Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “dynamic probabilistic risk assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

106 records · Page 6

An Integrated Reliability and Physics-Based Risk Modeling Approach for Assessing Human Spaceflight Systems

This paper presents an integrated reliability and physics-based risk modeling approach for assessing human spaceflight systems. The approach is demonstrated using an example, end-to-end risk assessment of a generic-crewed space transportation system during a reference mission to the International Space Station. The behavior of the system is modeled using analysis techniques from multiple disciplines in order to properly capture the dynamic time- and state- dependent consequences of failures encountered in different mission phases. We discuss how to combine traditional reliability analyses with Monte Carlo simulation methods and physics-based engineering models to produce loss-of- mission and loss-of-crew risk estimates supporting risk-based decision-making and requirement verification. This approach facilitates risk-informed design by providing more realistic representation of system failures and interactions; identifying key risk-driving sensitivities, dependencies, and assumptions; and tracking multiple figures of merit within a single, responsive assessment framework that can readily incorporate evolving design information throughout system development.

Risk assessment↗

Trade Studies of Space Launch Architectures using Modular Probabilistic Risk Analysis

A top-down risk assessment in the early phases of space exploration architecture development can provide understanding and intuition of the potential risks associated with new designs and technologies. In this approach, risk analysts draw from their past experience and the heritage of similar existing systems as a source for reliability data. This top-down approach captures the complex interactions of the risk driving parts of the integrated system without requiring detailed knowledge of the parts themselves, which is often unavailable in the early design stages. Traditional probabilistic risk analysis (PRA) technologies, however, suffer several drawbacks that limit their timely application to complex technology development programs. The most restrictive of these is a dependence on static planning scenarios, expressed through fault and event trees. Fault trees incorporating comprehensive mission scenarios are routinely constructed for complex space systems, and several commercial software products are available for evaluating fault statistics. These static representations cannot capture the dynamic behavior of system failures without substantial modification of the initial tree. Consequently, the development of dynamic models using fault tree analysis has been an active area of research in recent years. This paper discusses the implementation and demonstration of dynamic, modular scenario modeling for integration of subsystem fault evaluation modules using the Space Architecture Failure Evaluation (SAFE) tool. SAFE is a C++ code that was originally developed to support NASA s Space Launch Initiative. It provides a flexible framework for system architecture definition and trade studies. SAFE supports extensible modeling of dynamic, time-dependent risk drivers of the system and functions at the level of fidelity for which design and failure data exists. The approach is scalable, allowing inclusion of additional information as detailed data becomes available. The tool performs a Monte Carlo analysis to provide statistical estimates. Example results of an architecture system reliability study are summarized for an exploration system concept using heritage data from liquid-fueled expendable Saturn V/Apollo launch vehicles.

Mathias, Donovan L.↗

Estimating Software Reliability for Space Launch Vehicles in Probabilistic Risk Assessment (PRA)

It is acutely recognized in the Probabilistic Risk assessment (PRA) field that software plays a defining role in overall system reliability for all modern systems across a wide variety of industries. Regardless if the software is embedded firmware for working components or elements, part of a Human-Machine-Interface, or automated command and control logic, the success of the software to fulfill its function under nominal and off-nominal environments will be a dominant contributor to system reliability. It is also recognized that software reliability prediction and estimation is one of the more challenging and questionable aspects of any PRA or system analyses due to the nature of software and its integration with physics based systems. Irrespective of this dichotomy, any incorporation of software reliability methods requires that the contributions are accountable, quantitative, and tractable. This paper provides a brief overview of software reliability methods, establishes some minimum requirements that the methods should incorporate for completeness, and provides a logic structure for applying software reliability. Model resolution will be discussed that supports current testing plans and trade studies. We will provide initial recommendations for use in the NASA PRA and present a future dynamic option for software and PRA. Space Launch Vehicle Software is recognized to be reliable in static conditions, yet relatively vulnerable to a set of failure modes in changing environments/flight phases. Two quantitative methods were chosen to incorporate software reliability into a Space Launch Vehicle PRA accounting for phase adjustments. One method predicts latent software failure using statistical methods, and the second provides estimates of coding errors and software operating system failures based on test and historical data, respectively. Software uncertainty will also be discussed. We determined that recommendations for PRA software reliability should be modeled at the software module level where multiple software components compose a module and combinations of the software architecture can lead to a functional failure.

Novack, Steven↗

Reliability and Probabilistic Risk Assessment - How They Play Together

PRA methodology is one of the probabilistic analysis methods that NASA brought from the nuclear industry to assess the risk of LOM, LOV and LOC for launch vehicles. PRA is a system scenario based risk assessment that uses a combination of fault trees, event trees, event sequence diagrams, and probability and statistical data to analyze the risk of a system, a process, or an activity. It is a process designed to answer three basic questions: What can go wrong? How likely is it? What is the severity of the degradation? Since 1986, NASA, along with industry partners, has conducted a number of PRA studies to predict the overall launch vehicles risks. Planning Research Corporation conducted the first of these studies in 1988. In 1995, Science Applications International Corporation (SAIC) conducted a comprehensive PRA study. In July 1996, NASA conducted a two-year study (October 1996 - September 1998) to develop a model that provided the overall Space Shuttle risk and estimates of risk changes due to proposed Space Shuttle upgrades. After the Columbia accident, NASA conducted a PRA on the Shuttle External Tank (ET) foam. This study was the most focused and extensive risk assessment that NASA has conducted in recent years. It used a dynamic, physics-based, integrated system analysis approach to understand the integrated system risk due to ET foam loss in flight. Most recently, a PRA for Ares I launch vehicle has been performed in support of the Constellation program. Reliability, on the other hand, addresses the loss of functions. In a broader sense, reliability engineering is a discipline that involves the application of engineering principles to the design and processing of products, both hardware and software, for meeting product reliability requirements or goals. It is a very broad design-support discipline. It has important interfaces with many other engineering disciplines. Reliability as a figure of merit (i.e. the metric) is the probability that an item will perform its intended function(s) for a specified mission profile. In general, the reliability metric can be calculated through the analyses using reliability demonstration and reliability prediction methodologies. Reliability analysis is very critical for understanding component failure mechanisms and in identifying reliability critical design and process drivers. The following sections discuss the PRA process and reliability engineering in detail and provide an application where reliability analysis and PRA were jointly used in a complementary manner to support a Space Shuttle flight risk assessment.

Safie, Fayssal M.↗

Estimating Software Reliability for Space Launch Vehicles in Probabilistic Risk Assessment (PRA)

It is acutely recognized in the Probabilistic Risk Assessment (PRA) field that software plays a defining role in overall system reliability for all modern systems across a wide variety of industries. Regardless of whether the software is embedded firmware for working components or elements, part of a Human-Machine-Interface, or automated command and control logic, the success of the software to fulfill its function under nominal and off-nominal environments will be a dominant contributor to system reliability. It is also recognized that software reliability prediction and estimation is one of the more challenging and questionable aspects of any PRA or system analyses due to the nature of software and its integration with physics based systems. Irrespective of this dichotomy, any incorporation of software reliability methods requires that the contributions are accountable, quantitative, and tractable. This paper provides a brief overview of software reliability methods, establishes some minimum requirements that the methods should incorporate for completeness, and provides a logic structure for applying software reliability. Model resolution will be discussed that supports current testing plans and trade studies. We will provide initial recommendations for use in the National Aeronautics and Space Administration (NASA) PRA and present a future dynamic option for software and PRA. Space Launch Vehicle software is recognized to be reliable in static conditions, yet relatively vulnerable to a set of failure modes in changing environments/flight phases. Two quantitative methods were chosen to incorporate software reliability into a Space Launch Vehicle PRA accounting for phase adjustments. One method predicts latent software failure using statistical methods, and the second provides estimates of coding errors and software operating system failures based on test and historical data. Software uncertainty will also be discussed. It is determined that recommendations for PRA software reliability should be modeled at the software module level where multiple software components compose a module and combinations of the software architecture can lead to a functional failure.

Steven D. Novack↗

Data-Driven Transition Path Analysis Yields a Statistical Understanding of Sudden Stratospheric Warming Events in an Idealized Model

Abstract Atmospheric regime transitions are highly impactful as drivers of extreme weather events, but pose two formidable modeling challenges: predicting the next event (weather forecasting) and characterizing the statistics of events of a given severity (the risk climatology). Each event has a different duration and spatial structure, making it hard to define an objective “average event.” We argue here that transition path theory (TPT), a stochastic process framework, is an appropriate tool for the task. We demonstrate TPT’s capacities on a wave–mean flow model of sudden stratospheric warmings (SSWs) developed by Holton and Mass, which is idealized enough for transparent TPT analysis but complex enough to demonstrate computational scalability. Whereas a recent article (Finkel et al. 2021) studied near-term SSW predictability, the present article uses TPT to link predictability to long-term SSW frequency. This requires not only forecasting forward in time from an initial condition, but also backward in time to assess the probability of the initial conditions themselves. TPT enables one to condition the dynamics on the regime transition occurring, and thus visualize its physical drivers with a vector field called the reactive current . The reactive current shows that before an SSW, dissipation and stochastic forcing drive a slow decay of vortex strength at lower altitudes. The response of upper-level winds is late and sudden, occurring only after the transition is almost complete from a probabilistic point of view. This case study demonstrates that TPT quantities, visualized in a space of physically meaningful variables, can help one understand the dynamics of regime transitions.

Meteorology & Atmospheric Sciences↗

Flood Hazard Assessment from Storm Tides, Rain and Sea Level Rise for a Tidal River Estuary

Cities and towns along the tidal Hudson River are highly vulnerable to flooding through the combination of storm tides and high streamflows, compounded by sea level rise. Here a three-dimensional hydrodynamic model, validated by comparing peak water levels for 76 historical storms, is applied in a probabilistic flood hazard assessment. In simulations, the model merges streamflows and storm tides from tropical cyclones (TCs), offshore extratropical cyclones (ETCs) and inland "wet extratropical" cyclones (WETCs). The climatology of possible ETC and WETC storm events is represented by historical events (1931-2013), and simulations include gauged streamflows and inferred ungauged streamflows (based on watershed area) for the Hudson River and its tributaries. The TC climatology is created using a stochastic statistical model to represent a wider range of storms than is contained in the historical record. TC streamflow hydrographs are simulated for tributaries spaced along the Hudson, modeled as a function of TC attributes (storm track, sea surface temperature, maximum wind speed) using a statistical Bayesian approach. Results show WETCs are important to flood risk in the upper tidal river (e.g., Albany, New York), ETCs are important in the estuary (e.g., New York City) and lower tidal river, and TCs are important at all locations due to their potential for both high surge and extreme rainfall. The raising of floods by sea level rise is shown to be reduced by approximately 30-60 percent at Albany due to the dominance of streamflow for flood risk. This can be explained with simple channel flow dynamics, in which increased depth throughout the river reduces frictional resistance, thereby reducing the water level slope and the upriver water level.

Tidal river↗

Nuclear Safety [Vol. 32, No. 4, October-December 1991]

Nuclear Safety is a review journal that covers significant developments in the field of nuclear safety. Its scope includes the analysis and control of hazards associated with nuclear energy, operations involving fissionable materials, and the products of nuclear fission and their effects on the environment. Primary emphasis is on safety in reactor design, construction, and operation; however, the safety aspects of the entire fuel cycle, including fuel fabrication, spent-fuel processing, nuclear waste disposal, handling of radioisotopes, and environmental effects of these operations, are also treated. Table of Contents for this issue follows. GENERAL SAFETY CONSIDERATIONS: 477 Report on the International Symposium on the Use of Probabilistic Safety Assessment for Operational Safety—PSA '91, S. Chakraborty and M. Khatib-Rahbar; 488 Good Relationships Are Pivotal in Nuclear Data Bases, A. S. Heger and B. V. Koen; 494 Technical Note: The Interagency Nuclear Safety Review Panel's Evaluation of the Ulysses Space Mission, J. A. Sholtis, Jr., D. A. Huff, L. B. Gray, N. P. Klug, and R. O. Winchester; ACCIDENT ANALYSIS: 502 The Severe Accident Analysis Program for the Savannah River Nuclear Production Reactors, M. L. Hyder; CONTROL AND INSTRUMENTATION: 511 A Framework for Selecting Suitable Control Technologies for Nuclear Power Plant Systems, R. A. Kisner; DESIGN FEATURES: 521 Containments for Gas-Cooled Power Reactors History and Status, P.W. Williams; ENVIRONMENTAL EFFECTS: 537 Indoor Radon: A Natural Risk, N. H. Harley and J.H. Harley; On the Importance of the Atmospheric Parameters in the Fission Products Distribution of a Severe Reactor Accident, M. C. Barla and A. R. Bayulken; Book Review: Health Effects of Exposure to Low Levels of Ionizing Radiation BEIR V, C. R. Richmond; WASTE AND SPENT FUEL MANAGEMENT: 555 Activities Related to Waste and Spent Fuel Management, M. D. Muhlheim and E. G. Silver OPERATING EXPERIENCES: 567 Effects of Component Aging on the Westhinghouse Control Rod Drive System, K. Sullivan and W. Gunther; 577 Reactor Shutdown Experience, Compiled by J. W. Cletcher, 580 Selected Safety-Related Events, Compiled by G. A. Murphy; 582 Operating U 8 Power Reactors, Compiled by M. D. Muhlheim and E. G. Silver, RECENT DEVELOPMENTS: 596 General Administrative Activities, Compiled by M. D. Muhlheim and E. G. Silver; 610 Reports, Standards, and Safety Guides, D. S. Queener; 614 Proposed Rule Changes as of June 30, 1991; ANNOUNCEMENTS: 520 Workshop on PC PRAISE: A Probabilistic Fracture Mechanics Personal Computer Code for Nuclear Power Plant Piping Reliability Assessment; 536 Fifth Workshop on Nuclear Power Plant Containment Integrity; 624 New OECD "International Information System on Occupational Exposure (ISOE)"; 625 Harvard School of Public Health Announces Short Courses; 625 Eighth Power Plant Dynamics, Control and Testing Symposium; 626 Second Training Course on Off-Site Emergency Planning and Response for Nuclear Accidents; 618 The Authors; 622 Reviewers of Nuclear Safety, Vol 32.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Nuclear Safety [Vol. 32, No. 4, October-December 1991]

Nuclear Safety is a review journal that covers significant developments in the field of nuclear safety. Its scope includes the analysis and control of hazards associated with nuclear energy, operations involving fissionable materials, and the products of nuclear fission and their effects on the environment. Primary emphasis is on safety in reactor design, construction, and operation; however, the safety aspects of the entire fuel cycle, including fuel fabrication, spent-fuel processing, nuclear waste disposal, handling of radioisotopes, and environmental effects of these operations, are also treated. Table of Contents for this issue follows. GENERAL SAFETY CONSIDERATIONS: 477 Report on the International Symposium on the Use of Probabilistic Safety Assessment for Operational Safety—PSA '91, S. Chakraborty and M. Khatib-Rahbar; 488 Good Relationships Are Pivotal in Nuclear Data Bases, A. S. Heger and B. V. Koen; 494 Technical Note: The Interagency Nuclear Safety Review Panel's Evaluation of the Ulysses Space Mission, J. A. Sholtis, Jr., D. A. Huff, L. B. Gray, N. P. Klug, and R. O. Winchester; ACCIDENT ANALYSIS: 502 The Severe Accident Analysis Program for the Savannah River Nuclear Production Reactors, M. L. Hyder; CONTROL AND INSTRUMENTATION: 511 A Framework for Selecting Suitable Control Technologies for Nuclear Power Plant Systems, R. A. Kisner; DESIGN FEATURES: 521 Containments for Gas-Cooled Power Reactors History and Status, P.W. Williams; ENVIRONMENTAL EFFECTS: 537 Indoor Radon: A Natural Risk, N. H. Harley and J.H. Harley; On the Importance of the Atmospheric Parameters in the Fission Products Distribution of a Severe Reactor Accident, M. C. Barla and A. R. Bayulken; Book Review: Health Effects of Exposure to Low Levels of Ionizing Radiation BEIR V, C. R. Richmond; WASTE AND SPENT FUEL MANAGEMENT: 555 Activities Related to Waste and Spent Fuel Management, M. D. Muhlheim and E. G. Silver OPERATING EXPERIENCES: 567 Effects of Component Aging on the Westhinghouse Control Rod Drive System, K. Sullivan and W. Gunther; 577 Reactor Shutdown Experience, Compiled by J. W. Cletcher, 580 Selected Safety-Related Events, Compiled by G. A. Murphy; 582 Operating U 8 Power Reactors, Compiled by M. D. Muhlheim and E. G. Silver, RECENT DEVELOPMENTS: 596 General Administrative Activities, Compiled by M. D. Muhlheim and E. G. Silver; 610 Reports, Standards, and Safety Guides, D. S. Queener; 614 Proposed Rule Changes as of June 30, 1991; ANNOUNCEMENTS: 520 Workshop on PC PRAISE: A Probabilistic Fracture Mechanics Personal Computer Code for Nuclear Power Plant Piping Reliability Assessment; 536 Fifth Workshop on Nuclear Power Plant Containment Integrity; 624 New OECD "International Information System on Occupational Exposure (ISOE)"; 625 Harvard School of Public Health Announces Short Courses; 625 Eighth Power Plant Dynamics, Control and Testing Symposium; 626 Second Training Course on Off-Site Emergency Planning and Response for Nuclear Accidents; 618 The Authors; 622 Reviewers of Nuclear Safety, Vol 32.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

The HUNTER Dynamic Human Reliability Analysis Tool: Development of a Module for Performance Shaping Factors

Human Unimodel for Nuclear Technology to Enhance Reliability (HUNTER) is a framework to support dynamic human reliability analysis (HRA) in communication with a variety of methods and tools. In this paper, how we have developed one of the HUNTER modules, the individual module for evaluating performance shaping factors (PSFs), is introduced. The PSF refers to any factor that influences human performance such as workload or complexity. It has been used for highlighting human errors and adjusting the error probabilities in the existing HRA. We consider the eight PSFs suggested in the Standardized Plant Analysis Risk-HRA (SPAR-H) method, which is the representative HRA method widely used in the nuclear field. To support our dynamic modeling using the eight SPAR-H PSFs, we reviewed human performance literature and developed data-based mathematical models to rate and quantify PSFs in the context of dynamic HRA. We also design the individual module composed of the two functions: 1) the PSF qualification function that automatically or manually evaluates a PSF level, and 2) the PSF quantification function that dynamically or statically determines the PSF multiplier values and integrate them to adjust human error probabilities (HEPs). How each function works with the SPAR-H PSFs and how the PSFs adjust the HEPs are investigated through literature and discussed in this paper.

99 GENERAL AND MISCELLANEOUS↗

Upper bounds for 21st-century surface air temperatures in the Western United States

The last decade has seen a large number of severe heatwaves that were unprecedented in the observational record, highlighting challenges associated with observationally-based statistical quantification of the likelihood and magnitude of future extreme temperatures. An alternative to such probabilistic assessments is identification of upper bounds that quantify the hottest surface air temperatures that can possibly be achieved by the end of the 21st century. Theory, simulations, and observational analyses support the existence of a finite upper bound for surface air temperature; however, estimates for future upper-bound values that are realistic and usable for planning remain unavailable. Here, we combine atmospheric theory with large ensembles of dynamically downscaled projections to estimate historical and end-of-century upper bounds for surface air temperatures. A number of physical mechanisms can influence upper bounds, and at the end of the 21st century, estimates based on mechanisms that yield more moderate upper-bounds produce values around 60∘C for much of the Western United States and in excess of 80∘C for the hottest parts of the domain. Even cooler high-altitude locations have end-of-century upper bounds over 50∘C. Although these upper-bound estimates might seem implausibly large, increases in the upper bounds over the 21st century are similar to increases in dynamically downscaled peak surface temperatures after adjusting those downscaled temperatures to eliminate the possibly biased model trends in surface specific humidity. While upper bound estimates are high relative to historical observations, they nonetheless suggest that heatwave intensity risk is bounded, with uncertainty dominated by projections of surface and upper-level humidity.

Risser, Mark D↗

High-Fidelity Multi-Rotor Unmanned Aircraft System Simulation Development for Trajectory Prediction Under Off-Nominal Flight Dynamics

The NASA Unmanned Aircraft System (UAS) Traffic Management (UTM) project is conducting research to enable civilian low-altitude airspace and UAS operations. A goal of this project is to develop probabilistic methods to quantify risk during failures and off nominal flight conditions. An important part of this effort is the reliable prediction of feasible trajectories during off-nominal events such as control failure, atmospheric upsets, or navigation anomalies that can cause large deviations from the intended flight path or extreme vehicle upsets beyond the normal flight envelope. Few examples of high-fidelity modeling and prediction of off-nominal behavior for small UAS (sUAS) vehicles exist, and modeling requirements for accurately predicting flight dynamics for out-of-envelope or failure conditions are essentially undefined. In addition, the broad range of sUAS aircraft configurations already being fielded presents a significant modeling challenge, as these vehicles are often very different from one another and are likely to possess dramatically different flight dynamics and resultant trajectories and may require different modeling approaches to capture off-nominal behavior. NASA has undertaken an extensive research effort to define sUAS flight dynamics modeling requirements and develop preliminary high fidelity six degree-of-freedom (6-DOF) simulations capable of more closely predicting off-nominal flight dynamics and trajectories. This research has included a literature review of existing sUAS modeling and simulation work as well as development of experimental testing methods to measure and model key components of propulsion, airframe and control characteristics. The ultimate objective of these efforts is to develop tools to support UTM risk analyses and for the real-time prediction of off-nominal trajectories for use in the UTM Risk Assessment Framework (URAF). This paper focuses on modeling and simulation efforts for a generic quad-rotor configuration typical of many commercial vehicles in use today. An overview of relevant off-nominal multi-rotor behaviors will be presented to define modeling goals and to identify the prediction capability lacking in simplified models of multi-rotor performance. A description of recent NASA wind tunnel testing of multi-rotor propulsion and airframe components will be presented illustrating important experimental and data acquisition methods, and a description of preliminary propulsion and airframe models will be presented. Lastly, examples of predicted off-nominal flight dynamics and trajectories from the simulation will be presented.

Foster, John V.↗

Wildfire Risk Evaluation Framework for Grid Operations and Planning

The United States (US) environmental protection agency's (EPA's) climate change indicators for wildfires show a long-term trend of increased annual wildfire activity, larger wildfire size, and more variable dynamics in wildfire behavior. This has caused more frequent preemptive public safety power shutoff (PSPS) events in the regions with recognized high wildfire risk. These preemptive power shutoffs attempt to prevent the ignition of a wildfire but it nonetheless renders the transmission line non-operational, which often sheds load of downstream communities. As wildfires and PSPS events become more frequent, it is crucial to find the communities most at risk of load shedding. To that end, this paper proposes the wildfire risk evaluation of the system (WiRES) framework, which is a performance-based framework that translates extreme weather-related and PSPS event probabilities into a cumulative probability of a non-operational transmission line. This study also provides a geospatial visualization tool that breaks down the entire western electrical coordinating council (WECC) region into 50 km grid cells which can be used to 1) filter out transmission lines with higher than a threshold outage probability, and 2) graphically discover the affected regions and their biophysical and socioeconomic metrics. %such as the social vulnerability index, population density, gross domestic product, etc. Lastly, an impact assessment study is conducted which connects the results of the proposed framework to python and powerworld-based contingency analysis to highlight the applicability of the framework.

Wildfire, Resilience, Extreme Events, Grid Reslien↗

User’s Manual for RESRAD-BUILD Code V.4: Vol. 1 – Methodology and Models Used in RESRAD-BUILD Code

The RESRAD-BUILD computer code models radionuclide release and transport in indoor environments and performs pathway analyses to evaluate the potential radiological dose and risk incurred by an individual who works or lives in a building contaminated with radioactive material or housing radioactively contaminated furniture or equipment. The code provides four geometries to characterize a radiation source: point, line, area, and volume, in which radionuclides are homogeneously distributed. Radionuclides contained in a source are considered to be released to the indoor air due to various processes including erosion (mechanically or weathering), diffusion (for tritium and radon in a volume source), or emanation (radon in a point, line, or area source). The release can proceed through different time phases with different rates. In RESRAD-BUILD Version 4.0, a dynamic ventilation model is implemented to simulate the fate and transport of source material particles and radionuclides after their releases. This dynamic ventilation model considers (1) air exchange between rooms in the building and between the rooms and the outdoor environment, (2) deposition from air to floor, (3) resuspension from the floor to the air, and (4) periodical vacuuming that reduces the floor deposition. The fate and transport modeling provides estimates of radionuclide concentrations in the source, in the air, and on the floor at different times, which are then integrated over the exposure duration for the calculation of radiation doses and cancer risks. A single run of the RESRAD-BUILD code can model a building with up to 9 rooms, 10 sources, and 10 receptors. The potential radiation dose and cancer risk incurred by each receptor are calculated for seven exposure pathways: (1) external radiation directly from the sources (accounting for shielding), (2) external radiation from radioactive particles deposited on the floors, (3) external radiation from airborne radionuclides, (4) inhalation of airborne radionuclides, (5) inhalation of radon and radon progenies, (6) inadvertent ingestion of radioactive particles directly from the source, and (7) ingestion of radioactive particles deposited on the floors. Various exposure scenarios can be modeled with RESRAD-BUILD, including but are not limited to, office worker, renovation worker, decontamination worker, building visitor, and resident. Both deterministic and probabilistic analyses can be performed to obtain results in both text reports and graphic displays.

61 RADIATION PROTECTION AND DOSIMETRY↗

Probabilistic Risk Assessment for Decision Making During Spacecraft Operations

Decisions made during the operational phase of a space mission often have significant and immediate consequences. Without the explicit consideration of the risks involved and their representation in a solid model, it is very likely that these risks are not considered systematically in trade studies. Wrong decisions during the operational phase of a space mission can lead to immediate system failure whereas correct decisions can help recover the system even from faulty conditions. A problem of special interest is the determination of the system fault protection strategies upon the occurrence of faults within the system. Decisions regarding the fault protection strategy also heavily rely on a correct understanding of the state of the system and an integrated risk model that represents the various possible scenarios and their respective likelihoods. Probabilistic Risk Assessment (PRA) modeling is applicable to the full lifecycle of a space mission project, from concept development to preliminary design, detailed design, development and operations. The benefits and utilities of the model, however, depend on the phase of the mission for which it is used. This is because of the difference in the key strategic decisions that support each mission phase. The focus of this paper is on describing the particular methods used for PRA modeling during the operational phase of a spacecraft by gleaning insight from recently conducted case studies on two operational Mars orbiters. During operations, the key decisions relate to the commands sent to the spacecraft for any kind of diagnostics, anomaly resolution, trajectory changes, or planning. Often, faults and failures occur in the parts of the spacecraft but are contained or mitigated before they can cause serious damage. The failure behavior of the system during operations provides valuable data for updating and adjusting the related PRA models that are built primarily based on historical failure data. The PRA models, in turn, provide insight into the effect of various faults or failures on the risk and failure drivers of the system and the likelihood of possible end case scenarios, thereby facilitating the decision making process during operations. This paper describes the process of adjusting PRA models based on observed spacecraft data, on one hand, and utilizing the models for insight into the future system behavior on the other hand. While PRA models are typically used as a decision aid during the design phase of a space mission, we advocate adjusting them based on the observed behavior of the spacecraft and utilizing them for decision support during the operations phase.

dynamic fault trees↗

Improving Safety on the International Space Station: Transitioning to Electronic Emergency Procedure Books on the International Space Station

The National Aeronautics and Space Administration (NASA) originally designed the International Space Station (ISS) to operate until 2015, but have extended operations until at least 2020. As part of this very dynamic Program, there is an effort underway to simplify the certification of Commercial ]of ]the ]Shelf (COTS) hardware. This change in paradigm allows the ISS Program to take advantage of technologically savvy and commercially available hardware, such as the iPad. The iPad, a line of tablet computers designed and marketed by Apple Inc., was chosen to support this endeavor. The iPad is functional, portable, and could be easily accessed in an emergency situation. The iPad Electronic Flight Bag (EFB), currently approved for use in flight by the Federal Aviation Administration (FAA), is a fraction of the cost of a traditional Class 2 EFB. In addition, the iPad fs ability to use electronic aeronautical data in lieu of paper in route charts and approach plates can cut the annual cost of paper data in half for commercial airlines. ISS may be able to benefit from this type of trade since one of the most important factors considered is information management. Emergency procedures onboard the ISS are currently available to the crew in paper form. Updates to the emergency books can either be launched on an upcoming visiting vehicle such as a Russian Soyuz flight or printed using the onboard ISS printer. In both cases, it is costly to update hardcopy procedures. A new operations concept was proposed to allow for the use of a tablet system that would provide a flexible platform to support space station crew operations. The purpose of the system would be to provide the crew the ability to view and maintain operational data, such as emergency procedures while also allowing Mission Control Houston to update the procedures. The ISS Program is currently evaluating the safety risks associated with the use of iPads versus paper. Paper products can contribute to the flammability risk and require manual updates that take time away from research tasks. The ISS program has recently purchased three iPads for the astronauts and the certification has been approved. The crew is currently using the iPads onboard. The results of this analysis could be used to discern whether the iPad is a viable option for use in emergencies by assessing the risk posture through the development of a quantitative probabilistic risk assessment (PRA).

Carter-Journet, Katrina↗