Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “safety case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Evaluation of advanced high rate Li-SOCl2 cells

Under NASA sponsorship, JPL is developing advanced, high rate Li-SOCl2 cells for future space missions. As part of this effort, Li-SOCl2 cells of various designs were examined for performance and safety. The cells differed from one another in several aspects, such as: nature of carbon cathode, catalysts, cell configuration, case polarity, and safety devices. Performance evaluation included constant-current discharge over a range of currents and temperatures. Abuse-testing consisted of shortcircuiting, charging, and over-discharge. Energy densities greater than 300 Wh/Kg at the C/2 rate were found for some designs. A cell design featuring a high-surface-area carbon cathode was found to deliver nearly 500 Wh/Kg at moderate discharge rates. Temperature influenced the performance significantly.

Deligiannis, F.↗

A Framework for the Analysis of Deep Neural Networks in Autonomous Aerospace Applications using Bayesian Statistics

Deep Neural Networks (DNNs) are considered to be key components in many autonomous systems. Applications range from vision-based obstacle avoidance to intelligent/learning control and planning. Safety-critical applications as found in the aerospace domain require that the behavior of the DNN is validated and tested rigorously for safety of the autonomous system (AUS). In this paper, we present a framework to support testing of DNNs and the analysis of the network structure. Our framework employs techniques from statistical modeling and active learning to effectively generate test cases for DNN safety testing and performance analysis. We will present results of a case study on a physics-based Deep recurrent residual neural network (DR-RNN), which has been trained to emulate the aerodynamics behavior of a fixed-wing aircraft.

Deep Neural networks↗

ESTIMATING THE BENEFIT OF TRMM TROPICAL CYCLONE DATA IN SAVING LIVES

The Tropical Rainfall Measuring Mission (TRMM) is a joint NASA/JAXA research mission launched in late 1997 to improve our knowledge of tropical rainfall processes and climatology (Kummerow et ai., 2000; Adler et ai., 2003). In addition to being a highly successful research mission, its data are available in real time and operational weather agencies in the U.S. and internationally are using TRMM data and images to monitor and forecast hazardous weather (tropical cyclones, floods, etc.). For example, in 2004 TRMM data were used 669 times for determining tropical cyclone location fixes (National Research Council, 2004). TRMM flies at a relatively low altitude, 400 km, and requires orbit adjustment maneuvers to maintain altitude against the small drag of the atmosphere. There is enough fuel used for these maneuvers remaining on TRMM for the satellite to continue flying until 2011-12. However, most of the remaining fuel may be used to perform a controlled re-entry of the satellite into the Pacific Ocean. The fuel threshold for this operation will be reached in the summer of 2005, although the maneuver would actually occur in late 2006 or 2007. The full science mission would end in 2005 under the controlled re-entry option. This re-entry option is related to the estimated probability of injury (1/5,000) that might occur during an uncontrolled re-entry of the satellite. If the estimated probability of injury exceeds 1/10,000 a satellite is a candidate for a possible controlled re-entry. In the TRMM case the NASA Safety Office examined the related issues and concluded that, although TRMM exceeded the formal threshold, the use of TRMM data in the monitoring and forecasting of hazardous weather gave a public safety benefit that compensated for TRMM slightly exceeding the orbital debris threshold (Martin, 2002). This conclusion was based in part on results of an independent panel during a workshop on benefits of TRMM data in concluded that the benefit of TRMM data in saving lives through its use in operational forecasting could not be quantified. The objective of this paper is to describe a possible technique to estimate the number of lives saved per year and apply it to the TRMM case and the use of its data in monitoring and forecasting tropical cyclones.

Adler, Robert F.↗

Real Time Safety Monitoring: Concept for Supporting Safe Flight Operations

A number of organizations are working on processes, procedures, regulations, and technologies to maintain or improve the safety of the National Airspace System (NAS). In this paper, we describe a Real Time Safety Monitoring (RTSM) system that benefits from these efforts to define a set of safety metrics that are automatically monitored in real-time. In addition to providing information about current potentially adverse conditions to a variety of users, from those who need a broad overview of a day's flight operations to those who need to decide on a control tactic to employ in the next five minutes, the RTSM system predicts conditions within a specified prediction horizon. Its intelligent interface alerts the user, presenting the information as appropriate considering the current context and circumstances. We illustrate the system concept with five conceptual use cases, describing which safety metrics may be of the most interest to five user groups and suggesting a multi-modal display format. We posit that having access to information about adverse conditions in time to make efficient preemptive decisions without sacrificing safety will improve the already high level of safety and aid in the expansion planned for the NAS under the Next Generation Air Transportation System (NextGen).

safety↗

Obtaining Valid Safety Data for Software Safety Measurement and Process Improvement

We report on a preliminary case study to examine software safety risk in the early design phase of the NASA Constellation spaceflight program. Our goal is to provide NASA quality assurance managers with information regarding the ongoing state of software safety across the program. We examined 154 hazard reports created during the preliminary design phase of three major flight hardware systems within the Constellation program. Our purpose was two-fold: 1) to quantify the relative importance of software with respect to system safety; and 2) to identify potential risks due to incorrect application of the safety process, deficiencies in the safety process, or the lack of a defined process. One early outcome of this work was to show that there are structural deficiencies in collecting valid safety data that make software safety different from hardware safety. In our conclusions we present some of these deficiencies.

Basili, Victor r.↗

Testing Ceramics for Diesel Engines

Adaptation of diesel engine allows prestressed ceramic materials evaluated under realistic pressure, temperature, and stress without introducing extraneous stress. Ceramic specimen part of prechamber of research engine. Specimen held in place by clamp, introduces required axial compressive stress. Specimen -- cylindrical shell -- surrounded by chamber vented or pressurized to introduce requisite radial stress in ceramic. Pressure chamber also serves as safety shield in case speimen disintegrates. Materials under consideration as cylinder liners for diesel engines.

Schneider, H. W.↗

An in-depth probabilistic study of external tank attach ring

This report deals with conducting a probabilistic study of the external tank attach ring (ETA) used as an interface between the external tank attach struts and the solid rocket booster. The ideas were to use probabilistic distributions for material, geometric, and load properties; to calculate probabilistic margins of safety; and then to compare results against the deterministic factors of safety that were used in the actual design process. The report describes how this was done and discusses some of the road blocks and data problems that were encountered during the study and provides some conclusions. A further refinement of this study is being considered for future work which would make more direct use of finite element analysis data coupled with Monte Carlo simulation. The basic conclusion herein indicates that the probabilistic margins of safety for the cases analyzed (by use of existing data) appear to support deterministic results and actually indicate higher reliabilities.

Pizzano, Frank↗

Proceedings of the Third International Workshop on Proof-Carrying Code and Software Certification

This NASA conference publication contains the proceedings of the Third International Workshop on Proof-Carrying Code and Software Certification, held as part of LICS in Los Angeles, CA, USA, on August 15, 2009. Software certification demonstrates the reliability, safety, or security of software systems in such a way that it can be checked by an independent authority with minimal trust in the techniques and tools used in the certification process itself. It can build on existing validation and verification (V&V) techniques but introduces the notion of explicit software certificates, Vvilich contain all the information necessary for an independent assessment of the demonstrated properties. One such example is proof-carrying code (PCC) which is an important and distinctive approach to enhancing trust in programs. It provides a practical framework for independent assurance of program behavior; especially where source code is not available, or the code author and user are unknown to each other. The workshop wiII address theoretical foundations of logic-based software certification as well as practical examples and work on alternative application domains. Here "certificate" is construed broadly, to include not just mathematical derivations and proofs but also safety and assurance cases, or any fonnal evidence that supports the semantic analysis of programs: that is, evidence about an intrinsic property of code and its behaviour that can be independently checked by any user, intermediary, or third party. These guarantees mean that software certificates raise trust in the code itself, distinct from and complementary to any existing trust in the creator of the code, the process used to produce it, or its distributor. In addition to the contributed talks, the workshop featured two invited talks, by Kelly Hayhurst and Andrew Appel. The PCC 2009 website can be found at http://ti.arc.nasa.gov /event/pcc 091.

Ewen, Denney, W.↗

The Friendly Argument Notation (FAN)

This document defines and explains through examples the Friendly Argument Notation (FAN). FAN builds on previous work investigating text-based ways to express arguments [2, 3]. Its primary intended use is for creating and evaluating arguments about safety-critical systems, especially the types of arguments common within safety and assurance cases [4], but nothing in its design constrains its use to that domain. Compared to existing notations commonly used within this domain (for example [6]), FAN corresponds more closely to traditional argument concepts (for example [1]), allows greater flexibility in expression, provides for including counter-arguments, and requires less knowledge of computer-science-specific concepts. Only time and use will determine how beneficial these differences are in practice. This paper concentrates on showing how FAN looks to someone who is using it manually to develop or assess arguments. A later document will concentrate on providing the information necessary for software tools to be created for FAN.

arugment↗

Implementation Procedure for STS Payloads, System Safety Requirements

Guidelines and instructions for the implementation of the SP&R system safety requirements applicable to STS payloads are provided. The initial contact meeting with the payload organization and the subsequent safety reviews necessary to comply with the system safety requirements of the SP&R document are described. Waiver instructions are included for the cases in which a safety requirement cannot be met.

Source record↗

AdvoCATE User Guide

This tutorial gives an overview of AdvoCATE - the assurance case automation toolset - which provides a suite of features for safety risk management, including hazard analysis, the linking of hazards to requirement logs, risk modeling using bow tie diagrams, structured arguments, and evidence logs. In this tutorial we show how these related assurance artifacts can be combined with each other in an integrated assurance case.

Safety assurance↗

Adaptive Independent Verification and Validation (IV&V) Reduces Risk of Software Impacting Safety in Artemis Missions

The National Aeronautics and Space Administration (NASA) is asking more of its human spaceflight programs than ever before through the collective Artemis Missions. The NASA Independent Verification and Validation (IV&V) Program contributes to NASA’s human spaceflight goals by providing IV&V services for NASA’s critical spacecraft and ground software. The IV&V Program is tasked with providing assurance from both individual and integrated mission software perspectives. The Artemis IV&V organization is actively supporting six distinct development efforts: Orion, the Space Launch System (SLS), Exploration Ground Systems (EGS), Mission Control Center (MCC), the Lunar Gateway, and the Human Landing System (HLS), representing a wide diversity of developer organizations, management structures, and development approaches. With much of this extremely complex flight and ground software being essential to human safety both on the ground and in space, Artemis IV&V is likewise challenged to provide more value-added assurance to future Artemis missions within a constrained budget. To meet this challenge, Artemis IV&V employs a variety of novel and evolving “Adaptive IV&V” approaches for planning and executing IV&V analysis to increase both the efficiency and effectiveness of the IV&V Program’s assurance activities, and to address the difficulties imposed by assuring software for a large, highly integrated, multi-mission enterprise managed and executed by physically and organizationally distinct programs. Instilling agile principles like iterative planning cycles, self-organizing teams, and regular retrospectives, into IV&V planning and execution has led to a more rapid turnaround of a minimum viable assurance product and allowed for increased alignment of assurance activities with development progress. Adopting an assurance case methodology has led to greater consistency and clearer communication of assurance design and provided a foundation for long-term maintenance of assurance plans, products, and results across missions. The IV&V-developed Assurance / Safety Case Analytical Network (A-SCAN) framework and tool has enabled the quantification and tracking of system/software risk and confidence. These confidence measures provide a means to repeatedly express the impact of planned and completed assurance work and the remaining residual risk. Applied as part of a “Follow-the-Risk” organizational ethos, this allows consistent rightsizing of analysis rigor and intensity commensurate with the perceived risk of defects, as well as appropriate targeting of the highest risk areas of the software to find safety issues before they can manifest. Finally, the development of the IV&V Advanced Risk Reduction Integrated Software Test and Operations Tri-program Lightweight Environment (ARRISTOTLE), an integrated software-only simulation of Orion, SLS, and EGS systems, has made it possible to independently test integrated pad and flight scenarios and inject faults to observe how the Artemis multi-program, mission software behaves in degraded modes and in response to hazards. These adaptive IV&V investments have enabled Artemis IV&V to become more efficient and effective in IV&V planning and execution and respond more readily to changes in the risk landscape, increasing the breadth and depth of risk reduction possible within the available resources. Residual risk tracking allows IV&V to communicate more effectively with stakeholders, both internal and external at all levels, and inform key decision-making personnel. This evolving assurance design approach provides IV&V surety that work is performed in the highest risk, most value-added areas of the software, to keep our astronauts and ground crews safe and ensure mission success.

Gerek A Whitman↗

Adaptive Independent Verification and Validation (IV&V) Reduces Risk of Software Impacting Safety in Artemis Missions

The National Aeronautics and Space Administration (NASA) is asking more of its human spaceflight programs than ever before through the collective Artemis Missions. The NASA Independent Verification and Validation (IV&V) Program contributes to NASA’s human spaceflight goals by providing IV&V services for NASA’s critical spacecraft and ground software. The IV&V Program is tasked with providing assurance from both individual and integrated mission software perspectives. The Artemis IV&V organization is actively supporting six distinct development efforts: Orion, the Space Launch System (SLS), Exploration Ground Systems (EGS), Mission Control Center (MCC), the Lunar Gateway, and the Human Landing System (HLS), representing a wide diversity of developer organizations, management structures, and development approaches. With much of this extremely complex flight and ground software being essential to human safety both on the ground and in space, Artemis IV&V is likewise challenged to provide more value-added assurance to future Artemis missions within a constrained budget. To meet this challenge, Artemis IV&V employs a variety of novel and evolving “Adaptive IV&V” approaches for planning and executing IV&V analysis to increase both the efficiency and effectiveness of the IV&V Program’s assurance activities, and to address the difficulties imposed by assuring software for a large, highly integrated, multi-mission enterprise managed and executed by physically and organizationally distinct programs. Instilling agile principles like iterative planning cycles, self-organizing teams, and regular retrospectives, into IV&V planning and execution has led to a more rapid turnaround of a minimum viable assurance product and allowed for increased alignment of assurance activities with development progress. Adopting an assurance case methodology has led to greater consistency and clearer communication of assurance design and provided a foundation for long-term maintenance of assurance plans, products, and results across missions. The IV&V-developed Assurance / Safety Case Analytical Network (A-SCAN) framework and tool has enabled the quantification and tracking of system/software risk and confidence. These confidence measures provide a means to repeatedly express the impact of planned and completed assurance work and the remaining residual risk. Applied as part of a “Follow-the-Risk” organizational ethos, this allows consistent rightsizing of analysis rigor and intensity commensurate with the perceived risk of defects, as well as appropriate targeting of the highest risk areas of the software to find safety issues before they can manifest. Finally, the development of the IV&V Advanced Risk Reduction Integrated Software Test and Operations Tri-program Lightweight Environment (ARRISTOTLE), an integrated software-only simulation of Orion, SLS, and EGS systems, has made it possible to independently test integrated pad and flight scenarios and inject faults to observe how the Artemis multi-program, mission software behaves in degraded modes and in response to hazards. These adaptive IV&V investments have enabled Artemis IV&V to become more efficient and effective in IV&V planning and execution and respond more readily to changes in the risk landscape, increasing the breadth and depth of risk reduction possible within the available resources. Residual risk tracking allows IV&V to communicate more effectively with stakeholders, both internal and external at all levels, and inform key decision-making personnel. This evolving assurance design approach provides IV&V surety that work is performed in the highest risk, most value-added areas of the software, to keep our astronauts and ground crews safe and ensure mission success.

Gerek Whitman↗

Generalized implementation of software safety policies

As part of a research program in the engineering of software for safety-critical systems, we are performing two case studies. The first case study, which is well underway, is a safety-critical medical application. The second, which is just starting, is a digital control system for a nuclear research reactor. Our goal is to use these case studies to permit us to obtain a better understanding of the issues facing developers of safety-critical systems, and to provide a vehicle for the assessment of research ideas. The case studies are not based on the analysis of existing software development by others. Instead, we are attempting to create software for new and novel systems in a process that ultimately will involve all phases of the software lifecycle. In this abstract, we summarize our results to date in a small part of this project, namely the determination and classification of policies related to software safety that must be enforced to ensure safe operation. We hypothesize that this classification will permit a general approach to the implementation of a policy enforcement mechanism.

Knight, John C.↗

Safety and IVHM

When we address safety in a book on the business case for IVHM, the question arises whether safety isn t inherently in conflict with the need of operators to run their systems as efficiently (and as cost effectively) as possible. The answer may be that the system needs to be just as safe as needed, but not significantly more. That begs the next question: How safe is safe enough? Several regulatory bodies provide guidelines for operational safety, but irrespective of that, operators do not want their systems to be known as lacking safety. We illuminate the role of safety within the context of IVHM.

Goebel, Kai↗

HFIR LEU High Density Silicide Dispersion Optimized Design Steady-State Heat Transfer Analyses

Steady-state heat transfer simulations of the Oak Ridge National Laboratory High Flux Isotope Reactor (HFIR) with the low-enriched uranium (LEU) high-density silicide dispersion Optimized fuel design were performed to support comprehensive performance and safety metric studies concerning this design. The LEU Optimized design operates at 95 MW to maintain HFIR’s current highly enriched uranium (HEU) core performance level at 85 MW. Full cycle Mode 1 full flow Case 1 (inlet temperature), Case 2 (flux-to-flow), and Case 3 (inlet pressure) safety limit analyses were performed to assess the margins to critical heat flux. Under the prescribed conditions, this LEU design meets the safety limit and limiting control setting requirements outlined in HFIR’s documented safety analysis; however, the safety margins are less than those for the 85 MW HEU core, and several assumptions were made where fuel fabrication and qualification data are currently lacking for the silicide fuel design. Effects of changes to pertinent fuel fabrication assumptions and uncertainty factors on thermal safety margins were also evaluated, showing that the margins are sensitive to many of these parameters. Power and pressure perturbations were also performed, indicating that significant steady-state thermal margins could be gained by increasing the coolant inlet pressure.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

NASA Engineering and Safety Center Technical Bulletin No. 24-04: 6DOF Check Cases

In 2015, the NESC released benchmark Earth-based check-cases for well specified, rigid-body, six-degree-of-freedom (6DOF) aero/spacecraft models to promote consistent and accurate flight simulations across multiple Agency tools and facilities. Recently, the NESC expanded upon that effort to add Lunar-based check-cases to support new lunar exploration initiatives. This study produced a smaller, focused set of cases that exercise new and unique features of missions in the lunar environment in comparison with 8 high-fidelity NASA simulation tools and provides a measure of validation for simulations supporting Human Landing Systems.

Flight Mechanics↗

Retrospectively Documenting Satisfaction of the Overarching Properties: An Exploratory Prototype

Software-intensive aviation systems are typically developed in accordance with recognized development process, safety analysis, and software development standards such as SAE ARP4754A, SAE ARP4761, and RTCA DO-178C. Efforts to streamline assurance processes and make them flexible enough to handle future assurance challenges have produced the Overarching Properties (OPs) for airworthiness approval. Each of the three OPs is a property systems must possess to be certifiable. There is no mandated means of documenting possession of the OPs. To explore possible means, we have prepared retrospective documentation showing that a specimen software system possesses the OPs. The specimen system, Safeguard, enforces geofencing restrictions on unmanned aerial vehicles. Our OP-possession case for its airborne component comprises eight arguments in the Goal Structuring Notation (GSN): a main argument for each OP and five cross-cutting auxiliary arguments. We present this argument as an example for discussion and further research, e.g., into means of assessing OP possession.

safety case↗