Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Safety Case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Fire safety: A case study of technology transfer

Two basic ways in which NASA-generated technology is being used by the fire safety community are described. First, improved products and systems that embody NASA technical advances are entering the marketplace. Second, NASA test data and technical information related to fire safety are being used by persons concerned with reducing the hazards of fire through improved design information and standards. The development of commercial fire safety products and systems typically requires adaptation and integration of aerospace technologies that may not have been originated for NASA fire safety applications.

Heins, C. F.

TRISO Fuel’s Safety Functions, Contributions to Reactor Safety, and Necessary Safety Limits

Safety functions are the actions, passive or active, that structures, systems, and components of nuclear facility that contribute to the safety of the workers, the public, or the environment. Well-defined safety functions are the foundation of a solid safety case for a reactor. For reactors that use TRISO-coated particles, the TRISO fuel plays an important part of the safety case because of its ability to contain radionuclides in the fuel itself. This ability enables the use of a functional containment strategy for the reactor where radionuclide retention is the primary safety function supported by the safety functions of controlling reactivity control and controlling heat rejection. This paper establishes at a deeper level the role that TRISO fuel plays in each of these safety functions and associated quality assurance and testing requirements for TRISO particle manufacturing to ensure these safety functions. Safety limits necessary to protect these safety functions include: operational limits, time at temperature limits, and fission gas release activity limits. In conclusion, this approach demonstrates the role that specific aspects of TRISO fuel play in protecting the safety of workers, the public, and the environment.

11 - NUCLEAR FUEL CYCLE AND FUEL MATERIALS

Safety Benefit Analysis of Conformance Monitoring for Situation Awareness in UTM

This work presents an analytical approach to address situations in drone operations when strategic coordination alone cannot ensure safety, requiring support from the Conformance Monitoring for Situation Awareness service and potentially other deconfliction services. This study focuses on evaluating the impact of off-nominal operations on both UA-to-UA collision risk and ground injury risk. It first establishes a relationship between the likelihood of off-nominal flights and the effectiveness of strategic coordination. The analysis then derives operational conditions where strategic coordination alone is insufficient to meet target safety requirements, particularly when the likelihood of off-nominal operations exceeds a certain threshold. The results indicate that higher operational tempo or density requires a lower likelihood of offnominal operations for strategic coordination to remain effective and meet safety targets. These findings provide quantitative operational thresholds for when CMSA services are necessary. This work contributes to the safety case for both strategic coordination and CMSA services, offering analysis on when CMSA should be employed to support strategic coordination in achieving the desired safety levels. It also establishes a framework for incorporating other deconfliction services in future safety case analyses.

Strategic deconfliction

Safety Benefit Analysis of Conformance Monitoring for Situation Awareness in UTM

This work presents an analytical approach to address situations in drone operations when strategic coordination alone cannot ensure safety, requiring support from the Conformance Monitoring for Situation Awareness service and potentially other deconfliction services. This study focuses on evaluating the impact of off-nominal operations on both UA-to-UA collision risk and ground injury risk. It first establishes a relationship between the likelihood of off-nominal flights and the effectiveness of strategic coordination. The analysis then derives operational conditions where strategic coordination alone is insufficient to meet target safety requirements, particularly when the likelihood of off-nominal operations exceeds a certain threshold. The results indicate that higher operational tempo or density requires a lower likelihood of offnominal operations for strategic coordination to remain effective and meet safety targets. These findings provide quantitative operational thresholds for when CMSA services are necessary. This work contributes to the safety case for both strategic coordination and CMSA services, offering analysis on when CMSA should be employed to support strategic coordination in achieving the desired safety levels. It also establishes a framework for incorporating other deconfliction services in future safety case analyses.

Strategic deconfliction

NASA System Safety Handbook. Volume 2: System Safety Concepts, Guidelines, and Implementation Examples

This is the second of two volumes that collectively comprise the NASA System Safety Handbook. Volume 1 (NASASP-210-580) was prepared for the purpose of presenting the overall framework for System Safety and for providing the general concepts needed to implement the framework. Volume 2 provides guidance for implementing these concepts as an integral part of systems engineering and risk management. This guidance addresses the following functional areas: 1.The development of objectives that collectively define adequate safety for a system, and the safety requirements derived from these objectives that are levied on the system. 2.The conduct of system safety activities, performed to meet the safety requirements, with specific emphasis on the conduct of integrated safety analysis (ISA) as a fundamental means by which systems engineering and risk management decisions are risk-informed. 3.The development of a risk-informed safety case (RISC) at major milestone reviews to argue that the systems safety objectives are satisfied (and therefore that the system is adequately safe). 4.The evaluation of the RISC (including supporting evidence) using a defined set of evaluation criteria, to assess the veracity of the claims made therein in order to support risk acceptance decisions.

Safety Case

Ensuring Safety of Government Personnel During Suborbital Spaceflight

The NASA Suborbital Crew (SubC) project is focused on enabling flights by NASA civil servants, such as scientists and engineers conducting research, on suborbital vehicles. A broader goal is ensuring that commercial human spaceflight is both viable and safe. Within the Commercial Crew Program (CCP), the SubC project is exploring game-changing methods to perform safety assessments to enable NASA personnel to fly on suborbital missions. Commercial suborbital space flight capabilities are anticipated to be more accessible, affordable, and available than missions to the International Space Station and could provide additional opportunities for testing and qualification of space flight hardware, human-tended microgravity research, and further cutting-edge research enabled by the space environment. Although NASA currently permits human tended suborbital payloads for non-civil servants under auspices of NASA’s Flight Opportunities Program, the SubC effort will enable civil servant scientists, researchers, and even engineers to accompany their experiments and tests into the space microgravity environment. Figure 1 illustrates how the SubC program complements other microgravity experimental platforms. The targeted scope for SubC includes end-to-end suborbital capabilities reaching ~80km with several minutes of sustained microgravity (Table 1). The NASA SubC project office is working with the Federal Aviation Administration’s Office of Commercial Space Transportation (FAA-AST) and the commercial suborbital space transportation industry to develop an efficient and holistic approach to a safety review and eventual government participation in suborbital flight. The current FAA certification process for suborbital launches is congressionally mandated to only consider public safety. NASA is responsible for understanding the risks to its employees should they fly on a commercially available suborbital flight. The SubC project is employing a Safety Case approach, applied to commercial suborbital providers, which is not a traditional certification process as was used for the SpaceX Dragon and Boeing Starliner vehicles. Rather, it is an assessment using elements of NASA’s Risk-Informed Safety Case and the Armstrong Flight Research Center’s Airworthiness Assessment process.

Elizabeth C Blome

Software Safety Risk in Legacy Safety-Critical Computer Systems

Safety Standards contain technical and process-oriented safety requirements. Technical requirements are those such as "must work" and "must not work" functions in the system. Process-Oriented requirements are software engineering and safety management process requirements. Address the system perspective and some cover just software in the system > NASA-STD-8719.13B Software Safety Standard is the current standard of interest. NASA programs/projects will have their own set of safety requirements derived from the standard. Safety Cases: a) Documented demonstration that a system complies with the specified safety requirements. b) Evidence is gathered on the integrity of the system and put forward as an argued case. [Gardener (ed.)] c) Problems occur when trying to meet safety standards, and thus make retrospective safety cases, in legacy safety-critical computer systems.

Hill, Janice L.

Progress on the US-Japan Source Term Benchmark Analysis Collaboration

There has been a resurgence in global interest in advanced reactor technology, with a variety of innovative concepts being proposed and developed. Sodium-cooled Fast Reactors (SFRs) have garnered considerable attention given their beneficial characteristics and extensive historical development programs and operating experience. Central to the licensing of non-light water reactor (non-LWR) technology is the characterization of the safety case. At its basics, reactor safety focuses on the prevention and mitigation of the release of radioactive material to the environment.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Towards a Rigorous Basis for Specific Operations Risk Assessment of UAS

The Specific Operations Risk Assessment (SORA) guidance represents the consensus of various national aviation authorities on a common process to identify, qualitatively assess, and manage the safety risk posed by unmanned aircraft systems (UAS), when preparing the safety case required for regulatory approval to conduct certain types of operations. As such, it can be considered a de facto standard, being increasingly adopted by various relevant stakeholders. This paper first gives an overview of the SORA process and associated methods, identifying a number of inconsistencies in risk identification and assessment, also discussing plausible strategies to close the associated gaps. Then, we give a well-founded basis for the applicable concepts, such as barrier integrity, assurance, and robustness, following which we present a preliminary and simple probabilistic formalization of the underpinning barrier-based safety model. We illustrate our overall approach through a worked example, also discussing how a Bayesian framework can facilitate extending and enhancing our initial formalization. We conclude with a discussion of the opportunities afforded by our approach, such as a well-founded basis for barrier selection, whilst addressing the associated challenges. The main objective of this work is to complement the current SORA guidance through a principled, mathematicallybased approach to risk assessment, particularly when it is applied to higher-risk operational concepts that warrant greater rigor in safety assessment and assurance.

Safety Cases

"Evidence" Under a Magnifying Glass: Thoughts on Safety Argument Epistemology

Common definitions of "safety case" emphasize that evidence is the basis of a safety argument, yet few widely referenced works explicitly define "evidence". Their examples suggest that similar things can be regarded as evidence. But the category evidence seems to contain (1) processes for finding things out, (2) information resulting from such processes, and (3) relevant documents. Moreover, any item of evidence could be replaced by further argument. Normative models of informal argumentation do not offer clear guidance on when a safety argument should cite evidence rather than appeal to a more detailed argument. Disciplines such as the law address the problem with a practical, domain-specific epistemology. In this paper, we explore these problems associated with evidence citations in safety arguments, identify goals for a theory of safety argument evidence and a practical safety argument epistemology, propose a model of safety evidence citation that advances the identified goals, and present a related extension to the Goal Structuring Notation (GSN).

Graydon, P. J.

FUELEAP Model-Based System Safety Analysis

NASA researchers, in a partnership with Boeing, are investigating a fuel-cell powered variant of the X-57 “Maxwell” Mod-II electric propulsion aircraft, which is itself derived from a stock Tecnam P2006T. The “Fostering Ultra-Efficient Low-Emitting Aviation Power” (FUELEAP) project will replace the X-57 power subsystem with a hybrid Solid-Oxide Fuel Cell (SOFC) system to increase the potential range of the electric-propulsion aircraft while dramatically improving efficiency and emissions over stock internal-combustion engines. Our FUELEAP safety analysis faces two primary challenges. First, the Part 23 certificated Tecnam P2006T is undergoing significant modifications to host the hybrid electric-propulsion system, and the challenge is to assure that the safety inherent in the stock aircraft (and subsequently in X-57 Mod-II) is not compromised by changes in avionics, aircraft structural loading, weight and balance, or other considerations. Secondly, because the SOFC power system has little (if any) relevant in-service precedent, our challenge is to assure that we identify and mitigate all reasonably plausible hazards introduced by unique FUELEAP equipage. We are investigating and utilizing Model-Based Safety Analysis (MBSA) methods to help us address these FUELEAP safety challenges. We captured aircraft-level system hazard conditions using instances of a SysML hazard block via aircraft-level Functional Hazard Analysis (FHA). Then, using SysML models of the FUELEAP architecture, we related the hazard conditions to initiating system events and possible mitigations, such as design architecture modifications or operational constraints. We are continuing to define our approach to MBSA by developing a component-by-component inventory of local failure modes and tracing their possible contribution to hazard conditions. Finally, we are applying an argument-based approach to FUELEAP assurance. Through a FUELEAP “safety case,” we are providing an explicit argument for FUELEAP safety by associating assurance evidence with overarching safety claims through a structured argument.

Woodham, Kurt P.

Uncertainty Propagation from Experiment Measurements to Modeling Approaches: A Case for SMR Steam Entrainment Testing

To license new and advanced reactor designs, regulators must be convinced that their unique safety cases—relative to existing large scale reactors—have been adequately addressed by the designed reactor protection systems. In water cooled small modular reactors (SMRs), droplet entrainment in steam flow has significant implications on the progression of accident scenarios due to its compact design features, which requires representative test data applicable to SMR designs. Computer code, modeling and simulation (M&S) tools and models require adequate verification, assessment, and qualification. This includes M&S results validation against scaled empirical data within allowable uncertainty bands to gain regulatory approvals during the various stages of reactor system design, demonstration, and commercialization. However, measurement uncertainty within the empirical datasets and test data applicability ranges requires careful consideration of M&S inputs (i.e., boundary conditions, and initial conditions), and verification and validation efforts. This study focuses on uncertainty quantification in designing scaled test facilities for SMR applications with appropriate measurements and a standard data-reduction method to estimate thermal hydraulics characteristics parameters that incorporate physics phenomena of interest. In addition, this study supports the evaluation model development and assessment process using M&S that interfaces with advanced computing tools and digital twin capabilities. This will allow synchronization between experiment and modeling approaches for droplet entrainment testing and analysis, improving diagnostics, prognostics, and decision-making to accelerate regulatory approval.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS

Characteristics of a Well Clear Definition and Alerting Criteria for Encounters Between UAS and Manned Aircraft in Class E Airspace

Unmanned aircraft systems (UAS) will be required to equip with a detect-and-avoid (DAA) system in order to satisfy the federal aviation regulations to remain well clear of other aircraft. For a DAA system to satisfy the requirement to stay well clear of other airborne traffic, a quantitative definition of well clear needs to be defined and evaluated. This study investigates the implications of UAS using proposed well clear definitions as a separation standard for conducting operations in the National Airspace System (NAS). The first analysis considers three well clear definitions and presents the relative state conditions of intruder aircraft as they encroach upon the well clear boundary. The second analysis focuses on the definition of the alerting criteria needed to inform the UAS operator of a potential loss of well clear. All analyses are conducted in a NAS-wide fast-time simulation environment using UAS aircraft models, proposed UAS missions, and historical air defense radar data to populate the background traffic operating under visual flight rules. The results presented in this study inform the safety case, requirements development, and the operational environment for DAA minimum operational performance standards.

Safety

A Systems Approach to AI Model Integration and Performance Evaluation for the Generic UAM Simulation Framework

This paper introduces py-guam, an open-source experimentation framework developed for the NASA Generic Urban Air Mobility simulation (GUAM) environment, facilitating the integration and evaluation of advanced artificial intelligence (AI) algorithms. We present a systems approach which enables the seamless incorporation of data-driven models, including off-nominal and failure state detection, into the GUAM’s Cognitive Architecture (CA). The framework supports customizable experimentation parameters, derives Safety Performance Indicators (SPIs) from UL 4600 safety case analyses, and employs rapid UAM simulations to assess AI impacts on flight performance across diverse scenarios. Through comprehensive testing and validation experiments, we demonstrate GUAM’s capability to enhance safety and efficiency in urban air mobility operations. Additionally, the open-source nature of py-guam fosters community collaboration, ensuring continuous improvement and adaptability to evolving technological advancements. This work establishes a robust tool for developing and testing AI-driven urban air mobility (UAM) systems, advancing the safety and reliability of autonomous urban air vehicles.

Artificial Intelligence

"Source Term Modeling for Advanced Gas Micro-Reactors"

Maintaining the safety of the public, environment, and operating personnel is the most important factor in designing, operating, maintaining, and decommissioning nuclear reactors. In recent years, there has been a growing interest in the development of micro-reactors employing TRi-structural ISOtropic (TRISO)-coated particle fuel. In gas reactors, TRISO fuel plays an important role in the safety case for high temperature reactors because of the fission product retention properties of the fuel. This ability enables the use of a functional containment strategy for the reactor where multiple barriers are used to prevent fission product release to the environment. Part of the safety analysis of these advanced reactors is the assessment of radionuclide releases under normal and accident conditions through the multiple credited safety barriers. Using conservative assumptions, a mechanistic analysis can be performed to quantify these releases that combines the probabilistic assessment of failure with analytic solutions to radionuclide transport equations. Source term modeling for TRISO fuel has been performed for previous reactor designs; however, these models are outdated, in many cases proprietary, and need updates to be applied to the current state of TRISO fuel technology and alternative gas reactor core configurations [1]. Currently, the only publicly available source term assessment for gas reactors is an expert-based Monte Carlo simulation based on the effectiveness of the fuel kernel, coating layers, and graphite block in a modular high temperature gas reactor [2]. Thus, there is a need to develop a simple, versatile, and mechanistic model of fission product release and transport in gas reactor cores that could be applied to a variety of reactors through user inputs and reactor-specific radionuclide inventories. The release is calculated by the diffusion of the key safety important fission products through the kernel, silicon carbide (SiC), graphite for both intact and defective TRISO particles based on fuel and graphite temperatures in the reactor under normal operation. These releases from the fuel enter the coolant where they can plate-out on cooler surfaces. A clean-up model is included for designs with a coolant purification system to remove fission gases. This initial distribution of fission products in the reactor serves as an initial condition for potential releases under postulated accident conditions. The model then can calculate the fission product release for any transient temperature profile and fission product releases can then be used to assess radiological dose to the workers and the public using conventional dose tools. Data on the diffusion of fission products is based on historic German TRISO experiments and the more current Department of Energy (DOE) Advanced Gas Reactor (AGR) TRISO fuel development program. The model is coded in python with inputs and outputs in excel spreadsheets, as well as python plotting utilities to aid in the interpretation of the results. References: [1] INL, NGNP Mechanistic Source Term White Paper, INL-10-17997, July 2010. [2] David A. Petti, Richard R. Hobbins, Peter Lowry, Hans Gougar, “Representative Source Terms and The Influence of Reactor Attributes on Functional Containment in Modular High Temperature Gas-cooled Reactors,” Nuclear Technology, Vol. 184, p. 181-197, Nov. 2013.

07 ISOTOPE AND RADIATION SOURCES

HTO and selenate diffusion through compacted Na-, Na–Ca-, and Ca-montmorillonite

Radionuclide transport in smectite clay barrier systems used for nuclear waste disposal is controlled by diffusion, with adsorption significantly retarding transport rates. While a relatively minor component of spent nuclear fuel, 79 Se is a major driver of the safety case for spent fuel disposal due to its long half-life (3.3×10 5 yr) and its low adsorption to clay (K D < 10 L/kg), thus a thorough understanding of Se diffusion through clay is critical for understanding the long-term safety of spent fuel disposal systems. Through-diffusion experiments with tritiated water (HTO, conservative tracer) and Se(VI) were conducted with a well-characterized, purified montmorillonite source clay (SWy-2) under a constant ionic strength (0.1 M) and three different electrolyte compositions: Na + , Ca 2+ , and a Na + -Ca 2+ mixture at pH 6.5 in order to probe the effects of electrolyte composition and interlayer cation composition on clay microstructure, Se(VI) aqueous speciation, and ultimately diffusion. Further, the results were modeled using a reactive transport modeling approach to determine values of porosity (ε), D e (effective diffusion coefficient), and K D (distribution coefficient for adsorption). HTO diffusive flux was higher in Ca-montmorillonite (D e =1.68×10 -10 m 2 s -1 ) compared to Na-montmorillonite (De=7.83×10 -11 m 2 s -1 ). This increase in flux is likely due to a greater degree of clay layer stacking in the presence of Ca 2+ compared to Na + , which leads to larger inter-particle pores. Overall, the Se(VI) flux was much lower than the HTO flux due to anion exclusion, with Se(VI) flux following the order Ca (D e = 1.03×10 -11 m 2 s -1 ) > Na–Ca (D e = 2.12×10 -12 m 2 s -1 ) > Na (D e = 1.28×10 -12 m 2 s -1 ). These differences in Se(VI) flux are due to a combination of factors, including (1) larger accessible porosity in Ca-montmorillonite due to clay layer stacking and smaller electrostatic effects compared to Na-montmorillonite, (2) larger accessible porosity for neutral-charge CaSeO4 species which makes up 32% of aqueous Se(VI) in the pure Ca system, and (3) possibly higher Se(VI) adsorption for Ca-montmorillonite. Through a combination of experimental and modeling work, this study highlights the compounding effects that electrolyte and counterion compositions can have on radionuclide transport through clay. Diffusion models that neglect these effects are not transferable from laboratory experimental conditions to in situ repository conditions.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W

An Investigation of Proposed Techniques for Quantifying Confidence in Assurance Arguments

The use of safety cases in certification raises the question of assurance argument sufficiency and the issue of confidence (or uncertainty) in the argument's claims. Some researchers propose to model confidence quantitatively and to calculate confidence in argument conclusions. We know of little evidence to suggest that any proposed technique would deliver trustworthy results when implemented by system safety practitioners. Proponents do not usually assess the efficacy of their techniques through controlled experiment or historical study. Instead, they present an illustrative example where the calculation delivers a plausible result. In this paper, we review current proposals, claims made about them, and evidence advanced in favor of them. We then show that proposed techniques can deliver implausible results in some cases. We conclude that quantitative confidence techniques require further validation before they should be recommended as part of the basis for deciding whether an assurance argument justifies fielding a critical system.

Graydon, Patrick J.

Product Engineering Class in the Software Safety Risk Taxonomy for Building Safety-Critical Systems

When software safety requirements are imposed on legacy safety-critical systems, retrospective safety cases need to be formulated as part of recertifying the systems for further use and risks must be documented and managed to give confidence for reusing the systems. The SEJ Software Development Risk Taxonomy [4] focuses on general software development issues. It does not, however, cover all the safety risks. The Software Safety Risk Taxonomy [8] was developed which provides a construct for eliciting and categorizing software safety risks in a straightforward manner. In this paper, we present extended work on the taxonomy for safety that incorporates the additional issues inherent in the development and maintenance of safety-critical systems with software. An instrument called a Software Safety Risk Taxonomy Based Questionnaire (TBQ) is generated containing questions addressing each safety attribute in the Software Safety Risk Taxonomy. Software safety risks are surfaced using the new TBQ and then analyzed. In this paper we give the definitions for the specialized Product Engineering Class within the Software Safety Risk Taxonomy. At the end of the paper, we present the tool known as the 'Legacy Systems Risk Database Tool' that is used to collect and analyze the data required to show traceability to a particular safety standard

Hill, Janice