Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Safety Case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Proposal for a Sample Pilot Response Model

Regulations to establish operational and performance requirements for unmanned aircraft systems (UAS) are being developed by a consortium of government, industry and academic institutions. Those requirements will apply to the new detect and avoid (DAA) systems and other equipment necessary to integrate UAS with the National Airspace System (NAS) and are determined according to their contribution to the overall safety case for such an integration. In order to perform end-to-end verification and validation of DAA requirements, a committee accepted pilot response model is needed to emulate UAS pilots in closed-loop Monte Carlo fast-time simulations. This briefing focuses on background of the pilot model used in previous Airspace Concept Evaluation System studies, identification of strengths and weaknesses in that model, and proposals on model improvements. The briefing also looks to build consensus around a common architecture and assumptions for modeling the pilot for UAS DAA systems.

Santiago, Confesor

Model Based Mission Assurance: NASA's Assurance Future

Model Based Systems Engineering (MBSE) is seeing increased application in planning and design of NASA’s missions. This suggests the question: what will be the corresponding practice of Model Based Mission Assurance (MBMA)? Contemporaneously, NASA’s Office of Safety and Mission Assurance (OSMA) is evaluating a new objectives based approach to standards to ensure that the Safety and Mission Assurance disciplines and programs are addressing the challenges of NASA’s changing missions, acquisition and engineering practices, and technology. MBSE is a prominent example of a changing engineering practice. We use NASA’s objectives-based strategy for Reliability and Maintainability as a means to examine how MBSE will affect assurance. We surveyed MBSE literature to look specifically for these affects, and find a variety of them discussed (some are anticipated, some are reported from applications to date). Predominantly these apply to the early stages of design, although there are also extrapolations of how MBSE practices will have benefits for testing phases. As the effort to develop MBMA continues, it will need to clearly and unambiguously establish the roles of uncertainty and risk in the system model. This will enable a variety of uncertainty-based analyses to be performed much more rapidly than ever before and has the promise to increase the integration of CRM (Continuous Risk Management) and PRA (Probabilistic Risk Analyses) even more fully into the project development life cycle. Various views and viewpoints will be required for assurance disciplines, and an over-arching viewpoint will then be able to more completely characterize the state of the project/program as well as (possibly) enabling the safety case approach for overall risk awareness and communication.

Evans, John

A Primer on Argument

The purpose of this document is to provide a common understanding of terms, concepts, principles, and uses of argument. It emphasizes the practical over the theoretical and the simple over the complicated.

argument

SCM overview & the EBR-II shutdown heat removal tests validation.

Pronghorn is an engineering-scale, coarse-mesh, thermal-hydraulics tool for supporting reactor-core simulations of advanced nuclear reactors. Most of the current efforts in Pronghorn have been devoted in developing porous finite-volume capabilities and adapting closure correlations for coarse-mesh thermal-hydraulics modeling. However, for liquid-metal reactors (LMRs) with wire-wrapped fuel pin assemblies, a pin-level thermal-hydraulic resolution is required for most safety case studies (pin rupture, channel blockage, etc.). For this purpose, a new Subchannel application is developed in MOOSE, which affords the required flow field resolution, while still preserving an engineering-scale approach. This new solver can be natively coupled to Pronghorn and other MOOSE objects to enable full-core, multi-physics, multi-scale engineering studies. This presentation presents the main features of the SCM code and demonstrates a validation case based on the EBR-II SHRT tests.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

Risk Posture

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

42 ENGINEERING

Safety Assurance Framework for Nuclear Digital Instrumentation and Control Software

Software in digital instrumentation and control (D&C) systems poses unique challenges for the safety assurance of nuclear power plants. Through a literature survey of 21 sources, we analyzed various claims, arguments, and evidence used in safety assurance cases across industries. These were organized into a Goal Structuring Notation (GSN) safety assurance case framework to organize and visualize the various arguments for DI&C safety. We developed a classification for the levels of the framework, which can be used in other safety assurance cases to improve clarity.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN

A Case Study of Measuring Process Risk for Early Insights into Software Safety

In this case study, we examine software safety risk in three flight hardware systems in NASA's Constellation spaceflight program. We applied our Technical and Process Risk Measurement (TPRM) methodology to the Constellation hazard analysis process to quantify the technical and process risks involving software safety in the early design phase of these projects. We analyzed 154 hazard reports and collected metrics to measure the prevalence of software in hazards and the specificity of descriptions of software causes of hazardous conditions. We found that 49-70% of 154 hazardous conditions could be caused by software or software was involved in the prevention of the hazardous condition. We also found that 12-17% of the 2013 hazard causes involved software, and that 23-29% of all causes had a software control. The application of the TPRM methodology identified process risks in the application of the hazard analysis process itself that may lead to software safety risk.

Layman, Lucas

Development of a software safety process and a case study of its use

The goal of this research is to continue the development of a comprehensive approach to software safety and to evaluate the approach with a case study. The case study is a major part of the project, and it involves the analysis of a specific safety-critical system from the medical equipment domain. The particular application being used was selected because of the availability of a suitable candidate system. We consider the results to be generally applicable and in no way particularly limited by the domain. The research is concentrating on issues raised by the specification and verification phases of the software lifecycle since they are central to our previously-developed rigorous definitions of software safety. The theoretical research is based on our framework of definitions for software safety. In the area of specification, the main topics being investigated are the development of techniques for building system fault trees that correctly incorporate software issues and the development of rigorous techniques for the preparation of software safety specifications. The research results are documented. Another area of theoretical investigation is the development of verification methods tailored to the characteristics of safety requirements. Verification of the correct implementation of the safety specification is central to the goal of establishing safe software. The empirical component of this research is focusing on a case study in order to provide detailed characterizations of the issues as they appear in practice, and to provide a testbed for the evaluation of various existing and new theoretical results, tools, and techniques. The Magnetic Stereotaxis System is summarized.

Knight, John C.

AdvoCATE - User Guide

The basic vision of AdvoCATE is to automate the creation, manipulation, and management of large-scale assurance cases based on a formal theory of argument structures. Its main purposes are for creating and manipulating argument structures for safety assurance cases using the Goal Structuring Notation (GSN), and as a test bed and proof-of-concept for the formal theory of argument structures. AdvoCATE is available for Windows 7, Macintosh OSX, and Linux. Eventually, AdvoCATE will serve as a dashboard for safety related information and provide an infrastructure for safety decisions and management.

Safety Case

The reduction of a ""safety catastrophic'' potential hazard: A case history

A worst case analysis is reported on the safety of time watch movements for triggering explosive packages on the lunar surface in an experiment to investigate physical lunar structural characteristics through induced seismic energy waves. Considered are the combined effects of low pressure, low temperature, lunar gravity, gear train error, and position. Control measures constitute a seal control cavity and design requirements to prevent overbanking in the mainspring torque curve. Thus, the potential hazard is reduced to safety negligible.

Joseph P. Jones

DMBZ Polyimides Provide an Alternative to PMR-15 for High-Temperature Applications

PMR-15, a high-temperature polyimide developed in the mid-1970's at the NASA Lewis Research Center, offers the combination of ease of processing, low cost, and good stability and performance at temperatures up to 288 C (500 F). This material is widely regarded as one of the leading high-temperature matrix resins for polymer-matrix-composite aircraft engine components. PMR-15 is widely used in both military and civilian aircraft engines. The current worldwide market for PMR-15 is on the order of 50,000 lb, with a total sales of around $5 to $10 million. However, PMR-15 is made from methylene dianiline (MDA), a known animal mutagen and a suspected human mutagen. Recent concerns about the safety of workers involved in the manufacture and repair of PMR-15 components have led to the implementation of costly protective measures to limit worker exposure and ensure workplace safety. In some cases, because of safety and economic concerns, airlines have eliminated PMR-15 components from engines in their fleets. Current efforts at Lewis are focused on developing suitable replacements for PMR-15 that do not contain mutagenic constituents and have processability, stability, and mechanical properties comparable to that of PMR-15. A recent development from these efforts is a new class of thermosetting polyimides based on 2,2'-dimethylbenzidine (DMBZ). Autoclave processing developed for PMR-15 composites was used to prepare low-void-content T650-35 carbon-fiber-reinforced laminates from DMBZ-15 polyimides. The glass transition temperatures of these laminates were about 50 C higher than those of the T650- 35/PMR-15 composites (400 versus 348 C). In addition, DMBZ-15 polyimide composites aged for 1000 hr in air at 288 C (500 F) had weight losses close to those of comparable PMR-15 laminates (0.9 versus 0.7 percent). The elevated (288 C) and room temperature mechanical properties of T650-35-reinforced DMBZ-15 polyimide and PMR-15 laminates were comparable. Standard Ames tests are being conducted on this diamine to assess its mutagenicity.

Source record

Interrelation Between Safety Factors and Reliability

An evaluation was performed to establish relationships between safety factors and reliability relationships. Results obtained show that the use of the safety factor is not contradictory to the employment of the probabilistic methods. In many cases the safety factors can be directly expressed by the required reliability levels. However, there is a major difference that must be emphasized: whereas the safety factors are allocated in an ad hoc manner, the probabilistic approach offers a unified mathematical framework. The establishment of the interrelation between the concepts opens an avenue to specify safety factors based on reliability. In cases where there are several forms of failure, then the allocation of safety factors should he based on having the same reliability associated with each failure mode. This immediately suggests that by the probabilistic methods the existing over-design or under-design can be eliminated. The report includes three parts: Part 1-Random Actual Stress and Deterministic Yield Stress; Part 2-Deterministic Actual Stress and Random Yield Stress; Part 3-Both Actual Stress and Yield Stress Are Random.

Elishakoff, Isaac

Development of a Software Safety Process and a Case Study of Its Use

Research in the year covered by this reporting period has been primarily directed toward: continued development of mock-ups of computer screens for operator of a digital reactor control system; development of a reactor simulation to permit testing of various elements of the control system; formal specification of user interfaces; fault-tree analysis including software; evaluation of formal verification techniques; and continued development of a software documentation system. Technical results relating to this grant and the remainder of the principal investigator's research program are contained in various reports and papers.

Knight, J. C.

Development of a Software Safety Process and a Case Study of Its Use

Research in the year covered by this reporting period has been primarily directed toward the following areas: (1) Formal specification of user interfaces; (2) Fault-tree analysis including software; (3) Evaluation of formal specification notations; (4) Evaluation of formal verification techniques; (5) Expanded analysis of the shell architecture concept; (6) Development of techniques to address the problem of information survivability; and (7) Development of a sophisticated tool for the manipulation of formal specifications written in Z. This report summarizes activities under the grant. The technical results relating to this grant and the remainder of the principal investigator's research program are contained in various reports and papers. The remainder of this report is organized as follows. In the next section, an overview of the project is given. This is followed by a summary of accomplishments during the reporting period and details of students funded. Seminars presented describing work under this grant are listed in the following section, and the final section lists publications resulting from this grant.

Knight, J. C.

NASA Accident Precursor Analysis Handbook, Version 1.0

Catastrophic accidents are usually preceded by precursory events that, although observable, are not recognized as harbingers of a tragedy until after the fact. In the nuclear industry, the Three Mile Island accident was preceded by at least two events portending the potential for severe consequences from an underappreciated causal mechanism. Anomalies whose failure mechanisms were integral to the losses of Space Transportation Systems (STS) Challenger and Columbia had been occurring within the STS fleet prior to those accidents. Both the Rogers Commission Report and the Columbia Accident Investigation Board report found that processes in place at the time did not respond to the prior anomalies in a way that shed light on their true risk implications. This includes the concern that, in the words of the NASA Aerospace Safety Advisory Panel (ASAP), "no process addresses the need to update a hazard analysis when anomalies occur" At a broader level, the ASAP noted in 2007 that NASA "could better gauge the likelihood of losses by developing leading indicators, rather than continue to depend on lagging indicators". These observations suggest a need to revalidate prior assumptions and conclusions of existing safety (and reliability) analyses, as well as to consider the potential for previously unrecognized accident scenarios, when unexpected or otherwise undesired behaviors of the system are observed. This need is also discussed in NASA's system safety handbook, which advocates a view of safety assurance as driving a program to take steps that are necessary to establish and maintain a valid and credible argument for the safety of its missions. It is the premise of this handbook that making cases for safety more experience-based allows NASA to be better informed about the safety performance of its systems, and will ultimately help it to manage safety in a more effective manner. The APA process described in this handbook provides a systematic means of analyzing candidate accident precursors by evaluating anomaly occurrences for their system safety implications and, through both analytical and deliberative methods used to project to other circumstances, identifying those that portend more serious consequences to come if effective corrective action is not taken. APA builds upon existing safety analysis processes currently in practice within NASA, leveraging their results to provide an improved understanding of overall system risk. As such, APA represents an important dimension of safety evaluation; as operational experience is acquired, precursor information is generated such that it can be fed back into system safety analyses to risk-inform safety improvements. Importantly, APA utilizes anomaly data to predict risk whereas standard reliability and PRA approaches utilize failure data which often is limited and rare.

Groen, Frank

Safety Assurance of Software and Machine Learning Development for Nuclear Instrumentation and Controls

Digital instrumentation and control (DI&C) systems monitor and control parameters in nuclear power plants. Ensuring their safety is a critical part of ensuring overall plant safety. Nuclear power plant licensing generates thousands of safety documents that could be organized more effectively using a safety assurance case (SAC). We conducted a literature survey of SACs and created a SAC framework for DI&C software using Goal Structuring Notation (GSN). This framework focuses on four software development processes: management & assurance, pre-developed software (PDS) qualification, the Software Development Life Cycle (SDLC), and the Machine Learning Development Life Cycle (MLDLC). We organized our framework using a novel level structure that can be applied to other SACs to improve their clarity. Finally, we demonstrate how our framework can be incorporated as part of a SAC for a larger reactor system.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN