Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Risk Management Framework”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Trends in Human Spaceflight: Failure Tolerance, High Reliability and Correlated Failure History

In a half century of human spaceflight, NASA has continuously refined agency safety and reliability requirements in response to mission demands, critical failures, and technology development. Early spacecraft, including Mercury, Gemini and Apollo vehicles, were highly reliant on dissimilar redundancy and demonstrated test margins. Later programs, such as the reusable Space Transportation System (STS) and International Space Station (ISS), introduced probabilistic studies and isolated two-failure tolerance to improve robustness at the expense of added complexity. More recently, the Orion Multi-Program Crew Vehicle (MPCV) program adopted universal single-failure tolerance with two categorical exceptions; Zero-Failure Tolerant (0FT) and Design for Minimum Risk (DFMR) hardware. Failure tolerance variances are defined and managed in accordance with agency human-rating requirements, and require concurrence from program Technical Authorities (TA) as well as the MPCV Safety and Mission Assurance Safety and Engineering Review Panel (MSERP). To understand and reaffirm standards applied to Apollo, Space Shuttle and Orion vehicles, Orion and Deep Space Gateway Safety and Mission Assurance (S&MA) representatives conducted accelerated research to compare unique safety and reliability criteria against ground and flight anomalies, based on information contained in post-mission reports and the Problem Reporting and Corrective Action (PRACA) database. In some cases, high-profile failures and narrow escapes have reinforced decisions to maintain or adapt safety requirements. In others, empirical trends have highlighted the need for vigilance and innovative safety guidelines. Given the inability to achieve absolute compliance with evolving safety and reliability requirements, the team conducted a targeted review of DFMR and 0FT propulsion elements within the framework of changing system design, inspection, materials and process developments to formulate conclusions on technological maturity, failure density, and net changes in safety risk. Based on the aggregate performance of high-reliability and failure-tolerant systems, the authors have attempted to establish best practices and guidelines to inform future program decisions. On a somewhat cautionary note, this study is not intended to direct a universal set of requirements for future missions based on prior lessons learned. Spacecraft safety is a multi-variable problem, and attempts to mitigate past failures will not guarantee future success. However, this assessment offers a retrospective review of policy changes, implementation and effectiveness. In the future, NASA, European Space Agency (ESA) and industry partners may benefit from a more robust correlation between requirements and performance, as space-faring nations work toward more challenging, complex and long-duration commercial and deep-space ventures.

Green, Carrie↗

Aeronautical Satellite Data Link System (SDLS) for high-density air-traffic areas

The European Space Agency has recently commissioned a study to investigate the feasibility of a low-cost aeronautical Satellite Data Link System (SDLS) to provide for the needs of Air Traffic Services, i.e. safety related communications over continental areas with high air-traffic density. This study is placed in today's context which sees the first generation of Aeronautical Mobile Satellite System (AMSS) being gradually but restrictively put into service in oceanic airspaces with low air-traffic density. This paper first discusses the case of ATS dedicated versus mixed (ATS and commercial) Comms service provision and identifies the specific ATS comms requirements context. Specific emphasis is put on the ICAO (International Civil Aviation Organization) standardization framework for both the ATN (Aeronautical Telecommunication Network) and the SSR (Secondary Surveillance Radar) Mode S specific services. An architectural system and network design for a future SDLS is then proposed, such as to meet the ATS comms requirements within the realm of existing technologies. To minimize development risk and cost, consideration is given to re-use the ESA-developed Land Mobile Communication Technology, known as MSBN (Mobile Satellite Business Network) featuring distinct subnetworks. It is particularly suited to an ATM (Air Traffic Management) decentralized architecture made of independent ATC (Air Traffic Control) Centers. Finally the study follow-on phase is introduced, which is intended to cover system design and development leading to a demonstration program, as a first step towards proposals for international standardization and acceptance.

Alain Delrieu↗

NASA's Exploration and In-Space Services (NExIS) Division OSAM-1 Propellant Transfer Subsystem Progress 2020

National Aeronautics and Space Administration (NASA)’s Exploration and In-Space Services (NExIS) Division of Goddard Space Flight Center has been developing technology for the On-orbit Servicing, Assembly and Manufacturing Mission 1 (OSAM-1) to robotically refuel heritage and new satellites on-orbit. OSAM-1, formerly known as Restore-L, successfully passed an important NASA milestone called Key Decision Point-C (KDP-C), receiving agency-level approval for its implementation. The decision point also establishes the mission’s official schedule and budget. The OSAM-1 spacecraft, Servicing Payload and the Space Infrastructure Dexterous Robot (SPIDER) payload will refuel a satellite in space, assemble a communications antenna and manufacture a beam. By demonstrating these capabilities, the mission is advancing never-before tested technologies for use in future missions (by NASA and other government organizations and private industry). The mission is funded by the Technology Demonstration Missions program within NASA’s Space Technology Mission Directorate. This paper covers a review of servicing extensibility and critical technologies that are being developed within NExIS with a focus on the fluid transfer refueling technology within the framework of the Propellant Transfer Subsystem (PTS). An overview of the planned initial technology demonstration servicing mission via the OSAM-1 Space Vehicle is provided as an extension of the technology development progress reported in 20181, and 20192. The general objectives, challenges, and key technologies are presented as an introduction to the context of the OSAM-1 mission, and a precursor to the OSAM-1 PTS specific development status. Development and progress of the Hose Management Assembly (HMA) and Propellant Transfer Assembly (PTA) are discussed. HMA risk reduction test results including those of thermal vacuum testing are presented. Important analytical results are discussed and progress of drawings and procedures developed for the fabrication and testing phase are shown. A summary of the PTS overall verification status and design activities prepared for the critical design peer review are presented. Procurement progress is shown with status on long, medium, and short term efforts to acquire the hardware required to support the mission objectives. Technology development, challenges, and testing status are discussed with particular regard to the OSAM-1 specific key assemblies including the PTA and HMA along with the overall integrated flight mockup of the spacecraft to client fluid transfer testing conducted in the servicing testbeds. The paper concludes with key milestones leading to the goal of on-orbit refueling to be demonstrated in 2024. The overall mission Launch Readiness Date (LRD) has been realigned to accommodate budget profiles and incorporation of additional on-orbit assembly and manufacturing demonstration efforts.

Propellant transfer, satellite servicing↗

Exploring Digital Transformation for NASA Nuclear Flight Safety

The U.S. National Aeronautics and Space Administration’s (NASA)’s Nuclear Flight Safety discipline is exploring opportunities to combine incremental advancements in many contributing areas in a way that produces a transformative change for how work is performed. More specifically, after providing some general NASA and space nuclear policy background, the authors will describe concepts and efforts that enable: (i) the use of objectives-d riven approaches (in concert with internal and external constraints) to establish a mission risk posture; (ii) the use of that risk posture in the planning process to risk-inform the selection of Safety and Mission Success (S&MS) methods and models; (iii) use of model-based and machine-assisted techniques to manage the complex and ponderous amount of information and interfaces that typify spaceflight efforts; (iv ) the means by which that infrastructure can directly feed an assurance case (including use of systems modelling language, ontological formulation, and semantic web technology) so as to address known weaknesses in our ability to communicate and manage that complexity; and (v) use of that case-assured framework to demonstrate that one did the adequate and sufficient S&MS work and that the S&MS work was done competently.

Donald Helton↗

Integrated Computational Materials Engineering (ICME) Capability Maturity Levels for Ecosystems Enabling Digital Transformation

Digital engineering (DE) and integrated computational materials engineering (ICME) are widely recognized as critical enablers of faster, more affordable, and more reliable aerospace systems. However, many organizations have struggled to realize the promised return on investment (ROI) from digital initiatives. A primary reason is the absence of a shared, decision-focused framework that distinguishes simple digitization of existing workflows from true digital transformation that fundamentally changes how engineering decisions are made. This paper introduces an ICME capability maturity framework that fills this gap. The framework defines six cumulative ICME capability maturity levels (CMLs), explicitly tied to decision authority, engineering integration, optimization, and uncertainty management across material, process, structure, and performance scales. It is designed to complement established readiness metrics such as technology readiness levels (TRLs), manufacturing readiness levels (MRLs), and integration readiness levels (IRLs), by addressing a missing dimension: the conditions required for model-informed decision authority across scales. A unifying figure and capability table illustrate the six-level ICME Capability Maturity Framework, showing how organizations progress from digitization—with limited or negative ROI—to true digital transformation, where ICME-enabled workflows deliver measurable improvements in decision quality, cycle time, risk reduction, and reuse. The framework is intended for both technical practitioners and executive leadership, providing a common language to assess current state, guide roadmaps, align software ecosystem investments, and set realistic expectations for digital transformation outcomes. A regulatory-relevant statement clarifying the relationship between ICME capability and existing certification frameworks is provided.

ICME↗

Bioastronautics Roadmap: A Risk Reduction Strategy for Human Space Exploration

The Bioastronautics Critical Path Roadmap is the framework used to identify and assess the risks to crews exposed to the hazardous environments of space. It guides the implementation of research strategies to prevent or reduce those risks. Although the BCPR identifies steps that must be taken to reduce the risks to health and performance that are associated with human space flight, the BCPR is not a "critical path" analysis in the strict engineering sense. The BCPR will evolve to accommodate new information and technology development and will enable NASA to conduct a formal critical path analysis in the future. As a management tool, the BCPR provides information for making informed decisions about research priorities and resource allocation. The outcome-driven nature of the BCPR makes it amenable for assessing the focus, progress and success of the Bioastronautics research and technology program. The BCPR is also a tool for communicating program priorities and progress to the research community and NASA management.

Source record↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

air traffic privacy & authentication↗

Air Traffic Management Blockchain Infrastructure for Security, Authentication, and Privacy

Current radar-based air traffic service providers may preserve privacy for military and corporate operations by procedurally preventing public release of selected flight plans, position, and state data. The FAA mandate for national adoption of Automatic Dependent Surveillance Broadcast (ADS-B) in 2020 does not include provisions for maintaining these same aircraft-privacy options, nor does it address the potential for spoofing, denial of service, and other well-documented risk factors. This paper presents an engineering prototype that embodies a design and method that may be applied to mitigate these ADS-B security issues. The design innovation is the use of an open source permissioned blockchain framework to enable aircraft privacy and anonymity while providing a secure and efficient method for communication with Air Traffic Services, Operations Support, or other authorized entities. This framework features certificate authority, smart contract support, and higher-bandwidth communication channels for private information that may be used for secure communication between any specific aircraft and any particular authorized member, sharing data in accordance with the terms specified in the form of smart contracts. The prototype demonstrates how this method can be economically and rapidly deployed in a scalable modular environment.

ADS-B cybersecurity↗

Risk analysis simulation of rover operations for Mars surface exploration

Risk management advocates have long sought to directly influence the early stages of the systems engineering process through a more effective role in system design trade studies. The principal obstacle to this has been the lack of credible ways to represent and quantify mission risk—that is, a combination of the probability of mission success (“system safety”) and science value—for the project manager and the rest of the design team. If it were possible to quantify mission risk, then the effects of proposed mission and system design changes could be calculated, and along with life-cycle costs, could be used to explore the design space more extensively and select better designs. JPL has been working to build the capability to quantify the probability of mission success using a federation of diverse simulations and models, each of which contributes some vital piece of the puzzle. The initial institutional focus has been on Mars surface operations. This ensemble computing framework enables the diverse models and simulations to work together seamlessly. Recent work at JPL has demonstrated the capability to exercise this ensemble from end-to-end using an Oracle-based database to automatically move results from one model/simulation to the next stage in the analysis.

Shishko, Robert↗

Application of Lightweight Formal Methods to Software Security

Formal specification and verification of security has proven a challenging task. There is no single method that has proven feasible. Instead, an integrated approach which combines several formal techniques can increase the confidence in the verification of software security properties. Such an approach which species security properties in a library that can be reused by 2 instruments and their methodologies developed for the National Aeronautics and Space Administration (NASA) at the Jet Propulsion Laboratory (JPL) are described herein The Flexible Modeling Framework (FMF) is a model based verijkation instrument that uses Promela and the SPIN model checker. The Property Based Tester (PBT) uses TASPEC and a Text Execution Monitor (TEM). They are used to reduce vulnerabilities and unwanted exposures in software during the development and maintenance life cycles.

security↗

Next Steps Following Quality Management System Implementation

While Quality Management Systems (QMS) have become increasingly common in industry over the past twenty-five to thirty years, government has been slow to adopt. There are several reasons, including the fact that government is not as tightly focused on specific groups of products as is private industry, and therefore must adapt from a product realization focus to a mission realization focus. This article will present an approach for translating the production-oriented Quality Management Systems Standards, such as those included in ISO 9001, Quality management systems-Requirements and translating them to a mission realization approach. Once a mission approach is developed and understood, it will provide the needed greater clarity and a framework for an agency to implement a QMS. When the QMS is established and implemented, agencies can then take the next steps toward continual improvement. The graphic in Table 1 illustrates the ISO 9001 provisions and the corresponding mission-related concepts and definitions are included in Table 2.

Quality Management System↗

The First Flight Decision for New Human Spacecraft Vehicles - A General Approach

Determining when it is safe to fly a crew on a launch vehicle/spacecraft for the first time, especially when the test flight is a part of the overall system certification process, has long been a challenge for program decision makers. The decision on first flight is ultimately the judgment of the program and agency management in conjunction with the design and operations team. To aid in this decision process, a NASA team undertook the task to develop a generic framework for evaluating whether any given program or commercial provider has sufficiently complete and balanced plans in place to allow crewmembers to safely fly on human spaceflight systems for the first time. It was the team s goal to establish a generic framework that could easily be applied to any new system, although the system design and intended mission would require specific assessment. Historical data shows that there are multiple approaches that have been successful in first flight with crew. These approaches have always been tailored to the specific system design, mission objectives, and launch environment. Because specific approaches may vary significantly between different system designs and situations, prescriptive instructions or thorough checklists cannot be provided ahead of time. There are, however, certain general approaches that should be applied in thinking through the decision for first flight. This paper addresses some of the most important factors to consider when developing a new system or evaluating an existing system for whether or not it is safe to fly humans to/from space. In the simplest terms, it is time to fly crew for the first time when it is safe to do so and the benefit of the crewed flight is greater than the residual risk. This is rarely a straight-forward decision. The paper describes the need for experience, sound judgment, close involvement of the technical and management teams, and established decision processes. In addition, the underlying level of confidence the manager has in making the decision will also be discussed. By applying the outlined thought processes and approaches to a specific design, test program and mission objectives, a project team will be better able to focus the debate and discussion on critical areas for consideration and added scrutiny -- allowing decision makers to adequately address the first crewed flight decision.

Schaible, Dawn M.↗

Tradeoffs When Considering Deep Reinforcement Learning for Contingency Management in Advanced Air Mobility

Air transportation is undergoing a rapid evolution globally with the introduction of Advanced Air Mobility (AAM) and with it comes novel challenges and opportunities for transforming aviation. As AAM operations introduce increasing heterogeneity in vehicle capabilities and density, increased levels of automation are likely necessary to achieve operational safety and efficiency goals. This paper focuses on one example where increased automation has been suggested. Autonomous operations will need contingency management systems that can monitor evolving risk across a span of interrelated (or interdependent) hazards and, if necessary, execute appropriate control interventions via supervised or automated decision making. Accommodating this complex environment may require automated functions (autonomy) that apply artificial intelligence (AI) techniques that can adapt and respond to a quickly changing environment. This paper explores the use of Deep Reinforcement Learning (DRL) which has shown promising performance in complex and high-dimensional environments where the objective can be constructed as a sequential decision-making problem. An extension of a prior formulation of the contingency management problem as a Markov Decision Process (MDP) is presented and uses a DRL framework to train agents that mitigate hazards present in the simulation environment. A comparison of these learning-based agents and classical techniques is presented in terms of their performance, verification difficulties, and development process.

machine learningautonomous systems; flight simulat↗

Tradeoffs When Considering Deep Reinforcement Learning for Contingency Management in Advanced Air Mobility

Air transportation is undergoing a rapid evolution globally with the introduction of Advanced Air Mobility (AAM) and with it comes novel challenges and opportunities for transforming aviation. As AAM operations introduce increasing heterogeneity in vehicle capabilities and density, increased levels of automation are likely necessary to achieve operational safety and efficiency goals. This paper focuses on one example where increased automation has been suggested. Autonomous operations will need contingency management systems that can monitor evolving risk across a span of interrelated (or interdependent) hazards and, if necessary, execute appropriate control interventions via supervised or automated decision making. Accommodating this complex environment may require automated functions (autonomy) that apply artificial intelligence (AI) techniques that can adapt and respond to a quickly changing environment. This paper explores the use of Deep Reinforcement Learning (DRL) which has shown promising performance in complex and high-dimensional environments where the objective can be constructed as a sequential decision-making problem. An extension of a prior formulation of the contingency management problem as a Markov Decision Process (MDP) is presented and uses a DRL framework to train agents that mitigate hazards present in the simulation environment. A comparison of these learning-based agents and classical techniques is presented in terms of their performance, verification difficulties, and development process.

machine learning↗

Creating Portfolio Management Concepts for Highly Agile and Innovative Government Research Programs Using Design Thinking and Lean Startup Methodologies

Managing a research and development (R&D) portfolio presents numerous challenges, such as prioritizing research areas, remaining agile, strategic workforce planning, and measuring return on investment, impact, and innovation. One government R&D program is charged with producing a high degree of innovative, transformational breakthroughs in aviation technology. A practical, structured methodology for strategically prioritizing emerging aviation R&D in such an environment is lacking. The existing multi-criteria decision aid tools are primarily utilized at an enterprise level, take months to set up and collect data, require large teams of experts, are used on an infrequent basis, and are not conducive to a highly innovative, high-risk portfolio. Prior to audaciously creating a new portfolio prioritization process, the exact challenges with portfolio management for R&D projects were identified using the design thinking and lean start-up methods. A key part of this discovery process was interviewing stakeholders, as well as other managers of organizations charged with producing innovative portfolios. These interviews, as well as additional techniques, were used to develop a deeper understanding of the challenges and, subsequently, lay the foundation for development of an effective portfolio prioritization process. Four potential concepts that represent key findings emerged: carefully selected criteria for portfolio assessment and selection, targeted portfolio turnover rate, dynamic portfolio prioritization framework, and streamlined transition or commercialization of R&D. Acting on any one of the resulting portfolio management concepts will increase the transparency and confidence in portfolio decisions and, ideally, result in a greater degree of transformational breakthroughs in aviation technology.

project portfolio management↗

Aerial Vehicle Routing and Scheduling for UAS Traffic Management: A Hybrid Monte Carlo Tree Search Approach

We present the Multi-Route Weighted Package Delivery Problem (MRWPDP) and a scalable solution methodology as a major step towards enabling an airspace deconfliction service for drone delivery operations. The problem is motivated by Strategic deconfliction under the FAA’s “Unmanned Aircraft Systems Traffic Management” Concept of Operations. MRWPDP falls under a class of vehicle routing and scheduling problems, and as such is NP-Hard. In MRWPDP, a graph network is given which consists of depots, drop-off sites, and multiple routes connecting the two. In addition, routes are weighted by the associated ground risk and total travel distance for package delivery. The goal is to optimally schedule the departure time and assign routes to a known set of vehicles at the depot. We propose a heuristic solution to the problem by borrowing techniques from Mixed Integer Linear Programming (MILP), Constraint Programming, and Monte Carlo Tree Search (MCTS). The resulting hybrid framework is MCTS with Bound-and-Prune (BP) and rapid simulated updates (U), or MCTS-BP-U. This approach is able to quickly provide a feasible solution for MRWPDP, even for large problem instances up to 1000 vehicles. We provide a MILP formulation of MRWPDP and compare its performance against MCTS-BP-U in terms of solution quality. An agent-based model simulation is conducted as a final step to validate the efficacy of our approach.

air traffic scheduling↗

Aerial Vehicle Routing and Scheduling for UAS Traffic Management: A Hybrid Monte Carlo Tree Search Approach

We present the Multi-Route Weighted Package Delivery Problem (MRWPDP) and a scalable solution methodology as a major step towards enabling an airspace deconfliction service for drone delivery operations. The problem is motivated by Strategic deconfliction under the FAA’s “Unmanned Aircraft Systems Traffic Management” Concept of Operations. MRWPDP falls under a class of vehicle routing and scheduling problems, and as such is NP-Hard. In MRWPDP, a graph network is given which consists of depots, drop-off sites, and multiple routes connecting the two. In addition, routes are weighted by the associated ground risk and total travel distance for package delivery. The goal is to optimally schedule the departure time and assign routes to a known set of vehicles at the depot. We propose a heuristic solution to the problem by borrowing techniques from Mixed Integer Linear Programming (MILP), Constraint Programming, and Monte Carlo Tree Search (MCTS). The resulting hybrid framework is MCTS with Bound-and-Prune (BP) and rapid simulated updates (U), or MCTS-BP-U. This approach is able to quickly provide a feasible solution for MRWPDP, even for large problem instances up to 1000 vehicles. We provide a MILP formulation of MRWPDP and compare its performance against MCTS-BP-U in terms of solution quality. An agent-based model simulation is conducted as a final step to validate the efficacy of our approach.

air traffic scheduling↗

Mission Planning and Scheduling System for NASA's Lunar Reconnaissance Mission

In the framework of NASA's return to the Moon efforts, the Lunar Reconnaissance Orbiter (LRO) is the first step. It is an unmanned mission to create a comprehensive atlas of the Moon's features and resources necessary to design and build a lunar outpost. LRO is scheduled for launch in April, 2009. LRO carries a payload comprised of six instruments and one technology demonstration. In addition to its scientific mission LRO will use new technologies, systems and flight operations concepts to reduce risk and increase productivity of future missions. As part of the effort to achieve robust and efficient operations, the LRO Mission Operations Team (MOT) will use its Mission Planning System (MPS) to manage the operational activities of the mission during the Lunar Orbit Insertion (LOI) and operational phases of the mission. The MPS, based on GMV's flexplan tool and developed for NASA with Honeywell Technology Solutions (prime contractor), will receive activity and slew maneuver requests from multiple science operations centers (SOC), as well as from the spacecraft engineers. flexplan will apply scheduling rules to all the requests received and will generate conflict free command schedules in the form of daily stored command loads for the orbiter and a set of daily pass scripts that help automate nominal real-time operations.

Garcia, Gonzalo↗