Search NASASearch

Engineering topics

Apostolakis, G. E.

Publications and source records attributed to Apostolakis, G. E..

Development of a methodology for assessing the safety of embedded software systems

A Dynamic Flowgraph Methodology (DFM) based on an integrated approach to modeling and analyzing the behavior of software-driven embedded systems for assessing and verifying reliability and safety is discussed. DFM is based on an extension of the Logic Flowgraph Methodology to incorporate state transition models. System models which express the logic of the system in terms of causal relationships between physical variables and temporal characteristics of software modules are analyzed to determine how a certain state can be reached. This is done by developing timed fault trees which take the form of logical combinations of static trees relating the system parameters at different point in time. The resulting information concerning the hardware and software states can be used to eliminate unsafe execution paths and identify testing criteria for safety critical software functions.

Garrett, C. J.

Findings of a review of spacecraft fire safety needs

Discussions from a workshop to guide UCLA and NASA investigators on the state of knowledge and perceived needs in spacecraft fire safety and its risk management are reviewed, for an introduction to an analytical and experimental project in this field. The report summarizes the workshop discussions and includes the visual aids used in the presentations. Probabilistic Safety Assessment (PSA) methods, which are currently not used, would be of great value to the designs and operation of future human-crew spacecraft. Key points in the discussions were the importance of understanding and testing smoldering as a likely fire scenario in space and the need for smoke damage modeling, since many fire-risk models ignore this mechanism and consider only heat damage.

Apostolakis, G. E.

Logic flowgraph methodology - A tool for modeling embedded systems

The logic flowgraph methodology (LFM), a method for modeling hardware in terms of its process parameters, has been extended to form an analytical tool for the analysis of integrated (hardware/software) embedded systems. In the software part of a given embedded system model, timing and the control flow among different software components are modeled by augmenting LFM with modified Petrinet structures. The objective of the use of such an augmented LFM model is to uncover possible errors and the potential for unanticipated software/hardware interactions. This is done by backtracking through the augmented LFM mode according to established procedures which allow the semiautomated construction of fault trees for any chosen state of the embedded system (top event). These fault trees, in turn, produce the possible combinations of lower-level states (events) that may lead to the top event.

Muthukumar, C. T.

Risk-Based Fire Safety Experiment Definition for Manned Spacecraft

Risk methodology is used to define experiments to be conducted in space which will help to construct and test the models required for accident sequence identification. The development of accident scenarios is based on the realization that whether damage occurs depends on the time competition of two processes: the ignition and creation of an adverse environment, and the detection and suppression activities. If the fire grows and causes damage faster than it is detected and suppressed, then an accident occurred. The proposed integrated experiments will provide information on individual models that apply to each of the above processes, as well as previously unidentified interactions and processes, if any. Initially, models that are used in terrestrial fire risk assessments are considered. These include heat and smoke release models, detection and suppression models, as well as damage models. In cases where the absence of gravity substantially invalidates a model, alternate models will be developed. Models that depend on buoyancy effects, such as the multizone compartment fire models, are included in these cases. The experiments will be performed in a variety of geometries simulating habitable areas, racks, and other spaces. These simulations will necessitate theoretical studies of scaling effects. Sensitivity studies will also be carried out including the effects of varying oxygen concentrations, pressures, fuel orientation and geometry, and air flow rates. The experimental apparatus described herein includes three major modules: the combustion, the fluids, and the command and power modules.

Apostolakis, G. E.