Search NASA⌕ Search

SEARCH · Search NASA

Results for “Program verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 235 records · Page 13

HYDRA, a new tool for mechanical testing

The introduction outlines the verification concept for programs of the European Space Agency (ESA). The role of the Agency in coordinating the activities of major European space test centers is summarized. Major test facilities of the environmental test center at ESTEC, the Space Research and Technology Center of ESA, are shown and their specific characteristics are highlighted with special emphasis on the 6-degree-of-freedom (6-DOF) hydraulic shaker. The specified performance characteristics for sine and transient tests are presented. Results of single-axis hardware tests and 6-DOF computer simulations are included. Efforts employed to protect payloads against accidental damage in case of malfunctions of the facility are listed. Finally the operational advantages of the facility, as well as the possible use of the HYDRA control system design for future applications are indicated.

Brinkmann, P. W.↗

Jeagle: a JAVA Runtime Verification Tool

We introduce the temporal logic Jeagle and its supporting tool for runtime verification of Java programs. A monitor for an Jeagle formula checks if a finite trace of program events satisfies the formula. Jeagle is a programming oriented extension of the rule-based powerful Eagle logic that has been shown to be capable of defining and implementing a range of finite trace monitoring logics, including future and past time temporal logic, real-time and metric temporal logics, interval logics, forms of quantified temporal logics, and so on. Monitoring is achieved on a state-by-state basis avoiding any need to store the input trace. Jeagle extends Eagle with constructs for capturing parameterized program events such as method calls and method returns. Parameters can be the objects that methods are called upon, arguments to methods, and return values. Jeagle allows one to refer to these in formulas. The tool performs automated program instrumentation using AspectJ. We show the transformational semantics of Jeagle.

DAmorim, Marcelo↗

On-Orbit Software Analysis

The On-Orbit Software Analysis Research Infusion Project was done by Intrinsyx Technologies Corporation (Intrinsyx) at the National Aeronautics and Space Administration (NASA) Ames Research Center (ARC). The Project was a joint collaborative effort between NASA Codes IC and SL, Kestrel Technology (Kestrel), and Intrinsyx. The primary objectives of the Project were: Discovery and verification of software program properties and dependencies, Detection and isolation of software defects across different versions of software, and Compilation of historical data and technical expertise for future applications

Moran, Susanne I.↗

Progress of Ongoing NASA Lithium-Ion Cell Verification Testing for Aerospace Applications

A Lithium-ion Verification and Validation Program with the purpose to assess the capabilities of current aerospace lithium-ion (Li-ion) battery cells to perform in a low-earth-orbit (LEO) regime was initiated in 2002. This program involves extensive characterization and LEO life testing at ten different combinations of depth-of-discharge, temperature, and end-of-charge voltage. The test conditions selected for the life tests are defined as part of a statistically designed test matrix developed to determine the effects of operating conditions on performance and life of Li-ion cells. Results will be used to model and predict cell performance and degradation as a function of test operating conditions. Testing is being performed at the Naval Surface Warfare Center/Crane Division in Crane, Indiana. Testing was initiated in September 2004 with 40 Ah cells from Saft and 30 Ah cells from Lithion. The test program has been expanded with the addition of modules composed of 18650 cells from ABSL Power Solutions in April 2006 and the addition of 50 Ah cells from Mine Safety Appliances Co. (MSA) in June 2006. Preliminary results showing the average voltage and average available discharge capacity for the Saft and Lithion packs at the test conditions versus cycles are presented.

McKissock, Barbara I.↗

Generating Code Review Documentation for Auto-Generated Mission-Critical Software

Model-based design and automated code generation are increasingly used at NASA to produce actual flight code, particularly in the Guidance, Navigation, and Control domain. However, since code generators are typically not qualified, there is no guarantee that their output is correct, and consequently auto-generated code still needs to be fully tested and certified. We have thus developed AUTOCERT, a generator-independent plug-in that supports the certification of auto-generated code. AUTOCERT takes a set of mission safety requirements, and formally verifies that the autogenerated code satisfies these requirements. It generates a natural language report that explains why and how the code complies with the specified requirements. The report is hyper-linked to both the program and the verification conditions and thus provides a high-level structured argument containing tracing information for use in code reviews.

Denney, Ewen↗

Model Transformation for a System of Systems Dependability Safety Case

Software plays an increasingly larger role in all aspects of NASA's science missions. This has been extended to the identification, management and control of faults which affect safety-critical functions and by default, the overall success of the mission. Traditionally, the analysis of fault identification, management and control are hardware based. Due to the increasing complexity of system, there has been a corresponding increase in the complexity in fault management software. The NASA Independent Validation & Verification (IV&V) program is creating processes and procedures to identify, and incorporate safety-critical software requirements along with corresponding software faults so that potential hazards may be mitigated. This Specific to Generic ... A Case for Reuse paper describes the phases of a dependability and safety study which identifies a new, process to create a foundation for reusable assets. These assets support the identification and management of specific software faults and, their transformation from specific to generic software faults. This approach also has applications to other systems outside of the NASA environment. This paper addresses how a mission specific dependability and safety case is being transformed to a generic dependability and safety case which can be reused for any type of space mission with an emphasis on software fault conditions.

Murphy, Judy↗

Material Model Evaluation of a Composite Honeycomb Energy Absorber

A study was conducted to evaluate four different material models in predicting the dynamic crushing response of solid-element-based models of a composite honeycomb energy absorber, designated the Deployable Energy Absorber (DEA). Dynamic crush tests of three DEA components were simulated using the nonlinear, explicit transient dynamic code, LS-DYNA . In addition, a full-scale crash test of an MD-500 helicopter, retrofitted with DEA blocks, was simulated. The four material models used to represent the DEA included: *MAT_CRUSHABLE_FOAM (Mat 63), *MAT_HONEYCOMB (Mat 26), *MAT_SIMPLIFIED_RUBBER/FOAM (Mat 181), and *MAT_TRANSVERSELY_ANISOTROPIC_CRUSHABLE_FOAM (Mat 142). Test-analysis calibration metrics included simple percentage error comparisons of initial peak acceleration, sustained crush stress, and peak compaction acceleration of the DEA components. In addition, the Roadside Safety Verification and Validation Program (RSVVP) was used to assess similarities and differences between the experimental and analytical curves for the full-scale crash test.

Jackson, Karen E.↗

Star Tracker Performance Estimate with IMU

A software tool for estimating cross-boresight error of a star tracker combined with an inertial measurement unit (IMU) was developed to support trade studies for the Integrated Radio and Optical Communication project (iROC) at the National Aeronautics and Space Administration Glenn Research Center. Typical laser communication systems, such as the Lunar Laser Communication Demonstration (LLCD) and the Laser Communication Relay Demonstration (LCRD), use a beacon to locate ground stations. iROC is investigating the use of beaconless precision laser pointing to enable laser communication at Mars orbits and beyond. Precision attitude knowledge is essential to the iROC mission to enable high-speed steering of the optical link. The preliminary concept to achieve this precision attitude knowledge is to use star trackers combined with an IMU. The Star Tracker Accuracy (STAcc) software was developed to rapidly assess the capabilities of star tracker and IMU configurations. STAcc determines the overall cross-boresight error of a star tracker with an IMU given the characteristic parameters: quantum efficiency, aperture, apparent star magnitude, exposure time, field of view, photon spread, detector pixels, spacecraft slew rate, maximum stars used for quaternion estimation, and IMU angular random walk. This paper discusses the supporting theory used to construct STAcc, verification of the program and sample results.

Error Budget↗

Wilson Corners SWMU 001 2015 Annual Long Term Monitoring Report Kennedy Space Center, Florida

This document presents the findings of the 2015 Long Term Monitoring (LTM) that was completed at the Wilson Corners site, located at the National Aeronautics and Space Administration John F. Kennedy Space Center, Florida. The objectives of the 2015 LTM event were to evaluate the groundwater flow direction and gradient, to monitor the vertical and horizontal extent of the volatile organic compounds (VOCs; including the upgradient and sidegradient extents, which are monitored every five years), and to monitor select locations internal to the dissolved groundwater plume. The 2015 LTM event included several upgradient and sidegradient monitoring wells that are not sampled annually to verify the extent of VOCs in this portion of the site. The December 2015 LTM groundwater sampling event included, depth to groundwater measurements, 40 VOC samples collected using passive diffusion bags, and one VOC sample collected using low-flow techniques. Additionally, monitoring well MW0052DD was overdrilled and abandoned using rotasonic drilling techniques. The following conclusions can be made based on the 2015 LTM results: groundwater flow is generally to the west with northwest and southwest flow components from the water table to approximately 55 feet below land surface (ft BLS); peripheral monitoring wells generally delineate VOCs to groundwater cleanup target levels (GCTLs) except for monitoring wells MW0088, MW0090, MW0095, and NPSHMW0039, which had vinyl chloride (VC) concentrations near the GCTL and MW0062, which had trichloroethene (TCE), cis-1,2-dichloroethenen (cDCE), and VC concentrations above natural attenuation default concentrations (NADCs); VOCs in interior downgradient wells generally fluctuate within historic ranges except for monitoring wells in the north-northwest portion of the site, which have increasing VC concentrations indicating potential plume migration and expansion; Historically, the vertical extents of the VOCs were delineated by monitoring wells screened greater than 60 ft BLS (MW0083 through MW0086, and MW0078). The 2015 LTM results indicate that concentrations of daughter product cDCE is greater than the NADC in MW0078 and that cDCE and VC are greater than NADCs in MW0130. TCE was greater than the GCTL in monitoring well MW130 and not detected above method detection limits (9 micrograms per Liter) in monitoring well MW0078. No GCTL exceedances were identified in monitoring wells MW0083 or MW0086; the dissolved plume footprint appears generally stable, though not fully delineated by monitoring well data in the northeast portion of the site; and 2015 LTM results generally support the existing Conceptual Site Model. Geosyntec recommends modifying the LTM program, collecting a verification sample from monitoring well MW0062, and performing a direct push technology instigation in the northnortheastern portion of the site. A cluster of monitoring wells (MW0132 [2 to 12 ft BLS], MW0133 [15 to 25 ft BLS], and MW0134 [29 to 34 ft BLS]) is proposed to delineate impacts in the northnortheast portion of the site. Geosyntec recommends installation of a vertical extent well in the center of the site (Hot Spot 2 area) post-remediation implementation.

groundwater↗

Structural, Thermal, and Optical Performance (STOP) Modeling and Results for the James Webb Space Telescope Integrated Science Instrument Module

The James Webb Space Telescope includes the Integrated Science Instrument Module (ISIM) element that contains four science instruments (SI) including a Guider. We performed extensive structural, thermal, and optical performance(STOP) modeling in support of all phases of ISIM development. In this paper, we focus on modeling and results associated with test and verification. ISIMs test program is bound by ground environments, mostly notably the 1g and test chamber thermal environments. This paper describes STOP modeling used to predict ISIM system performance in 0g and at various on-orbit temperature environments. The predictions are used to project results obtained during testing to on-orbit performance.

structural↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification Validation (IVV) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASA's Office of Safety and Mission Assurance defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domaincomponent, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IVV enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

Fault management↗

Introduction to ISS Crew Displays

The International Space Station (ISS) began payload operations in earnest in 2000 with the arrival of the Expedition 1. To date, ISS has offered Principal Investigators (PIs) a reliable platform for microgravity research, having hosted thousands of onboard science experiments. Most of this research is supported by experiment hardware and software and many include a crew‐operated Graphical User Interface (GUI). The purpose of this article is to share information with PIs and Payload Developer (PD) teams about the processes, standards, and guidelines applicable to crew GUI design that must be complied with when planning payload software. The goal is not to enumerate all of the ISS display standards, but rather to highlight design guidelines and the ISS Program milestones for verification and approval of onboard crew displays.

Graphical User Interface↗

Mars 2020 Entry, Descent, and Landing System Software Implementation

On February 18th, 2021, the Mars 2020 project's Perseverance Rover successfully touched down on the Martian surface after nearly eight years of development. The Mars 2020 Entry, Descent, and Landing (EDL) System largely leveraged heritage from the Mars Science Laboratory (MSL) EDL System while employing targeted technological advancements. The landing process is autonomously directed by a software behavior implemented in the rover's primary flight computer called the EDL Timeline that assumes control of the vehicle six days before atmospheric entry. This paper first walks through the basics of the EDL Timeline mechanics and how the behavior is designed to account for internal system variations and environmental unknowns. It then summarizes the interactions between the EDL timeline and other high-level system behaviors like spacecraft mode transitions and system fault protection, focusing on the complications that arise when passing spacecraft control between executive functions. Although the MSL-inherited EDL System is reliable and capable, targeted updates and a thorough verification and validation program were required for Mars 2020. This paper discusses changes made to close vulnerabilities discovered during both MSL and Mars 2020 development cycles, landing system capability enhancements that were enabling for Mars 2020's mission, and how these updates were integrated with the heritage system. It then describes how both analysis and testing campaigns were utilized to verify and validate all aspects of EDL and system behaviors that run during the six days before landing, as well as the operational workarounds that were needed to address problems found during the development and commissioning process. Finally, this paper imparts lessons learned from Mars 2020 EDL development, implementation, and operations, emphasizing how systems designed to conduct time-critical mission events with low margin of error can be improved in the future.

Stehura, Aaron↗

Mars 2020 Entry, Descent, and Landing Software Implementation

On February 18th, 2021, the Mars 2020 project's Perseverance Rover successfully touched down on the Martian surface after nearly eight years of development. The Mars 2020 Entry, Descent, and Landing (EDL) System largely leveraged heritage from the Mars Science Laboratory (MSL) EDL System while employing targeted technological advancements. The landing process is autonomously directed by a software behavior implemented in the rover's primary flight computer called the EDL Timeline that assumes control of the vehicle six days before atmospheric entry. In addition to performing the critical function of landing the rover on the Martian surface, the EDL timeline behavior must co-exist in a non-partitioned software and system environment with other high-level functions that accomplish the goals for the rest of the mission. Due to the criticality of EDL, the potential for loss of mission, and a need for complete system autonomy, the standard for how the EDL Timeline interacts with other functions in the system is highly constrained. This paper first walks through the basics of the EDL Timeline mechanics and how the behavior is designed to account for internal system variations and environmental unknowns. It then summarizes the interactions between the EDL timeline and other high-level system behaviors like spacecraft mode transitions and system fault protection, focusing on the complications that arise when passing spacecraft control between executive functions. Although the MSL-inherited EDL System is reliable and capable, targeted updates and a thorough verification and validation program were required for Mars 2020. This paper discusses changes made to close vulnerabilities discovered during both MSL and Mars 2020 development cycles, landing system capability enhancements that were enabling for Mars 2020's mission, and how these updates were integrated with the heritage system. It then describes how both analysis and testing campaigns were utilized to verify and validate all aspects of EDL and system behaviors that run during the six days before landing, as well as the operational workarounds that were needed to address problems found during the development and commissioning process. Finally, this paper imparts lessons learned from Mars 2020 EDL development, implementation, and operations, emphasizing how systems designed to conduct time-critical mission events with low margin of error can be improved in the future.

Stehura, Aaron↗

Transcriptomics Processing Pipelines for Space Biology: An Open Source and Consensus-Driven Approach

Transcriptomics holds significant value in elucidating the relationship between gene expression, experimental factors, biological factors, and various types of omics data. Enhancing our understanding of these connections is paramount for foundational biology, which plays a pivotal role in devising solutions for challenges pertinent to both space travel and terrestrial life. The NASA GeneLab project, part of the Open Science Data Repository (OSDR.nasa.gov), seeks to accelerate space biology research through cataloging and democratizing ‘omics data, including transcriptomics. Since raw omics data are largely inaccessible to non-bioinformaticians, GeneLab works with the scientific community via the Open Science Analysis Working Groups (AWGs) to develop standard processing pipelines to generate and publish processed data. Unlike raw data, processed data have greater immediate value to diverse users with varying technical backgrounds and computational capabilities. Standardizing processing workflows is essential to match the pace of raw data generation, ensure reproducibility, and enable standardized processed data for comparison across datasets. As of June 2023, transcriptomics studies comprise over half of GeneLab datasets hosted on the OSDR, including data from bulk RNA-seq and Affymetrix or Agilent 1-Channel DNA microarray assays. In collaboration with the AWGs, GeneLab developed consensus processing pipelines for these transcriptomics data types that includes quality control, background correction (microarray only), data normalization and quantification, culminating in the detection and annotation of differentially expressed genes. The work presented here describes Nextflow implementations of GeneLab’s consensus transcriptomics pipelines that automates and accelerates processing of these datasets. In addition to the core data processing, these workflows also include raw data staging and a robust verification and validation program to identify errors in real-time, stop additional downstream computation, and preserve computational resources. These workflows are used to generate GeneLab processed data hosted on the OSDR, and are publicly available as open source software for others to use at: https://github.com/nasa/GeneLab_Data_Processing.

Jonathan Oribello↗