Engineering PapersSearch

SEARCH · Engineering Papers

Results for “resiliency”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Resilient Propulsion Control Research for the NASA Integrated Resilient Aircraft Control (IRAC) Project

Gas turbine engines are designed to provide sufficient safety margins to guarantee robust operation with an exceptionally long life. However, engine performance requirements may be drastically altered during abnormal flight conditions or emergency maneuvers. In some situations, the conservative design of the engine control system may not be in the best interest of overall aircraft safety; it may be advantageous to "sacrifice" the engine to "save" the aircraft. Motivated by this opportunity, the NASA Aviation Safety Program is conducting resilient propulsion research aimed at developing adaptive engine control methodologies to operate the engine beyond the normal domain for emergency operations to maximize the possibility of safely landing the damaged aircraft. Previous research studies and field incident reports show that the propulsion system can be an effective tool to help control and eventually land a damaged aircraft. Building upon the flight-proven Propulsion Controlled Aircraft (PCA) experience, this area of research will focus on how engine control systems can improve aircraft safe-landing probabilities under adverse conditions. This paper describes the proposed research topics in Engine System Requirements, Engine Modeling and Simulation, Engine Enhancement Research, Operational Risk Analysis and Modeling, and Integrated Flight and Propulsion Controller Designs that support the overall goal.

Guo, Ten-Huei

Foundational Concepts in Simulation-Based Resilience Analysis and Design

Resilience is a topic of increasing interest–with ever-present calls from policymakers to increase the resilience of complex systems and infrastructure. However, resilience as a concept can be confusing, because of a lack of a common unified definition and frame of reference. Sometimes it can appear as if resilience analysis is merely duplicating other, more mature fields such as safety, reliability, or risk, while other times it seems as if resilience is providing an “alternative” view with limited rigor. To better understand the resilience concept (and its relation to the broader field of risk management), this paper will present the perspective of simulation-based resilience analysis and design, including some of the foundational precepts and resultant concepts defining the resilience concept. It will further present the motivation for using simulation to understand resilience and highlight some ongoing work and research challenges in this area. From this frame of reference, one can better understand the field of resilience, including how different aspects and definitions of resilience relate to each other, and how resilience relates to broader design considerations and practices.

resilience

Foundational Concepts in Simulation-Based Resilience Analysis and Design

Resilience is a topic of increasing interest–with ever-present calls from policymakers to increase the resilience of complex systems and infrastructure. However, resilience as a concept can be confusing, because of a lack of a common unified definition and frame of reference. Sometimes it can appear as if resilience analysis is merely duplicating other, more mature fields such as safety, reliability, or risk, while other times it seems as if resilience is providing an “alternative” view with limited rigor. To better understand the resilience concept (and its relation to the broader field of risk management), this paper will present the perspective of simulation-based resilience analysis and design, including some of the foundational precepts and resultant concepts defining the resilience concept. It will further present the motivation for using simulation to understand resilience and highlight some ongoing work and research challenges in this area. From this frame of reference, one can better understand the field of resilience, including how different aspects and definitions of resilience relate to each other, and how resilience relates to broader design considerations and practices.

resilience

Understanding Resilience Optimization Architectures With an Optimization Problem Repository

Optimizing a system’s resilience can be challenging, especially when it involves considering both the inherent resilience of a robust design and the active resilience of a health management system to a set of computationally-expensive hazard simulations. While prior work has developed specialized architectures to effectively and efficiently solve combined design and resilience optimization problems, the comparison of these architectures has been limited to a single case study. To further study resilience optimization formulations, this work develops a problem repository which includes previously-developed resilience optimization problems and additional problems presented in this work: a notional system resilience model, a pandemic response model, and a cooling tank hazard prevention model. This work then uses models in the repository at large to understand the characteristics of resilience optimization problems and study the applicability of optimization architectures and decomposition strategies. Based on the comparisons in the repository, applying an optimization architecture effectively requires understanding the alignment and coupling relationships between the design and resilience models, as well as the efficiency characteristics of the algorithms. While alignment determines the necessity of a surrogate of resilience cost in the upper-level design problem, coupling determines the overall applicability of a sequential, alternating, or bilevel structure. Additionally, the application of decomposition strategies is dependent on there being limited interactions between variable sets, which often does not hold when a resilience policy is parameterized in terms of actions to take in hazardous model states rather than specific given scenarios.

Resilience

Going beyond reliability to robustness and resilience in space systems

The words reliability, robustness, and resilience, are often used interchangeably to describe tough and dependable systems but the distinctions between them suggest how to design more serviceable space systems. Reliability is simply the quality of consistently performing well. A system that dependably meets its design requirements in the specified environments is reliable. The designers may not consider themselves responsible for failures under unanticipated conditions. Robustness is the capability of performing without failure under a wide range of conditions, which can go beyond the expected range to include possible off-nominal conditions. Resilience is the ability to recover from or adapt to damaging events, such as failures, accidents, external disruptions, and repurposing. Such changes are usually unanticipated. They often invalidate the usual operating assumptions and cause system failure. Reliability, robustness, and resilience describe dependable performance under increasingly difficult conditions, first the specified environment, then a wider possible environment, and finally unanticipated damaging events. These three are increasingly desirable and increasingly difficult to achieve. Engineering for resilience would design systems that can ignore or repair failures, survive accidents, and recover from disruptions. Increasing the resilience of space systems, the ability to perform after unanticipated events, would greatly increase space crew safety. Improving reliability and robustness can be done by dealing with known sources of problems, but improving resilience requires implementing a general approach to reducing the impact of unknown future events. Two contrasting approaches are reducing system complexity and adding supervisory control. The need for resilience has been claimed for decades but little has been accomplished. Systems designers assume that they understand requirements, technologies, designs, architectures, integration, testing, operations, and environments. The potential problems of changes, failures, accidents, unknown environments, and unknown unknowns are ignored. Systems designers are typically overconfident and ignore the need for robustness and resilience.

Harry W Jones

Going Beyond Reliability to Robustness and Resilience in Space Life Support Systems

The words reliability, robustness, and resilience are often used interchangeably to describe tough and dependable systems but the distinctions between them suggest how to design more serviceable space systems. Reliability is simply the quality of consistently performing well. A system that dependably meets its design requirements in the specified environment is reliable. The designers may not consider themselves responsible for failures under unanticipated conditions. Robustness is the capability of performing without failure under a wide range of conditions, which can go beyond the expected range to include possible off-nominal conditions. Resilience is the ability to recover from or adapt to unanticipated damaging events, such as failures, accidents, external disruptions, and repurposing. Such changes can invalidate the usual operating assumptions and cause system failure. Reliability, robustness, and resilience describe dependable performance under increasingly difficult conditions, first the specified environment, then a wider possible environment, and finally unanticipated damaging conditions. These three qualities are increasingly desirable and increasingly difficult to achieve. Engineering for resilience would design systems that can ignore or repair failures, survive accidents, and recover from unanticipated disruptions. Increasing the resilience of space systems would greatly increase space crew safety. Improving reliability and robustness requires dealing with known problems, but improving resilience requires implementing a general approach to reducing the impact of unknown future events. The need for robustness and resilience has been stated for decades but little has been done. Systems designers often assume that they understand everything they need to know. The potential failures caused by changes, failures, accidents, unknown environments, and unknown unknowns can be ignored. Such overconfidence can lead to neglect of reliability, robustness, and resilience.

Harry W. Jones

Going Beyond Reliability to Robustness and Resilience in Space Life Support Systems

The words reliability, robustness, and resilience are often used interchangeably to describe tough and dependable systems but the distinctions between them suggest how to design more serviceable space systems. Reliability is simply the quality of consistently performing well. A system that dependably meets its design requirements in the specified environment is reliable. The designers may not consider themselves responsible for failures under unanticipated conditions. Robustness is the capability of performing without failure under a wide range of conditions, which can go beyond the expected range to include possible off-nominal conditions. Resilience is the ability to recover from or adapt to unanticipated damaging events, such as failures, accidents, external disruptions, and repurposing. Such changes can invalidate the usual operating assumptions and cause system failure. Reliability, robustness, and resilience describe dependable performance under increasingly difficult conditions, first the specified environment, then a wider possible environment, and finally unanticipated damaging conditions. These three qualities are increasingly desirable and increasingly difficult to achieve. Engineering for resilience would design systems that can ignore or repair failures, survive accidents, and recover from unanticipated disruptions. Increasing the resilience of space systems would greatly increase space crew safety. Improving reliability and robustness requires dealing with known problems, but improving resilience requires implementing a general approach to reducing the impact of unknown future events. The need for robustness and resilience has been stated for decades but little has been done. Systems designers often assume that they understand everything they need to know. The potential failures caused by changes, failures, accidents, unknown environments, and unknown unknowns can be ignored. Such overconfidence can lead to neglect of reliability, robustness, and resilience.

Harry W. Jones

Resiliency in Future Cislunar Space Architectures

This work introduces and explores the concept of resiliency as it relates to future cislunar space architectures by 1) citing examples of its growing demand across government; 2) describing potential characteristics of resilient systems; 3) introducing a framework for evaluating the linkages between resilient capabilities and visions for future cislunar architectures; and 4) exercising the framework to identify and evaluate resiliency-enabling technical capabilities for cislunar space architectures. We assert that resiliency can emerge from a layered approach of deliberately chosen capabilities with overlap and flexibility that, in aggerate, result in a resilient system. The challenge is to identify capabilities that contribute to resiliency and to accurately characterize their value. Resiliency is discussed through the lens of future architecture planning, outlining how the National Aeronautics and Space Administration (NASA) can benefit from a shift in approach when transitioning focus to the cislunar environment.

Jason Hay

Using Degradation Modeling to Identify Fragile Operational Conditions in Human- and Component-driven Resilience Assessment

Studying failure events shows that many high-impact events result from the complex interactions between precipitating failure events and degraded operational conditions. Often, when a system is put in operations, unforeseen practical realities (e.g., maintenance and/or workforce availability) lead the system to be operated in configurations outside its envisioned nominal range. However, design-time failure models often assume that the failure events are initiated in an idealized, nominal state of system operation, resulting in an incomplete assessment of future risk. To solve this, this paper develops a framework to consider degraded operational performance in scenario-based resilience models which uses a corresponding model of performance degradation to determine the values of deteriorated model parameters in the resilience model. This framework is demonstrated on a remotely-piloted rover to determine the (individual and combined) effect of drive-train wear and operator fatigue on the resilience of the rover to drive-train faults. This demonstration showed the substantial impact that degradation has on resilience, highlighting the need to account for degradation in resilience models–specifically, unconsidered degradation can lead to overestimates of resilience (and thus underestimates of safety margin) and because resilience can degrade prior to visible unreliability, which can lead to an operational environment with a high propensity for high-impact unforeseen failure events.

resilience

Using Degradation Modeling to Identify Fragile Operational Conditions in Human- and Component-driven Resilience Assessment

Studying failure events shows that many high-impact events result from the complex interactions between precipitating failure events and degraded operational conditions. Often, when a system is put in operations, unforeseen practical realities (e.g., maintenance and/or workforce availability) lead the system to be operated in configurations outside its envisioned nominal range. However, design-time failure models often assume that the failure events are initiated in an idealized, nominal state of system operation, resulting in an incomplete assessment of future risk. To solve this, this paper develops a framework to consider degraded operational performance in scenario-based resilience models which uses a corresponding model of performance degradation to determine the values of deteriorated model parameters in the resilience model. This framework is demonstrated on a remotely-piloted rover to determine the (individual and combined) effect of drive-train wear and operator fatigue on the resilience of the rover to drive-train faults. This demonstration showed the substantial impact that degradation has on resilience, highlighting the need to account for degradation in resilience models--specifically, unconsidered degradation can lead to overestimates of resilience (and thus underestimates of safety margin) and because resilience can degrade prior to visible unreliability, which can lead to an operational environment with a high propensity for high-impact unforeseen failure events.

Daniel Hulse

Resilience Modeling in Complex Engineered Systems with Human-Machine Interactions

In recent times, there has been a growing interest in resilience-based design. Resilience-based design operates on the concept that failures and unexpected events will happen, and when they occur, complex engineered systems should be able to operate within acceptable bounds and recover reasonably. Humans can contribute to the resilience of a system by quickly detecting unforeseen events and taking corrective measures. To this effect, researchers have proposed guidelines and design approaches that can help promote human-system resilience. However, there is no early design stage tool to validate if a system is indeed resilient after applying these guidelines and design methods. In this research, we integrate the Human Error and Functional Failure Reasoning (HEFFR) framework into the fmdtools toolkit to enable designers to model the combined (machine, human, and joint) failures, including their propagation and dynamic effects, during early design stages. This integrated tool also allows designers to model the effects of performance shaping factors, team dynamics, and human-machine interactions in systems of systems. A demonstrative example of a remotely operated rover is explored to demonstrate how this approach can be applied to understand resilience in complex engineered systems with human interactions.

Lukman Irshad

Resiliency in Future Cislunar Space Architectures

Resiliency is an aspirational metric, and it is a common goal for complex systems – be they engineered space architectures, geopolitical networks, or the human immune system. However, despite the ubiquitous desire for resiliency, the concept is surprisingly difficult to define and apply to future planning efforts. We assert that resiliency can emerge from a layered approach of deliberately chosen capabilities with overlap and flexibility that, in aggregate, result in a resilient system. The challenge is to identify capabilities that contribute to resiliency and to accurately characterize their value. Resiliency is discussed through the lens of future architecture planning, outlining how the National Aeronautics and Space Administration (NASA) can benefit from a shift in approach when transitioning focus to the cislunar environment.

Jason Hay

The System Modeling and Analysis of Resiliency in STEReO (SMARt-STEReO)

Wildfire emergency response has remained rooted in relatively low-tech solutions for coordination between ground and aerial assets. These low-tech solutions are robust for the remote environments in which wildfires are usually fought, but limit strategic cross-organizational support and the ability to deploy and effectively utilize aerial assets. As aircraft become more advanced and new technology, including drones, become available to firefighters, a new, more modern method of asset coordination is needed. NASA is working on a project called ‘Scalable Traffic Management for Emergency Response Operations’ (STEReO) to integrate unmanned aerial systems (UAS)and UAS traffic management (UTM)into wildfire response. STEReO’s goals include simplifying the coordination of aerial assets, improving the existing UAS framework, and increasing the role of additional autonomous systems to reduce human risk and to increase system resilience. This paper describes the development of the ‘System Modeling and Analysis of Resiliency in STEReO’ (SMARt-STEReO) project, which aims to model wildfire response and to quantify the additional system resilience that STEReO technology provides firefighters. This paper verifies SMARt-STEReO and defines its scope; it includes experimental and statistical analysis of the impact that the addition of UAS has on both performance metrics and also on performance resiliency response to a given fault. SMARt-STEReO is a grid-based model of fire propagation that incorporates varying crew responses. Through the use of a Python package called ‘fmdtools’, the model easily allows for the addition of faults to the system. These faults allow analysts to investigate various response parameters. Factors including terrain, fuel type and wind speed can be modified to affect the fire propagation; additionally, the number of ground crews, engines, fixed wing aircraft, helicopters, and UAS can be changed to affect the crew response. The communication lines between actors mimic those used in real life situations. This paper explains the development of SMARt-STEReO including background research, verification and validation, and preliminary experimental analysis of system resilience to both a minor and major fault in systems with and without UAS.

Resiliency

Resilience Engineering's Potential for Advanced Air Mobility (AAM)

The national airspace (NAS) will rapidly evolve in the next ten to twenty years. Plans for Advanced Air Mobility (AAM) during that period envision highly automated airspace management systems and electrically powered vehicles. AAM concepts also anticipate limited human roles. The goal of limiting the human role is to minimize the potential for misadventures, yet how the human role is limited needs to be carefully considered in order to also preserve the potential for human successes. The field of resilience engineering (RE) focuses on how systems can change in order to seize an opportunity or withstand an unforeseen challenge. RE methods rely on the use of empirical data to optimize the ability of any system to adapt. RE studies have shown how individual and team initiatives ensure resilient system performance by creating safety through flexibility. Benefits of the RE approach include improved awareness of operational circumstances and how system elements depend on each other, and the ability to allocate limited resources and prepare for surprise. RE offers the ability to account for and incorporate the human role as an essential element in order to ensure NAS systems’ resilient performance. Data on the human contribution to safe and resilient system performance, which is termed “work as done,” are available but are not being considered as the NAS evolves. We present an approach that describes how use of RE can enable the evolving NAS to adapt, and perform, in a resilient manner.

Aviation Safety

Strategies for Identifying Resilient Behavior In Aviation

When we imagine a situation where people fly aircraft and nothing scary happens, we assume it is the system that affords this phenomenon. That is, the overall design is the cause of the success. However, this is not always true. There are many examples of how the presence of a human in the system is the reason for a successful outcome, despite flaws in the system’s design. This resilient behavior is often overlooked and challenging to characterize. In an attempt to identify this phenomenon in a generalizable way, we named and investigated two strategies, as well as identification methods, that exemplify resilient performance: 1) controls; and 2) modifications. First, controls are resilient actions in situations known to be problematic. To capture this, instead of looking at the examples of how the problem became a reality, we look at the examples of how the problem was successfully avoided or controlled. For example, a country road may have a hairpin turn where a higher-than-normal rate of accidents occur. Given that there is a likely system flaw identified, we would look at how the successful drivers navigated the turn. This can be accomplished using current safety reporting systems. Second, modifications are augmentations or changes that people create to fill in the gap between work-as-imagined and work-as-done. This type of resilient performance is directly related to poor design. In aviation, work-as-imagined is often scripted explicitly, so it can be compared to work-as-done through the use of examining system-generated data as well as narrative reports written by the system operators. These two approaches aim to identify resilient human actions to better understand how current systems function, as well as how people contribute to successes that were otherwise unknown.

human factors

Resilient Braided Rope Seal

A resilient braided rope seal for use in high temperature applications. The resilient braided rope seal includes a center core of fibers, a resilient 5 member overbraided by at least one layer of braided sheath fibers tightly packed together. The resilient member adds significant stiffness to the seal while maintaining resiliency. Furthermore, the seal permanent set and hysteresis are greatly reduced. Finally, improved load capabilities are provided.

Steinetz, Bruce M.