Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Safety Assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Considerations in Assuring Safety of Increasingly Autonomous Systems

Recent technological advances have accelerated the development and application of increasingly autonomous (IA) systems in civil and military aviation. IA systems can provide automation of complex mission tasks-ranging across reduced crew operations, air-traffic management, and unmanned, autonomous aircraft-with most applications calling for collaboration and teaming among humans and IA agents. IA systems are expected to provide benefits in terms of safety, reliability, efficiency, affordability, and previously unattainable mission capability. There is also a potential for improving safety by removal of human errors. There are, however, several challenges in the safety assurance of these systems due to the highly adaptive and non-deterministic behavior of these systems, and vulnerabilities due to potential divergence of airplane state awareness between the IA system and humans. These systems must deal with external sensors and actuators, and they must respond in time commensurate with the activities of the system in its environment. One of the main challenges is that safety assurance, currently relying upon authority transfer from an autonomous function to a human to mitigate safety concerns, will need to address their mitigation by automation in a collaborative dynamic context. These challenges have a fundamental, multidimensional impact on the safety assurance methods, system architecture, and V&V capabilities to be employed. The goal of this report is to identify relevant issues to be addressed in these areas, the potential gaps in the current safety assurance techniques, and critical questions that would need to be answered to assure safety of IA systems. We focus on a scenario of reduced crew operation when an IA system is employed which reduces, changes or eliminates a human's role in transition from two-pilot operations.

Alves, Erin E.

Dynamic Safety Cases for Through-Life Safety Assurance

We describe dynamic safety cases, a novel operationalization of the concept of through-life safety assurance, whose goal is to enable proactive safety management. Using an example from the aviation systems domain, we motivate our approach, its underlying principles, and a lifecycle. We then identify the key elements required to move towards a formalization of the associated framework.

Dynamic Safety Case

Critical safety assurance factors for manned spacecraft - A fire safety perspective

Safety assurance factors for manned spacecraft are discussed with a focus on the Space Station Freedom. A hazard scenario is provided to demonstrate a process commonly used by safety engineers and other analysts to identify onboard safety risks. Fire strategies are described, including a review of fire extinguishing agents being considered for the Space Station. Lessons learned about fire safety technology in other areas are also noted. NASA and industry research on fire safety applications is discussed. NASA's approach to ensuring safety for manned spacecraft is addressed in the context of its multidiscipline program.

Rodney, George A.

Safety Assurance Framework for Nuclear Digital Instrumentation and Control Software

Software in digital instrumentation and control (D&C) systems poses unique challenges for the safety assurance of nuclear power plants. Through a literature survey of 21 sources, we analyzed various claims, arguments, and evidence used in safety assurance cases across industries. These were organized into a Goal Structuring Notation (GSN) safety assurance case framework to organize and visualize the various arguments for DI&C safety. We developed a classification for the levels of the framework, which can be used in other safety assurance cases to improve clarity.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN

Designing for Advanced Aerial Mobility: Human-Autonomy Teaming and In-Time System-Wide Safety Assurance

The continued growth of aviation shall require new innovative technologies and operational concepts to meet the ever-increasing demands on air transportation. The NASA Advanced Air Mobility (AAM) project focuses on emerging aviation markets, such as Urban Air Mobility (UAM). UAM is defined as “...a safe and efficient system for air passenger and cargo transportation within an urban area. It is inclusive of small package delivery and other urban unmanned aerial system services and supports a mix of onboard/ground-piloted and increasingly autonomous operations” ([1]). The AAM project emphasizes technology development and validating system-level concepts and solutions in coordination with other NASA Aeronautics Research Mission Directorate (ARMD) projects to enable UAM metro- and micro-plex vertiport and airspace concepts of operations. The NASA AAM research portfolio includes the concepts of Remote Supervisor-in-Command (RSC) and Fleet and Airspace Manager (FAM) as possible human roles for consumer fleet providers. NASA research in RSC is focused on development of guidelines and standards for remote pilots/operators passively and actively controlling a large fleet of autonomous aircraft. For FAM, flight and ground system concepts and technologies to enable high density homogeneous operations at increased scale from vertiport(s), and coordination with other humans in the systems (e.g., UAM urban airspace manager, Air Traffic Control) are key research areas. The envisioned UAM operations are posited to require autonomous systems to enable functions ranging from fleet and resource management to vehicle control. Although automation has become increasingly sophisticated and ubiquitous in civil aviation, autonomy represents a significant evolution in automation, which has generally been limited in functional scope and capability. As autonomy takes on increasing responsibilities, humans and machines will be required to work together in new and different ways [2], rather than traditional design approaches focused on how machines (i.e., autonomy) can do the work of people. The emerging field of human-autonomy teaming (HAT) represents a comprehensive and prioritized research-driven approach to enable the success of future emerging aviation market applications through capabilities and principles that facilitate humans and machine working and thinking better together. The NASA Transformational Tools and Technologies (TTT) Autonomous System (AS) Sub-project was created to assist with the transition into higher levels of autonomy to enable new modes of air transportation, such as UAM. TTT-AS has identified HAT as a key research need to enable UAM while maintaining today’s ultra-safe aviation system safety levels. The latter challenge has been taken up by the NASA System-Wide Safety (SWS) Project, which recognizes that aviation safety, as it evolves, shall require new ways of thinking about safety to include integration of a wide-range of existing and new safety systems and practices, enhanced tools and technologies, increased access to data and data fusion, improved data analysis capabilities, enhanced in-time risk monitoring and detection, hazard prioritization and mitigation, safety assurance decision-support, and in-time integrated system analytics [3].The operational concept of UAM represents a variety of work that has been termed, “work-as-imagined” to characterize the idea that how people think that work is done and how work is actually done are often not the same [4]. To ensure design success and system safety, looking at “work-as-done” provides a comparative approach toward UAM concept and technology design through examination of corresponding analogs found today in aviation (e.g., on-demand operations) and other transportation domains (e.g., port operations). The paper shall discuss various alternative applications with specific focus on airline operation center (AOC) operations, and unmanned aerial system (UAS) command-and-control to inform scaled-versions of FAM and RSC, respectively, and with consideration of the national airspace system contextual environment. The tenets and principles of the HAT field and current NASA research efforts under the TTT-AS sub-project shall also be described. Finally, the SWS sub-project efforts to develop In-Time System-Wide Safety Assurance (ISSA) and In-Time Safety Management Systems (IASMS) are discussed in terms of how “in-time” safety assurance may be conceptualized for the on-demand mobility air taxi “work-as-imagined” operational concept [5]. As part of this effort, concepts from the emerging field of resilience engineering, are being studied. Traditional approaches to aviation safety have focused on what can go wrong and how to prevent it. Another approach to thinking about system safety should reflect not only “avoiding things that go wrong” (protective safety) but also “ensuring that things go right” (productive safety), that enables a system to exhibit the resilient performance [6] necessary for the success of the future aviation system emerging concepts of operations. The paper shall describe efforts focused on how productive safety and resilience may enable a more complete approach to system safety thinking and design of ISSA and IASMS for UAM. Future directions and research needs shall also be discussed.

resilience

Safety Assurance of Software and Machine Learning Development for Nuclear Instrumentation and Controls

Digital instrumentation and control (DI&C) systems monitor and control parameters in nuclear power plants. Ensuring their safety is a critical part of ensuring overall plant safety. Nuclear power plant licensing generates thousands of safety documents that could be organized more effectively using a safety assurance case (SAC). We conducted a literature survey of SACs and created a SAC framework for DI&C software using Goal Structuring Notation (GSN). This framework focuses on four software development processes: management & assurance, pre-developed software (PDS) qualification, the Software Development Life Cycle (SDLC), and the Machine Learning Development Life Cycle (MLDLC). We organized our framework using a novel level structure that can be applied to other SACs to improve their clarity. Finally, we demonstrate how our framework can be incorporated as part of a SAC for a larger reactor system.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN

Safety assurance of complex integrated systems

Interface hazard analysis (IHA) is used as a 'tool' to systematically assess safety for the integration of a diverse set of experiments and payload hardware into the Spacelab carrier which flies in the Space Shuttle's Orbiter cargo bay. The IHA when performed by a thorough analysis provides safety assurance of complex integrated systems by systematically linking analysis efforts performed by the organizations thus providing the respective elements to be integrated into an objective, unique analysis. Particular attention is given to verification methods of the safety assurance of the Spacelab carrier and its experiment payload for which the IHA was performed.

Abrignani, Vincent A.

In-time System-wide Safety Assurance (ISSA) Concept of Operations and Design Considerations for Urban Air Mobility (UAM)

Emerging operations involving Advanced Air Mobility (AAM), such as Urban Air Mobility (UAM), pose a challenge to safety assurance and to accessibility within the National Airspace System (NAS).In particular, the public has a low tolerance for risk in aviation and the current NAS tends to be labor-intensive with limited ability to scale up for UAM. In response to this landscape, NASA is collaborating with industry to define a Concept of Operations (ConOps) for In-time System-Wide Safety Assurance (ISSA) for scalable UAM involving a service-oriented architecture. This architecture focuses safety investments for technological solutions that can overcome safety related barriers for emerging operations. By working with industry, consensus can be reached on desirable system traits that are based on integration and fusion of data and leverage increasingly autonomous and automated systems. These complex systems can identify anomalies, precursors, and trends that together enable more proactive management of operational risks. AAM and UAM elevate the need for risk management in relation to increasing density and heterogeneity of vehicles and operations. Whereas safety in today’s NAS is built on a history of programs and technologies that react to incidents and accidents, AAM presents an opportunity to leverage that experience and its implications and proactively integrate safety into the earliest designs of vehicles and systems. In a perfect world AAM and UAM would not be inherently dangerous but until then ensuring the highest quality of safety requirements is the bridge to mitigating risks.

In-Time System-Wide Safety Assurance

In-Time System-Wide Safety Assurance (ISSA) Concept of Operations

Emerging operations involving Urban Air Mobility (UAM) poses a challenge to safety assurance and accessibility to the NAS. In particular, the public has a low tolerance for risk in aviation and the current NAS tends to be labor-intensive with limited ability to scale up for UAM. In response to this landscape, NASA is collaborating with industry to define an In-time Aviation Safety Management System (IASMS) Concept of Operations (ConOps) for a scalable UAM along with a service-oriented architecture. This architecture would better focus safety investments for technological solutions that overcome safety related barriers for emerging operations. By working with industry, consensus can be reached on desirable system traits that are based on integration of data and leverage increasingly autonomous and automated systems. These complex systems can identify anomalies, precursors, and trends that together enable more proactive management of operational risks.

Ellis, Kyle

Risk-Informed Safety Assurance and Probabilistic Assessment of Mission-Critical Software-Intensive Systems

This report validates and documents the detailed features and practical application of the framework for software intensive digital systems risk assessment and risk-informed safety assurance presented in the NASA PRA Procedures Guide for Managers and Practitioner. This framework, called herein the "Context-based Software Risk Model" (CSRM), enables the assessment of the contribution of software and software-intensive digital systems to overall system risk, in a manner which is entirely compatible and integrated with the format of a "standard" Probabilistic Risk Assessment (PRA), as currently documented and applied for NASA missions and applications. The CSRM also provides a risk-informed path and criteria for conducting organized and systematic digital system and software testing so that, within this risk-informed paradigm, the achievement of a quantitatively defined level of safety and mission success assurance may be targeted and demonstrated. The framework is based on the concept of context-dependent software risk scenarios and on the modeling of such scenarios via the use of traditional PRA techniques - i.e., event trees and fault trees - in combination with more advanced modeling devices such as the Dynamic Flowgraph Methodology (DFM) or other dynamic logic-modeling representations. The scenarios can be synthesized and quantified in a conditional logic and probabilistic formulation. The application of the CSRM method documented in this report refers to the MiniAERCam system designed and developed by the NASA Johnson Space Center.

Guarro, Sergio B.

SAFEGUARD: An Assured Safety Net Technology for UAS

As demands increase to use unmanned aircraft systems (UAS) for a broad spectrum of commercial applications, regulatory authorities are examining how to safely integrate them without loss of safety or major disruption to existing airspace operations. This work addresses the development of the Safeguard system as an assured safety net technology for UAS. The Safeguard system monitors and enforces conformance to a set of rules defined prior to flight (e.g., geospatial stay-out or stay-in regions, speed limits, altitude limits). Safeguard operates independently of the UAS autopilot and is strategically designed in a way that can be realized by a small set of verifiable functions to simplify compliance with regulatory standards for commercial aircraft. A framework is described that decouples the system from any other devices on the UAS as well as introduces complementary positioning source(s) for applications that require integrity and availability beyond what the Global Positioning System (GPS) can provide. Additionally, the high level logic embedded within the software is presented, as well as the steps being taken toward verification and validation (V&V) of proper functionality. Next, an initial prototype implementation of the described system is disclosed. Lastly, future work including development, testing, and system V&V is summarized.

Dill, Evan T.

Safety Assurance in NextGen

The generation of minimum operational, safety, performance, and interoperability requirements is an important aspect of safely integrating new NextGen components into the Communication Navigation Surveillance and Air Traffic Management (CNS/ATM) system. These requirements are used as part of the implementation and approval processes. In addition, they provide guidance to determine the levels of design assurance and performance that are needed for each element of the new NextGen procedures, including aircraft, operator, and Air Navigation and Service Provider. Using the enhanced Airborne Traffic Situational Awareness for InTrail Procedure (ATSA-ITP) as an example, this report describes some limitations of the current process used for generating safety requirements and levels of required design assurance. An alternative process is described, as well as the argument for why the alternative can generate more comprehensive requirements and greater safety assurance than the current approach.

HarrisonFleming, Cody

NASA/Navy Benchmarking Exchange (NNBE). Volume 1. Interim Report. Navy Submarine Program Safety Assurance

The NASA/Navy Benchmarking Exchange (NNBE) was undertaken to identify practices and procedures and to share lessons learned in the Navy's submarine and NASA's human space flight programs. The NNBE focus is on safety and mission assurance policies, processes, accountability, and control measures. This report is an interim summary of activity conducted through October 2002, and it coincides with completion of the first phase of a two-phase fact-finding effort.In August 2002, a team was formed, co-chaired by senior representatives from the NASA Office of Safety and Mission Assurance and the NAVSEA 92Q Submarine Safety and Quality Assurance Division. The team closely examined the two elements of submarine safety (SUBSAFE) certification: (1) new design/construction (initial certification) and (2) maintenance and modernization (sustaining certification), with a focus on: (1) Management and Organization, (2) Safety Requirements (technical and administrative), (3) Implementation Processes, (4) Compliance Verification Processes, and (5) Certification Processes.

SUBSAFE PROGRAM

Certification Strategies using Run-Time Safety Assurance for Part 23 Autopilot Systems

Part 23 aircraft operation, and in particular general aviation, is relatively unsafe when compared to other common forms of vehicle travel. Currently, there exists technologies that could increase safety statistics for these aircraft; however, the high burden and cost of performing the requisite safety critical certification processes for these systems limits their proliferation. For this reason, many entities, including the Federal Aviation Administration, NASA, and the US Air Force, are considering new options for certification for technologies that will improve aircraft safety. Of particular interest, are low cost autopilot systems for general aviation aircraft, as these systems have the potential to positively and significantly affect safety statistics. This paper proposes new systems and techniques, leveraging run-time verification, for the assurance of general aviation autopilot systems, which would be used to supplement the current certification process and provide a viable path for near-term low-cost implementation. In addition, discussions on preliminary experimentation and building the assurance case for a system, based on these principles, is provided.

automatic collision avoidance

Software Safety Assurance of Programmable Logic

Programmable Logic (PLC, FPGA, ASIC) devices are hybrids - hardware devices that are designed and programmed like software. As such, they fall in an assurance gray area. Programmable Logic is usually tested and verified as hardware, and the software aspects are ignored, potentially leading to safety or mission success concerns. The objective of this proposal is to first determine where and how Programmable Logic (PL) is used within NASA and document the current methods of assurance. Once that is known, raise awareness of the PL software aspects within the NASA engineering community and provide guidance for the use and assurance of PL form a software perspective.

Berens, Kalynnda

Flight Testing of In-Time Safety Assurance Technologies for UAS Operations

Ongoing research at NASA is driven by a strategic plan defined by the Aeronautics Research Mission Directorate and a vision for future In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. In both visions, system safety awareness and provision are expanded through increased access to relevant data; integrated analysis and predictive capabilities; improved real-time detection and alerting of domain-specific hazards; decision support, and in some cases, automated risk mitigation strategies. One primary research focus is to develop means by which more timely (i.e., “in-time”) actions may be taken to mitigate precursors, anomalies, or trends that are observed during operations. In this paper, we describe such means as a collection of Services, Functions, and Capabilities (SFCs) that are supported by an underlying information system. For example, an integrated risk assessment capability is envisioned that continuously monitors safety-related metrics and margins and recommends timely operational changes. Assessment functions and/or services can be based on data analytics and predictive models derived from heterogeneous data sets that span relevant indicator metrics and their time histories. Likewise, on-board functions can identify and reduce susceptibility to precursor conditions that have led (and can lead) to aircraft loss-of-control or out-of-control accidents. This paper summarizes development and testing of such an information system tailored to hazards anticipated for future highly autonomous flight missions near and over densely populated areas. Testing is accomplished via simulation and by using small, unmanned aircraft operating over a test range at NASA’s Langley Research Center. Flight plans and test scenarios are defined to emulate several use-cases, including package delivery; reconnaissance; fire management; and urban air taxi vertiport operations. Two test phases are summarized with Phase 1 occurring in (2019-2020) and Phase 2 ongoing (2021-present). Results focus on SFC performance, technology readiness level assessment, and requirements discovery/validation. Companion papers are cited throughout for additional details on the recent testing.

safety management