Toward Safe Reuse of Product Family Specifications
Upcoming spacecraft plan extensive reuse of software components, to the extent that some systems will form product families of similar or identical units (e.g. a fleet of spaceborne telescopes).
Engineering topics
Publications and source records attributed to Lutz, R..
Upcoming spacecraft plan extensive reuse of software components, to the extent that some systems will form product families of similar or identical units (e.g. a fleet of spaceborne telescopes).
This paper proposes the use of Bi-directional Analysis (BDA), an integrated extension of SFMEA and SFTA, as a core assessment technique by which saftey-critical software can be certified.
Immersive virtual environments (VEs) technology has matured to the point where it can be utilized as a scientific and engineering problem solving tool. In particular, VEs are starting to be used to design and evaluate safety-critical systems that involve human operators, such as flight and driving simulators, complex machinery training, and emergency rescue strategies.
This experience report describes a method that has been used successfully to detect hidden failure modes in critical, embedded spacecraft software. The method is an adaptation of an earlier, controversial approach called failure modes and effects analysis. The adapted method was found to be well-suited to identifying latent software design weaknesses involving complex system interactions and dependencies in the two applications described here. This experience may be useful for other high-integrity software systems in which the possibility of hidden failure modes is a major concern.
Formal specification and analysis of requirements continues to gain support as a method for producing more reliable software. However, the introduction of formal methods to a large software project is difficult, due in part to the unfamiliarity of the specification languages and the lack of graphics. This paper reports results of an investigation into the effectiveness of formal methods as an aid to the requirements analysis of critical, system-level fault-protection software on a spacecraft currently under development. Our experience indicates that formal specification and analysis can enhance the accuracy of the requirements and add assurance prior to design development in this domain.
An accelerometer based on a spring-suspended reference mass and its precise relative motion measurement by means of 3 two-dimensional position sensitive detectors (PSD) is described. A breadboard model achieves a resolution (longterm linearity) of 25 nm in one direction. Due to the physical principle of the PSD, the second layer is slightly less sensitive than the top layer; accordingly for gravity gradient detection the more sensitive layer is selected for the Z/X component detection. At 10 Hz sampling rate an acceleration gradient of under 10 to the minus 12th power g (i.e., 0.01 E or 0.001 Gal/km) is considered to be detectable.
Three monthly mean simulations of the global atmosphere were computed for February 1976 with the GISS model from observed initial conditions on the first day of the month. In a replication experiment, two of these computations generated slightly different monthly mean states, apparently due to the schedule of interruptions on the computer. The root-mean-square errors of replication over the Northern Hemisphere were found to be about 2 mb, 20 m and 1 K for sea level pressure, 500 mb height and 850 mb temperature, respectively. The monthly mean 500 mb forecast results for February 1976 over the Northern Hemisphere are consistent with those from earlier GISS model experiments and again indicate some predictive skill at that level. Use of the observed monthly mean sea surface temperature (SST) field for February 1976 in place of the climatological SST field for February resulted in slightly improved simulations over the globe and Northern Hemisphere,