Establishing a Framework and Testbed for Evaluating and Infusing Software Assurance Tools
No abstract available
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
No abstract available
The CERES SYN1deg product provides climate quality 3-hourly globally gridded and temporally complete maps of top of atmosphere, in atmosphere, and surface fluxes. This product requires efficient release to the public and validation to maintain quality assurance. The CERES team developed web-tools for the distribution of both the global gridded products and grid boxes that contain long term validation sites that maintain high quality flux observations at the Earth's surface. These are found at: http://ceres.larc.nasa.gov/order_data.php. In this poster we explore the various tools available to users to sub-set, download, and validate using surface observations the SYN1Deg and Surface-EBAF products. We also analyze differences found in long-term records from well-maintained land surface sites such as the ARM central facility and high quality buoy radiometers, which due to their isolated nature cannot be maintained in a similar manner to their land based counterparts.
Over the past 4 years, the United States (U.S.) Government has issued several new National policies that fundamentally change the approach to nuclear flight safety for aerospace applications, including the complete revision of the Federal policy for handling launch of spacecraft containing space nuclear systems. In response, the National Aeronautics and Space Administration (NASA) is updating its nuclear flight safety program while still maintaining consistency with other Federal policies, international conventions, and NASA’s own policies. To achieve this evolution, NASA is factoring in an objectives-driven and assurance case mindset to develop a risk-informed and performance-based program. NASA and others have successfully applied this mindset in other disciplines and contexts and it is being pursued here via broad cooperation within NASA and with external stakeholders. This paper will briefly describe how the NASA nuclear flight safety program is evolving to meet these changing needs.
In recent years, the United States (U.S.) Government has issued several new National policies that fundamentally change the approach to nuclear flight safety for aerospace applications, including the complete revision of the Federal policy for handling launch of spacecraft containing space nuclear systems. In response, the National Aeronautics and Space Administration (NASA) is updating its nuclear flight safety program while still maintaining consistency with other Federal policies, international conventions, and NASA’s own policies. To achieve this evolution, NASA is factoring in an objectives-driven and assurance case mindset to develop a risk-informed and performance-based program. NASA and others have successfully applied this mindset in other disciplines and contexts and it is being pursued here via broad cooperation within NASA and with external stakeholders. This paper will briefly describe how the NASA nuclear flight safety program is evolving to meet these changing needs.
A new tool has been developed to perform variance-based global sensitivity analysis (VBGSA) on data from a set-based concurrent engineering software called Success Assured (SA). The tool is part of a digital component design app, which is currently in production as an Accelerated Digital Engineering Pathfinder at Sandia National Laboratories. When working with complex digital models, it is important to understand relationships between inputs and outputs, i.e., how “sensitive” model outputs are to changes in model inputs. After extensive research and trials of various sensitivity analysis methods, it was determined that estimation of Sobol’ indices for VBGSA with Monte Carlo simulation, paired with simple surrogate models, produces the best results for SA data. This tool increases understanding of SA models and streamlines the creation of SA datasets. This report details the methodology and implementation of this sensitivity analysis tool so others can understand it and implement it.
Autonomous systems react intelligently to their environments, making them capable of handling many possible conditions, but challenging to test. We are investigating a new test development method that aims to maximize the confidence to be achieved by combining Assurance Cases with High Throughput Testing (HTT). Assurance Cases, developed for safety-critical systems, are a rigorous argument that the system satisfies a property (e.g., the Mars rover will not tip over during a traverse). They integrate testing, analysis, and environmental and operational assumptions, from which the set of conditions that testing must cover is determined. In our method, information from the Assurance Case is used to determine the test coverage needed, and then input to HTT to generate the minimal test suites needed to provide that coverage.
The successful launch of a space shuttle vehicle depends on the proper operation of two tail service masts (TSMs). Reliable TSM operation is assured through a comprehensive design, development, and testing program. The results of the concept verification test (CVT) and the resulting impact on prototype TSM design are presented. The design criteria are outlined, and the proposed prototype TSM tests are described.
In developing a permanently crewed space station, the importance of medical care has been continually reaffirmed; and the health maintenance facility (HMF) is an integral component. It has diagnostic, therapeutic, monitoring, and information management capability. It is designed to allow supportive care for: (1) non-life-threatening illnesses; e.g., headache, lacerations; (2) moderate to severe, possibly life-threatening illnesses; e.g., appendicitis, kidney stones; and (3) severe, incapacitating, life-threatening illnesses; e.g., major trauma, toxic exposure. Since the HMF will not have a general surgical capability, the need for emergency escape and recovery methods has been studied. Medical risk assessments have determined that it is impossible to accurately predict the incidence of crewmember illness/injury. A best estimate is 1:3 per work-year, with 1% of these needing an ACRV. For an eight-person crew, this means that one assured crew return vehicle (ACRV) will be used every 4 to 12 years. The ACRV would serve at least three basic objectives as: (1) a crew return if the space shuttle is unavailable; (2) an escape vehicle from a major time-critical space station emergency; and (3) a full or partial crew return vehicle for a medical emergency. The focus of this paper is the third objective for the ACRV.
In 2010, the National Aeronautics and Space Administration (NASA) established the Commercial Crew Program (CCP) in order to provide human access to the International Space Station and low Earth orbit via the commercial (non-governmental) sector. A particular challenge to NASA has been how to determine that the Commercial Provider's transportation system complies with programmatic safety requirements. The process used in this determination is the Safety Technical Review Board which reviews and approves provider submitted hazard reports. One significant product of the review is a set of hazard control verifications. In past NASA programs, 100% of these safety critical verifications were typically confirmed by NASA. The traditional Safety and Mission Assurance (S&MA) model does not support the nature of the CCP. To that end, NASA S&MA is implementing a Risk Based Assurance process to determine which hazard control verifications require NASA authentication. Additionally, a Shared Assurance Model is also being developed to efficiently use the available resources to execute the verifications.
The activities conducted in support of the Environmental Control and Life Support Team during December 7, 1987 through September 30, 1988 are summarized. The majority of the ongoing support has focused on the ECLSS area. Through a series of initial meetings with the ECLSS team and technical literature review, an initial list of critical topics was developed. Subtasks were then identified or additional related tasks received as action items from the ECLSS group meetings. Although most of the efforts focused on providing MSFC personnel with information regarding specific questions and problems related to ECLSS issues, other efforts regarding identifying an ECLSS Medical Support Team and constructing data bases of technical information were also initiated and completed. The specific tasks are as follows: (1) Provide support to the mechanical design and integration of test systems as related to microbiological concerns; (2) Assist with design of Human Subjects Test Protocols; (3) Interpretation and recommendations pertaining to air/water quality requirements; (4) Assist in determining the design specifications required as related to the Technical Demonstration Program; (5) Develop a data base of all microorganisms recovered from previous subsystem testing; (6) Estimates of health risk of individual microbes to test subjects; (7) Assist with setting limits for safety of test subjects; (8) Health monitoring of test subjects; (9) Assist in the preparation of test plans; (10) Assist in the development of a QA/QC program to assure the validity, accuracy and precision of the analyses; and (11) Assist in developing test plans required for future man in the loop testing.
This paper discusses the need for a space qualification guide, provides a brief description of some common GaAs failure mechanisms, the approach that the NASA MMIC Reliability Assurance Program is following to develop the guide, and the status of the program.
This standard specifies the software assurance program for the provider of software. It also delineates the assurance activities for the provider and the assurance data that are to be furnished by the provider to the acquirer. In any software development effort, the provider is the entity or individual that actually designs, develops, and implements the software product, while the acquirer is the entity or individual who specifies the requirements and accepts the resulting products. This standard specifies at a high level an overall software assurance program for software developed for and by NASA. Assurance includes the disciplines of quality assurance, quality engineering, verification and validation, nonconformance reporting and corrective action, safety assurance, and security assurance. The application of these disciplines during a software development life cycle is called software assurance. Subsequent lower-level standards will specify the specific processes within these disciplines.
A number of specific benefits that fit within the hallmarks of effective development are realized with implementation of model-based approaches to systems and assurance. Model Based Systems Engineering (MBSE) enabled by standardized modeling languages (e.g., SysML®) is at the core. These benefits in the context of spaceflight system challenges can include [1]: • Improved management of complex development • Reduced risk in the development process • Improved cost management • Improved design decisions With appropriate modeling techniques the assurance community also can improve early oversight and insight into project development. NASA has shown the basic constructs of SysML in an MBSE environment offer several key advantages, within a Model Based Mission Assurance (MBMA) initiative [2, 3]. These include the following: • Model viewpoints that promote rapid and systematic assessment of requirements coverage, hazard tagging and risk management • Embedded safety assessments for launch vehicles • Deployment of model assisted development of reliability products - Failure Modes and Effects Analyses (FMEAs) and Fault Trees • Test Planning • Validation and Verification of complex functions • Support of Assurance Case development for complex systems In addition, while there are benefits to be harvested, there is a realization that these do not come without effort and cost. Enabling model-based approaches requires structure, not only in an organizational context, but in a modeling context as well. There can be a steep learning curve and costs associated to train skilled modelers. But, on the other hand, not all of the assurance community need to be modelers. Models themselves must conform to ontologies that enable assurance. This places constraints upon the models and modelers. Optimums have yet to be developed where resources and constraints on modeling must be traded off in the organization and modeling efforts for projects. A number of barriers need to be overcome, as well, which pose challenges to the developers of the software that supports MBSE/MBMA. Information and data must be made to flow seamlessly through the life cycle. Because there is a wide variety of tools used in the community, to avoid the problems of the past of silos, delays, and diverging interests, information should flow among these tools to support the “single source of truth” paradigm of MBSE. This will greatly facilitate MBMA and advancement of assurance functions.
On November 20, 2017, ASTERIA (Arcsecond Space Telescope Enabling Research in Astrophysics), a 6U CubeSat performing a technology demonstration of astrophysical measurements, deployed from the ISS. The technology demonstration goals to achieve precision photometry via arcsecond-level line-of-sight pointing error and highly stable focal plane temperature control were met by February 2018. Extended mission operations are ongoing, with the primary focus on observing nearby stars for transiting exoplanets. Throughout development and operations, the roles of mission assurance and fault protection have proven critical to achieving the primary technical goals and to maintaining a healthy spacecraft through multiple extended missions. Given the budget and schedule constraints typical of a CubeSat, innovative tailoring of processes has been critical to success throughout both development and operations of ASTERIA. Mission assurance plays an important role in identifying and evaluating risk and developing cost-effective mitigations. Flexibility in the fault protection design offers a variety of options for implementing risk mitigations as risks have been uncovered both in pre-delivery testing and in mission operations. This paper will discuss the approach taken on ASTERIA to implement mission assurance and fault protection and the resulting benefits to operational efficiency and success. It will briefly address the advantages of this approach during development, in which the combination of the roles provided mission assurance significant insight to system risks, which feeds back into testing methodologies and directly into fault protection design. Operations will be discussed in detail. During this phase, the roles merge to identify in-flight fault protection updates to efficiently respond to anomalies and improve the likelihood of successful technology demonstrations. The paper will also detail the tools that are used to analyse data, identify anomalies, and develop the updates to uplink to the spacecraft. Finally, the general operational approach will be discussed to highlight the usefulness of the ASTERIA processes and their applicability to future CubeSat missions.
A capability for rapidly performing quantitative risk assessments has been developed by JSC Safety and Mission Assurance for use on project design trade studies early in the project life cycle, i.e., concept development through preliminary design phases. A risk assessment tool set has been developed consisting of interactive and integrated software modules that allow a user/project designer to assess the impact of alternative design or programmatic options on the probability of mission success or other risk metrics. The risk and design trade space includes interactive options for selecting parameters and/or metrics for numerous design characteristics including component reliability characteristics, functional redundancy levels, item or system technology readiness levels, and mission event characteristics. This capability is intended for use on any project or system development with a defined mission, and an example project will used for demonstration and descriptive purposes, e.g., landing a robot on the moon. The effects of various alternative design considerations and their impact of these decisions on mission success (or failure) can be measured in real time on a personal computer. This capability provides a high degree of efficiency for quickly providing information in NASA s evolving risk-based decision environment
NASA, JPL, and DOD are collaborating with GaAs MMIC users, manufacturers, and international space agencies to develop the “GaAs MMIC Reliability and Space Qualification Guide.” This paper discusses the need for a space qualification guide, provides a brief description of some common GaAs failure mechanisms, the approach that the NASA MMIC Reliability Assurance Program is following to develop the guide, and the status of the program.
The growth in cost and importance of software to NASA has caused NASA to address the improvement of software development across the agency. One of the products of this program is a series of guidebooks that define a NASA concept of the assurance processes that are used in software development. The Software Assurance Guidebook, NASA-GB-A201, issued in September, 1989, provides an overall picture of the NASA concepts and practices in software assurance. Second level guidebooks focus on specific activities that fall within the software assurance discipline, and provide more detailed information for the manager and/or practitioner. This is the second level Software Quality Assurance Audits Guidebook that describes software quality assurance audits in a way that is compatible with practices at NASA Centers.
The SMART-NAS Testbed for Safe Trajectory Based Operations Project will deliver an evaluation capability, critical to the ATM community, allowing full NextGen and beyond-NextGen concepts to be assessed and developed. To meet this objective a strong focus will be placed on concept integration and validation to enable a gate-to-gate trajectory-based system capability that satisfies a full vision for NextGen. The SMART-NAS for Safe TBO Project consists of six sub-projects. Three of the sub-projects are focused on exploring and developing technologies, concepts and models for evolving and transforming air traffic management operations in the ATM+2 time horizon, while the remaining three sub-projects are focused on developing the tools and capabilities needed for testing these advanced concepts. Function Allocation, Networked Air Traffic Management and Trajectory Based Operations are developing concepts and models. SMART-NAS Test-bed, System Assurance Technologies and Real-time Safety Modeling are developing the tools and capabilities to test these concepts. Simulation and modeling capabilities will include the ability to assess multiple operational scenarios of the national airspace system, accept data feeds, allowing shadowing of actual operations in either real-time, fast-time and/or hybrid modes of operations in distributed environments, and enable integrated examinations of concepts, algorithms, technologies, and NAS architectures. An important focus within this project is to enable the development of a real-time, system-wide safety assurance system. The basis of such a system is a continuum of information acquisition, analysis, and assessment that enables awareness and corrective action to detect and mitigate potential threats to continuous system-wide safety at all levels. This process, which currently can only be done post operations, will be driven towards "real-time" assessments in the 2035 time frame.