Safety Approach.pdf
PDF 2 MB Posted
- Attached to
- Commercial Low Earth Orbit (LEO) Development Program Phase 2 Requirements and Safety Technical Interchange Meeting Federal contract opportunity
- Solicitation number
- 80JSC025REQ_SAFETY_TIM
About this file
This is a presentation outlining NASA's Commercial LEO Development Program (CLDP) safety approach strategy for commercial space stations and destinations. The presentation covers the program's safety requirements, processes, and risk management approach, including two failure tolerance to catastrophic hazards and single failure tolerance for critical hazards at destinations, crew survivability methods, Loss of Crew (LOC) and Loss of Mission (LOM) risk controls, and Design for Minimum Risk (DFMR) protocols.
The document details specific safety review processes, including hazard analysis requirements, configuration management, and emergency response protocols. It establishes a framework for transitioning from NASA oversight to commercial provider safety processes through a "Trusted Vendor" accreditation system. Key requirements include MMOD PNP assessments, collision avoidance, quantitative medical risk assessment, and failure tolerance variances requiring NASA approval. The presentation is part of a Technical Interchange Meeting scheduled for January 28, 2025, where NASA seeks industry feedback on draft documents CLDP-REQ-1130 and CLDP-REQ-3102, with responses due by February 14, 2025.
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
COMMERCIAL LEO
D E V E L O P M E N T P R O G R A M
Purpose
• Provide industry a look at NASA’s current approach to managing Loss of Crew and Loss of Mission risk
• Identifies considerations that informed the development of the current approach
• High lights key requirements that are a part risk management approach
• Provide industry an opportunity to comment and/or highlight concerns with the approach
• Comments or concerns should be Emailed to jsc-cldp-cdff@mail.nasa.gov by 2/10
• Please include Safety TIM 2 in the subject line
• A copy of the charts will be made available after the meeting mailto:jsc-cldp-cdff@mail.nasa.gov mailto:jsc-cldp-cdff@mail.nasa.gov
P R O G R A M
Section Content
• S&MA Approach Overview
• Goals
• Considerations
• Scope
• CLDP Safety Requirements
• Safety Requirements development
• Failure Tolerance
• CLDS Safety Approach
• Loss of Crew
• Loss of Mission
• Safety Threshold
• Recommendations and Forward Work
P R O G R A M
Safety Approach Overview
• CLDP’s safety approach pulls from CCP, ISS, and Gateway best practices and lessons learned
• ISS
• RISE
• Process ability to support high volume utilization
• Effectiveness of failure tolerance strategy
• CCP
• Implications of a commercial contract
• Effectiveness of failure tolerance strategy
• Gateway
• Human rating a destination
• The overall safety approach provides a commercially compatible implementation that provides for safe, robust, and cost-effective Low Earth Orbits services for NASA and its partners while ensuring CLD provider maintains safety responsibility and management of their systems supporting Commercial LEO goals.
P R O G R A M
Safety Approach Considerations
Support Agency Acquisition Strategy
• Goal to award more than1provider if possible
• NASA will not operate the destination or visiting vehicles
• NASA will human rate the service (for US government crew missions – CCP/CLDP joint activity)
• NASA is one of many customers and may not have crew on board continuously
Incorporate approaches from other NASA Program and lessons learned - Shuttle, ISS, CRS, CCP, Gateway, and Orion
Support Legacy visiting vehicles (crew and cargo) and heritage payloads
• Minimize administrative documentation and delta certification for transportation and Axiom CDISS where possible
• Avoid NASA driven changes to delta payload certification where possible
Meet the intent of NPR 8705.2 and NASA-STD-8719.29 and levy applicable requirements such as:
• Failure tolerance
• Crew survivability
• Loss of Crew (LOC)/ Loss of Mission (LOM)/PRA
Support Commercial Provider run safety processes since NASA may not always be participating in mission CCP will be responsible for commercial transportation certification and safety https://NASA-STD-8719.29
P R O G R A M
CLDP Safety Requirements Development
• Destination Human Rating Tailoring will be captured in SOMD-CSD-10001
• RFI released on 5/4/2022 (Destination only) – Key components included:
• PRA Loss of Crew/Loss of Mission and single failure tolerance for catastrophic hazards at the destination tailored to 2 failure tolerance to catastrophic hazards and single failure tolerance for critical hazards
• SOMD document baseline planned by 2QFY25
• Safety Requirements in CLDP-REQ-1130
• RFI released on 9/30/2023 (Transportation and Destination)
• Started with CCP-REQ-1130
• Verified that all applicable, current Human Rating Requirements (NPR 8705.2/ NASA-STD-8719.29) are included
• Verified requirements language reflects the CLD Services scope
• Ensure consistency and support for new and legacy vehicles
• Ensure requirements with overlapping effectivity address both the Visiting Vehicle, destination, and joint mission scope
• Added requirements unique to a destination mission
• Eliminated requirements that are derivable from higher level requirements to arrive at a minimal set of Level 2 requirements while maintaining traceability to the applicable Human Rating requirements
• Added content to address lessons learned from CCP
Forward work: Define requirements to control re-entry risk to the general public https://Verifiedthatallapplicable,currentHumanRatingRequirements(NPR8705.2/NASA-STD-8719.29
P R O G R A M
Destination Failure Tolerance Approach
2FT to Catastrophic hazards
•Loss of life, loss of crew return vehicle, permanent disabling injury are considered a catastrophic event •Evacuation of the CLD after 2 failures is acceptable as a third control to hazards whose only catastrophic effect is loss of crew.
1FT to Critical hazards
•A nondisabling personnel injury, severe occupational illness, loss of mission, loss of destination, or damage to the Crew Transport Vehicle.
•Loss of mission is early termination of a mission or the inability to support utilization •Reinforces the importance of maintaining a continuous human presence in Low Earth Orbit
Design for Minimum Risk (DFMR) and exceptions available as an equivalency to single or 2 FT in areas where standards and margin is used to prevent the hazard
From 8719.29 4.3.2 Note: An early mission termination utilizing nominal systems and operations is not considered to be part of "emergency equipment and systems," and may, therefore, be considered part of the failure tolerance of the system.
Proposed 1130 definition Verified Evacuation Method A verified evacuation method demonstrates the ability of the destination systems to alert the crew to a potentially catastrophic event and allow for the crew involved in the worst case activity (e.g., sleeping, maintenance, exercise, payload ops) to safe their area, translate to the crew return vehicle, undock, depart, reenter, descent, land, be recovered, and for the NASA Crew to be handed over to NASA.
P R O G R A M DFMR
• DFMR is an alternate approach to FT using the safety related properties and characteristics of the design to reduce the associated risk to an acceptable level.
• Based on NASA-STD-8719.29
• Other potentially catastrophic hazards that cannot be controlled using failure tolerance are exempted from the failure tolerance requirements with mandatory concurrence (as required by NPR 8705.2) from the Technical Authorities and the Director, JSC (for crew risk acceptance) provided the hazards are controlled through a defined process in which approved standards and margins are implemented that account for the absence of failure tolerance.
• The hazards of the system are controlled through a defined process (Captured CLDP-REQ-3102):
• Approved standards,
• Margin,
• Minimize the likelihood of occurrence,
• Capability of the material, the operating environment, and their known variability.
• DFMR can provide the equivalency of either one or two failure tolerance.
https://onNASA-STD-8719.29
P R O G R A M
Emergency Response
• Crew survivability analysis required by NPR 8705.2. Requires the design be assessed, crew survivability methods be identified as a part of the hazard analysis, and the results be captured in a crew survivability report.
• CLDP expanded the scope of the assessment to include all Emergency Response activities.
• Emergency Response Goal
• To establish a set of planned and executable emergency procedures analogous to what exist for aircraft, labs, offices, and ships. Emergency response activities cover activities to save the crew (Crew Survivability) and efforts to save the destination.
The end goal is to interrupt the progress of the hazardous event and/or provide a means to separate the crew from the hazardous event. At a minimum, the procedures need to ensure the safety of the crew.
• Emergency response analysis is part of CLD Service Hazard Analysis and is assessed as a part of the Safety Review
• Emergency response activities cover activities to save the crew (Crew Survivability) and efforts to save the destination(Destination Survivability).
• Takes into account that Emergency response, a traditional government responsibility, is now the responsibility of the Partner.
P R O G R A M
Crew Survivability
• Crew survival scenarios occur after all hazard controls have failed.
• Analysis required by NPR 8705.2 Human Rating Requirements for Space
Systems (HRR) and is described as:
• Identification of scenarios including system failures and emergencies (such as fire, collision, toxic atmosphere, decreasing atmospheric pressure, and medical emergencies) with specific capabilities (such as abort, safe haven, rescue, emergency egress, emergency systems, and emergency medical equipment or access to emergency medical care) identified to protect the crew.
• Crew survivability scenario hazard analysis is required for release of a hazardous substance, toxic environment, fire, depress, LOAC, and medical emergency response including return of injured crew
• Emergency response equipment and/or capabilities required for hazardous substance, toxic environment, fire, depress, LOAC, and medical emergency response including return of injured crew needs to be defined and verified
• C&W, detection methods, PPE, clean up equipment
P R O G R A M
Destination Survivability
• No requirements are levied on the CLDs to provide for destination recovery and/or survivability after the occurrence of a hazardous event.
• Expectation is that partners will want the ability to preserve their destination in the event of a potentially catastrophic event
• Hazardous release, MMOD strike resulting in depress, fire, etc.
• Destination survivability mitigations will be documented in the hazard analysis
• If US government personnel are involved in the response, then the procedures and associated hazard analysis will need to be reviewed, approved, and concurred with by NASA
P R O G R A M
Loss of Crew Approach – Destination
• Loss of Crew is captured in the definition of a catastrophic hazard
• An event with the potential for loss of life or permanently disabling injury or an event that results in the loss of a crew return vehicle.
• Controls and mitigations to prevent Loss of Crew
• Two failure tolerance to Loss of crew in lieu of Human Rating’s “a minimum of Single Failure Tolerance”
• Crew survivability methods/actions/procedures are required for hazardous substance release (gas, liquid, particulate), depress, fire, Loss of Attitude Control (LOAC), and medical emergency (emergencies)
• CLDP-REQ-1130 requirements for MMOD PNP and collision avoidance (PDAM)
• Quantitative assessment of medical risk
• Failure tolerance variances are NASA approved and include a NASA risk assessment (PRA where applicable)
• Post certification mission to mission risk monitoring
• Hazard analysis and CoFR address mission unique operations and deltas from the certified design
• MMOD risk maintained over Program life
• Crew medical risk maintained for each destination over Program life
• Failure tolerance variances are NASA approved and include a NASA risk assessment (PRA where applicable)
Note: Greater than 80% of ISS Loss of Crew risk is accounted for by MMOD and Crew medical events
P R O G R A M
Rationale for Destination Loss of Crew approach
• Approach selected to provide clear requirements on minimum levels of failure tolerance for Loss of Crew
• Not dependent on engineering judgement or PRA to determine where additional failure tolerance is required
• Accounts for the fact that providers are expected to be a PDR+ level of maturity at contract award
• NASA PRA not in the critical path for failure tolerance decisions
• Reduces likelihood of cost and schedule impacts related to late identification of a need for increased failure tolerance
• Less likely to identify the need for additional failure tolerance post contract award
• Allows design flexibility for hazards with long time to effects
• Avoids being zero failure tolerant to an immediately catastrophic failure after the first failure
• Avoids having to prove a design is not safe enough to drive additional failure tolerance
• Approach not impacted by commercial provider unique services
• Key contributors to loss of crew (MMOD and Crew Medical Event) still monitored to understand how risk is evolving
• Provides additional robustness for a destination with multi-year, continuous operations without the ability to return for refurbishment
• Enhanced Crew survivability approach that exceeds current Human Rating requirements
P R O G R A M
Loss of Mission Approach – Destination
• Loss of Mission is captured in the definition of a critical hazard
• A hazard with a potential for non-disabling personnel injury or severe occupational illness; loss of Destination, mission, or the ability to support a crewed mission over the planned mission duration
• Controls and mitigations to prevent Loss of Mission
• Single failure tolerance to critical hazard in lieu of a quantitative requirement
• CLDP-REQ-1130 requirements for MMOD PNP and collision avoidance (PDAM)
• Quantitative assessment of medical risk
• Failure tolerance variances are NASA approved and include a NASA risk assessment (PRA where applicable)
• Leverage contract payment structure to incentivize meeting NASA requirements (time on orbit, facility up time, crew time available for utilization)
• Similar to Cargo Resupply Services Contract approach
• Specifically for Loss of Destination - Leverage industry “skin in the game” and ownership of the vehicle to drive decisions impacting
LOM.
• Post certification mission to mission risk monitoring
• Hazard analysis and CoFR address mission unique operations and deltas from the certified design
• CLDP-REQ-1130 requirements for MMOD PNP and collision avoidance (PDAM)
• Quantitative assessment of medical risk
• Failure tolerance variances are NASA approved and include a NASA risk assessment (PRA where applicable)
• Leverage post flight reviews and contract payment structure to incentivize Provider decision making (time on orbit, facility up time, crew time available for utilization)
Greater than 80% of ISS Loss of Mission risk is accounted for by MMOD and Crew medical events NOTE: Loss of destination is not considered catastrophic in this approach which is different than ISSP concentrating requirements on crew safety and relying on mitigations below.
P R O G R A M
Rationale for Loss of Mission approach
• Approach provides a failure tolerance requirement for Loss of Mission
• Not dependent on engineering judgement or PRA to determine where failure tolerance is required
• Accounts for the fact that providers are expected to be a PDR+ level of maturity at contract award
• NASA PRA not in the critical path for failure tolerance decisions
• Reduces likelihood of cost and schedule impacts related to late identification of a need for increased failure tolerance
• Less likely to identify the need for failure tolerance post contract award
• Providers are not penalized for larger crew sizes (Loss of mission due to crew medical event is directly related to crew size)
• Proposed contract payment structure to reimburse based on mission metrics provides incentives to reduce likelihood of Mission impacts (time on orbit, facility up time, crew time available for utilization)
• Approach not impacted by commercial provider unique services
• Key contributors to loss of mission still monitored to understand how risk is evolving
(MMOD and Crew Medical Event)
• Provides for additional robustness for a destination with multi-year, continuous operations
P R O G R A M
Overall CLD Transportation System Failure tolerance Approach
• Crew Transportation System (CTS) Failure Tolerance will remain the same
• Existing variance will be assessed to determine if modifications are required to reflect differences between ISS and the Destination
• Any updates will be reviewed through the nominal process
• CTS Predeclared Exceptions
• Same CTS exception for structures captured in the failure tolerance requirement text (existing exemption equivalent to failure tolerance)
• Same CTS exceptions for functional failure tolerance by mission phase
• Launch vehicle failure tolerance
• Two failure tolerance or dissimilar redundancy for critical functions
• Visiting Vehicles within Approach Ellipsoid follow the same 2 Failure Tolerant strategy that was used by the ISS Program (SSP 41162/SSP 50808)
P R O G R A M
Overall CLD Transportation System Approach
• Crew Transportation System (CTS) Failure Tolerance will remain the same
• Existing variance will be assessed to determine if modifications are required to reflect differences between
ISS and the Destination
• Any updates will be reviewed through the nominal process
• CTS Predeclared Exceptions
• Same CTS exception for structures captured in the failure tolerance requirement text
(existing exemption equivalent to failure tolerance)
• Same CTS exceptions for functional failure tolerance by mission phase
• Launch vehicle failure tolerance
• Two failure tolerance or dissimilar redundancy for critical functions
• CTS Loss of Crew and Loss of Mission Approach is unchanged for existing systems
• Visiting Vehicles within Approach Ellipsoid follow the same 2 Failure Tolerant strategy that was used by the ISS Program (SSP 41162/SSP 50808)
P R O G R A M
Summary and Forward Work
• Summary
• CLDP’s proposed safety threshold maintains “levels of crew safety equivalent to ISS crew safety”
• Rationale based on failure tolerance, probabilistic requirements for orbital debris penetration and crew medical risk modeling
• Does not include a “Loss of Crew” metric
• No safety goals above the baseline threshold
• Establishes a recurring safety assessment process administered by the program
• Forward Work
• Finalize and release the baseline version of CLDP-REQ-1130 (NET Jan 2025)
• Hold second Safety TIM with industry to review Safety Approach and Strategy
(ECD TBD; NLT January 2025)
• Comments and feedback to be collected during 1 on 1's post TIM
• Define requirements to control deorbit/ re-entry risk to the general public
ISS (SSP 30599) CLDP (CLDP-REQ-3102)
Risk Paper Approval Authority Compliance Safety Paper Risk Paper Approval Authority Compliance Safety
Paper Risk Paper Approval Authority
(catastrophic, Option 2 shown)
Safety Technical Review Board
HRs – failure Tolerance controls Safety Review Panel HRs – failure
Tolerance controls
DFMR can end up as Eq Safety or Program Level Variances
Safety Technical Review Board HRs – DFMR controls Safety Review Panel
HRs – DFMR/Exceptions controls
Eq Safety Variances
Safety Technical Review Board
Eq Safety NCRs (delegation letter), moving to be in structured HRs
Safety Review Panel (delegated) Eq Safety NCRs
Program Level NCRs Program CB Program Level NCRs Program CB Program Level NCRs Program CB
Gateway (GP 10024) Orion (MPCV 70038 and/or ESD 10010) (Risk Informed Process) (Risk Informed Process)
Compliance Safety Paper Risk Paper Approval Authority Compliance Safety
Paper Risk Paper Approval Authority (catastrophic) (catastrophic)
HRs Likelihood 1-2: (as appropriate)
Level 2 Safety Review Panel Approval OR Level 3 Control Board (can be delegated) Likelihood 3 & 4:
Program CB Likelihood 5:
Administrator
Likelihood 1-2: (as appropriate)
Joint Program CB (Integrated)
OR
MPCV Program CB (MPCV Only)
Likelihood 3 & 4: ESD CB Likelihood 5:
Administrator
HRs - Exemption A (specifically defined DFMR- essentially structures and models)
HRs - Exemption B (any non-compliance and non-specified DFMR) – rationale could be reliability-informed
HRs - Exemption B (any non-compliance and non-specified DFMR)
Waivers (temporary exemption or risk increase associated ith h ft
Human Rating Waivers:
HQ OSMA (for Human Rating Waivers), TAs, JSC Center Director or 25
CCP (CCP-PLN-1120)
(Compliance Based Process)
Compliance Safety Paper
HRs – failure Tolerance controls and exemption for primary structure and structural failure of pressure vessels
Key takeaways: Overview of how different programs have assessed and approved safety compliance and risk.
Compliance based Programs operate from a risk baseline established in the requirements. Violation of the requirements (delta risk) requires Program Manager approval.
The Gateway Program and MPCV Program use risk informed processes. A minimum of 1FT is generically levied, but the appropriate level for each hazard should be based on risk balanced against other design constraints.
Additionally, exemptions to FT are written directly into the HR as long as the safety review panel (TAs, chair, etc.)
concur. Because HRs are risk acceptance documents, the Program Manager (or delegate) must approve them.
Assessed risk determines the level of approval required.
January 28 2025
P R O G R A M
CLDP Safety Review Process
• The Safety Review process supports NASA’s Human Rating of the CLDP Services Mission for USG Crew
• Ensures that the design controls hazards and related risks are mitigated to an acceptable level
• Systematically reviews the Mission to identify and document safety risk (likelihood and consequence)
• Identifies controls and verifications options to reduce the likelihood and/or severity of a hazard
• For CCP greater than 50% of requirements were derived through the safety process
• Documents how standards and process controls are applied to control safety risk
• Assesses the design for compliance with Failure tolerance requirements
• Identifies and baselines DFMR exemptions
• Identifies crew survivability opportunities and assesses them to determine feasibility and residual risks
• Hazard analysis is required for release of a hazardous substance release, toxic environment, fire, depress, LOAC, and medical emergency response including return of injured crew
• Assesses Destination survivability mitigations to ensure efforts to save/recover the destination after a hazard is realized do not expose the crew to unacceptable risk
P R O G R A M
Safety Review Assumptions
• CLDP Provider is responsible for the safety of the destination and its occupants
• CLDP Provider develops and maintains hazard analysis for the end-to-end mission
• CLDP Provider is responsible for the integrated safety of payloads and operations
• NASA participates in the safety process using insight (flight following and surveillance/participation in safety reviews) and oversight activities (Joint safety reviews and DRDs)
• Visiting Vehicle Provider is responsible for the safety of the Vehicle and its occupants
• Develops and maintains hazard analysis for the end-to-end mission
• Coordinates with Destinations and Utilization providers to ensure safe delivery/return (and disposal) of crew and utilization
• NASA participates in the safety process using insight (flight following and surveillance/participation in safety reviews) and oversight activities (Joint safety reviews and DRDs)
• NASA is responsible for ensuring the safety and well being of the USG crew during their mission and has responsibility for supporting NASA payload safety
• Need to maintain insight and confidence in Partner activities
• Need to support partner payload safety process and provide oversight as required
• Payload Provider is responsible for the safety of their end item/hardware
• There may be periods of time between USG Crews (~6 months)
• Need streamlined insight approach and program processes to maintain cognizance of the readiness of the destination for future missions
• NASA is intended to be one of many customers
P R O G R A M
CLDP Safety Process Requirements
• CLDP Safety Process Requirements are documented in CLDP-REQ-3102, Commercial Low
Earth Orbit Development Program Hazard Analysis Process Requirements Document
• Document is a blend of ISS (SSP 30599) and Gateway (GP 10024) Hazard analysis and safety process requirements
• Planned to be released to industry as part of an August Safety TIM
• Focused on defining the Program’s Hazard Analysis approach and supporting Human Rating Process
Requirements
• CLDP-REQ-3102 establishes the requirements Safety Analysis (NPR 8705.2 2.2.3)
• Includes requirements analyzing and controlling software and human error contributions to the realization of hazards
• Requirements for identification, maturing, and analyzing of crew survival approaches (NPR 8705.2 2.3)
• Includes requirements for identification and analyzing of Destination survival methods
• Includes process to baseline and approve DFMR approaches
• CLDP-REQ-3102 is Program approved and in the final signature loop
P R O G R A M
Destination Safety Process Requirements
Documented safety process based on CLDP-REQ-3102 •Provider has NASA approved Hazard Analysis and process requirements •Structured compliance-based Review •Partner management risk acceptance •Closed loop verification process with traceability from Hazard reports to as implemented verification artifacts •Captures and assesses data required to support NASA’s Human Rating of USG crewed missions •Identification, tracking, and formal risk acceptance of Safety noncompliances
Safety Requirements •Provider has developed and allocated detailed vehicle/system safety requirements •Includes Design and Construction standards and requirements associated with NASA approved DFMR approaches •Provider has developed payload safety requirements and/or IRD (SSP 51721, SSP 50835, SSP 57000, SSP 57003) •Provider developed VV IRD with integrated safety requirements (SSP 50808 equivalent)
Chartered safety “Board” •Defines Provider review team/ mandatory and ad hoc membership •Defines authority of the safety panel •Identifies formal dissent process •Identifies reporting to and obtaining “approval” from the Destinations’ Program Manager
P R O G R A M Destination Safety Process Requirements
Cont.
Configuration management process for HRs, noncompliance data, supporting data (including Emergency Response), and verification data
• Accessible by NASA, Destination Operators, VV operators (as applicable), and Payload Operators (as applicable)
• Action Capture and Tracking
• Method to identify, track, and resolve errors/discrepancies in approved hazard reports
• Capture of minutes for safety reviews, WGs, and OSB meetings
• Maintain master schedule for payload, end item, integrated safety reviews
• Closed loop tracking of hazard controls and verification through implementation
Equivalent Operational Control Implementation process
• Captures hazard controls implemented in training, flight rules, and/or flight procedures
• Provides traceability from HR to implementation
• Provides real time status of implementation
• Identification of hazard controls in Ops Products (Flight Rules, Procedures, Etc.)
Provisions for NASA access to safety data
• Hazard reports are type 1 DRD
P R O G R A M
CLDP Safety Reviews - Phase 1(Pre-Contract Award)
• For each of the Partners under Phase 1 Space Act Agreements (SAAs) or CDISS contract, NASA will participate (as invited) in their internal safety review process to provide early insight and feedback as design matures
• Many providers will complete Phase 0, I and potentially II Safety Reviews prior to Phase 2 contract award
• Partner process will be utilized to:
• Support the identification and classification of hazards
• Identify potential technical gaps in Partner processes
• Gain insight into the capability of the Partner’s safety process
• NASA participation
• May be limited based on resource availability
• Will not address compliance with requirements and processes
• Based on Partner approval to participate
NOTE: All CLD-FF partners have requests/allowed NASA to participate to date and are interested in NASA feedback
P R O G R A M CLDP Safety Reviews (under Destination Services Contract)
• Reviews are nominally led by the Provider
• NASA may lead reviews if Provider requests as a government service or does not have an established processes and/or infrastructure
• NASA review team is led by the Program with primary responsibility for certification
• CLDP SRB leads Destination only reviews
• CCP STRB leads reviews for activities outside the AE
• Visiting vehicle Integrated Operations are co-chaired by CCP and CLDP
• Board Membership
• Partner SRB - Partner determines the composition of its safety board
• Follows CLDP-REQ-3102 Process
• CLDP SRB - Chaired by CLDP
• Follows CLDB-P-4007, Commercial Low-Earth Orbit (LEO) Development Program Office (CLDPO) CLDP Safety Review Board Charter and Process
• CLDP Safety Board has representatives from CLD SE&I, CLDP Vehicle Office, CLDP Operations and Training Office, S&MA TA, Engineering TA, and Health and Medical TA, and FOD
• CCP STRB - Chaired by CCP
• Follows CCT-P-4003, Commercial Crew Program Safety Technical Review Board Charter and Process
• The CCP STRB has representatives from CCP Spacecraft Systems Office, CCP Launch Vehicle Systems
Office, CCP Ground and Mission Operations Office, Chief Safety Officer (CSO), Chief Engineer, Chief Health and Medical Officer, and FOD
• Delta Phase 1 review conducted shortly after contract award
P R O G R A M
Safety Review Scope (under Destination Services Contract)
• Joint Safety reviews will focus on impacts to the NASA crew
• Common environment
• Visiting vehicle operations that impact the US government
Crew
• US government Crew crew activities
• Safety Reviews are compliance based and associated with Certification of the Destination Services
• Assessed against the Initial Operating Capability baseline design and operational concept
• Ensure the Destination, Visiting Vehicles, Payload Systems, and operations have been assessed for compliance to requirements both as independent end items, part of integrated operations (within the Approach Ellipsoid), and as part of an integrated system (Cargo Vehicle, Crew Vehicle, other free flyers)
P R O G R A M
Safety Review Updates(under Destination Services Contract)
• After approval of Destination services for IOC, additional safety reviews will be required for each Increment to address changes to operations and vehicle configuration to:
• Ensures that the Destination Services are operating within their certification
• Assess changes in controls or verification approach
• Assess new visiting vehicles, modules and/or capabilities, etc.
• This includes vehicle changes associated with evolutionary capabilities or assembly missions that occur after IOC
• Mission analysis not complete at the start of the increment will be tracked as open work and completed prior to initiation of mission related activities.
• Cargo mission and associated payloads and cargo will be analyzed prior to flight
• Critical operations will be assessed prior to execution
• Mission to mission changes are reviewed and approved as part of the CoFR process
• Significant changes may also require an update to the Destination’s Human Rating
Certification such as:
• Changes in how failure tolerance requirements are satisfied
• Addition of new modules
• Changes in operations that impact the overall risk profile for the mission
P R O G R A M
Historic Safety Process Challenges
• Unclear and incomplete understanding of expectations
• Partner and NASA issue
• Disconnect between working level teams and management regarding status
• Partner and NASA issue
• Schedule and resource challenges
• Partner and NASA issue
• Not completing or combining early phase reviews
• Increases rework and increases resources needed to catch up
• Failure to understand what the Hazard process does ~50% of hazard controls/verifications are derived
• Late low-quality deliveries
• Design and safety analysis worked independently and in parallel with the design
• Driven by schedule and resource challenges
• Failing to elevate risk and policy issues that have reached an impasse in panel
P R O G R A M
Safety Process Mitigations – Phase 2
• Establish an integrated hazard analysis schedule with Partners at the beginning of Phase 2
• Track performance to plan and brief at quarterlies
• Set expectations for panel and support teams
• Focus on having a consistent core team supporting reviews
• Track and manage performance to expectations
• Familiarization training for participants
• Establish a standard presentation template for hazard reports and causes
• Avoid line by line review
• Criteria for elevation to Program Control Board when Panel reaches a technical impasse
P R O G R A M
Partner Safety Review - Trusted Vendor
• CLDP is developing a process based on ISS Safety Review Panel Franchise agreements to incrementally transition safety reviews from a joint NASA and Partner forum to a NASA accredited Commercial Provider Safety Process
• Establishes that the Partner has the resources, processes, and demonstrated capability to perform a safety review in accordance with CLDP-REQ-3102 without NASA joint board or NASA approval process (Surveillance will still occur)
• Accreditation is not schedule driven, but a reflection partner process maturity and capability
• Based on pre-established criteria and demonstrated success
• Supports the commercialization of the LEO Economy
• The Trusted Vendor accreditation process includes endorsements for technical areas that reflect the ability to perform associated reviews and is expected to be incremental
• Sample endorsements
• Materials only hazards
• Standard hazards
• CBCS
• Pressure Systems
• Once a partner receives accreditation, NASA will use surveillance to ensure that partner capabilities and processes remain at an acceptable level
• Integrated and Vehicle level/module safety reviews are not planned to be part of the trusted vendor process
P R O G R A M
Trusted Vendor Timeline
• Prior to Phase 2 contract award
• Focus is on confidence building and working with the Partner to mature their safety process
• Partners are able to demonstrate and refine their process
• After Contract award and safety process DRD delivery (prior to accreditation)
• Initial assessment of process maturity
• Perform Joint reviews with the Partner through initial flight
• Assess partner compliance with their safety process
• Assess the effectiveness of Safety Review Board and Process
• As partners matures in areas accredit/ partially accredit them to review products in that area
• Post accreditation
• Audit/ maintain insight partner performance
• Delta accreditation based on process escapes, key personnel changes, and/or process changes
P R O G R A M
Partner Endorsement Levels
• Review Levels
• Joint Panel (NASA or Partner led)
• NASA participation
• Full accreditation (Audit and surveillance of products and processes)
Fully Compliant Equivalent Safety NCR Program NCRs
Accreditation area (Simple Payloads)
Full NASA Participation
Endorsement
NASA Participation
P R O G R A M
Considerations for LOC/LOM tailoring recommendation
• Requirements for successful LOC/LOM implementation
• Agency quantitative risk thresholds (Acquisition limit and Program requirement values)(How much risk is acceptable for NASA Crew on a CLD)
• LOC – Loss of Crew
• Define standard NASA DRM(s)
• Loss of Crew (LOC) metrics dependent on DRM
• Duration
• Standard mission profile
• Destination resources and capability definition
• CLDP PRA Resources
• Partner reliability data (source and heritage)
• Partner hardware description (size/capability, technology, heritage, quality level)
• Partner architecture data
• Reliability prediction updates based on operational experience (Operating hours and failure history)
Fundamental Challenge: How to create a meaningful metric that captures risk without penalizing innovation
P R O G R A M
LOC implementation on 2 phase Commercial Services procurement
• Traditionally (ref: Gafka 2012) PRA has served two main functions:
• To drive system design to improve overall safety
• To communicate relative risk on a mission or inherent in an architecture to stakeholder communities
• In a commercial multi-phase procurement model, using PRA to drive the design is impractical (CCP Lesson learned)
• By the time requirements are levied in a “Phase 2” contract, major architectural decisions are already made
• Changing design after contract award comes with significant cost/schedule/technical risk impacts
• Destination capabilities are driven by market forces, internal needs and not solely by NASA requirements (e.g. at least 2 Destinations have proposed an EVA capability, but EVA is not required by NASA)
• Testing to verify and validate reliability is cost and schedule prohibitive
P R O G R A M
Recommended approach
• System Design Risk Mitigation
• Two failure tolerance to Loss of crew in lieu of Human Rating’s “a minimum of Single Failure Tolerance”
• Single failure tolerance to loss of mission in lieu of a quantitative requirement
• Crew survivability methods/actions/procedures are required for hazardous substance release (gas, liquid, particulate), depress, fire, Loss of Attitude Control (LOAC), and medical emergency (emergencies)
• CLDP-REQ-1130 requirements for MMOD PNP and collision avoidance (PDAM)
• Quantitative assessment of medical risk
• NASA PRA for failure tolerance variances
• Mission to mission risk monitoring
• Greater than 80% of ISS risk is accounted for in MMOD and Crew medical
• MMOD risk maintained over Program life
• Crew medical risk maintained for each destination over Program life
• NASA PRA for failure tolerance variances and dynamic operations
• Continue to evaluate on ramping Loss of Crew metric for operational phase of program
P R O G R A M
Proposed Definitions for PRA Metric Option Trade Options
• Loss of Crew
• Limited to loss of NASA Crew
• Based on the likelihood of an event that would result in the loss of one or more crew
• Does not include commercial astronauts
• No requirements/ limitations on the number of commercial astronauts on the destination
• Early provider discussions include expanding access to LEO to crew beyond the historic selection criteria (Crew would still need to meet a minimum NASA standard)
• Alternate option
• Likelihood of loss of any crew
• Since Loss of Crew likelihood is directly tied to the total number of crew on a destination, metric would capture non-NASA owned/controlled risk
• Can be influenced by services not requirement by NASA (EVA)
P R O G R A M Loss of Crew
MMOD PhenomenologicalFire
Human Error Human Contribution Loss of CrewMedical
Destination System Visiting Vehicles contribution
• Each of the contributors are independent
• MMOD – Model that will be submitted/ verified as part of the PNP requirement
• Fire – Model based on fire contributors, system capabilities, and operational response
• Medical – is a model generated by HH&P that is based on NASA Crew selection requirements, on orbit medical capability, number of crew, and standard mission duration
• Human error – Human reliability analysis based on critical tasks list
• Destination, VV – Hardware contribution (modeling options, details, and approaches are discussed later)
P R O G R A M
System contribution
• System contribution consist software, hazardous hardware failures
(pressure vessel rupture, battery thermal runaway, etc.), and hardware functional contributions that contribute to an end state
• Each contributor can be determined independently
• Software
• Can be calculated as a percentage of the hardware functional contribution
• Software Reliability prediction tool (e.g. REQUS AI PREDICT)
• Hazardous hardware failures
• Modeled/calculated
• Hardware functional contributions
• Modeled/calculated
• MMOD contribution calculated
P R O G R A M
Proposed Definitions for PRA Metric Option
• Loss of Mission scoped to be loss of Destination
• CLDP’s primary mission is to maintain a continuous US presence in LEO
• Early termination of an “increment” is considered a critical hazard
(Single failure tolerant to the event occurring) but not a LOM event
• Limits definition to design/ mission content within the scope of NASA’s certification activities
• Alternate definition: Loss of mission scope to early “increment” termination
• Captures potential impacts to science objectives
• Since Loss of Mission likelihood is directly tied to the total number of crew on a destination, metric would capture non NASA owned/controlled risk
P R O G R A M Loss of Destination
MMOD PhenomenologicalFire
Human Error Human Contribution Loss of Destination (Loss of Mission)
Destination System Visiting Vehicles contribution
• Each of the contributors are independent
• MMOD – Model that will be submitted/ verified as part of the PNP requirement
• Fire – Model based on fire contributors, system capabilities, and operational response
• Human error – Human reliability analysis based on critical tasks list
• Destination, VV – Hardware contribution (modeling options, details, and approaches are discussed later)
P R O G R A M
System contribution
• System contribution consist software, hazardous hardware failures
(pressure vessel rupture, battery thermal runaway, etc.), and hardware functional contributions that contribute to an end state
• Each contributor can be determined independently
• Software
• Can be calculated as a percentage of the hardware functional contribution
• Software Reliability prediction tool (e.g. REQUS AI PREDICT)
• Hazardous hardware failures
• Modeled/calculated
• Hardware functional contributions
• Modeled/calculated
• MMOD contribution calculated
P R O G R A M
What CLDF Probabilistic Requirements would look like if levied…
• Destination Loss of Crew (LOC) – The CD-FF Probability of LOC goal shall have a mean value no greater than 1 in 100 (TBR), for a one-year crewed mission with 2 crewed sorties. (1000X requirement)
• Destination Loss of Mission (LOM) – Probability of LOM shall have a mean value no greater than 1 in 20(TBR), for a one-year mission with 2 crewed sorties and 2 cargo vehicles. (1000X requirement).
• CD-FF Reliability – The CD-FF shall have an annual predicted system hardware reliability of .98 (TBR) for its defined mission environment and destination life.
Corrective maintenance may be used to achieve the reliability requirement.
(1130 Requirement)
• Destination Reliability – The CD-FF shall have an annual predicted reliability of .996 (TBR) over a year for functions required to keep the Destination in orbit. Corrective maintenance may be used to achieve the reliability requirement. (1130 Requirement)
P R O G R A M MMOD Analysis
• ISS PRA gets MMOD risk by module from the Astromaterials Research and Exploration Science Division (XI), who provide us with results from the new Orbital Debris Engineering Model (ORDEM) and Meteoroid Environment Model (MEM)
• The updated ORDEM environment model now includes five different debris densities (including aluminum and steel), three-dimensional threat directions, new debris events, and improved speed distribution
• XI uses a Monte Carlo simulator to estimate overall penetration risk from MMOD particle penetration and examines the end state in the event of a penetration
• ISS PRA uses the results from XI’s model (probability of each consequence for each module) in our fault tree model; the probabilities in our basic events are taken directly from the probabilities provided to us by XI
P R O G R A M Environments
• The micrometeoroid environment and orbital debris environments are modeled independently; the models are maintained independently
• The Orbital Debris environment (ORDEM) models the man-made debris that results from satellite breakups and other events
• Maintained by the Orbital Debris Program Office (ODPO) at JSC
• The Micrometeoroid environment (MEM) models naturally occurring particles in space
• Maintained by the Meteoroid Environment Office (MEO) at MSFC
• Used to determine flux that would impact the ISS over a period of time
P R O G R A M Shield Response
• The Shield Response describes what impacts cause failure
• Ballistic Limit Equations (BLEs) are determined by hypervelocity impact testing of the shield configurations; the BLEs determine whether an impact causes a failure and is a function of impact angle, particle size, particle material, and impact velocity
• The ISS Testing and BLEs are determined by JSC/XI via the Hypervelocity Impact Technology Facility (HVIT); the testing is often performed at the White Sands Test Facility (WSTF)
• BLEs are written to a selected failure criteria, most often detached spall or perforation
P R O G R A M
ISS Surface Model & Analysis Run
• A surface model of the ISS is constructed with regions of the surface marked by property identifiers linked to the shield properties & proper BLE and is oriented with respect to the environments to gather flux data; the ISS MMOD surface model is maintained by XI
• The Analysis Runs which generate the Probability of No Penetration (PNP) data are performed by BUMPER II, a tool maintained by XI
• BUMPER II uses an ISS Surface Model, BLEs associated with each region of the ISS, ORDEM and MEM environments, and other inputs/post processing (such as duration) to deliver PNP values;
BUMPER II determines the flux in terms of particle density and size, and impact angle and velocity, through each shield region of the model that exceeds the BLE and therefore the number of penetrations (which also mathematically determines PNP)
P R O G R A M Parsing for End States
• To present the MMOD results in terms of specific End States, the Manned Spacecraft Crew Survivability (MSCSurv) code is used;
MSCSurv is maintained by XI
• MSCSurv uses a Monte Carlo simulation specific to each shield region, determines the relative frequency of each end state, and delivers factors to parse the PNP value into a PNP-like number for each end state of concern in that region; accumulated, these results are the familiar “1 in X for EVAC for 6 months”
P R O G R A M
Formula
= 𝑒𝑒−𝜆𝜆𝑡𝑡 : t > 0 𝑅𝑅 𝑡𝑡
𝑀𝑀𝑀𝑀𝑀𝑀𝑀𝑀 =
𝜆𝜆
P R O G R A M
Number of test hours required to verify a MTBF Inputs:
Required reliability, R(t): 0.90 Mission time, t: 87,600 hours (ten years).
Allowable failures: 0 Confidence: 70% A reliability of 0.90 at mission time 87,600 hours is equivalent to an MTBF of 831,431 hours, assuming an exponential failure distribution.
Solution:
1,001,020 total test hours are required, with 0 allowable failures occurring, to demonstrate a unit reliability of 0.90 for a 87,600 hour mission, with 70% confidence.
P R O G R A M
Number of test hours required to verify a MTBF Inputs:
Required reliability, R(t): 0.97 Mission time, t: 87,600 hours (10 Years).
Allowable failures: 0 Confidence: 70% A reliability of 0.97 at mission time 87,600 hours is equivalent to an MTBF of 2,693,463 hours, assuming an exponential failure distribution.
Solution:
3,242,856 total test hours are required, with 0 allowable failures occurring, to demonstrate a unit reliability of 0.97 for a 87,600 hour mission, with 70% confidence.
Confidence: 70% A reliability of 0.97 at mission time 87,600 hours is equivalent to an MTBF of 2,693,463 hours, assuming an exponential failure distribution.
Solution:
1,866,966 total test hours are required, with 0 allowable failures occurring, to demonstrate a unit reliability of 0.97 for a 87,600 hour mission, with 50% confidence.
https://R(t):0.97
| Slide Number 1 |
| Purpose |
| Section Content |
| Safety Approach Overview |
| Commercial LEO Safety Goals |
| Safety Approach Considerations |
| Slide Number 7 |
| CLDP Safety Requirements |
| CLDP Safety Requirements Development |
| Destination Failure Tolerance Approach |
| DFMR |
| DFMR versus FT |
| FT requirements/DFMR Decision Flow |
| Emergency Response |
| Crew Survivability |
| Destination Survivability |
| Loss of Crew Approach – Destination |
| Rationale for Destination Loss of Crew approach |
| Loss of Mission Approach – Destination |
| Rationale for Loss of Mission approach |
| Overall CLD Transportation System Failure tolerance Approach |
| Overall CLD Transportation System Approach |
| Summary and Forward Work |
| Safety Process |
| Slide Number 25 |
| CLDP Safety Review Process |
| Safety Review Assumptions |
| CLDP Safety Process Requirements |
| Destination Safety Process Requirements |
| Destination Safety Process Requirements Cont. |
| CLDP Safety Reviews - Phase 1(Pre-Contract Award) |
| CLDP Safety Reviews (under Destination Services Contract)� |
| Safety Review Scope (under Destination Services Contract)� |
| Safety Review Updates(under Destination Services Contract)�� |
| Historic Safety Process Challenges |
| Safety Process Mitigations – Phase 2 |
| Partner Safety Review - Trusted Vendor |
| Trusted Vendor Timeline |
| Trusted Vendor Accreditation Schedule |
| Slide Number 40 |
| Partner Endorsement Levels |
| Key takeaways |
| Back-up |
| Loss of Crew Metric �Trade |
| Considerations for LOC/LOM tailoring recommendation |
| LOC implementation on 2 phase Commercial Services procurement |
| Recommended approach |
| Proposed Definitions for PRA Metric Option Trade Options |
| Loss of Crew |
| System contribution |
| Proposed Definitions for PRA Metric Option |
| Loss of Destination |
| System contribution |
| What CLDF Probabilistic Requirements would look like if levied… |
| MMOD Analysis |
| Slide Number 56 |
| Environments |
| Shield Response |
| � |
| Parsing for End States |
| Formula |
| Number of test hours required to verify a MTBF |
| Number of test hours required to verify a MTBF |
File details come from the government source that posted it. Updated .