1130 Baseline Requirement and Verification.xlsx
XLSX spreadsheet 232 KB Posted
- Attached to
- Commercial Low Earth Orbit (LEO) Development Program Phase 2 Requirements and Safety Technical Interchange Meeting Federal contract opportunity
- Solicitation number
- 80JSC025REQ_SAFETY_TIM
About this file
This document is a comprehensive technical requirements specification for the Commercial Low Earth Orbit Development Program's safety and technical requirements for spacecraft systems. The file details over 100 specific technical requirements across multiple domains including spacecraft control systems, environmental controls, payload management, fire suppression, communication systems, crew safety, and scientific research capabilities. Key requirements include ensuring failure tolerance to catastrophic events, providing emergency systems and abort capabilities, maintaining habitable environments, supporting scientific research through specialized facilities like gloveboxes and centrifuges, and implementing robust computing and command systems with multiple layers of safety controls.
The requirements specification covers critical aspects such as crew transportation, spacecraft operations, system monitoring, environmental controls, payload accommodation, and safety protocols. Specific technical requirements range from precise specifications like maintaining cabin atmosphere within defined parameters, providing emergency breathing apparatus, enabling remote payload operations, supporting various sample preservation temperatures, implementing fire detection and suppression systems, and ensuring robust computing systems with fail-safe mechanisms. The document appears to be part of NASA's strategy to develop commercial low Earth orbit capabilities with rigorous technical and safety standards for future space destinations and transportation systems.
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
1130 clean
| Req ID | Req Section | Name | REQUIREMENT | RATIONALE | VR ID | VR Section | VERIFICATION | SUCCESS CRITERIA | Method |
| R.CLDS.006 | 3.2.1.1 | FAILURE TOLERANCE TO CATASTROPHIC EVENTS | The CLDS shall be two failure tolerant to a catastrophic hazard, except for Design for Minimum Risk items defined and approved in accordance with CLDP-REQ-3102 - CLDP Hazard Analysis and Safety Process Requirements, where applicability to Visiting Vehicles is only during Integrated Operations. | Compliance with this requirement can be accomplished at the end item level or through a combination of hazard controls at the Module/System levels and end item level. A common way to improve reliability and, thus, meet safety requirements is to use systems that tolerate failures when complete failure avoidance is not practical. Specific hazard controls and implementation can be derived from an integrated design and safety analysis in accordance with CLDP-REQ-3102 - CLDP Hazard Analysis and Safety Process Requirements. Micrometeoroid and Orbital Debris hazards, material compatibility, fire and other potentially catastrophic hazards that cannot be controlled using failure tolerance are exempted from the failure tolerance requirements provided the hazards are controlled through the process documented in CLDP-REQ-3102 in which approved standards and margins are implemented that account for the absence of failure tolerance. A verified evacuation method is acceptable as a third control to a catastrophic hazard for the Destination. | V.CLDS.006 | 4.2.1.1 | The CLDS shall verify failure tolerance against catastrophic hazards by analysis, inspection, and test. |
An integrated hazard analysis, in compliance with CLDP-REQ-3102, Hazard Analysis and Safety Process Requirements, shall identify catastrophic hazards, their causes, controls, and verification of the controls, using end item hazard analyses, operational procedures, integrated schematics and drawings, and integration documentation.
An inspection shall verify physical presence and configuration of hazard controls.
A test shall verify functional performance to specification. The verification shall be considered successful when the analysis, inspection, and test show that all identified catastrophic hazards have controls such that they are either two failure tolerant or have been CLDP-approved as DFMR. Analysis Inspection Test R.CLDS.007 3.3.1 TRANSPORT CREW The CTS shall transport USG crew to the Destination. USG crew will be transported to the Destination to meet the United States Operations demand for crew time based on utilization of the Commercial Destination to perform science and support the National Laboratory Program. V.CLDS.007 4.3.1 The CTS shall verify the ability to transport crew to the Destination by test and analysis.
The tests shall verify the required performance of the flight systems and determine the statistical dispersions on their performance.
Analysis shall include verified 3DOF and 6DOF simulations, including appropriate modeling of all systems affecting vehicle dynamics, along with their production variability and uncertainties for all appropriate flight phases. The trajectory simulations shall model the spacecraft's entire trajectory from launch through first contact between the docking mechanisms at the Destination for all crew and cargo configurations. The analysis shall assume that the Destination does not perform translational maneuvers to support rendezvous.
A ground propulsion system hotfire test shall verify performance of propulsion, avionics, and structural subsystems across all mission phases of the CVV, using a flight like integrated system test article. The verification shall be considered successful when the Monte Carlo simulation(s) of the required transport scenarios, with Natural Environment and flight performance dispersions, achieves a 99.73% probability of success with at least 90% confidence throughout the transport mission profile.
The verification shall be considered successful when the simulation shows the spacecraft docks, and both the spacecraft and launch vehicle operate within verified capabilities, within defined limits for human capability, and while maintaining the expected factors of safety for vehicle thermal limits and structural load limits.
Ground hotfire testing shall be considered successful when it demonstrates integrated propulsion system functionality and characterizes system performance. Analysis Test R.CLDS.008 3.3.1 RETURN CREW The CTS shall return USG crew from the Destination. USG crew are required to be returned from the Commercial Destination to meet the United States Operations demand for crew time based on full utilization of the Commercial Destination to perform science and support the National Laboratory Program. V.CLDS.008 4.3.1 The CTS shall verify the ability to return crew from the Destination by test and analysis.
The tests shall verify the required performance of the flight systems and may determine the statistical dispersions on their performance.
The analysis shall include verified 3DOF and 6DOF simulations, including appropriate modeling of all systems affecting vehicle dynamics, along with their production variability and uncertainties for all appropriate flight phases. The trajectory simulations shall model the spacecraft's entire trajectory from un-docking within the expected Destination operational altitude range through landing at each supported site for all crew and cargo configurations.
A ground propulsion system hotfire test shall verify performance of propulsion, avionics, and structural subsystems across all mission phases of the CVV, using a flight like integrated system test article. The verification shall be considered successful when the Monte Carlo simulation(s) of the required return scenarios, with Natural Environment and flight performance dispersions, achieves a 99.73% probability of success with at least 90% confidence throughout the return mission profile.
The verification shall be considered successful when the simulation for each case shows the spacecraft successfully lands within the boundaries of a supported landing site, when the spacecraft operates within verified capabilities, while observing defined limits for human capability, and while maintaining the expected factors of safety for vehicle thermal limits and structural load limits.
Ground hotfire testing shall be considered successful when it demonstrates integrated propulsion system functionality and characterizes system performance. Analysis Test R.CLDS.011 3.3.1 LAUNCH SITES The CLDS shall launch from a U.S. (or U. S. State Department approved) launch site(s). Launching from a designated U.S. (or U.S. State Department approved) launch sites reduces risk by minimizing necessary abort recovery force assets, increasing proximity to U.S. medical facilities, increasing security, and ensuring a prepared launch and emergency landing site, which minimizes unknown hazards and potential security issues. V.CLDS.011 4.3.1 The CTS shall verify the ability to launch NASA crew from a U.S. (or U. S. State Department approved) launch site(s) by inspection.
| The inspection shall consist of a review of the documentation describing the facilities and plans developed to accomplish a launch. | The verification shall be considered successful when an inspection of the launch site shows the selected location(s) is in the U.S. (or U. S. State Department approved location) and all necessary facilities and launch plans to facilitate a launch are in place. | Inspection | ||||||
| R.CLDS.012 | 3.3.1 | LANDING SITES | The CTS and CaTS shall return the USG crew to a designated Primary Landing Site for nominal landings to within either the Continental United States (CONUS) or adjacent United States territorial waters. | Returning to a designated continental U.S. landing site or waters directly extending from the coast reduces risk by minimizing necessary recovery force assets, increasing proximity to U.S. medical facilities, increasing security, and ensuring a prepared landing site free of hazards. Deconditioned crewmembers have impaired musculoskeletal, cardiopulmonary, and neurovestibular capabilities as a result of long duration exposure to the micro-gravity and space environment, resulting in degraded crewmember performance in the post-landing timeframe. Because of the deconditioned state of the crew, special considerations need to be provided for medical and other post-landing care. | V.CLDS.012 | 4.3.1 | The CTS shall verify the ability to return NASA crew to a designated Primary Landing Site by inspection supported by analysis. |
A functional analysis shall to determine the Ground System capabilities required at the landing site.
An inspection of drawings, equipment lists, and landing site features shall show Ground System capabilities. The verification shall be considered successful when analysis of Ground System capabilities and the inspection of drawings, equipment lists, and landing site features determine that Ground System capabilities are available throughout the landing site and the landing sites are within the continental United States or adjacent United States territorial waters. Analysis Inspection R.CLDS.014 3.2.2.2 TIME-CRITICAL CARGO PRE-LAUNCH HANDLING The CTS and CaTS shall provide the capability to install and maintain 10% of pressurized cargo by volume as time-critical cargo within 24 hours of a scheduled launch. Once Time-Critical cargo has been handed over to CLDS, it is critical that cargo services be maintained to ensure the integrity of the cargo. Late cargo installation, within 24 hours of scheduled launch, is required to maintain the integrity of Time-Critical cargo. The CLDS may select the specific integration window, as long as it is within 24 hours of scheduled launch. This requirement addresses both soft stowage and hard mounted Time-Critical cargo. The Time-Critical cargo installation may include an Integrated Verification Test (IVT) to verify the interface between the spacecraft and the payload and completed within the L-24 window of opportunity. V.CLDS.014 4.2.2.2 The CLDS shall verify the capability to install and maintain 10% of cargo by volume within 24 hours of a scheduled launch by demonstration and inspection.
A demonstration shall evaluate the time to install and checkout critical cargo within the allocated timeline in the L-24 flight representative configuration.
An inspection of the L-24 pre-launch timeline shall confirm an allocation for Time-Critical cargo stowage activities.
An inspection shall show that legacy interfaced defined in CLDP-REQ-1102, can be accommodated within this volume
An inspection of spacecraft drawings shall verify access to all areas of the spacecraft available for storage of Time-Critical cargo and the availability of these areas within the L-24 pre-launch timeline. The verification shall be considered successful when the demonstration and inspection show that the time to install and checkout Time-Critical cargo is equal to or less than the allotted time allowed by the pre-launch payload installation timeline in the L-24 window of opportunity and cargo services. Demonstration Inspection R.CLDS.015 3.2.2.2 TIME-CRITICAL CARGO REMOVAL The CTS and CaTS shall accommodate the removal of time critical cargo and maintain services through transfer to USG Personnel within 4 hours after landing. Time critical cargo and experiments must be turned over to the providers in a shorter amount of time to maintain the integrity time critical cargo. V.CLDS.015 4.2.2.2 The CTS and CaTS shall verify the capability to accommodate the removal and transfer of time critical cargo to USG Personnel post landing. The CTS and CaTS shall verify the ability to remove cargo from the pressurized volume from post crew egress through transfer within four hours after hatch opening and crew egress by demonstration and inspection.
The post-landing demonstration shall be performed with vehicle and cargo hardware in the landed-flight configuration in 1-g environment to ensure range of motion, clearance, and fit.
| The inspection shall show processing timelines and environments for post-landing scenarios support cargo removal and transfer to USG personnel within four hours after hatch opening and crew egress (for CVV). | The verification shall be considered successful when the inspection and demonstration shows processing timelines and environments for post-landing provide for cargo removal and transfer to USG personnel within four hours after hatch opening and crew egress (for CVV). | Demonstration | ||||||
| R.CLDS.021 | 3.3.5.1 | LANDING LIGHTING | The CTS shall be capable of landing in all ambient lighting conditions. | The capability to land in day or night lighting conditions will maximize landing opportunities, which may be required and/or driven by the Commercial Partner's logistic and business model (for non-USG crew). Additionally, for launch abort landings or for early mission termination, the lighting may be either daylight or dark. In order to maximize crew survivability, the CTS should be able to land in all lighting conditions. | V.CLDS.021 | 4.3.5.1 | The CTS shall verify the ability to land independent of all ambient lighting conditions by analysis. |
| The analysis shall include CTS systems required to enable landing during any lighting conditions and shows operation of flight systems, facility systems, and GSE independent of ambient lighting conditions for landing. Systems to be considered include tracking (optics and radar), navigational landing aids, recovery/rescue aids, imagery (ground and flight based), GSE, and facilities. | The verification shall be considered successful when the analyses show successful probability of landing CVV independent of ambient lighting conditions. | Analysis | |||
| R.CLDS.022 | 3.3.4.1 | RPOD LIGHTING | The CTS shall be capable of rendezvous, proximity operations, docking (RPOD) and undocking independent of ambient lighting conditions and ground overflight constraints, to enable docking and undocking during 95% of the planned orbit. | The intent of this requirement is that ambient lighting or ground overflight constraints should not affect final rendezvous, proximity operations, docking or undocking operations, or normal Commercial Destination operations, in terms of crew timeline considerations or docking attitudes. |
This does not necessarily require that each navigation sensor be capable of operating in all lighting conditions. The CTS should not require proximity operations and docking to be aborted due to ambient lighting conditions. The trajectory and timeline should be forgiving enough to accommodate minor approach adjustments during brief periods of degraded navigation/crew visibility due to orbital lighting conditions and allow docking and undocking operations to occur over a large portion of the planned orbit.
Docking over a particular set of ground stations could limit docking to a very small allowable time period. This could overly constrain launch time or could require a significant wait time on orbit, particularly if a docking opportunity is missed. Docking independent of ground overflight constraints avoids these restrictions and added resource requirements. V.CLDS.022 4.3.4.1 The CTS shall verify the capability to perform rendezvous, proximity operations, docking, and undocking independent of lighting and ground site overflight constraints by inspection and analysis.
An inspection shall show the CTS constraints (such as GNC, communications, sensors, thermal control) determine the effects of ambient lighting and ground site location on CVV operations for rendezvous, proximity operations, docking and undocking.
The analysis shall show that the dispersed nominal and planned contingency trajectories and timeline are uninhibited by lighting and ground site overflight constraints, where minor approach adjustments during brief periods of degraded navigation/crew visibility are allowed. The analysis shall encompass all possible lighting conditions including the complete range of solar and lunar beta angles. The verification shall be considered successful when the inspection and analysis shows that ground overflight and ambient lighting constraints used in the trajectory design, including selection of planned docking and undocking times, allow docking and undocking at designated docking ports to occur within 95% of the planned orbit. Analysis Inspection R.CLDS.028 3.3.2.3 FAILURE TOLERANCE TO CATASTROPHIC EVENTS - CREW TRANSPORTATION The CTS shall provide failure tolerance for the control of catastrophic hazards, with the specific level of failure tolerance (one or more) and implementation (the use of similar or dissimilar redundancy) derived from an analysis of hazards, failure modes, and risk associated with the system.
a. The CTS shall provide dual failure tolerance or single failure tolerance with dissimilar redundancy for the control of catastrophic hazards in the systems that provide the guidance, navigation, and flight path/trajectory control functions for the deorbit burn, entry, and landing phases of the mission for the control of catastrophic hazards, with the specific level of failure tolerance and implementation (the use of similar or dissimilar redundancy) derived from an analysis of hazards, failure modes, and risk associated with the system with the following exceptions:
b. Failure of primary structure, structural failure of pressure vessel walls, and failure of pressurized lines are excepted from the failure tolerance requirement, provided the potentially catastrophic failures are controlled through a defined process approved by NASA and in which standards and margins are implemented that account for the absence of failure tolerance. Although failure tolerance is not required for providing structural capability, the functions that maintain the pressure within the structural capability shall provide dual failure tolerance for the control of catastrophic hazards. See the definition of Maximum Design Pressure (MDP) provided in the structural requirements document.
c. Failure of aerodynamic control effectors and parachutes are excepted from the dual failure tolerance requirement in sub-paragraph a., and are governed by the base requirement for one or more levels of failure tolerance as derived from an analysis of hazards, failure modes, and risk associated with the system. This requirement applies for nominal and post abort descent and landing phases.
d. The CTS shall provide dual failure tolerance for the control of catastrophic hazards from inadvertent activation of pyrotechnic initiation methods. The overall objective is to provide the safest design that can accomplish the mission, given the constraints imposed on the Program. Since a CTS development will always have mass, volume, schedule, and cost constraints, choosing where and how to apply failure tolerance requires integrated analyses at the system level to assess safety and mission risks. First and foremost, the failure tolerance is applied at the overall system level to include all capabilities of the system (software, hardware, operations). While failure tolerance is a term frequently used to describe minimum acceptable redundancy, it may also be used to describe two similar systems, dissimilar systems, cross-strapping, or functional interrelationships that ensure minimally acceptable system performance despite failures, or additional features that completely mitigate the effects of failures. Even when assessing failure tolerance at the integrated system level, the increased complexity, and the additional utilization of system resources (e.g., mass, power) required by a failure tolerant design may negatively impact overall system safety as the level of failure tolerance is increased.
Ultimately, the level and type of redundancy (similar or dissimilar) is an important and often controversial aspect of system design. Since redundancy does not, by itself, make a system safe, it is the responsibility of the engineering and safety teams to determine the safest practical system design given the mission requirements and constraints. Additionally, the overall system reliability is a significant element of the integrated safety and design analysis used in the determination of the level of redundancy. Redundancy alone without sufficient reliability does not meet the intent of this requirement. Catastrophic events, as defined in this document and consistent with NPR 8715.3, NASA General Safety Program Requirements, include crew fatality and the unplanned loss/destruction of a major element of the crewed space system during the mission that could potentially lead to death or permanent disability of the crew or passengers.
Where failure tolerance is not the appropriate approach to control hazards, specific measures need to be employed to: 1) recognize the importance of the hazards being controlled, 2) ensure robustness of the design, and 3) ensure adequate attention/focus is being applied to the design, manufacture, implementation, test, analysis, and inspection of the items and/or software. Where the CTS cannot provide the minimum required failure tolerance to control a catastrophic hazard, NASA may grant an exception to the requirements provided: a) the analysis can quantify, with sufficient confidence, the risk delta associated with the reduction in failure tolerance, b) NASA determines the risk is acceptable, or c) the hazard is controlled through a defined process in which standards and margins are implemented that account for the reduced failure tolerance. V.CLDS.028 4.3.2.3 The CTS shall verify failure tolerance for catastrophic hazards by analysis.
| An integrated hazard analysis, in compliance with CLDP-REQ-3102, Hazard Analysis and Safety Process Requirements, shall identify potential hazard causes and controls and show compliance with the required level of failure tolerance. | The verification shall be considered successful when the analysis shows that all identified catastrophic hazards that are mitigated by failure tolerance are controlled and verified. | Analysis | ||||||
| R.CLDS.029 | 3.2.1.1 | FAILURE TOLERANCE WITHOUT EMERGENCY SYSTEMS | The CLDS shall provide the required level of failure tolerance for critical and catastrophic hazards without the use of emergency equipment and systems except for a verified evacuation method is acceptable as a third control to catastrophic hazards for the Destination. | Emergency systems are there to mitigate the effects of a hazard. Examples of emergency equipment and systems include fire suppression systems, fire extinguishers, emergency breathing masks, and pressure suits. For CTS, pad or ascent aborts, ballistic unguided entry, and emergency deorbit are also considered emergency systems. However the use of EVA, emergency systems, and contingency or emergency operations will be considered a Crew Survival Method (CSM) to prevent Loss of Crew in the event all other approved hazard controls have failed. | V.CLDS.029 | 4.2.1.1 | The CLDS shall verify failure tolerance without emergency systems or equipment by analysis. |
| An integrated hazard analysis, in compliance with CLDP-REQ-3102, Hazard Analysis and Safety Process Requirements, shall identify potential hazard causes, controls, and verification of the controls and show compliance with the required level of failure tolerance without the use of emergency equipment and systems except for a verified evacuation method as a third control to catastrophic hazards for the Destination. | The verification shall be considered successful when the integrated hazard analysis ensures that failure tolerance is not met through reliance on the proper operation of pad or ascent aborts or emergency equipment or systems and the CLD Program has approved the hazard analysis. | Analysis | ||||||
| R.CLDS.030 | 3.2.1.1 | FAULT DETECTION AND ANNUNCIATION | The CLDS shall automatically detect and Annunciate faults to ground and to crew within the Destination and Visiting Vehicles, including across the hatches during docked operations, that affect Safety-Critical systems, the environment, and/or crew health. | An alerting system decreases the cognitive load on the crew. Fault annunciations which cross the hatch enable crew situational awareness and quicker response times. Terminology, references, and graphics used are to be coordinated with other crew task demands to minimize additional training. Medical emergencies do not require vehicle wide annunciation. | V.CLDS.030 | 4.2.1.1 | The CLDS shall verify automatic fault detection and annunciation to crew and ground by test supported by analysis. |
A safety analysis shall identify faults that affect Safety-Critical systems, the environment, and/or crew health and define which fault annunciations cross the hatch during docked operations and are Annunciated in which vehicle (Destination, CVV, CaVV) in addition to ground.
A test shall simulate faults and show the system can automatically detect and Annunciate the faults to ground and within and across the Destination, CVV, and CaVV as defined in the analysis. The verification shall be considered successful when the faults that affect Safety-Critical systems, the environment, and/or crew health identified by the safety analysis have been confirmed by test to be automatically detected and Annunciated to crew and ground and within and across the Destination, CVV, and CaVV as determined by the analysis. Analysis Test R.CLDS.031 3.2.1.1 FAULT DETECTION, ISOLATION AND RECOVERY The CLDS shall automatically detect, isolate, and recover from faults that would result in a Safety-Critical event. A hazard analysis identifies the causes of hazards and the controls needed for these causes to assure safety. It is necessary to ensure the controls can be activated to isolate the fault and prevent further propagation of the hazard. Once the fault is isolated, critical functions continue to operate, which is protected for by the failure tolerance requirement. The isolation of faults cannot interfere with the implementation of failure tolerance. V.CLDS.031 4.2.1.1 The CLDS shall verify automatic fault detection, isolation and recovery of functions by test supported by analysis.
A safety analysis shall identify Safety-Critical hardware and software faults and their effect on the system, in compliance with CLDP-REQ-3102, Hazard Analysis and Safety Process Requirements, and identify the associated recovery response and time to effect to prevent the Safety-Critical event.
A test shall be performed to inject Safety-Critical fault simulations and show successful automatic system detection, isolation, and recovery within the time to effect. The verification shall be considered successful when the test shows that the system can automatically detect and isolate the system faults identified in the analysis and confirms that where redundancy exists, FDIR logic can isolate a detected fault to the level required for recovery of function in time against the Safety-Critical faults identified in the analysis. Analysis Test R.CLDS.032 3.2.3 RECORD AND DISPLAY HEALTH AND STATUS The CLDS shall generate, display, transmit, including delayed downlinks due to loss of signal, and record health, status, and engineering data for use by the crew, ground control centers, and recovery forces, including backup of critical data for the life of the Destination. Data is necessary onboard and on the ground to be used for understanding the state of systems; for Anomaly resolution, event reconstruction and mission decisions; and to allow delayed downlink due to loss of signal. Recording and backup of critical data provides ability to review for Anomaly resolution, post-activity analysis and delayed transmission for loss of signal. System design will determine storage volume and data rates. Important status information includes system states and configurations, levels of automation, modes and mode changes, rationale for automation decisions, and pending failures or hazards. V.CLDS.032 4.2.3 The CLDS shall verify generation, display, transmission, and recording of health, status, and engineering data by analysis supported by test.
The analysis shall identify the required health, status, and engineering data sets needed and the timeliness required for the intended use in nominal operations, Anomaly resolution, event reconstruction, and mission decisions. The analysis shall also determine what data sets are deemed critical.
The test shall confirm the required health, status, and engineering data are generated, displayed, transmitted, including delayed downlinks due to loss of signal, and recorded for use by the crew, ground control centers, and recovery forces, including backup of critical data. The verification shall be considered successful when the test confirms the required sets of generated health, status, and engineering data are generated, displayed, transmitted, including delayed downlinks due to loss of signal, recorded, and received for use by the crew, ground control centers, and recovery forces, backup of critical data in a time consistent for the purposes they are intended, in support of nominal operations, flight Anomaly resolution, event reconstruction, and mission decisions. Analysis Test R.CLDS.033 3.2.1.2 EMERGENCY RESPONSE The CLDS shall provide the capability for crew emergency response in all flight phases within the time required to minimize vehicle damage and prevent harm to the crew. The system design impacts timely crew response to an emergency situation. Emergency response begins at the time the system or crewmember detects the hazard or event. The crew response and time to effect are dependent on which vehicle the crew are in and the phase of flight of each vehicle. V.CLDS.033 4.2.1.2 The CLDS shall verify the capabilities for crew emergency response by demonstration supported by analysis.
An analysis shall identify emergency events, including medical emergencies, and determine the time to respond to the emergency. The analysis shall identify crew actions and any equipment required to mitigate the emergency.
A demonstration shall utilize operational flight procedures identified by the analysis to show that the system allows crew to respond to emergency events within the time necessary to minimize vehicle damage and prevent harm to the crew. The verification shall be considered successful when the demonstration shows that a flight-representative crew can respond to the emergency events identified in the analysis within the time required to minimize vehicle damage and prevent harm to the crew. Analysis Demonstration R.CLDS.034 3.2.1.3 BREATHING APPARATUS The CLDS shall supply a portable breathing apparatus (mask) for all crewmembers whenever the cabin atmosphere may be contaminated and whenever an unplanned reduction in cabin pressure occurs which:
a. Prevents contaminants from entering the apparatus.
b. Maintains breathing zone ppO2 and ppCO2 levels, defined in Appendix E: Habitable Atmosphere, for response to a contamination contingency until the pressurized volume is returned to the 1-hour SMAC limits defined by JSC 20584.
c. Supplies nominal 100% oxygen for a depressurization contingency until crewmembers are in a safe habitable atmosphere as defined in Appendix E.
d. Meets the intent of SAE-AS-8047 - Performance Standard for Cabin Crew Portable Protective Breathing Equipment for Use During Aircraft Emergencies for Class 2 equipment.
e. Allows voice communication between each of the crewmembers and the ground control center when wearing the contingency breathing apparatus. The intent of this requirement is to supply crew with breathing apparatuses that provide protection and breathing gases within established limits and to define duration for apparatus function. The two scenarios for which a breathing mask would be employed include a Contaminated Atmosphere due to fire or toxic release and an unplanned reduction in cabin pressure. This requirement can be met with many different implementations involving one or more masks. The mask protects the eyes and respiratory tract from the contaminated cabin.
For the Contaminated Atmosphere case, the intent is to avoid crew performance impacts and allow for crew survival until the pressurized volume is returned to the 1-hour SMAC limits. The timeframe for which masks are required is governed by the system that removes particulates from the cabin, including cabin purges and/or a filtering system. For the depress contingency, the breathing apparatus is used until each crewmember is in a fully functional pressure suit or is in a Habitable Environment as defined in Appendix E. The timeframe for fully functional suit includes donning, buttoning up, flowing O2, and passing a leak check.
In the case that an unplanned reduction in cabin pressure occurs, the 100% oxygen reduces the risk of decompression sickness (DCS) and prevents hypoxia. V.CLDS.034 4.2.1.3 The CLDS shall verify the ability to supply a portable contingency breathing apparatus whenever the cabin atmosphere may be contaminated and whenever an unplanned reduction in cabin pressure occurs by inspection, analysis, and demonstration.
An inspection shall show the breathing apparatus prevents contaminants from entering the apparatus during an emergency event and meets the intent of the evaluation criteria shown in CLDP-STD-1140 for SAE-AS-8047 - Performance Standard for Cabin Crew Portable Protective Breathing Equipment for Use During Aircraft Emergencies for CLass 2 equipment.
An inspection shall confirm there are enough breathing apparatuses onboard the spacecraft to support all crew.
An analysis shall show that the contingency breathing apparatus can fit the varying size of all crew onboard the spacecraft.
An analysis shall show that for contamination events, the contingency breathing apparatus maintains breathing zone ppO2 and ppCO2 as defined in Appendix E for the entire crew simultaneously until the habitable atmosphere has returned to 1-hour SMAC levels as defined in JSC 20584.
An analysis shall show that for unplanned reduction in cabin pressure, the contingency breathing apparatus can supply 100% oxygen and maintain breathing zone ppO2 and ppCO2 as defined in Appendix E for crew simultaneously until crew are in a safe, Habitable Environment as defined in Appendix E.
A demonstration shall show communication between each of the crewmembers and with the ground control center personnel with expected ambient noise levels. The verification shall be considered successful when the inspection, analysis, and demonstration show that each crewmember is provided a safe, individual contingency breathing apparatus that (1) meets the intent of SAE-AS-8047, (2) allows for communication between crewmembers and ground control center personnel, (3) maintains a breathing zone ppO2 and ppCO2 per Appendix E until either 1-hour SMAC levels per JSC 20584 are returned or crew is in a safe, habitable atmosphere per Appendix E. Analysis Demonstration Inspection R.CLDS.036 3.2.1.2 EMERGENCY LIGHTING The CLDS shall provide automatically activated, powered emergency lighting in accordance with the Emergency Lighting Intensity Levels Table within one second of a lighting system failure to support egress and/or operational recovery. Emergency lighting allows for crew egress and/or operational recovery in the event of a general power failure. The emergency lighting system is to be automatically activated and powered to allow operators to perform recovery operations and other occupants of a vehicle to move to a safe location, including allowing efficient transit between any inhabited location and designated safe haven(s). Efficient transit includes appropriate orientation with respect to doorways and hatches, as well as obstacle avoidance along the egress path. Design guidance for emergency lighting can be found in NASA/SP-2010-3407, Human Integration Design Handbook (HIDH). ISS experience showed a significant amount of crew time and resupply up-mass performing preventative maintenance on Emergency Egress Lighting Systems, like replacing batteries. Give consideration to a design that minimizes crew time for preventative maintenance. V.CLDS.036 4.2.1.2 The CLDS shall verify emergency lighting by analysis, test, and demonstration.
A task analysis shall determine the operations required for operational recovery and crew egress, the estimated time of the operations, and task surfaces required to support those operations.
A test shall measure the illumination levels on task surface(s) with a subject positioned to perform the operational tasks, including egress.
A test shall evaluate automatic activation of emergency lighting by interrupting primary power and measuring elapsed time to activation of emergency lighting to the levels identified in the Emergency Lighting Intensity Levels Table.
A demonstration shall show the capability for crew egress and operational recovery tasks during a lighting failure. The verification shall be considered successful when test shows that emergency lighting can be automatically activated and illumination levels support operational recovery activities and the demonstration shows that unpowered emergency illumination sources support crew egress. Analysis Demonstration Test R.CLDS.040 3.3.2.1 PROTECTION FROM CABIN DEPRESSURIZATION The CVV shall provide LEA suits as an emergency system to protect each individual crewmember from a depressurized cabin during ascent and entry.
a. The LEA suit shall operate at a minimum pressure of 3.5 psia.
b. The LEA suit shall prevent hypoxia.
c. The LEA suit shall limit ppCO2 to less than 5 mm Hg to mitigate the effects of hypercapnia.
d. The LEA suit in conjunction with the vehicle ECLSS system shall mitigate risk of DCS per NASA-STD-3001 V2; V2 6008 DCS Risk Identification. Pressure suits for each crewmember are required to protect the crew when a large cabin leak causes depressurization to 0 psia. Both U.S. and Russian human space flight experience has demonstrated that the ascent/entry timeframe is highest risk period for catastrophic failures. The conversion of energy during these timeframes using the processes, materials, and structural factors of safety place the crew at a much greater risk during these flight phases. For these reasons and given the hazard time to effect, the crewmembers will wear pressure suits during ascent and entry. Pressure suits will protect the crew from the low-pressure cabin environment and allow the crew to take advantage of the spacecraft operability that exists below certified limits to return the crew to Earth. For short term operations in a spacesuit, the crew needs to be protected against hypoxia and decompression sickness. This requirement does not preclude the crew docking with the Destination in an emergency. V.CLDS.040 4.3.2.1 The CVV shall verify the ability to protect each individual crewmember from a depressurized cabin during ascent and entry by test and analysis.
a. A test shall be performed to show the LEA suit operates at a minimum pressure of 3.5 psia while in a reduced pressure cabin.
b. A test shall be performed with a flight representative O2 supply system to show that the LEA suit system provides nominal 100% O2 when operated in a depressurized cabin.
c. Testing shall be performed to show that the spacecraft systems and LEA suit limits ppCO2 to less than 5 mm Hg around the face area without violating the cabin nominal oxygen concentration limits. The test shall be performed at representative operational metabolic rates as shown in NASA/TP-2015-218570, Life Support Baseline Values and Assumptions Document and at ambient cabin conditions for nominal ascent and entry operations to show that the LEA suit limits ppCO2 to less than 5 mm Hg around the face area. The test shall also be performed to show that the LEA suit limits ppCO2 to less than 5 mm Hg around the face area when operated during reduced cabin pressure. Testing of the spacecraft shall be performed to show that the spacecraft can provide the necessary resources to the LEA suits to support keeping the ppCO2 levels in the face area to less than 5 mmHg without violating the cabin nominal oxygen concentration limits.
| d. An analysis shall be performed to show the LEA suit and spacecraft system will mitigate DCS per NASA-STD-3001 V2; V2 6008 DCS Risk Identification | The verification shall be considered successful when the LEA suit and spacecraft tests confirm that the suit operates at a minimum pressure of 3.5 psia, provides nominal 100% O2 when operated in a depressurized cabin, limits ppCO2 to less than 5 mm Hg around the face area in a nominal and depressurized cabin without violating the cabin nominal oxygen concentration limits, and demonstrates compliance with NASA-STD-3001 V2; V2 6008 DCS Risk Identification. | Test | ||||||
| R.CLDS.041 | 3.2.10 | CREW CAPABILITY TO OVERRIDE SOFTWARE | The CLDS shall provide the capability for the crew to override software functionality including shutdown when the transition from automated operations to manual operations will not cause a catastrophic event. | This is a specific capability necessary for the crew to control the integrated space vehicle and ensure crew survival. This allows the crew the capability to control and shutdown automated configuration changes and mode changes, including automated aborts, during all mission phases post launch vehicle separation. This is to be completed at the system level as long as the transition to manual control is feasible and will not cause a catastrophic event. The crew is to remain in ultimate control of the vehicle at all times throughout a mission. This allows the crew to manually override software control/automation. When a system has been shutdown, a restart is to be initiated by the crew only. | V.CLDS.041 | 4.2.10 | The CLDS shall verify manual override capability of the automation system by analysis and demonstration. |
The analysis will identify the automated tasks to be performed by the flight software. Hazard analysis will identify which automated tasks can be overridden without directly causing a catastrophic event.
The demonstration shall engage the automated system and have a human operator manually override each automated task identified in the analysis. The verification shall be considered successful when the demonstration shows that crew can manually override all identified automated tasks whose transition to manual control will not cause a catastrophic event, and that crew cannot manually override automated tasks where transition to manual override would cause a catastrophic event. Analysis Demonstration R.CLDS.042 3.2.2 OPERATION OF SYSTEM WITHOUT GROUND The CLDS shall provide the capability to operate Safety-Critical system and subsystem functions independent of ground mission support operations. This capability means crewed spacecraft do not depend on communication with ground personnel to perform functions that are required to keep the crew alive and return the crew safely. The intent of this requirement is for crewed space vehicles only, and not to drive an uncrewed capability. V.CLDS.042 4.2.2 The CLDS shall verify the operation of system and subsystem functions independent from ground by analysis and test.
A functional analysis shall determine the Safety Critical functions in compliance with CLDP-REQ-3102, Hazard Analysis and Safety Process Requirements.
The test shall perform that the Safety Critical functions defined by the functional analysis can be regulated without input from the ground control center. The verification shall be considered successful when the analysis and test shows that all identified critical functions can operate without input from ground. Analysis Test R.CLDS.043 3.3.3.1 PAD ABORT The CTS shall provide pad abort capability to protect the crew from a hazardous condition on the launch pad with a 95% probability of success with at least 90% confidence. During the final phase of the launch countdown when the crew has been secured in the vehicle, hazardous situations can arise which require the spacecraft to be quickly separated from the launch vehicle to protect the crew from imminent danger. For example, a launch vehicle propellant leak, impending explosion, or other hazardous situation may require the crew to utilize the pad abort capability to separate the spacecraft from the launch vehicle in a manner that allows a landing at a distance from the pad that protects the crew from the hazard. In order to protect the crew, the system must consider a wide range of hazardous situations, including an explosion of the launch vehicle. V.CLDS.043 4.3.3.1 The CTS shall verify pad abort capability requirement by test and analysis.
The tests shall determine the performance of the abort logic and abort flight systems.
Analysis shall include verified 6DOF simulations, including appropriate modeling of all systems affecting pad abort dynamics, along with their uncertainties. The analysis shall simulate the spacecraft's entire abort trajectory from abort initiation through landing location.
A ground propulsion system hotfire test shall verify performance of propulsion, avionics, and structural subsystems across all mission phases of the CVV, using a flight like integrated system test article. The abort capability shall be considered successful for each analysis if the aborting spacecraft demonstrates controllability, no near-field re-contact with the launch vehicle or ground infrastructure, operation within hardware thermal constraints, human capability constraints, structural loads limits, and ability to achieve acceptable landing.
The verification shall be considered successful when a Monte Carlo simulation of the required abort scenario with environmental and spacecraft dispersions achieve a 95% probability of success with at least 90% confidence.
See CLDP-STD-1140, "Integrated Abort Analysis" section for technical verification expectations.
Ground hotfire testing shall be considered successful when it demonstrates integrated propulsion system functionality and characterizes system performance. Analysis Test R.CLDS.044 3.3.3.1 DETERMINE ABORT MODE The CTS shall automatically and autonomously determine the mode for an abort. For many abort scenarios, the timeframe between the initiating event (engine, thrust vector control, or other significant failure) and the resulting catastrophic event is so short that a human cannot react quickly enough to prevent the loss of the crew. The dynamics of the separation event may result in temporary loss of communications with the CVCC; therefore, an automated system is needed onboard the spacecraft to determine the appropriate abort mode. V.CLDS.044 4.3.3.1 The CTS shall verify the automatic selection of abort modes by the spacecraft by analysis.
| The analysis shall include the conditions throughout the ascent flight phase and for different types of ascent aborts. The analysis shall include both nominal and off-nominal ascent trajectories to the CLD. | The verification shall be considered successful when the analysis shows that the probability is at least 99.865% with 90% confidence that the spacecraft automatically selects the correct abort mode for the conditions. | Analysis | ||||||
| R.CLDS.045 | 3.3.3.1 | DETECT AND INITIATE ABORT | The CTS IS shall detect and automatically initiate a pad and ascent abort when immediate abort is the only method of crew survival prior to nominal spacecraft separation from launch vehicle. | The primary emphasis of this capability is focused on launch vehicle failures where an immediate safe separation and return of the spacecraft will provide a chance for crew survival. However, spacecraft system failure modes are to be assessed to determine if the immediate response of an automated abort is necessary to save the crew as opposed to a manually initiated abort. Not all potentially catastrophic failures can be detected prior to manifestation. Similarly, system design and analysis cannot guarantee the crew will Survive all catastrophic failures of the launch system, but the abort system should provide the best possible chance for the crew to Survive. When an imminent catastrophic failure of the launch vehicle is detected, the time to effect requires the abort system to be initiated automatically. Also, if the catastrophic failure itself is detected by a monitoring system, the abort is initiated automatically. This is not intended to require independent implementation by the spacecraft of capabilities inherent to the launch vehicle. | V.CLDS.045 | 4.3.3.1 | The CTS IS shall verify the detection and automatic initiation of an abort by analysis and test. |
Safety analysis shall be used to identify the failure modes for which the monitoring system will be required to detect and initiate an abort. The analysis shall identify detection and confirmation methods including the maximum detection latency times for each failure.
The test shall be conducted using flight representative hardware and flight software for the launch vehicle, spacecraft, abort systems, and interfaces to Ground Systems. The test shall include worst case latency during pad and ascent flight phases and exercise all abort triggers. The tests shall determine the performance of the detection system and abort initiation logic. The verification shall be considered successful when the analysis shows, for identified failure modes, the space vehicle is able to detect the need for an abort with sufficient time for the crew to depart prior to catastrophic failure and the test shows successful performance of the detection system and abort initiation logic. Analysis Test R.CLDS.046 3.3.3.1 ASCENT ABORT The CTS shall provide continuous autonomous launch abort capability from lift-off through orbital insertion with a 95% probability of success with at least 90% confidence in the event of a loss of thrust or loss of attitude control. Flying a spacecraft through the atmosphere to orbit entails inherent risk.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .