Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Safety architecture”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Model-Driven Development of Safety Architectures

We describe the use of model-driven development for safety assurance of a pioneering NASA flight operation involving a fleet of small unmanned aircraft systems (sUAS) flying beyond visual line of sight. The central idea is to develop a safety architecture that provides the basis for risk assessment and visualization within a safety case, the formal justification of acceptable safety required by the aviation regulatory authority. A safety architecture is composed from a collection of bow tie diagrams (BTDs), a practical approach to manage safety risk by linking the identified hazards to the appropriate mitigation measures. The safety justification for a given unmanned aircraft system (UAS) operation can have many related BTDs. In practice, however, each BTD is independently developed, which poses challenges with respect to incremental development, maintaining consistency across different safety artifacts when changes occur, and in extracting and presenting stakeholder specific information relevant for decision making. We show how a safety architecture reconciles the various BTDs of a system, and, collectively, provide an overarching picture of system safety, by considering them as views of a unified model. We also show how it enables model-driven development of BTDs, replete with validations, transformations, and a range of views. Our approach, which we have implemented in our toolset, AdvoCATE, is illustrated with a running example drawn from a real UAS safety case. The models and some of the innovations described here were instrumental in successfully obtaining regulatory flight approval.

Safety case↗

A Comparison of Bus Architectures for Safety-Critical Embedded Systems

We describe and compare the architectures of four fault-tolerant, safety-critical buses with a view to deducing principles common to all of them, the main differences in their design choices, and the tradeoffs made. Two of the buses come from an avionics heritage, and two from automobiles, though all four strive for similar levels of reliability and assurance. The avionics buses considered are the Honeywell SAFEbus (the backplane data bus used in the Boeing 777 Airplane Information Management System) and the NASA SPIDER (an architecture being developed as a demonstrator for certification under the new DO-254 guidelines); the automobile buses considered are the TTTech Time-Triggered Architecture (TTA), recently adopted by Audi for automobile applications, and by Honeywell for avionics and aircraft control functions, and FlexRay, which is being developed by a consortium of BMW, DaimlerChrysler, Motorola, and Philips.

Rushby, John↗

Robonaut 2 - Building a Robot on the International Space Station

In 2010, the Robonaut Project embarked on a multi‐phase mission to perform technology demonstrations on‐board the International Space Station (ISS), showcasing state of the art robotics technologies through the use of Robonaut 2 (R2). This phased approach implements a strategy that allows for the use of ISS as a test bed during early development to both demonstrate capability and test technology while still making advancements in the earth based laboratories for future testing and operations in space. While R2 was performing experimental trials onboard the ISS during the first phase, engineers were actively designing for Phase 2, Intra‐Vehicular Activity (IVA) Mobility, that utilizes a set of zero‐g climbing legs outfitted with grippers to grasp handrails and seat tracks. In addition to affixing the new climbing legs to the existing R2 torso, it became clear that upgrades to the torso to both physically accommodate the climbing legs and to expand processing power and capabilities of the robot were required. In addition to these upgrades, a new safety architecture was also implemented in order to account for the expanded capabilities of the robot. The IVA climbing legs not only needed to attach structurally to the R2 torso on ISS, but also required power and data connections that did not exist in the upper body. The climbing legs were outfitted with a blind mate adapter and coarse alignment guides for easy installation, but the upper body required extensive rewiring to accommodate the power and data connections. This was achieved by mounting a custom adapter plate to the torso and routing the additional wiring through the waist joint to connect to the new set of processors. In addition to the power and data channels, the integrated unit also required updated electronics boards, additional sensors and updated processors to accommodate a new operating system, software platform, and custom control system. In order to perform the unprecedented task of building a robot in space, extensive practice sessions and meticulous procedures were required. Since crew training time is at a premium, the R2 team took a skills‐based training approach to ensure the astronauts were proficient with a basic skill set while refining the detailed procedures over several practice sessions and simulations. In addition to the crew activities, meticulous ground procedures were required in order to upgrade firmware on the upper body motor drivers. The new firmware for the IVA mobility unit needed to be deployed using the old software system. This also provided an opportunity to upgrade the upper body joints with new software and allowed for limited insight into the success of the updates. Complete verification that the updated firmware was successfully loaded was not confirmed until the rewiring of the upper body torso was complete.

Diftler, Myron↗

Architectural Modeling and Analysis for Safety Engineering

Model-based development tools are increasingly being used for system-level development of safety-critical systems. Architectural and behavioral models provide important information that can be leveraged to improve the system safety analysis process. Model-based design artifacts produced in early stage development activities can be used to perform system safety analysis, reducing costs and providing accurate results throughout the system life-cycle. In this report we describe an extension to the Architecture Analysis and Design Language (AADL) that supports modeling of system behavior under failure conditions. This Safety Annex enables the independent modeling of component failures and allows safety engineers to weave various types of fault behavior into the nominal system model. The accompanying tool support uses model checking to propagate errors from their source to their effect on safety properties without the need to add separate propagation specifications. The tool also captures all minimal set of fault combinations that can cause violation of the safety properties, that can be compared to qualitative and quantitative objectives as part of the safety assessment process. We describe the Safety Annex, illustrate its use with a representative example, and discuss and demonstrate the tool support enabling an analyst to investigate the system behavior under failure conditions.

FTA↗

Selecting an Architecture for a Safety-Critical Distributed Computer System with Power, Weight and Cost Considerations

This report presents an example of the application of multi-criteria decision analysis to the selection of an architecture for a safety-critical distributed computer system. The design problem includes constraints on minimum system availability and integrity, and the decision is based on the optimal balance of power, weight and cost. The analysis process includes the generation of alternative architectures, evaluation of individual decision criteria, and the selection of an alternative based on overall value. In this example presented here, iterative application of the quantitative evaluation process made it possible to deliberately generate an alternative architecture that is superior to all others regardless of the relative importance of cost.

Torres-Pomales, Wilfredo↗

A safety-based decision making architecture for autonomous systems

Engineering systems designed specifically for space applications often exhibit a high level of autonomy in the control and decision-making architecture. As the level of autonomy increases, more emphasis must be placed on assimilating the safety functions normally executed at the hardware level or by human supervisors into the control architecture of the system. The development of a decision-making structure which utilizes information on system safety is detailed. A quantitative measure of system safety, called the safety self-information, is defined. This measure is analogous to the reliability self-information defined by McInroy and Saridis, but includes weighting of task constraints to provide a measure of both reliability and cost. An example is presented in which the safety self-information is used as a decision criterion in a mobile robot controller. The safety self-information is shown to be consistent with the entropy-based Theory of Intelligent Machines defined by Saridis.

Musto, Joseph C.↗

Architecting Safer Autonomous Aviation Systems

The aviation literature gives relatively little guidance to practitioners about the specifics of architecting systems for safety, particularly the impact of architecture on allocating safety requirements, or the relative ease of system assurance resulting from system or subsystem level architectural choices. As an exemplar, this paper considers common architectural patterns used within traditional aviation systems and explores their safety and safety assurance implications when applied in the context of integrating artificial intelligence (AI) and machine learning (ML) based functionality. Considering safety as an architectural property, we discuss both the allocation of safety requirements and the architectural trade-offs involved early in the design lifecycle. This approach could be extended to other assured properties, similar to safety, such as security. We conclude with a discussion of the safety considerations that emerge in the context of candidate architectural patterns that have been proposed in the recent literature for enabling autonomy capabilities by integrating AI and ML. A recommendation is made for the generation of a property-driven architectural pattern catalogue.

Architecture patterns↗

Architecting Safer Autonomous Aviation Systems

The aviation literature gives relatively little guidance to practitioners about the specifics of architecting systems for safety, particularly the impact of architecture on allocating safety requirements, or the relative ease of system assurance resulting from system or subsystem level architectural choices. As an exemplar, this paper considers common architectural patterns used within traditional aviation systems and explores their safety and safety assurance implications when applied in the context of integrating artificial intelligence (AI) and machine learning (ML) based functionality. Considering safety as an architectural property, we discuss both the allocation of safety requirements and the architectural trade-offs involved early in the design lifecycle. This approach could be extended to other assured properties, similar to safety, such as security. We conclude with a discussion of the safety considerations that emerge in the context of candidate architectural patterns that have been proposed in the recent literature for enabling autonomy capabilities by integrating AI and ML. A recommendation is made for the generation of a property-driven architectural pattern catalogue.

Architecture patterns↗

Safety-Critical Partitioned Software Architecture: A Partitioned Software Architecture for Robotic

The flight software on virtually every mission currently managed by JPL has several major flaws that make it vulnerable to potentially fatal software defects. Many of these problems can be addressed by recently developed partitioned operating systems (OS). JPL has avoided adopting a partitioned operating system on its flight missions, primarily because doing so would require significant changes in flight software design, and the risks associated with changes of that magnitude cannot be accepted by an active flight project. The choice of a partitioned OS can have a dramatic effect on the overall system and software architecture, allowing for realization of benefits far beyond the concerns typically associated with the choice of OS. Specifically, we believe that a partitioned operating system, when coupled with an appropriate architecture, can provide a strong infrastructure for developing systems for which reusability, modifiability, testability, and reliability are essential qualities. By adopting a partitioned OS, projects can gain benefits throughout the entire development lifecycle, from requirements and design, all the way to implementation, testing, and operations.

(Avionics Application Standard Software Interface ↗

In-time System-wide Safety Assurance (ISSA) Concept of Operations and Design Considerations for Urban Air Mobility (UAM)

Emerging operations involving Advanced Air Mobility (AAM), such as Urban Air Mobility (UAM), pose a challenge to safety assurance and to accessibility within the National Airspace System (NAS).In particular, the public has a low tolerance for risk in aviation and the current NAS tends to be labor-intensive with limited ability to scale up for UAM. In response to this landscape, NASA is collaborating with industry to define a Concept of Operations (ConOps) for In-time System-Wide Safety Assurance (ISSA) for scalable UAM involving a service-oriented architecture. This architecture focuses safety investments for technological solutions that can overcome safety related barriers for emerging operations. By working with industry, consensus can be reached on desirable system traits that are based on integration and fusion of data and leverage increasingly autonomous and automated systems. These complex systems can identify anomalies, precursors, and trends that together enable more proactive management of operational risks. AAM and UAM elevate the need for risk management in relation to increasing density and heterogeneity of vehicles and operations. Whereas safety in today’s NAS is built on a history of programs and technologies that react to incidents and accidents, AAM presents an opportunity to leverage that experience and its implications and proactively integrate safety into the earliest designs of vehicles and systems. In a perfect world AAM and UAM would not be inherently dangerous but until then ensuring the highest quality of safety requirements is the bridge to mitigating risks.

In-Time System-Wide Safety Assurance↗

Autonomous Surface Site Establishment to Ensure Safe Crew Arrival and Operations

Traditional human Mars missions have relied on crew to support the surface systems. However, for safety, the surface systems will likely need to be setup and capable of operating prior to the arrival of crew. To mitigate risks to the crew, a novel surface architecture has been developed that addresses risks associated with other Mars missions. This architecture relies on a reusable descent and ascent vehicle, extensive in-situ resource utilization, redundant habitation systems, and emerging autonomous capabilities. The resulting surface architecture increases safety for the crew while also providing potential to expand to support longer missions with larger populations in the future.

Jones, Christopher A.↗

Identification of Safety Metrics for Airport Surface Operations

A large fraction of safety incidents occurs on the ground during airport surface operations. Although these incidents are mostly non-fatal with a few exceptions, they are high profile incidents that remain a source of concern for the National Transportation Safety Board (NTSB), the Federal Aviation Administration (FAA), major airlines, and other stakeholders of the National Airspace System (NAS). These incidents have historically been mitigated by implementing changes to regulations, policies, and procedures over time. This approach has minimized but not eliminated the risk of occurrence of safety incidents. It is thus important to develop integrated techniques to assess, model, and prevent these incidents by analyzing the risk and likelihood of occurrence and communicating results of the analysis to decision-making personnel who can mitigate and prevent incidents in real time. The work presented in this paper builds on a previously developed architecture for safety, Real-Time Safety Monitoring (RTSM), to enable monitoring and prediction of the safety of the NAS. In the RTSM framework, hazards to flight are translated to safety metrics such as wake vortex encounters or loss of separation, that can be modeled and analyzed offline and also predicted and monitored in real time (online). The intent of this paper is to integrate predictable incidents that occur during surface and ground operations into the safety portfolio of the RTSM project by (i) identifying suitable information sources from which ground incidents can be studied, (ii) developing safety metrics correlated with surface operations, and (iii) recommending suitable data sources that can be quantified and used for the computation of pertinent safety metrics.

safety↗

ADEPT: A Pedagogical Framework for Integrating Agentic AI with Deterministic Scientific Workflows

The integration of Large Language Models (LLMs) into scientific research promises to accelerate discovery, yet a significant gap remains between the dynamic reasoning of Artificial Intelligence (AI) agents and the static, deterministic nature of canonical scientific workflows. This paper introduces ADEPT (Agentic Discovery and Exploration Platform for Tools), a reference architecture and pedagogical framework explicitly designed to bridge this gap. ADEPT's primary mission is to provide a transparent, "glass-box" environment where researchers and engineers can learn to effectively wrap established scientific software (e.g., BLAST, Nextflow pipelines) and compose it into reliable, agent-driven workflows. We describe its modular, multi-server architecture, which leverages the Model Context Protocol (MCP) for tool serving, LangGraph for robust agentic orchestration, and a secure nsjail-based sandbox for safe code execution. By prioritizing architectural clarity, safety, and modularity, ADEPT serves as an extensible blueprint for building trustworthy AI-augmented systems and fosters the collaborative development necessary to responsibly employ agentic AI for science. We provide practical examples of how to adapt and extend this framework, highlighting its utility in workforce development and AI-readiness capabilities across research and development projects.

97 MATHEMATICS AND COMPUTING↗

Technology drivers for flight telerobotic system software

Viewgraphs on technology drivers for flight telerobotic system software are included. Topics covered include: flight software lines of code; flight computer architecture; system safety; safety critical parameters; system safety - software functions.

Labaugh, Robert↗

An Approach for Defining IASMS Services, Functions, and Capabilities

Assuring safety in the NAS with the inclusion of new entrants, such as Advanced Air Mobility (AAM), will require overcoming unique safety challenges that result from combining innovative technologies with novel airspace concepts for moving people and cargo using autonomous vehicles. The focus of the In-time Aviation Safety Management System (IASMS) is to overcome AAM’s safety assurance challenges. The IASMS Concept of Operations (ConOps) describes an interconnected set of services, functions, and capabilities (SFCs) designed to manage operational risks, identify unknown risks, and inform system designs. This paper describes an approach for defining SFCs based on technology trends in research, assessment of known and unknown risks in voluntary safety reports, and causal and contributing factors in aviation accidents and incidents. This approach would identify potential SFCs that further expand the Monitor, Assess, and Mitigate (M-A-M) functionality that represents the enabling framework of the IASMS. Safety implications that will result from integration of AAM in the transformation of the National Airspace System (NAS) were addressed in National Academies committees reports on AAM and IASMS. Development of a ConOps for IASMS was a top recommendation and can be represented as a reframing of safety assurance that builds on real-time alerting such as the Traffic Alert and Collision Avoidance System, and adds the more encompassing in-time temporal parameter in recognition of the different timelines for collecting and assessing safety data for risk mitigations. For example, mining for safety trends from data sources such as the Aviation Safety Information Analysis and Sharing system occurs over a longer time period. Research on AAM operations poses that SFCs can be designed to monitor the safety margin appropriate for AAM including with regards to the distance between current flight parameters and nominal ideal conditions. These in-time comparisons will become more complex as the density of operations increases at least in certain areas and can include planned and actual 4D trajectory, and in-time comparisons having implications on conflict modeling and prediction including expected and actual departure time, fix/waypoint crossing times, and arrival time. These comparisons would be integrated as part of SFCs that redefine and inform new safety margin. An increased safety margin improves management of operational risks while reducing the potential for anomalies. An increased safety margin also has implications for operator confidence in the certainty of its operations and trust in automation. Technology trends in research could be used to refine existing SFCs and define needs for additional SFCs that provide safety improvements to the design and operation of vehicles, airspace design, and operator performance requirements. NASA is developing innovative approaches to safeguard against major accidents and incidents that have occurred in the NAS and those anticipated with the inclusion of envisioned AAM operations. The innovations use operational performance data to monitor, detect, and predict flight variations exceeding safe nominal patterns, such as would be caused by navigational error, severe weather complications, or hijacking of UAS controls. These innovative approaches have high potential to prevent accidents and incidents in the new AAM era. It is anticipated that elements of the innovations will evolve into SFCs for the IASMS. Voluntary safety reports can be monitored to identify anomalies related to design or operational performance risks. Reports could be periodically monitored and assessed for specific topics. Reports might serve as weak signals or precursors indicative of emergent risk such as when combined with other safety information. The architecture could include SFCs that are based on voluntary safety reports recognizing the periodic temporal nature of data analysis. As previously mentioned, aviation accidents with their causal and contributing precursors can inform the need for SFCs in the IASMS. Accidents and incidents at San Francisco International Airport such as Asiana 214 and Air Canada 759 illustrate how combinations of different factors lead to increased risk. These types of precursors and different factors have implications on the types of SFCs that could be needed to monitor and manage different sources and types of design and operational risk. Continuing to assure the safety of AAM as designs and operations gain in complexity can be accompanied by defining SFCs that also increase in complexity. These SFCs can leverage information from findings and recommendations synthesized across on-going research, voluntary safety reports, and accident and incident reports. These SFCs can serve to refine accuracy of algorithms and resolve limitations with current practices. The IASMS architecture represents the framework for the SFCs and their critical role in safety assurance.

In-Time Aviation Safety Management System↗

Solid-state Architecture Batteries for Enhanced Rechargeability and Safety (SABERS) for Extended Deep Space Applications

Extended duration deep space missions as well as permanent space habitats face numerous technical challenges, key among them is energy generation and energy storage. There are considerable monetary and technical barriers to the generation of power in space. Therefore, it is important to store and be able to access power in an efficient and safe manner over a large number of cycles. Energy storage and in particular, batteries, are vital to the operation of next-generation extraterrestrial shuttles, rovers, habitats and extravehicular activity (EVA) space suits. The performance metrics for extended duration space missions are at least 2 times greater than those set for terrestrial applications such as electric automobiles. Furthermore, safety is essential for operation of space missions particularly involving astronauts such as shuttles, habitats and EVA space suits. Preliminary systems level analysis has indicated that there are five key properties which must be optimized for successful implementation of battery systems. Those five key criteria are: safety, energy density, power, packaging design and scalability. Current state-of-the-art (SOA) lithium-ion batteries can meet or exceed the requirements for certain space applications in the areas of power and scalability, yet are insufficient in the key performance criteria of energy, safety and packaging design. The SABERS concept proposes a battery that meets all five key performance criteria through development of a solid-state architecture battery utilizing high capacity sulfur-selenium cathode and lithium metal anode. The combination of sulfur and selenium offers a balanced energy-to-power density ratio, which can be tailored to the specific application by altering the stoichiometric ratios of sulfur to selenium. This hybrid cathode will be developed by implementing NASA patented holey graphene technology as a highly conductive, ultra-lightweight electrode scaffold. A solid-state electrolyte will be used as a safe, non-flammable replacement to the highly flammable liquid organic electrolytes currently used in SOA lithium-ion batteries. This solid-state lithium-sulfur/selenium cell will be designed into a serial stacking configuration to enable dense packaging of the battery cells. The serial stacking configuration is termed a bipolar stack, which has the advantages of reducing overall cell weight, simplifying the interfaced connections for the cell, and minimizing the cooling requirements for the cell. Lastly, optimization of battery components will occur through a robust and rigorous combination of various computational modeling techniques covering multiple length scales. The expected result will be a fully solid-state battery with operational temperatures up to 150 °C which provides the required energy density, discharge rates, and inherent safety to meet the strict space mission performance criteria. In particular, the wide operational temperature window is required for the large temperature ranges which are experienced across a broad range of potential space missions. This presentation will show initial results that demonstrate the SABERS team has developed a composite carbon-sulfur cathode which exceeds 1100 Wh/kg at a discharge rate of 0.4C, and 804 Wh/kg at a discharge rate of 1C. Additionally, this presentation will show the SABERS team multiscale computational modeling approach and has produced a novel particle dynamics method called Solid Electrolyte Sphere Approximation Model (SESAM). SESAM is on the 1-10 µm scale and provides electromechanical and grain interactions for predictive design guidelines for the experimental team to follow.

Urban Air Mobility (UAM) Vehicles↗