Search NASA⌕ Search

SEARCH · Search NASA

Results for “Requirements Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

Study of techniques for redundancy verification without disrupting systems, phases 1-3

The problem of verifying the operational integrity of redundant equipment and the impact of a requirement for verification on such equipment are considered. Redundant circuits are examined and the characteristics which determine adaptability to verification are identified. Mutually exclusive and exhaustive categories for verification approaches are established. The range of applicability of these techniques is defined in terms of signal characteristics and redundancy features. Verification approaches are discussed and a methodology for the design of redundancy verification is developed. A case study is presented which involves the design of a verification system for a hypothetical communications system. Design criteria for redundant equipment are presented. Recommendations for the development of technological areas pertinent to the goal of increased verification capabilities are given.

Source record↗

Expert system verification concerns in an operations environment

The Space Shuttle community is currently developing a number of knowledge-based tools, primarily expert systems, to support Space Shuttle operations. It is proposed that anticipating and responding to the requirements of the operations environment will contribute to a rapid and smooth transition of expert systems from development to operations, and that the requirements for verification are critical to this transition. The paper identifies the requirements of expert systems to be used for flight planning and support and compares them to those of existing procedural software used for flight planning and support. It then explores software engineering concepts and methodology that can be used to satisfy these requirements, to aid the transition from development to operations and to support the operations environment during the lifetime of expert systems. Many of these are similar to those used for procedural hardware.

Goodwin, Mary Ann↗

Verification of Anisotropic Mesh Adaptation for Turbulent Simulations over ONERA M6 Wing

Unstructured anisotropic mesh adaptation is known to be an efficient way to control discretization errors in Computational Fluid Dynamics (CFD) simulations. Method verification is required to provide the confidence for routine use in production analysis. The current work aims at verification of anisotropic mesh adaptation for RANS simulations over the ONERA M6 wing. The present verification study is performed using four different flow solvers, three different implementations of the metric field, and three mesh mechanics packages. Two of the flow solvers use stabilized finite-element discretizations (FUN3D-SFE and GGNS), one uses finite-volume discretization (FUN3D-FV), and the last one uses mixed finite-volume and finite element discretizations (Wolf). The mesh adaptation is based on an error estimator that aims to control the quadratic error term in the linear interpolation of Mach number. Two sets of adaptations were performed; the first one controls the interpolation error in L2 norm and the second one controls the interpolation error in L4 norm. Convergence studies were performed on the forces and the pitching moment using all four solvers, and the results are compared with previously verified convergence studies on fixed (nonadapted) meshes. Both forces and pitching moment on adapted meshes are found to be converging to the fine mesh values faster than those on fixed meshes. In addition to forces and moments, convergence of surface pressure and skin friction coefficients at various measurement locations on the wing are also presented. Adapted-mesh surface pressure distributions agree with the fine fixed mesh pressure distributions. Adapted-mesh skin friction distributions contain high frequency noise with mean values approaching the fixed mesh pressure skin friction distributions.

Aravind Balan↗

Synthesis of Correct Digital Controller Models from Specifications by Model Transformation (21-0320)

The design of high consequence controllers (in weapons systems, autonomy, etc.) that do what they are supposed to do is a significant challenge. Testing simply does not come close to meeting the requirements for assurance. Today circuit designers at Sandia (and elsewhere) typically capture the core behavior of their components using state models in tools such as STATEFLOW. They then check that their models meet certain requirements (e.g. “The system bus must not deadlock” or “both traffic lights at an intersection must not be green at the same time”) using tools called model checkers. If the model checker returns “yes” then the property is guaranteed to be satisfied by the model. However, there are several drawbacks to this industry practice: (1) there is a lot of detail to get right, this is particularly challenging when there are multiple components requiring complex coordination (2) any errors returned by the model checker have to be traced back through the design and fixed, necessitating rework, (3) there are severe scalability problems with this approach, particularly when dealing with concurrency. All this places high demands on the designers who now face not only an accelerated schedule but also controllers of increasing complexity. This report describes a new and fundamentally different approach to the construction of safety-critical digital controllers. Instead of directly constructing a complete model and then trying to verify it, the designer can start with an initial abstract (think “sketch”) model plus the requirements, from which a correct concrete model is automatically synthesized. There is no need for post-hoc verification of required functional properties. Having tool to carry this out will significantly impact the nation’s ability to ensure the safety of high-consequence digital systems. The approach has been implemented in a prototype tool, along with a suite of examples, including ones that reflect actual problems faced by designers. Our approach operates on a variant of Statecharts developed at Sandia called Qspecs. Statecharts are a widely used formalism for developing concurrent reactive systems, supporting scalability through allowing state models containing composite states, which are the serial or parallel composition of substates which can themselves contain statecharts. Statecharts enable an incremental style of development, in which states are progressively refined to incorporate greater detail in an incremental model of software development. Our approach formulates a set of constraints from the structure of the models and the requirements and propagates these constraints to a fixpoint. The solution to the constraints is an inductive invariant along with guards on the transitions. We also show how our approach extends to implementation refinement, decomposition, composition, and elaboration. We currently handle safety requirements written in LTL (Linear Temporal Logic)

42 ENGINEERING↗

Innovative Research Program: Supershields for Gamma-Ray Astronomy

The supershield project evaluated the importance of novel shield configurations for suppressing neutron induced background in new classes of gamma-ray detectors such as CZT. The basic concept was to use a two-part shield. The outer shield material heavily moderates the incoming neutron spectrum. This moderated neutron beam is then more easily absorbed by the inner material, which is an efficient neutron absorber. This approach is, in principle, more efficient than that in previous attempts to make neutron shields. These previous attempts involved biatomic, monlithic shields (eg. LiH) in which the shield consisted of a single material but with two types of atoms - one for moderating and one for absorbing. The problem with this type of monolithic shield is that moderating neutrons, without the efficient absorption of them, leads to the leakage into the detector of neutrons with a low energy component (approx. 10-100 KeV). These energy neutrons are particularly problematic for many types of detectors. The project was roughly divided into phases. In the first phase we attempted to carefully define the neutron source function incident on any space instrument. This is essential since the design of any shield depends on the shape of the incident neutron spectrum. We found that approximations commonly used in gamma-ray astronomy for photon background is inadequate. In addition, we found that secondary neutrons produced in any passive shield, and dominated by inelastic neutron scattering, are far more important than background due to neutron activation. The second phase of our work involved design of supershield geometries (one and three dimensional) in order to compare different shield configurations and materials for their effectiveness as neutron shields. Moreover we wanted to compare these supershields with previous neutron shields to confirm the performance differences between the supershield (two material) and monolithic (one material) designs and to understand the physics origins of these differences more clearly. The third phase of the supershield program involved the benchmarking of the supershield designs through direct experimental verification. This required fabricating various supershields and exposing them to beams of neutrons to directly characterize their performance. With explicit verification that our modeling procedures can be used with confidence, we are now in a position to design shields for realistic space geometries. Using the supershield modeling capacity developed as part of this program we are attempting to evaluate their utility for a specific proposed mission--the Energetic X-ray Imaging Survey Telescope (EXIST). It is anticipated that this experiment, which is limited by internal background at high energies, might benefit from a neutron shield.

Hailey, Charles J.↗

Drive program documentation

The program description and user's guide for the Downlist Requirement Integrated Verification and Evaluation (DRIVE) program is provided. The program is used to compare existing telemetry downlist files with updated downlist requirements.

Graham, S.↗

Hierarchical Design and Verification for VLSI

The specification and verification work is described in detail, and some of the problems and issues to be resolved in their application to Very Large Scale Integration VLSI systems are examined. The hierarchical design methodologies enable a system architect or design team to decompose a complex design into a formal hierarchy of levels of abstraction. The first step inprogram verification is tree formation. The next step after tree formation is the generation from the trees of the verification conditions themselves. The approach taken here is similar in spirit to the corresponding step in program verification but requires modeling of the semantics of circuit elements rather than program statements. The last step is that of proving the verification conditions using a mechanical theorem-prover.

Shostak, R. E.↗

Code Verification of Multiple Physics-Fidelity Models in Hypersonic Aerodynamics

Hypersonic aerodynamics models exist across a range of physics fidelities with associated computational expenses. These models may be run independently or in a multifidelity framework that leverages their complementary strengths of speed for lower-fidelity and accuracy for higher-fidelity models. This work presents applied code verification of two lower-fidelity models contained within the Sandia hypersonic aerodynamics code. Each model has a different form that requires individualized verification approaches, including comparison to analytical solutions as well as manufactured solutions with order-of-accuracy testing. In conclusion, results of this effort include the identification and resolution of code errors and shortcomings, as well as the demonstration of code correctness and consistency for both models.

Aerodynamics↗

Status on the Verification of Combustion Stability for the J-2X Engine Thrust Chamber Assembly

Development is underway of the J -2X engine, a liquid oxygen/liquid hydrogen rocket engine for use on the Space Launch System. The Engine E10001 began hot fire testing in June 2011 and testing will continue with subsequent engines. The J -2X engine main combustion chamber contains both acoustic cavities and baffles. These stability aids are intended to dampen the acoustics in the main combustion chamber. Verification of the engine thrust chamber stability is determined primarily by examining experimental data using a dynamic stability rating technique; however, additional requirements were included to guard against any spontaneous instability or rough combustion. Startup and shutdown chug oscillations are also characterized for this engine. This paper details the stability requirements and verification including low and high frequency dynamics, a discussion on sensor selection and sensor port dynamics, and the process developed to assess combustion stability. A status on the stability results is also provided and discussed.

Casiano, Matthew↗

Uncertainty Propagation from Experiment Measurements to Modeling Approaches: A Case for SMR Steam Entrainment Testing

To license new and advanced reactor designs, regulators must be convinced that their unique safety cases—relative to existing large scale reactors—have been adequately addressed by the designed reactor protection systems. In water cooled small modular reactors (SMRs), droplet entrainment in steam flow has significant implications on the progression of accident scenarios due to its compact design features, which requires representative test data applicable to SMR designs. Computer code, modeling and simulation (M&S) tools and models require adequate verification, assessment, and qualification. This includes M&S results validation against scaled empirical data within allowable uncertainty bands to gain regulatory approvals during the various stages of reactor system design, demonstration, and commercialization. However, measurement uncertainty within the empirical datasets and test data applicability ranges requires careful consideration of M&S inputs (i.e., boundary conditions, and initial conditions), and verification and validation efforts. This study focuses on uncertainty quantification in designing scaled test facilities for SMR applications with appropriate measurements and a standard data-reduction method to estimate thermal hydraulics characteristics parameters that incorporate physics phenomena of interest. In addition, this study supports the evaluation model development and assessment process using M&S that interfaces with advanced computing tools and digital twin capabilities. This will allow synchronization between experiment and modeling approaches for droplet entrainment testing and analysis, improving diagnostics, prognostics, and decision-making to accelerate regulatory approval.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Verification and Quantification of Single Event Effects on High Speed SRAM in Terrestrial Environments

As integrated circuits become more sensitive to charged particles and neutrons, anomalous performance due to single event effects (SEE) is a concern and requires experimental verification and quantification. The Center for Applied Radiation Research (CARR) at Prairie View A&M University has developed experiments as a participant in the NASA ER-2 Flight Program, the APEX balloon flight program and the Student Launch Program. Other high altitude and ground level experiments of interest to DoD and commercial applications are being developed. The experiment characterizes the SEE behavior of high speed and high density SRAM's. The system includes a PC-104 computer unit, an optical drive for storage, a test board with the components under test, and a latchup detection and reset unit. The test program will continuously monitor the stored checkerboard data pattern in the SW and record errors. Since both the computer and the optical drive contain integrated circuits, they are also vulnerable to radiation effects. A latchup detection unit with discrete components will monitor the test program and reset the system when necessary. The first results will be obtained from the NASA ER-2 flights, which are now planned to take place in early 1998 from Dryden Research Center in California. The series of flights, at altitudes up to 70,000 feet, and a variety of flight profiles should yield a distribution of conditions for correlating SEES. SEE measurements will be performed from the time of aircraft power-up on the ground throughout the flight regime until systems power-off after landing.

Huff, H.↗

The Roles of Verification, Validation and Uncertainty Quantification in the NASA Standard for Models and Simulations

The National Aeronautics and Space Administration (NASA) recently issued an interim version of the Standard for Models and Simulations (M&S Standard) [1]. The action to develop the M&S Standard was identified in an internal assessment [2] of agency-wide changes needed in the wake of the Columbia Accident [3]. The primary goal of this standard is to ensure that the credibility of M&S results is properly conveyed to those making decisions affecting human safety or mission success criteria. The secondary goal is to assure that the credibility of the results from models and simulations meets the project requirements (for credibility). This presentation explains the motivation and key aspects of the M&S Standard, with a special focus on the requirements for verification, validation and uncertainty quantification. Some pilot applications of this standard to computational fluid dynamics applications will be provided as illustrations. The authors of this paper are the members of the team that developed the initial three drafts of the standard, the last of which benefited from extensive comments from most of the NASA Centers. The current version (number 4) incorporates modifications made by a team representing 9 of the 10 NASA Centers. A permanent version of the M&S Standard is expected by December 2007. The scope of the M&S Standard is confined to those uses of M&S that support program and project decisions that may affect human safety or mission success criteria. Such decisions occur, in decreasing order of importance, in the operations, the test & evaluation, and the design & analysis phases. Requirements are placed on (1) program and project management, (2) models, (3) simulations and analyses, (4) verification, validation and uncertainty quantification (VV&UQ), (5) recommended practices, (6) training, (7) credibility assessment, and (8) reporting results to decision makers. A key component of (7) and (8) is the use of a Credibility Assessment Scale, some of the details of which were developed in consultation with William Oberkampf, David Peercy and Timothy Trocano of Sandia National Laboratories. The focus of most of the requirements, including those for VV&UQ, is on the documentation of what was done and the reporting, using the Credibility Assessment Scale, of the level of rigor that was followed. The aspects of one option for the Credibilty Assessment Scale are (1) code verification, (2) solution verification, (3) validation, (4) predictive capability, (5) technical review, (6) process control, and (7) operator and analyst qualification.

Zang, Thomas A.↗

MPLM On-Orbit Interface Dynamic Flexibility Modal Test

Now that the International Space Station (ISS) is being constructed, payload developers have to not only verify the Shuttle-to-payload interface, but also the interfaces their payload will have with the ISS. The Multi Purpose Logistic Module (MPLM) being designed and built by Alenia Spazio in Torino, Italy is one such payload. The MPLM is the primary carrier for the ISS Payload Racks, Re-supply Stowage Racks, and the Resupply Stowage Platforms to re-supply the ISS with food, water, experiments, maintenance equipment and etc. During the development of the MPLM there was no requirement for verification of the on-orbit interfaces with the ISS. When this oversight was discovered, all the dynamic test stands had already been disassembled. A method was needed that would not require an extensive testing stand and could be completed in a short amount of time. The residual flexibility testing technique was chosen. The residual flexibility modal testing method consists of measuring the free-free natural frequencies and mode shapes along with the interface frequency response functions (FRF's). Analytically, the residual flexibility method has been investigated in detail by, MacNeal, Martinez, Carne, and Miller, and Rubin, but has not been implemented extensively for model correlation due to difficulties in data acquisition. In recent years improvement of data acquisition equipment has made possible the implementation of the residual flexibility method as in Admire, Tinker, and Ivey, and Klosterman and Lemon. The residual flexibility modal testing technique is applicable to a structure with distinct points (DOF) of contact with its environment, such as the MPLM-to-Station interface through the Common Berthing Mechanism (CBM). The CBM is bolted to a flange on the forward cone of the MPLM. During the fixed base test (to verify Shuttle interfaces) some data was gathered on the forward cone panels. Even though there was some data on the forward cones, an additional modal test was performed to better characterize its behavior. The CBM mounting flange is the only remaining structure of the MPLM that no test data was available. This paper discusses the implementation of the residual flexibility modal testing technique on the CBM flange and the modal test of the forward cone panels.

Bookout, Paul S.↗

Shuttle automatic landing system

The Shuttle automatic landing system design requirements are discussed, the approach and landing flight phase is described, and the hardware and software subsystems are functionally described. Emphasis is placed on the complexity, flexibility, and criticality of the software function. The software structure, critical computational problems, and verification process as a subsystem are discussed. Finally, the hardware/software verification activities required before flight test of the autoland system are described, along with the results from two flight tests and the planned system certification to the operational flight boundaries.

Tsikalas, G.↗

Fly-by-light flight control system technology development plan

The results of a four-month, phased effort to develop a Fly-by-Light Technology Development Plan are documented. The technical shortfalls for each phase were identified and a development plan to bridge the technical gap was developed. The production configuration was defined for a 757-type airplane, but it is suggested that the demonstration flight be conducted on the NASA Transport Systems Research Vehicle. The modifications required and verification and validation issues are delineated in this report. A detailed schedule for the phased introduction of fly-by-light system components has been generated. It is concluded that a fiber-optics program would contribute significantly toward developing the required state of readiness that will make a fly-by-light control system not only cost effective but reliable without mitigating the weight and high-energy radio frequency related benefits.

Chakravarty, A.↗

Category B Plastic Pane Testing for JSC 66320 Rev A Requirements Verifiable Through Acceptance Testing

JSC 66320, Revision A, Optical Property Requirements for Glasses, Ceramics, and Plastics in Spacecraft Window Systems, lists several quantitative requirements that spacecraft windowpanes must meet. Recently, we were asked to establish a capability at the Kennedy Space Center to perform these measurements on category B plastic panes, i.e., plastic panes that could be used on a spacecraft for long-focal-length photography and piloting. Two of the criteria, normal wavefront and 30-degree wavefront attributes, can be measured with existing equipment and processes (see NASA TM NESC-RP-14-00951, April 2016) and are not discussed in this document. However, the other six criteria-haze, wedge angle, birefringence, reflectance, transmittance, and color balance-required substantial development and are the subject of this document. In this document, we do not discuss the rationale behind the requirements, but we did engage in discussions with the authors of JSC 66320 in order to better understand the requirements and the verifications being imposed on windows and their testing. Accordingly, this document presents our best understanding of the requested requirements and verifications. We also present our methodology for performing each of the six measurements, along with applicable mathematics and a description, with photos, of the hardware used. In addition, we supply the results of a test on a low-quality in-house plastic window as an example of the system operation. Only requirements that can be met by acceptance test and analysis, as opposed to optical inspection, are considered in this document.

spaceflight windows↗

Towards the formal specification of the requirements and design of a processor interface unit

Work to formally specify the requirements and design of a Processor Interface Unit (PIU), a single-chip subsystem providing memory interface, bus interface, and additional support services for a commercial microprocessor within a fault-tolerant computer system, is described. This system, the Fault-Tolerant Embedded Processor (FTEP), is targeted towards applications in avionics and space requiring extremely high levels of mission reliability, extended maintenance free operation, or both. The approaches that were developed for modeling the PIU requirements and for composition of the PIU subcomponents at high levels of abstraction are described. These approaches were used to specify and verify a nontrivial subset of the PIU behavior. The PIU specification in Higher Order Logic (HOL) is documented in a companion NASA contractor report entitled 'Towards the Formal Specification of the Requirements and Design of a Processor Interfacs Unit - HOL Listings.' The subsequent verification approach and HOL listings are documented in NASA contractor report entitled 'Towards the Formal Verification of the Requirements and Design of a Processor Interface Unit' and NASA contractor report entitled 'Towards the Formal Verification of the Requirements and Design of a Processor Interface Unit - HOL Listings.'

Fura, David A.↗

Use of COTS Batteries on ISS and Shuttle

This presentation focuses on COTS Battery testing for energy content, toxicity, hazards, failures modes and controls for different battery chemistries. It also discusses the current program requirements, challenges with COTS Batteries in manned vehicle COTS methodology, JSC test details, and gives a list of incidents from consumer protection safety commissions. The Battery test process involved testing new batteries for engineering certification, qualification of batteries, flight acceptance, cell and battery, environment, performance and abuse. Their conclusions and recommendations were that: high risk is undertaken with the use of COTS batteries, hazard control verification is required to allow the use of these batteries on manned space flights, failures during use cannot be understood if different scenarios of failure are not tested on the ground, and that testing is performed on small sample numbers due to restrictions on cost and time. They recommend testing of large sample size to gain more confidence in the operation of the hazard controls.

Jeevarajan, Judith A.↗