Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Engineering Risk Management”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Data systems and computer science: Software Engineering Program

An external review of the Integrated Technology Plan for the Civil Space Program is presented. This review is specifically concerned with the Software Engineering Program. The goals of the Software Engineering Program are as follows: (1) improve NASA's ability to manage development, operation, and maintenance of complex software systems; (2) decrease NASA's cost and risk in engineering complex software systems; and (3) provide technology to assure safety and reliability of software in mission critical applications.

Zygielbaum, Arthur I.

Systems Integration Processes for NASA's Crew Launch Vehicle

NASA's Exploration Initiative will require development of many new elements to constitute a robust system of systems. New launch vehicles are needed to place cargo and crew in stable low earth orbit. This paper examines the systems integration processes NASA is utilizing to ensure integration and control of propulsion and non-propulsion elements within NASA's Crew Launch Vehicle (CLV). The objective of the CLV is to provide the transportation capabilities to meet the Constellation Program requirements for delivering a Crew Exploration Vehicle (CEV) or other payload to Low Earth Orbit (LEO) in support of the lunar and Mars missions. The CLV must successfully provide the capability within cost and schedule with an acceptable risk approach. This paper will describe in detail the systems engineering management processes that will be applied to assure CLV Project success through complete and efficient technical integration. Discussion of specific processes for requirements development and verification, integrated design and analysis, integrated simulation and testing and the integration of reliability, maintainability and supportability (RMS) into the design will also be included. The CLV Project is broken logically into elements by the major hardware groupings, and associated management, system engineering, and integration functions. The processes to be described herein are designed to integrate within these CLV elements and among the other Constellation projects. Launch vehicle stack integration (CLV to CEV, and Ground and Flight Operations integration) throughout the life cycle, including integrated vehicle performance through orbital insertion, recovery of the first stage, and reentry of the upper stage will also be discussed. The processes for decomposing requirements to the Elements and ensuring that requirements have been correctly validated, decomposed, allocated, and that the verification requirements are properly defined to ensure that the system design meets requirements will be discussed.

Reuter, James L.

Managing Analysis Models in the Design Process

Design of large, complex space systems depends on significant model-based support for exploration of the design space. Integrated models predict system performance in mission-relevant terms given design descriptions and multiple physics-based numerical models. Both the design activities and the modeling activities warrant explicit process definitions and active process management to protect the project from excessive risk. Software and systems engineering processes have been formalized and similar formal process activities are under development for design engineering and integrated modeling. JPL is establishing a modeling process to define development and application of such system-level models.

design

NASA Engineering and Safety Center Lunar Rover Design Concepts Assessments

Mass is a significant risk to programs and projects as they transition from formulation to implementation, especially in larger human space systems where delivery mass or volume can be a constrained commodity. • Concepts developed without an adequate systems-engineering basis, including design and operations experience, may miss significant functionality and subsequent mass required for integration or operations. • Further uncertainty can be associated with not fully understanding design best practices and standards that drive mass, such as design for minimum risk or fault tolerance.1 • Finally, the appropriate systems engineering mass properties management rigor and technical discipline insight are required to set the mass baseline, including appropriate mass growth allowance (MGA) to ensure program success. Mass is a key quantity that should be constantly monitored by the systems engineer and the program/project management stakeholder to ensure mission compatibility throughout the project life cycle. In addition, mass is a key programmatic performance metric monitored by the NASA Chief Financial Officer for current and future program cost estimating. NASA Exploration Systems sought an assessment of reasonableness with respect to different potential rover concepts that balances mass needs and human-class cargo lander capabilities. Appropriate systems engineering mass properties management rigor and technical discipline insight were used, and are required to set the mass baseline, including appropriate MGA to ensure program success. Two independent Lunar rover concepts were evaluated, with a goal to understand concept credibility and the Lunar rover designs potential extensibility for Mars surface operations. A notional generic rover concept is shown in Figure 1.

Systems Engineering

Demonstration of Rapid Development Through Containerization: OSE-SAT

Modern advancements in spacecraft technology have enabled engineers to develop radically smaller and lighter spacecraft, which has drastically reduced the cost of putting spacecraft into space. Despite these advancements and the shrinking cost to get spacecraft into space, space exploration is still prohibitively expensive. So much so that many space missions prefer to err on the side of caution than take on additional risk by trying newer, unproven technologies. This risk-averse mission design, while very reasonable from a program management point of view, significantly impacts engineers’ ability to solve newer, more complicated problems and limits scientists’ ability to develop more complex experiments that rely on newer technology. Often these new technologies remain stuck at lower technology readiness levels for many years due to the space community's reluctance to take on the additional risks of proving out unproven technology. The Distributed Spacecraft Autonomy (DSA) team at NASA Ames Research Center is developing a containerized solution to enable the rapid development of newer space technologies and accelerate their adoption into space missions. The Opportunistic Software Experiments for Spacecraft Autonomy Testbeds (OSE-SAT) is an on-orbit test bed that aims to reduce the amount of risk associated with newer, unproven space technologies by containerizing each experiment in its own isolated environment and providing a safe, robust, and controlled interface to access spacecraft host resources that is monitored in real time by thoroughly tested Trusted Container developed by DSA. This paper will describe DSA’s implementation of OSE-SAT and discuss the benefits, as well as challenges, of on-orbit containerization.

Aaron J Woodard

Engineering and Safety Partnership Enhances Safety of the Space Shuttle Program (SSP)

Project Management must use the risk assessment documents (RADs) as tools to support their decision making process. Therefore, these documents have to be initiated, developed, and evolved parallel to the life of the project. Technical preparation and safety compliance of these documents require a great deal of resources. Updating these documents after-the-fact not only requires substantial increase in resources - Project Cost -, but this task is also not useful and perhaps an unnecessary expense. Hazard Reports (HRs), Failure Modes and Effects Analysis (FMEAs), Critical Item Lists (CILs), Risk Management process are, among others, within this category. A positive action resulting from a strong partnership between interested parties is one way to get these documents and related processes and requirements, released and updated in useful time. The Space Shuttle Program (SSP) at the Marshall Space Flight Center has implemented a process which is having positive results and gaining acceptance within the Agency. A hybrid Panel, with equal interest and responsibilities for the two larger organizations, Safety and Engineering, is the focal point of this process. Called the Marshall Safety and Engineering Review Panel (MSERP), its charter (Space Shuttle Program Directive 110 F, April 15, 2005), and its Operating Control Plan emphasizes the technical and safety responsibilities over the program risk documents: HRs; FMEA/CILs; Engineering Changes; anomalies/problem resolutions and corrective action implementations, and trend analysis. The MSERP has undertaken its responsibilities with objectivity, assertiveness, dedication, has operated with focus, and has shown significant results and promising perspectives. The MSERP has been deeply involved in propulsion systems and integration, real time technical issues and other relevant reviews, since its conception. These activities have transformed the propulsion MSERP in a truly participative and value added panel, making a difference for the safety of the Space Shuttle Vehicle, its crew, and personnel. Because of the MSERP's valuable contribution to the assessment of safety risk for the SSP, this paper also proposes an enhanced Panel concept that takes this successful partnership concept to a higher level of 'true partnership'. The proposed panel is aimed to be responsible for the review and assessment of all risk relative to Safety for new and future aerospace and related programs.

Duarte, Alberto

Bridging Equipment Reliability Data and Risk Informed Decisions in a Plant Operation Context

Industry equipment reliability and asset management programs are essential elements that help ensure the safe and economical operation of nuclear power plants. The effectiveness of these programs is addressed in several industry-developed and regulatory programs. The Risk-Informed Asset Management (RIAM) project is tasked to develop tools in support of the equipment reliability and asset management programs at nuclear power plants. These tools are designed to create a direct bridge between component health/lifecycle data and decision making (e.g., maintenance scheduling and project prioritization). The goal of this article is to provide a guide for specific use cases that the RIAM project is targeting. We have grouped uses cases into three main areas. The first area focuses on the analysis of equipment reliability data with a particular emphasis on condition-based data, such as test/surveillance reports and component monitoring data. The second area focuses on the integration of equipment reliability into system/plant reliability models to determine system/plant health and identify the components that are critical to maintain an operational system. Lastly, the third area manages plant resources, such as maintenance activities and replacement scheduling using optimization methods. Here the primary focus is on supporting typical system engineer decisions regarding maintenance activity scheduling and component aging management. This is performed in a risk-informed context where the term “risk” is broadly constructed to include both plant reliability and economics. This framework combines data analytics tools to analyze equipment reliability data with risk-informed methods designed to support system engineer decisions (e.g., maintenance and replacement schedules, optimal maintenance posture) in a customizable workflow.

97 - MATHEMATICS AND COMPUTING

Methods for Determining the Level of Autonomy to Design into a Human Spaceflight Vehicle: A Function Specific Approach

The next-generation human spaceflight vehicle is in a unique position to realize the benefits of more than thirty years of technological advancements since the Space Shuttle was designed. Computer enhancements, the emergence of highly reliable decision-making algorithms, and an emphasis on efficiency make an increased use of autonomous systems highly likely. NASA is in a position to take advantage of these advances and apply them to the human spaceflight environment. One of the key paradigm shifts will be the shift, where appropriate, of monitoring, option development, decision-making, and execution responsibility from humans to an Autonomous Flight Management (AFM) system. As an effort to reduce risk for development of an AFM system, NASA engineers are developing a prototype to prove the utility of previously untested autonomy concepts. This prototype, called SMART (Spacecraft Mission Assessment and Replanning Tool), is a functionally decomposed flight management system with an appropriate level of autonomy for each of its functions. As the development of SMART began, the most important and most often asked question was, How autonomous should an AFM system be? A thorough study of the literature through 2002 surrounding autonomous systems has not yielded a standard method for designing a level of autonomy into either a crewed vehicle or an uncrewed vehicle. The current focus in the literature on defining autonomy is centered on developing IQ tests for built systems. The literature that was analyzed assumes that the goal of all systems is to strive for complete autonomy from human intervention, rather than identifying how autonomous each function within the system should have been. In contrast, the SMART team developed a method for determining the appropriate level of autonomy to be designed into each function within a system. This paper summarizes the development of the Level of Autonomy Assessment Tool and its application to the SMART project.

AFM (AUTONOMOUS FLIGHT MANAGEMENT)

Lessons Learned in Systems Engineering Availability and Recommendations for Mission Technical Leaders

In spaceflight missions at Goddard Space Flight Center (GSFC), the Mission System Engineer (MSE) is the technical leader of the overall engineering team and also is the Independent Engineering Technical Authority. The responsibility of this role includes the definition of the mission design architecture, concept of operations, and mission requirements, management of risk throughout the development, and verification and validation of the final system performance and function amongst other duties. This responsibility inherently requires time management, enabling focus on a balanced development with appropriate risk. Time is the most valuable resource of the MSE. The system engineer’s availability to interact with the development team (often product or component design leads and technicians, often in different worksites) to discover and mitigate mission risks during development is key to mission success. This paper presents examples from Lunar Reconnaissance Orbiter, Landsat 9, and Neutron star Interior Composition ExploreR (NICER) which represent in-house and out-of-house hardware builds. These examples demonstrate how interactions between the Mission Systems Engineers and other project and partner engineers result in discovery of critical risks, leading to early mitigation with significant cost and performance savings. These three missions would have suffered test failures or on-orbit failures had their MSEs not set aside time to visit engineers and technicians that were working on key pieces of space flight hardware. Availability is more than just time; it is openness to listen to concerns and questions. It begins by building a level of trust in the team that it is safe to ask questions or share concerns without the fear of blame or additional workload. It also requires enabling informal conversations (over lunch, coffee, in the clean room, or at the team members desk, etc.) where key information can be exchanged, and team members may even provide an easy-to-implement mitigation idea for another subsystem. Availability is a highly valuable commodity and completely non-obvious to protect and optimize. The natural tendency of engineers is to keep themselves busy with solving problems that they know about. This paper is encouraging MSEs to resist this tendency to try and solve all the complex problems themselves and actively devote daily time to learning and solving problems that are found with informal communications with other team members.

Lessons Learned

Assessing Hurricane Katrina Vegetation Damage at Stennis Space Center using IKONOS Image Classification Techniques

Hurricane Katrina inflicted widespread damage to vegetation in southwestern coastal Mississippi upon landfall on August 29, 2005. Storm damage to surface vegetation types at the NASA John C. Stennis Space Center (SSC) was mapped and quantified using IKONOS data originally acquired on September 2, 2005, and later obtained via a Department of Defense ClearView contract. NASA SSC management required an assessment of the hurricane s impact to the 125,000-acre buffer zone used to mitigate rocket engine testing noise and vibration impacts and to manage forestry and fire risk. This study employed ERDAS IMAGINE software to apply traditional classification techniques to the IKONOS data. Spectral signatures were collected from multiple ISODATA classifications of subset areas across the entire region and then appended to a master file representative of major targeted cover type conditions. The master file was subsequently used with the IKONOS data and with a maximum likelihood algorithm to produce a supervised classification later refined using GIS-based editing. The final results enabled mapped, quantitative areal estimates of hurricane-induced damage according to general surface cover type. The IKONOS classification accuracy was assessed using higher resolution aerial imagery and field survey data. In-situ data and GIS analysis indicate that the results compare well to FEMA maps of flooding extent. The IKONOS classification also mapped open areas with woody storm debris. The detection of such storm damage categories is potentially useful for government officials responsible for hurricane disaster mitigation.

Spruce, Joseph P.

Development and Certification of Ultrasonic Background Noise Test (UBNT) System for use on the International Space Station (ISS)

As a next step in the development and implementation of an on-board leak detection and localization system on the International Space Station (ISS), there is a documented need to obtain measurements of the ultrasonic background noise levels that exist within the ISS. This need is documented in the ISS Integrated Risk Management System (IRMA), Watch Item #4669. To address this, scientists and engineers from the Langley Research Center (LaRC) and the Johnson Space Center (JSC), proposed to the NASA Engineering and Safety Center (NESC) and the ISS Vehicle Office a joint assessment to develop a flight package as a Station Development Test Objective (SDTO) that would perform ultrasonic background noise measurements within the United States (US) controlled ISS structure. This document contains the results of the assessment

Prosser, William H.

Autonomous, In-Flight Crew Health Risk Management for Exploration-Class Missions: Leveraging the Integrated Medical Model for the Exploration Medical System Demonstration Project

The Integrated Medical Model (IMM) captures organizational knowledge across the space medicine, training, operations, engineering, and research domains. IMM uses this knowledge in the context of a mission and crew profile to forecast risks to crew health and mission success. The IMM establishes a quantified, statistical relationship among medical conditions, risk factors, available medical resources, and crew health and mission outcomes. These relationships may provide an appropriate foundation for developing an in-flight medical decision support tool that helps optimize the use of medical resources and assists in overall crew health management by an autonomous crew with extremely limited interactions with ground support personnel and no chance of resupply.

Butler, D. J.

The X-43A Flight Research Program: Lessons Learned on the Road to Mach 10

During an aerospace engineer's undergraduate studies, he or she will attend classes in aerodynamics, thermodynamics, structures, stability and control, dynamics, design, propulsion, and computer science, along with the related courses in mathematics, physics, statistics, and chemistry required to understand the material. Upon graduation, the new engineer will have acquired a basic knowledge of how to build an aerospace vehicle. What only comes through experience, however, is the understanding of the inevitable imperfect process through which an aerospace vehicle is built. This is the adventure of turning a basic concept into functional hardware. Engineers working on a project must often deal with ambiguous situations. They are routinely asked by management to provide risk assessments of a project, yet even after careful analysis uncertainties remain. The project must be accomplished within finite limits of time and money. The question an engineer answers is whether the solution to potential problem is worth the cost and schedule delay, or if the solution might actually be worse than the problem it is meant to solve. Review protocols are established to ensure that an unknown has not been overlooked. But these cannot protect against an unknown unknown. Examples of these situations can be found in the history of the X-43A Hyper-X (Hypersonic Experiment) program. In this NASA project, a supersonic combustion ramjet (scramjet) engine was flight tested on a subscale vehicle. The X-43A Hyper-X Research Vehicle (HXRV) was launched from a B-52B mothership, then boosted to the test speed by a modified Pegasus rocket first stage, called the Hyper-X Launch Vehicle (HXLV). Once at the proper speed and altitude, the X-43A separated from the booster, stabilized itself, and then the engine test began. Although wind-tunnel scramjet engine tests had begun in the late 1950s, before the Hyper-X program there had never been an actual in-flight test of such an engine integrated with an appropriate airframe. Thus, while the scramjet had successfully operated in the artificial airflow of wind tunnels, the concept had yet to be proven in real air. These conditions meant changes in density and temperature, as well as changes in angle of attack and sideslip of a free-flying vehicle. A wind tunnel is limited in its ability to simulate these subtle factures, which have a major impact on almost any vehicle, but especially that of a scramjet's performance. The Hyper-X project was to provide a real-world benchmark of the ground test data. The full scale X-43A engine would be operated in the wind tunnel, and then flown, and the data from its operation would then be compared with projections. If these matched, the wind tunnel data would be considered a reliable design tool for future scramjet. If there were significant differences, the reasons for these would have to be identified. Until such information was available, scramjets would lack the technological maturity to be considered for future space launch or high-speed atmospheric flight vehicles.

Peebles, Curtis

Intertwining Risk Insights and Design Decisions

The state of systems engineering is such that a form of early and continued use of risk assessments is conducted (as evidenced by NASA's adoption and use of the 'Continuous Risk Management' paradigm developed by SEI). ... However, these practices fall short of theideal: (1) Integration between risk assessment techniques and other systems engineering tools is weak. (2) Risk assessment techniques and the insights they yield are only informally coupled to design decisions. (3) Individual riskassessment techniques lack the mix of breadth, fidelity and agility required to span the gamut of the design space. In this paper we present an approach that addresses these shortcomings. The hallmark of our approach is a simple representation comprising objectives (what the system is to do), risks (whose occurrence would detract from attainment of objectives) and activities (a.k.a. 'mitigations') that, if performed, will decrease those risks. These are linked to indicate by how much a risk would detract from attainment of an objective, and by how much an activity would reduce a risk. The simplicity of our representational framework gives it the breadth to encompass the gamut of the design space concerns, the agility to be utilized in even the earliest phases of designs, and the capability to connect to system engineering models and higher-fidelity risk tools. It is through this integration that we address the shortcomings listed above, and so achieve the intertwining between risk insights and design decisions needed to guide systems engineering towards superior final designs while avoiding costly rework to achieve them. The paper will use an example, constructed to be representative of space mission design, to illustrate our approach.

systems engineering

Testing of the Multi-Fluid Evaporator Engineering Development Unit

Hamilton Sundstrand is under contract with the NASA Johnson Space Center to develop a scalable, evaporative heat rejection system called the Multi-Fluid Evaporator (MFE). It is being designed to support the Orion Crew Module and to support future Constellation missions. The MFE would be used from Earth sea level conditions to the vacuum of space. The current Shuttle configuration utilizes an ammonia boiler and flash evaporator system to achieve cooling at all altitudes. The MFE system combines both functions into a single compact package with significant weight reduction and improved freeze-up protection. The heat exchanger core is designed so that radial flow of the evaporant provides increasing surface area to keep the back pressure low. The multiple layer construction of the core allows for efficient scale up to the desired heat rejection rate. The full scale MFE prototype will be constructed with four core sections that, combined with a novel control scheme, manage the risk of freezing the heat exchanger cores. A sub-scale MFE engineering development unit (EDU) has been built, and is identical to one of the four sections of a full scale prototype. The EDU has completed testing at Hamilton Sundstrand. The overall test objective was to determine the thermal performance of the EDU. The first set of tests simulated how each of the four sections of the prototype would perform by varying the chamber pressure, evaporant flow rate, coolant flow rate and coolant temperature. A second set of tests was conducted with an outlet steam header in place to verify that the outlet steam orifices prevent freeze-up in the core while also allowing the desired thermal turn-down ratio. This paper discusses the EDU tests and results.

Quinn, Gregory

History and Logic Model NASA Goddard Space Flight Center Instrument and Payload Systems Engineering Technical Performance Study

Historically, some NASA missions have exceeded schedule and cost commitments. Studies suggest technical performance is a contributor. The 1980 NASA Project Management Study concluded, "one of the most significant contributors to cost and schedule growth is inadequate definition of technical and management aspects of a program..." (as cited in GAO/NSIAD-93-97, p. 11). The 1991 NASA Roles and Missions Report identified a "need for increased emphasis on technological readiness and requirements on the front end of a program" (as cited in GAO/NSIAD-93-97, p. 11). The 1992 NASA Program Costs Report stated that NASA officials identified, among other things, "insufficient definition studies... [and] program redesigns and technical complexities" as reasons for cost and schedule overruns (GAO/NSAID-93-97, p. 11). The 2002 Task Force on Acquisition of National Security Space Programs found "requirements definition and control issues, unhealthy cost bias in proposal evaluation, widespread lack of budget reserves required to implement high risk programs on schedule, and an overall underappreciation of the importance of appropriately staffed and trained system engineering staff to manage the technologically demanding and unique aspects of space programs" (DoD, 2003, p.i.) In 2007, The NASA Office of the Chief Engineer chartered the NASA Instrument Capability Study (NICS) “to determine whether NASA instrument developers are facing challenges that impact the capability to design and build quality instruments or whether there are flaws in the acquisition strategy evidenced by schedule delays, cost overruns, and increased technical risk via design deficiencies. The... team was also chartered to determine if occurrences [are]... isolated cases or if there are generic issues... If the issues [are] found to be generic, the team [is] to offer solutions to recover such capability" (NICS Report, 2008, p. vi). The 2008 NICS Report, led by Goddard Space Flight Center (GSFC), identified challenges to instrument technical performance consistent with findings from previous reports. In 2017, the Instrument Project Division (IPD) Implementation Study was initiated to determine if there was a change in meeting schedule and cost commitments after implementing certain NICS recommendations. In 2018, the Instrument Technical Performance Study was initiated to determine the current state of Instrument Technical Performance in the GSFC Payload & Instrument Systems Engineering Branch. The purpose of the combined studies is to answer the question, "Is there a relationship between meeting NASA scientific instrument technical success and meeting schedule and cost commitments? If yes, what is the relationship?" References Department of Defense Office of the Under Secretary of Defense for Acquisition, Technology, and Logistics. (2003). The report of the defense science board/ air force scientific advisory board joint task force on acquisition of national security space programs. Washington DC. Government Accounting Office. (1992). NASA program costs: Space missions require substantially more funding than initially estimated. GAO/NSIAD-93-97. Washington DC. National Aeronautics and Space Administration, National Oceanic and Atmospheric Agency, Department of Defense. (2008). The NASA instrument capability study final report. NP-2008-11-058-GSFC. Washington DC.

Robbins, Geraldine

Engineering risk reduction in satellite programs

Methods developed in planning and executing system safety engineering programs for Lockheed satellite integration contracts are presented. These procedures establish the applicable safety design criteria, document design compliance and assess the residual risks where non-compliant design is proposed, and provide for hazard analysis of system level test, handling and launch preparations. Operations hazard analysis identifies product protection and product liability hazards prior to the preparation of operational procedures and provides safety requirements for inclusion in them. The method developed for documenting all residual hazards for the attention of program management assures an acceptable minimum level of risk prior to program deployment. The results are significant for persons responsible for managing or engineering the deployment and production of complex high cost equipment under current product liability law and cost/time constraints, have a responsibility to minimize the possibility of an accident, and should have documentation to provide a defense in a product liability suit.

Dean, E. S., Jr.

Enabling Deep Space Science Missions with Nuclear Thermal Propulsion

Nuclear thermal propulsion (NTP) enables entirely new classes of deep-space science missions to yield scientific returns that, in most cases, are simply not possible with traditional architectures. NTP systems can yield dramatically reduced interplanetary travel times, deliver roughly 2- 3 times (or more) the mass that can be delivered by conventional chemical propulsion systems, or provide a combination of these advantages to further enhance scientific return. Present NASA and DoD-sponsored plans for NTP systems will mature the technology using prototype and flight demonstration engines to prove the designs. These prototype engines will have performance in the correct thrust range so as to permit use as a low-risk propulsion stage in support of high-payoff deep space science missions. Additionally, the use of low-enriched Uranium (LEU) fuels over highly-enriched Uranium (HEU) fuels reduce the costs of engine development, qualification, acceptance and launch, and lowers the risks associated with proliferation management.

Kurt A Polzin