Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Safety Case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Building confidence in models for complex barrier systems for radionuclides

The modeling and simulation of the Cement-clay Interaction-Diffusion field (CI-D) experiment at the Mont Terri site in Switzerland presented here demonstrates that it is possible to capture the multiscale physical and chemical features of natural and engineered barrier systems for radionuclides. The simulations are successfully carried out with the newly developed CrunchODiTi high-performance computing software that accounts for multiple continua, including a continuum representing the electrical double layer (EDL) developed along negatively charged clay particles in clay rock. The simulation also accounts for both the complex three-dimensional (3D) geometry, expected as the norm in a geological waste repository, and the anisotropy of the geological formation. In addition, the high resolution of the model makes it possible to include "skin effects" developed at the interface between highly reactive materials, in this case between the high pH cement and the circumneutral but electrostatic Opalinus Clay. The successful history matching with the field experiment demonstrates that the distinct geochemical and physical properties of the cement and the Opalinus Clay in the CI-D experiment can be accounted for. Such analyses are essential for developing a defensible safety case for the underground storage of radioactive waste.

Sarsenbayev, Dauren

Evidence Arguments for Using Formal Methods in Software Certification

We describe a generic approach for automatically integrating the output generated from a formal method/tool into a software safety assurance case, as an evidence argument, by (a) encoding the underlying reasoning as a safety case pattern, and (b) instantiating it using the data produced from the method/tool. We believe this approach not only improves the trustworthiness of the evidence generated from a formal method/tool, by explicitly presenting the reasoning and mechanisms underlying its genesis, but also provides a way to gauge the suitability of the evidence in the context of the wider assurance case. We illustrate our work by application to a real example-an unmanned aircraft system- where we invoke a formal code analysis tool from its autopilot software safety case, automatically transform the verification output into an evidence argument, and then integrate it into the former.

Argumentation

Prospective Safety Analysis and the Complex Aviation System

Fatal accident rates in commercial passenger aviation are at historic lows yet have plateaued and are not showing evidence of further safety advances. Modern aircraft accidents reflect both historic causal factors and new unexpected "Black Swan" events. The ever-increasing complexity of the aviation system, along with its associated technology and organizational relationships, provides fertile ground for fresh problems. It is important to take a proactive approach to aviation safety by working to identify novel causation mechanisms for future aviation accidents before they happen. Progress has been made in using of historic data to identify the telltale signals preceding aviation accidents and incidents, using the large repositories of discrete and continuous data on aircraft and air traffic control performance and information reported by front-line personnel. Nevertheless, the aviation community is increasingly embracing predictive approaches to aviation safety. The "prospective workshop" early assessment tool described in this paper represents an approach toward this prospective mindset-one that attempts to identify the future vectors of aviation and asks the question: "What haven't we considered in our current safety assessments?" New causation mechanisms threatening aviation safety will arise in the future because new (or revised) systems and procedures will have to be used under future contextual conditions that have not been properly anticipated. Many simulation models exist for demonstrating the safety cases of new operational concepts and technologies. However the results from such models can only be as valid as the accuracy and completeness of assumptions made about the future context in which the new operational concepts and/or technologies will be immersed. Of course that future has not happened yet. What is needed is a reasonably high-confidence description of the future operational context, capturing critical contextual characteristics that modulate both the likelihood of occurrence of hazards, and the likelihood that those hazards will lead to negative safety events. Heuristics extracted from scenarios, questionnaires, and observed trends from scanning the aviation horizon may be helpful in capturing those future changes in a way conducive to safety assessment. What is also needed is a checklist of potential sources of emerging risk that arise from organizational features that are frequently overlooked. The ultimate goal is to develop a pragmatic, workable method for using descriptions of the future aviation context, to generate valid predictions of safety risks.

prospection

Comprehensive Forced Response Analysis of J2X Turbine Bladed-Discs with 360 Degree Variation in CFD Loading

The temporal frequency content of the dynamic pressure predicted by a 360 degree computational fluid dynamics (CFD) analysis of a turbine flow field provides indicators of forcing function excitation frequencies (e.g., multiples of blade pass frequency) for turbine components. For the Pratt and Whitney Rocketdyne J-2X engine turbopumps, Campbell diagrams generated using these forcing function frequencies and the results of NASTRAN modal analyses show a number of components with modes in the engine operating range. As a consequence, forced response and static analyses are required for the prediction of combined stress, high cycle fatigue safety factors (HCFSF). Cyclically symmetric structural models have been used to analyze turbine vane and blade rows, not only in modal analyses, but also in forced response and static analyses. Due to the tortuous flow pattern in the turbine, dynamic pressure loading is not cyclically symmetric. Furthermore, CFD analyses predict dynamic pressure waves caused by adjacent and non-adjacent blade/vane rows upstream and downstream of the row analyzed. A MATLAB script has been written to calculate displacements due to the complex cyclically asymmetric dynamic pressure components predicted by CFD analysis, for all grids in a blade/vane row, at a chosen turbopump running speed. The MATLAB displacements are then read into NASTRAN, and dynamic stresses are calculated, including an adjustment for possible mistuning. In a cyclically symmetric NASTRAN static analysis, static stresses due to centrifugal, thermal, and pressure loading at the mode running speed are calculated. MATLAB is used to generate the HCFSF at each grid in the blade/vane row. When compared to an approach assuming cyclic symmetry in the dynamic flow field, the current approach provides better assurance that the worst case safety factor has been identified. An extended example for a J-2X turbopump component is provided.

Elrod, David

Multiscale Modeling of the Mechanical Response of Silicon Carbide Composite Within the Accelerated Fuel Qualification Framework

The accelerated fuel qualification (AFQ) framework has been used for the initial development of multiscale modeling of silicon carbide (SiC) fiber reinforced composite (SiC-SiC). The AFQ framework provides a methodology to leverage physics-informed multiscale modeling along with a reduced set of empirical test data to reduce the time and cost of licensing and qualification of new nuclear fuel systems while maintaining the overall nuclear power plant safety case. SiC-SiC is being proposed for in-core applications, most notably fuel cladding, for current and next-generation nuclear reactors because of its high temperature stability, irradiation tolerance, and ability to withstand many accident conditions. As these composites exhibit multiscale architectures and complex microstructure-based fracture mechanics, it is an appealing use case for the AFQ methodology. While the end goal of this work is a single multiscale model that can be used for predictive in-core performance, current focus is on the individual various length scale models. Four individual models have been initially developed from microscale to engineering system level to capture key physics-based effects across different length scales. These models include a microscale homogenized tow model, a mesoscale fast Fourier transform–based weave model that integrates the homogenized tow model, a mesoscale finite element–based weave model, and a system-level BISON fuel performance model. Results of these models have undergone an initial comparison with separate-effects test data showing a good match to experimental results. By using the AFQ framework during model development, several near-term benefits have been secured including a reduction in development time for the SiC-SiC cladding, more targeted irradiation testing, and a better understanding of uncertainty.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

Brine Availability Test in Salt (BATS) FY24 Update

This report summarizes fiscal year 2024 (FY24) activities centered around a series of field tests in bedded salt at the Waste Isolation Pilot Plant (WIPP) funded by the Office of Spent Fuel and Waste Science and Technology in the Spent Fuel and Waste Disposition (SFWD) program of the US Department of Energy’s Office of Nuclear Energy (DOE-NE). High-level Purpose of Experiments: The Brine Availability Test in Salt (BATS) field tests are revealing both brine occurrence (i.e., where, and how much) and brine migration (i.e., how easily it moves) in the excavation damaged zone (EDZ). This understanding is foundational to develop a safety case for a future heat-generating waste repository in salt, and to starting up a generic repository program in salt to buy down risk. BATS seeks to predict how much brine can flow into both ambient and heated excavations (e.g., boreholes or rooms) in salt. This work is educating and empowering new repository scientists on two fronts: “design and execution of field tests” and “prediction and modeling of coupled processes.” DOE-NE capabilities in salt have grown and been tested through international modeling and benchmarking exercises (e.g., DECOVALEX, RANGERS, KOMPASS, and MEASURES; see Mills et al., 2024). The hands-on expertise we are building is a necessary step towards large-scale disposal demonstrations and eventual implementation.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W

DECOVALEX-2023: Task B Final Report

In all repository concepts for the geological disposal of radioactive waste, an engineered barrier system (EBS) is used to encapsulate the waste canister, or, to act as borehole or gallery seals. These systems are often based on bentonite clays due to their low permeability and high swelling capacity enabling the closure of engineering voids. However, in all repository concepts gases will be generated through the corrosion of metallic materials (under anoxic conditions), the radioactive decay of waste and the radiolysis of water. Thus, understanding the processes and mechanisms controlling the advective movement of gas (as a discrete phase) in clay-based materials is a key aspect when assessing the impact of gas flow in a repository safety case.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W

Modeling the PV System Level Economic Impact of PV Connector Failure Modes

Photovoltaic (PV) connectors must maintain mechanical integrity for over 25 years while operating under UV exposure, elevated temperature, and mechanical loading. Connector degradation increases with electrical resistance, leading to energy losses, unplanned downtime, and higher operation and maintenance (O&M) costs and in severe cases, safety risks from overhearing or arcing. Connector related failures remain among the most frequent causes of disruption in utility-scale PV (UPV) systems, yet their lifetime economic impacts are poorly quantified. This work presents a techno-economic analysis (TEA) framework that links identified connector failure modes to system level energy losses and lifetime cost impacts using identified resistance measurements and failure rates from 6,2761 PV connectors inspected. Connector failures increase system level O&M costs, raising LCOE by roughly 5%. Downtime driven availability losses dominate economic impact. Resistance-driven I2R and IV-curve losses are secondary, but remain non-negligible. Thermal damage, bend-radius violations, and loose connections drive the majority of LCOE uplift Improving connector reliability through better installation quality, inspection, and design can meaningfully reduce lost energy, O&M costs, and LCOE.

14 SOLAR ENERGY

Mars Radiator Characterization Experimental Program

Radiators are an enabling technology for the human exploration and development of the moon and Mars. As standard components of the heat rejection subsystem of space vehicles, radiators are used to reject waste heat to space and/or a planetary environment. They are typically large components of the thermal control system for a space vehicle or human habitation facility, and in some cases safety factors are used to oversize them when the operating environment cannot be fully characterized. Over-sizing can impose significant weight and size penalties that might be prohibitive for future missions. Radiator performance depends on the size of the radiator surface, its emittance and absorptance, the radiator temperature, the effective sky temperature surrounding the radiator, solar radiation and atmospheric irradiation levels, convection to or from the atmosphere (on Mars), and other conditions that could affect the nature of the radiator surface, such as dust accumulation. Most particularly, dust is expected to be a major contributor to the local environmental conditions on either the lunar or Martian surface. This conclusion regarding Mars is supported by measurements of dust accumulation on the Mars Sojourner Rover solar array during the Pathfinder mission. This Final Report describes a study of the effect of Martian dust accumulation on radiator performance. It is comprised of quantitative measurements of effective emittance for a range of dust accumulation levels on surfaces of known emittance under clean conditions. The test radiator coatings were Z-93P, NS-43G, and Silver Teflon (10 mil) film. The Martian dust simulant was Carbondale Red Clay. Results were obtained under vacuum conditions sufficient to reduce convection effects virtually to zero. The experiments required the development of a calorimetric apparatus that allows simultaneous measurements of the effective emittance for all the coatings at each set of experimental conditions. A method of adding dust to multiple radiator coupons was developed and shown to be capable of depositing dust on the surfaces with acceptable uniformity. In these experiments, the dust layer accumulates under earth gravity and in the presence of an earth atmosphere. An invention disclosure for the dust deposition apparatus is being filed through NASA and University of Houston.

Witte, Larry C.

NASA Dryden's UAS Service Capabilities

The vision of NASA s Dryden Flight Research Center is to "fly what others only imagine." Its mission is to advance technology and science through flight. Objectives supporting the mission include performing flight research and technology integration to revolutionize aviation and pioneer aerospace technology, validating space exploration concepts, conducting airborne remote sensing and science missions, and supporting operations of the Space Shuttle and the International Space Station. A significant focus of effort in recent years has been on Unmanned Aircraft Systems (UAS), both in support of the Airborne Science Program and as research vehicles to advance the state of the art in UAS. Additionally, the Center has used its piloted aircraft in support of UAS technology development. In order to facilitate greater access to the UAS expertise that exists at the Center, that expertise has been organized around three major capabilities. The first is access to high-altitude, long-endurance UAS. The second is the establishment of a test range for small UAS. The third is safety case assessment support.

Bauer, Jeff

Proceedings of the Sixth NASA Langley Formal Methods (LFM) Workshop

Today's verification techniques are hard-pressed to scale with the ever-increasing complexity of safety critical systems. Within the field of aeronautics alone, we find the need for verification of algorithms for separation assurance, air traffic control, auto-pilot, Unmanned Aerial Vehicles (UAVs), adaptive avionics, automated decision authority, and much more. Recent advances in formal methods have made verifying more of these problems realistic. Thus we need to continually re-assess what we can solve now and identify the next barriers to overcome. Only through an exchange of ideas between theoreticians and practitioners from academia to industry can we extend formal methods for the verification of ever more challenging problem domains. This volume contains the extended abstracts of the talks presented at LFM 2008: The Sixth NASA Langley Formal Methods Workshop held on April 30 - May 2, 2008 in Newport News, Virginia, USA. The topics of interest that were listed in the call for abstracts were: advances in formal verification techniques; formal models of distributed computing; planning and scheduling; automated air traffic management; fault tolerance; hybrid systems/hybrid automata; embedded systems; safety critical applications; safety cases; accident/safety analysis.

Rozier, Kristin Yvonne

State-Based Implicit Coordination and Applications

In air traffic management, pairwise coordination is the ability to achieve separation requirements when conflicting aircraft simultaneously maneuver to solve a conflict. Resolution algorithms are implicitly coordinated if they provide coordinated resolution maneuvers to conflicting aircraft when only surveillance data, e.g., position and velocity vectors, is periodically broadcast by the aircraft. This paper proposes an abstract framework for reasoning about state-based implicit coordination. The framework consists of a formalized mathematical development that enables and simplifies the design and verification of implicitly coordinated state-based resolution algorithms. The use of the framework is illustrated with several examples of algorithms and formal proofs of their coordination properties. The work presented here supports the safety case for a distributed self-separation air traffic management concept where different aircraft may use different conflict resolution algorithms and be assured that separation will be maintained.

Narkawicz, Anthony J.

Neither Pollyanna nor Chicken Little: Thoughts on the Ethics of Automation

This paper has raised issues concerning the ethics of automation in aviation systems, and outlined ways of thinking about the issues that may help in ethical decision making. It is very easy to be carried along by technology and the Pollyanna view, but just because we can do something, doesn't mean we should - which is perhaps a little milder than the Chicken Little view. Both views have merits, and we would view ethical decisions as ones that more appropriately balance or reconcile these conflicting viewpoints. We have set out some of the background to the problems of automation in aviation systems, but are aware that there is much more that could be said (considering military UAS, for example). We hope, however, that the brief introduction provides a foundation for the ethical questions that we have set out. The underlying aim in proposing ESCs is to make understanding ethical issues easier so that ethically-informed decisions can be made. Whilst we have not linked the discussion directly back to specific ethical decisions, we believe that making explicit those issues on which such judgments are based is a contribution to ethically informed decision making. We also believe that the four principles set out by the RAEng are reflected in this approach. We acknowledge that what we have set out, especially the ideas of ESC, goes some way beyond current practice and principles and there are significant technical issues to resolve before such an approach could be implemented. It is hoped, however, that the ideas will help improve the production and presentation of safety cases in a range of industries not just aviation - a Pollyanna view, of course!

Holloway, C. Michael

The Evolution of System Safety at NASA

The NASA system safety framework is in the process of change, motivated by the desire to promote an objectives-driven approach to system safety that explicitly focuses system safety efforts on system-level safety performance, and serves to unify, in a purposeful manner, safety-related activities that otherwise might be done in a way that results in gaps, redundancies, or unnecessary work. An objectives-driven approach to system safety affords more flexibility to determine, on a system-specific basis, the means by which adequate safety is achieved and verified. Such flexibility and efficiency is becoming increasingly important in the face of evolving engineering modalities and acquisition models, where, for example, NASA will increasingly rely on commercial providers for transportation services to low-earth orbit. A key element of this objectives-driven approach is the use of the risk-informed safety case (RISC): a structured argument, supported by a body of evidence, that provides a compelling, comprehensible and valid case that a system is or will be adequately safe for a given application in a given environment. The RISC addresses each of the objectives defined for the system, providing a rational basis for making informed risk acceptance decisions at relevant decision points in the system life cycle.

Dezfuli, Homayoon

Java Architecture for Detect and Avoid Extensibility and Modeling

Unmanned aircraft will equip with a detect-and-avoid (DAA) system that enables them to comply with the requirement to "see and avoid" other aircraft, an important layer in the overall set of procedural, strategic and tactical separation methods designed to prevent mid-air collisions. This paper describes a capability called Java Architecture for Detect and Avoid Extensibility and Modeling (JADEM), developed to prototype and help evaluate various DAA technological requirements by providing a flexible and extensible software platform that models all major detect-and-avoid functions. Figure 1 illustrates JADEM's architecture. The surveillance module can be actual equipment on the unmanned aircraft or simulators that model the process by which sensors on-board detect other aircraft and provide track data to the traffic display. The track evaluation function evaluates each detected aircraft and decides whether to provide an alert to the pilot and its severity. Guidance is a combination of intruder track information, alerting, and avoidance/advisory algorithms behind the tools shown on the traffic display to aid the pilot in determining a maneuver to avoid a loss of well clear. All these functions are designed with a common interface and configurable implementation, which is critical in exploring DAA requirements. To date, JADEM has been utilized in three computer simulations of the National Airspace System, three pilot-in-the-loop experiments using a total of 37 professional UAS pilots, and two flight tests using NASA's Predator-B unmanned aircraft, named Ikhana. The data collected has directly informed the quantitative separation standard for "well clear", safety case, requirements development, and the operational environment for the DAA minimum operational performance standards. This work was performed by the Separation Assurance/Sense and Avoid Interoperability team under NASA's UAS Integration in the NAS project.

unmanned aircraft systems

A Vision and Roadmap for Increasing User Autonomy in Flight Operations in the National Airspace

The purpose of Air Transportation is to move people and cargo safely, efficiently and swiftly to their destinations. The companies and individuals who use aircraft for this purpose, the airspace users, desire to operate their aircraft according to a dynamically optimized business trajectory for their specific mission and operational business model. In current operations, the dynamic optimization of business trajectories is limited by constraints built into operations in the National Airspace System (NAS) for reasons of safety and operational needs of the air navigation service providers. NASA has been developing and testing means to overcome many of these constraints and permit operations to be conducted closer to the airspace user's changing business trajectory as conditions unfold before and during the flight. A roadmap of logical steps progressing toward increased user autonomy is proposed, beginning with NASA's Traffic Aware Strategic Aircrew Requests (TASAR) concept that enables flight crews to make informed, deconflicted flight-optimization requests to air traffic control. These steps include the use of data communications for route change requests and approvals, integration with time-based arrival flow management processes under development by the Federal Aviation Administration (FAA), increased user authority for defining and modifying downstream, strategic portions of the trajectory, and ultimately application of self-separation. This progression takes advantage of existing FAA NextGen programs and RTCA standards development, and it is designed to minimize the number of hardware upgrades required of airspace users to take advantage of these advanced capabilities to achieve dynamically optimized business trajectories in NAS operations. The roadmap is designed to provide operational benefits to first adopters so that investment decisions do not depend upon a large segment of the user community becoming equipped before benefits can be realized. The issues of equipment certification and operational approval of new procedures are addressed in a way that minimizes their impact on the transition by deferring a change in the assignment of separation responsibility until a large body of operational data is available to support the safety case for this change in the last roadmap step.This paper will relate the roadmap steps to ongoing activities to clarify the economics-based transition to these technologies for operational use.

Cotton, William B.

Investigating the Impacts of a Separation Standard for UAS Operations in Enroute and Transition Airspace

Unmanned aircraft systems will be required to equip with a detect and avoid system in order to satisfy the federal aviation regulations to remain well clear of other aircraft. To comply with regulations in today’s operations manned aircraft must “see and avoid” other aircraft and use subjective judgment to determine whether those aircraft are well clear. For a detect-and- avoid (DAA) system to satisfy the requirement to stay well clear, a quantitative definition of well clear needs to be defined and evaluated. Definitions for the boundary of well clear have been proposed by the Unmanned Aircraft System (UAS) Executive Committee Science and Research Panel (SaRP) and the Radio Technical Commission for Aeronautics (RTCA) Special Committee 228 on Detect and Avoid Systems. This study investigates the interoperability implications of UAS using proposed well clear definitions as a separation standard for conducting operations in the national airspace system. The first analysis in the study focuses on the effect of variations in well clear definition parameters on the rate of losses of well clear per flight hour. The second analysis considers three well clear definitions and presents the relative state conditions of intruder aircraft as they encroach upon the well clear boundary. The third analysis focuses on the definition of the alerting criteria needed to inform the UAS operator of a potential loss of well clear. All three analyses are conducted in a NAS-wide fast-time simulation environment using UAS aircraft models, proposed UAS missions, and historical air defense radar data to populate the background traffic operating under visual flight rules. The results from the three analyses presented in this study inform the safety case, requirements development, and the operational environment for the DAA minimum operational performance standards.

UAS Seperation Standard

NASA ACES V&V Alignment Briefing

Regulations to establish operational and performance requirements for unmanned aircraft systems (UAS) are being developed by a consortium of government, industry and academic institutions. Those requirements will apply to the new detect and avoid (DAA) systems and other equipment necessary to integrate UAS with the National Airspace System (NAS) and are determined according to their contribution to the overall safety case for such an integration. This briefing focuses on providing an overview of the Airspace Concept Evaluation System (ACES) platform, review of detect-and-avoid models incorprated in ACES, sumamry of two planned ACES studies, and a way forward to impact the SC-228 VV plan.

Santiago, Confesor