Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software engineering safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 289 records · Page 16

Station Program Note Pull Automation

Upon commencement of my internship, I was in charge of maintaining the CoFR (Certificate of Flight Readiness) Tool. The tool acquires data from existing Excel workbooks on NASA's and Boeing's databases to create a new spreadsheet listing out all the potential safety concerns for upcoming flights and software transitions. Since the application was written in Visual Basic, I had to learn a new programming language and prepare to handle any malfunctions within the program. Shortly afterwards, I was given the assignment to automate the Station Program Note (SPN) Pull process. I developed an application, in Python, that generated a GUI (Graphical User Interface) that will be used by the International Space Station Safety & Mission Assurance team here at Johnson Space Center. The application will allow its users to download online files with the click of a button, import SPN's based on three different pulls, instantly manipulate and filter spreadsheets, and compare the three sources to determine which active SPN's (Station Program Notes) must be reviewed for any upcoming flights, missions, and/or software transitions. Initially, to perform the NASA SPN pull (one of three), I had created the program to allow the user to login to a secure webpage that stores data, input specific parameters, and retrieve the desired SPN's based on their inputs. However, to avoid any conflicts with sustainment, I altered it so that the user may login and download the NASA file independently. After the user has downloaded the file with the click of a button, I defined the program to check for any outdated or pre-existing files, for successful downloads, to acquire the spreadsheet, convert it from a text file to a comma separated file and finally into an Excel spreadsheet to be filtered and later scrutinized for specific SPN numbers. Once this file has been automatically manipulated to provide only the SPN numbers that are desired, they are stored in a global variable, shown on the GUI, and transferred over to a new Excel worksheet for comparison. I managed to get my application to acquire the CSWG (Computer Safety Working Group) and the SPNWG (Space Station Working Group) SPN's with just two mouse clicks for each pull, as opposed to several from the original process. When all three pulls are performed, an Excel sheet containing all three different results will be generated for the user to compare and determine which SPN's will be presented or reviewed the following month. The experience from this internship has been spectacular. As a high school senior who will begin attending college in the fall, this internship has been both educationally and occupationally beneficial. The internship has allowed me the opportunities to learn new programming languages, effectively network with NASA personnel from a variety of departments at JSC, and allowed me to learn new professional skills and etiquette. My internship at NASA's Johnson Space Center has further motivated me to pursue a Master's degree in Software Engineering and strive for a prosperous career with NASA as a civil servant.

Delgado, Ivan↗

Bootstrapping Multi-Agent Unmanned Aerial Vehicle (UAV) System Integration Using Ground-Based Assets: Lessons Learned

The highly dynamic nature of UAVs imposes significant challenges when conducting initial testing ranging from safety risks posed by high-capacity lithium batteries and spinning propellers to rigorous timing demands on controllers and the consequences of failures mid-air. Flight testing of a single vehicle is time and labor intensive due to these challenges and more, and the complexity increases exponentially with the number of vehicles. While simulations and hardware-in-the-loop bench testing can provide adequate environments for preliminary validation, differences in system deployment architecture, software interfaces, and hardware infrastructure between simulation and a fleet of real UAVs create a sizable gap that must be navigated carefully during system integration. In support of the Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR) project, which had the goal of establishing a basis of certification of trust and trustworthiness in multi-agent autonomous systems, this gap was tackled from two directions. First, a novel mixed-reality simulation environment was engineered to blur the transition from simulation to flight hardware. Second, a fleet of Unmanned Surface Vehicles (USVs) was developed as a test and evaluation platform that more closely represented the final aerial fleet while eliminating many of the risks associated with air vehicles. This paper delves into the second element, analyzing the efficacy of the USV platform in performing system integration testing for the UAV system. In this paper we present the USV fleet and its role in reducing the aforementioned gaps in deployment architecture, software interfaces, and hardware infrastructure when moving from simulation to flight. An overview of the hardware and software onboard the vehicles will be provided along with supporting infrastructure. The system integration process will be documented including results in supporting both the overarching design reference mission (DRM) of ATTRACTOR and individual research efforts conducted during the project. Finally, we will discuss some of the practical lessons learned regarding the testing, deployment, and operation of multi-agent autonomous systems.

Matthew P Vaughan↗

Building confidence in models for complex barrier systems for radionuclides

The modeling and simulation of the Cement-clay Interaction-Diffusion field (CI-D) experiment at the Mont Terri site in Switzerland presented here demonstrates that it is possible to capture the multiscale physical and chemical features of natural and engineered barrier systems for radionuclides. The simulations are successfully carried out with the newly developed CrunchODiTi high-performance computing software that accounts for multiple continua, including a continuum representing the electrical double layer (EDL) developed along negatively charged clay particles in clay rock. The simulation also accounts for both the complex three-dimensional (3D) geometry, expected as the norm in a geological waste repository, and the anisotropy of the geological formation. In addition, the high resolution of the model makes it possible to include "skin effects" developed at the interface between highly reactive materials, in this case between the high pH cement and the circumneutral but electrostatic Opalinus Clay. The successful history matching with the field experiment demonstrates that the distinct geochemical and physical properties of the cement and the Opalinus Clay in the CI-D experiment can be accounted for. Such analyses are essential for developing a defensible safety case for the underground storage of radioactive waste.

Sarsenbayev, Dauren↗

Reliability and Maintainability Analysis for the Amine Swingbed Carbon Dioxide Removal System

I have performed a reliability & maintainability analysis for the Amine Swingbed payload system. The Amine Swingbed is a carbon dioxide removal technology that has gone through 2,400 hours of International Space Station on-orbit use between 2013 and 2016. While the Amine Swingbed is currently an experimental payload system, the Amine Swingbed may be converted to system hardware. If the Amine Swingbed becomes system hardware, it will supplement the Carbon Dioxide Removal Assembly (CDRA) as the primary CO2 removal technology on the International Space Station. NASA is also considering using the Amine Swingbed as the primary carbon dioxide removal technology for future extravehicular mobility units and for the Orion, which will be used for the Asteroid Redirect and Journey to Mars missions. The qualitative component of the reliability and maintainability analysis is a Failure Modes and Effects Analysis (FMEA). In the FMEA, I have investigated how individual components in the Amine Swingbed may fail, and what the worst case scenario is should a failure occur. The significant failure effects are the loss of ability to remove carbon dioxide, the formation of ammonia due to chemical degradation of the amine, and loss of atmosphere because the Amine Swingbed uses the vacuum of space to regenerate the Amine Swingbed. In the quantitative component of the reliability and maintainability analysis, I have assumed a constant failure rate for both electronic and nonelectronic parts. Using this data, I have created a Poisson distribution to predict the failure rate of the Amine Swingbed as a whole. I have determined a mean time to failure for the Amine Swingbed to be approximately 1,400 hours. The observed mean time to failure for the system is between 600 and 1,200 hours. This range includes initial testing of the Amine Swingbed, as well as software faults that are understood to be non-critical. If many of the commercial parts were switched to military-grade parts, the expected mean time to failure would be 2,300 hours. Both calculated mean times to failure for the Amine Swingbed use conservative failure rate models. The observed mean time to failure for CDRA is 2,500 hours. Working on this project and for NASA in general has helped me gain insight into current aeronautics missions, reliability engineering, circuit analysis, and different cultures. Prior my internship, I did not have a lot knowledge about the work being performed at NASA. As a chemical engineer, I had not really considered working for NASA as a career path. By engaging in interactions with civil servants, contractors, and other interns, I have learned a great deal about modern challenges that NASA is addressing. My work has helped me develop a knowledge base in safety and reliability that would be difficult to find elsewhere. Prior to this internship, I had not thought about reliability engineering. Now, I have gained a skillset in performing reliability analyses, and understanding the inner workings of a large mechanical system. I have also gained experience in understanding how electrical systems work while I was analyzing the electrical components of the Amine Swingbed. I did not expect to be exposed to as many different cultures as I have while working at NASA. I am referring to both within NASA and the Houston area. NASA employs individuals with a broad range of backgrounds. It has been great to learn from individuals who have highly diverse experiences and outlooks on the world. In the Houston area, I have come across individuals from different parts of the world. Interacting with such a high number of individuals with significantly different backgrounds has helped me to grow as a person in ways that I did not expect. My time at NASA has opened a window into the field of aeronautics. After earning a bachelor's degree in chemical engineering, I plan to go to graduate school for a PhD in engineering. Prior to coming to NASA, I was not aware of the graduate Pathways program. I intend to apply for the graduate Pathways program as positions are opened up. I would like to pursue future opportunities with NASA, especially as my engineering career progresses.

Dunbar, Tyler↗

General Pressurization Model in Simscape

System integration is an essential part of the engineering design process. The Ares I Upper Stage (US) is a complex system which is made up of thousands of components assembled into subsystems including a J2-X engine, liquid hydrogen (LH2) and liquid oxygen (LO2) tanks, avionics, thrust vector control, motors, etc. System integration is the task of connecting together all of the subsystems into one large system. To ensure that all the components will "fit together" as well as safety and, quality, integration analysis is required. Integration analysis verifies that, as an integrated system, the system will behave as designed. Models that represent the actual subsystems are built for more comprehensive analysis. Matlab has been an instrument widely use by engineers to construct mathematical models of systems. Simulink, one of the tools offered by Matlab, provides multi-domain graphical environment to simulate and design time-varying systems. Simulink is a powerful tool to analyze the dynamic behavior of systems over time. Furthermore, Simscape, a tool provided by Simulink, allows users to model physical (such as mechanical, thermal and hydraulic) systems using physical networks. Using Simscape, a model representing an inflow of gas to a pressurized tank was created where the temperature and pressure of the tank are measured over time to show the behavior of the gas. By further incorporation of Simscape into model building, the full potential of this software can be discovered and it hopefully can become a more utilized tool.

Servin, Mario↗

Proceedings of the Second NASA Formal Methods Symposium

This publication contains the proceedings of the Second NASA Formal Methods Symposium sponsored by the National Aeronautics and Space Administration and held in Washington D.C. April 13-15, 2010. Topics covered include: Decision Engines for Software Analysis using Satisfiability Modulo Theories Solvers; Verification and Validation of Flight-Critical Systems; Formal Methods at Intel -- An Overview; Automatic Review of Abstract State Machines by Meta Property Verification; Hardware-independent Proofs of Numerical Programs; Slice-based Formal Specification Measures -- Mapping Coupling and Cohesion Measures to Formal Z; How Formal Methods Impels Discovery: A Short History of an Air Traffic Management Project; A Machine-Checked Proof of A State-Space Construction Algorithm; Automated Assume-Guarantee Reasoning for Omega-Regular Systems and Specifications; Modeling Regular Replacement for String Constraint Solving; Using Integer Clocks to Verify the Timing-Sync Sensor Network Protocol; Can Regulatory Bodies Expect Efficient Help from Formal Methods?; Synthesis of Greedy Algorithms Using Dominance Relations; A New Method for Incremental Testing of Finite State Machines; Verification of Faulty Message Passing Systems with Continuous State Space in PVS; Phase Two Feasibility Study for Software Safety Requirements Analysis Using Model Checking; A Prototype Embedding of Bluespec System Verilog in the PVS Theorem Prover; SimCheck: An Expressive Type System for Simulink; Coverage Metrics for Requirements-Based Testing: Evaluation of Effectiveness; Software Model Checking of ARINC-653 Flight Code with MCP; Evaluation of a Guideline by Formal Modelling of Cruise Control System in Event-B; Formal Verification of Large Software Systems; Symbolic Computation of Strongly Connected Components Using Saturation; Towards the Formal Verification of a Distributed Real-Time Automotive System; Slicing AADL Specifications for Model Checking; Model Checking with Edge-valued Decision Diagrams; and Data-flow based Model Analysis.

Munoz, Cesar↗

Research and Development of The Immersive Simulations and Engineering Environment

March of 2018 marked the conclusion of the primary updates to the immersive Simulations and Engineering Environment (iSEE) at Kennedy Space Center (KSC). Many of the problems that had arisen during the previous semester have been addressed and rectified. These included the malfunction to one of the lab's primary routers, the inefficiency of the capture environment, and various interface issues in the analysis software, Jack. This semester was primarily research and development oriented with some focus on implementation of the new hardware and software that was received last semester. The new computers and cameras that arrived sometime during the winter were installed, and the lab received its second operation opportunity. The second operation was a major milestone for the lab, both in terms of what the abilities were and what can be learned from its use. The operation performed was a virtual simulation of a critical task that would occur, if it should be needed, in the Multi Payload Processing Facility. It was done to gather human factors data on its safety and process controls. The technicians were able to come to a number of conclusions about how to perform their task as a result of utilizing iSEE. Another key breakthrough this semester was the introduction to Jack Script, a scripting language built into our analysis software that further extend Jack capabilities. In addition to the aforementioned, many preparations were made for family day, an exposition for KSC families to come out and tour the spaceport. Due to family day being moved to the spring, the video made last fall had to be updated with recent environment changes in preparation for the Family Day demonstrations.

Motion Capture↗

Actuator and Motor Control End-to-End V&V on the Mars 2020 Rover

The Mars 2020 Perseverance rover is the most advanced robotic exploration system ever sent to another planet. To support the complex scientific and mobility needs of the mission, the rover utilizes 33 actuators, three multi-degree-of-freedom force-torque sensors, fifteen single or dual-speed resolvers, two solenoid valves, and twelve contact switches. The control for these actuators and sensors is achieved by several levels of flight software, coordinated between two computers with varying bandwidth control loops. Furthermore, the actuators and sensors were integrated into multiple larger robotic mechanisms that were delivered by different organizations at various points in the Integration and Test (I&T) timeline. All of this created a very complex Verification and Validation (V&V) scenario involving multiple subsystems and teams, several hardware and software testbeds with varying levels of fidelity, and significant systems engineering to ensure the overall I&T schedule could be maintained while ensuring system hardware safety.This paper details the integrated V&V effort across multiple teams and venues to provide full coverage of all necessary functionality, performance, and fault protection. First, it provides an overview of how the V&V campaign was subdivided among teams and venues and provides descriptions of the various hardware configurations used to support the testing. The Mars 2020 implementation of the plan incorporates many of the lessons learned from Mars Science Laboratory’s test campaign, and these value-added modifications are discussed here. Also included in this section is the system-level environmental testing approach used for mechanisms. Second, the paper describes the phased approach used by the teams to support new hardware and software deliveries to testbed and Systems I&T. In this approach the test campaign was built upon higher-level mechanism needs for performance, functionality, and safety at specific times in the campaign. Finally, the paper discusses lessons learned from the V&V campaign that should be applied to future large-scale motion control testing efforts.

Borne, Davis↗

The Integrated Medical Model: Outcomes from Independent Review

In 2016, the Integrated Medical Model (IMM) v4.0 underwent an extensive external review in preparation for transition to an operational status. In order to insure impartiality of the review process, the Exploration Medical Capabilities Element of NASA's Human Research Program convened the review through the Systems Review Office at NASA Goddard Space Flight Center (GSFC). The review board convened by GSFC consisted of persons from both NASA and academia with expertise in the fields of statistics, epidemiology, modeling, software development, aerospace medicine, and project management (see Figure 1). The board reviewed software and code standards, as well as evidence pedigree associated with both the input and outcomes information. The board also assesses the models verification, validation, sensitivity to parameters and ability to answer operational questions. This talk will discuss the processes for designing the review, how the review progressed and the findings from the board, as well as summarize the IMM project responses to those findings. Overall, the board found that the IMM is scientifically sound, represents a necessary, comprehensive approach to identifying medical and environmental risks facing astronauts in long duration missions and is an excellent tool for communication between engineers and physicians. The board also found IMM and its customer(s) should convene an additional review of the IMM data sources and to develop a sustainable approach to augment, peer review, and maintain the information utilized in the IMM. The board found this is critically important because medical knowledge continues to evolve. Delivery of IMM v4.0 to the Crew Health and Safety (CHS) Program will occur in the 2017. Once delivered for operational decision support, IMM v4.0 will provide CHS with additional quantitative capability in to assess astronaut medical risks and required medical capabilities to help drive down overall mission risks.

medical equipment↗

Develop Advanced Nonlinear Signal Analysis Topographical Mapping System

During the development of the SSME, a hierarchy of advanced signal analysis techniques for mechanical signature analysis has been developed by NASA and AI Signal Research Inc. (ASRI) to improve the safety and reliability for Space Shuttle operations. These techniques can process and identify intelligent information hidden in a measured signal which is often unidentifiable using conventional signal analysis methods. Currently, due to the highly interactive processing requirements and the volume of dynamic data involved, detailed diagnostic analysis is being performed manually which requires immense man-hours with extensive human interface. To overcome this manual process, NASA implemented this program to develop an Advanced nonlinear signal Analysis Topographical Mapping System (ATMS) to provide automatic/unsupervised engine diagnostic capabilities. The ATMS will utilize a rule-based Clips expert system to supervise a hierarchy of diagnostic signature analysis techniques in the Advanced Signal Analysis Library (ASAL). ASAL will perform automatic signal processing, archiving, and anomaly detection/identification tasks in order to provide an intelligent and fully automated engine diagnostic capability. The ATMS has been successfully developed under this contract. In summary, the program objectives to design, develop, test and conduct performance evaluation for an automated engine diagnostic system have been successfully achieved. Software implementation of the entire ATMS system on MSFC's OISPS computer has been completed. The significance of the ATMS developed under this program is attributed to the fully automated coherence analysis capability for anomaly detection and identification which can greatly enhance the power and reliability of engine diagnostic evaluation. The results have demonstrated that ATMS can significantly save time and man-hours in performing engine test/flight data analysis and performance evaluation of large volumes of dynamic test data.

Jong, Jen-Yi↗

Mission planning for photogrammetry-based autonomous 3D Mapping of Dams using a commercial UAV

The application of autonomous unmanned aerial vehicles (UAVs) for conducting inspections of dams represents an innovative approach aimed at enhancing safety, efficiency, and cost-effectiveness. In this context, this paper presents algorithms for UAV mission design in autonomous dam inspections that include the creation of a 3D map based on photogrammetry. The algorithms were systematically developed to incorporate a comprehensive set of parameters that account for the geometric characteristics of the dam and adhere to photogrammetry specifications. To validate the proposed methodology, we utilized a commercial programmable quadrotor, specifically the Parrot Anafi USA Gov drone, which is equipped with high-quality cameras and can be programmed with the help of a software development kit (SDK) provided by the manufacturer. Our results demonstrate the efficacy of our method, highlighting how the generated maps can be used for hazard detection in the downstream slope of dams.

42 ENGINEERING↗

Orion Launch Abort System Performance on Exploration Flight Test 1

This paper will present an overview of the flight test objectives and performance of the Orion Launch Abort System during Exploration Flight Test-1. Exploration Flight Test-1, the first flight test of the Orion spacecraft, was managed and led by the Orion prime contractor, Lockheed Martin, and launched atop a United Launch Alliance Delta IV Heavy rocket. This flight test was a two-orbit, high-apogee, high-energy entry, low-inclination test mission used to validate and test systems critical to crew safety. This test included the first flight test of the Launch Abort System preforming Orion nominal flight mission critical objectives. NASA is currently designing and testing the Orion Multi-Purpose Crew Vehicle (MPCV). Orion will serve as NASA's new exploration vehicle to carry astronauts to deep space destinations and safely return them to earth. The Orion spacecraft is composed of four main elements: the Launch Abort System, the Crew Module, the Service Module, and the Spacecraft Adapter (Fig. 1). The Launch Abort System (LAS) provides two functions; during nominal launches, the LAS provides protection for the Crew Module from atmospheric loads and heating during first stage flight and during emergencies provides a reliable abort capability for aborts that occur within the atmosphere. The Orion Launch Abort System (LAS) consists of an Abort Motor to provide the abort separation from the Launch Vehicle, an Attitude Control Motor to provide attitude and rate control, and a Jettison Motor for crew module to LAS separation (Fig. 2). The jettison motor is used during a nominal launch to separate the LAS from the Launch Vehicle (LV) early in the flight of the second stage when it is no longer needed for aborts and at the end of an LAS abort sequence to enable deployment of the crew module's Landing Recovery System. The LAS also provides a Boost Protective Cover fairing that shields the crew module from debris and the aero-thermal environment during ascent. Although the Orion Program has tested a number of the critical systems of the Orion spacecraft on the ground, the launch environment cannot be replicated completely on Earth. A number of flight tests have been conducted and are planned to demonstrate the performance and enable certification of the Orion Spacecraft. Exploration Flight Test 1, the first flight test of the Orion spacecraft, was successfully flown on December 5, 2014 from Cape Canaveral Air Force Station's Space Launch Complex 37. Orion's first flight was a two-orbit, high-apogee, high-energy entry, low-inclination test mission used to validate and test systems critical to crew safety, such as heat shield performance, separation events, avionics and software performance, attitude control and guidance, parachute deployment and recovery operations. One of the key separation events tested during this flight was the nominal jettison of the LAS. Data from this flight will be used to verify the function of the jettison motor to separate the Launch Abort System from the crew module so it can continue on with the mission. The LAS nominal jettison event on Exploration Flight Test 1 occurred at six minutes and twenty seconds after liftoff (See Fig. 3). The abort motor and attitude control motors were inert for Exploration Flight Test 1, since the mission did not require abort capabilities. A suite of developmental flight instrumentation was included on the flight test to provide data on spacecraft subsystems and separation events. This paper will focus on the flight test objectives and performance of the LAS during ascent and nominal jettison. Selected LAS subsystem flight test data will be presented and discussed in the paper. Exploration Flight Test -1 will provide critical data that will enable engineering to improve Orion's design and reduce risk for the astronauts it will protect as NASA continues to move forward on its human journey to Mars. The lessons learned from Exploration Flight Test 1 and the other Flight Test Vehicles will certainly contribute to the vehicle architecture of a human-rated space launch vehicle.

McCauley, R.↗

Evaluation of a Shuttle Derived Vehicle (SDV) for Cargo Transportation

In this new era of space exploration, a host of launch vehicles are being examined for possible use in transporting cargo and crew to low Earth orbit and beyond. Launch vehicles derived from the Space Shuttle Program (SSP), known as Shuttle Derived Vehicles (SDVs), are prime candidates for heavy-lift duty because of their potential to minimize non-recurring costs and because the Shuttle can leverage off proven high-performance flight systems with established ground and flight support. To determine the merits of SDVs, a detailed evaluation was performed. This evaluation included a trade study and risk assessment of options based on performance, safety reliability, cost, operations, and evolution. The purpose of this paper is to explain the approach, processes, and tools used to evaluate launch vehicles for heavy lift cargo transportation. The process included defining the trade space, characterizing the concepts, analyzing the systems, and scoring the options. The process also included a review by subject experts from NASA and industry to compare past and recent study data and assess the risks. A set of technical performance measures (TPMs) was generated based on the study requirements and constraints. Tools such as INTROS and POST were used to calculate performance, FIRST was used for prediction of reliability, and other software packages, both commercial and NASA-owned, were applied to study the trade space. By following a clear process and using the right tools a thorough assessment was performed. An SDV can be classified as either a side-mount vehicle (SMV) or an in-line vehicle OLV). An SMV is a Space Shuttle where the Orbiter is replaced by a cargo carrier. An ILV is comprised of a modified Shuttle External Tank (ET) with engines mounted to the bottom and cargo mounted atop. For both families of vehicles, Solid Rocket Boosters (SRBs) are attached to the ET. The first derivate of Shuttle is defined as the vehicle with minimum changes necessary to transform the Space Shuttle into an SDV. Deltas from the first derivate were also formulated to study more SDV options. Examples of deltas include replacing the SRBs with larger and/or more SRBs, adding an upper stage, increasing the size of the ET, changing the engines, and modifying the elements. Challenges for SDV range from tailoring infrastructure to meeting the exploration schedule. Although SDV is based on the Space Shuttle, it still includes development risk for designing and building a Cargo Carrier. There are also performance challenges in that Shuttle is not optimized for cargo-only missions, but it is a robust system built on reusability. Balancing the strengths and weaknesses of the Shuttle to meet Lunar and Mars mission objectives provides the framework for an informative trade study. SDV was carefully analyzed and the results of the study provide invaluable data for use in the new exploration initiative.

Roman, Jose M.↗

NASA Tech Briefs, February 2014

Topics include: JWST Integrated Simulation and Test (JIST) Core; Software for Non-Contact Measurement of an Individual's Heart Rate Using a Common Camera; Rapid Infrared Pixel Grating Response Testbed; Temperature Measurement and Stabilization in a Birefringent Whispering Gallery Resonator; JWST IV and V Simulation and Test (JIST) Solid State Recorder (SSR) Simulator; Development of a Precision Thermal Doubler for Deep Space; Improving Friction Stir Welds Using Laser Peening; Methodology of Evaluating Margins of Safety in Critical Brazed Joints; Interactive Inventory Monitoring; Sensor for Spatial Detection of Single-Event Effects in Semiconductor-Based Electronics; Reworked CCGA-624 Interconnect Package Reliability for Extreme Thermal Environments; Current-Controlled Output Driver for Directly Coupled Loads; Bulk Metallic Glasses and Matrix Composites as Spacecraft Shielding; Touch Temperature Coating for Electrical Equipment on Spacecraft; Li-Ion Electrolytes Containing Flame-Retardant Additives; Autonomous Robotic Manipulation (ARM); CARVE Log; Platform Perspective Toolkit; Convex Hull-Based Plume and Anomaly Detection; Pre-Filtration of GOSAT Data Using Only Level 1 Data and an Intelligent Filter to Remove Low Clouds; Affordability Comparison Tool - ACT; "Ascent - Commemorating Shuttle" for iPad; Cassini Mission App; Light-Weight Workflow Engine: A Server for Executing Generic Workflows; Model for System Engineering of the CheMin Instrument; Timeline Central Concepts; Parallel Particle Filter Toolkit; Particle Filter Simulation and Analysis Enabling Non-Traditional Navigation; Quasi-Terminator Orbits for Mapping Small Primitive Bodies; The Subgrid-Scale Scalar Variance Under Supercritical Pressure Conditions; Sliding Gait for ATHLETE Mobility; and Automated Generation of Adaptive Filter Using a Genetic Algorithm and Cyclic Rule Reduction.

Source record↗

Toward Synthesis, Analysis, and Certification of Security Protocols

Implemented security protocols are basically pieces of software which are used to (a) authenticate the other communication partners, (b) establish a secure communication channel between them (using insecure communication media), and (c) transfer data between the communication partners in such a way that these data only available to the desired receiver, but not to anyone else. Such an implementation usually consists of the following components: the protocol-engine, which controls in which sequence the messages of the protocol are sent over the network, and which controls the assembly/disassembly and processing (e.g., decryption) of the data. the cryptographic routines to actually encrypt or decrypt the data (using given keys), and t,he interface to the operating system and to the application. For a correct working of such a security protocol, all of these components must work flawlessly. Many formal-methods based techniques for the analysis of a security protocols have been developed. They range from using specific logics (e.g.: BAN-logic [4], or higher order logics [12] to model checking [2] approaches. In each approach, the analysis tries to prove that no (or at least not a modeled intruder) can get access to secret data. Otherwise, a scenario illustrating the &tack may be produced. Despite the seeming simplicity of security protocols ("only" a few messages are sent between the protocol partners in order to ensure a secure communication), many flaws have been detected. Unfortunately, even a perfect protocol engine does not guarantee flawless working of a security protocol, as incidents show. Many break-ins and security vulnerabilities are caused by exploiting errors in the implementation of the protocol engine or the underlying operating system. Attacks using buffer-overflows are a very common class of such attacks. Errors in the implementation of exception or error handling can open up additional vulnerabilities. For example, on a website with a log-in screen: multiple tries with invalid passwords caused the expected error message (too many retries). but let the user nevertheless pass. Finally, security can be compromised by silly implementation bugs or design decisions. In a commercial VPN software, all calls to the encryption routines were incidentally replaced by stubs, probably during factory testing. The product worked nicely. and the error (an open VPN) would have gone undetected, if a team member had not inspected the low-level traffic out of curiosity. Also, the use secret proprietary encryption routines can backfire, because such algorithms often exhibit weaknesses which can be exploited easily (see e.g., DVD encoding). Summarizing, there is large number of possibilities to make errors which can compromise the security of a protocol. In today s world with short time-to-market and the use of security protocols in open and hostile networks for safety-critical applications (e.g., power or air-traffic control), such slips could lead to catastrophic situations. Thus, formal methods and automatic reasoning techniques should not be used just for the formal proof of absence of an attack, but they ought to be used to provide an end-to-end tool-supported framework for security software. With such an approach all required artifacts (code, documentation, test cases) , formal analyses, and reliable certification will be generated automatically, given a single, high level specification. By a combination of program synthesis, formal protocol analysis, certification; and proof-carrying code, this goal is within practical reach, since all the important technologies for such an approach actually exist and only need to be assembled in the right way.

Schumann, Johann↗

Digital Image Correlation Data Processing and Analysis Techniques to Enhance Test Data Assessment and Improve Structural Simulations

The NASA Shell Buckling Knockdown Factor Project (SBKF) was established in 2007 by the NASA Engineering and Safety Center (NESC) with the primary goal to develop new analysis-based buckling design factors (a.k.a. knockdown factors) and high-fidelity buckling simulations for selected launch-vehicle-like cylindrical shell structures. A series of tests are being conducted on large-scale metallic and composite cylindrical shells in order to provide validation data for these new factors and simulations. However, the validation of these new factors and simulations is quite demanding and requires test data that is commensurate with their fidelity. Traditional instrumentation, such as linear variable displacement transducers (LVDTs) and electrical-resistance strain gages serve a critical role in providing accurate displacement and strain measurements in these tests, but only allow for data to be recorded at a select number of point locations and are not sufficient to provide all the necessary validation data. Advanced measurement technologies can be used effectively to complement traditional instrumentation and gather additional data required to validate these structural simulations. In particular, three-dimensional digital image correlation (DIC) was implemented during SBKF cylinder testing to characterize the full-field displacement and strain behavior. Commercially available VIC-3DTM software and user-written data processing scripts were used to generate valuable data and insight into the complex buckling response of the cylinders that otherwise would be impossible to gather using traditional instrumentation. In addition, the measured data from DIC was used to verify measured test data obtained from other instrumentation, enhance test and analysis correlation, and help identify the root cause of anomalous test results that may have gone unexplained if only traditional instrumentation was used. Selected test results that demonstrate the use of DIC on the SBKF cylinders are presented and a portion of the data processing methods are described.

Gardner, Nathaniel W.↗

JUSTIFI: Software for Improving Performance Objectives via Energy Efficiency

With growing energy supply concerns and rising costs, energy efficiency is a critical component of industrial energy resilience and competitiveness by directly reducing energy operating costs. Energy efficiency projects in manufacturing also yield valuable benefits to other key metrics, such as improved quality, reduced maintenance costs, improved safety, decreased pollution, and enhanced productivity. However, it is difficult to receive approval for energy efficiency projects, so implementation rates are low, even when meeting capital project payback period criteria. The inclusion and quantification of non-energy benefits (NEBs) in the decision-making process for energy efficiency projects can improve the overall financial payback period while demonstrating a positive impact on the firm's key performance metrics and business strategy. Despite their significant financial and strategic value, NEBs are rarely factored into decision-making due to lack of tools to effectively identify and quantify them. Therefore, a comprehensive and integrative approach is needed for the rapidly evolving energy landscape. To address these challenges, through funding from U.S. Department of Energy, our new assessment methodology integrates common continuous improvement six sigma concepts, such as the DMAIC process, and a protocol of guiding questions, into energy efficiency assessments to identify NEBs. We have also developed open-source software, JUSTIFI, to guide users through this process, data collection, and quantification. It is designed to be used concurrently with DOE energy system analysis software suite, MEASUR. Our methodology and tools inform energy assessors, firm engineering, decision makers, and workforce seeking to increase energy resilience and to maximize benefits aligned with performance metrics.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

JUSTIFI: Software for Improving Performance Objectives via Energy Efficiency

With growing energy supply concerns and rising costs, energy efficiency is a critical component of industrial energy resilience and competitiveness by directly reducing energy operating costs. Energy efficiency projects in manufacturing also yield valuable benefits to other key metrics, such as improved quality, reduced maintenance costs, improved safety, decreased pollution, and enhanced productivity. However, it is difficult to receive approval for energy efficiency projects, so implementation rates are low, even when meeting capital project payback period criteria. The inclusion and quantification of non-energy benefits (NEBs) in the decision-making process for energy efficiency projects can improve the overall financial payback period while demonstrating a positive impact on the firm's key performance metrics and business strategy. Despite their significant financial and strategic value, NEBs are rarely factored into decision-making due to lack of tools to effectively identify and quantify them. Therefore, a comprehensive and integrative approach is needed for the rapidly evolving energy landscape. To address these challenges, through funding from U.S. Department of Energy, our new assessment methodology integrates common continuous improvement six sigma concepts, such as the DMAIC process, and a protocol of guiding questions, into energy efficiency assessments to identify NEBs. We have also developed open-source software, JUSTIFI, to guide users through this process, data collection, and quantification. It is designed to be used concurrently with DOE energy system analysis software suite, MEASUR. Our methodology and tools inform energy assessors, firm engineering, decision makers, and workforce seeking to increase energy resilience and to maximize benefits aligned with performance metrics.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗