safety/security concerns when automating slr systems · safety/security concerns when automating...

15
ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 1 Space Geodesy Satellite Laser Ranging Howard Donovan 2 , Scott Wetzel 2 , Donald Patterson 2 , Julie Horvath 2 , Alice Nelson 2 , Jan McGarry 1 , Evan Hoffman 1 , John, Cheek 3 1 NASA Goddard Space Flight Center 2 KBRwyle (formerly HTSI) 3 Sigma Space Corporation Safety/Security Concerns when Automating SLR Systems

Upload: others

Post on 06-Aug-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 1

Space Geodesy Satellite Laser Ranging

HowardDonovan2,ScottWetzel2,DonaldPatterson2,JulieHorvath2,AliceNelson2,JanMcGarry1,EvanHoffman1,John,Cheek3

1NASAGoddardSpaceFlightCenter2KBRwyle (formerlyHTSI)3SigmaSpaceCorporation

Safety/SecurityConcernswhenAutomatingSLRSystems

Page 2: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 2

Abstract

Safety/SecurityConcernswhenAutomatingSLRSystems

Thispresentationfocusesontheidentification,analysisandassessmentofsafetyandsecurityissuesnecessarytoachievingautomationofSLRsystems.ThefocuswillbeonSGSLRbutwillberelevanttoanySLRsystem.Areasofconsiderationincludeautomationregulatoryanalysis,hazardanalysis,situationknowledgeandaction,supportingsafetysystems,hazardreporting,ITSecurity,andoverallsiteassessment.Thepresentationwilldiscusswhatisneededduringdesign,implementationandverificationofthesystem.

Page 3: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 3

SafetyOverviewu Canweautomatesafetyissuesandsystemintegrityissues?u Identifytheentityorentitiesthatprovidetheconcurrenceon

non-objectiontotheautomatedoperationofhazardousoutdoorlaseroperationsthroughthegovernedairspace.– HostCountry

• Highlevelgovernment(Federal/National)• LocallevelGovernment(State/Region)– Requirementsoftheseentities

u Currentlyexistordotheyneedtobecreatedu Unattended/automatedoutdoorlaseroperationsexplicitlyallowedoraretheyinferred

– Organization(Science)sponsoringtheoutdoorlaseroperations• Safetyrequirements• Proceduresforacquiringconcurrence• Safetyplanandimplementation• Safetyplanimplementationverification

– InternationalRequirementsifinanothercountry– Whichrequirementstakepriority(moststringentineachcategory)– Periodicrenewal

Page 4: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 4

uRequirements/StandardsUsedInclude:–NASAProceduralRequirements(NPR8715.3)–GoddardProceduralRequirement(GPR:1860.2)– FederalAviationAdministration(FAA:AC70-1)–AmericanNationalStandardsInstitution(ANSI-Multiple)– SocietyofAutomotiveEngineers(SAE:3includingAS6029A)

SGSLRLaserSafetyPlan

Page 5: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 5

PerformFullSystemHazardAnalysisu Indoorlasersafetyanalysis

– Laserroomaccess– Operationsareaaccess– Buildingaccess

u Outdoorlasersafetyanalysis– Lasertransmitteraccess– Aidedviewing– Airspaceidentification– Identifyingusersoftheairspace(planes,helicopters,balloons,

Gliders,Parachutists,etc.u IndoorandOutdoorsafetyanalysismusttakeintoaccount

– Operations– Maintenance– GeneralPublicaccess– Effectson,orby,closeproximityprojects/offices/etc.

Page 6: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 6

u Performacomprehensivehazardanalysistoidentifyallhazardsassociatedwiththedevelopment,implementation,test,operation,andmaintenanceinvolvingtheuseofthelaser– IndoorLaserHazards• Local,state,federal,hostnationlaseroperationsrequirements• Laserparametersanddetermine– MaximumPermissibleEnergy(MPE)– NominalOcularHazardDistance(NOHD)• Reviewthephysicallayoutofthelaserroomandoperationsarea,identifypotentiallaserhazardsandhazardzones

• Reviewlayoutoftheopticalbench,determineenergydensities,identifyassociatedlaserhazards

• Reviewopticalalignmentprocedures,identifyassociatedlaserhazards

HazardAnalysis- Indoor

Page 7: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 7

u Identifylocal,state,federal,andhostnationlaseroperationsrequirements

u Performairspaceanalysis– IdentifyairportswithintheNOHD,Sensitive,Critical,andLaserFreehazardranges

– Determinetypesofaircraft,aircraftaltitudes,andaircraftspeedsthatareexpectedtobeintheairspacevolume

– Identifyannualairportoperations– Identifynearbyoperationsthatusetheaffectedairspacevolume

u Identifynearbyoperationsthatmaybeaffectedbysatellitelaserrangingactivities

HazardAnalysis- Outdoor

Page 8: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 8

Laser-Free&CriticalZoneConditions

Critical Zone5 µW/cm2

Laser Free Zone50 nW/cm2

10,000feet

5.2 Statute Miles

20 º

NGSLRSystem

RunwayAirport Reference Point11.5 Statute Miles

Critical Zone5 µW/cm2

Runway5.75 Statute Miles1.04 Statute Miles

20 ºLaser Free Zone 2,000

feet

NGSLRSystem

50 nW/cm2

• IdentifyairportSensitive,Critical,andLaserFreezones• IdentifyairportswhichthetransmittedlaserenergywillpenetrateSensitive,Critical,andLaserFreezones

Page 9: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 9

u Identifylocal,state,federal,andhostnationoffices/agenciesmitigationrequirements

u Identifymethodstomitigateallidentifiedindoorlaserhazards– Hazardelimination,engineeringcontrols,useofsafetydevices,use

ofcautionandwarningdevices,implementationofproceduresandtraining,andtheuseofPPE

u Correlatemitigationmethodswithallidentifiedindoorlaserhazards– Hazardelimination,engineeringcontrols,useofsafetydevices,use

ofcautionandwarningdevices,implementationofproceduresandtraining,andtheuseofPPE

– Identifylasersafetysubsystemcapabilities– Implementchangestomitigationmethods/subsystemsasneeded

u Implementandverifymitigationmethods/subsystems

HazardMitigation– Indoor&Outdoor

Page 10: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 10

u Emergencyreportingu Recordkeepingu Timetaggingofcriticaldata

HazardReporting

Page 11: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 11

u Safetyinherentindesignu PersonalProtectiveEquipment(PPE)u Automatedemergencynotificationsystemu Laserhazardwarnings,labels,andcontrolmeasures

– Warningsignsandlabels– Videomonitoringsystem– Proceduresandbeamblocks

u Integratedsystemsafetyfeatures– AreaSafety- DoorwaySensors/StairwayPressureplates– KeyedAccesstoBuildingandLaser– Beamcontainmentbarriers– LaserSafetyChassiswithautomatedbeamblockandlaserfire(trigger)inhibitsignal

u Safetyrequirementsandprocedures– GeneralSafetyRequirements (SGSLRSafetyHandbook)– OperationsProcedures (SGSLROperationsManual)– SystemMaintenanceProcedures (SGSLROperationsManual)– LaserAlignmentProcedures (SGSLRAlignmentManual)– EmergencyProcedures (SGSLRSafetyHandbook)

SafetyControls(1)

Page 12: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 12

u CertificationandTraining– TrainingandCertificationRequirementsforallusersofthesystem-System

Operators,LaserUsersandOpticalAlignments– Allusersmustfollowtherequirementsandprocedureslistedinsystem

manuals

u SafetyEquipment(Lasersafetygoggles,fallprotection,etc.)

u SafetyVerification– RoutineSafetyInspection,periodictestingandcommunications

u SecurityConcerns– SituationalAwarenessofSystemHealthandsurroundingenvironment– PreventionofUnauthorizedEntry– BothPhysicalandElectronic

SafetyControls(2)

Page 13: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 13

SystemSecurityu Physicalsecurityassessment

– Securecompound– Buildingaccess– Lasertransmitteraccess– ReactiontoUnauthorizedaccess– Reactiontoauthorizedaccessbutunauthorizedoperations– Securityimplementation

• Redundancy• Securitylevels

u ITSecurityassessment– Internetaccess– Instantterminationoflaseroperationsinanemergency– Systemmonitorandcontrol– Upgrades– Unauthorizedcontrol

Page 14: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 14

ImplementationPhaseu Implementaccordingtoallguidelines,requirementsandimplementationplansdevelopedduringdesignphase.

u Ensureallplans,Hardware,Software,othercontrolsareimplementedanddocumentedpriortotesting.

u Allpossiblescenariosmustbedetermined,documented,reviewed,testedandverified.

u Allpossibledecisionpathsforthesoftwaremustbedocumentedandtested.Inanautomatedsystemthehardware/softwarebecomesafetycritical.

u Subsystemsthatcanbetestedseparatelyshouldbe,butfinalverificationcanonlybedoneatthesystemlevelinasclosetoactualusageaspossible.

Page 15: Safety/Security Concerns when Automating SLR Systems · Safety/Security Concerns when Automating SLR Systems. ILRS Technical Workshop Riga 1-6 Oct, 2017 (Wetzel) 2 Abstract Safety/Security

ILRSTechnicalWorkshopRiga1-6Oct,2017(Wetzel) 15

TestingPhaseu Testingandverificationshouldbedocumentedandtestedinall

operationalmodes,maintenancemodes,diagnosticmodesandsimulations.Shutdownandpower-upshouldalsobepartofthis.

u Somesoftwaretestingmayrequiresimulationbecausesomepathsmaynoteasilybereached.

u Methodstotestmustbedeterminedthatdonotharmanyhumans,ordamageanyinstrumentation,facilities,aircraft,butthatallowtestingascloseaspossibletorealsystemuse.

u Alltestingandverificationwillneedtobeperformedwithahumanpresentbutonlywatching(incasesomethinggoeswrong).Thehumanwilldocumentperformanceseen,butthefinalverificationwillbefromanalysisperformedusingthedatacollected(includingvideo)duringtesting.

Safety/securityforfullautomationisamajordesign,documentationandtestingeffort.