Dependability Quantification and Assurance of Mission-Critical Software Systems
No abstract available
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
No abstract available
This is a tutorial on how to use the IKOS tool for static analysis of C/C++ code for flight critical system. The tutorial explains what static code analysis is, what kind of errors IKOS can find, and how to use the tool on single or multiple file projects. Simple examples are given to illustrate the use of the tool. This tutorial also describes the use of IKOS on real mission code, in this case, the flight software for the BioSentinel mission and the Troupe project in the Robust Software Engineering group.
This presentation gives an overview of the technology, methods and processes developed during the TC3 Technical Challenge of the System-Wide Safety (SWS) project. The presentation goes over the motivation for doing this research, gives an overview of the tool, methods and process developed under this program, and describes case studies and impact in industry.
Explore the source record for details and available documents.
Computational tools have a crucial role to play in accelerating the deployment of fusion as a clean, reliable, abundant, and sustainable energy source. Multiphysics, high-fidelity simulation capabilities can help model, study, and predict intricate interactions between materials performance, plasma exposure, neutron irradiation, and engineering processes. As such, they can assist in the resolution of scientific and engineering challenges underpinning design, construction, and commission of fusion power plants. To address these needs, ongoing efforts are leveraging the Multiphysics Object-Oriented Simulation Environment (MOOSE) framework and delivering new computational tools for the fusion community. These tools inherit crucial attributes from MOOSE. They are open-source, modular, integrated with nuclear industry-standard software quality assurance processes, and enable multiphysics, multi-fidelity, fully integrated, zero- to three-dimensional, and massively parallel simulations. After a short overview of these capabilities, we will present the development of Fusion ENergy Integrated multiphys-X (FENIX), a MOOSE-based application designed to enable plasma facing component design and performance evaluation. Throughout their lifetime, plasma facing components are exposed to extreme thermal loads, repeated thermal shocks, and irradiation by plasma ions, neutral particles, and high-energy neutrons. Consequently, designing a plasma facing component with acceptable lifetime degradation is extremely challenging. FENIX aims to model the multiphysics environment in which plasma facing components evolve to accelerate their design studies. To that end, FENIX couples existing MOOSE capabilities such as heat transfer, thermomechanics, and thermal hydraulics, with tritium transport via the MOOSE-based Tritium Migration Analysis Program, Version 8 (TMAP8), with neutronics via the MOOSE-based high-fidelity neutron-photon transport and fluid dynamics code Cardinal, and finally with Particle-in-Cell plasma simulation capabilities being developed in this project. In this study, we present the current FENIX capabilities and preliminary results of its application to model the Tritium Plasma Experiment set up at Idaho National Laboratory.
As the need for fusion as a clean, sustainable, and abundant energy source grows internationally, so does the need for multiphysics, computational tools to model, study, and predict the complex interactions between plasma, materials, and engineering processes. These tools have a crucial role to play in solving scientific and engineering challenges and accelerating fusion energy deployment. To address these needs, modeling capabilities should enable massively parallel, multiphysics, fully integrated high-fidelity simulations of fusion systems. Additional attributes, such as being open source and modular while maintaining high software quality assurance standards will maximize impact by ensuring accessibility for all and wide acceptance, rapid expansion and development, as well as reliability, efficiency, and robustness. In this paper, we describe how the Multiphysics Object-Oriented Simulation Environment (MOOSE) framework, which has a track record of success in the fission space thanks to the attributes listed above, can be leveraged in the fusion energy field. We highlight key successes of the MOOSE application in the fission space and describe how MOOSE has been and is being applied to fusion applications in the United States---e.g., Tritium Migration Analysis Program, version 8 (TMAP8), MOOSE Fusion Module, Fusion ENergy Integrated multiphys-X (FENIX)---and the United Kingdom---e.g., AURORA, Achlys, Apollo. These efforts aim to establish a suite of tools that can be further extended to accelerate fusion energy deployment.
Advanced modeling and simulation tools have a crucial role to play in accelerating fusion energy deployment as a sustainable power source. Multiphysics, high-fidelity computational tools can help understand, model, and quantify the complex interactions between materials performance, plasma and neutron exposure, and engineering processes. As a result, they accelerate the design, safety analysis, and performance evaluation of fusion systems. This webinar introduces the Fusion ENergy Integrated multiphys-X (FENIX) framework, an open-source multiphysics tool for plasma facing component modeling. FENIX leverages the Multiphysics Object-Oriented Simulation Environment (MOOSE) framework, which has been developed by the United States Department of Energy Nuclear Energy Advanced Modeling and Simulation (NEAMS) program. FENIX couples various MOOSE capabilities such as heat transfer, thermomechanics, thermal hydraulics, electromagnetics, and plasma kinetics with the MOOSE-based applications Cardinal (neutronics) and TMAP8 (tritium transport). During the webinar, we will present FENIX and discuss how its modularity, openness, software quality assurance processes, and licensing approach supports effective collaborations, including public-private partnerships.
A suite of experimental infrastructure projects has been developed by the National Reactor Innovation Center to accelerate advanced reactor demonstrations and facilitate their development, addressing crucial gaps in data, materials characterization, and modeling. First, the Molten Salt Thermophysical Examination Capability (MSTEC) provides a specialized platform for post-irradiation characterization of molten salt reactor fuel, coolant salts, and structural materials, essential for supporting the design and operation of advanced reactors and future commercial molten salt reactor development and licensing. The Virtual Test Bed (VTB) complements these efforts by leveraging advanced modeling and simulation tools to evaluate reactor performance and safety. Serving as a library of reference models, the VTB offers a database of multiphysics reactor models, facilitating rapid safety evaluations and includes continuous software quality assurance, crucial for accelerating deployment while maintaining reliability. Additionally, the Helium Component Test Facility (HeCTF) addresses the need for high-temperature helium-cooled reactor component testing. As the first-of-its-kind facility in the United States, HeCTF emulates high-temperature gas reactor conditions, reducing time and cost associated with component validation, thereby accelerating reactor development. Finally, In-cell Thermal Creep Frames provide a unique solution for obtaining thermal creep data from irradiated materials, critical for materials qualification and licensing. Developed by the National Reactor Innovation Center, these compact frames enable the examination of previously irradiated materials, overcoming traditional limitations and enhancing the understanding of mechanical properties crucial for reactor development. Collectively, these experimental infrastructure projects form a comprehensive framework aimed at expediting advanced reactor demonstrations, fostering innovation, and ensuring the viability of next-generation nuclear energy solutions.
This report has been prepared to supplement a forthcoming chapter on formal methods in the FAA Digital Systems Validation Handbook. Its purpose is as follows: to outline the technical basis for formal methods in computer science; to explain the use of formal methods in the specification and verification of software and hardware requirements, designs, and implementations; to identify the benefits, weaknesses, and difficulties in applying these methods to digital systems used on board aircraft; and to suggest factors for consideration when formal methods are offered in support of certification. These latter factors assume the context for software development and assurance described in RTCA document DO-178B, 'Software Considerations in Airborne Systems and Equipment Certification,' Dec. 1992.
This paper summarizes key findings related to methods for the risk considerations of autonomy software. Existing methods for Verification and Validation (V&V) of autonomy software are summarized and a method for the assurance of autonomy software is suggested and demonstrated on a command execution use case. Risk and reliability are defined in the context of autonomy and an approach for risk assessment of autonomy is presented using an example use case. Key insights regarding areas of uncertainty for autonomy are provided, along with a suggested architecture for the systematic consideration of reliability within the context of a given autonomous planner.
Verification and validation (V&V) is used to increase the level of assurance of critical software, particularly that of safety-critical and mission critical software. This paper describes the working group's success in identifying V&V tasks that could be performed in the domain engineering and transition levels of reuse-based software engineering. The primary motivation for V&V at the domain level is to provide assurance that the domain requirements are correct and that the domain artifacts correctly implement the domain requirements. A secondary motivation is the possible elimination of redundant V&V activities at the application level. The group also considered the criteria and motivation for performing V&V in domain engineering.
Fault Management (FM) systems are ranked high in risk-based assessment of criticality within flight software, emphasizing the importance of establishing highly competent domain expertise to provide assurance for NASA projects, especially as spaceflight systems continue to increase in complexity. Insight into specific characteristics of FM architectures seen embedded within safety- and mission-critical software systems analyzed by the NASA Independent Verification Validation (IVV) Program has been enhanced with an FM Technical Reference (TR) suite. Benefits are aimed beyond the IVV community to those that seek ways to efficiently and effectively provide software assurance to reduce the FM risk posture of NASA and other space missions. The identification of particular FM architectures, visibility, and associated IVV techniques provides a TR suite that enables greater assurance that critical software systems will adequately protect against faults and respond to adverse conditions. The role FM has with regard to overall asset protection of flight software systems is being addressed with the development of an adverse condition (AC) database encompassing flight software vulnerabilities.Identification of potential off-nominal conditions and analysis to determine how a system responds to these conditions are important aspects of hazard analysis and fault management. Understanding what ACs the mission may face, and ensuring they are prevented or addressed is the responsibility of the assurance team, which necessarily should have insight into ACs beyond those defined by the project itself. Research efforts sponsored by NASAs Office of Safety and Mission Assurance defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs, and allowing queries based on project, mission type, domain component, causal fault, and other key characteristics. The repository has a firm structure, initial collection of data, and an interface established for informational queries, with plans for integration within the Enterprise Architecture at NASA IVV, enabling support and accessibility across the Agency. The development of an improved workflow process for adaptive, risk-informed FM assurance is currently underway.
Verification and Validation (V&V) is used to increase the level of assurance of critical software, particularly that of safety-critical and mission-critical software. V&V is a systems engineering discipline that evaluates the software in a systems context, and is currently applied during the development of a specific application system. In order to bring the effectiveness of V&V to bear within reuse-based software engineering, V&V must be incorporated within the domain engineering process.
NASA (National Aeronautics and Space Administration) relies more and more on software to control, monitor, and verify its safety critical systems, facilities and operations. Since the 1960's there has hardly been a spacecraft (manned or unmanned) launched that did not have a computer on board that provided vital command and control services. Despite this growing dependence on software control and monitoring, there has been no consistent application of software safety practices and methodology to NASA's projects with safety critical software. Led by the NASA Headquarters Office of Safety and Mission Assurance, the NASA Software Safety Standard (STD-18l9.13B) has recently undergone a significant update in an attempt to provide that consistency. This paper will discuss the key features of the new NASA Software Safety Standard. It will start with a brief history of the use and development of software in safety critical applications at NASA. It will then give a brief overview of the NASA Software Working Group and the approach it took to revise the software engineering process across the Agency.
This paper explores a new approach to validating software implementations that have been produced from formally-verified algorithms. Although visual inspection gives some confidence that the implementations faithfully reflect the formal models, it does not provide complete assurance that the software is correct. The proposed approach, which is based on animation of formal specifications, compares the outputs computed by the software implementations on a given suite of input values to the outputs computed by the formal models on the same inputs, and determines if they are equal up to a given tolerance. The approach is illustrated on a prototype air traffic management system that computes simple kinematic trajectories for aircraft. Proofs for the mathematical models of the system's algorithms are carried out in the Prototype Verification System (PVS). The animation tool PVSio is used to evaluate the formal models on a set of randomly generated test cases. Output values computed by PVSio are compared against output values computed by the actual software. This comparison improves the assurance that the translation from formal models to code is faithful and that, for example, floating point errors do not greatly affect correctness and safety properties.
This report validates and documents the detailed features and practical application of the framework for software intensive digital systems risk assessment and risk-informed safety assurance presented in the NASA PRA Procedures Guide for Managers and Practitioner. This framework, called herein the "Context-based Software Risk Model" (CSRM), enables the assessment of the contribution of software and software-intensive digital systems to overall system risk, in a manner which is entirely compatible and integrated with the format of a "standard" Probabilistic Risk Assessment (PRA), as currently documented and applied for NASA missions and applications. The CSRM also provides a risk-informed path and criteria for conducting organized and systematic digital system and software testing so that, within this risk-informed paradigm, the achievement of a quantitatively defined level of safety and mission success assurance may be targeted and demonstrated. The framework is based on the concept of context-dependent software risk scenarios and on the modeling of such scenarios via the use of traditional PRA techniques - i.e., event trees and fault trees - in combination with more advanced modeling devices such as the Dynamic Flowgraph Methodology (DFM) or other dynamic logic-modeling representations. The scenarios can be synthesized and quantified in a conditional logic and probabilistic formulation. The application of the CSRM method documented in this report refers to the MiniAERCam system designed and developed by the NASA Johnson Space Center.
Independent verification and validation (IV&V) is a systems engineering discipline which seeks to provide confidence that mission-critical software-dependent systems will operate safely and achieve all mission objectives. In order to optimize application of IV&V resources, it is necessary to identify specific assurance objectives that are most likely to reveal difficulty and therefore to increase confidence. Software assurance literature deals predominantly with the code itself. However, our experience is that the most significant software-related issues are discovered via analysis of other system artifacts such as operations concepts, requirements and design. Consequently, it is desirable to, when assessing risk and defining assurance objectives, consider all facets of the software system architecture. We describe in this presentation progress and lessons learned from an IV&V capability development initiative to enhance the IV&V project planning process using all available architecture information.
This monograph contains standards for software development and engineering. The book sets forth rules for design, specification, coding, testing, documentation, and quality assurance audits of software; it also contains detailed outlines for the documentation to be produced.