<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-20T07:20:41Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/107593" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/107593</identifier><datestamp>2022-01-13T07:55:19Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor" lang="en_US">Nancy Leveson.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author" lang="en_US">Ujiie, Ryo</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="other" lang="en_US">Massachusetts Institute of Technology. Engineering Systems Division.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="en_US">Massachusetts Institute of Technology. Engineering and Management Program</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="coverage" qualifier="spatial" lang="en_US">a-ja---</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2017-03-20T19:41:39Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2017-03-20T19:41:39Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="copyright" lang="en_US">2016</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued" lang="en_US">2016</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">http://hdl.handle.net/1721.1/107593</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="oclc" lang="en_US">974710088</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Thesis: S.M. in Engineering and Management, Massachusetts Institute of Technology, School of Engineering, System Design and Management Program, Engineering and Management Program, 2016.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Cataloged from PDF version of thesis.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Includes bibliographical references (pages 120-122).</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">As with other critical systems, space systems are also getting larger and more complex. Although Japan Aerospace Exploration Agency (JAXA) has designed various spacecraft and had not experienced any serious accident for more than 10 years, loss of an astronomical satellite finally happened in 2016 even though the development process was not drastically different from the past. The accident implies that the complexity of space systems can no longer be managed by the traditional safety analysis. Furthermore, in huge system developments, the fluidity of design is rapidly lost as the development proceeds. Thus, creating a safer system design in the early development phase that is capable of handling various undesirable scenarios will significantly contribute to the success of huge and complex system development. The goal of this thesis is to establish the way to design a safer system in the context of modern huge and complex systems and demonstrate its effectiveness in an actual JAXA future transfer vehicle design. As a solution, in this thesis a new accident model called System Theoretic Accident Model and Process (STAMP) is used. The safety analysis methods based on STAMP were invented to handle the characteristics of modem complex systems. Furthermore, detailed designs are not required in the analysis. Therefore, the issues of modern complex systems are expected to be solved by the system theoretic safety design methods. In this thesis, two types of system analysis were conducted based on STAMP: concept design analysis in the target system and incident analysis in a similar previous system. While any detailed specification was not available, various unsafe off-nominal system behaviors were derived from the concept design, and it was refined. Remarkably, off-nominal behaviors due to a new design policy being applied in the system were successfully described. Furthermore, various design flaws involving human-automation interactions were also found, which usually tends to be discussed in the later development phase. The result indicates the proposed system theoretic safety design approaches can be successfully interwoven with the early stage of development process, and systems can be fundamentally refined from a safety perspective to prevent future serious losses.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="statementofresponsibility" lang="en_US">by Ryo Ujiie.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree" lang="en_US">S.M. in Engineering and Management</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent" lang="en_US">151 pages</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="en_US">eng</dim:field>
   <dim:field mdschema="dc" element="publisher" lang="en_US">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights" lang="en_US">MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission.</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri" lang="en_US">http://dspace.mit.edu/handle/1721.1/7582</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">Engineering and Management Program.</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">Engineering Systems Division.</dim:field>
   <dim:field mdschema="dc" element="title" lang="en_US">Safety guided design analysis in multi-purposed Japanese unmanned transfer vehicle</dim:field>
   <dim:field mdschema="dc" element="type" lang="en_US">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dspace" element="authorsordered">false</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="a64feb88-855a-4988-bf31-d0a1c2b20f01">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
	&lt;Language>eng&lt;/Language>
   	&lt;Title>Safety guided design analysis in multi-purposed Japanese unmanned transfer vehicle&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2016&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Ujiie, Ryo&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>http://dspace.mit.edu/handle/1721.1/7582&lt;/License>
    &lt;Keyword>Engineering and Management Program.&lt;/Keyword>
    &lt;Keyword&gt;System Design and Management Program.&lt;/Keyword>
    &lt;Keyword>Engineering Systems Division.&lt;/Keyword>
   	&lt;Abstract>As with other critical systems, space systems are also getting larger and more complex. Although Japan Aerospace Exploration Agency (JAXA) has designed various spacecraft and had not experienced any serious accident for more than 10 years, loss of an astronomical satellite finally happened in 2016 even though the development process was not drastically different from the past. The accident implies that the complexity of space systems can no longer be managed by the traditional safety analysis. Furthermore, in huge system developments, the fluidity of design is rapidly lost as the development proceeds. Thus, creating a safer system design in the early development phase that is capable of handling various undesirable scenarios will significantly contribute to the success of huge and complex system development. The goal of this thesis is to establish the way to design a safer system in the context of modern huge and complex systems and demonstrate its effectiveness in an actual JAXA future transfer vehicle design. As a solution, in this thesis a new accident model called System Theoretic Accident Model and Process (STAMP) is used. The safety analysis methods based on STAMP were invented to handle the characteristics of modem complex systems. Furthermore, detailed designs are not required in the analysis. Therefore, the issues of modern complex systems are expected to be solved by the system theoretic safety design methods. In this thesis, two types of system analysis were conducted based on STAMP: concept design analysis in the target system and incident analysis in a similar previous system. While any detailed specification was not available, various unsafe off-nominal system behaviors were derived from the concept design, and it was refined. Remarkably, off-nominal behaviors due to a new design policy being applied in the system were successfully described. Furthermore, various design flaws involving human-automation interactions were also found, which usually tends to be discussed in the later development phase. The result indicates the proposed system theoretic safety design approaches can be successfully interwoven with the early stage of development process, and systems can be fundamentally refined from a safety perspective to prevent future serious losses.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>