not internet-facing, and equipping them with sensors that collect information about their environment and the people that inhabit it. These data-enabled systems can potentially deliver improved occupant and resident experiences and help meet the U.S. Department of Energy (DOE) national energy and carbon reduction goals. Deploying connected devices new to being networked, however, is not without its challenges. This paper explores tools available to system designers and integrators that facilitate a cybersecurity landscape assessment – or more specifically the identification of threats, vulnerabilities, and adversarial behaviors that could be used against these networked systems. These assessments can help stakeholders shift security prioritization proactively toward the beginning of the development process.

cyber-risk assesment, adversarial behavior, MITRE ↗

A Markov Decision Process Framework for Optimal Airport Reconfiguration

The airport runway configuration is defined as a combination set of runways for arrivals and departures used at a point during operation of the airport. An optimal configuration of these runways depends on a number of factors, including traffic demand, wind magnitude and direction, other adverse weather conditions, and noise restrictions, among others. Based on the current state of these factors and predictions of traffic demand and weather conditions, runway configuration changes are made and coordinated between tower controller, other air traffic control facilities, pilots, and ground personnel. Reconfigurations can be quite disruptive to airport operations; minimizing their frequency and scheduling them well in advance is essential for mitigating some of the added workload for controllers and pilots. Unfortunately, deciding on an appropriate time to change is challenging for human decision makers. Not only do multiple factors need to be evaluated, but the uncertainty in their forecasts must also be considered. Previous optimization methods, such as mixed linear integer programming, have been proposed. Although these methods can reason over a large set of variables, they do not systematically handle the uncertainty associated with weather movement, traffic demands, and other variables. In this work, we introduce a Markov Decision Process (MDP)-based decision making framework which can reason effectively over the inherent uncertainties and make optimal decisions on if/when to change the airport configuration. In a prototype implementation, we present a single runway with three aircraft and utilize knowledge of the forecasted wind speed and direction to determine whether to keep or change the current runway configuration. Our aim through this work is to present a framework for airport reconfiguration which can be scalable to additional aircraft, multiple runways, and various input parameters. This technique will optimize the airport reconfiguration procedure by providing a proactive approach, optimizing not just at the next optimal opportunity for a reconfiguration based on varying atmospheric and traffic conditions in the terminal airspace, but also anticipating future necessary reconfigurations. This will eliminate the inefficiencies of frequent changes currently associated with runway reconfiguration procedures.

runway reconfiguration↗

NASA System Safety Handbook: System Safety Framework and Concepts for Implementation - Volume 1

System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual basis but to consider measures of aggregate safety risk and to ensure wherever possible that there be quantitative measures for evaluating how effective the controls are in reducing these aggregate risks. The term aggregate risk, when used in this handbook, refers to the accumulation of risks from individual scenarios that lead to a shortfall in safety performance at a high level: e.g., an excessively high probability of loss of crew, loss of mission, planetary contamination, etc. Without aggregated quantitative measures such as these, it is not reasonable to expect that safety has been optimized with respect to other technical and programmatic objectives. At the same time, it is fully recognized that not all sources of risk are amenable to precise quantitative analysis and that the use of qualitative approaches and bounding estimates may be appropriate for those risk sources. Second, the handbook stresses the necessity of developing confidence that the controls derived for the purpose of achieving system safety not only handle risks that have been identified and properly characterized but also provide a general, more holistic means for protecting against unidentified or uncharacterized risks. For example, while it is not possible to be assured that all credible causes of risk have been identified, there are defenses that can provide protection against broad categories of risks and thereby increase the chances that individual causes are contained. Third, the handbook strives at all times to treat uncertainties as an integral aspect of risk and as a part of making decisions. The term "uncertainty" here does not refer to an actuarial type of data analysis, but rather to a characterization of our state of knowledge regarding results from logical and physical models that approximate reality. Uncertainty analysis finds how the output parameters of the models are related to plausible variations in the input parameters and in the modeling assumptions. The evaluation of unrtainties represents a method of probabilistic thinking wherein the analyst and decision makers recognize possible outcomes other than the outcome perceived to be "most likely." Without this type of analysis, it is not possible to determine the worth of an analysis product as a basis for making decisions related to safety and mission success. In line with these considerations the handbook does not take a hazard-analysis-centric approach to system safety. Hazard analysis remains a useful tool to facilitate brainstorming but does not substitute for a more holistic approach geared to a comprehensive identification and understanding of individual risk issues and their contributions to aggregate safety risks. The handbook strives to emphasize the importance of identifying the most critical scenarios that contribute to the risk of not meeting the agreed-upon safety objectives and requirements using all appropriate tools (including but not limited to hazard analysis). Thereafter, emphasis shifts to identifying the risk drivers that cause these scenarios to be critical and ensuring that there are controls directed toward preventing or mitigating the risk drivers. To address these and other areas, the handbook advocates a proactive, analytic-deliberative, risk-informed approach to system safety, enabling the integration of system safety activities with systems engineering and risk management processes. It emphasizes how one can systematically provide the necessary evidence to substantiate the claim that a system is safe to within an acceptable risk tolerance, and that safety has been achieved in a cost-effective manner. The methodology discussed in this handbook is part of a systems engineering process and is intended to be integral to the system safety practices being conducted by the NASA safety and mission assurance and systems engineering organizations. The handbook posits that to conclude that a system is adequately safe, it is necessary to consider a set of safety claims that derive from the safety objectives of the organization. The safety claims are developed from a hierarchy of safety objectives and are therefore hierarchical themselves. Assurance that all the claims are true within acceptable risk tolerance limits implies that all of the safety objectives have been satisfied, and therefore that the system is safe. The acceptable risk tolerance limits are provided by the authority who must make the decision whether or not to proceed to the next step in the life cycle. These tolerances are therefore referred to as the decision maker's risk tolerances. In general, the safety claims address two fundamental facets of safety: 1) whether required safety thresholds or goals have been achieved, and 2) whether the safety risk is as low as possible within reasonable impacts on cost, schedule, and performance. The latter facet includes consideration of controls that are collective in nature (i.e., apply generically to broad categories of risks) and thereby provide protection against unidentified or uncharacterized risks.

Dezfuli, Homayoon↗

Cleanroom Contamination Identification Method Development

During fabrication, assembly, and testing of spacecraft and flight hardware it is vital to avoid contaminants that can cause degradation and could result in significant failure. Yet, there is no existing contamination monitoring method that provides the identity of airborne particles in a cleanroom facility. Knowing the particle identities, would allow scientists and engineers to determine the source of the contaminants and prevent setbacks before they occur or cause damage. Current cleanliness monitoring methods include airborne particle counters (APCs), fallout filters, and visual inspections. Particle counts from APCs are the primary metric used to define a cleanroom class and hence its level of cleanliness, but do not provide identification nor can they differentiate between large and small sizes of particles. In addition, using fallout filters is not a proactive, timely, or representative approach to cleanroom contamination monitoring because these samples are only retrieved after 30 days and are placed away from spacecraft processing to avoid interference with operations. In contrast, the forced air sampling method can collect a sample within an hour at any location required and provide results in less than a day. This system uses a cassette and filter sample medium to capture airborne particles which are then taken to a scanning electron microscope with energy dispersive spectroscopy (SEM/EDS) to identify and size the captured particles. Development of forced air sampling into an established laboratory capability will allow for fast sampling and routine identification of unknown contamination sources within the cleanroom. The test method development required market research for an air sampling cassette that increases sample collection efficiency and a filter with low enough background contamination to allow differentiation between a blank (control) and the collected sample. It was determined that a conductive black cassette and a polycarbonate filter were the best options. Conductive black cassettes, in comparison to the standard styrene, are manufactured using polypropylene filled with carbon. This makes the cassette conductive and minimizes the tendency of particles to stick to the wall of the cassette due to electrostatic force. In previous trials a mixed cellulose ester (MCE) filter was used to capture the contaminants, however the rougher surface of the filter contributed to entrapment of the particles within the filter structure and made it harder to identify the particles. In comparison, track etched polycarbonate filters have random cylindrical pores and a smooth surface which contributes to uniform sample distribution on the surface of the filter. Future work includes: testing the system using control samples to determine the efficiency and suitability of the medium, performing sample collection in various environments to establish ideal operating parameters and analyzing contaminant particles using SEM/EDS and assistant characterization techniques. Once fully developed, employing the forced air sampling method will help to prevent damage to spacecraft, avoid schedule delays, and allow for mission success.

Hernandez Melendez, Jailyn M.↗

Accelerated Materials Deployment in Advanced Nuclear Power Plants

The purpose of this report is to begin the development of a maximally efficient process for licensing and deploying new materials in Advanced Non-Light-Water Reactors (ANLWRs). Some new materials that are to be used in some new plants are seen as possibly introducing risks, because our understanding of those new materials’ behavior in the conditions generated by some novel plant designs is less complete than our understanding of the behavior of materials with long use histories in existing designs. In these cases, an approved code/standard or a code case to support the use of these materials in the novel design’s safety case may not exist for the regulator to utilize as part of the licensing determination. This circumstance creates the potential for an extremely long licensing process for new designs using new materials. The present strategy is to show how to manage these risks proactively, in such a way as to permit licensing decisions to be made in a timely manner, based on this risk management process. The present report outlines the gaps in the current codes to support deployment and use of novel materials and begins the development of the necessary risk management framework that is focused on the subject materials issues; it is based on risk-informed in-service surveillance practices, carried out in such a way as to compensate for current limitations in our state of knowledge. This development will enable licensing and deployment of the subject materials, conditional on the proactive surveillance process to be established. While this report is occasioned by limitations in our knowledge of certain materials issues that may arise in advanced designs, in-service surveillance is always done in order to compensate for a lack of knowledge: if we knew that components were not already failed and not trending toward failure, we would not perform surveillance, even in current-generation plants (except that prescriptive requirements would force us to do so). What is different about the surveillance program discussed here is that the issues are newer and the relevant experience base is less complete, so the surveillance presently contemplated may need to measure new things and/or measure them more often than has been traditional for surveillance coupons. The present report is devoted to the risk management framework and applies American Society of Mechanical Engineers Boiler and Pressure Vessel Code Section XI, Division [1] to establish the structure of a protocol for carrying out the necessary surveillance. These documents are generic: they do not tell us how often to surveille, or what to surveille, or what to measure, but rather how to determine those things, given certain technical inputs. The Regulatory Development R&D Program [2] is currently developing the companion supporting technical basis for the materials surveillance technology that, when completed and validated, can be used by owner/operator and NRC to implement a materials degradation management program for ANLWRs. This report also outlines salient points of discussion, positive potential outcomes, and potential concerns from industry and the USNRC. These aspects of the report intend to inform future work to develop a proposed technical process for adoption by the industry and endorsement by the USNRC to allow developers to propose a risk informed and conservative approach for the use of materials where operating experience/data and codes and standards may not exist for use of a novel material in an operating reactor environment. Additionally, such a technology could be leveraged to potentially reduce part of the upfront materials data requirements from ongoing long-term materials testing so that early action on license application could be undertaken by NRC, in parallel with the continuation of long-term data collection. This could accelerate the schedule for a first-of-a-kind ANLWR deployment or a nth-of-a-kind new materials insertion for established ANLWR designs.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Concept of Operations for Management by Trajectory

This document describes Management by Trajectory (MBT), a concept for future air traffic management (ATM) in which every flight operates in accordance with a four-dimensional trajectory (4DT) that is negotiated between the airspace user and the Federal Aviation Administration (FAA) to respect the airspace user's goals while complying with National Airspace System (NAS) constraints. In the present-day NAS, the ATM system attempts to predict the trajectory for each flight based on the approved flight plan and scheduled or controlled departure time. However, once the aircraft starts to move, controllers tactically manage the aircraft to implement traffic management restrictions, separate otherwise conflicting aircraft, and address arising NAS constraints. Tactical controller actions are not directly communicated to the automation systems or other stakeholders. Furthermore, the initial trajectory prediction does not anticipate these disruptions or how they will impact the flight. Consequently, and compounded by gaps in required data and models, trajectory predictions are less accurate than possible, which affects Traffic Flow Management (TFM) performance. A cornerstone of the MBT concept is that all air vehicles have, at all times, an assigned 4DT from their current state to their destination. These assigned trajectories consist of trajectory constraints and descriptions. Pilots and air traffic controllers, with the aid of automation, operate the aircraft to comply with the assigned trajectory, unless first negotiating a revision. Equipped aircraft have substantial responsibility for complying with the assigned trajectory without controller intervention. To maximize the operational flexibility available to the airspace user, the assigned trajectory only imposes trajectory constraints as required to achieve the ATM goals of NAS constraint compliance and aircraft separation. Trajectory descriptions are added to the assigned trajectory to ensure sufficient predictability. To further improve trajectory prediction accuracy, airspace users supplement the assigned trajectory by broadcasting intent information and updating it as necessary. Air vehicle intent is a more detailed description of the airspace user's plan for how the flight will fly the assigned trajectory. Air vehicle intent can change freely, without negotiation, as long as it remains in compliance with the assigned trajectory. Aircraft assigned trajectories, air vehicle intent, and predicted trajectories are shared, creating a common view among stakeholders. A NAS Constraint Service gathers and publishes information about all known NAS constraints, enabling airspace users to be informed participants in trajectory negotiation. Trajectory constraints in the assigned trajectory are mapped to NAS constraints to facilitate identifying which aircraft are affected when NAS constraints change. To support efficient trajectory negotiation, all aircraft provide current information about air vehicle capabilities. Assigned trajectories are constructed to satisfy all known NAS constraints, improving trajectory stability and predictability. Uncertainty and disruptions are handled by modifying the assigned trajectory as far in advance as possible. By proactively negotiating changes to the assigned trajectory, rather than relying on controller-selected tactical actions such as vectors to resolve traffic conflicts or implement miles-in-trail restrictions, MBT keeps aircraft on closed trajectories that are fully known to all stakeholders. Since reactive air traffic control actions cannot be predicted in advance, the downstream trajectory cannot be accurately predicted until they happen. Reliable trajectory predictions allow the system to identify needed modifications to trajectories further in advance, where they can be negotiated and communicated as amendments (i.e., additional or altered trajectory constraints) to the assigned trajectory. Decision Support Tools (DSTs) aid controllers in rapidly defining and communicating closed trajectories to the aircraft and support all stakeholders in trajectory negotiation. Anticipated MBT benefit mechanisms include more accurate trajectory predictions, improved ATM performance and robustness to off-nominal conditions, increased flexibility and operational efficiency, reduced impediments to emerging classes of airspace users accessing NAS resources, reduced environmental impacts, and enhanced safety.

ConOps↗

A Machine Learning Approach to Improve Air Traffic Management Initiatives

Collaborating closely with commercial air carriers and related organizations, the Federal Aviation Administration(FAA) regulates air traffic and ensures the safety and efficiency of air operations. Air traffic controllers make strategic decisions, such as delaying, rerouting, or canceling flights, partly based on guidance provided by the FAA’s Air TrafficControl System Command Center (ATCSCC). The guidance includes, among other things, control measures known asTraffic Management Initiatives (TMIs) designed to enhance safety and improve operational efficiency. TMIs play a crucial role in managing the demand and capacity within the U.S. National Airspace System (NAS). Two major TMIs that are routinely used (primarily to mitigate the adverse effects of bad weather) are Ground Delay Programs (GDPs) andGround Stops (GSs). In a GDP, flights destined for airports facing thunderstorm activity experience delays at their origin airports. This proactive approach minimizes the risk of routing aircraft through hazardous weather conditions and also replaces (fuel burning) airborne delays with ground delays. In a GS, a temporary restriction is imposed on the departure or arrival of aircraft at a specific airport or within a designated airspace. Although other TMIs (e.g., miles-in-trail) are also implemented as part of (air) traffic flow management in the NAS, the focus of this work is on GDPs and GSs. Since TMIs, by design, lead to flight delays or cancellations, it is crucial to put in place the right set of parameters(e.g., scope and duration of the GDP). For example, when the end time of a GDP extends beyond what is necessary, it imposes unnecessary delays on departing flights. This situation could occur as a result of inaccurate prediction of the(required) duration of the GDP based on the weather forecast. On the other hand, if a GDP ends prematurely before the underlying capacity constraints are resolved at the destination airport, it may result in airborne holding. The delicate balance lies in matching the termination of the GDP precisely with the resolution of capacity constraints, avoiding both the imposition of unnecessary ground delays and the need for airborne holding due to premature program termination.Failing to specify the right parameters for TMIs also leads to flight delays, creating a significant obstacle in managing the increasing traffic volumes causing increased work load for the controllers. To address this issue, we propose the integration of Machine Learning (ML) models in the traffic flow management(TFM) pipeline. In current operations, decisions are made by human experts based on extensive training, historical patterns, available traffic and weather data. Since we have an abundance of data from past events that tell us the likely impact of various TMIs, by ingesting historical data, properly trained ML models can offer valuable insights and aid human decision-making. With the FAA increasingly exploring advanced analytics, ML emerges as a focal point for enhancing TFM within the National Airspace System (NAS). As a first step, this study aims to provide traffic controllers with decision-making support for the issuance and adjustment of TMIs. Data analytics and machine learning have been previously employed to address some of the challenges associated with TMIs. Numerous studies have concentrated on various facets of TMI issuance, exploring factors influencing TMI parameters, including arrival rate, airport capacity, and delay prediction. For example, using weather forecasts, several statistical methods were used to produce probabilistic capacity profiles which in conjunction with deterministic models provided insights into the GDP planning process [1–4]. The downside of using deterministic models is that they rely on fixed inputs and predetermined rules, which lack the ability to account for the inherent uncertainty and variability present in real-world scenarios. In a separate series of studies, researchers aimed to predict the occurrences of GDPs and GSs. The majority of these studies utilized various supervised learning methods, including Decision Trees, Naive Bayes, Support VectorMachines, and Random Forests to analyze the influence of weather conditions and arrival demand on TMI incidents[5–8]. However, these studies primarily focused on predicting the incidence of TMIs without explicitly addressing the scope of TMIs, including their duration and their geographical coverage. Furthermore, the emphasis of these studies was largely on GDPs, given their higher frequency and longer duration when compared to GSs. A limited number of studies focused on predicting the parameters of TMIs, specifically addressing their duration and extent. In one such study focusing on optimizing the TMI parameters at San Francisco International Airport (SFO),the authors utilized a probabilistic forecast of fog [9]. They simulated various capacity scenarios based on the (fog)burn-off forecasts, selecting GDP parameters that minimized airborne and overall ground delays. However, this approach exclusively emphasizes stratus (fog) burn-off as the primary determinant of GDP and GS, neglecting other influential factors like severe weather events, runway closures, lower capacity than traffic demand, and other important variables. Given the complexity of predicting the TMI and determining its scope, we seek a more holistic approach. We aim to consider all significant factors that could impact TMIs and their parameters. What sets this research apart is the fusion of all data sources relevant to the issuance and adjustment of TMIs and it represents the first comprehensive attempt to optimize TMIs in this manner. Since this comprehensive solution involves various aspects, we break down the problem into smaller components and input all parameters into a unified model called the “TMI Adjuster”. Figure 1 shows the overall framework and the list of datasets used in each model. The objective of the TMI Adjuster module is to deliver reliable, consistent and expedited recommendations for the progression, adjustment, and termination of TMIs. The ML solution entails developing a pipeline capable of predicting the necessity of a TMI (e.g., GS or GDP) along with its various parameters. For example, in the case of a GS, this includes the scope of the GS either in terms of distance from the destination airport or based on pre-defined airspace sectors. Here, scope refers to those regions and departing airports that are subject to the GS. In this paper, we concentrate on the issuance of GSs in the three major airports in the New York area — LaGuardia(LGA), John F. Kennedy International (JFK), and Newark Liberty International (EWR). We fuse traffic, weather and other relevant aviation data from years 2017 to 2019 to train and validate the ML models. In particular, we use the following datasets: •Terminal Aerodrome Forecast (TAF): meteorological forecasts specific to each airport, issued four times a day, covering predefined time periods. •TMI data: includes all GSs and GDPs along with their respective parameters. •Aviation System Performance Metrics (ASPM): includes traffic related data such as aircraft delays, arrival, and departure rates. •Notices to Airmen (NOTAMs): utilized to extract runway closure data and manage interdependencies between terminals in close proximity. •Flight cancellation data •Airspace Flow Programs (AFP): includes information on flight airborne holdings caused by TMIs. The data preprocessing entails transforming ASPM, TMI, AFP, NOTAMs, and weather data into an hourly format and consolidating all datasets by merging them based on date and time as the primary key. The TMI Adjuster framework comprises two parallel models: one dedicated to GS and a second model focused on GDP. As previously mentioned, our specific focus is on the GS model as a multi-classification problem. In this framework, each data point of the GS model input summarizes ten hours of data. Specifically, the data loader for the GS model generates the input and output of the model as follows: at a given time step, the input includes the actual traffic, weather, and TMI data from the two-hour window before the time step, alongside the weather forecast and scheduled traffic for the next 8 hours starting from the time step. Based on this information, the output of the GS model for each time interval consists of three dimensions. The first dimension represents a binary decision on whether there should be a GS in place for the next hour or not. The second dimension is related to the scope of the GS in the United States, and the third dimension is related to the scope of the GS in Canada (i.e., to determine if the GS impacts airports in Canada).One of the challenges with TMI modeling is the sparsity of TMI events, particularly regarding its scope. To address this challenge in the scope of the GS model output, we implement grouping. The GS scope for the US region is defined based on a list of centers that should be included when the GS is in place. With 20 centers in the US, we utilized historical data to group them into 4 categories. In particular, we summarized our historical data in a graph format where nodes represent centers, and link weights are defined based on the co-occurrence of centers in the scope parameter ofTMIs. By identified strongly connected components in this graph, we were able to partition the centers into four groups. We consider two model structures for the GS Model. Firstly, a hierarchical classification model [10], where the human decision-making for a GS is of hierarchical nature. The decision-maker first decides whether there is a need fora GS, and if the answer is yes, determines the scope. A hierarchical classification model organizes the problem into a class hierarchy, typically a tree or a Directed Acyclic Graph (DAG) structure, and considers the dependency of the decision in the previous step to the next component [10]. Here, we employ the local classifier per level approach, which involves training one multi-class classifier for each level of the class hierarchy. The second structure is the independent structure. In this setting, as the name suggests, we do not consider the dependency of the decisions in the different dimensions of the output of the model. Instead, for each dimension, we train a multi-class classifier independently. Table 1 summarizes GS model statistics for training, validation and testing. The table documents the effect of limiting data to the time steps when there was actually a TMI in place or when a TMI had just terminated. This resulted in a more balanced distribution of the GS class(GS positive class)versus “No GS”(GS negative class), which might help the training process. While JFK and LGA follow very similar distributions, with 40% and 42% GS positive class respectively, EWR has proportionally fewer GS incidents at 28%. Our subsequent phase involves evaluating the performance of both hierarchical structure and independent structure using different state-of-the-art multi-class classifier models such as Random Forest, Decision Trees, K-nearest Neighbors, and Logistic Regression and forecast the duration and scope of the GSs.

Farzan Masrour Shalmani↗