Engineering PapersSearch

SEARCH · Engineering Papers

Results for “safety assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Survey of Methods for Assessing Safety Compliance of sUAS BVLOS Operations

To ensure the safety of small Unmanned Aircraft System (sUAS) Beyond Line of Sight (BVLOS) operations in the National Airspace System (NAS), the FAA offers a guideline on how sUAS operators can demonstrate compliance with FAA rules, including regulations, advisory circulars, policy statements, and acceptable means of compliance (AMOC), using a formal and top-down approach. According to FAA Advisory Circular 23.2010-1, the AMOC refers to “one method, but not the only method, to show compliance with a regulatory requirement.” It is common for regulations to include a performance and safety standard rather than a detailed design or operation requirement, which allows for flexibility in fulfilling the regulatory requirements while still achieving a predetermined level of safety. This technical report explores existing frameworks for sUAS BVLOS safety analysis. It begins by discussing how sUAS BVLOS operations can be strategically deconflicted and then discusses their hazards. The next step is to establish safety assessment methods commonly used by the aviation industry and the FAA, illustrate how these methods can be applied to several safety-critical air traffic systems, and list collision models that the FAA and industry use. This investigation documents the processes for assessing safety risks in sUAS BVLOS operations and will allow sUAS BVLOS operations to be assessed for safety compliance more efficiently.

sUAS BVLOS Operations

A computer-based Safety Assessment for Flight Evacuation - SAFE

The Safety Assessment for Flight Evacuation (SAFE) system has been developed for the computerized evaluation of safety in civil Emergency Medical Service (EMS) operations. The speed of the microprocessor used to analyze data allows many individual factors to be considered, as well as the interactions among those factors. SAFE's data base is structured as if-then conditional statements. SAFE also allows the most important of the factors to be given greater weight in the final score. The questionnaire filled by EMS crews encompassed mission-, crew-, organization-, environment-, and aircraft-related factors; each of these was subdivided into as many as eight variables affecting the EMS-mission risk of that factor.

Shively, Robert J.

Mars Sample Return: Risk Management & Sample Safety Assessment

Returning samples from Mars has long been a major planetary science objective due to the high scientific value and transformative potential of the resulting data. An exciting dimension of this objective is the potential for the detection of ancient microbiological life, and the possibility of improving our understanding of the evolution of habitable environments on Mars and the development of life on Earth. To ensure that returned samples meet stringent planetary protection requirements and do not expose Earth to potential biohazards, the joint NASA/ESA Sample Receiving Project (SRP) assembled the Sample Safety Assessment Protocol Tiger Team (SSAP-TT). Members were recruited with the specific goal of creating a multi-disciplinary and internationally distributed team of experts in their respective fields across the federal government, academia, and private industry. This team was chartered with reassessing previous sample safety assessment strategies, defining what constitutes a biological hazard, developing a protocol to test for potential biohazards, and establishing a statistical framework to determine if samples are “safe” for release. The team developed a three-step protocol, supported by a Bayesian statistical framework, to assess whether returned samples contain potential biohazards that could present a risk to Earth’s biosphere. Initial conclusions indicated that an effective and comprehensive safety assessment protocol is feasible using modern techniques and does not require an excessive amount of sample consumption or traditional microbiological detection methodology. Herein, we will present an overview of the MSR SRP, the proposed safety assessment protocol, and how aspects of this novel approach can be applied to biological assessment in healthcare product manufacturing practices.

Alvin L Smith

Safety Assessment of a Machine Learning-Based Aircraft Emergency Braking System: A Case Study

Machine Learning (ML) is revolutionizing many technological fields, but its use in aviation remains restricted due to stringent certification requirements. Efforts by the aviation community to establish standards for certifying ML-based systems are progressing, yet challenges persist, particularly with safety assessment methods for ML-based systems. This research addresses these challenges through a case study of an autonomous emergency braking system utilizing a computer vision deep neural network (DNN). We demonstrate a safety assessment process tailored to ML-specific concerns, such as low integrity and performance variability in quantitative safety analysis. This study can serve as an illustrative example to facilitate the discussion and convergence on certification aspects for ML-based systems within the aviation community.

Safety certification

Some thoughts about system safety assessment and its current application in aerospace

The various issues and requirements which must be considered during the actual work of safety assessment are discussed. The task and its objectives are considered and the importance of presentation is stressed, so that problems and their solution are displayed adequately to the many disciplines involved. The definition of areas of influence to which the requirements can be applied, and safety objectives derived, is also discussed. Emphasis is placed on the need to determine and set out safety objectives with precision so that the analysis is not complicated with occurrences which are not relevant to safety.

Peter R. Allison

Terrain Safety Assessment in Support of the Mars Science Laboratory Mission

In August 2012, the Mars Science Laboratory (MSL) mission will pioneer the next generation of robotic Entry, Descent, and Landing (EDL) systems by delivering the largest and most capable rover to date to the surface of Mars. The process to select the MSL landing site took over five years and began with over 50 initial candidate sites from which four finalist sites were chosen. The four finalist sites were examined in detail to assess overall science merit, EDL safety, and rover traversability on the surface. Ultimately, the engineering assessments demonstrated a high level of safety and robustness at all four finalist sites and differences in the assessment across those sites were small enough that neither EDL safety nor rover traversability considerations could significantly discriminate among the final four sites. Thus the MSL landing site at Gale Crater was selected from among the four finalists primarily on the basis of science considerations.

Kipp, Devin

In-Time Safety Assessment & Risk Prediction for Unmanned Aerial Systems

One of the critical challenges in emerging autonomous systems is timely mitigation of hazards encountered during operation which may not be known or accounted for at the time of design. Efficient execution of unmanned systems therefore demands a paradigm shift from scheduled periodic maintenance to predictive risk analysis that includes condition-based-monitoring, real-time reliability assessment and hazard mitigation. Particularly, the state-of-health parameters needs to be computed at the component level, unit level as well as the integrated system level. While in the former two levels, the physics of health propagation may be based on underlying electro-mechanical properties, system level prognostics often relies on data-driven models. Further, uncertainty from model, measurements and input sources should be accurately quantified to generate meaningful prediction results that can be fed into reliable decision making processes. Finally, the expected risk and time to failure has to be computed based on the current state-of-health of the overall system. This talk presents a conceptual design of such an in-time safety assurance approach for unmanned aerial vehicles (UAV) operating at low altitudes near and over populated areas. Typical in-flight hazard incidents include unplanned detour, proximity to obstacles, mid-flight component faults, limited battery life and poor quality of GPS measurements. Safety assessment therefore comprises trajectory generation and re-plan, battery RUL computation, distributed fault diagnostics and uncertainty management of predicted trajectory based on GPS measurement noise. The entire monitoring framework will be demonstrated on simulated as well as real UAV flight experiments conducted at the NASA Langley Research Center. This tutorial will therefore guide the audience through a step-by-step tracking of an autonomous system with focus on in-time risk prediction in the presence of unforeseen hazards and uncertain environment.

diagnostics

EDL Simulation Results for the Mars 2020 Landing Site Safety Assessment

The Mars 2020 rover is NASA’s next flagship mission, set to explore Mars in search of scientific evidence of past microbial life. Importantly, the rover will also, for the first time, have the ability to collect and cache rock and soil samples for retrieval and return to laboratories here on Earth. A key step in the development of the Mars 2020 mission is the selection of a suitable landing site with the largest likelihood of meeting scientific goals. This decision is a complex and critical one that requires close interaction between the scientific and engineering communities. The chosen landing site must be both scientifically interesting — providing the project with the greatest possible chance of gathering credible and defendable scientific evidence — and also safe enough to attempt a landing in the first place. Thus, arguably one of the most important undertakings of the Entry, Descent, and Landing (EDL) team, is to effectively enumerate, quantify, and communicate the landing risks to all of the stakeholders. The culmination of this effort is the Landing Site Safety Assessment, which is a review commissioned by the project, presided over by the EDL Standing Review Board, and attended by management and science stakeholders, in which the EDL team communicates their assessment of the associated landing risks and the statistical probability of a successful landing at each of the final candidate landing sites. This paper summarizes the results of high-fidelity computer simulations of the Mars 2020 EDL sequence used in this assessment. From an EDL performance perspective, all four candidates offer similar level of robustness, which is in-family with Mars Science Laboratory (MSL). However, two new features of the Mars 2020 EDL sequence – range trigger and Terrain-Relative Navigation (TRN) – dramatically enhance the capability of the EDL system to safely land at landing sites with much more rugged terrain than ever before considered. This has allowed the landing site selection for Mars 2020 to proceed in a manner that has been unprecedentedly weighted more heavily toward scientific interest and less heavily on engineering constraints. With TRN, the overall probability of success is predicted to be approximately 99% for all of the candidates.

David Way

Reliability and Safety Assessment of Urban Air Mobility Concept Vehicles

The following work was commissioned by the National Aeronautics and Space Administration (NASA) to guide industry and future regulation related to urban air mobility (UAM). Prior studies compared the relative safety of NASA concept vehicles, Figure ES1, designed for UAM and provided recommendations for industry research, aircraft architectural improvements, and regulatory updates. After the prior study completed, the European Aviation Safety Agency (EASA) released regulatory guidance in the form of a special condition (SC), SC-VTOL-01, for multirotors with distributed propulsion and flight controls (DPFC). The objective of the current work was to develop DPFC architectures that will comply with SC-VTOL-01. Vehicle designs, DPFC architectures, and stability & control (S&C) models were developed to find limitations and trends to guide industry. To guide this task, NASA developed quad, hex, and an octorotor to better define vehicle attributes and trade space. Aircraft for study included electric, hybrid-electric, and turboshaft powerplants and collective and RPM control schemes. Assessments are in terms of the safety level achieved, and/or aircraft component/features needed to meet SC-VTOL-01. The most challenging criteria being the catastrophic failure rate, ≤10-9 catastrophic failures per flight hour, and that no single failures may result in a catastrophic event. A disciplined process was followed, similar to that in Aerospace Recommended Practice (ARP) 4761. A preliminary system safety assessment (PSSA) leveraged prior work as a basis of creating failure rate budgets for system design teams. System designs were updated and iterated upon, working with reliability and safety subject matter experts to develop SC-VTOL-01 compliant designs. Design changes were reflected in updated PSSAs for initial verification of compliance. The DPFC architecture was broken into four system design teams, the (1) flight control system (FCS), (2) drive and power system, (3) thermal management system (TMS), and (4) electrical power and distribution system. The FCS including elements necessary to control the aircraft, drive and power including elements necessary to generate and transmit shaft power, the TMS including elements necessary to maintain temperature limits in all operating environments, and electrical pow-er and distribution including equipment necessary to store and transmit electrical energy. Results found that all aircraft evaluated may have paths to comply with SC-VTOL-01, Figure ES2. However, S&C models showed large power transients that must be addressed and PSSA results show that future work is needed in single load path structures, high voltage power storage and distribution, and in motor/rotor overspeed protection.

Boeing

Environmental, health and safety assessment of photovoltaics

The environmental, health, and safety (E, H and S) concerns associated with the fabrication, deployment, and decommissioning of photovoltaic (PV) systems in terrestial applications are identified and assessed. Discussion is limited to crystalline silicon technologies. The primary E, H, and S concerns that arise during collector fabrication are associated with occupational exposure to materials of undetermined toxicity or to materials that are known to be hazardous, but for which process control technology may be inadequate. Stricter exposure standards are anticipated for some materials and may indicate a need for further control technology development. Minimizing electric shock hazards is a significant concern during system construction, operation and maintenance, and decommissioning.

Rose, E. C.

Safety assessment for EPS electron-proton spectrometer

A safety analysis was conducted to identify the efforts required to assure relatively hazard free operation of the EPS and to meet the safety requirements of the program. Safety engineering criteria, principles, and techniques in applicable disciplines are stressed in the performance of the system and subsystem studies; in test planning; in the design, development, test, evaluation, and checkout of the equipment; and the operating procedures for the EPS program.

Gleeson, P.

Reliability and Safety Assessment of Urban Air Mobility Concept Vehicles

The primary objective of this research effort is to identify failure modes and hazards associated with several configurations of multicopter concept vehicles supplied by NASA. Functional hazard analyses (FHA) and failure modes and effects criticality analyses (FMECA) are performed for each of the eight vehicle configurations under review. Conceptual design of notional powertrain configurations (turboshaft, electric, hybrid electric), notional thrust control systems (rpm control and collective control), and navigation control systems for the concept vehicles were to support the reliability and safety analysis and to assess whether a mission can be completed safely. Two kinds of analyses are performed: static safety analysis which enable the quantification of the likelihood of individual events, and dynamic safety analyses which allows the investigation of multiple time-dependent failures. Their objective is to quantify the likelihood of catastrophic failures.

Urban Air Mobility

Comparative health and safety assessment of the SPS and alternative electrical generation systems

A comparative analysis of health and safety risks is presented for the Satellite Power System and five alternative baseload electrical generation systems: a low-Btu coal gasification system with an open-cycle gas turbine combined with a steam topping cycle; a light water fission reactor system without fuel reprocessing; a liquid metal fast breeder fission reactor system; a central station terrestrial photovoltaic system; and a first generation fusion system with magnetic confinement. For comparison, risk from a decentralized roof-top photovoltaic system with battery storage is also evaluated. Quantified estimates of public and occupational risks within ranges of uncertainty were developed for each phase of the energy system. The potential significance of related major health and safety issues that remain unquantitied are also discussed.

Habegger, L. J.

Spacecraft Passive Safety Assessment Using Ellipse Constraints and Relative Orbital Elements

This paper presents necessary and sufficient conditions for validating spacecraft passive safety using relative orbital elements (ROE) centered around the far-field to near-field trajectory design of a hypothetical autonomous rendezvous and docking (AR&D) mission. The specific formulation of the ROEs used in this study are of quasi-nonsingular form based on elative eccentricity/inclination vectors. Current methodologies for ensuring passive safety apply keep-out volumes (KOV) to maintain appropriate separation between the Servicer and Client. Widely used techniques to assess the integrity of the KOV involve forward propagation of the relative Cartesian state to check for a potential KOV breach. In this study, an alternative approach to the propagation-based method is proposed using ROEs due to their valuable geometric insights of spacecraft relative motion. Modeling the relative trajectory and KOV ellipsoids as ellipses into the 2-D ROE sub-space simplifies the passive safety validation to a root-finding problem within the unit disk with high computational efficiency. Other approaches to intersection detection of the KOV are also evaluated in accuracy and run-time. Furthermore, a Monte Carlo simulation was employed to compare the ROE-based and relative Cartesian approaches in terms of maneuver error.

Bruce Barbour

Safety Assessment of Conformance Monitoring for Situational Awareness in UTM Operations

This report presents a systematic approach to evaluating the safety benefit of utilizing strategic deconfliction and Conformance Monitoring for Situational Awareness to manage the traffic that is comprised of both conforming aircraft and contingent aircraft. First, we developed a Monte-Carlo-based simulation platform that generates a range of nominal flight paths, a set of flight paths associated with contingent aircraft, encounters between conforming and contingent aircraft, and simulates aircraft's reported positions within conformance bounds. Next, we derived the mathematical equations for quantifying the level of safety, represented by the probability of mid-air collision per flight hour, using the flight data from the simulation platform. Finally, we compared the safety benefit of CMSA services in scenarios generated at different traffic densities and rates of contingent aircraft. This study suggests that strategic deconfliction and CMSA services can collaboratively handle traffic mixed with conforming and contingent aircraft more safely than strategic deconfliction alone.

CMSA

NextGen Future Safety Assessment Game

The successful implementation of the next generation infrastructure systems requires solid understanding of their technical, social, political and economic aspects along with their interactions. The lack of historical data that relate to the long-term planning of complex systems introduces unique challenges for decision makers and involved stakeholders which in turn result in unsustainable systems. Also, the need to understand the infrastructure at the societal level and capture the interaction between multiple stakeholders becomes important. This paper proposes a methodology in order to develop a holistic approach aiming to provide an alternative subject-matter expert (SME) elicitation and data collection method for future sociotechnical systems. The methodology is adapted to Next Generation Air Transportation System (NextGen) decision making environment in order to demonstrate the benefits of this holistic approach.

Ancel, Ersin

NextGen Future Safety Assessment Game

The successful implementation of the next generation infrastructure systems requires solid understanding of their technical, social, political and economic aspects along with their interactions. The lack of historical data that relate to the long-term planning of complex systems introduces unique challenges for decision makers and involved stakeholders which in turn result in unsustainable systems. Also, the need to understand the infrastructure at the societal level and capture the interaction between multiple stakeholders becomes important. This paper proposes a methodology in order to develop a holistic approach aiming to provide an alternative subject-matter expert (SME) elicitation and data collection method for future sociotechnical systems. The methodology is adapted to Next Generation Air Transportation System (NextGen) decision making environment in order to demonstrate the benefits of this holistic approach.

Ancel, Ersin