Search NASA⌕ Search

SEARCH · Search NASA

Results for “Formal Reasoning”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Automated Theorem Proving in High-Quality Software Design

The amount and complexity of software developed during the last few years has increased tremendously. In particular, programs are being used more and more in embedded systems (from car-brakes to plant-control). Many of these applications are safety-relevant, i.e. a malfunction of hardware or software can cause severe damage or loss. Tremendous risks are typically present in the area of aviation, (nuclear) power plants or (chemical) plant control. Here, even small problems can lead to thousands of casualties and huge financial losses. Large financial risks also exist when computer systems are used in the area of telecommunication (telephone, electronic commerce) or space exploration. Computer applications in this area are not only subject to safety considerations, but also security issues are important. All these systems must be designed and developed to guarantee high quality with respect to safety and security. Even in an industrial setting which is (or at least should be) aware of the high requirements in Software Engineering, many incidents occur. For example, the Warshaw Airbus crash, was caused by an incomplete requirements specification. Uncontrolled reuse of an Ariane 4 software module was the reason for the Ariane 5 disaster. Some recent incidents in the telecommunication area, like illegal "cloning" of smart-cards of D2GSM handies, or the extraction of (secret) passwords from German T-online users show that also in this area serious flaws can happen. Due to the inherent complexity of computer systems, most authors claim that only a rigorous application of formal methods in all stages of the software life cycle can ensure high quality of the software and lead to real safe and secure systems. In this paper, we will have a look, in how far automated theorem proving can contribute to a more widespread application of formal methods and their tools, and what automated theorem provers (ATPs) must provide in order to be useful.

Schumann, Johann↗

Rotational excitation of symmetric top molecules by collisions with atoms. II - Infinite order sudden approximation

The infinite order sudden (IOS) approximation is extended to rotational excitation of symmetric tops by collisions with atoms. After development of a formalism for 'primitive' or 'one-ended' tops, proper parity-adapted linear combinations describing real rotors are considered and modifications needed for asymmetric rigid rotors are noted. The generalized spectroscopic relaxation cross sections are discussed. IOS calculations for NH3-He and H2CO-He are performed and compared with more accurate calculations, and the IOS approximation is found to provide a reasonably accurate description.

Green, S.↗

Swarm Mentality: Toward Automatic Swarm State Awareness with Runtime Verification

Cyber-Physical Systems (CPSs) already exhibit impressive performance in all areas of human life, and swarms of CPSs promise to increase their capabilities even further. However, to effectively utilize CPS swarms their complexity of operation has to scale sub-linearly with the number of swarm members. Presenting the swarm to an operator as a single entity almost eliminates the additional per-member overhead entirely. To operate a swarm as one entity, and/or to increase the swarm’s autonomy, the operator and the swarm members need to reason and communicate at the same level of abstraction, i.e. the swarm needs a sense of “self.” Therefore, we require the ability to specify whole swarm properties yet monitor them at the member level. We examine one architecture for achieving this awareness by: 1) Defining a taxonomy for comparing techniques that synthesize this belief-state 2) Propose use of the Runtime Verification formal method to fill this role 3) Present preliminary designs for extending and embedding such a system in the Distributed Spacecraft Autonomy architecture to generate per-member monitors from swarm level specification.

Runtime Verification↗

Inversion of vegetation canopy reflectance models for estimating agronomic variables. I - Problem definition and initial results using the Suits model

An important but relatively uninvestigated problem in remote sensing is the inversion of vegetative canopy reflectance models to obtain agrophysical parameters, given measured reflectances. The problem is here formally defined and its solution outlined. Numerical nonlinear optimization techniques are used to implement this inversion to obtain the leaf area index using Suits' canopy reflectance model. The results for a variety of cases indicate that this can be done successfully using infrared reflectances at different views or azimuth angles or a combination thereof. The other parameters of the model must be known, although reasonable measurement errors can be tolerated without seriously degrading the accuracy of the inversion. The application of the technique to ground based remote-sensing experiments is potentially useful, but is limited to the degree to which the canopy reflectance model can accurately predict observed reflectances.

Goel, N.↗

A model for accretion of the terrestrial planets

One possible origin of the terrestrial planets involves their formation by gravitational accretion of particles originally in Keplerian orbits about the sun. Some implications of this theory are considered. A formal expression for the rate of mass accretion by a planet is developed. The formal singularity of the gravitational collision cross section for low relative velocities is shown to be without physical significance when the accreting bodies are in heliocentric orbits. The distribution of particle velocities relative to an accreting planet is considered; the mean velocity increases with time. The internal temperature of an accreting planet is shown to depend simply on the accretion rate. A simple and physically reasonable approximate expression for a planetary accretion rate is proposed.

Weidenschilling, S. J.↗

Transition elements based on transfinite interpolation

In this study the transfinite interpolation methodology, a 'blending-function' method in particular, is utilized for the formulation of transition elements. The method offers a formal way of meeting continuity requirements in a transition element. Element shape functions are derived by blending the continuity requirements of individual boundary segments. The blending directions are naturally orthogonal in rectangular domains therefore interpolation of the boundaries over rectangular 2D and 3D elements can be performed with minimal effort. In triangular domains, however, the choice of blending directions and interpolants is not straightforward. For that reason, two interpolation techniques are proposed for blending of the boundaries of triangular domains. A series of transition elements of various classes compatible with elements of different orders and dimensions is developed and the full potential of the transfinite interpolation, as it applies to element formulation, is explored.

Odabas, Onur R.↗

Combined Uncertainty and A-Posteriori Error Bound Estimates for General CFD Calculations: Theory and Software Implementation

This workshop presentation discusses the design and implementation of numerical methods for the quantification of statistical uncertainty, including a-posteriori error bounds, for output quantities computed using CFD methods. Hydrodynamic realizations often contain numerical error arising from finite-dimensional approximation (e.g. numerical methods using grids, basis functions, particles) and statistical uncertainty arising from incomplete information and/or statistical characterization of model parameters and random fields. The first task at hand is to derive formal error bounds for statistics given realizations containing finite-dimensional numerical error [1]. The error in computed output statistics contains contributions from both realization error and the error resulting from the calculation of statistics integrals using a numerical method. A second task is to devise computable a-posteriori error bounds by numerically approximating all terms arising in the error bound estimates. For the same reason that CFD calculations including error bounds but omitting uncertainty modeling are only of limited value, CFD calculations including uncertainty modeling but omitting error bounds are only of limited value. To gain maximum value from CFD calculations, a general software package for uncertainty quantification with quantified error bounds has been developed at NASA. The package provides implementations for a suite of numerical methods used in uncertainty quantification: Dense tensorization basis methods [3] and a subscale recovery variant [1] for non-smooth data, Sparse tensorization methods[2] utilizing node-nested hierarchies, Sampling methods[4] for high-dimensional random variable spaces.

CFD↗

A Variational Formalism for the Radiative Transfer Equation: Prelude to Model 3

The MODEL III variational data assimilation model is the third of four general assimilation models designed to blend weather data measured from space based platforms in the meteorological data mainstream in a way that maximizes the information content of the satellite data. Because there are many different observation locations and there are many instruments with different measurement error characteristics, it is also necessary to require that the blending be done to maximize the information content of the data and simultaneously to retain a dynamically consistent and reasonably accurate description of the state of the atmosphere. This is ideally a variational problem for which the data receive relative weights that are inversely proportional to measurement error and are adjusted to satisfy a set of dynamical equations that govern atmospheric processes. The advantage of MODEL III over the previous two models is that radiance, the atmospheric variable measured by satellite, becomes a dependent variable. In the previous versions, mean layer temperatures that had been retrieved from the radiances by some method, were included in the assimilation by substituting them in place of the rawinsonde temperatures. Now both rawinsonde temperatures and satellite radiances are included independently in the assimilation.

Achtemeier, Gary L.↗

Architecting the Human Space Flight Program with Systems Modeling Language (SysML)

The next generation of missions in NASA's Human Space Flight program focuses on the development and deployment of highly complex systems (e.g., Orion Multi-Purpose Crew Vehicle, Space Launch System, 21st Century Ground System) that will enable astronauts to venture beyond low Earth orbit and explore the moon, near-Earth asteroids, and beyond. Architecting these highly complex system-of-systems requires formal systems engineering techniques for managing the evolution of the technical features in the information exchange domain (e.g., data exchanges, communication networks, ground software) and also, formal correlation of the technical architecture to stakeholders' programmatic concerns (e.g., budget, schedule, risk) and design development (e.g., assumptions, constraints, trades, tracking of unknowns). This paper will describe how the authors have applied System Modeling Language (SysML) to implement model-based systems engineering for managing the description of the End-to-End Information System (EEIS) architecture and associated development activities and ultimately enables stakeholders to understand, reason, and answer questions about the EEIS under design for proposed lunar Exploration Missions 1 and 2 (EM-1 and EM-2).

scheduling↗

Probabilistic simulation of the human factor in structural reliability

A formal approach is described in an attempt to computationally simulate the probable ranges of uncertainties of the human factor in structural probabilistic assessments. A multi-factor interaction equation (MFIE) model has been adopted for this purpose. Human factors such as marital status, professional status, home life, job satisfaction, work load and health, are considered to demonstrate the concept. Parametric studies in conjunction with judgment are used to select reasonable values for the participating factors (primitive variables). Suitability of the MFIE in the subsequently probabilistic sensitivity studies are performed to assess the validity of the whole approach. Results obtained show that the uncertainties for no error range from five to thirty percent for the most optimistic case.

Chamis, C. C.↗

Simple methods of exploiting the underlying structure of rule-based systems

Much recent work in the field of expert systems research has aimed at exploiting the underlying structures of the rule base for reasons of analysis. Such techniques as Petri-nets and GAGs have been proposed as representational structures that will allow complete analysis. Much has been made of proving isomorphisms between the rule bases and the mechanisms, and in examining the theoretical power of this analysis. In this paper we describe some early work in a new system which has much simpler (and thus, one hopes, more easily achieved) aims and less formality. The technique being examined is a very simple one: OPS5 programs are analyzed in a purely syntactic way and a FSA description is generated. In this paper we describe the technique and some user interface tools which exploit this structure.

Hendler, James↗

From natural language to control signals: a conceptual framework for semantic channel finding in complex experimental infrastructure

Modern experimental platforms such as particle accelerators, fusion devices, telescopes, and industrial process control systems expose tens to hundreds of thousands of control and diagnostic channels, accumulated over decades of hardware evolution. Operators and AI systems alike depend on informal expert knowledge, inconsistent naming conventions, and scattered documentation to locate the signals required for monitoring, troubleshooting, and automated control, creating a persistent bottleneck for reliability, scalability, and emerging language-model-driven interfaces. We formalize semantic channel finding, the task of mapping natural-language intent to concrete control-system signals, as a general problem in complex experimental infrastructure, and introduce a four-paradigm conceptual framework to guide architecture selection based on facility-specific data regimes. The paradigms span (i) direct in-context lookup over small, curated channel dictionaries, (ii) constrained hierarchical navigation through structured trees, (iii) interactive agent exploration using iterative reasoning and tool-based database queries, and (iv) ontology-grounded semantic search that decouples channel meaning from facility-specific naming conventions. We demonstrate the practical feasibility of each paradigm through proof-of-concept implementations at four operational facilities spanning two orders of magnitude in scale: from compact free-electron lasers to large synchrotron light sources, operating under diverse control-system architectures ranging from clean hierarchical naming schemes to legacy environments with decades of heterogeneous conventions. Where evaluated against expert-curated operational queries, these instantiations achieve 90%–97% accuracy, validating the framework’s applicability across real-world deployment scenarios. To accelerate adoption across the broader scientific and industrial control-system community, we release open-source, plug-and-play implementations of all three interactive paradigms-direct lookup, hierarchical navigation, and middle-layer exploration-within the Osprey framework, together with tools for channel database generation, interactive testing, and minimal-configuration deployment. This work establishes semantic channel finding as a foundational capability for human-centric and agentic AI interfaces at large-scale facilities, providing both a systematic framework for architecture design and practical resources to enable adoption without building custom infrastructure from scratch.

channel finding↗

DEVS representation of dynamical systems - Event-based intelligent control

It is shown how systems can be advantageously represented as discrete-event models by using DEVS (discrete-event system specification), a set-theoretic formalism. Such DEVS models provide a basis for the design of event-based logic control. In this control paradigm, the controller expects to receive confirming sensor responses to its control commands within definite time windows determined by its DEVS model of the system under control. The event-based contral paradigm is applied in advanced robotic and intelligent automation, showing how classical process control can be readily interfaced with rule-based symbolic reasoning systems.

Zeigler, Bernard P.↗

OSSE observations of GX 339-4

The Oriented Scintillation Spectrometer Experiment (OSSE) on the Compton Gamma Ray Observatory (CGRO) observed the Galactic black hole candidate GX 339-4 as a target of oppurtunity in 1991 September, in response to the outburst reported by Burst and Transient Source Experiment (BATSE). We report here on energy spectra in the 50 keV-10 MeV range obtained by OSSE. The source was detected from 50 to 400 keV at a level relative to the Crab Nebula of approximately 30%. The observed spectrum was prescribed reasonably well by a power law with an exponential cutoff; a least-squares fit yielded a photon index of 0.88 +/- 0.05 and a cutoff energy of 68 +/- 2 keV. The addition of a Compton reflection component did not significantly improve the overall fit. An optically thin thermal bremsstrahlung spectrum also provides a good fit, and the thermal Comptonization model of Sunyaev & Titarchuk, while deficient in describing the data above approximately 200 keV, cannot formally be ruled out. A pure power law with reflection does not fit the observed spectrum. During a follow-up observation made in 1991 November the intensity of the source below 100 keV had dropped by more than a factor of 40, and it was no longer detected above approximately 100 keV. The energy spectrum during the November observation could be characterized by a power law with a photon index of 2.3 +/- 0.3; the spectrum was fitted equally well with the same exponentially cutoff power-law model applied to the September observation, reduced in intensity by a factor of approximately 40. During the 1991 September observation, the luminosity in the 50-400 keV band was approximately 2 x 10(exp 37) ergs/s (assuming a distance of 4 kpc), no more than a factor of 5 below the soft X-ray luminosity of GX 339-4 observed in its X-ray high state. The luminosity during the 1991 November observation was approximately 5 x 10(exp 35) ergs/s. Extrapolations of both the exponentially cutoff power-law and Sunyaev-Titarchuk models to the approximately 5-20 keV X-ray band yield flux levels very close to that observed by Ginga during an overlapping interval in 1991 September, when GX 339-4 was reported to be in its low state. This may be one of the strongest indications to date of a direct correspondence between the low X-ray state and gamma-ray outbursts of GX 339-4.

Grabelsky, D. A.↗

Formal development of a clock synchronization circuit

This talk presents the latest stage in formal development of a fault-tolerant clock synchronization circuit. The development spans from a high level specification of the required properties to a circuit realizing the core function of the system. An abstract description of an algorithm has been verified to satisfy the high-level properties using the mechanical verification system EHDM. This abstract description is recast as a behavioral specification input to the Digital Design Derivation system (DDD) developed at Indiana University. DDD provides a formal design algebra for developing correct digital hardware. Using DDD as the principle design environment, a core circuit implementing the clock synchronization algorithm was developed. The design process consisted of standard DDD transformations augmented with an ad hoc refinement justified using the Prototype Verification System (PVS) from SRI International. Subsequent to the above development, Wilfredo Torres-Pomales discovered an area-efficient realization of the same function. Establishing correctness of this optimization requires reasoning in arithmetic, so a general verification is outside the domain of both DDD transformations and model-checking techniques. DDD represents digital hardware by systems of mutually recursive stream equations. A collection of PVS theories was developed to aid in reasoning about DDD-style streams. These theories include a combinator for defining streams that satisfy stream equations, and a means for proving stream equivalence by exhibiting a stream bisimulation. DDD was used to isolate the sub-system involved in Torres-Pomales' optimization. The equivalence between the original design and the optimized verified was verified in PVS by exhibiting a suitable bisimulation. The verification depended upon type constraints on the input streams and made extensive use of the PVS type system. The dependent types in PVS provided a useful mechanism for defining an appropriate bisimulation.

Miner, Paul S.↗

Modular Certification

Airplanes are certified as a whole: there is no established basis for separately certifying some components, particularly software-intensive ones, independently of their specific application in a given airplane. The absence of separate certification inhibits the development of modular components that could be largely "precertified" and used in several different contexts within a single airplane, or across many different airplanes. In this report, we examine the issues in modular certification of software components and propose an approach based on assume-guarantee reasoning. We extend the method from verification to certification by considering behavior in the presence of failures. This exposes the need for partitioning, and separation of assumptions and guarantees into normal and abnormal cases. We then identify three classes of property that must be verified within this framework: safe function, true guarantees, and controlled failure. We identify a particular assume-guarantee proof rule (due to McMillan) that is appropriate to the applications considered, and formally verify its soundness in PVS.

Rushby, John↗

A Unified Representation Scheme for Solid Geometric Objects Using B-splines (extended Abstract)

A geometric representation scheme called the B-spline cylinder, which consists of interpolation between pairs of uniform periodic cubic B-spline curves is discussed. This approach carries a number of interesting implications. For one, a single relatively simple database schema can be used to represent a reasonably large class of objects, since the spline representation is flexible enough to allow a large domain of representable objects at very little cost in data complexity. The model is thus very storage-efficient. A second feature of such a system is that it reduces to one the number of routines which the system must support to perform a given operation on objects. Third, the scheme enables easy conversion to and from other representations. The formal definition of the cylinder entity is given. In the geometric properties of the entity are explored and several operations on such objects are defined. Some general purpose criteria for evaluating any geometric representation scheme are introduced and the B-spline cylinder scheme according to these criteria is evaluated.

Bahler, D.↗

The Costs of Knowledge

Acquiring knowledge-genuinely learning something new-requires the consent and commitment of the person you're trying to learn from. In contrast to information, which can usually be effectively transmitted in a document or diagram, knowledge comes from explaining, clarifying, questioning, and sometimes actually working together. Getting this kind of attention and commitment often involves some form of negotiation, since even the most generous person's time and energy are limited. Few experts sit around waiting to share their knowledge with strangers or casual acquaintances. In reasonably collaborative enterprises- I think NASA is one-this sort of negotiation isn't too onerous. People want to help each other and share what they know, so the "cost" of acquiring knowledge is relatively low. In many organizations (and many communities and countries), however, there are considerable costs associated with this activity, and many situations in which negotiations fail. The greatest knowledge cost is in and adopting knowledge to one's own use. Sometimes this means formally organizing what one learns in writing. Sometimes it means just taking time to reflect on someone else's thoughts and experiences-thinking about knowledge that is not exactly what you need but can lead you to develop ideas that will be useful. A long, discursive conversation, with all the back-and-forth that defines conversation, can be a mechanism of knowledge exchange. I have seen many participants at NASA APPEL Masters Forums talking, reflecting, and thinking-adapting what they are hearing to their own needs. Knowledge transfer is not a simple proposition. An enormous amount of information flows through the world every day, but knowledge is local, contextual, and "stickyn-that is, it takes real effort to move it from one place to another. There is no way around this. To really learn a subject, you have to work at it, you have to pay your "knowledge dues." So while, thanks to advances in technology, almost infinite amounts of information are instantly available, it still takes the same amount of time and work to learn French as it did in the year 1800-or to master physics or philosophy.

Prusak, Laurence↗