Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Safety-related functionality”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

MARVEL Instrumentation, Control, and Software Considerations

This paper details the various I&C considerations and design decisions made throughout the MARVEL (Micro-reactor Applications Research Validation and Evaluation) project, including sensor and actuator selection, safety-related functionality, digital control hardware and software, and testing methodologies. Key challenges such as managing radiation, temperature, and space constraints are discussed, along with the trade-offs between using standard equipment and custom solutions. The successful integration of off-the-shelf components, the emphasis on minimizing safety-related instrumentation, and the lessons learned from prototyping and testing are highlighted. The authors aim to provide insights that can benefit future micro-reactor designs and emphasize the importance of real-world testing in advancing reactor technology.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN

Survey of space flight safety systems.

Preventive and remedial conceptual approaches may be employed to enhance the safety of space flight operations. The preventive approach makes use of components of high reliability and the incorporation of redundancy in crew safety-related functions. According to the second conceptual approach the means are to be provided to cope with accidents when they arise. The remedial means include onboard systems, pre-positioned aids, and earth-launched systems. Reports or papers dealing with rescue and survival systems of various types are considered, and a summary of the results of space escape, rescue, and survivability investigations is presented.

Fleisig, R.

Control System Upgrade for Battery State-of-Charge Indications

The Advanced Test Reactor (ATR) Complex at Idaho National Laboratory (INL) relies on Battery Backed Power (BBP) systems and Uninterruptible Power Supplies (UPS) to ensure continuous power supply to critical components. This project aims to enhance the reliability and functionality of the battery monitoring and control systems by updating the State-of-Charge (SOC) system, Programmable Logic Controller (PLC), and Human-Machine Interface (HMI) for the nuclear safety-related battery banks. The current system, while functional, has areas for improvement, particularly in recharging calculations and alarm functions. The project objectives include developing flow charts, programming the new PLC and HMI, conducting bench tests, and updating design documentation. Additionally, the project ensures compliance with safety standards, develops training materials, creates comprehensive documentation, and integrates seamlessly with existing ATR infrastructure. The new SOC system is designed to be scalable for future upgrades, improve efficiency, enhance data accuracy, implement redundancy features, and achieve project goals within budget constraints while considering environmental impact. The methodology involved familiarizing with BBP and UPS systems, collecting current readings, rescaling signals, learning ladder logic, and updating the HMI. The transition from SLC 5/03 PLC using RS Logix 500 to CompactLogix 5380 using Studio 5000 was a key step. Despite challenges in transferring outdated PLC ladder logic and HMI code, starting from scratch led to a more accurate and efficient monitoring system, contributing to improved safety and operational efficiency. The project is currently awaiting approval of the Engineering Calculation and Analysis Report (ECAR) before implementation.

42 - ENGINEERING

Flight Testing of In-Time Safety Assurance Technologies for UAS Operations

Ongoing research at NASA is driven by a strategic plan defined by the Aeronautics Research Mission Directorate and a vision for future In-Time Aviation Safety Management Systems (IASMS) as described by the National Academies. In both visions, system safety awareness and provision are expanded through increased access to relevant data; integrated analysis and predictive capabilities; improved real-time detection and alerting of domain-specific hazards; decision support, and in some cases, automated risk mitigation strategies. One primary research focus is to develop means by which more timely (i.e., “in-time”) actions may be taken to mitigate precursors, anomalies, or trends that are observed during operations. In this paper, we describe such means as a collection of Services, Functions, and Capabilities (SFCs) that are supported by an underlying information system. For example, an integrated risk assessment capability is envisioned that continuously monitors safety-related metrics and margins and recommends timely operational changes. Assessment functions and/or services can be based on data analytics and predictive models derived from heterogeneous data sets that span relevant indicator metrics and their time histories. Likewise, on-board functions can identify and reduce susceptibility to precursor conditions that have led (and can lead) to aircraft loss-of-control or out-of-control accidents. This paper summarizes development and testing of such an information system tailored to hazards anticipated for future highly autonomous flight missions near and over densely populated areas. Testing is accomplished via simulation and by using small, unmanned aircraft operating over a test range at NASA’s Langley Research Center. Flight plans and test scenarios are defined to emulate several use-cases, including package delivery; reconnaissance; fire management; and urban air taxi vertiport operations. Two test phases are summarized with Phase 1 occurring in (2019-2020) and Phase 2 ongoing (2021-present). Results focus on SFC performance, technology readiness level assessment, and requirements discovery/validation. Companion papers are cited throughout for additional details on the recent testing.

safety management

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS

A system safety model for developmental aircraft programs

Basic tenets of safety as applied to developmental aircraft programs are presented. The integration of safety into the project management aspects of planning, organizing, directing and controlling is illustrated by examples. The basis for project management use of safety and the relationship of these management functions to 'real-world' situations is presented. The rationale which led to the safety-related project decision and the lessons learned as they may apply to future projects are presented.

Amberboy, E. J.

Analyzing Software Requirements Errors in Safety-Critical, Embedded Systems

This paper analyzes the root causes of safety-related software errors in safety-critical, embedded systems. The results show that software errors identified as potentially hazardous to the system tend to be produced by different error mechanisms than non- safety-related software errors. Safety-related software errors are shown to arise most commonly from (1) discrepancies between the documented requirements specifications and the requirements needed for correct functioning of the system and (2) misunderstandings of the software's interface with the rest of the system. The paper uses these results to identify methods by which requirements errors can be prevented. The goal is to reduce safety-related software errors and to enhance the safety of complex, embedded systems.

Lutz, Robyn R.

Properties and Performance Attributes of Novel Co-extruded Polyolefin Battery Separator Materials: Electrical Properties - Part 2

As NASA prepares for its next era of manned spaceflight missions, advanced energy storage technologies are being developed and evaluated to address and enhance future mission needs and technical requirements. Cell-level components for advanced lithium-ion batteries possessing higher energy, more reliable performance and enhanced, inherent safety characteristics have been under development within the NASA infrastructure. A key component for safe and reliable cell performance is the cell separator, which separates the two energetic electrodes and functions to inhibit the occurrence of an internal short circuit but preserves an ionic current. Recently, a new generation of co-extruded separator films has been developed by ExxonMobil Chemical and introduced into their battery separator product portfolio. Several grades of this new separator material were evaluated with respect to dynamic mechanical properties and safety-related performance attributes, and the results of these evaluations were previously reported in "Part 1: Mechanical Properties" of this publication. This current paper presents safety-related performance results for these novel materials obtained by employing a complementary experimental methodology, which involved the analysis of separator impedance characteristics as a function of temperature. The experimental results from this study are discussed with respect to potential cell safety enhancement for future aerospace as well as for terrestrial energy storage needs, and they are compared with pertinent mechanical properties of these materials, as well as with current state-of-the practice separator materials.

Baldwin, Richard S.

Properties and Performance Attributes of Novel Co-Extruded Polyolefin Battery Separator Materials: Mechanical Properties - Part 1

As NASA prepares for its next era of manned spaceflight missions, advanced energy storage technologies are being developed and evaluated to address future mission needs and technical requirements and to provide new mission-enabling technologies. Cell-level components for advanced lithium-ion batteries possessing higher energy, more reliable performance and enhanced, inherent safety characteristics are actively under development within the NASA infrastructure. A key component for safe and reliable cell performance is the cell separator, which separates the two energetic electrodes and functions to prevent the occurrence of an internal short-circuit while enabling ionic transport. Recently, a new generation of co-extruded separator films has been developed by ExxonMobil Chemical and introduced into their battery separator product portfolio. Several grades of this new separator material have been evaluated with respect to dynamic mechanical properties and safety-related performance attributes. This paper presents the results of these evaluations in comparison to a current state-ofthe-practice separator material. The results are discussed with respect to potential opportunities to enhance the inherent safety characteristics and reliability of future, advanced lithium-ion cell chemistries.

Baldwin, Richard S.

Space and Ground Trades for Human Exploration and Wearable Computing

Human exploration of the Moon and Mars will present unique trade study challenges as ground system elements shift to planetary bodies and perhaps eventually to the bodies of human explorers in the form of wearable computing technologies. This presentation will highlight some of the key space and ground trade issues that will face the Exploration Initiative as NASA begins designing systems for the sustained human exploration of the Moon and Mars, with an emphasis on wearable computing. We will present some preliminary test results and scenarios that demonstrate how wearable computing might affect the trade space noted below. We will first present some background on wearable computing and its utility to NASA's Exploration Initiative. Next, we will discuss three broad architectural themes, some key ground and space trade issues within those themes and how they relate to wearable computing. Lastly, we will present some preliminary test results and suggest guidance for proceeding in the assessment and creation of a value-added role for wearable computing in the Exploration Initiative. The three broad ground-space architectural trade themes we will discuss are: 1. Functional Shift and Distribution: To what extent, if any, should traditional ground system functionality be shifted to, and distributed among, the Earth, Moon/Mars, and the human. explorer? 2. Situational Awareness and Autonomy: How much situational awareness (e.g. environmental conditions, biometrics, etc.) and autonomy is required and desired, and where should these capabilities reside? 3. Functional Redundancy: What functions (e.g. command, control, analysis) should exist simultaneously on Earth, the Moon/Mars, and the human explorer? These three themes can serve as the axes of a three-dimensional trade space, within which architectural solutions reside. We will show how wearable computers can fit into this trade space and what the possible implications could be for the rest of the ground and space architecture(s). We intend this to be an example of explorer-centric thinking in a fully integrated explorer paradigm, where integrated explorer refers to a human explorer having instant access to all relevant data, knowledge of the environment, science models, health and safety-related events, and other tools and information via wearable computing technologies. The trade study approach will include involvement from the relevant stakeholders (Constellation Systems, CCCI, EVA Project Office, Astronaut office, Mission Operations, Space Life Sciences, etc.) to develop operations concepts (and/or operations scenarios) from which a basic high-level set of requirements could be extracted. This set of requirements could serve as a foundation (along with stakeholder buy-in) that would help define the trade space and assist in identifying candidate technologies for further study and evolution to higher-level technology readiness levels.

Lupisella, Mark

Nuclear Data Impact Assessment for the HTR-10 Pebble-Bed Reactor Using SCALE

The HTR-10 was used as a representative pebble-bed high-temperature gas-cooled reactor in this assessment of nuclear data’s impact on important reactor and spent fuel metrics, including safety-related quantities such as the effective multiplication factor (k eff ), temperature reactivity feedback, spent fuel inventory, and decay heat. Using the SCALE code system tools and ENDF/B-VII.1 nuclear data libraries, we quantify the effect of nuclear data uncertainties on these key performance metrics for both fresh fuel and equilibrium core configurations. For reactor core key parameters, important contributors to uncertainty include reactions of 235 U [$\bar{v}$, fission, (n, γ)], 238 U [elastic, (n, γ)], and graphite [elastic, (n, γ)]. Additional important contributors for the equilibrium core include reactions of higher actinides ( 239 Pu, 240 Pu) and fission products ( 135 Xe, 149 Sm). For spent fuel analysis, most nuclide inventory uncertainties remain below 5%. Higher uncertainties up to 11% are being observed for minor actinides like 243 Am and 244 Cm. Additionally, fission product uncertainties in 155 Eu and 155 Gd, of 25% and 23% respectively, are also significant and have implications for burnup credit applications. 110m Ag also shows high uncertainty of up to 11%, mainly due to fission product yield uncertainties. Decay heat relative uncertainties remain below 0.6% up to 10 years’ cooling time after fuel discharge. The highest relative uncertainty of 1.5% occurs at 500 years of cooling; however, because the decay heat value is very low at that time, the absolute uncertainty is not significant. This work demonstrates that extending assessments beyond fresh fuel k eff to include irradiated cores, nuclide inventories, and decay heat is essential in understanding the behavior of uncertainties as a function of fuel burnup and can support improvements of safety margins and spent fuel management.

Nuclear data impact

Review of Reactor Facilities without Main Control Rooms

Small, advanced reactors may require few, if any, safety-related human actions (HAs) and fewer HAs to monitor and control the plant. In comparison to large light water reactors, these are significant changes that have implications for many aspects of an applicant's human factors engineering (HFE), including control room design, plant staffing, and the management of safety functions. To support the Nuclear Regulatory Commission's (NRC) ability to evaluate these changes, information needs to be developed addressing the characteristics and potential issues. The objectives of our research were to (1) identify when a traditional main control room (MCR) may not be necessary, (2) identify workplace design alternatives to traditional MCRs, and (3) develop guidance for reviewing an applicant's workplace designs with and without a MCR. We determined that the safety question isn't so much justifying why a design has no MCR, but rather verifying that important human actions can be accurately and reliably performed under a range of challenging conditions using the HSIs provided regardless of their location. We developed guidance to review alternatives to MCRs based on HFE analyses for determining workplace location and design.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Consideration of Decabromodiphenyl Ether Flame Retardant in Thermal and Radiation Aging of Crosslinked Polyethylene Cable Insulation

Decabromodiphenyl ether (decaBDE) has been used as a flame-retardant additive in nuclear-grade electrical cable insulation. However, decaBDE has been identified as a persistent, bioaccumulative and toxic (PBT) substance, leading to regulatory scrutiny. On January 6, 2021, the Environmental Protection Agency (EPA) published a final rule to phase out decaBDE. The 2021 rule set a two-year compliance deadline for “processing and distribution in commerce of decaBDE for use in wire and cable insulation in nuclear power generation facilities.” In recognition of industry concerns following a sudden discontinuation of decaBDE-containing Class 1E wire and cable essential for nuclear power operations and the time needed for qualifying the individual components using the alternative insulation technology, an extended compliance deadline was set in the finalized amendments to the 2021 rule as published by the Environmental Appeals Board on November 12, 2024. The 2024 rule set the compliance deadline for processing and distributing decaBDE-containing wire and cable insulation until the end of the service life of these materials. Since decaBDE has long been relied upon as the flame retardant in one of the most common cross-linked polyethylene (XLPE) nuclear cable insulation formulations, RSCC Firewall III insulation, questions have naturally arisen regarding whether changes in cable performance might be expected for XLPE containing a decaBDE alternative, especially for safety-related cables that must perform their safety function in a design basis event such as a loss of coolant accident.

22 GENERAL STUDIES OF NUCLEAR REACTORS

FY 1991 safety program status report

In FY 1991, the NASA Safety Division continued efforts to enhance the quality and productivity of its safety oversight function. Recent initiatives set forth in areas such as training, risk management, safety assurance, operational safety, and safety information systems have matured into viable programs contributing to the safety and success of activities throughout the Agency. Efforts continued to develop a centralized intra-agency safety training program with establishment of the NASA Safety Training Center at the Johnson Space Center (JSC). The objective is to provide quality training for NASA employees and contractors on a broad range of safety-related topics. Courses developed by the Training Center will be presented at various NASA locations to minimize travel and reach the greatest number of people at the least cost. In FY 1991, as part of the ongoing efforts to enhance the total quality of NASA's safety work force, the Safety Training Center initiated development of a Certified Safety Professional review course. This course provides a comprehensive review of the skills and knowledge that well-rounded safety professionals must possess to qualify for professional certification. FY 1992 will see the course presented to NASA and contractor employees at all installations via the NASA Video Teleconference System.

Source record

Aerospace Safety Advisory Panel

This report covers the activities of the Aerospace Safety Advisory Panel (ASAP) for calendar year 1998-a year of sharp contrasts and significant successes at NASA. The year opened with the announcement of large workforce cutbacks. The slip in the schedule for launching the International Space Station (ISS) created a five-month hiatus in Space Shuttle launches. This slack period ended with the successful and highly publicized launch of the STS-95 mission. As the year closed, ISS assembly began with the successful orbiting and joining of the Functional Cargo Block (FGB), Zarya, from Russia and the Unity Node from the United States. Throughout the year, the Panel maintained its scrutiny of NASA's safety processes. Of particular interest were the potential effects on safety of workforce reductions and the continued transition of functions to the Space Flight Operations Contractor. Attention was also given to the risk management plans of the Aero-Space Technology programs, including the X-33, X-34, and X-38. Overall, the Panel concluded that safety is well served for the present. The picture is not as clear for the future. Cutbacks have limited the depth of talent available. In many cases, technical specialties are 'one deep.' The extended hiring freeze has resulted in an older workforce that will inevitably suffer significant departures from retirements in the near future. The resulting 'brain drain' could represent a future safety risk unless appropriate succession planning is started expeditiously. This and other topics are covered in the section addressing workforce. The major NASA programs are also limited in their ability to plan property for the future. This is of particular concern for the Space Shuttle and ISS because these programs are scheduled to operate well into the next century. In the case of the Space Shuttle, beneficial and mandatory safety and operational upgrades are being delayed because of a lack of sufficient present funding. Likewise, the ISS has little flexibility to begin long lead-time items for upgrades or contingency planning. For example, the section on computer hardware and software contains specific findings related to required longer range safety-related actions. NASA can be proud of its accomplishments this past year, but must remain ever vigilant, particularly as ISS assembly begins to accelerate. The Panel will continue to focus on both the short- and long-term aspects of risk management and safety planning. This task continues to be made manageable and productive by the excellent cooperation the Panel receives from both NASA and its contractors. Particular emphasis will continue to be directed to longer term workforce and program planning issues as well as the immediate risks associated with ISS assembly and the initial flights of the X-33 and X-34. Section 2 of this report presents specific findings and recommendations generated by ASAP activities during 1998. Section 3 contains more detailed information in support of these findings and recommendations. Appendix A is a current roster of Panel members, consultants, and staff. Appendix B contains NASA's response to the findings and recommendations from the 1997 ASAP Annual Report. Appendix C details the fact-finding activities of the Panel in 1998. During the year, Mr. Richard D. Blomberg was elected chair of the Panel and Vice Admiral (VADM) Robert F Dunn was elected deputy chair. VADM Bernard M. Kauderer moved from consultant to member. Mr. Charles J. Donlan retired from the Panel after many years of meritorious service. Ms. Shirley C. McCarty and Mr. Robert L. ('Hoot') Gibson joined the Panel as consultants.

Source record

Unmanned Aircraft Systems (UAS) Integration in the National Airspace System (NAS) Project KDP-C Review

The topics discussed are the UAS-NAS project life-cycle and ARMD thrust flow down, as well as the UAS environments and how we operate in those environments. NASA's Armstrong Flight Research Center at Edwards, CA, is leading a project designed to help integrate unmanned air vehicles into the world around us. The Unmanned Aircraft Systems Integration in the National Airspace System project, or UAS in the NAS, will contribute capabilities designed to reduce technical barriers related to safety and operational challenges associated with enabling routine UAS access to the NAS. The project falls under the Integrated Systems Research Program office managed at NASA Headquarters by the agency's Aeronautics Research Mission Directorate. NASA's four aeronautics research centers - Armstrong, Ames Research Center, Langley Research Center, and Glenn Research Center - are part of the technology development project. With the use and diversity of unmanned aircraft growing rapidly, new uses for these vehicles are constantly being considered. Unmanned aircraft promise new ways of increasing efficiency, reducing costs, enhancing safety and saving lives 460265main_ED10-0132-16_full.jpg Unmanned aircraft systems such as NASA's Global Hawks (above) and Predator B named Ikhana (below), along with numerous other unmanned aircraft systems large and small, are the prime focus of the UAS in the NAS effort to integrate them into the national airspace. Credits: NASA Photos 710580main_ED07-0243-37_full.jpg The UAS in the NAS project envisions performance-based routine access to all segments of the national airspace for all unmanned aircraft system classes, once all safety-related and technical barriers are overcome. The project will provide critical data to such key stakeholders and customers as the Federal Aviation Administration and RTCA Special Committee 203 (formerly the Radio Technical Commission for Aeronautics) by conducting integrated, relevant system-level tests to adequately address safety and operational challenges of national airspace access by unmanned aircraft systems, or UAS. In the process, the project will work with other key stakeholders to define necessary deliverables and products to help enable such access. Within the project, NASA is focusing on five sub-projects. These five focus areas include assurance of safe separation of unmanned aircraft from manned aircraft when flying in the national airspace; safety-critical command and control systems and radio frequencies to enable safe operation of UAS; human factors issues for ground control stations; airworthiness certification standards for UAS avionics and integrated tests and evaluation designed to determine the viability of emerging UAS technology. Five Focus Areas of the UAS Integration in the NAS Project Separation Assurance Provide an assessment of how planned Next Generation Air Transportation System (NextGen) separation assurance systems, with different functional allocations, perform for UAS in mixed operations with manned aircraft Assess the applicability to UAS and the performance of NASA NextGen separation assurance systems in flight tests with realistic latencies and uncertain trajectories Assess functional allocations ranging from today's ground-based, controller-provided aircraft separation to fully autonomous airborne self-separation Communications Develop data and rationale to obtain appropriate frequency spectrum allocations to enable safe and efficient operation of UAS in the NAS Develop and validate candidate secure safety-critical command and control system/subsystem test equipment for UAS that complies with UAS international/national frequency regulations, standards and recommended practices and minimum operational and aviation system performance standards for UAS Perform analysis to support recommendations for integration of safety-critical command and control systems and air traffic control communications to ensure safe and efficient operation of UAS in the NAS Human Systems Integration Develop a research test bed and database to provide data and proof of concept for GCS - ground control station - operations in the NAS Coordinate with standards organizations to develop human-factors guidelines for GCS operation in the NAS Certification Define a UAS classification scheme and approach to determining Federal Aviation Regulation airworthiness requirements applicable to all UAS digital avionics Provide hazard and risk-related data to support development of type design criteria and best development practices Integrated Tests and Evaluation Integrate and test mature concepts from technical elements to demonstrate and test viability Evaluate the performance of technology development in a relevant environment (full-mission, human-in-the-loop simulations and flight tests)

outreach

NASA System-Wide Safety Wildland Firefighting Operations Workshop Report

On March 9-11, 2022, NASA’s System-Wide Safety Wildland Firefighting Operations Workshop engaged the broader wildland firefighting management ecosystem in a safety-oriented discussion via a virtual platform. This enabled a better understanding of how NASA and community expertise can be leveraged in the safe development of current and future firefighting systems and operations. The goals of the workshop were to: (1) identify and prioritize the top safety-oriented risks, gaps in capabilities, and emerging technologies to enhance wildland firefighting for both near-term and far-term concepts, with a specific focus on aviation operations and (2) engage the stakeholder community in defining emergent safety-oriented scope, roles, responsibilities, and procedures for agents undergoing increasingly complex wildland firefighting operations in information-rich, but uncertain environments. Workshop participants were solicited from wildland firefighting stakeholders across government, industry, and academia. All levels of government were engaged, as NASA sought attendees from federal, state, local, and tribal government agencies. Industry participants from traditional wildland firefighting domains such as data visualization and equipment manufacturers were invited, and corporate attendees from novel application domains such as aerial robotics and autonomous systems were present as well. The top three findings were as follows: (1) Enhancing situation awareness is a safety priority, especially in the use of aerial assets; (2) Timely access to information along with data fusion and integrated displays will enhance safety-critical decision-making both inside and outside aviation contexts; and (3) Tailorable standards and common operating pictures in the field will enhance inter-agency cooperation in the wildland firefighting lifecycle and enable the optimal use of limited resources such as aerial assets. The workshop helped inform NASA of the relevant safety-related wildland firefighting concerns and aided the broader ecosystem in understanding the potential safety-oriented role NASA might play in this community. Increased engagement with crucial governmental stakeholders (e.g., U.S. Forest Service, CAL FIRE, etc.) along with industry partners in cutting- edge information -centric domains is a fundamental next step. Additionally, the workshop findings will help define the first of a series of operationally challenging demonstrations, held in concert with strategic ecosystem partners, known as the Safety Demonstrator Series for NASA’s System-Wide Safety project. The first demonstration is set in the wildland firefighting application domain and will: (1) examine high risk operational scenarios to reduce their overall risk via services, functions or capabilities that act as risk mitigators (or transfer that risk to automated systems better able to tolerate it) and (2) explore novel tools and technologies that will enhance safety margins by enabling non-traditional or neoteric operational paradigms.

wildland firefighting