Search NASA⌕ Search

SEARCH · Search NASA

Results for “Formal methods”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

Recommendations on Evidence and Process for Certification of Learning-enabled Components in Aerospace Systems

This report primarily identifies a collection of relevant and necessary evidence for assurance of machine learnt components (MLCs)—also known as learning-enabled components—integrated into aircraft systems, and gives preliminary suggestions on the elements of a certification process that invoke the identified evidence. The main focus is on feedforward neural networks that are static and trained offline through supervised learning. A brief background on the generic elements of the lifecycle of an MLC is given to contextualize the assurance considerations and, consequently, the evidence that is relevant and necessary to support certification. At the level of an MLC, those considerations relate to: (i) the consistency and correctness of MLC contributions to system functions in the context of a validated functional intent; and (ii) the absence of MLC contributions to aircraft-level failure conditions. At an ML model level, confidence in model and data properties contribute to assurance of the containing MLC, in particular: (a) generalizability and robustness of models, in the presence of inputs not previously seen during training, disturbances to inputs, and unexpected inputs; and (b) valid data, i.e., data that are at least representative, relevant, complete, and accurate. Evidence for the above span the elements of the ML lifecycle, and includes, at a minimum, lifecycle artifacts that pertain to: (1) properties of requirements capturing functional intent, safety constraints, and aspects of the intended use and operating environment; (2) model performance, model complexity and design, and algorithm choice; (3) achievement of required performance at the levels of a trained model during model development, a trained model after model development is complete, and a trained model that is transformed into an executable equivalent; (4) model implementation aspects necessary for transforming a trained model into the executable equivalent; (5) integration of the executable trained model into the containing MLC, and eventually the larger system; and, (6) lastly, the verification and validation (V&V) of each of the above. Such V&V lifecycle artifacts themselves include: aspects of coverage, e.g., of various levels of requirements by the input space of the model and the data; traceability (where applicable); application of formal methods for property specification, analysis, and checking. Examples of evidence generation methods and tools further ground the discussion on what constitutes evidence, and the contribution to assurance during certification. The identified assurance considerations and supporting evidence is not a comprehensive set. Additionally, neither what should be considered as sufficient evidence relative to the assigned criticality of an MLC, nor how criticality ought to be determined and adjusted, have been considered in this report. However, suggestions are made for potential activities of the ML lifecycle that are aimed at providing confidence that an MLC can be relied upon when integrated into its containing (aircraft) system. Those activities are proposed as candidate elements of a certification process for MLCs. The main purpose of this report to inform regulatory guidance and consensus standards that may be used to meet the safety intent of the applicable regulations.

Aviation safety↗

High-Order Entropy Stable Finite Difference Schemes for Nonlinear Conservation Laws: Finite Domains

Developing stable and robust high-order finite difference schemes requires mathematical formalism and appropriate methods of analysis. In this work, nonlinear entropy stability is used to derive provably stable high-order finite difference methods with formal boundary closures for conservation laws. Particular emphasis is placed on the entropy stability of the compressible Navier-Stokes equations. A newly derived entropy stable weighted essentially non-oscillatory finite difference method is used to simulate problems with shocks and a conservative, entropy stable, narrow-stencil finite difference approach is used to approximate viscous terms.

Fisher, Travis C.↗

Information Security and Integrity Systems

Viewgraphs from the Information Security and Integrity Systems seminar held at the University of Houston-Clear Lake on May 15-16, 1990 are presented. A tutorial on computer security is presented. The goals of this tutorial are the following: to review security requirements imposed by government and by common sense; to examine risk analysis methods to help keep sight of forest while in trees; to discuss the current hot topic of viruses (which will stay hot); to examine network security, now and in the next year to 30 years; to give a brief overview of encryption; to review protection methods in operating systems; to review database security problems; to review the Trusted Computer System Evaluation Criteria (Orange Book); to comment on formal verification methods; to consider new approaches (like intrusion detection and biometrics); to review the old, low tech, and still good solutions; and to give pointers to the literature and to where to get help. Other topics covered include security in software applications and development; risk management; trust: formal methods and associated techniques; secure distributed operating system and verification; trusted Ada; a conceptual model for supporting a B3+ dynamic multilevel security and integrity in the Ada runtime environment; and information intelligence sciences.

Source record↗

Requirements-Driven Log Analysis Extended Abstract

Imagine that you are tasked to help a project improve their testing effort. In a realistic scenario it will quickly become clear, that having an impact is diffcult. First of all, it will likely be a challenge to suggest an alternative approach which is significantly more automated and/or more effective than current practice. The reality is that an average software system has a complex input/output behavior. An automated testing approach will have to auto-generate test cases, each being a pair (i; o) consisting of a test input i and an oracle o. The test input i has to be somewhat meaningful, and the oracle o can be very complicated to compute. Second, even in case where some testing technology has been developed that might improve current practice, it is then likely difficult to completely change the current behavior of the testing team unless the technique is obviously superior and does everything already done by existing technology. So is there an easier way to incorporate formal methods-based approaches than the full edged test revolution? Fortunately the answer is affirmative. A relatively simple approach is to benefit from possibly already existing logging infrastructure, which after all is part of most systems put in production. A log is a sequence of events, generated by special log recording statements, most often manually inserted in the code by the programmers. An event can be considered as a data record: a mapping from field names to values. We can analyze such a log using formal methods, for example checking it against a formal specification. This separates running the system for analyzing its behavior. It is not meant as an alternative to testing since it does not address the important in- put generation problem. However, it offers a solution which testing teams might accept since it has low impact on the existing process. A single person might be assigned to perform such log analysis, compared to the entire testing team changing behavior.

log analysis↗

Using Computational Reflection in PVS

Computational reflection is a well-known and powerful way to speed up the proof process in an interactive theorem prover. This presentation introduces the concept using PVS, and showcases 2 of the strategies using the method.

formal methods↗

A method to stabilize linear systems using eigenvalue gradient information

Formal optimization methods and eigenvalue gradient information are used to develop a stabilizing control law for a closed loop linear system that is initially unstable. The method was originally formulated by using direct, constrained optimization methods with the constraints being the real parts of the eigenvalues. However, because of problems in trying to achieve stabilizing control laws, the problem was reformulated to be solved differently. The method described uses the Davidon-Fletcher-Powell minimization technique to solve an indirect, constrained minimization problem in which the performance index is the Kreisselmeier-Steinhauser function of the real parts of all the eigenvalues. The method is applied successfully to solve two different problems: the determination of a fourth-order control law stabilizes a single-input single-output active flutter suppression system and the determination of a second-order control law for a multi-input multi-output lateral-directional flight control system. Various sets of design variables and initial starting points were chosen to show the robustness of the method.

Wieseman, C. D.↗

Systems, methods and apparatus for implementation of formal specifications derived from informal requirements

Systems, methods and apparatus are provided through which in some embodiments an informal specification is translated without human intervention into a formal specification. In some embodiments the formal specification is a process-based specification. In some embodiments, the formal specification is translated into a high-level computer programming language which is further compiled into a set of executable computer instructions.

Hinchey, Michael G.↗

On the effect of boundary layer growth on the stability of compressible flows

The method of multiple scales is used to describe a formally correct method based on the nonparallel linear stability theory, that examines the two and three dimensional stability of compressible boundary layer flows. The method is applied to the supersonic flat plate layer at Mach number 4.5. The theoretical growth rates are in good agreement with experimental results. The method is also applied to the infinite-span swept wing transonic boundary layer with suction to evaluate the effect of the nonparallel flow on the development of crossflow disturbances.

El-Hady, N. M.↗

HDL to verification logic translator

The increasingly higher number of transistors possible in VLSI circuits compounds the difficulty in insuring correct designs. As the number of possible test cases required to exhaustively simulate a circuit design explodes, a better method is required to confirm the absence of design faults. Formal verification methods provide a way to prove, using logic, that a circuit structure correctly implements its specification. Before verification is accepted by VLSI design engineers, the stand alone verification tools that are in use in the research community must be integrated with the CAD tools used by the designers. One problem facing the acceptance of formal verification into circuit design methodology is that the structural circuit descriptions used by the designers are not appropriate for verification work and those required for verification lack some of the features needed for design. We offer a solution to this dilemma: an automatic translation from the designers' HDL models into definitions for the higher-ordered logic (HOL) verification system. The translated definitions become the low level basis of circuit verification which in turn increases the designer's confidence in the correctness of higher level behavioral models.

Gambles, J. W.↗

Scatter in Carbon/Silicon Carbide (C/SiC) Composites Quantified

Carbon-fiber-reinforced silicon carbide matrix (C/SiC) composites processed by chemical vapor infiltration are candidate materials for aerospace thermal structures. Carbon fibers can retain properties at very high temperatures, but they are known to have poor oxidation resistance in adverse, high-temperature environments. Nevertheless, the combination of CVI-SiC matrix with higher stiffness and oxidation resistance, the interfacial coating, and additional surface-seal coating provides the necessary protection to the carbon fibers, and makes the material viable for high-temperature space applications operating under harsh environments. Furthermore, C/SiC composites, like other ceramic matrix composites (CMCs), exhibit graceful non-catastrophic failure because of various inherent energy dissipating mechanisms. The material exhibits nonlinearity in deformation even at very low stress levels. This is the result of the severe matrix microcracking present in the as processed composite because of large differences between the coefficients of thermal expansion of the fiber and the matrix. Utilization of these advanced composites in next generation space vehicles will require innovative structural configurations, updated materials, and refined analyses. Structural safety issues for these vehicles are in direct competition with performance and cost. One would have to quantify the uncertainties associated with the design using formal probabilistic methods. Specifically four fundamental aspects on which analyses are based-- (1) loading conditions, (2) material behavior, (3) geometrical configurations, and (4) structural connections between the composite components and baseline structure--are stochastic in nature. A direct way to formally account for uncertainties is to develop probabilistic structural analysis methods where all participating variables are described by appropriate probability density functions. The present work, however, focuses on analyzing the stochastic material behavior of these advanced composites using formal probabilistic analysis methods. Often, some of the desirable property characteristics that allow composites to offer advantages over conventional structural materials (like tailoring of composite properties) and the complexity are in fact responsible for their greater statistical variability and the requirements for more characterization tests. Composite properties are anisotropic as well, having different properties in different directions. This means that characterization of a property such as stiffness--which will vary greatly depending on the orientation of the fiber relative to the direction of the testing--must be repeated for several different directions and loading conditions. The fabrication process for composites also introduces statistical variations in properties and geometry. A composite part is produced in a number of steps, each of which introduces statistical variability. The matrix is usually produced from a combination of raw materials; and the fiber, which has its own set of properties, is often coated or surface treated, introducing yet another source of variability.

Murthy, Pappu L. N.↗

Tidal Energy Available for Deep Ocean Mixing: Bounds from Altimetry Data

Maintenance of the large-scale thermohaline circulation has long presented a problem to oceanographers. Observed mixing rates in the pelagic ocean are an order of magnitude too small to balance the rate at which dense bottom water is created at high latitudes. Recent observational and theoretical work suggests that much of this mixing may occur in hot spots near areas of rough topography (e.g., mid-ocean ridges and island arcs). Barotropic tidal currents provide a very plausible source of energy to maintain these mixing processes. Topex/Poseidon (T/P) satellite altimetry data have made precise mapping of open ocean tidal elevations possible for the first time. We can thus obtain empirical, spatially localized, estimates of barotropic tidal dissipation. These provide an upper bound on the amount of tidal energy that is dissipated in the deep ocean, and hence is available for deep mixing. We will present and compare maps of open ocean tidal energy flux divergence, and estimates of tidal energy flux into shallow seas, derived from T/P altimetry data using both formal data assimilation methods and empirical approaches. With the data assimilation methods we can place formal error bars on the fluxes. Our results show that 20-25% of tidal energy dissipation occurs outside of the shallow seas, the traditional sink for tidal energy. This suggests that up to 1 TW of energy may be available from the tides (lunar and solar) for mixing the deep ocean. The dissipation indeed appears to be concentrated over areas of rough topography.

Egbert, Gary D.↗

Tidal Energy Available for Deep Ocean Mixing: Bounds from Altimetry Data

Maintenance of the large-scale thermohaline circulation has long presented an interesting problem. Observed mixing rates in the pelagic ocean are an order of magnitude too small to balance the rate at which dense bottom water is created at high latitudes. Recent observational and theoretical work suggests that much of this mixing may occur in hot spots near areas of rough topography (e.g., mid-ocean ridges and island arcs). Barotropic tidal currents provide a very plausible source of energy to maintain these mixing processes. Topex/Poseidon satellite altimetry data have made precise mapping of open ocean tidal elevations possible for the first time. We can thus obtain empirical, spatially localized, estimates of barotropic tidal dissipation. These provide an upper bound on the amount of tidal energy that is dissipated in the deep ocean, and hence is available for deep mixing. We will present and compare maps of open ocean tidal energy flux divergence, and estimates of tidal energy flux into shallow seas, derived from T/P altimetry data using both formal data assimilation methods and empirical approaches. With the data assimilation methods we can place formal error bars on the fluxes. Our results show that 20-25% of tidal energy dissipation occurs outside of the shallow seas, the traditional sink for tidal energy. This suggests that up to 1 TW of energy may be available from the tides (lunar and solar) for mixing the deep ocean. The dissipation indeed appears to be concentrated over areas of rough topography.

Ray, Richard D.↗

Tidal Energy Available for Deep Ocean Mixing: Bounds From Altimetry Data

Maintenance of the large-scale thermohaline circulation has long presented a problem to oceanographers. Observed mixing rates in the pelagic ocean are an order of magnitude too small to balance the rate at which dense bottom water is created at high latitudes. Recent observational and theoretical work suggests that much of this mixing may occur in hot spots near areas of rough topography (e.g., mid-ocean ridges and island arcs). Barotropic tidal currents provide a very plausible source of energy to maintain these mixing processes. Topex/Poseidon satellite altimetry data have made precise mapping of open ocean tidal elevations possible for the first time. We can thus obtain empirical, spatially localized, estimates of barotropic tidal dissipation. These provide an upper bound on the amount of tidal energy that is dissipated in the deep ocean, and hence is available for deep mixing. We will present and compare maps of open ocean tidal energy flux divergence, and estimates of tidal energy flux into shallow seas, derived from T/P altimetry data using both formal data assimilation methods and empirical approaches. With the data assimilation methods we can place formal error bars on the fluxes. Our results show that 20-25% of tidal energy dissipation occurs outside of the shallow seas, the traditional sink for tidal energy. This suggests that up to 1 TW of energy may be available from the tides (lunar and solar) for mixing the deep ocean. The dissipation indeed appears to be concentrated over areas of rough topography.

Egbert, Gary D.↗

Experimental validation of structural optimization methods

The topic of validating structural optimization methods by use of experimental results is addressed. The need for validating the methods as a way of effecting a greater and an accelerated acceptance of formal optimization methods by practicing engineering designers is described. The range of validation strategies is defined which includes comparison of optimization results with more traditional design approaches, establishing the accuracy of analyses used, and finally experimental validation of the optimization results. Examples of the use of experimental results to validate optimization techniques are described. The examples include experimental validation of the following: optimum design of a trussed beam; combined control-structure design of a cable-supported beam simulating an actively controlled space structure; minimum weight design of a beam with frequency constraints; minimization of the vibration response of helicopter rotor blade; minimum weight design of a turbine blade disk; aeroelastic optimization of an aircraft vertical fin; airfoil shape optimization for drag minimization; optimization of the shape of a hole in a plate for stress minimization; optimization to minimize beam dynamic response; and structural optimization of a low vibration helicopter rotor.

Adelman, Howard M.↗

Aerodynamic Optimization of Rocket Control Surface Geometry Using Cartesian Methods and CAD Geometry

Aerodynamic design is an iterative process involving geometry manipulation and complex computational analysis subject to physical constraints and aerodynamic objectives. A design cycle consists of first establishing the performance of a baseline design, which is usually created with low-fidelity engineering tools, and then progressively optimizing the design to maximize its performance. Optimization techniques have evolved from relying exclusively on designer intuition and insight in traditional trial and error methods, to sophisticated local and global search methods. Recent attempts at automating the search through a large design space with formal optimization methods include both database driven and direct evaluation schemes. Databases are being used in conjunction with surrogate and neural network models as a basis on which to run optimization algorithms. Optimization algorithms are also being driven by the direct evaluation of objectives and constraints using high-fidelity simulations. Surrogate methods use data points obtained from simulations, and possibly gradients evaluated at the data points, to create mathematical approximations of a database. Neural network models work in a similar fashion, using a number of high-fidelity database calculations as training iterations to create a database model. Optimal designs are obtained by coupling an optimization algorithm to the database model. Evaluation of the current best design then gives either a new local optima and/or increases the fidelity of the approximation model for the next iteration. Surrogate methods have also been developed that iterate on the selection of data points to decrease the uncertainty of the approximation model prior to searching for an optimal design. The database approximation models for each of these cases, however, become computationally expensive with increase in dimensionality. Thus the method of using optimization algorithms to search a database model becomes problematic as the number of design variables is increased.

Nelson, Andrea↗

Probabilistic Unsteady Aerodynamic Analysis

Probabilistic CFD design is needed because we are asked to do more with less. To cost effectively accomplish the design task, we need to formally quantify the effect of uncertainties (variables) in the design. Probabilistic design is one effective method to formally quantify the effect of uncertainties. Our objective is to establish a revolutionary new early design process, by developing non-deterministic physics-based probabilistic design tools, which will include all the life cycle processes. This work was concerned with the usefulness of parametric optimization method coupled with a Navier-Stokes analysis code for the aero-thermodynamic design of turbomachinery combustor liner. The interconnection between the CFD code and NESSUS codes will facilitate the coupling between the thermal profiles and structural design. We have developed new concepts for reducing the computational cost of unsteady, three-dimensional, compressible aerodynamic analyses for multistage turbomachinery flows. The flow was modeled by the three-dimensional Favre-Reynolds-averaged Navier-Stokes equations using the k-E turbulence closure, which was integrated using an implicit third-order upwind solver. The methodology developed in this work is expected to lead to the design optimization of turbomachinery blades.

Gorla, Rama S. R.↗

Probabilistic Study of Fluid Structure Interaction

Probabilistic CFD design is needed because we are asked to do more with less. To cost effectively accomplish the design task, we need to formally quantify the effect of uncertainties (variables) in the design. Probabilistic design is one effective method to formally quantify the effect of uncertainties. Our objective is to establish a revolutionary new early design process, by developing non-deterministic physics-based probabilistic design tools, which will include all the life cycle processes. Breakthroughs will be sought in speed, accuracy, intelligence, and usability of the system. This paper is concerned with the usefulness of parametric optimization method coupled with a Navier-Stokes analysis code for the aero-thermodynamic design of turbomachinery combustor liner. The interconnection between the CFD code and NESSUS codes facilitated the coupling between the thermal profiles and structural design. We have developed new concepts for reducing the computational cost of unsteady, three-dimensional, compressible aerodynamic analyses for multistage turbomachinery flows. The flow was modeled by the three-dimensional Favre-Reynolds-averaged Navier-Stokes equations using the k-epsilon turbulence closure, which was integrated using an implicit third-order upwind solver. The methodology developed in this paper is expected to lead to the design optimization of turbomachinery blades.

Gorla, Rama S. R.↗

Fuzzy Logic Controller Stability Analysis Using a Satisfiability Modulo Theories Approach

While many widely accepted methods and techniques exist for validation and verification of traditional controllers, at this time no solutions have been accepted for Fuzzy Logic Controllers (FLCs). Due to the highly nonlinear nature of such systems, and the fact that developing a valid FLC does not require a mathematical model of the system, it is quite difficult to use conventional techniques to prove controller stability. Since safety-critical systems must be tested and verified to work as expected for all possible circumstances, the fact that FLC controllers cannot be tested to achieve such requirements poses limitations on the applications for such technology. Therefore, alternative methods for verification and validation of FLCs needs to be explored. In this study, a novel approach using formal verification methods to ensure the stability of a FLC is proposed. Main research challenges include specification of requirements for a complex system, conversion of a traditional FLC to a piecewise polynomial representation, and using a formal verification tool in a nonlinear solution space. Using the proposed architecture, the Fuzzy Logic Controller was found to always generate negative feedback, but inconclusive for Lyapunov stability.

Fuzzy Logic Controller↗