Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “dynamic probabilistic risk assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Development of A Crew Health and Performance System Probabilistic Risk Assessment Tool: Proof-of-Concept Approach

The crew health and performance (CHP) system represents the span of technological interventions and tested processes and procedures that in combination address the human risk to space flight. The Human Research Program (HRP) mental model of the CHP system breaks the capabilities needed to meet NASA human flight systems standards into specific categories (i.e., countermeasures, behavioral health, medical intervention). These categories are further broken down into specific sub-groups generally associated with the human system risks that these capabilities seek to mitigate. Like the approach used to develop the Integrated Medical Model (IMM) and the Medical Extensible Dynamic Probabilistic Risk Analysis Tool (MEDPRAT), HRP tasked NASA GRC’s Cross-Cutting Computational Modeling Project with developing a CHP probabilistic risk assessment tool, the CHP-PRA. The CHP-PRA model seeks to quantify and relatively assess the human risk state within the crew health and performance domain, using a combination of knowledge about human system risks and technology and practices likely to be applied during space flight missions. This modeling system will incorporate customer and stakeholder feedback and be flexible enough to address multiple different questions about important low-level mission-specific parameters. This presentation will introduce the initial concept and development timeline for this tool and demonstrate proof-of-concept through an application addressing a specific human risk question posed within the Artemis program.

Risk analysis↗

Nuclear safety Enhanced: A Deep dive into current and future RAVEN applications

As the horizon of nuclear energy expands with the advent of small modular reactors, IV generation reactors, and fusion reactors, there is a growing perspective that the licensing process could benefit from a more comprehensive approach. Moving beyond traditional deterministic and PRA analysis might pave the way for a novel safety analysis paradigm propelled by the increasing computational power at our disposal. This paper explores different methodologies that can improve the outcomes of nuclear safety analysis. These range from uncertainty quantification techniques, aimed at enhancing the precision of safety margins, to deploying dynamic event trees by driving system code simulations, capturing the potential evolutions of severe accidents. These methodologies introduce innovative dimensions to safety analysis, considering the consequences of postulated events and the dynamics of accident sequences. However, they also bring forth challenges, especially in managing the complexity and sheer volume of potential scenarios. The paper touches upon some strategies to counter these challenges, emphasizing the importance of adaptability and continuous evolution in the face of emerging nuclear safety concerns. Additionally, the paper sheds light on the need for advanced tools to apply these methodologies. Among these tools is RAVEN, an open-source software designed for parametric and probabilistic analyses. Its core components, including distribution, sampler, and reduced order model, enable various applications, from risk assessment and mitigation to dynamic learning and plant control logic simulations.

97 - MATHEMATICS AND COMPUTING↗

Dynamic systems-engineering process - The application of concurrent engineering

A system engineering methodology is described which enables users, particulary NASA and DOD, to accommodate changing needs; incorporate emerging technologies; identify, quantify, and manage system risks; manage evolving functional requirements; track the changing environment; and reduce system life-cycle costs. The approach is a concurrent, dynamic one which starts by constructing a performance model defining the required system functions and the interrelationships. A detailed probabilistic risk assessment of the system elements and their interrelationships is performed, and quantitative analysis of the reliability and maintainability of an engineering system allows its different technical and process failure modes to be identified and their probabilities to be computed. Decision makers can choose technical solutions that maximize an objective function and minimize the probability of failure under resource constraints.

Wiskerchen, Michael J.↗

Dynamic Modeling of Ascent Abort Scenarios for Crewed Launches

For the last 30 years, the United States' human space program has been focused on low Earth orbit exploration and operations with the Space Shuttle and International Space Station programs. After over 40 years, the U.S. is again working to return humans beyond Earth orbit. To do so, NASA is developing a new launch vehicle and spacecraft to provide this capability. The launch vehicle is referred to as the Space Launch System (SLS) and the spacecraft is called Orion. The new launch system is being developed with an abort system that will enable the crew to escape launch failures that would otherwise be catastrophic as well as probabilistic design requirements set for probability of loss of crew (LOC) and loss of mission (LOM). In order to optimize the risk associated with designing this new launch system, as well as verifying the associated requirements, NASA has developed a comprehensive Probabilistic Risk Assessment (PRA) of the integrated ascent phase of the mission that includes the launch vehicle, spacecraft and ground launch facilities. Given the dynamic nature of rocket launches and the potential for things to go wrong, developing a PRA to assess the risk can be a very challenging effort. Prior to launch and after the crew has boarded the spacecraft, the risk exposure time can be on the order of three hours. During this time, events may initiate from either the spacecraft, the launch vehicle, or the ground systems, thus requiring an emergency egress from the spacecraft to a safe ground location or a pad abort via the spacecraft's launch abort system. Following launch, again either the spacecraft or the launch vehicle can initiate the need for the crew to abort the mission and return home. Obviously, there are thousands of scenarios whose outcome depends on when the abort is initiated during ascent and how the abort is performed. This includes modeling the risk associated with explosions and benign system failures that require aborting a spacecraft under very dynamic conditions, particularly in the lower atmosphere, and returning the crew home safely. This paper will provide an overview of the PRA model that has been developed of this new launch system, including some of the challenges that are associated with this effort.

Bigler, Mark↗

Dynamic Modeling of Ascent Abort Scenarios for Crewed Launches

For the last 30 years, the United States's human space program has been focused on low Earth orbit exploration and operations with the Space Shuttle and International Space Station programs. After nearly 50 years, the U.S. is again working to return humans beyond Earth orbit. To do so, NASA is developing a new launch vehicle and spacecraft to provide this capability. The launch vehicle is referred to as the Space Launch System (SLS) and the spacecraft is called Orion. The new launch system is being developed with an abort system that will enable the crew to escape launch failures that would otherwise be catastrophic as well as probabilistic design requirements set for probability of loss of crew (LOC) and loss of mission (LOM). In order to optimize the risk associated with designing this new launch system, as well as verifying the associated requirements, NASA has developed a comprehensive Probabilistic Risk Assessment (PRA) of the integrated ascent phase of the mission that includes the launch vehicle, spacecraft and ground launch facilities. Given the dynamic nature of rocket launches and the potential for things to go wrong, developing a PRA to assess the risk can be a very challenging effort. Prior to launch and after the crew has boarded the spacecraft, the risk exposure time can be on the order of three hours. During this time, events may initiate from either of the spacecraft, the launch vehicle, or the ground systems, thus requiring an emergency egress from the spacecraft to a safe ground location or a pad abort via the spacecraft's launch abort system. Following launch, again either the spacecraft or the launch vehicle can initiate the need for the crew to abort the mission and return to the home. Obviously, there are thousands of scenarios whose outcome depends on when the abort is initiated during ascent as to how the abort is performed. This includes modeling the risk associated with explosions and benign system failures that require aborting a spacecraft under very dynamic conditions, particularly in the lower atmosphere, and returning the crew home safely. This paper will provide an overview of the PRA model that has been developed of this new launch system, including some of the challenges that are associated with this effort. Key Words: PRA, space launches, human space program, ascent abort, spacecraft, launch vehicles

Bigler, Mark↗

Validating a Dynamic PWR Safety and Security Model?

Nuclear power plants (NPPs) are assessed for safety and security using separate models that cannot capture how an attacker's decisions and a plant's response unfold together in real time, leaving regulators and operators without a complete picture of true plant vulnerability. Traditional probabilistic risk assessment (PRA) methods treat adversarial events as fixed initiators with predetermined outcomes, and are structurally incapable of representing the time-dependent interplay between physical security events, safety system response, and operator mitigative actions. At Idaho National Laboratory (INL), I contributed to the development and validation of Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF). Where static PRA relies on event-tree logic that cannot evolve mid-scenario, MASS-DEF couples a time-dependent dynamic PRA tool EMRALD (Event Modeling Risk Assessment using Linked Diagrams) with attack simulation software, allowing attacker behavior, plant system states, and operator actions to interact across time. My work focused on validating a general Pressurized Water Reactor (PWR) model. I traced model logic against PWR plant to identified errors in logic and confirm accuracy. I then built and tested attack scenarios against a general PWR model to verify that the model produced expected outcomes across all logical pathways. I also contributed a section to a related technical paper applying the same EMRALD platform to radiation dose modeling. Results show that MASS-DEF can quantitatively demonstrate that many plants exceed their regulatory security thresholds. This demonstrated margin provides a technically defensible basis for reducing the number of guards without compromising regulatory compliance. Physical security costs represent roughly 10% of annual operating budgets, making such reductions directly meaningful to INL's mission of sustaining existing commercial NPPs. This internship strengthened my understanding of nuclear systems, probabilistic modeling, and technical writing, and has solidified my pursuit of a career at a national laboratory.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Design for Reliability and Safety Approach for the NASA New Launch Vehicle

The United States National Aeronautics and Space Administration (NASA) is in the midst of a space exploration program intended for sending crew and cargo to the international Space Station (ISS), to the moon, and beyond. This program is called Constellation. As part of the Constellation program, NASA is developing new launch vehicles aimed at significantly increase safety and reliability, reduce the cost of accessing space, and provide a growth path for manned space exploration. Achieving these goals requires a rigorous process that addresses reliability, safety, and cost upfront and throughout all the phases of the life cycle of the program. This paper discusses the "Design for Reliability and Safety" approach for the NASA new crew launch vehicle called ARES I. The ARES I is being developed by NASA Marshall Space Flight Center (MSFC) in support of the Constellation program. The ARES I consists of three major Elements: A solid First Stage (FS), an Upper Stage (US), and liquid Upper Stage Engine (USE). Stacked on top of the ARES I is the Crew exploration vehicle (CEV). The CEV consists of a Launch Abort System (LAS), Crew Module (CM), Service Module (SM), and a Spacecraft Adapter (SA). The CEV development is being led by NASA Johnson Space Center (JSC). Designing for high reliability and safety require a good integrated working environment and a sound technical design approach. The "Design for Reliability and Safety" approach addressed in this paper discusses both the environment and the technical process put in place to support the ARES I design. To address the integrated working environment, the ARES I project office has established a risk based design group called "Operability Design and Analysis" (OD&A) group. This group is an integrated group intended to bring together the engineering, design, and safety organizations together to optimize the system design for safety, reliability, and cost. On the technical side, the ARES I project has, through the OD&A environment, implemented a probabilistic approach to analyze and evaluate design uncertainties and understand their impact on safety, reliability, and cost. This paper focuses on the use of the various probabilistic approaches that have been pursued by the ARES I project. Specifically, the paper discusses an integrated functional probabilistic analysis approach that addresses upffont some key areas to support the ARES I Design Analysis Cycle (DAC) pre Preliminary Design (PD) Phase. This functional approach is a probabilistic physics based approach that combines failure probabilities with system dynamics and engineering failure impact models to identify key system risk drivers and potential system design requirements. The paper also discusses other probabilistic risk assessment approaches planned by the ARES I project to support the PD phase and beyond.

Safie, Fayssal, M.↗

IMPACT 1.0—Task Impairment: A Novel Approach for Assessing Impairment during Exploration-Class Missions

Exploration-class and International Space Station (ISS) missions have significantly different levels of associated medical risk for crewmembers. The Integrated Medical Model (IMM), the probabilistic risk assessment tool used for ISS medical trade-space analyses, uses a Functional Impairment (FI) metric to determine quality time lost should a crewmember be afflicted with a medical condition. While IMM-based FI has been successful for ISS operations, it has limitations when applied to exploration-class missions. As the National Aeronautics and Space Administration (NASA) looks ahead to Gateway, Artemis, and Martian missions, a novel, dynamic, and mission-appropriate impairment paradigm is necessary for accurate contingency planning. This paradigm, Task Impairment (TI), fulfills that need by utilizing mission-specific tasks. TI will allow future capability for a loss of mission metric, previously not available with IMM. TI serves as a replacement metric for FI within IMPACT, the next-generation trade-space analysis tool suite created to replace the IMM. IMPACT significantly increases the fidelity of probabilistic risk assessment for exploration-class missions. The Human Exploration of Mars Preliminary List of Crew Tasks (MTL, a source of 1100+ exploration-class mission-specific tasks for crewmembers) was used to calculate TI. Using the Task List, 18 individual Human System Categories were identified as being required to perform each task (e.g., Cardiopulmonary, Cognitive, etc.). Each of the 1200+ tasks were mapped to the Human System categories listed in the Task List. The total number of tasks in each category were tallied to determine how many tasks required each Human System. Lastly, each of the 120 medical conditions from the IMPACT condition list were mapped to the Human System categories to complete the TI calculation. NASA subject matter experts across five medical specialties established consensus for the mapping of each condition. The resulting total tasks impaired by each condition were used to calculate discrete TI values. This process was repeated for each of the four severity/resource utilization variants of each condition, and for each of the three phases of clinical care. Through this process, discrete TI values were calculated for each of the 120 IMPACT medical conditions and their variants. The Task Impairment metric provides higher fidelity, dynamic utility, and quicker analysis of medical impairment compared to the previous Functional Impairment metric used for the Integrated Medical Model. TI will be used for higher fidelity medical impairment analysis and contingency planning during Lunar, Martian, and other long-term exploration-class missions.

William L Fernandez↗

Light Water Reactor Sustainability Program: Use of Time Distributions to Predict Operator Procedure Performance in Dynamic Human Reliability Analysis

The Human Unimodel for Nuclear Technology to Enhance Reliability (HUNTER) framework affords software capable of conducting human reliability analysis (HRA) using a dynamic approach built around operating procedures (OPs) from nuclear power plants (NPPs). Previous HUNTER reports document the development of this software tool, the coupling of HUNTER to the simulator code, the collection of operator performance data by using simulators to calibrate HUNTER models, and linking HUNTER to probabilistic risk assessment (PRA) software. The present report largely addresses two topics. The first is a new function in HUNTER called the HUNTER Procedure Performance Predictor (P3). HUNTER P3 uses HUNTER’s built in Monte Carlo tools featuring human performance variability to identify potential error traps in procedures. The second topic is time distribution analysis to generate time inputs for dynamic HRA. The current analysis was performed to investigate time distributions for task primitives, which are the minimum task unit of analysis used in dynamic HRA modeling. Using the time distribution data, the elapsed time for human actions in an extended loss of AC power (ELAP) scenario is then investigated. Time data and prediction are essential for modeling procedure performance.

99 GENERAL AND MISCELLANEOUS↗

Probabilistic Modeling of a Three-Stage Human Landing System Architecture

Unmitigated uncertainties are known to have previously led to failed development programs; in order to combat these uncertainties, risks and their impacts must be understood and handled to ensure program success. In this paper, a probabilistic methodology to handle uncertainties is demonstrated on a three-element Human Landing System (HLS) concept, which allows tracking of current best estimates of the vehicle’s performance and assessment of its robustness against uncertainties. This methodology has two key parts: first, the creation of a dynamic architecture model of a three-element HLS concept; and second, its use with surrogate modeling and range estimating techniques to capture and propagate uncertainties. The DYnamic Rocket EQuation Tool (DYREQT), a space systems synthesis and sizing framework used by NASA, was used as to model the HLS architecture. For the probabilistic analysis, uncertainties of interest within the HLS concept were enumerated and represented as parameters within the DYREQT model as inputs for vehicle stages or mission profile events. Range estimating — a probabilistic method that combines Monte Carlo sampling, focus on critical parameters, and heuristics to assess risk and opportunities — is then adapted with operational parameters as well as vehicle parameters in the DYREQT model to capture mission uncertainty alongside vehicle uncertainty. To perform the range estimation portion of this methodology, the DYREQT model was sampled using a Design of Experiments (DoE) to efficiently explore the architecture design space with respect to the set of uncertainty parameters. Then, the results were used to create surrogate models, multivariate regressions that can visualize hypercube trends in the design space, of the architecture with respect to the uncertainty parameters. Using a correlation matrix constructed for the uncertainty parameters, previously independent samples were transformed to perform a Correlated Monte Carlo on the surrogate models. This probabilistic methodology was proved to provide insight into the underlying uncertainties of the three-element HLS architecture.

Stephanie Y Zhu↗

Probabilistic Modeling of a Three-Stage Human Landing System Architecture

Unmitigated uncertainties are known to have previously led to failed development programs; in order to combat these uncertainties, risks and their impacts must be understood and handled to ensure program success. In this paper, a probabilistic methodology to handle uncertainties is demonstrated on a three-element Human Landing System (HLS) concept, which allows tracking of current best estimates of the vehicle’s performance and assessment of its robustness against uncertainties. This methodology has two key parts: first, the creation of a dynamic architecture model of a three-element HLS concept; and second, its use with surrogate modeling and range estimating techniques to capture and propagate uncertainties. The DYnamic Rocket EQuation Tool (DYREQT), a space systems synthesis and sizing framework used by NASA, was used as to model the HLS architecture. For the probabilistic analysis, uncertainties of interest within the HLS concept were enumerated and represented as parameters within the DYREQT model as inputs for vehicle stages or mission profile events. Range estimating — a probabilistic method that combines Monte Carlo sampling, focus on critical parameters, and heuristics to assess risk and opportunities — is then adapted with operational parameters as well as vehicle parameters in the DYREQT model to capture mission uncertainty alongside vehicle uncertainty. To perform the range estimation portion of this methodology, the DYREQT model was sampled using a Design of Experiments (DoE) to efficiently explore the architecture design space with respect to the set of uncertainty parameters. Then, the results were used to create surrogate models, multivariate regressions that can visualize hypercube trends in the design space, of the architecture with respect to the uncertainty parameters. Using a correlation matrix constructed for the uncertainty parameters, previously independent samples were transformed to perform a Correlated Monte Carlo on the surrogate models. This probabilistic methodology was proved to provide insight into the underlying uncertainties of the three-element HLS architecture.

Stephanie Y. Zhu↗

Application of Fault Management Theory to the Quantitative Selection of a Launch Vehicle Abort Trigger Suite

The theory of System Health Management (SHM) and of its operational subset Fault Management (FM) states that FM is implemented as a "meta" control loop, known as an FM Control Loop (FMCL). The FMCL detects that all or part of a system is now failed, or in the future will fail (that is, cannot be controlled within acceptable limits to achieve its objectives), and takes a control action (a response) to return the system to a controllable state. In terms of control theory, the effectiveness of each FMCL is estimated based on its ability to correctly estimate the system state, and on the speed of its response to the current or impending failure effects. This paper describes how this theory has been successfully applied on the National Aeronautics and Space Administration's (NASA) Space Launch System (SLS) Program to quantitatively estimate the effectiveness of proposed abort triggers so as to select the most effective suite to protect the astronauts from catastrophic failure of the SLS. The premise behind this process is to be able to quantitatively provide the value versus risk trade‐off for any given abort trigger, allowing decision makers to make more informed decisions. All current and planned crewed launch vehicles have some form of vehicle health management system integrated with an emergency launch abort system to ensure crew safety. While the design can vary, the underlying principle is the same: detect imminent catastrophic vehicle failure, initiate launch abort, and extract the crew to safety. Abort triggers are the detection mechanisms that identify that a catastrophic launch vehicle failure is occurring or is imminent and cause the initiation of a notification to the crew vehicle that the escape system must be activated. While ensuring that the abort triggers provide this function, designers must also ensure that the abort triggers do not signal that a catastrophic failure is imminent when in fact the launch vehicle can successfully achieve orbit. That is, the abort triggers must have low false negative rates to be sure that real crew‐threatening failures are detected, and also low false positive rates to ensure that the crew does not abort from non‐crew‐threatening launch vehicle behaviors. The analysis process described in this paper is a compilation of over six years of lessons learned and refinements from experiences developing abort triggers for NASA's Constellation Program (Ares I Project) and the SLS Program, as well as the simultaneous development of SHM/FM theory. The paper will describe the abort analysis concepts and process, developed in conjunction with SLS Safety and Mission Assurance (S&MA) to define a common set of mission phase, failure scenario, and Loss of Mission Environment (LOME) combinations upon which the SLS Loss of Mission (LOM) Probabilistic Risk Assessment (PRA) models are built. This abort analysis also requires strong coordination with the Multi‐Purpose Crew Vehicle (MPCV) and SLS Structures and Environments (STE) to formulate a series of abortability tables that encapsulate explosion dynamics over the ascent mission phase. The design and assessment of abort conditions and triggers to estimate their Loss of Crew (LOC) Benefits also requires in‐depth integration with other groups, including Avionics, Guidance, Navigation and Control(GN&C), the Crew Office, Mission Operations, and Ground Systems. The outputs of this analysis are a critical input to SLS S&MA's LOC PRA models. The process described here may well be the first full quantitative application of SHM/FM theory to the selection of a sensor suite for any aerospace system.

Lo, Yunnhon↗

A Reliable Earth Return System for Safe Recovery of Mars Samples

The objective of a Mars sample return mission is to bring selected Mars surface materials to Earth. Numerous approaches for the Earth-return segment have been analyzed including propulsive or aerocapture return to low-Earth orbit followed by Space Shuttle rendezvous and direct entry. Of these approaches, ballistic entry of a small capsule terminating in a ground landing has been shown to be the lowest risk strategy. Over the past two years, significant work has been performed towards development of a robust direct entry vehicle for Mars sample return. In June 1999, the NASA Planetary Protection Officer provided initial guidance to the former Mars Sample Return Project. The sample return phase of the mission was assigned a restricted Earth return planetary protection classification. The draft mission requirement states that the total mean probability of release of unsterilized Mars material into the Earth;s biosphere must be less than 1.0E-06 (1 in a million). This strict requirement drives the approach and design of the Earth return system. To meet this requirement, selection of the Earth return strategy and development of the Earth return system must be guided by risk, not performance, based decisions. An initial Probabilistic Risk Assessment (PRA) was performed to address the direct entry Earth return system containment assurance reliability and to identify high-risk elements of this system. The results of this PRA identified risk elements that include thermal protection system performance during entry, spin-eject orientation and aerodynamic stability during entry, structural integrity under atmospheric deceleration and impact loads, and tracking/recovery of this system. This initial probabilistic risk quantification demonstrates that, with the proper development program, a prototypical direct entry design can satisfy the containment assurance reliability requirement. Through the current Mars Sample Return Advanced Technology Development effort, an extensive design, analysis, and test program is presently proceeding with the aim of reducing the containment assurance risk of this system. This technology development effort, guided by a continuing PRA, focuses on key risk areas of a direct entry Earth return system including: the thermal protection system, impact dynamics, structural performance, aerodynamic stability, and ground recovery. This development program will culminate in a system validation flight test, 1-2 years prior to launch of the flight system. This flight test would include the launch, entry, and recovery of a full-scale Earth return system, as a scientific validation of the key risk elements to verify nominal design performance. The results of the initial PRA suggested several dominant failure sequences that can be validated in a flight test. These include: demonstrating the thermal protection system reliability and performance during entry, demonstrating the spin-eject orientation and aero-dynamic stability during entry, demonstrating the structural integrity under atmospheric deceleration and impact loads, and demonstrating tracking and recovery of the Earth return system. This single test will directly address over 50% of the total containment assurance risk elements. This presentation will begin by presenting the relative risk of various Earth return strategies. The results of the initial probabilistic risk assessment will be presented followed by a discussion of the development accomplishments and plans for demonstration of a highly reliable direct entry Earth return system.

Braun, R.↗

An Integrated Physics-Based Risk Model for Assessing the Asteroid Threat

Although most asteroids and other near-Earth objects (NEOs) do not pose a threat to Earth’s inhabitants, impacts from objects that are just tens of meters in diameter can cause significant damage if they occur over a populated area. This paper forms the foundation of an effort at NASA Ames Research Center to quantify these risks and identify the greatest risk-driving parameters and uncertainties. An integrated risk model that couples dynamic probabilistic simulations of strike occurrences with physics-based models of NEO impact damage factors has been developed to generate casualty estimates for a range of NEO impact properties. Currently, the model focuses on the risk due to blast overpressure damage from airbursts and impacts on land. The model is first used to reproduce results from established sources, and then is extended to perform sensitivity studies that yield greater insights into risk driving parameters. Results show that meteor strength and entry angle play a role for small to mid-size NEOs, and that accounting for the specific target location significantly affects casualty estimates and dominates the risk. Future work will continue to refine and expand the models to better characterize key impact risk factors, include additional types of threats such as tsunamis and climate effects, and ultimately support assessments of potential asteroid mitigation strategies.

Asteroid Threat↗

Probabilistic evaluation of uncertainties and risks in aerospace components

This paper summarizes a methodology developed at NASA Lewis Research Center which computationally simulates the structural, material, and load uncertainties associated with Space Shuttle Main Engine (SSME) components. The methodology was applied to evaluate the scatter in static, buckling, dynamic, fatigue, and damage behavior of the SSME turbo pump blade. Also calculated are the probability densities of typical critical blade responses, such as effective stress, natural frequency, damage initiation, most probable damage path, etc. Risk assessments were performed for different failure modes, and the effect of material degradation on the fatigue and damage behaviors of a blade were calculated using a multi-factor interaction equation. Failure probabilities for different fatigue cycles were computed and the uncertainties associated with damage initiation and damage propagation due to different load cycle were quantified. Evaluations on the effects of mistuned blades on a rotor were made; uncertainties in the excitation frequency were found to significantly amplify the blade responses of a mistuned rotor. The effects of the number of blades on a rotor were studied. The autocorrelation function of displacements and the probability density function of the first passage time for deterministic and random barriers for structures subjected to random processes also were computed. A brief discussion was included on the future direction of probabilistic structural analysis.

Shah, A. R.↗

De-risking fault leakage risk and containment integrity for subsurface storage applications

The subsurface is pivotal in the energy transition, for the sequestration of CO 2 and energy storage. It is crucial to understand to what extent geological faults may form leakage pathways that threaten the containment integrity of these projects. Fault flow behavior has been studied in the context of hydrocarbon development, supported by observations from wells drilled through faults, but such observations are rare in geoenergy projects. Focusing on mechanical behavior as early indicator of potential leakage risks, a probabilistic Coulomb Failure Stress workflow is developed and demonstrated using data from the Decatur CO 2 sequestration project to rank faults based on their containment risk. The analysis emphasizes the importance of fault throw relative to reservoir thickness and pore pressure change in assessing reactivation risks. Integrating this mechanical assessment with geological and dynamic fault analyses contributes to derisking fault containment for geoenergy applications, providing valuable insights for the successful development of subsurface storage projects.

58 GEOSCIENCES↗

Simulation-Based Recovery Action Analysis Using the EMRALD Dynamic Risk Assessment Tool

A recovery action is defined as the action that prevents deviant conditions from producing unwanted effects. It generally indicates a kind of countermeasure performed in response to a failure of human action. The recovery actions especially play an important role in complex systems like nuclear power plants (NPPs), which consist of highly sophisticated controllers to ensure that desired performance and safety must be achieved and maintained. This is because a combination of human error and its recovery failure may be able to cause a catastrophic effect on a system. Analyzing recovery actions has been a critical part of HRA, which is a technique to evaluate human errors and provide human error probabilities (HEPs) for application in probabilistic safety assessment (PSA). If recovery actions are not adequately analyzed and applied to PSA models, the PSA results may be under-estimated or be not able to reasonably account for the failure of human actions in the context of PSA. For this reason, some regulatory documents such as ASME/ANS RA-Sb-2013 by the American Society for Mechanical Engineers and the American Nuclear Society and NUREG-1792 by U.S. Nuclear Regulatory Commission have emphasized the importance of recovery analysis within the HRA. A couple of existing HRA methods, such as the Technique for Human Error-Rate Prediction (THERP), the Cause-Based Decision Tree (CBDT), and the Korean Standard HRA (K-HRA), have respectively suggested their own approaches to the HRA recovery analysis. However, there are a couple of limitations to treating recovery actions using only the current HRA methods available. The biggest limitation is that the existing recovery analysis does not explicitly consider a variety of recovery action types and recovery sequences as they occur in actual NPPs. To handle the limitations of existing recovery analysis, this study proposes a simulation-based recovery analysis method using the Event Modeling Risk Assessment Using Linked Diagram (EMRALD) software. The EMRALD software is a dynamic simulation tool for PSA. It supports realistic and dynamic modeling of human actions as they would be performed at NPPs. It is also favorable to simultaneously model the specific moment at which an action is performed, the time it takes to perform the action, and the failure probability of that action. In this paper, a detailed methodology for modeling recovery actions in the simulation platform is proposed with a couple of examples. Then, outputs from the simulation are discussed as reviewing if this novel approach can complement the challenges of existing recovery analyses.

99 GENERAL AND MISCELLANEOUS↗

Risk-Informed Safety Assurance and Probabilistic Assessment of Mission-Critical Software-Intensive Systems

This report validates and documents the detailed features and practical application of the framework for software intensive digital systems risk assessment and risk-informed safety assurance presented in the NASA PRA Procedures Guide for Managers and Practitioner. This framework, called herein the "Context-based Software Risk Model" (CSRM), enables the assessment of the contribution of software and software-intensive digital systems to overall system risk, in a manner which is entirely compatible and integrated with the format of a "standard" Probabilistic Risk Assessment (PRA), as currently documented and applied for NASA missions and applications. The CSRM also provides a risk-informed path and criteria for conducting organized and systematic digital system and software testing so that, within this risk-informed paradigm, the achievement of a quantitatively defined level of safety and mission success assurance may be targeted and demonstrated. The framework is based on the concept of context-dependent software risk scenarios and on the modeling of such scenarios via the use of traditional PRA techniques - i.e., event trees and fault trees - in combination with more advanced modeling devices such as the Dynamic Flowgraph Methodology (DFM) or other dynamic logic-modeling representations. The scenarios can be synthesized and quantified in a conditional logic and probabilistic formulation. The application of the CSRM method documented in this report refers to the MiniAERCam system designed and developed by the NASA Johnson Space Center.

Guarro, Sergio B.↗