Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Safety Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

COLD-SAT feasibility study safety analysis

The Cryogenic On-orbit Liquid Depot-Storage, Acquisition, and Transfer (COLD-SAT) satellite presents some unique safety issues. The feasibility study conducted at NASA-Lewis desired a systems safety program that would be involved from the initial design in order to eliminate and/or control the inherent hazards. Because of this, a hazards analysis method was needed that: (1) identified issues that needed to be addressed for a feasibility assessment; and (2) identified all potential hazards that would need to be controlled and/or eliminated during the detailed design phases. The developed analysis method is presented as well as the results generated for the COLD-SAT system.

Mchenry, Steven T.↗

Conjugate Heat Transfer Modeling of Salt-Filled Fuel Pins for Stable Salt Reactor Safety Analysis

The Stable Salt Reactor (SSR) combines the proven structural design of light water reactor fuel assemblies with the inherent safety and fuel-cycle advantages of molten salt technology. In its fast reactor configuration, the SSR utilizes recycled nuclear waste as fuel, sealed within narrow salt-filled fuel pins and cooled by a surrounding liquid salt coolant. Reliable transfer of heat from the molten fuel salt through the cladding to the external coolant is essential for both reactor safety and performance. This work investigates conjugate heat transfer (CHT) in the SSR’s salt-filled fuel pins using NekRS, a high-fidelity spectral element computational fluid dynamics (CFD) solver. The analyses capture internal natural convection within the molten fuel salt and external forced convection in the coolant, under steady-state and transient operating conditions. Parametric studies evaluate how variations in reactor power and coolant flow rate influence heat transfer distributions and system response. The high-fidelity CFD results are time-averaged and post-processed for direct comparison with moderate-fidelity Reynolds-averaged Navier–Stokes (RANS) models, and for the development of reduced-order models within the SAM system code. These validated models support fast-running safety analyses of normal and off-normal transients, improving predictive capability for key safety margins. By integrating advanced CFD with system-level safety tools, this study strengthens the modeling framework for SSR design, reduces uncertainty in molten salt CHT simulations, and accelerates the engineering and licensing of next-generation nuclear reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Forced flow transient safety analysis of irradiation device with adjustable orifice for research reactor fuel assemblies

The Belgium Reactor 2 (BR2) of the Belgian Nuclear Research Centre (SCK CEN) has several irradiation devices or rigs that are dedicated to the fuel performance and qualification demonstration testing of research reactor fuels. In support of the U.S. High Performance Research Reactor (USHPRR) LEU conversion project, a new flexible irradiation apparatus, MUSTANG-R, has been constructed. SCK CEN has completed the design and safety study, in cooperation with Idaho National Laboratory (INL) and Argonne National Laboratory (ANL), to allow for the irradiation testing of a full-size fuel assembly in a 200 mm diameter channel in the BR2 reactor. The moveable valve is a key design feature of the device and acts like an adjustable orifice enhancing or restricting the flow through a coolant channel inlet located in the BR2 upper plenum. This moveable valve allows the flow through the device to be adjusted prior to each BR2 cycle to obtain the necessary conditions for the fuel qualification test. This ensures accurate and representative thermal-hydraulic conditions of the fuel design are achieved. The device was designed and qualified as passively safe, implying verification by a combination of mechanical and thermal-hydraulic analysis and testing. This includes characterization of the safety margin required for a scenario where the moveable valve is assumed to be erroneously closed during irradiation. A simplified and conservative method is proposed for analyzing the corresponding forced flow transient using a critical heat flux criterion. In conclusion, this allows the required minimum valve opening to be determined for the experiments' design and safety studies.

11 - NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

A Radiation Safety Analysis for Lunar Lava Tubes

The purpose of this work is an assessment of the lunar lava tubes physical characteristics and an evaluation of the their actual safety features from the point of view of the ionizing radiation environment as potential habitats for future lunar exploration crews. Additional information is contained in the original extended abstract.

DeAngelis, G.↗

Prospective Safety Analysis and the Complex Aviation System

Fatal accident rates in commercial passenger aviation are at historic lows yet have plateaued and are not showing evidence of further safety advances. Modern aircraft accidents reflect both historic causal factors and new unexpected "Black Swan" events. The ever-increasing complexity of the aviation system, along with its associated technology and organizational relationships, provides fertile ground for fresh problems. It is important to take a proactive approach to aviation safety by working to identify novel causation mechanisms for future aviation accidents before they happen. Progress has been made in using of historic data to identify the telltale signals preceding aviation accidents and incidents, using the large repositories of discrete and continuous data on aircraft and air traffic control performance and information reported by front-line personnel. Nevertheless, the aviation community is increasingly embracing predictive approaches to aviation safety. The "prospective workshop" early assessment tool described in this paper represents an approach toward this prospective mindset-one that attempts to identify the future vectors of aviation and asks the question: "What haven't we considered in our current safety assessments?" New causation mechanisms threatening aviation safety will arise in the future because new (or revised) systems and procedures will have to be used under future contextual conditions that have not been properly anticipated. Many simulation models exist for demonstrating the safety cases of new operational concepts and technologies. However the results from such models can only be as valid as the accuracy and completeness of assumptions made about the future context in which the new operational concepts and/or technologies will be immersed. Of course that future has not happened yet. What is needed is a reasonably high-confidence description of the future operational context, capturing critical contextual characteristics that modulate both the likelihood of occurrence of hazards, and the likelihood that those hazards will lead to negative safety events. Heuristics extracted from scenarios, questionnaires, and observed trends from scanning the aviation horizon may be helpful in capturing those future changes in a way conducive to safety assessment. What is also needed is a checklist of potential sources of emerging risk that arise from organizational features that are frequently overlooked. The ultimate goal is to develop a pragmatic, workable method for using descriptions of the future aviation context, to generate valid predictions of safety risks.

prospection↗

Accelerated Monte Carlo Simulation for Safety Analysis of the Advanced Airspace Concept

Safe separation of aircraft is a primary objective of any air traffic control system. An accelerated Monte Carlo approach was developed to assess the level of safety provided by a proposed next-generation air traffic control system. It combines features of fault tree and standard Monte Carlo methods. It runs more than one order of magnitude faster than the standard Monte Carlo method while providing risk estimates that only differ by about 10%. It also preserves component-level model fidelity that is difficult to maintain using the standard fault tree method. This balance of speed and fidelity allows sensitivity analysis to be completed in days instead of weeks or months with the standard Monte Carlo method. Results indicate that risk estimates are sensitive to transponder, pilot visual avoidance, and conflict detection failure probabilities.

Thipphavong, David↗

Sense and Avoid Safety Analysis for Remotely Operated Unmanned Aircraft in the National Airspace System. Version 5

This document describes a method to demonstrate that a UAS, operating in the NAS, can avoid collisions with an equivalent level of safety compared to a manned aircraft. The method is based on the calculation of a collision probability for a UAS , the calculation of a collision probability for a base line manned aircraft, and the calculation of a risk ratio given by: Risk Ratio = P(collision_UAS)/P(collision_manned). A UAS will achieve an equivalent level of safety for collision risk if the Risk Ratio is less than or equal to one. Calculation of the probability of collision for UAS and manned aircraft is accomplished through event/fault trees.

Carreno, Victor↗

Safety Analysis of Soybean Processing for Advanced Life Support

Soybeans (cv. Hoyt) is one of the crops planned for food production within the Advanced Life Support System Integration Testbed (ALSSIT), a proposed habitat simulation for long duration lunar/Mars missions. Soybeans may be processed into a variety of food products, including soymilk, tofu, and tempeh. Due to the closed environmental system and importance of crew health maintenance, food safety is a primary concern on long duration space missions. Identification of the food safety hazards and critical control points associated with the closed ALSSIT system is essential for the development of safe food processing techniques and equipment. A Hazard Analysis Critical Control Point (HACCP) model was developed to reflect proposed production and processing protocols for ALSSIT soybeans. Soybean processing was placed in the type III risk category. During the processing of ALSSIT-grown soybeans, critical control points were identified to control microbiological hazards, particularly mycotoxins, and chemical hazards from antinutrients. Critical limits were suggested at each CCP. Food safety recommendations regarding the hazards and risks associated with growing, harvesting, and processing soybeans; biomass management; and use of multifunctional equipment were made in consideration of the limitations and restraints of the closed ALSSIT.

Hentges, Dawn L.↗

Architectural Modeling and Analysis for Safety Engineering

Model-based development tools are increasingly being used for system-level development of safety-critical systems. Architectural and behavioral models provide important information that can be leveraged to improve the system safety analysis process. Model-based design artifacts produced in early stage development activities can be used to perform system safety analysis, reducing costs and providing accurate results throughout the system life-cycle. In this report we describe an extension to the Architecture Analysis and Design Language (AADL) that supports modeling of system behavior under failure conditions. This Safety Annex enables the independent modeling of component failures and allows safety engineers to weave various types of fault behavior into the nominal system model. The accompanying tool support uses model checking to propagate errors from their source to their effect on safety properties without the need to add separate propagation specifications. The tool also captures all minimal set of fault combinations that can cause violation of the safety properties, that can be compared to qualitative and quantitative objectives as part of the safety assessment process. We describe the Safety Annex, illustrate its use with a representative example, and discuss and demonstrate the tool support enabling an analyst to investigate the system behavior under failure conditions.

FTA↗

A Modeling Approach for Handling Qualities and Controls Safety Analysis of Electric Air Taxi Vehicles

The combination of modern advances in electric propulsion, fly-by-wire controls, autonomy, and increasing demand for short range air taxi operations, is currently producing an outburst of vehicle designs more diverse than ever before. Advanced software tools are needed to support the rapid and safe introduction of any design into the airspace, including the safety of the deployed flight control system and vehicle handling qualities. This paper presents a methodology for building air taxi vehicle models with distributed electric propulsion for use in analyzing flight control system safety at the conceptual design level.The approach builds on existing software tools capable of outputting aeromechanics-based linear perturbation models for Vertical Take-off and Landing vehicles with multiple rotors. Rotor torque inputs are then converted into equivalent voltage control inputs, and the linear state and input dynamics matrices are modified to include electric motor dynamics with common parameters for direct-current electric motors. The linear perturbation dynamics are then stitched across multiple operating points into a quasi-Linear Parameter Varying model that covers the full flight envelope. A Model Predictive Controller is developed for use with the full envelope model, and a tradeoff analysis between handling quality and motor requirements is demonstrated using a six passenger NASA air taxi reference design.

Urban Air Mobility↗

Integrated Handling Qualities Safety Analysis For Conceptual Design of Urban Air Mobility Vehicles

The recent emergence of distributed electric propulsion Vertical Takeoff and Landing (VTOL) aircraft has created a rapid introduction of new design concepts with unique stability and control characteristics. A challenge to realizing the full potential of these vehicles for urban transportation is to gain public acceptance which is largely driven by flight safety. This paper describes ongoing research to address the feasibility of integrating flying qualities safety metrics into conceptual design of VTOL Urban Air Mobility (UAM) vehicles. The discussion is composed of the approach and progress toward a toolbox that integrates with existing NASA rotorcraft design software and processes. Several key challenges are highlighted including modeling requirements for failures, identification of critical failures, and capturing critical failures, with robustness to model uncertainty. A discussion of requirements for safety metrics, specific to UAM vehicles, as well as the effects of the control system design is also included. Results to date have demonstrated the degradation in flying qualities metrics due to propulsion failures.

George Altamirano↗

Radiological Safety Analysis Computer Program V 7.2

Users generates a fission product inventory from either reactor operating history or a nuclear criticality event. RSAC-7 models the effects of high-efficiency particulate air filters or other cleanup systems and calculates the decay and ingrowth during transport through processes, facilities, and the environment. Doses are calculated for inhalation, air immersion, ground surface, ingestion, and cloud gamma pathways. RSAC-7 is used as a tool to evaluate accident conditions in emergency response scenarios, radiological sabotage events, and safety basis accident consequences.

Jordan, RobertaA. [Idaho National Laboratory (INL)↗

A Mathematical Basis for the Safety Analysis of Conflict Prevention Algorithms

In air traffic management systems, a conflict prevention system examines the traffic and provides ranges of guidance maneuvers that avoid conflicts. This guidance takes the form of ranges of track angles, vertical speeds, or ground speeds. These ranges may be assembled into prevention bands: maneuvers that should not be taken. Unlike conflict resolution systems, which presume that the aircraft already has a conflict, conflict prevention systems show conflicts for all maneuvers. Without conflict prevention information, a pilot might perform a maneuver that causes a near-term conflict. Because near-term conflicts can lead to safety concerns, strong verification of correct operation is required. This paper presents a mathematical framework to analyze the correctness of algorithms that produce conflict prevention information. This paper examines multiple mathematical approaches: iterative, vector algebraic, and trigonometric. The correctness theories are structured first to analyze conflict prevention information for all aircraft. Next, these theories are augmented to consider aircraft which will create a conflict within a given lookahead time. Certain key functions for a candidate algorithm, which satisfy this mathematical basis are presented; however, the proof that a full algorithm using these functions completely satisfies the definition of safety is not provided.

Maddalon, Jeffrey M.↗

The SAS4A/SASSYS-1 Version 5.8 Safety Analysis Code System

SAS4A/SASSYS-1 is a software simulation tool used to perform deterministic analysis of anticipated events as well as design basis and beyond design basis accidents for advanced nuclear reactors. Detailed, mechanistic models of steady-state and transient thermal, hydraulic, kinetic, and mechanical phenomena are employed to describe the response of the reactor core, the reactor primary and secondary coolant loops, the reactor control and protection systems, and the balance-of-plant to accidents caused by changes in coolant flow, loss of heat rejection, or reactivity insertion. The consequences of single and double-fault accidents can be modeled, including fuel and coolant heating, fuel and cladding mechanical behavior, core reactivity feedbacks, coolant loop performance including natural circulation, and decay heat removal. Analyses are typically terminated upon demonstration of reactor and plant shutdown to permanently coolable conditions, or upon violation of design basis margins. The objective of the analysis is to quantify accident consequences as measured by the transient behavior of system performance parameters, such as fuel and cladding temperatures, reactivity, and cladding strain. Originally developed for analysis of sodium cooled reactors with oxide fuel clad by stainless steel, the models were subsequently extended and specialized to metallic fuel clad with advanced alloys and to several other coolant options, including lead, LBE, and water.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗