Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Cognitive Bias in Systems Verification

Working definition of cognitive bias: Patterns by which information is sought and interpreted that can lead to systematic errors in decisions. Cognitive bias is used in diverse fields: Economics, Politics, Intelligence, Marketing, to name a few. Attempts to ground cognitive science in physical characteristics of the cognitive apparatus exceed our knowledge. Studies based on correlations; strict cause and effect is difficult to pinpoint. Effects cited in the paper and discussed here have been replicated many times over, and appear sound. Many biases have been described, but it is still unclear whether they are all distinct. There may only be a handful of fundamental biases, which manifest in various ways. Bias can effect system verification in many ways . Overconfidence -> Questionable decisions to deploy. Availability -> Inability to conceive critical tests. Representativeness -> Overinterpretation of results. Positive Test Strategies -> Confirmation bias. Debiasing at individual level very difficult. The potential effect of bias on the verification process can be managed, but not eliminated. Worth considering at key points in the process.

Cognitive bias↗

Europa Clipper Payload Verification and Validation: Avionics-Instrument Interface Test Campaign

NASA's Europa Clipper mission will investigate Jupiter's icy moon Europa using a payload suite consisting of nine instruments to address a range of scientific objectives concerning Europa's habitability. As the project proceeds past its Critical Design Review, confidence is being built in the system's ability to achieve mission objectives through the implementation of a rigorous payload verification and validation (V&V) program. As part of this payload V&V program, instrument box-level testing was performed by the payload team to verify select instrument-avionics interface requirements. This testing was performed at JPL using the avionics testbed's Bulk Data Storage Emulator (BDSEM) with visiting instrument Test Models. This paper summarizes the Data Link test campaign involving roughly four days of functional testing per instrument, including planning, testing methods, types of issues found, and the requirement closure process. Detail is also provided on the development, deployment, and validation of a standardized analysis tool used in data reviews. This testing verified requirements related to commanding rates, loss of link, packet format, clock counters, loopback test capability, and SpaceWire jitter and skew margins. Additional risk reduction testing of basic commanding, counter behavior, science data collection and transfer, and interface swapping was also performed. Because the BDSEM venue was not originally designed to be a run for record venue, the process of characterizing venue fidelity and establishing suitability for requirement closure using data collected in this venue will also be addressed.In order to close requirements, an extensible tool was developed to post-process instrument command and telemetry data from their original binary to a human-readable format and give visibility to errors detected within the data, such as packets with Cyclic Redundancy Check errors. This tool, called payload-packet-parser, is a Python 3.9 command line tool built using a variety of open-source Python libraries. Payload-packet-parser was designed to support parsing command and telemetry packets for all Europa Clipper instruments and additional analysis tools were developed for verification of specific information interface requirements. This test campaign, including post-processing using a single parsing and verification toolset, allowed for early interface testing, alleviating testing burdens on instrument teams and buying down risk on the instrument-avionics interface by finding hardware and software issues and idiosyncrasies prior to integration with system test venues. Over twenty issues were discovered across the payload, resulting in software updates and instrument rework well in advance of any system impacts. This paper concludes with an assessment of benefits and costs of this type of testing and lessons learned.

Montanez, Leticia↗

Autonomy Verification & Validation Roadmap and Vision 2045

Advanced capabilities planned for the next generation of autonomous and increasingly autonomous air vehicles will include non-traditional components based on artificial intelligence, machine learning, and complex optimization and planning algorithms. These complex components will be used to provide enhanced safety and high-level decision-making functions. However, there are serious barriers to the deployment of autonomous aircraft in the National Airspace System (NAS). Current civil aviation certification processes are based on the concept that the correct behavior of a system or a component must be completely specified and verified prior to operation. This report from the Autonomy Verification and Validation (V&V) Roadmap and Vision 2045 project presents the most recent effort to build a comprehensive list of verification challenges and needs for autonomous aircraft, a roadmap to meet those autonomy V&V needs, the services they can enable, and point to the certification gaps they fill. To accomplish these goals, we assembled a team of world-class researchers from the aerospace industry (Boeing, Collins Aerospace, and GeneralElectric) and academia (University of Michigan, University of Texas, and Massachusetts Institute of Technology) with deep expertise in autonomy, aerospace systems, and assurance of Artificial Intelligence/machine learning systems.

Software Assurance↗

The MPD thruster development program

Recent research results have inferred that the self-field magnetoplasmadynamic (MPD) thruster can attain efficiency and specific impulse levels which are competitive with ion thrusters. Based on these results, a program was initiated at JPL to develop this thruster for application on future spacecraft. Preliminary mission analyses have shown that the high thrust density MPD arcjet is advantageous for high power missions, such as a short trip time earth orbit transfer vehicle or a nuclear powered outer planet explorer. Direct thrust stand verification of the inferred performance levels used in these analyses is planned for a facility being assembled at Princeton University. A parallel effort at JPL is considering various thruster system configurations, energy storage concepts and propellant control techniques. In addition, a one pulse per second thruster test facility is planned at JPL to be used for thruster optimization studies including erosion and lifetime measurements.

Rudolph, L. K.↗

Reconstruction of the shuttle reentry air data parameters using a linearized Kalman filter

This paper presents the reconstruction of the space shuttle's wind-relative reentry trajectory for the orbital flights. The technique uses a linearized Kalman filter (LKF) to merge highand low-frequency inertial and wind-relative data to obtain enhanced high-frequency results that closely follow expected mean levels. Two verifications are presented. First, wind trajectories resulting from the reconstruction are compared with analytically predicted values. There is close comparison. Second, the frequency characteristics are investigated using system identification techniques. The stability and control model generated using the LKF trajectory shows good agreement between measured and predicted spacecraft response for both high and low frequencies.

Whitmore, S. A.↗

Multibody Based Digital Astronaut Dynamics Simulation

BACKGROUND: This study provides the Software, Robotics, & Simulation Division at the NASA Johnson Space Center with a verification tool for multibody dynamics simulation requiring human motion. The motivation stems from current studies of several Vibration Isolation & Stabilization(VIS)system designs that attenuate the moments and forces which would be transmitted to a spacecraft during an exercise. A multibody dynamics model for a proposed VIS was available previously[1], therefore modeling of the VIS was not needed for this work. The interest here is in creating the multibody dynamics model of an astronaut in motion which may be utilized independently or while attached to a mechanism. An existing simulation [2] that utilizes OpenSim [3,4] and an in-house multibody dynamics package (MBDyn) [5] is used in order to verify the astronaut model. The main advantage this model will have over the existing simulation is that everything will be processed in one tool. METHODS AND RESULTS: Creating the simulation required; estimation of Body Segment Inertial Parameters (BSIP),a multibody model of the human-VIS system, joint acceleration profiles, and input files for MBDyn, which is used for this analysis. The scaling factors provided by Dumas et al. [6] are utilized in estimating the BSIP. Anthropometric data are used for estimating these parameters, the Anthropometric Survey of US Army Personnel (ANSUR II) [7] was the source. The astronaut model consists of 15 bodies, 14 joints and 32 degrees of freedom, with the dynamics topology generated using the center of mass locations and anthropometric data. MBDyn has an option for prescribed joint motion (PJM), which requires joint acceleration data as input. The joint angle data is first obtained from a motion capture system and then processed through code that has been created to generate approximate joint acceleration profiles. The topology tree for the astronaut model begins at the right foot up to the pelvis where there is one branch for going down the left leg and another for the torso. The torso branch leads to branches for the arms and a leaf body for the head/neck segment. For attachment to the VIS, the heel of the right foot is connected to the VIS platform through a fixed joint, resembling a foot restraint. The left foot does not attach to the platform in order to prevent a system with a closed loop. Topology and symmetry of the astronaut model were verified through kinematic analysis. Further verification of the forces and moments transmitted to the VIS were verified against the existing simulation. There was a satisfactory level of agreement when testing a simple motion, for example, rocking back and forth. Full exercise motions are to be tested soon. The main outcome has been a novel application of MBDyn for biomechanics modeling that is now available for dynamic simulations involving human motion. The estimation of BSIP was another useful result of this study, requiring only 15 inputs for generating mass properties of a theoretical astronaut model. Expansion on this work is possible by going through an alternative route in obtaining the joint motion data. Instead of high-tech and often expensive motion capture systems, an individual may watch videos with high focus and at a slow motion for each individual segment in order to determine the initial and final time and angle for that specific degree of freedom. Synthetic trajectories may also be created if there is no video reference available.

F N Matari↗

HIFiRE Flight 2 Unstart Reliability Analysis

The objective of this work was to assess the unstart reliability of the HIFiRE Flight 2 system. To do this, a quantification of margins and uncertainties framework was used for comparing model predictions of the predicted combustion induced shock location to the predicted last stable shock location within the isolator. Uncertainty sources included parametric uncertainty in the flight conditions, the heat release model, and turbulence modeling, as well as model verification errors. Additionally, an estimate of model-form uncertainty was established by comparing the model to measured ground test data. A computationally efficient non-intrusive polynomial chaos approach was used to propagate parametric uncertainty through the computational flu-ids dynamics models of both the ground test configuration and the flight vehicle. Compared to direct-connect ground test data, computational fluid dynamics predictions yielded about two duct heights of model-form uncertainty. This was applied to a prediction of flight vehicle unstart margin at the Mach 6.5 flight condition. Building up all of the computational model uncertainty, including parametric uncertainty, verification errors, and the determined model-form uncertainty, a 95% probability level based confidence ratio, or a ratio of total uncertainty to a statistical margin measure, was found to be 0.31 for the flight system.

Thomas K West↗

Hardware proofs using EHDM and the RSRE verification methodology

Examined is a methodology for hardware verification developed by Royal Signals and Radar Establishment (RSRE) in the context of the SRI International's Enhanced Hierarchical Design Methodology (EHDM) specification/verification system. The methodology utilizes a four-level specification hierarchy with the following levels: functional level, finite automata model, block model, and circuit level. The properties of a level are proved as theorems in the level below it. This methodology is applied to a 6-bit counter problem and is critically examined. The specifications are written in EHDM's specification language, Extended Special, and the proofs are improving both the RSRE methodology and the EHDM system.

Butler, Ricky W.↗

Towards Other Planetary Systems (TOPS): A technology needs identification workshop

The workshop identified a strong commonality between the technology needs for NASA's TOPS program and the technology needs that were identified for NASA's astrophysics program through its Astrotech 21 survey. The workshop encourages NASA to have the Solar System Exploration and Astrophysics Div. work cooperatively to share in technology studies that are common to both programs, rather than to conduct independent studies. It was also clear, however, that there are technology needs specific to TOPS, and these should be pursued by the Solar System Exploration Div. There are two technology areas that appear to be particularly critical to realizing the ultimate performance that is being sought under the TOPS program, these areas are metrology and optics. The former is critical in calibration and verification of instrument performance, while the latter is needed to provide optical systems of sufficient quality to conduct a search for and characterization of other planetary systems at the more extreme levels of performance identified in TOPS program.

Black, David C.↗

A Review of International Space Station Habitable Element Equipment Offgassing Characteristics

Crewed spacecraft trace contaminant control employs both passive and active methods to achieve acceptable cabin atmospheric quality. Passive methods include carefully selecting materials of construction, employing clean manufacturing practices, and minimizing systems and payload operational impacts to the cabin environment. Materials selection and manufacturing processes constitute the first level of equipment offgassing control. An element-level equipment offgassing test provides preflight verification that passive controls have been successful. Offgassing test results from multiple International Space Station (ISS) habitable elements and cargo vehicles are summarized and implications for active contamination control equipment design are discussed

Perry, Jay L.↗

System Engineering on the Use for Ares I,V - the Simpler, the Better

The Ares I and Ares V Vehicles will utilize the J-2X rocket engine developed for NASA by the Pratt & Whitney Rocketdyne Company. The J-2X is an improved higher power version of the original J-2 engine used during the Apollo program. With higher power and updated requirements for safety and performance, the J-2X becomes a new engine using state-of-the-art design methodology, materials and manufacturing processes. The implementation of Systems Engineering (SE) principles enables the rapid J-2X development program to remain aligned with the ARES I and V vehicle programs, Meeting the aggressive development schedule is a challenge. Coordinating the best expertise thai NASA and PWR have to offer requires effectively utilizing resources at multiple sites. This presents formidable communication challenges. SE allows honest and open discussions of issues and problems. This simple idea is often overlooked in large and complex SE programs. Regular and effective meetings linking SE objectives to component designs are used to voice differences of opinions with customer and contractor in attendance so that the best mutual decisions can be made on the shortest possible schedule. Regular technical interchange meetings on secure program wide computer networks and CM processes are effective,in the "Controlled Change" process that exemplifies good SE. Good communication is a key effective SE implementation. The System of Systems approach is the vision of the Orion program which facilitates the establishment of dynamic SE processes at all levels including the engine. SE enables requirements evolution by facilitating organizational and process agility. Flow down and distribution of requirements is controlled by Allocation Reports which breakdown numerical design objectives (weight, reliability, etc.) into quanta goals for each component area. Linked databases of design and verification requirements helps eliminate redundancy and potential mistakes inherent m separated systems. Another tool, the Architecture Design Description, is being used to control J-2X system architecture and effectively communicate configuration changes to those involved in the design process. But the proof is in successful program accomplishment. The SE is the methodology being used to meet the challenge of completing J-2X engine certification 2 years ahead of any engine program ever developed at PWR. The Ares I SE system of systems has delivered according to expectations thus far. All major design reviews (SRR. PDR, CDR) have been successfully conducted to satisfy overall program objectives using SE as the basis for accomplishment. The paper describes SE tools and techniques utilized to achieve this success.

Kelly, William↗

Design Limit Loads and Verification Approach for the TESS Observatory

The Transiting Exoplanet Survey Satellite (TESS) is a NASA Explorer mission. The TESS Observatory is scheduled to launch on Falcon 9 in April 2018. This presentation covers the process used to define and update design limit loads for the observatory, instrument, and components throughout the life of the program. The limit loads that drove the need for a SoftRide isolation system are highlighted. The testing performed to qualify the observatory for launch loads at the instrument and observatory level is also detailed. In addition, exchanges with the launch vehicle provider in terms of loads predictions and hardware for test are discussed along with the associated issues encountered and lessons learned. The loads development and verification success on TESS was a team effort. Orbital ATK is the spacecraft provider, NASA GSFC provides project management and technical oversight, the instrument is managed by MIT Kavli Institute and the instrument cameras are built and tested by MIT Lincoln Laboratory. Since the instrument was designed in parallel with the spacecraft, the instrument design limit loads were developed in partnership with NASA and the instrument team. The three teams collaborated on a regular basis starting in the early design phase and continuing through observatory level testing.

Limit Loads↗

Wind estimates from cloud motions - Results from Phases I, II and III of an in situ aircraft verification experiment

An experiment is in progress to verify geostationary-satellite-derived cloud-motion wind estimates by in-situ aircraft wind-velocity measurements. One or more low-level aircraft equipped with Inertial Navigation Systems (INS) were used to define the vertical extent and horizontal motion of a cloud and to measure the ambient wind field. A high-level aircraft, also equipped with an INS, took photographs to describe the horizontal extent of the cloud field and to measure cloud motion. To date the experiment has been conducted over tropical oceans and in the western Gulf of Mexico. A total of 60 h have been spent tracking some 40 tropical cumulus and five cirrus clouds. Results for tropical cumulus clouds indicate excellent agreement between the cloud motion and the wind at cloud base. The magnitude of the vector difference between the cloud motion and the cloud-base wind is less than 1.3 m/s for 67% of the cases with track lengths of 1 h or longer. Similarly, the vector differences between the cloud motion and the wind at sub-cloud (150 m), mid-cloud, and cloud-top levels are 1.5, 3.6 and 7.0 m/s, respectively. The cirrus cloud motions agreed best with the mean wind in the cloud layer with a vector difference of about 1.6 m/s.

Hasler, A. F.↗

Space power system design and development from an economic point of view

The concept of a satellite solar power system offers a feasible, but unproven, long-range energy alternative. While the basic physics of these systems is understood, many developments are necessary in order to reduce the system cost to the point of being cost-competitive with alternative energy sources. Thus, a substantial technology advancement and verification program, plus test and demonstration satellite programs are necessary before a full-scale satellite can be designed and built. It is important to properly identify those elements of the technology that should be subject to development efforts, the goals of the corresponding development programs and the appropriate funding levels and schedules. Systems studies and designs play a major role in rationally formulating a development program. This paper uses an economic approach to place these studies into a framework for formulating a viable satellite solar power system development plan.

Hazelrigg, G. A., Jr.↗

Inspection and Verification of Domain Models with PlanWorks and Aver

When developing a domain model, it seems natural to bring the traditional informal tools of inspection and verification, debuggers and automated test suites, to bear upon the problems that will inevitably arise. Debuggers that allow inspection of registers and memory and stepwise execution have been a staple of software development of all sorts from the very beginning. Automated testing has repeatedly proven its considerable worth, to the extent that an entire design philosophy (Test Driven Development) has been developed around the writing of tests. Unfortunately, while not entirely without their uses, the limitations of these tools and the nature of the complexity of models and the underlying planning systems make the diagnosis of certain classes of problems and the verification of their solutions difficult or impossible. Debuggers provide a good local view of executing code, allowing a fine-grained look at algorithms and data. This view is, however, usually only at the level of the current scope in the implementation language, and the data-inspection capabilities of most debuggers usually consist of on-line print statements. More modem graphical debuggers offer a sort of tree view of data structures, but even this is too low-level and is often inappropriate for the kinds of structures created by planning systems. For instance, god or constraint networks are at best awkward when visualized as trees. Any any non-structural link between data structures, as through a lookup table, isn't captured at all. Further, while debuggers have powerful breakpointing facilities that are suitable for finding specific algorithmic errors, they have little use in the diagnosis of modeling errors.

Bedrax-Weiss, Tania↗

V&V Within Reuse-Based Software Engineering

Verification and Validation (V&V) is used to increase the level of assurance of critical software, particularly that of safety-critical and mission-critical software. V&V is a systems engineering discipline that evaluates the software in a systems context, and is currently applied during the development of a specific application system. In order to bring the effectiveness of V&V to bear within reuse-based software engineering, V&V must be incorporated within the domain engineering process.

Addy, Edward A.↗

Space System Verification Approach Based on MEAL and Mission Risk Posture

There is no "one size fits all" solution for verifying space avionics systems to ensure safety and mission success. This paper presents a verification approach based on MEAL and risk posture for space systems. MEAL refers to Mission, mission Environment, Application, and Lifetime of the application. In addition to the description of the verification approach, the paper also provides the awareness of the different levels of risks associated with verification tests and inspections when performed at part-, board- and box-level, and discusses the applications of the approach for flight heritage verification, commercial off the shelf (COTS) verification and radiation-effects verification.

Mission Environment Application and Lifetime (MEAL↗

Space System Verification Approach Based on MEAL and Mission Risk Posture

There is no "one size fits all" solution for verifying space avionics systems to ensure safety and mission success. This paper presents a verification approach based on MEAL and risk posture for space systems. MEAL refers to Mission, mission Environment, Application, and Lifetime of the application. In addition to the description of the verification approach, the paper also provides the awareness of the different levels of risks associated with verification tests and inspections when performed at part-, board- and box-level, and discusses the applications of the approach for flight heritage verification, commercial off the shelf (COTS) verification and radiation-effects verification.

Mission Environment Application and Lifetime (MEAL↗