Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Criticality Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

Natural Language Interface for Safety Certification of Safety-Critical Software

Model-based design and automated code generation are being used increasingly at NASA. The trend is to move beyond simulation and prototyping to actual flight code, particularly in the guidance, navigation, and control domain. However, there are substantial obstacles to more widespread adoption of code generators in such safety-critical domains. Since code generators are typically not qualified, there is no guarantee that their output is correct, and consequently the generated code still needs to be fully tested and certified. The AutoCert generator plug-in supports the certification of automatically generated code by formally verifying that the generated code is free of different safety violations, by constructing an independently verifiable certificate, and by explaining its analysis in a textual form suitable for code reviews.

Denney, Ewen↗

Validation of Safety-Critical Systems for Aircraft Loss-of-Control Prevention and Recovery

Validation of technologies developed for loss of control (LOC) prevention and recovery poses significant challenges. Aircraft LOC can result from a wide spectrum of hazards, often occurring in combination, which cannot be fully replicated during evaluation. Technologies developed for LOC prevention and recovery must therefore be effective under a wide variety of hazardous and uncertain conditions, and the validation framework must provide some measure of assurance that the new vehicle safety technologies do no harm (i.e., that they themselves do not introduce new safety risks). This paper summarizes a proposed validation framework for safety-critical systems, provides an overview of validation methods and tools developed by NASA to date within the Vehicle Systems Safety Project, and develops a preliminary set of test scenarios for the validation of technologies for LOC prevention and recovery

Belcastro, Christine M.↗

System Guidelines for EMC Safety-Critical Circuits: Design, Selection, and Margin Demonstration

Demonstration of safety margins for critical points (circuits) has traditionally been required since it first became a part of systems-level Electromagnetic Compatibility (EMC) requirements of MIL-E-6051C. The goal of this document is to present cost-effective guidelines for ensuring adequate Electromagnetic Effects (EME) safety margins on spacecraft critical circuits. It is for the use of NASA and other government agencies and their contractors to prevent loss of life, loss of spacecraft, or unacceptable degradation. This document provides practical definition and treatment guidance to contain costs within affordable limits.

Lawton, R. M.↗

Mission and Safety Critical (MASC): An EVACS simulation with nested transactions

The Extra-Vehicular Activity Control System (EVACS) Simulation with Nested Transactions, a recent effort of the MISSION Kernel Team, is documented. The EVACS simulation is a simulation of some aspects of the Extra-Vehicular Activity Control System, in particular, just the selection of communication frequencies. The simulation is a tool to explore mission and safety critical (MASC) applications. For the purpose of this effort, its current definition is quite narrow serving only as a starting point for prototyping purposes. (Note that EVACS itself has been supplanted in a larger scenario of a lunar outpost with astronauts and a lunar rover). The frequency selection scenario was modified to embed its processing in nested transactions. Again as a first step, only two aspects of transaction support were implemented in this prototype: architecture and state recovery. Issues of concurrency and distribution are yet to be addressed.

Auty, David↗

Managing Risk in Safety Critical Operations - Lessons Learned from Space Operations

The Mission Control Center (MCC) at Johnson Space Center (JSC) has a rich legacy of supporting Human Space Flight operations throughout the Apollo, Shuttle and International Space Station eras. Through the evolution of ground operations and the Mission Control Center facility, NASA has gained a wealth of experience of what it takes to manage the risk in Safety Critical Operations, especially when human life is at risk. The focus of the presentation will be on the processes (training, operational rigor, team dynamics) that enable the JSC/MCC team to be so successful. The presentation will also share the evolution of the Mission Control Center architecture and how the evolution was introduced while managing the risk to the programs supported by the team. The details of the MCC architecture (e.g., the specific software, hardware or tools used in the facility) will not be shared at the conference since it would not give any additional insight as to how risk is managed in Space Operations.

Gonzalez, Steven A.↗

Exponential Backoff and Its Security Implications for Safety-Critical OT Protocols over TCP/IP Networks

The convergence of Operational Technology (OT) and Information Technology (IT) networks has become increasingly prevalent with the growth of Industrial Internet of Things (IIoT) applications. This shift, while enabling enhanced automation, remote monitoring, and data sharing, also introduces new challenges related to communication latency and cybersecurity. Oftentimes, legacy OT protocols were adapted to the TCP/IP stack without an extensive review of the ramifications to their robustness, performance, or safety objectives. To further accommodate the IT/OT convergence, protocol gateways were introduced to facilitate the migration from serial protocols to TCP/IP protocol stacks within modern IT/OT infrastructure. However, they often introduce additional vulnerabilities by exposing traditionally isolated protocols to external threats. This study investigates the security and reliability implications of migrating serial protocols to TCP/IP stacks and the impact of protocol gateways, utilizing two widely used OT protocols: Modbus TCP and DNP3. Our protocol analysis finds a significant safety-critical vulnerability resulting from this migration, and our subsequent tests clearly demonstrate its presence and impact. A multi-tiered testbed, consisting of both physical and emulated components, is used to evaluate protocol performance and the effects of device-specific implementation flaws. Through this analysis of specifications and behaviors during communication interruptions, we identify critical differences in fault handling and the impact on time-sensitive data delivery. The findings highlight how reliance on lower-level IT protocols can undermine OT system resilience, and they inform the development of mitigation strategies to enhance the robustness of industrial communication networks.

DNP3↗

Evaluating Models of Human Performance: Safety-Critical Systems Applications

This presentation is part of panel discussion on Evaluating Models of Human Performance. The purpose of this panel is to discuss the increasing use of models in the world today and specifically focus on how to describe and evaluate models of human performance. My presentation will focus on discussions of generating distributions of performance, and the evaluation of different strategies for humans performing tasks with mixed initiative (Human-Automation) systems. I will also discuss issues with how to provide Human Performance modeling data to support decisions on acceptability and tradeoffs in the design of safety critical systems. I will conclude with challenges for the future.

Feary, Michael S.↗

A new technology perspective and engineering tools approach for large, complex and distributed mission and safety critical systems components

Rapidly emerging technology and methodologies have out-paced the systems development processes' ability to use them effectively, if at all. At the same time, the tools used to build systems are becoming obsolescent themselves as a consequence of the same technology lag that plagues systems development. The net result is that systems development activities have not been able to take advantage of available technology and have become equally dependent on aging and ineffective computer-aided engineering tools. New methods and tools approaches are essential if the demands of non-stop and Mission and Safety Critical (MASC) components are to be met.

Carrio, Miguel A., Jr.↗

Credible Criticality Safety Margin in the 30B Package with LEU+ UF 6 and Hypothetical Water Ingress

The commercial nuclear industry is pursuing advancements in fuel and reactor design that increase the uranium enrichment above 5 wt. % 235 U. These advancements will necessitate the ability to transport bulk quantities of UF 6 at increased enrichments. Currently, the 30B cylinder is the primary container used by the industry for UF6 storage and transportation and has a long history of successful shipments. This container can transport up to 2,277 kg of UF 6 at a maximum enrichment of 5 wt. % 235 U. Previous evaluations have assessed the potential impact of criticality safety for 30B transport at higher enrichments but assumed moderator intrusion would not require evaluation. Although current regulations allow for the exception of moderator intrusion for UF6 packages through the design and quality control of the package content, this exception is limited to enrichments up to 5 wt. % 235 U. Thus, an investigation of moderator intrusion into a 30B cylinder should be performed.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Automated Translation of Safety Critical Application Software Specifications into PLC Ladder Logic

The numerous benefits of automatic application code generation are widely accepted within the software engineering community. A few of these benefits include raising the abstraction level of application programming, shorter product development time, lower maintenance costs, and increased code quality and consistency. Surprisingly, code generation concepts have not yet found wide acceptance and use in the field of programmable logic controller (PLC) software development. Software engineers at the NASA Kennedy Space Center (KSC) recognized the need for PLC code generation while developing their new ground checkout and launch processing system. They developed a process and a prototype software tool that automatically translates a high-level representation or specification of safety critical application software into ladder logic that executes on a PLC. This process and tool are expected to increase the reliability of the PLC code over that which is written manually, and may even lower life-cycle costs and shorten the development schedule of the new control system at KSC. This paper examines the problem domain and discusses the process and software tool that were prototyped by the KSC software engineers.

Leucht, Kurt W.↗

An ontology-based fault generation and fault propagation analysis approach for safety-critical computer systems at the design stage

Abstract Fault propagation analysis is a process used to determine the consequences of faults residing in a computer system. A typical computer system consists of diverse components (e.g., electronic and software components), thus, the faults contained in these components tend to possess diverse characteristics. How to describe and model such diverse faults, and further determine fault propagation through different components are challenging problems to be addressed in the fault propagation analysis. This paper proposes an ontology-based approach, which is an integrated method allowing for the generation, injection, and propagation through inference of diverse faults at an early stage of the design of a computer system. The results generated by the proposed framework can verify system robustness and identify safety and reliability risks with limited design level information. In this paper, we propose an ontological framework and its application to analyze an example safety-critical computer system. The analysis result shows that the proposed framework is capable of inferring fault propagation paths through software and hardware components and is effective in predicting the impact of faults.

97 MATHEMATICS AND COMPUTING↗

Validation and Verification (V&V) of Safety-Critical Systems Operating Under Off-Nominal Conditions

Loss of control (LOC) remains one of the largest contributors to aircraft fatal accidents worldwide. Aircraft LOC accidents are highly complex in that they can result from numerous causal and contributing factors acting alone or more often in combination. Hence, there is no single intervention strategy to prevent these accidents. Research is underway at the National Aeronautics and Space Administration (NASA) in the development of advanced onboard system technologies for preventing or recovering from loss of vehicle control and for assuring safe operation under off-nominal conditions associated with aircraft LOC accidents. The transition of these technologies into the commercial fleet will require their extensive validation and verification (V&V) and ultimate certification. The V&V of complex integrated systems poses highly significant technical challenges and is the subject of a parallel research effort at NASA. This chapter summarizes the V&V problem and presents a proposed process that could be applied to complex integrated safety-critical systems developed for preventing aircraft LOC accidents. A summary of recent research accomplishments in this effort is referenced.

Belcastro, Christine M.↗

Porosity in nuclear graphite and its impact on nuclear reactor science and criticality safety applications

Porosity in nuclear-grade graphite significantly influences its low-energy neutron scattering, yet its effect on underlying phonon properties remains debated. Here, this work integrates inelastic and small-angle neutron scattering (INS/SANS) experiments, advanced atomistic simulations with a novel machine-learned potential (DeepMD), total cross-section measurements, and neutronics calculations (SCALE, MCNP, OpenMC) to investigate porosity’s impact on neutron thermalization. INS measurements on diverse graphite grades reveal no discernible porosity effect on phonon spectra, which align with crystalline graphite. Conversely, total cross-section data below ≈10 meV show increased scattering attributable to SANS. Our DeepMD simulations demonstrate that realistic micropores do not distort phonon spectra, challenging the assumptions in current ENDF/B-VIII.1 porosity thermal scattering laws (TSLs). These TSLs, based on random atom removal, produce unphysical phonon spectra and inflate inelastic cross-sections. Augmenting a crystalline TSL with an SANS component accurately captures experimental total cross-sections. Neutronics benchmarks (ICSBEP/IRPhE) show ENDF porosity TSLs unphysically increase neutron multiplication factor, keff. Crucially, incorporating SANS physics (NCrystal/OpenMC) indicates accurately modeled porosity negligibly affects keff, reactor physics, or criticality safety.

Critical benchmarks↗

Impacts of LEU+ and ATF on Fresh Fuel Storage Criticality Safety

The use of increased fuel enrichment, which is still in the realm of low-enriched uranium (LEU) fuel, has been of interest to commercial light water reactor operators as part of the next iteration in fuel cycle technological advances and research and development. Using increased enrichment fuel, or high-assay LEU (HALEU), in power plants has clear benefits for being able to load cores with additional power-producing fuel. Although HALEU enrichments can range up to 20%, the more guarded approach of investigating enrichments above current fuels within 10% enrichment is referred to as LEU plus (LEU+) to reflect the less drastic change in operating conditions and requirements and similarity to current fuel cycles. Of additional interest and increasing maturity is the incorporation of accident-tolerant fuel (ATF) concepts, which are also applicable to the current fleet. This class of technologies involves changes such as cladding (e.g., chromium coating or FeCrAl) and fuel composition (e.g., chromia dopant) alterations to demonstrate improved fuel performance under accident scenarios. The ability to properly store fuel before and after residence time in the reactor is crucial to plant operation. Typically, this is done in either a new fuel vault (NFV) or spent fuel pool (SFP). Storing, loading, and unloading dozens of fuel assemblies within the same general area provides opportunities for obvious criticality concerns. These concerns are addressed with regulations to the subcriticality margin that the NFV and SFP must maintain in certain conditions. Adopting LEU+ fuel results in inherent reactivity increases, which are extremely relevant for safe fuel storage. Therefore, a clear understanding of the effects of LEU+ fuel and ATF on criticality safety margins to regulatory limits is required, as well as an understanding of the degree of absorber crediting under normal and accident conditions.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

System Guidelines for EMC Safety-Critical Circuits: Design, Selection, and Margin Demonstration

Demonstration of required safety margins on critical electrical/electronic circuits in large complex systems has become an implementation and cost problem. These margins are the difference between the activation level of the circuit and the electrical noise on the circuit in the actual operating environment. This document discusses the origin of the requirement and gives a detailed process flow for the identification of the system electromagnetic compatibility (EMC) critical circuit list. The process flow discusses the roles of engineering disciplines such as systems engineering, safety, and EMC. Design and analysis guidelines are provided to assist the designer in assuring the system design has a high probability of meeting the margin requirements. Examples of approaches used on actual programs (Skylab and Space Shuttle Solid Rocket Booster) are provided to show how variations of the approach can be used successfully.

Lawton, R. M.↗