Search NASA⌕ Search

SEARCH · Search NASA

Results for “Program verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

The NASA Commercial Crew Program (CCP) Mission Assurance Process

In 2010, NASA established the Commercial Crew Program in order to provide human access to the International Space Station and low earth orbit via the commercial (non-governmental) sector. A particular challenge to NASA has been how to determine the commercial providers transportation system complies with Programmatic safety requirements. The process used in this determination is the Safety Technical Review Board which reviews and approves provider submitted Hazard Reports. One significant product of the review is a set of hazard control verifications. In past NASA programs, 100 percent of these safety critical verifications were typically confirmed by NASA. The traditional Safety and Mission Assurance (SMA) model does not support the nature of the Commercial Crew Program. To that end, NASA SMA is implementing a Risk Based Assurance (RBA) process to determine which hazard control verifications require NASA authentication. Additionally, a Shared Assurance Model is also being developed to efficiently use the available resources to execute the verifications. This paper will describe the evolution of the CCP Mission Assurance process from the beginning of the Program to its current incarnation. Topics to be covered include a short history of the CCP; the development of the Programmatic mission assurance requirements; the current safety review process; a description of the RBA process and its products and ending with a description of the Shared Assurance Model.

Commercial Crew Program↗

The NASA Firefighter's Breathing System Program: A Status Report

The National Aeronautics and Space Administration (NASA), through its Technology Utilization Program, has been making its advanced technology developments available to the public. This has coincided in recent years with a growing demand within the fire service for improved protective equipment. A better breathing system for firefighters was one of the more immediate needs identified by the firefighting organizations. The Johnson Space Center (JSC), based upon their experience in providing life support systems for space flight, was subsequently requested to determine the feasibility of providing an improved breathing system for firefighters. Such a system was determined to be well within the current state of the art, and the Center is well into a development program to provide design verification of this improved protective' equipment. This report - outlines the overall objectives of this program, progress to date, and future planned activities.

McLaughlan, Pat B.↗

A program for the investigation of the Multibody Modeling, Verification, and Control Laboratory

The Multibody Modeling, Verification, and Control (MMVC) Laboratory is under development at NASA MSFC in Huntsville, Alabama. The laboratory will provide a facility in which dynamic tests and analyses of multibody flexible structures representative of future space systems can be conducted. The purpose of the tests are to acquire dynamic measurements of the flexible structures undergoing large angle motions and use the data to validate the multibody modeling code, TREETOPS, developed under sponsorship of NASA. Advanced control systems design and system identification methodologies will also be implemented in the MMVC laboratory. This paper describes the ground test facility, the real-time control system, and the experiments. A top-level description of the TREETOPS code is also included along with the validation plan for the MMVC program. Dynamic test results from component testing are also presented and discussed. A detailed discussion of the test articles, which manifest the properties of large flexible space structures, is included along with a discussion of the various candidate control methodologies to be applied in the laboratory.

Tobbe, Patrick A.↗

The Evolution of the NASA Commercial Crew Program Mission Assurance Process

In 2010, the National Aeronautics and Space Administration (NASA) established the Commercial Crew Program (CCP) in order to provide human access to the International Space Station and low Earth orbit via the commercial (non-governmental) sector. A particular challenge to NASA has been how to determine that the Commercial Provider's transportation system complies with programmatic safety requirements. The process used in this determination is the Safety Technical Review Board which reviews and approves provider submitted hazard reports. One significant product of the review is a set of hazard control verifications. In past NASA programs, 100% of these safety critical verifications were typically confirmed by NASA. The traditional Safety and Mission Assurance (S&MA) model does not support the nature of the CCP. To that end, NASA S&MA is implementing a Risk Based Assurance process to determine which hazard control verifications require NASA authentication. Additionally, a Shared Assurance Model is also being developed to efficiently use the available resources to execute the verifications.

Mission Assurance↗

Dynamic verification of very large space structures

A research program in spacecraft structures, structural dynamics, and controls verification using a relatively large, flexible beam as a focus is introduced. This research effort addresses fundamental problems applicable to the verification of large, flexible space structures and combines ground tests, flight behavior prediction, and instrumented orbital tests. The program is expected to produce quantitative results for use in improving the validity of ground tests for verifying flight performance analyses.

Hanks, B. R.↗

Using tools for verification, documentation and testing

Methodologies are discussed on four of the major approaches to program upgrading -- namely dynamic testing, symbolic execution, formal verification and static analysis. The different patterns of strengths, weaknesses and applications of these approaches are shown. It is demonstrated that these patterns are in many ways complementary, offering the hope that they can be coordinated and unified into a single comprehensive program testing and verification system capable of performing a diverse and useful variety of error detection, verification and documentation functions.

Osterweil, L. J.↗

Regression Verification Using Impact Summaries

Regression verification techniques are used to prove equivalence of syntactically similar programs. Checking equivalence of large programs, however, can be computationally expensive. Existing regression verification techniques rely on abstraction and decomposition techniques to reduce the computational effort of checking equivalence of the entire program. These techniques are sound but not complete. In this work, we propose a novel approach to improve scalability of regression verification by classifying the program behaviors generated during symbolic execution as either impacted or unimpacted. Our technique uses a combination of static analysis and symbolic execution to generate summaries of impacted program behaviors. The impact summaries are then checked for equivalence using an o-the-shelf decision procedure. We prove that our approach is both sound and complete for sequential programs, with respect to the depth bound of symbolic execution. Our evaluation on a set of sequential C artifacts shows that reducing the size of the summaries can help reduce the cost of software equivalence checking. Various reduction, abstraction, and compositional techniques have been developed to help scale software verification techniques to industrial-sized systems. Although such techniques have greatly increased the size and complexity of systems that can be checked, analysis of large software systems remains costly. Regression analysis techniques, e.g., regression testing [16], regression model checking [22], and regression verification [19], restrict the scope of the analysis by leveraging the differences between program versions. These techniques are based on the idea that if code is checked early in development, then subsequent versions can be checked against a prior (checked) version, leveraging the results of the previous analysis to reduce analysis cost of the current version. Regression verification addresses the problem of proving equivalence of closely related program versions [19]. These techniques compare two programs with a large degree of syntactic similarity to prove that portions of one program version are equivalent to the other. Regression verification can be used for guaranteeing backward compatibility, and for showing behavioral equivalence in programs with syntactic differences, e.g., when a program is refactored to improve its performance, maintainability, or readability. Existing regression verification techniques leverage similarities between program versions by using abstraction and decomposition techniques to improve scalability of the analysis [10, 12, 19]. The abstractions and decomposition in the these techniques, e.g., summaries of unchanged code [12] or semantically equivalent methods [19], compute an over-approximation of the program behaviors. The equivalence checking results of these techniques are sound but not complete-they may characterize programs as not functionally equivalent when, in fact, they are equivalent. In this work we describe a novel approach that leverages the impact of the differences between two programs for scaling regression verification. We partition program behaviors of each version into (a) behaviors impacted by the changes and (b) behaviors not impacted (unimpacted) by the changes. Only the impacted program behaviors are used during equivalence checking. We then prove that checking equivalence of the impacted program behaviors is equivalent to checking equivalence of all program behaviors for a given depth bound. In this work we use symbolic execution to generate the program behaviors and leverage control- and data-dependence information to facilitate the partitioning of program behaviors. The impacted program behaviors are termed as impact summaries. The dependence analyses that facilitate the generation of the impact summaries, we believe, could be used in conjunction with other abstraction and decomposition based approaches, [10, 12], as a complementary reduction technique. An evaluation of our regression verification technique shows that our approach is capable of leveraging similarities between program versions to reduce the size of the queries and the time required to check for logical equivalence. The main contributions of this work are: - A regression verification technique to generate impact summaries that can be checked for functional equivalence using an off-the-shelf decision procedure. - A proof that our approach is sound and complete with respect to the depth bound of symbolic execution. - An implementation of our technique using the LLVMcompiler infrastructure, the klee Symbolic Virtual Machine [4], and a variety of Satisfiability Modulo Theory (SMT) solvers, e.g., STP [7] and Z3 [6]. - An empirical evaluation on a set of C artifacts which shows that the use of impact summaries can reduce the cost of regression verification.

Backes, John↗

Verification approach for the Shuttle/Payload Contamination Evaluation computer program - Spacelab induced environment

The paper presents a compilation of the results of a systems level Shuttle/payload contamination analysis and related computer modeling activities. The current technical assessment of the contamination problems anticipated during the Spacelab program are discussed and recommendations are presented on contamination abatement designs and operational procedures based on experience gained in the field of contamination analysis and assessment, dating back to the pre-Skylab era. The ultimate test of the Shuttle/Payload Contamination Evaluation program will be through comparison of predictions with measured levels of contamination during actual flight.

Bareiss, L. E.↗

C formal verification with unix communication and concurrency

The results of a NASA SBIR project are presented in which CSP-Ariel, a verification system for C programs which use Unix system calls for concurrent programming, interprocess communication, and file input and output, was developed. This project builds on ORA's Ariel C verification system by using the system of Hoare's book, Communicating Sequential Processes, to model concurrency and communication. The system runs in ORA's Clio theorem proving environment. The use of CSP to model Unix concurrency and sketch the CSP semantics of a simple concurrent program is outlined. Plans for further development of CSP-Ariel are discussed. This paper is presented in viewgraph form.

Hoover, Doug N.↗

General Environmental Verification Specification

The NASA Goddard Space Flight Center s General Environmental Verification Specification (GEVS) for STS and ELV Payloads, Subsystems, and Components is currently being revised based on lessons learned from GSFC engineering and flight assurance. The GEVS has been used by Goddard flight projects for the past 17 years as a baseline from which to tailor their environmental test programs. A summary of the requirements and updates are presented along with the rationale behind the changes. The major test areas covered by the GEVS include mechanical, thermal, and EMC, as well as more general requirements for planning, tracking of the verification programs.

Milne, J. Scott, Jr.↗

Decision Engines for Software Analysis Using Satisfiability Modulo Theories Solvers

The area of software analysis, testing and verification is now undergoing a revolution thanks to the use of automated and scalable support for logical methods. A well-recognized premise is that at the core of software analysis engines is invariably a component using logical formulas for describing states and transformations between system states. The process of using this information for discovering and checking program properties (including such important properties as safety and security) amounts to automatic theorem proving. In particular, theorem provers that directly support common software constructs offer a compelling basis. Such provers are commonly called satisfiability modulo theories (SMT) solvers. Z3 is a state-of-the-art SMT solver. It is developed at Microsoft Research. It can be used to check the satisfiability of logical formulas over one or more theories such as arithmetic, bit-vectors, lists, records and arrays. The talk describes some of the technology behind modern SMT solvers, including the solver Z3. Z3 is currently mainly targeted at solving problems that arise in software analysis and verification. It has been applied to various contexts, such as systems for dynamic symbolic simulation (Pex, SAGE, Vigilante), for program verification and extended static checking (Spec#/Boggie, VCC, HAVOC), for software model checking (Yogi, SLAM), model-based design (FORMULA), security protocol code (F7), program run-time analysis and invariant generation (VS3). We will describe how it integrates support for a variety of theories that arise naturally in the context of the applications. There are several new promising avenues and the talk will touch on some of these and the challenges related to SMT solvers. Proceedings

Bjorner, Nikolaj↗

Real-Time Kennedy Space Center and Cape Canaveral Air Force Station High-Resolution Model Implementation and Verification

NASA's Launch Services Program, Ground Systems Development and Operations, Space Launch System and other programs at Kennedy Space Center (KSC) and Cape Canaveral Air Force Station (CCAFS) use the daily and weekly weather forecasts issued by the 45th Weather Squadron (45 WS) as decision tools for their day-to-day and launch operations on the Eastern Range (ER). Examples include determining if they need to limit activities such as vehicle transport to the launch pad, protect people, structures or exposed launch vehicles given a threat of severe weather, or reschedule other critical operations. The 45 WS uses numerical weather prediction models as a guide for these weather forecasts, particularly the Air Force Weather Agency (AFWA) 1.67 km Weather Research and Forecasting (WRF) model. Considering the 45 WS forecasters' and Launch Weather Officers' (LWO) extensive use of the AFWA model, the 45 WS proposed a task at the September 2013 Applied Meteorology Unit (AMU) Tasking Meeting requesting the AMU verify this model. Due to the lack of archived model data available from AFWA, verification is not yet possible. Instead, the AMU proposed to implement and verify the performance of an ER version of the high-resolution WRF Environmental Modeling System (EMS) model configured by the AMU (Watson 2013) in real time. Implementing a real-time version of the ER WRF-EMS would generate a larger database of model output than in the previous AMU task for determining model performance, and allows the AMU more control over and access to the model output archive. The tasking group agreed to this proposal; therefore the AMU implemented the WRF-EMS model on the second of two NASA AMU modeling clusters. The AMU also calculated verification statistics to determine model performance compared to observational data. Finally, the AMU made the model output available on the AMU Advanced Weather Interactive Processing System II (AWIPS II) servers, which allows the 45 WS and AMU staff to customize the model output display on the AMU and Range Weather Operations (RWO) AWIPS II client computers and conduct real-time subjective analyses.

Meteorology↗

Flight-test determination of aircraft cruise characteristics using acceleration and deceleration techniques

A flight-test technique has been developed under NASA Dryden sponsorship NSG 4028 to predict aircraft cruise performance characteristics. The technique used acceleration and deceleration maneuvers to define baseline aerodynamic and propulsion system characteristics, which were then input to a performance modeling prediction program. Conventional stabilized 'speed power' tests, which are normally used for cruise performance definition, can comprise a large portion of the flight time in a program. A significant reduction in flight time was estimated using the performance modeling approach with associated savings in cost and schedule. A 20-h verification flight-test program was accomplished.

Yechout, T. R.↗

U.S. Spacesuit Knowledge Capture – Chronicling Spacesuit Design for the Future

With less than 4 years until the United States is scheduled to land the first woman and next man on the Moon, NASA is leveraging 60 years of experience to build a spacesuit to assist in the success of this and future human space exploration missions. This experience comes from the achievements of retired and employed spacesuit experts, innovations that were conceived from existing ideas and inventions, and a plethora of archived knowledge. The U.S. Spacesuit Knowledge Capture (SKC) Program’s primary function is to capture, archive, and share current and legacy spacesuit-related knowledge with scientists, engineers, and technicians. To capture valuable spacesuit-related knowledge, the program uses various methods that have included hosting and recording classroom and online courses, workshops, and vignettes, and preserving thousands of legacy spacesuit-related files. In 2019, the SKC Program added to its role when it began coordinating the electronic recording of the new spacesuits’ buildup. This new, next-generation spacesuit is named the Exploration Extravehicular Mobility Unit (xEMU) and is a compilation of many components. As each component is tested and assembled into the suit, the SKC Program is chronicling this buildup using high-speed video production and photography that includes time-lapsed images. To complement the recording of the components, the SKC Program plans to record and photograph the design verification testing. In 2020, the SKC Program was given the initiative to research and identify the custodianship of historical spacesuit equipment that resides within the Crew and Thermal Systems Division. These archives will be added to the SKC Program’s expansive archived collection of spacesuit-related knowledge that represents over 5 decades of spacesuit legacy from the Apollo era to the pursuit of Mars and beyond. This paper describes the electronic documentation of the xEMU’s buildup and identifies the SKC Program’s 2020 accomplishments.

Cinda Chullen↗

U.S. Spacesuit Knowledge Capture – Chronicling Spacesuit Design for the Future

With less than 4 years until the United States is scheduled to land the first woman and next man on the Moon, NASA is leveraging 60 years of experience to build a spacesuit to assist in the success of this and future human space exploration missions. This experience comes from the achievements of retired and employed spacesuit experts, innovations that were conceived from existing ideas and inventions, and a plethora of archived knowledge. The U.S. Spacesuit Knowledge Capture (SKC) Program’s primary function is to capture, archive, and share current and legacy spacesuit-related knowledge with scientists, engineers, and technicians. To capture valuable spacesuit-related knowledge, the program uses various methods that have included hosting and recording classroom and online courses, workshops, and vignettes, and preserving thousands of legacy spacesuit-related files. In 2019, the SKC Program added to its role when it began coordinating the electronic recording of the new spacesuits’ buildup. This new, next-generation spacesuit is named the Exploration Extravehicular Mobility Unit (xEMU) and is a compilation of many components. As each component is tested and assembled into the suit, the SKC Program is chronicling this buildup using high-speed video production and photography that includes time-lapsed images. To complement the recording of the components, the SKC Program plans to record and photograph the design verification testing. In 2020, the SKC Program was given the initiative to research and identify the custodianship of historical spacesuit equipment that resides within the Crew and Thermal Systems Division. These archives will be added to the SKC Program’s expansive archived collection of spacesuit-related knowledge that represents over 5 decades of spacesuit legacy from the Apollo era to the pursuit of Mars and beyond. This paper describes the electronic documentation of the xEMU’s buildup and identifies the SKC Program’s 2020 accomplishments.

Cinda Chullen↗

Orbiter structural design and verification

The space shuttle development program provided the opportunity to challenge many of the established practices and approaches used in prior manned space flight programs. The most significant accomplishments and resulting precedents which emerged during the structural development of the space shuttle and the space shuttle orbiter are reviewed. Innovations in criteria, design solutions, and certification are highlighted, and brief comments on the lessons learned are included. Thermal stress, graphite epoxy moisture, window structure, and structural inspection are discussed under lessons learned.

Glynn, P. C.↗

The design integration of wingtip devices for light general aviation aircraft

An investigation was conducted to determine the load carrying capabilities and structural design requirements for wingtip devices on general aviation aircraft. Winglets were designed and analyzed as part of a research program involving a typical agricultural aircraft. This effort involved analytical load prediction for the winglets, structural design for both the winglets and aircraft installation, structural load testing and flight test verification. Conclusions from this program are believed to be applicable to the use of wingtip devices on light-weight general aviation aircraft.

Gifford, R. V.↗

Program Model Checking: A Practitioner's Guide

Program model checking is a verification technology that uses state-space exploration to evaluate large numbers of potential program executions. Program model checking provides improved coverage over testing by systematically evaluating all possible test inputs and all possible interleavings of threads in a multithreaded system. Model-checking algorithms use several classes of optimizations to reduce the time and memory requirements for analysis, as well as heuristics for meaningful analysis of partial areas of the state space Our goal in this guidebook is to assemble, distill, and demonstrate emerging best practices for applying program model checking. We offer it as a starting point and introduction for those who want to apply model checking to software verification and validation. The guidebook will not discuss any specific tool in great detail, but we provide references for specific tools.

Pressburger, Thomas T.↗