Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “safety risks”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Product Engineering Class in the Software Safety Risk Taxonomy for Building Safety-Critical Systems

When software safety requirements are imposed on legacy safety-critical systems, retrospective safety cases need to be formulated as part of recertifying the systems for further use and risks must be documented and managed to give confidence for reusing the systems. The SEJ Software Development Risk Taxonomy [4] focuses on general software development issues. It does not, however, cover all the safety risks. The Software Safety Risk Taxonomy [8] was developed which provides a construct for eliciting and categorizing software safety risks in a straightforward manner. In this paper, we present extended work on the taxonomy for safety that incorporates the additional issues inherent in the development and maintenance of safety-critical systems with software. An instrument called a Software Safety Risk Taxonomy Based Questionnaire (TBQ) is generated containing questions addressing each safety attribute in the Software Safety Risk Taxonomy. Software safety risks are surfaced using the new TBQ and then analyzed. In this paper we give the definitions for the specialized Product Engineering Class within the Software Safety Risk Taxonomy. At the end of the paper, we present the tool known as the 'Legacy Systems Risk Database Tool' that is used to collect and analyze the data required to show traceability to a particular safety standard

Hill, Janice↗

Software Safety Risk in Legacy Safety-Critical Computer Systems

Safety-critical computer systems must be engineered to meet system and software safety requirements. For legacy safety-critical computer systems, software safety requirements may not have been formally specified during development. When process-oriented software safety requirements are levied on a legacy system after the fact, where software development artifacts don't exist or are incomplete, the question becomes 'how can this be done?' The risks associated with only meeting certain software safety requirements in a legacy safety-critical computer system must be addressed should such systems be selected as candidates for reuse. This paper proposes a method for ascertaining formally, a software safety risk assessment, that provides measurements for software safety for legacy systems which may or may not have a suite of software engineering documentation that is now normally required. It relies upon the NASA Software Safety Standard, risk assessment methods based upon the Taxonomy-Based Questionnaire, and the application of reverse engineering CASE tools to produce original design documents for legacy systems.

Hill, Janice↗

Software Safety Risk in Legacy Safety-Critical Computer Systems

Safety Standards contain technical and process-oriented safety requirements. Technical requirements are those such as "must work" and "must not work" functions in the system. Process-Oriented requirements are software engineering and safety management process requirements. Address the system perspective and some cover just software in the system > NASA-STD-8719.13B Software Safety Standard is the current standard of interest. NASA programs/projects will have their own set of safety requirements derived from the standard. Safety Cases: a) Documented demonstration that a system complies with the specified safety requirements. b) Evidence is gathered on the integrity of the system and put forward as an argued case. [Gardener (ed.)] c) Problems occur when trying to meet safety standards, and thus make retrospective safety cases, in legacy safety-critical computer systems.

Hill, Janice L.↗

Aviation Safety Risk Modeling: Lessons Learned From Multiple Knowledge Elicitation Sessions

Aviation safety risk modeling has elements of both art and science. In a complex domain, such as the National Airspace System (NAS), it is essential that knowledge elicitation (KE) sessions with domain experts be performed to facilitate the making of plausible inferences about the possible impacts of future technologies and procedures. This study discusses lessons learned throughout the multiple KE sessions held with domain experts to construct probabilistic safety risk models for a Loss of Control Accident Framework (LOCAF), FLightdeck Automation Problems (FLAP), and Runway Incursion (RI) mishap scenarios. The intent of these safety risk models is to support a portfolio analysis of NASA's Aviation Safety Program (AvSP). These models use the flexible, probabilistic approach of Bayesian Belief Networks (BBNs) and influence diagrams to model the complex interactions of aviation system risk factors. Each KE session had a different set of experts with diverse expertise, such as pilot, air traffic controller, certification, and/or human factors knowledge that was elicited to construct a composite, systems-level risk model. There were numerous "lessons learned" from these KE sessions that deal with behavioral aggregation, conditional probability modeling, object-oriented construction, interpretation of the safety risk results, and model verification/validation that are presented in this paper.

Luxhoj, J. T.↗

Safety Risk Knowledge Elicitation in Support of Aeronautical R and D Portfolio Management: A Case Study

Aviation is a problem domain characterized by a high level of system complexity and uncertainty. Safety risk analysis in such a domain is especially challenging given the multitude of operations and diverse stakeholders. The Federal Aviation Administration (FAA) projects that by 2025 air traffic will increase by more than 50 percent with 1.1 billion passengers a year and more than 85,000 flights every 24 hours contributing to further delays and congestion in the sky (Circelli, 2011). This increased system complexity necessitates the application of structured safety risk analysis methods to understand and eliminate where possible, reduce, and/or mitigate risk factors. The use of expert judgments for probabilistic safety analysis in such a complex domain is necessary especially when evaluating the projected impact of future technologies, capabilities, and procedures for which current operational data may be scarce. Management of an R&D product portfolio in such a dynamic domain needs a systematic process to elicit these expert judgments, process modeling results, perform sensitivity analyses, and efficiently communicate the modeling results to decision makers. In this paper a case study focusing on the application of an R&D portfolio of aeronautical products intended to mitigate aircraft Loss of Control (LOC) accidents is presented. In particular, the knowledge elicitation process with three subject matter experts who contributed to the safety risk model is emphasized. The application and refinement of a verbal-numerical scale for conditional probability elicitation in a Bayesian Belief Network (BBN) is discussed. The preliminary findings from this initial step of a three-part elicitation are important to project management practitioners as they illustrate the vital contribution of systematic knowledge elicitation in complex domains.

Shih, Ann T.↗

Qualitative Future Safety Risk Identification an Update

The purpose of this report is to document the results of a high-level qualitative study that was conducted to identify future aviation safety risks and to assess the potential impacts to the National Airspace System (NAS) of NASA Aviation Safety research on these risks. Multiple external sources (for example, the National Transportation Safety Board, the Flight Safety Foundation, the National Research Council, and the Joint Planning and Development Office) were used to develop a compilation of future safety issues risks, also referred to as future tall poles. The primary criterion used to identify the most critical future safety risk issues was that the issue must be cited in several of these sources as a safety area of concern. The tall poles in future safety risk, in no particular order of importance, are as follows: Runway Safety, Loss of Control In Flight, Icing Ice Detection, Loss of Separation, Near Midair Collision Human Fatigue, Increasing Complexity and Reliance on Automation, Vulnerability Discovery, Data Sharing and Dissemination, and Enhanced Survivability in the Event of an Accident.

future aviation safety risk↗

Projected Impact of Compositional Verification on Current and Future Aviation Safety Risk

The projected impact of compositional verification research conducted by the National Aeronautic and Space Administration System-Wide Safety and Assurance Technologies on aviation safety risk was assessed. Software and compositional verification was described. Traditional verification techniques have two major problems: testing at the prototype stage where error discovery can be quite costly and the inability to test for all potential interactions leaving some errors undetected until used by the end user. Increasingly complex and nondeterministic aviation systems are becoming too large for these tools to check and verify. Compositional verification is a "divide and conquer" solution to addressing increasingly larger and more complex systems. A review of compositional verification research being conducted by academia, industry, and Government agencies is provided. Forty-four aviation safety risks in the Biennial NextGen Safety Issues Survey were identified that could be impacted by compositional verification and grouped into five categories: automation design; system complexity; software, flight control, or equipment failure or malfunction; new technology or operations; and verification and validation. One capability, 1 research action, 5 operational improvements, and 13 enablers within the Federal Aviation Administration Joint Planning and Development Office Integrated Work Plan that could be addressed by compositional verification were identified.

Reveley, Mary S.↗

A Software Safety Risk Taxonomy for Use in Retrospective Safety Cases

Safety standards contain technical and process-oriented safely requirements. The best time to include these requirements is early in the development lifecycle of the system. When software safety requirements are levied on a legacy system after the fact, a retrospective safety case will need to be constructed for the software in the system. This can be a difficult task because there may be few to no art facts available to show compliance to the software safely requirements. The risks associated with not meeting safely requirements in a legacy safely-critical computer system must be addressed to give confidence for reuse. This paper introduces a proposal for a software safely risk taxonomy for legacy safely-critical computer systems, by specializing the Software Engineering Institute's 'Software Development Risk Taxonomy' with safely elements and attributes.

Hill, Janice L.↗

Comprehensive Battery Safety Risk Evaluation: Aged Cells versus Fresh Cells Upon Mechanical Abusive Loadings

Abstract Despite their wide applications, lithium‐ion batteries (LIBs) have been struggling with their safety risks arising from different lifetime stages. Here, the NCMA pouch cell is taken as an example, and the safety of both fresh and aged cells from three milestone stages, that is, internal short circuit (ISC) triggering risk, ISC mode, and the subsequent thermal runaway (TR) consequence is investigated. By combining mechanical abusive testing and physics‐based models on commercialized cells with various states‐of‐health (SOH) and states‐of‐charge, it is discovered that the ISC triggering delays with the decay of SOH and soft ISC mode will be triggered more frequently, which is mainly due to the mechanical behaviors of the current collectors. The temperature rises and peak temperature during the subsequent TR also become milder for aged cells due to the reduced capacity and deterministic soft ISC process. Results here provide a mechanistic explanation of the safety risk comparison between the fresh and aged cells, offering cornerstone guidance to the evaluation and design of next‐generation safer LIBs.

25 ENERGY STORAGE↗

A Safety Risk Assessment Methodology for Decision Support Systems with an Application to the Expedite Departure Path Tool

In support of the NASA Advanced Air Transportation Technologies Project, the Volpe National Transportation Systems Center has developed a methodology to perform safety risk assessments for air traffic control/air traffic management decision Support systems and concepts. Changes in controller, pilot, and/or airline dispatcher tasks that are affected by the decision support system are related to associated hazards. These hazards are then assessed either qualitatively or quantitatively in terms of likelihood of occurring and the impact if they do occur. Those items that show a potential safety hazard level increase can then have research plans developed to address those safety risks areas. An application of this methodology will he demonstrated using the AATT decision support tool Expedite Departure Path.

Snyder, Phillip T.↗

C-Band Airport Surface Communications System Engineering-Initial High-Level Safety Risk Assessment and Mitigation

This document is being provided as part of ITT's NASA Glenn Research Center Aerospace Communication Systems Technical Support (ACSTS) contract: "New ATM Requirements--Future Communications, C-Band and L-Band Communications Standard Development." ITT has completed a safety hazard analysis providing a preliminary safety assessment for the proposed C-band (5091- to 5150-MHz) airport surface communication system. The assessment was performed following the guidelines outlined in the Federal Aviation Administration Safety Risk Management Guidance for System Acquisitions document. The safety analysis did not identify any hazards with an unacceptable risk, though a number of hazards with a medium risk were documented. This effort represents an initial high-level safety hazard analysis and notes the triggers for risk reassessment. A detailed safety hazards analysis is recommended as a follow-on activity to assess particular components of the C-band communication system after the profile is finalized and system rollout timing is determined. A security risk assessment has been performed by NASA as a parallel activity. While safety analysis is concerned with a prevention of accidental errors and failures, the security threat analysis focuses on deliberate attacks. Both processes identify the events that affect operation of the system; and from a safety perspective the security threats may present safety risks.

Zelkin, Natalie↗

System Safety Risk Analysis Models (SSRAM)

This presentation provides a high level overview of the System Safety Risk Analysis (SSRAM) methodology and motivation.

Clark, Andrew Jordan [Sandia National Laboratories↗

Extracting Lessons of Human Performance and Resilience Management from a Study of Weather-Related Safety Risks and Incidents Reported to NASA's Aviation Safety Reporting System (ASRS)

We present a study of weather-related incident reports submitted to NASA’s Aviation Safety Reporting System (ASRS) by air carrier pilots and air traffic controllers in the US. Using specific examples, we examine the weather-related risks reported and the relevant aspects of human performance and resilience management exhibited during these incidents. We describe our methods of lesson extraction to maximize learning, including the use of advance algorithms, and we conclude with a review of the weather-related risks encountered and the resilient practices employed to mitigate them.

resilience↗

Fast Earth-Mars Roundtrip Trajectories to Reduce Health and Safety Risks for Crewed Missions

The extended mission duration of a crewed Mars mission compounds integrated risks to crew health and safety. Shortening mission duration would therefore have a direct impact on reducing many human health and performance risk factors. This paper describes trajectory feasibility analyses performed to examine trajectory options for a fast crewed mission to Mars. Studies were conducted to examine options with short overall mission durations (≤ 400-day roundtrip) and options that focus on minimizing astronaut time in deep space, while allowing for longer Mars surface stays. Trade studies were performed to determine ∆v requirements for a range of launch dates, Mars orbit periods, Mars stay times, and Earth-to-Mars flight time maxima. The implications of a Venus gravity assist are also described. The analyses presented here build on and specifically aim to optimize and address key concerns of assumptions made in previously published studies of fast crewed Mars missions.

Mars↗

Use of System Safety Risk Assessments for the Space Shuttle Reusable Solid Rocket Motor (RSRM)

This paper discusses the System Safety approach used to assess risk for the Space Shuttle Reusable Solid Rocket Motor (RSRM). Previous to the first RSRM flight in the fall of 1988, all systems were analyzed extensively to assure that hazards were identified, assessed and that the baseline risk was understood and appropriately communicated. Since the original RSRM baseline was established, Thiokol and NASA have implemented a number of initiatives that have further improved the RSRM. The robust design, completion of rigorous testing and flight success of the RSRM has resulted in a wise reluctance to make changes. One of the primary assessments required to accompany the documentation of each proposed change and aid in the decision making process is a risk assessment. Documentation supporting proposed changes, including the risk assessments from System Safety, are reviewed and assessed by Thiokol and NASA technical management. After thorough consideration, approved changes are implemented adding improvements to and reducing risk of the Space Shuttle RSRM.

Greenhalgh, Phillip O.↗