Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “criticality accident”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Manned space flight nuclear system safety. Volume 3: Reactor system preliminary nuclear safety analysis. Part 2: Accident Model Document (AMD)

The Accident Model Document is one of three documents of the Preliminary Safety Analysis Report (PSAR) - Reactor System as applied to a Space Base Program. Potential terrestrial nuclear hazards involving the zirconium hydride reactor-Brayton power module are identified for all phases of the Space Base program. The accidents/events that give rise to the hazards are defined and abort sequence trees are developed to determine the sequence of events leading to the hazard and the associated probabilities of occurence. Source terms are calculated to determine the magnitude of the hazards. The above data is used in the mission accident analysis to determine the most probable and significant accidents/events in each mission phase. The only significant hazards during the prelaunch and launch ascent phases of the mission are those which arise form criticality accidents. Fission product inventories during this time period were found to be very low due to very limited low power acceptance testing.

Source record↗

Potential Improvements to the Nuclear Safety and Launch Approval Process for Nuclear Reactors Utilized for Space Power and Propulsion Applications

This study examines potential improvements that could be made to the nuclear safety and launch approval process for fission reactors to reduce the associated uncertainties in cost and schedule while continuing to ensure public safety and environmental protection. It concentrates on the launch approval and mission safety of fission power and propulsion applications of nuclear energy. Improvements to the launch approval process for radioisotope power systems (RPSs) are being considered elsewhere but are acknowledged throughout the report. The study considered technical, process, and organizational improvements to the launch approval processes. The study exclusively evaluated reactors that would not be started up prior to achieving a “sufficiently high orbit,” per United Nations (UN) Resolution 47/68.Potential criticality accidents were considered that could occur during a launch failure or abort or during reentry. Numerous scenarios were examined that might involve one or more Earth flybys as well as potential transportation missions that could intentionally return an active, or previously active fission reactor to Earth orbit. The Study Group was guided in its deliberations according to a number of fundamental principles. These included the paramount importance of adequate and appropriate levels of public safety and environmental protection as well as the importance of the inclusion of independent scientific, engineering, and safety reviews of the applications and proposals as a critical part of the process. Also considered was the need for the development of launch approval processes that might be different, depending upon the source of the application for launch approval, whether it be derived as a governmental launch, a commercial launch, or a hybrid/combination of the two. It is clear that all launches of nuclear reactors into space should have similar safety requirements; however, the safety review effort and the details of the analysis that are required should be commensurate with the potential hazards and the actual risk, which may differ based on the reactor design and its intended purpose. Finally, the study aimed at ensuring that whatever processes and procedures are developed should maximize the sufficiency, simplicity, and transparency of the processes. The Study Group reached five Conclusions and makes thirteen Recommendations. The Conclusions and Recommendations presented here are extensions of those presented previously in other studies. This report attempts to add specificity to the actions that need to be taken in order to move forward with successful space fission reactor programs. Without action to address the perceived and real problems in the launch approval process, designers and mission managers will be reluctant to commit the resources necessary to make space fission reactors a reality.

Camp, Allen↗

Safety aspects of nuclear waste disposal in space

Safety issues involved in the disposal of nuclear wastes in space as a complement to mined geologic repositories are examined as part of an assessment of the feasibility of nuclear waste disposal in space. General safety guidelines for space disposal developed in the areas of radiation exposure and shielding, containment, accident environments, criticality, post-accident recovery, monitoring systems and isolation are presented for a nuclear waste disposal in space mission employing conventional space technology such as the Space Shuttle. The current reference concept under consideration by NASA and DOE is then examined in detail, with attention given to the waste source and mix, the waste form, waste processing and payload fabrication, shipping casks and ground transport vehicles, launch site operations and facilities, Shuttle-derived launch vehicle, orbit transfer vehicle, orbital operations and space destination, and the system safety aspects of the concept are discussed for each component. It is pointed out that future work remains in the development of an improved basis for the safety guidelines and the determination of the possible benefits and costs of the space disposal option for nuclear wastes.

Rice, E. E.↗

Applying STAMP in Accident Analysis

Accident models play a critical role in accident investigation and analysis. Most traditional models are based on an underlying chain of events. These models, however, have serious limitations when used for complex, socio-technical systems. Previously, Leveson proposed a new accident model (STAMP) based on system theory. In STAMP, the basic concept is not an event but a constraint. This paper shows how STAMP can be applied to accident analysis using three different views or models of the accident process and proposes a notation for describing this process.

Leveson, Nancy↗

Fault tree applications within the safety program of Idaho Nuclear Corporation

Computerized fault tree analyses are used to obtain both qualitative and quantitative information about the safety and reliability of an electrical control system that shuts the reactor down when certain safety criteria are exceeded, in the design of a nuclear plant protection system, and in an investigation of a backup emergency system for reactor shutdown. The fault tree yields the modes by which the system failure or accident will occur, the most critical failure or accident causing areas, detailed failure probabilities, and the response of safety or reliability to design modifications and maintenance schemes.

W. E. Vesely↗

Nuclear safety considerations for the design of a shuttle launched 500 to 2000 watt isotope Brayton power system.

An extensive study was conducted to evaluate the safety requirements for the design of a heat source assembly for use in a shuttle launched, isotope Brayton electric power system for the 500-W(e) to 2 kWe range. The assembly is a self-contained package which supplies heat to a power conversion system. A typical mission profile for a shuttle launched, earth orbital mission was assumed. Critical mission accidents were identified and evaluated to determine their impact upon the design of the Heat Source Assembly. Earth-orbital decay reentry analyses were performed to demonstrate survivability of the heat source. Safety design requirements were developed to ensure survivability under credible accident conditions including loss of the power conversion system in orbit.

Garate, J. A.↗

Anti-Criticality Methods for Nuclear Thermal Rocket Launches and Their Associated Assembly / Disassembly in Space

When launching a nuclear reactor into space for use in a nuclear thermal rocket (NTR), safety to the public is of the outmost importance. Ensuring that the reactor will not go critical in an accident scenario is the biggest risk that must be overcome to protect the public. Use of anti-criticality devices and methods, such as the use of poison materials in the core or loading a select portion of the fuel on orbit, can prevent the reactor from going critical in any accident scenario. However, both methods (unpoisoning / loading fuel into the reactor core on orbit) will likely require the use of In Space Assembly and Manufacturing (ISAM) technology to remove the safeguards and ensure the reactor is fully operational before use. This paper discusses the use of ISAMs to help with the unpackaging of anti-criticality devices on orbit along with ISAMs ability to help verify and preform maintenance and inspection checks of the reactor system before operation and in between engine burns.

nuclear thermal propulsion↗

Associations between errors and contributing factors in aircraft maintenance

In recent years cognitive error models have provided insights into the unsafe acts that lead to many accidents in safety-critical environments. Most models of accident causation are based on the notion that human errors occur in the context of contributing factors. However, there is a lack of published information on possible links between specific errors and contributing factors. A total of 619 safety occurrences involving aircraft maintenance were reported using a self-completed questionnaire. Of these occurrences, 96% were related to the actions of maintenance personnel. The types of errors that were involved, and the contributing factors associated with those actions, were determined. Each type of error was associated with a particular set of contributing factors and with specific occurrence outcomes. Among the associations were links between memory lapses and fatigue and between rule violations and time pressure. Potential applications of this research include assisting with the design of accident prevention strategies, the estimation of human error probabilities, and the monitoring of organizational safety performance.

Professional Competence↗

Reliability and Maintainability Engineering - A Major Driver for Safety and Affordability

The United States National Aeronautics and Space Administration (NASA) is in the midst of an effort to design and build a safe and affordable heavy lift vehicle to go to the moon and beyond. To achieve that, NASA is seeking more innovative and efficient approaches to reduce cost while maintaining an acceptable level of safety and mission success. One area that has the potential to contribute significantly to achieving NASA safety and affordability goals is Reliability and Maintainability (R&M) engineering. Inadequate reliability or failure of critical safety items may directly jeopardize the safety of the user(s) and result in a loss of life. Inadequate reliability of equipment may directly jeopardize mission success. Systems designed to be more reliable (fewer failures) and maintainable (fewer resources needed) can lower the total life cycle cost. The Department of Defense (DOD) and industry experience has shown that optimized and adequate levels of R&M are critical for achieving a high level of safety and mission success, and low sustainment cost. Also, lessons learned from the Space Shuttle program clearly demonstrated the importance of R&M engineering in designing and operating safe and affordable launch systems. The Challenger and Columbia accidents are examples of the severe impact of design unreliability and process induced failures on system safety and mission success. These accidents demonstrated the criticality of reliability engineering in understanding component failure mechanisms and integrated system failures across the system elements interfaces. Experience from the shuttle program also shows that insufficient Reliability, Maintainability, and Supportability (RMS) engineering analyses upfront in the design phase can significantly increase the sustainment cost and, thereby, the total life cycle cost. Emphasis on RMS during the design phase is critical for identifying the design features and characteristics needed for time efficient processing, improved operational availability, and optimized maintenance and logistic support infrastructure. This paper discusses the role of R&M in a program acquisition phase and the potential impact of R&M on safety, mission success, operational availability, and affordability. This includes discussion of the R&M elements that need to be addressed and the R&M analyses that need to be performed in order to support a safe and affordable system design. The paper also provides some lessons learned from the Space Shuttle program on the impact of R&M on safety and affordability.

Safie, Fayssal M.↗

Effects of circadian rhythm phase alteration on physiological and psychological variables: Implications to pilot performance (including a partially annotated bibliography)

The effects of environmental synchronizers upon circadian rhythmic stability in man and the deleterious alterations in performance and which result from changes in this stability are points of interest in a review of selected literature published between 1972 and 1980. A total of 2,084 references relevant to pilot performance and circadian phase alteration are cited and arranged in the following categories: (1) human performance, with focus on the effects of sleep loss or disturbance and fatigue; (2) phase shift in which ground based light/dark alteration and transmeridian flight studies are discussed; (3) shiftwork; (4)internal desynchronization which includes the effect of evironmental factors on rhythmic stability, and of rhythm disturbances on sleep and psychopathology; (5) chronotherapy, the application of methods to ameliorate desynchronization symptomatology; and (6) biorythm theory, in which the birthdate based biorythm method for predicting aircraft accident susceptability is critically analyzed. Annotations are provided for most citations.

Holley, D. C.↗

Risk-based Classification of Incidents

As the penetration of software into safety-critical systems progresses, accidents and incidents involving software will inevitably become more frequent. Identifying lessons from these occurrences and applying them to existing and future systems is essential if recurrences are to be prevented. Unfortunately, investigative agencies do not have the resources to fully investigate every incident under their jurisdictions and domains of expertise and thus must prioritize certain occurrences when allocating investigative resources. In the aviation community, most investigative agencies prioritize occurrences based on the severity of their associated losses, allocating more resources to accidents resulting in injury to passengers or extensive aircraft damage. We argue that this scheme is inappropriate because it undervalues incidents whose recurrence could have a high potential for loss while overvaluing fairly straightforward accidents involving accepted risks. We then suggest a new strategy for prioritizing occurrences based on the risk arising from incident recurrence.

Greenwell, William S.↗

Return to Flight Task Group

It has been 29 months since Columbia was lost over East Texas in February 2003. Seven months after the accident, the Columbia Accident Investigation Board (CAIB) released the first volume of its final report, citing a variety of technical, managerial, and cultural issues within NASA and the Space Shuttle Program. To their credit, NASA offered few excuses, embraced the report, and set about correcting the deficiencies noted by the accident board. Of the 29 recommendations issued by the CAIB, 15 were deemed critical enough that the accident board believed they should be implemented prior to returning the Space Shuttle to flight. Some of these recommendations were relatively easy, most were straightforward, a few bordered on the impossible, and others were largely overcome by events, particularly the decision by the President to retire the Space Shuttle by 2010. The Return to Flight Task Group (RTF TG, or simply, the Task Group) was chartered by the NASA Administrator in July 2003 to provide an independent assessment of the implementation of the 15 CAIB return-to-flight recommendations. An important observation must be stated up-front: neither the CAIB nor the RTF TG believes that all risk can be eliminated from Space Shuttle operations; nor do we believe that the Space Shuttle is inherently unsafe. What the CAIB and RTF TG do believe, however, is that NASA and the American public need to understand the risks associated with space travel, and that NASA must make every reasonable effort to minimize such risk. Since the release of the CAIB report, NASA and the Space Shuttle Program expended enormous effort and resources toward correcting the causes of the accident and preparing to fly again. Relative to the 15 specific recommendations that the CAIB indicated should be implemented prior to returning to flight, NASA has met or exceeded most of them the Task Group believes that NASA met the intent of the CAIB for 12 of these recommendations. The remaining three recommendations were so challenging that NASA could not comply completely with the intent of the CAIB.

Source record↗

An analysis of pilot error-related aircraft accidents

A multidisciplinary team approach to pilot error-related U.S. air carrier jet aircraft accident investigation records successfully reclaimed hidden human error information not shown in statistical studies. New analytic techniques were developed and applied to the data to discover and identify multiple elements of commonality and shared characteristics within this group of accidents. Three techniques of analysis were used: Critical element analysis, which demonstrated the importance of a subjective qualitative approach to raw accident data and surfaced information heretofore unavailable. Cluster analysis, which was an exploratory research tool that will lead to increased understanding and improved organization of facts, the discovery of new meaning in large data sets, and the generation of explanatory hypotheses. Pattern recognition, by which accidents can be categorized by pattern conformity after critical element identification by cluster analysis.

Kowalsky, N. B.↗

Stabilized Approach Criteria: Bridging the Gap Between Theory and Practice

Approach and landing is the most common phase of flight for aviation accidents, accounting annually for approximately 65 percent of all accidents. A Flight Safety Foundation study of 16 years of runway excursions determined that 83 percent could have been avoided with a decision to go around. In other words, 54 percent of all accidents could potentially be prevented by going around. A critical industry policy designed to help prevent such accidents is the go-around policy. However, the collective industry performance of complying with go-around policies is extremely poor and only about three percent of unstable approaches result in a go-around. Improving the go-around compliance rate holds tremendous potential in reducing approach and landing accidents. There are many reasons for flight crews ignoring go-around policies related to pilot judgement and company policies. Examples are the collective industry norm to accept the noncompliance of go-around policies, management being disengaged from go-around noncompliance, and pilot fatigue and lack of situational awareness. One of the biggest factors is that pilots see current stabilized-approach criteria as too complex and restrictive for the operational environment. Following the American Airlines 1420 accident (Little Rock, 1999), where the aircraft overran the runway upon landing and crashed, the National Transportation Safety Board (NTSB) recommended that the Federal Aviation Administration (FAA) define detailed parameters for a stabilized approach, and develop detailed criteria indicating when a go-around should be performed. The experiment discussed in this presentation is the first step towards developing these go-around criteria for commercial transport aircraft.

pilot performance↗

Safety Metrics for Human-Computer Controlled Systems

The rapid growth of computer technology and innovation has played a significant role in the rise of computer automation of human tasks in modem production systems across all industries. Although the rationale for automation has been to eliminate "human error" or to relieve humans from manual repetitive tasks, various computer-related hazards and accidents have emerged as a direct result of increased system complexity attributed to computer automation. The risk assessment techniques utilized for electromechanical systems are not suitable for today's software-intensive systems or complex human-computer controlled systems.This thesis will propose a new systemic model-based framework for analyzing risk in safety-critical systems where both computers and humans are controlling safety-critical functions. A new systems accident model will be developed based upon modem systems theory and human cognitive processes to better characterize system accidents, the role of human operators, and the influence of software in its direct control of significant system functions Better risk assessments will then be achievable through the application of this new framework to complex human-computer controlled systems.

Leveson, Nancy G↗

A Model-based Framework for Risk Assessment in Human-Computer Controlled Systems

The rapid growth of computer technology and innovation has played a significant role in the rise of computer automation of human tasks in modem production systems across all industries. Although the rationale for automation has been to eliminate "human error" or to relieve humans from manual repetitive tasks, various computer-related hazards and accidents have emerged as a direct result of increased system complexity attributed to computer automation. The risk assessment techniques utilized for electromechanical systems are not suitable for today's software-intensive systems or complex human-computer controlled systems. This thesis will propose a new systemic model-based framework for analyzing risk in safety-critical systems where both computers and humans are controlling safety-critical functions. A new systems accident model will be developed based upon modem systems theory and human cognitive processes to better characterize system accidents, the role of human operators, and the influence of software in its direct control of significant system functions. Better risk assessments will then be achievable through the application of this new framework to complex human-computer controlled systems.

Hatanaka, Iwao↗

A Historical Analysis of Crane Mishaps at Kennedy Space Center

Cranes and hoists are widely used in many areas. Crane accidents and handling mishaps are responsible for injuries, costly equipment damage, and program delays. Most crane accidents are caused by preventable factors. Understanding these factors is critical when designing cranes and preparing lift plans. Analysis of previous accidents provides insight into current recommendations for crane safety. Cranes and hoists are used throughout Kennedy Space Center to lift everything from machine components to critical flight hardware. Unless they are trained crane operators, most NASA employees and contractors do not need to undergo specialized crane training and may not understand the safety issues surrounding the use of cranes and hoists. A single accident with a crane or hoist can injure or kill people, cause severe equipment damage, and delay or terminate a program. Handling mishaps can also have a significant impact on the program. Simple mistakes like bouncing or jarring a load, or moving the crane down when it should go up, can damage fragile flight hardware and cause major delays in processing. Hazardous commodities (high pressure gas, hypergolic propellants, and solid rocket motors) can cause life safety concerns for the workers performing the lifting operations. Most crane accidents are preventable with the correct training and understanding of potential hazards. Designing the crane with human factors taken into account can prevent many accidents. Engineers are also responsible for preparing lift plans where understanding the safety issues can prevent or mitigate potential accidents. Cranes are widely used across many areas of KSC. Failure of these cranes often leads to injury, high damage costs, and significant delays in program objectives. Following a basic set of principles and procedures during design, fabrication, testing, regular use, and maintenance can significantly minimize many of these failures. As the accident analysis shows, load drops are often caused or influenced by human factors. Therefore, proper training and understanding of crane safety throughout the workforce is critical. It is important that the engineers designing the cranes, lift planners preparing the lift plans, operators performing the lifts, and training officers conducting the operator training all understand the problems that can happen with cranes and how to ensure the safety of the workforce and equipment being lifted.

Materials Handling↗

Reliability and Probabilistic Risk Assessment - How They Play Together

Since the Space Shuttle Challenger accident in 1986, NASA has extensively used probabilistic analysis methods to assess, understand, and communicate the risk of space launch vehicles. Probabilistic Risk Assessment (PRA), used in the nuclear industry, is one of the probabilistic analysis methods NASA utilizes to assess Loss of Mission (LOM) and Loss of Crew (LOC) risk for launch vehicles. PRA is a system scenario based risk assessment that uses a combination of fault trees, event trees, event sequence diagrams, and probability distributions to analyze the risk of a system, a process, or an activity. It is a process designed to answer three basic questions: 1) what can go wrong that would lead to loss or degraded performance (i.e., scenarios involving undesired consequences of interest), 2) how likely is it (probabilities), and 3) what is the severity of the degradation (consequences). Since the Challenger accident, PRA has been used in supporting decisions regarding safety upgrades for launch vehicles. Another area that was given a lot of emphasis at NASA after the Challenger accident is reliability engineering. Reliability engineering has been a critical design function at NASA since the early Apollo days. However, after the Challenger accident, quantitative reliability analysis and reliability predictions were given more scrutiny because of their importance in understanding failure mechanism and quantifying the probability of failure, which are key elements in resolving technical issues, performing design trades, and implementing design improvements. Although PRA and reliability are both probabilistic in nature and, in some cases, use the same tools, they are two different activities. Specifically, reliability engineering is a broad design discipline that deals with loss of function and helps understand failure mechanism and improve component and system design. PRA is a system scenario based risk assessment process intended to assess the risk scenarios that could lead to a major/top undesirable system event, and to identify those scenarios that are high-risk drivers. PRA output is critical to support risk informed decisions concerning system design. This paper describes the PRA process and the reliability engineering discipline in detail. It discusses their differences and similarities and how they work together as complementary analyses to support the design and risk assessment processes. Lessons learned, applications, and case studies in both areas are also discussed in the paper to demonstrate and explain these differences and similarities.

Safie, Fayssal↗