Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “probabilistic safety assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

NSTS Orbiter auxiliary power unit turbine wheel cracking risk assessment

The present investigation of turbine-wheel cracking problems in the hydrazine-fueled APU turbine wheel of the Space Shuttle Orbiter's Main Engines has indicated the efficacy of systematic probabilistic risk assessment in flight certification and safety resolution. Nevertheless, real crack-initiation and propagation problems do not lend themselves to purely analytical studies. The high-cycle fatigue problem is noted to generally be unsuited to probabilistic modeling, due to its extremely high degree of intrinsic scatter. In the case treated, the cracks appear to trend toward crack arrest in a low cycle fatigue mode, due to a detuning of the resonance model.

Cruse, T. A.↗

Advancing Multi-Hazard Risk and Safety Considerations for Aging Nuclear Facilities

While probabilistic risk assessment (PRA) of nuclear facilities is expected to include internal and external hazards for a risk-informed and performance-based design, the current state of practice treats each hazard independently. However, such an independent treatment of hazards may not account for the correlations between different hazards and their response of and damage to the structures, systems, and components (SSCs) in a plant resulting in underestimating the overall risk. This project proposes to advance the multi-hazard PRA of nuclear facilities to more adequately evaluate concurrent hazards and contribute to an increased safety of nuclear plants. A framework for multi-hazard PRA will be developed by identifying concurrent hazard events (both internal and external) and event sequences that include interdependencies through the response of SSCs. An example application of the multi-hazard PRA framework will be demonstrated by considering a generic pressurized water reactor (PWR) subjected to seismic and internal flooding hazards. Computational models for the response of components will be developed to generated multi-hazard fragility surfaces under seismic and flooding loads. A PRA model consisting of event and fault trees will also be developed to quantify the multi-hazard risk profile and compare it with the independent hazard risk profile. Overall, by advancing the multi-hazard PRA of nuclear facilities, this project enhances nuclear safety and reduces costs by mitigating unforeseen consequences caused by correlations between concurrent hazards.

97 - MATHEMATICS AND COMPUTING↗

Constellation Probabilistic Risk Assessment (PRA): Design Consideration for the Crew Exploration Vehicle

Managed by NASA's Office of Safety and Mission Assurance, a pilot probabilistic risk analysis (PRA) of the NASA Crew Exploration Vehicle (CEV) was performed in early 2006. The PRA methods used follow the general guidance provided in the NASA PRA Procedures Guide for NASA Managers and Practitioners'. Phased-mission based event trees and fault trees are used to model a lunar sortie mission of the CEV - involving the following phases: launch of a cargo vessel and a crew vessel; rendezvous of these two vessels in low Earth orbit; transit to th$: moon; lunar surface activities; ascension &om the lunar surface; and return to Earth. The analysis is based upon assumptions, preliminary system diagrams, and failure data that may involve large uncertainties or may lack formal validation. Furthermore, some of the data used were based upon expert judgment or extrapolated from similar components~systemsT. his paper includes a discussion of the system-level models and provides an overview of the analysis results used to identify insights into CEV risk drivers, and trade and sensitivity studies. Lastly, the PRA model was used to determine changes in risk as the system configurations or key parameters are modified.

Prassinos, Peter G.↗

Common Cause Failure Modeling

Common Cause Failures (CCFs) are a known and documented phenomenon that defeats system redundancy. CCFS are a set of dependent type of failures that can be caused by: system environments; manufacturing; transportation; storage; maintenance; and assembly, as examples. Since there are many factors that contribute to CCFs, the effects can be reduced, but they are difficult to eliminate entirely. Furthermore, failure databases sometimes fail to differentiate between independent and CCF (dependent) failure and data is limited, especially for launch vehicles. The Probabilistic Risk Assessment (PRA) of NASA's Safety and Mission Assurance Directorate at Marshall Space Flight Center (MFSC) is using generic data from the Nuclear Regulatory Commission's database of common cause failures at nuclear power plants to estimate CCF due to the lack of a more appropriate data source. There remains uncertainty in the actual magnitude of the common cause risk estimates for different systems at this stage of the design. Given the limited data about launch vehicle CCF and that launch vehicles are a highly redundant system by design, it is important to make design decisions to account for a range of values for independent and CCFs. When investigating the design of the one-out-of-two component redundant system for launch vehicles, a response surface was constructed to represent the impact of the independent failure rate versus a common cause beta factor effect on a system's failure probability. This presentation will define a CCF and review estimation calculations. It gives a summary of reduction methodologies and a review of examples of historical CCFs. Finally, it presents the response surface and discusses the results of the different CCFs on the reliability of a one-out-of-two system.

Hark, Frank↗

Common Cause Failure Modeling

Common Cause Failures (CCFs) are a known and documented phenomenon that defeats system redundancy. CCFS are a set of dependent type of failures that can be caused by: system environments; manufacturing; transportation; storage; maintenance; and assembly, as examples. Since there are many factors that contribute to CCFs, the effects can be reduced, but they are difficult to eliminate entirely. Furthermore, failure databases sometimes fail to differentiate between independent and CCF (dependent) failure and data is limited, especially for launch vehicles. The Probabilistic Risk Assessment (PRA) of NASA's Safety and Mission Assurance Directorate at Marshal Space Flight Center (MFSC) is using generic data from the Nuclear Regulatory Commission's database of common cause failures at nuclear power plants to estimate CCF due to the lack of a more appropriate data source. There remains uncertainty in the actual magnitude of the common cause risk estimates for different systems at this stage of the design. Given the limited data about launch vehicle CCF and that launch vehicles are a highly redundant system by design, it is important to make design decisions to account for a range of values for independent and CCFs. When investigating the design of the one-out-of-two component redundant system for launch vehicles, a response surface was constructed to represent the impact of the independent failure rate versus a common cause beta factor effect on a system's failure probability. This presentation will define a CCF and review estimation calculations. It gives a summary of reduction methodologies and a review of examples of historical CCFs. Finally, it presents the response surface and discusses the results of the different CCFs on the reliability of a one-out-of-two system.

Hark, Frank↗

Probabilistic Risk Assessment Procedures Guide for NASA Managers and Practitioners (Second Edition)

Probabilistic Risk Assessment (PRA) is a comprehensive, structured, and logical analysis method aimed at identifying and assessing risks in complex technological systems for the purpose of cost-effectively improving their safety and performance. NASA's objective is to better understand and effectively manage risk, and thus more effectively ensure mission and programmatic success, and to achieve and maintain high safety standards at NASA. NASA intends to use risk assessment in its programs and projects to support optimal management decision making for the improvement of safety and program performance. In addition to using quantitative/probabilistic risk assessment to improve safety and enhance the safety decision process, NASA has incorporated quantitative risk assessment into its system safety assessment process, which until now has relied primarily on a qualitative representation of risk. Also, NASA has recently adopted the Risk-Informed Decision Making (RIDM) process [1-1] as a valuable addition to supplement existing deterministic and experience-based engineering methods and tools. Over the years, NASA has been a leader in most of the technologies it has employed in its programs. One would think that PRA should be no exception. In fact, it would be natural for NASA to be a leader in PRA because, as a technology pioneer, NASA uses risk assessment and management implicitly or explicitly on a daily basis. NASA has probabilistic safety requirements (thresholds and goals) for crew transportation system missions to the International Space Station (ISS) [1-2]. NASA intends to have probabilistic requirements for any new human spaceflight transportation system acquisition. Methods to perform risk and reliability assessment in the early 1960s originated in U.S. aerospace and missile programs. Fault tree analysis (FTA) is an example. It would have been a reasonable extrapolation to expect that NASA would also become the world leader in the application of PRA. That was, however, not to happen. Early in the Apollo program, estimates of the probability for a successful roundtrip human mission to the moon yielded disappointingly low (and suspect) values and NASA became discouraged from further performing quantitative risk analyses until some two decades later when the methods were more refined, rigorous, and repeatable. Instead, NASA decided to rely primarily on the Hazard Analysis (HA) and Failure Modes and Effects Analysis (FMEA) methods for system safety assessment.

Stamatelatos,Michael↗

Taking the Risk Out of Risk Assessment

The ability to understand risks and have the right strategies in place when risky events occur is essential in the workplace. More and more organizations are being confronted with concerns over how to measure their risks or what kind of risks they can take when certain events transpire that could have a negative impact. NASA is one organization that faces these challenges on a daily basis, as effective risk management is critical to the success of its missions especially the Space Shuttle missions. On July 29, 1996, former NASA Administrator Daniel Goldin charged NASA s Office of Safety and Mission Assurance with developing a probabilistic risk assessment (PRA) tool to support decisions on the funding of Space Shuttle upgrades. When issuing the directive, Goldin said, "Since I came to NASA [in 1992], we've spent billions of dollars on Shuttle upgrades without knowing how much they improve safety. I want a tool to help base upgrade decisions on risk." Work on the PRA tool began immediately. The resulting prototype, the Quantitative Risk Assessment System (QRAS) Version 1.0, was jointly developed by NASA s Marshall Space Flight Center, its Office of Safety and Mission Assurance, and researchers at the University of Maryland. QRAS software automatically expands the reliability logic models of systems to evaluate the probability of highly detrimental outcomes occurring in complex systems that are subject to potential accident scenarios. Even in its earliest forms, QRAS was used to begin PRA modeling of the Space Shuttle. In parallel, the development of QRAS continued, with the goal of making it a world-class tool, one that was especially suited to NASA s unique needs. From the beginning, an important conceptual goal in the development of QRAS was for it to help bridge the gap between the professional risk analyst and the design engineer. In the past, only the professional risk analyst could perform, modify, use, and perhaps even adequately understand PRA. NASA wanted to change this by developing a PRA tool that would be friendlier, more understandable, and more useful to the broader engineering community. This concept ultimately led to the look, feel, and functionality that QRAS has today.

Source record↗

Hydrogen Plus Other Alternative Fuels Risk Assessment Models (HyRAM+) Version 4.1 Technical Reference Manual

The HyRAM+ software toolkit provides a basis for conducting quantitative risk assessment and consequence modeling for hydrogen, methane, and propane systems. HyRAM+ is designed to facilitate the use of state-of-the-art models to conduct robust, repeatable assessments of safety, hazards, and risk. HyRAM+ integrates deterministic and probabilistic models for quantifying accident scenarios, predicting physical effects, characterizing hazards (thermal effects from jet fires, overpressure effects from delayed ignition), and assessing impacts on people. HyRAM+ is developed at Sandia National Laboratories to support the development and revision of national and international codes and standards, and to provide developed models in a publicly-accessible toolkit usable by all stakeholders. This document provides a description of the methodology and models contained in HyRAM+ version 4.1. The two most significant changes for HyRAM+ version 4.1 from HyRAM+ version 4.0 are direct incorporation of unconfined overpressure into the QRA calculations and modification of the models for cryogenic liquid flow through an orifice. In QRA mode, the user no longer needs to input peak overpressure and impulse values that were calculated separately; rather, the unconfined overpressure is estimated for the given system inputs, leak size, and occupant location. The orifice flow model now solves for the maximum mass flux through the orifice at constant entropy while conserving energy, which does not require a direct speed of sound calculation. This does not affect the mass flow for all-gaseous releases; the method results in the same speed of sound for choked flow. However, this method does result in a higher (and more realistic) mass flow rate for a given leak size for liquid releases than was previously calculated.

08 HYDROGEN↗

Hydrogen Plus Other Alternative Fuels Risk Assessment Models (HyRAM+) Version 5.0 Technical Reference Manual

The HyRAM+ software toolkit provides a basis for conducting quantitative risk assessment and consequence modeling for hydrogen, natural gas, and autogas systems. HyRAM+ is designed to facilitate the use of state-of-the-art models to conduct robust, repeatable assessments of safety, hazards, and risk. HyRAM+ integrates deterministic and probabilistic models for quantifying leak sizes and rates, predicting physical effects, characterizing hazards (thermal effects from jet fires, overpressure effects from delayed ignition), and assessing impacts on people. HyRAM+ is developed at Sandia National Laboratories to support the development and revision of national and international codes and standards, and to provide developed models in a publicly-accessible toolkit usable by all stakeholders. This document provides a description of the methodology and models contained in HyRAM+ version 5.0. The most significant change for HyRAM+ version 5.0 from HyRAM+ version 4.1 is the ability to model blends of different fuels. HyRAM+ was previously only suitable for use with hydrogen, methane, or propane, with users having the ability to use methane as a proxy for natural gas and propane as a proxy for autogas/liquefied petroleum gas. In version 5.0, real natural gas or autogas compositions can be modeled as the fuel, or even blends of natural gas with hydrogen. These blends can be used in the standalone physics models, but not yet in the quantitative risk assessment mode of HyRAM+.

03 NATURAL GAS↗

Hydrogen Plus Other Alternative Fuels Risk Assessment Models (HyRAM+) Version 5.1 Technical Reference Manual

The HyRAM+ software toolkit provides a basis for conducting quantitative risk assessment and consequence modeling for hydrogen, natural gas, and autogas systems. HyRAM+ is designed to facilitate the use of state-of-the-art models to conduct robust, repeatable assessments of safety, hazards, and risk. HyRAM+ integrates deterministic and probabilistic models for quantifying leak sizes and rates, predicting physical effects, characterizing hazards (thermal effects from jet fires, overpressure effects from delayed ignition), and assessing impacts on people. HyRAM+ is developed at Sandia National Laboratories to support the development and revision of national and international codes and standards, and to provide developed models in a publicly-accessible toolkit usable by all stakeholders. This document provides a description of the methodology and models contained in HyRAM+ version 5.1. The most significant changes for HyRAM+ version 5.1 from HyRAM+ version 5.0 are updated default leak frequency values for propane, new default component counts for different fuel types, and an improved fuel specification view in the graphical user interface.

02 PETROLEUM↗

Evaluating Faulty State Occurrence in Wildfire UAS Missions Using Markov Chains

As autonomous technology advances, unmanned aircraft systems are increasingly integrated into emergency response missions, such as wildfire response. These systems must be be safe with less risk than non-autonomous counter parts, yet quantifying the risk associated with present-day and future systems conventionally relies solely on expert opinion and little data. Instead, combining narrative mishap reports with probabilistic analysis can provide a method for evolutionary and timely risk analysis. In this paper, we present a framework for a data-driven probabilistic risk assessment style analysis, where hazard events and rates originate from documented UAS mishaps. The framework is applied to a UAS mapping mission in wildfire response, including a fault tree analysis, event tree analysis, and probabilistic analysis using Markov Chains. The analysis provides an enumeration of hazards in the system, hazard events that can lead to faults, the probability of a mission experiencing any fault, the probability of experiencing a specific fault, and the expected time spent until faulty states occur in present-day operations.

risk analysis↗

Evaluating Faulty State Occurrence in Wildfire UAS Missions Using Markov Chains

As autonomous technology advances, unmanned aircraft systems are increasingly integrated into emergency response missions, such as wildfire response. These systems must be be safe with less risk than non-autonomous counter parts, yet quantifying the risk associated with present-day and future systems conventionally relies solely on expert opinion and little data. Instead, combining narrative mishap reports with probabilistic analysis can provide a method for evolutionary and timely risk analysis. In this paper, we present a framework for a data-driven probabilistic risk assessment style analysis, where hazard events and rates originate from documented UAS mishaps. The framework is applied to a UAS mapping mission in wildfire response, including a fault tree analysis, event tree analysis, and probabilistic analysis using Markov Chains. The analysis provides an enumeration of hazards in the system, hazard events that can lead to faults, the probability of a mission experiencing any fault, the probability of experiencing a specific fault, and the expected time spent until faulty states occur in present-day operations.

risk analysis↗

Applications and Performance of a Lightning Risk Assessment using Geostationary Lightning Mapper (GLM) Data

Lightning is a hazard globally, particularly in lesser-developed countries. Cloud-to-ground lightning strikes are a threat to human safety, motivating a desire to monitor location-based lightning risk to mitigate harm. A lightning risk assessment for human safety was created that uses a combination of probabilistic risk calculation and spatial lightning mapping data to produce a risk magnitude. This risk magnitude evolves with time and changing conditions and is compared to tolerability thresholds in order to evaluate safety. The risk assessment using lightning mapping array (LMA) flash extent density (FED) data was found to perform comparatively (with respect to issuing lightning warnings) to a more standard method of monitoring lightning safety where National Lightning Detection Network (NLDN) flashes were monitored within a 5 nautical mile radius of a location of interest. This research investigates the replacement of LMA FED with FED from the Geostationary Lightning Mapper (GLM) within the risk assessment framework. Using GLM FED would allow for risk to be calculated outside of LMA domains and anywhere within the GLM field of view, including areas outside of the United States (US). A few applications of the risk method with GLM FED are shown and discussed for locations both in and outside of the US. Additionally, the performance of the risk method is compared based on the type of lightning input source (LMA vs GLM). The end goal of this work is to provide forecasters and end users with a tool to help monitor lightning risk in decision support scenarios.

Kelley Murphy↗

PSRP Approach to PRA

There have been two scenarios in which the Payload Safety Review Panel (PSRP) has considered a Probabilistic Risk Assessment (PRA) a viable tool. For use in considering trade-offs during the initial design. When in a waiver condition to explain rationale for acceptance. The PSRP would consider the use of PRA in other applications where credible.

Stewart, Christine↗

The Meaning of Risk for Safety, Security, and Safeguards in the Design of Advanced Nuclear Reactors

What is the meaning of risk as it applies to the design of advanced reactors in the disciplines of safety, security, and safeguards? How can we find common terminology for the concept of risk and how can we find interfaces between these disciplines? These are important questions that should be explored in order that they may be applied in an integrated manner for the most effective and efficient design approaches. Eliminating or minimizing risks is a key design driver that motivates and informs the development of nuclear reactors. For safety, risk is well understood and applied in Probabilistic Risk Assessments. For security, the risk-based concepts of vulnerability assessments and vital areas are all considered in designing security systems. For safeguards, the concept of risk is not formally defined, as it relates to the design and operation of nuclear reactors. International nuclear safeguards seek to reduce the risk of proliferation in the nuclear fuel cycle and as such the concept of risk does exist. Therefore, the current understanding of the “3S’ approach, which seeks to find the interfaces and conflicts between safety, security, and safeguards requires a thorough understanding of the role that the reduction of risk plays in all three disciplines. The intersection of risk for safety and security is now being developed as there is a strong correlation between reactor design and operations and their vulnerability to sabotage. The intersection of risk for security and safeguards has to date chiefly been focused on the nuclear material control and accounting systems, which are relied on by both the operator (State) and the IAEA. This paper explores the concept of risk in each of the three disciplines, how they interact, potential conflicts and interfaces , how these might be addressed and leveraged, and a notional framework for how this could be achieved.

Kovacic, Donald N↗

Risk-Informed Approach for Regulatory Approval of Microreactor Transport

Pacific Northwest National Laboratory (PNNL) is addressing the challenges associated with safe transport of microreactors including the development and evaluation of regulatory options. PNNL developed a risk-informed regulatory framework for the licensing of the transportation of microreactors in which irradiated nuclear fuel is part microreactor transportation package. The framework lays out a viable regulatory pathway, including decision points for regulatory options and the supporting technical evaluations for those options in phases from near to long term. A microreactor and its contents will likely not be able to meet all the federal regulatory requirements as a Type B or fissile material transportation package under 10 CFR Part 71 (“Packaging and Transportation of Radioactive Material”). However, the regulatory framework developed by PNNL lays out a viable risk-informed licensing options that are safe and feasible. Risk assessment such as probabilistic risk assessment (PRA) can be used to show comparable safety to that provided by a Type B or fissile material package for surface transport. The framework includes guidance on applicable regulations and discusses historical precedence in using risk information for transportation licensing. The framework includes guidance for performing a microreactor transportation PRA, use and development of risk evaluation criteria, and factors such of defense-in-depth and safety margin concepts. Key advantages of using the approach are (1) increasing the likelihood of successfully obtaining regulatory transportation package approval, (2) informing the design on the relative risk significance of microreactor containment and shielding, and (3) informing the need for transportation compensatory measures. This paper focuses on two primary elements of the framework which are development of a transportation PRA for microreactor packages and development of the risk acceptance guidelines to assess the results of the PRA for regulatory decision-making.

microreactor, micro nuclear power plant, MNPP, ris↗

Ares I Static Tests Design

Probabilistic engineering design enhances safety and reduces costs by incorporating risk assessment directly into the design process. In this paper, we assess the format of the quantitative metrics for the vehicle which will replace the Space Shuttle, the Ares I rocket. Specifically, we address the metrics for in-flight measurement error in the vector position of the motor nozzle, dictated by limits on guidance, navigation, and control systems. Analyses include the propagation of error from measured to derived parameters, the time-series of dwell points for the duty cycle during static tests, and commanded versus achieved yaw angle during tests. Based on these analyses, we recommend a probabilistic template for specifying the maximum error in angular displacement and radial offset for the nozzle-position vector. Criteria for evaluating individual tests and risky decisions also are developed.

Carson, William↗

Hydrogen Risk Assessment Models (HyRAM) (V.3.1) (Technical Reference Manual)

The HyRAM software toolkit provides a basis for conducting quantitative risk assessment and consequence modeling for hydrogen infrastructure and transportation systems. HyRAM is designed to facilitate the use of state-of-the-art science and engineering models to conduct robust, repeatable assessments of hydrogen safety, hazards, and risk. HyRAM includes generic probabilities for hydrogen equipment failures, probabilistic models for the impact of heat flux on humans and structures, and experimentally validated first-order models of hydrogen release and flame physics. HyRAM integrates deterministic and probabilistic models for quantifying accident scenarios, predicting physical effects, and characterizing hydrogen hazards (thermal effects from jet res, overpressure effects from deflagrations), and assessing impact on people and structures. HyRAM is developed at Sandia National Laboratories for the U.S. Department of Energy to increase access to technical data about hydrogen safety and to enable the use of that data to support development and revision of national and international codes and standards. HyRAM is a research software in active development and thus the models and data may change. This report will be updated at appropriate developmental intervals. This document provides a description of the methodology and models contained in HyRAM version 3.1. There have been several impactful updates since version 3.0. HyRAM 3.1 contains a correction to use the volume fraction for two-phase speed of sound calculations; this only affects cryogenic releases in which two-phase ow (vapor and liquid) is predicted in the orifice. Other changes include clarifications that inputs for tank pressure should be given in absolute pressure, not gauge pressure. Additionally, the interface now rejects invalid inputs to probability distributions, and the less accurate single-point radiative source model selection was removed from the interface.

08 HYDROGEN↗