Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “safety case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Modernizing NASA’s Space Flight Safety and Mission Success (S&MS) Assurance Framework In Line With Evolving Acquisition Strategies and Systems Engineering Practices

This paper presents the objectives-driven, case-based safety and mission success (S&MS) assurance framework being developed by the NASA Office of Safety and Mission Assurance (OSMA), including its motivations and its implementation via a S&MS Assurance Standard that is under development, supplemented by supporting standards including an S&MS Analysis Management Standard that is also under development. A need to evolve NASA’s S&MS assurance framework has emerged in recent years, resulting from the need to accommodate new acquisition models; the need to accommodate evolving systems engineering (SE) practices; the need to stipulate acceptable levels of S&MS risk; the need for improved integration of S&MS into SE; and the need for clearer risk acceptance accountability. The objectives-driven, case-based S&MS assurance framework proposed here is responsive to that need. Its key features include: • The establishment, by NASA Acquirers, of fundamental S&MS performance objectives that define limits of acceptability for the likelihoods that mission technical objectives will be accomplished and that people, assets, and environments put at risk by the mission will not be adversely affected; • The development and approval of Providers’ S&MS plans for meeting Acquirers’ S&MS performance objectives, including commitments to support Acquirer audit, investigation, and reporting needs; • The development, by Providers, of S&MS assurance cases that argue, supported by evidence, that the Provider has met, or is on track to meeting, the fundamental S&MS objectives; • The evaluation, throughout the program/project life cycle, of Provider S&MS assurance cases as the primary S&MS-related technical basis for Acquirer risk acceptance and the granting to the Provider of authority to proceed through the program/project life cycle. This proposed S&MS assurance framework is notable for its lack of prescription of traditional S&MS requirements and strategies such as defined failure tolerances, margins, or analysis requirements. Instead, Providers are given latitude to propose their own strategies for meeting the fundamental S&MS performance objectives, subject to independent review and Acquirer approval. The result is a framework for S&MS assurance that is at once both rigorous and flexible.

Assurance Case↗

System Safety in Early Manned Space Program: A Case Study of NASA and Project Mercury

This case study provides a review of National Aeronautics and Space Administration s (NASA's) involvement in system safety during research and evolution from air breathing to exo-atmospheric capable flight systems culminating in the successful Project Mercury. Although NASA has been philosophically committed to the principals of system safety, this case study points out that budget and manpower constraints-as well as a variety of internal and external pressures can jeopardize even a well-designed system safety program. This study begins with a review of the evolution and early years of NASA's rise as a project lead agency and ends with the lessons learned from Project Mercury.

Hansen, Frederick D.↗

Technology and Tool Development to Support Safety and Mission Assurance

The Assurance Case approach is being adopted in a number of safety-mission-critical application domains in the U.S., e.g., medical devices, defense aviation, automotive systems, and, lately, civil aviation. This paradigm refocuses traditional, process-based approaches to assurance on demonstrating explicitly stated assurance goals, emphasizing the use of structured rationale, and concrete product-based evidence as the means for providing justified confidence that systems and software are fit for purpose in safely achieving mission objectives. NASA has also been embracing assurance cases through the concepts of Risk Informed Safety Cases (RISCs), as documented in the NASA System Safety Handbook, and Objective Hierarchies (OHs) as put forth by the Agency's Office of Safety and Mission Assurance (OSMA). This talk will give an overview of the work being performed by the SGT team located at NASA Ames Research Center, in developing technologies and tools to engineer and apply assurance cases in customer projects pertaining to aviation safety. We elaborate how our Assurance Case Automation Toolset (AdvoCATE) has not only extended the state-of-the-art in assurance case research, but also demonstrated its practical utility. We have successfully developed safety assurance cases for a number of Unmanned Aircraft Systems (UAS) operations, which underwent, and passed, scrutiny both by the aviation regulator, i.e., the FAA, as well as the applicable NASA boards for airworthiness and flight safety, flight readiness, and mission readiness. We discuss our efforts in expanding AdvoCATE capabilities to support RISCs and OHs under a project recently funded by OSMA under its Software Assurance Research Program. Finally, we speculate on the applicability of our innovations beyond aviation safety to such endeavors as robotic, and human spaceflight.

Mission Assuranc↗

Reliability-Based Design of a Safety-Critical Automation System: A Case Study

In 1986, NASA funded a project to modernize the NASA Ames Research Center Unitary Plan Wind Tunnels, including the replacement of obsolescent controls with a modern, automated distributed control system (DCS). The project effort on this system included an independent safety analysis (ISA) of the automation system. The purpose of the ISA was to evaluate the completeness of the hazard analyses which had already been performed on the Modernization Project. The ISA approach followed a tailoring of the risk assessment approach widely used on existing nuclear power plants. The tailoring of the nuclear industry oriented risk assessment approach to the automation system and its role in reliability-based design of the automation system is the subject of this paper.

Carroll, Carol W.↗

How Safe Is Control Software

Paper examines issue of software safety. Presents four case histories of software-safety analysis. Concludes that, to be safe, software, for all practical purposes, must be free of errors. Backup systems still needed to prevent catastrophic software failures.

Dunn, William R.↗

Wildfire-fighting Use Case Requirements to Monitor

In this technical report, we provide requirements for a wildfire-fighting use-case, towards the Safety Demonstrator 1. The use case will incorporate ground and airborne assets operating in a coordinated fashion, and will comprise five activities, from detection to the execution of the initial attack. Depending on the activity and the data involved, the requirements identified may be non-probabilistic or probabilistic. In both cases, we first identify some of the requirements we wish to monitor, and then present a formalization using the language of requirements of the NASA requirements elicitation tool FRET. To formalize probabilistic requirements, we use a novel extension to FRET’s requirements language that incorporates notions of probability, and discuss how requirements can be translated into existing probabilistic temporal logics like PCTL. We exemplify how some of the requirements presented can be monitored using the existing tools Ogma and Copilot. We close with a summary and future directions.

Requirements↗

A methodology of MSL breakup analysis for Earth accidental reentry and its application to breakup analysis for Mars off-nominal entry

Vehicle breakup analysis has been performed for missions that may carry nuclear fuel for heating or power purposes to assess nuclear safety in case of launch failure leading to atmospheric reentry. Also, failure scenarios exist which could lead to breakup during Entry / Descent / Landing (EDL) at Mars due to off-nominal entries, with implications for planetary protection requirements. Since the Mars Science Laboratory (MSL) spacecraft may include a Multi-Mission Radioisotope Thermoelectric Generator (MMRTG), an analysis of breakup in case of launch failure is required. Also, breakup during Mars EDL due to off-nominal entries could release the RTG heat source that has implications for planetary protection requirements. This paper presents a methodology of MSL breakup analysis for launch failure with application to Mars off-nominal entry.

nuclear safety↗

Urban Air Mobility Conflict Resolution: Centralized or Decentralized?

This work begins to address one of the critical questions in the urban air mobility and small unmanned aircraft communities: Should the en-route conflict resolution function in an urban air mobility traffic system be centralized or decentralized? Three conflict resolution architectures are modeled and analyzed: centralized, decentralized with uniform rules, and decentralized with mixed rules. This study compares these architectures and investigates their robustness to communication and state information errors in terms of safety and efficiency metrics. Experiments are conducted using a high-fidelity Monte Carlo traffic simulator and a generic set of traffic scenarios with increasing traffic density. When no errors were modeled, the centralized architecture marginally outperformed the decentralized architecture. However, performance of the centralized architecture was found to be adversely affected by the modeled input errors to a greater degree than was the decentralized architecture. Performance of the centralized architecture also was degraded significantly by the modeled transmission errors of the centralized resolution maneuvers. In the decentralized architecture, uniform rules outperformed mixed rules because, in the mixed rules case, system safety performance was undermined and dominated by the poor performers.

Urban Air Mobility (UAM) traffic system↗

The PIP-II dedicated RFPI system final design

The Radio Frequency Protection Interlock (RFPI) system main responsibility is to collect predefined set of signals and to protect each RF station. In case of safety limits violations from any of this input signals the RFPI has to instantenously drop permits for the LLRF or RF amplifier (eq. Solid State Amplifier - SSA or klystron) operation.This paper presents an overview of the final design of the RFPI system dedicated for Proton Improvement Plan II (PIP-II) at Fermilab.

Cichalewski, Wojciech [Lodz, Tech. U.; Lodz U.]↗

Drag reduction - Jet breakup correlation with kerosene-based additives

The drag-reduction effectiveness of a number of high-polymer additives dissolved in aircraft fuel has been measured in a turbulent-flow rheometer. These solutions were further subjected to high elongational stress and breakup forces in a jet discharging in air. The jet was photographed using a high-resolution camera with special lighting. The object of the work was to study the possible spray-suppression ability of high-polymer additives to aircraft fuel and to correlate this with the drag-reducing properties of the additives. It was found, in fact, that the rheometer results indicate the most effective spray-suppressing additives. Using as a measure the minimum polymer concentration to give a maximum friction-reducing effect, the order of effectiveness of eight different polymer additives as spray-suppressing agents was predicted. These results may find application in the development of antimisting additives for aircraft fuel which may increase fire safety in case of crash or accident.

Hoyt, J. W.↗

Aircraft Canopy Lock

Mechanism easy to open intentionally but resists accidental opening. Locking or Unlocking occurs when pull pin enters or leaves conical base. Pushing ejection pin or pulling knob unlocks mechanism. Unintentional release unlikely since accidental pilot motions push on knob in most cases. This safety feature, coupled with simplicity and reliability of mechanism, useful for emergency exits for land vehicles or even buildings.

Nichols, G. H.↗

Importance of helium-3 for the future

Relevant plasma physics principles of thermonuclear research; the state of plasma physics as it pertains to the D-He(3) cycle; the technological benefits of the D-He(3) fuel cycle; the availability of He(3); and its location, methods of extraction and cost are discussed. A perspective on the rate of progress toward the goal of heating the confined plasma fuel to sufficiently high temperatures at high enough densities and for long enough times to cause substantial fusion of the atoms to take place is given in graphical form. The main technological advantages resulting from the D-He(3) fuel cycle, when compared with the DT cycle, are as follows: (1) increased electrical conversion efficiency; (2) reduced radiation damage to reactors; (3) reduced radioactive waste; (4) an increased level of safety in case of an accident; (5) the lower cost of electricity; and (6) the shorter time to commercialization. An account is given of mining He(3) on the Moon.

Kulcinski, Gerald L.↗

Unsymmetrical forces in an airplane cell

This paper calls attention to the desirability of expanding airplane building regulations to include proof of safety for cases of unsymmetrical loading, at least in the structural members which are thereby specially stressed.

WINGS - STRESSES & ANALYSIS↗

The Development and Implementation of Ground Safety Requirements for Project Orion Abort Flight Testing - A Case Study

A rigorous set of detailed ground safety requirements is required to make sure that ground support equipment (GSE) and associated planned ground operations are conducted safely. Detailed ground safety requirements supplement the GSE requirements already called out in NASA-STD-5005. This paper will describe the initial genesis of these ground safety requirements, the establishment and approval process and finally the implementation process for Project Orion. The future of the requirements will also be described. Problems and issues encountered and overcame will be discussed.

Kirkpatrick, Paul D.↗

The Friendly Argument Notation (FAN): 2023 Version

This document constitutes the official description of the current iteration of the Friendly Argument Notation (FAN). This new version provides several enhancements to the original 2020 instantiation, while maintaining essential compatibility with it. Specifically, the new version enables distinguishing between deductive and non-deductive arguments, removes the requirement for always providing an explicit statement of reasoning, and relaxes the rules for when labels may be used. The primary intended use of FAN is unchanged: creating and evaluating arguments about safety-critical systems, specifically the types of arguments common within safety and assurance cases.

language↗

Argument-Based Airworthiness Assurance of Small UAS

Presently, there are three avenues by which Unmanned Aircraft System (UAS) operations are authorized in the U.S. National Airspace System (NAS): obtaining either (i) a certificate of authorization (COA), or (ii) a special airworthiness certificate (SAC) in either the experimental, or the restricted category, or (iii) an exemption from an airworthiness certificate together with a civil COA. The first is meant primarily for public entities, such as NASA; the remaining two are the only available means for civil UAS operations. Recently, the Federal Aviation Administration (FAA) has also proposed a regulatory framework targeted for certain small UAS, specifically those weighing 55 pounds or less, although final rulemaking remains pending. We have previously shown how an assurance case can aggregate heterogeneous reasoning and safety evidence, with application to UAS safety. In this paper, we describe how assurance cases can serve as a common framework to justify overall system safety, unifying both operational aspects and airworthiness, in particular system design assurance. We also show how this approach can coexist with, and augment, existing safety analysis processes and best-practices, by transforming the artifacts they produce into structured assurance arguments. To illustrate the applicability and utility of our approach, we have been applying it for the design assurance of an unmanned rotorcraft system, intended for precision agriculture operations, as part of the NASA Unmanned Aircraft System (UAS) Integration in the National Airspace System (NAS) project.

Rotocraft↗

Machine-Learning for Safety Critical Airborne Applications Part II: Case Study

The exceptional progress in the field of Artificial Intelligence (AI) systems, enabled by Machine Learning (ML) technology in recent years provides historic opportunities for the aviation industry. Current certification standards for avionics were developed prior to the ML renaissance and have several fundamental incompatibilities with the ML technology. WG-114 is working hard to release a new standard as soon as possible but for now there is no recognized means of compliance for ML based systems even of low criticality. In this talk, we present the custom ML workflow that can be used comply with all objectives of the current certification standards for a low-criticality (DAL D and C) ML-based system. To illustrate the practical application of the custom ML workflow we present a case study of a system based on a Deep Neural Network (DNN) intended to detect and identify airport runway signs. We present the system design, data generation, training, and verification in detail and describe how the design assurance objectives can be met for a DAL D and DAL C systems.

Johann Schumann↗

NASA’s Safety, Reliability, and Mission Assurance Digital Future

The evolution from “document-centric” to “data-centric” and “model-centric” information leveraging structured data and model-based approaches is at the heart of digital engineering transformational efforts underway across industry and government. It is these approaches that pave the way for data lakes, Authoritative Sources of Truth (ASOTs), and systems- of-systems interoperability and the corresponding transformational benefits thereof. Such benefits include increased data availability, data access equity, data traceability, real-time analytics, batch analytics, and (most importantly) acceleration of the time-to-value and time-to-insights associated with engineering products and analyses. The longer-term benefits of reusability, customization and traceability are even more promising. For Safety and Mission Assurance (SMA), and Mission Success (SMS) activities; realization of such benefits is essential to provide engineers and analysts alike vital information when needed to support critical decision making throughout the entire life cycle. The SMA community often operate in parallel with engineering activities, for which information exchange with relevant context is paramount. Far too often, such information lags key decision points and/or is absent of the robust, integrated, knowledge needed, given inherent barriers associated with traditional document-centric means to data sharing, analysis, and reporting. This paper provides an overview of how NASA’s Office of Safety and Mission Assurance (OSMA) is evolving its policies, standards, guidance, and training to transform to eliminate such barriers, thus realizing the benefits emerging in this new digital era. A roadmap for achieving this digital future is presented along with key building blocks involving use and implementation of concepts such as: Objectives-Hierarchies, Objective-Driven Requirements, Accepted Standards, Safety and Assurance Cases, data digitization (i.e., ontologies, structured data, and model-centric data), FAIR (Findable, Accessible, Interoperable, & Reusable) and/or FAIRUST (Findable, Accessible, Interoperable, Reusable, Understandable, Secure, and Trusted) principles [1]. This paper also describes how OSMA, leveraging the Agency’s overall commitment to Digital Transformation (DT), is using the power of Policy, “Digital” Domain representation, Product Evolution, and Community Outreach and Engagement as part of a strategic vision and roadmap to evolve and transform its SMA organizations to become better able to serve its stakeholders and customers. Future publications will elaborate on these building blocks and deeper concepts.

Authoritative Source of Truth (ASOT),↗