Search NASA⌕ Search

SEARCH · Search NASA

Results for “Program verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 307 records · Page 17

Measured ground performance and predicted orbital performance of the superfluid helium dewar for the Cosmic Background Explorer

A critical component of the Cosmic Background Explorer observatory, which is to be lifted to orbit in 1988, is the 650-l superfluid He dewar housing a far-IR absolute spectrophotometer and a diffuse IR background experiment. Attention is presently given to the results of a four-month-long test program encompassing dewar filling verification, vibration characteristics, thermal performance over orbital lifetime, and aperture cover ejection behavior. No significant flaws have been noted; the orbital cryogen lifetime is projected to be 14 months.

Hopkins, Richard A.↗

Knowledge-based system V and V in the Space Station Freedom program

Knowledge Based Systems (KBS's) are expected to be heavily used in the Space Station Freedom Program (SSFP). Although SSFP Verification and Validation (V&V) requirements are based on the latest state-of-the-practice in software engineering technology, they may be insufficient for Knowledge Based Systems (KBS's); it is widely stated that there are differences in both approach and execution between KBS V&V and conventional software V&V. In order to better understand this issue, we have surveyed and/or interviewed developers from sixty expert system projects in order to understand the differences and difficulties in KBS V&V. We have used this survey results to analyze the SSFP V&V requirements for conventional software in order to determine which specific requirements are inappropriate for KBS V&V and why they are inappropriate. Further work will result in a set of recommendations that can be used either as guidelines for applying conventional software V&V requirements to KBS's or as modifications to extend the existing SSFP conventional software V&V requirements to include KBS requirements. The results of this work are significant to many projects, in addition to SSFP, which will involve KBS's.

Kelley, Keith↗

Fan Acoustic Issues in the NASA Space Flight Experience

Emphasis needs to be placed on choosing quiet fans compatible with systems design and specifications that control spec levels: a) Sound power; b) Choose quiet fan or plan to quiet it, early in program; c) Plan early verification that fan source allocations are met. Airborne noise: a) System design should function/play together with fans used (flow passages, restrictions, bends, expansions & contractions, and acoustics) vs. fan speed understood (nominal, worst case, & unplanned variances); b) Fan inlets treated, as required; c) Fan Outlets treated, as required; d) Ducted system inlets are outlets designed for acoustic compliance compatibility & designed so some late required modifications can be made without significant impacts. Structure Borne Noise: a) Structure borne noise dealt with as part of fan package or installation; b) Duct attachments and lines isolated. Case Radiated Noise: - Treatment added as much as possible to fan package (see example).

Allen, Christopher S.↗

Technical Reference Suite Addressing Challenges of Providing Assurance for Fault Management Architectural Design

Research into complexities of software systems Fault Management (FM) and how architectural design decisions affect safety, preservation of assets, and maintenance of desired system functionality has coalesced into a technical reference (TR) suite that advances the provision of safety and mission assurance. The NASA Independent Verification and Validation (IVV) Program, with Software Assurance Research Program support, extracted FM architectures across the IVV portfolio to evaluate robustness, assess visibility for validation and test, and define software assurance methods applied to the architectures and designs. This investigation spanned IVV projects with seven different primary developers, a wide range of sizes and complexities, and encompassed Deep Space Robotic, Human Spaceflight, and Earth Orbiter mission FM architectures. The initiative continues with an expansion of the TR suite to include Launch Vehicles, adding the benefit of investigating differences intrinsic to model-based FM architectures and insight into complexities of FM within an Agile software development environment, in order to improve awareness of how nontraditional processes affect FM architectural design and system health management.

Fitz, Rhonda↗

First Image Products from EcoSAR - Osa Peninsula, Costa Rica

Designed especially for forest ecosystem studies, EcoSAR employs state-of-the-art digital beamforming technology to generate wide-swath, high-resolution imagery. EcoSARs dual antenna single-pass imaging capability eliminates temporal decorrelation from polarimetric and interferometric analysis, increasing the signal strength and simplifying models used to invert forest structure parameters. Antennae are physically separated by 25 meters providing single pass interferometry. In this mode the radar is most sensitive to topography. With 32 active transmit and receive channels, EcoSARs digital beamforming is an order of magnitude more versatile than the digital beamforming employed on the upcoming NISAR mission. EcoSARs long wavelength (P-band, 435 MHz, 69 cm) measurements can be used to simulate data products for ESAs future BIOMASS mission, allowing scientists to develop algorithms before the launch of the satellite. EcoSAR can also be deployed to collect much needed data where BIOMASS satellite wont be allowed to collect data (North America, Europe and Arctic), filling in the gaps to keep a watchful eye on the global carbon cycle. EcoSAR can play a vital role in monitoring, reporting and verification schemes of internationals programs such as UN-REDD (United Nations Reducing Emissions from Deforestation and Degradation) benefiting global society. EcoSAR was developed and flown with support from NASA Earth Sciences Technology Offices Instrument Incubator Program.

InSAR↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification & Validation (IV&V) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASAs Office of Safety and Mission Assurance (OSMA) defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domain/component, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IV&V enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

IV&V↗

Real-Time Kennedy Space Center and Cape Canaveral Air Force Station High-Resolution Model Implementation and Verification

Customer: NASA's Launch Services Program (LSP), Ground Systems Development and Operations (GSDO), and Space Launch System (SLS) programs. NASA's LSP, GSDO, SLS and other programs at Kennedy Space Center (KSC) and Cape Canaveral Air Force Station (CCAFS) use the daily and weekly weather forecasts issued by the 45th Weather Squadron (45 WS) as decision tools for their day-to-day and launch operations on the Eastern Range (ER). For example, to determine if they need to limit activities such as vehicle transport to the launch pad, protect people, structures or exposed launch vehicles given a threat of severe weather, or reschedule other critical operations. The 45 WS uses numerical weather prediction models as a guide for these weather forecasts, particularly the Air Force Weather Agency (AFWA) 1.67 kilometer Weather Research and Forecasting (WRF) model. Considering the 45 WS forecasters' and Launch Weather Officers' (LWO) extensive use of the AFWA model, the 45 WS proposed a task at the September 2013 Applied Meteorology Unit (AMU) Tasking Meeting requesting the AMU verify this model. Due to the lack of archived model data available from AFWA, verification is not yet possible. Instead, the AMU proposed to implement and verify the performance of an ER version of the AMU high-resolution WRF Environmental Modeling System (EMS) model (Watson 2013) in real-time. The tasking group agreed to this proposal; therefore the AMU implemented the WRF-EMS model on the second of two NASA AMU modeling clusters. The model was set up with a triple-nested grid configuration over KSC/CCAFS based on previous AMU work (Watson 2013). The outer domain (D01) has 12-kilometer grid spacing, the middle domain (D02) has 4-kilometer grid spacing, and the inner domain (D03) has 1.33-kilometer grid spacing. The model runs a 12-hour forecast every hour, D01 and D02 domain outputs are available once an hour and D03 is every 15 minutes during the forecast period. The AMU assessed the WRF-EMS 1.33-kilometer domain model performance for the 2014 warm season (May-September). Verification statistics were computed using the Model Evaluation Tools, which compared the model forecasts to observations. The mean error values were close to 0 and the root mean square error values were less than 1.8 for mean sea-level pressure (millibars), temperature (degrees Kelvin), dewpoint temperature (degrees Kelvin), and wind speed (per millisecond), all very small differences between the forecast and observations considering the normal magnitudes of the parameters. The precipitation forecast verification results showed consistent under-forecasting of the precipitation object size. This could be an artifact of calculating the statistics for each hour rather than for the entire 12-hour period. The AMU will continue to generate verification statistics for the 1.33-kilometer WRF-EMS domain as data become available in future cool and warm seasons. More data will produce more robust statistics and reveal a more accurate assessment of model performance. Once the formal task was complete, the AMU conducted additional work to better understand the wind direction results. The results were stratified diurnally and by wind speed to determine what effects the stratifications would have on the model wind direction verification statistics. The results are summarized in the addendum at the end of this report. In addition to verifying the model's performance, the AMU also made the output available in the Advanced Weather Interactive Processing System II (AWIPS II). This allows the 45 WS and AMU staff to customize the model output display on the AMU and Range Weather Operations AWIPS II client computers and conduct real-time subjective analyses. In the future, the AMU will implement an updated version of the WRF-EMS model that incorporates local data assimilation. This model will also run in real-time and be made available in AWIPS II.

Numerical Weather Prediction↗

Improved Verification for Aerospace Systems

Aerospace systems are subject to many stringent performance requirements to be verified with low risk. This report investigates verification planning using conditional approaches vice the standard classical statistical methods, and usage of historical surrogate data for requirement validation and in verification planning. The example used in this report to illustrate the results of these investigations is a proposed mission assurance requirement with the concomitant maximum acceptable verification risk for the NASA Constellation Program Orion Launch Abort System (LAS). This report demonstrates the following improvements: 1) verification planning using conditional approaches vice classical statistical methods results in plans that are more achievable and feasible; 2) historical surrogate data can be used to bound validation of performance requirements; and, 3) incorporation of historical surrogate data in verification planning using conditional approaches produces even less costly and more reasonable verification plans. The procedures presented in this report may produce similar improvements and cost savings in verification for any stringent performance requirement for an aerospace system.

Powell, Mark A.↗

Drive-train dynamics technology - State-of-the-art and design of a test facility for advanced development

A program for the development and verification of drive-train dynamic technology is described along with its basis and the results expected from it. A central feature of this program is a drive-train test facility designed for the testing and development of advanced drive-train components, including shaft systems, dampers, and couplings. Previous efforts in designing flexible dynamic drive-train systems are reviewed, and the present state of the art is briefly summarized. The design of the test facility is discussed with major attention given to the formulation of the test-rig concept, dynamic scaling of model shafts, and the specification of design parameters. Specific efforts envisioned for the test facility are briefly noted, including evaluations of supercritical test shafts, stability thresholds for various sources and types of instabilities that can exist in shaft systems, effects of structural flexibility on the dynamic performance of dampers, and methods for vibration control in two-level and three-level flexible shaft systems.

Badgley, R. H.↗

A progress report on a NASA research program for embedded computer systems software

The paper presents the results of the second stage of the Multipurpose User-oriented Software Technology (MUST) program. Four primary areas of activities are discussed: programming environment, HAL/S higher-order programming language support, the Integrated Verification and Testing System (IVTS), and distributed system language research. The software development environment is provided by the interactive software invocation system. The higher-order programming language (HOL) support chosen for consideration is HAL/S mainly because at the time it was one of the few HOLs with flight computer experience and it is the language used on the Shuttle program. The overall purpose of IVTS is to provide a 'user-friendly' software testing system which is highly modular, user controlled, and cooperative in nature.

Foudriat, E. C.↗

Development of advanced high-temperature heat flux sensors. Phase 2: Verification testing

A two-phase program is conducted to develop heat flux sensors capable of making heat flux measurements throughout the hot section of gas turbine engines. In Phase 1, three types of heat flux sensors are selected; embedded thermocouple, laminated, and Gardon gauge sensors. A demonstration of the ability of these sensors to operate in an actual engine environment is reported. A segmented liner of each of two combustors being used in the Broad Specification Fuels Combustor program is instrumented with the three types of heat flux sensors then tested in a high pressure combustor rig. Radiometer probes are also used to measure the radiant heat loads to more fully characterize the combustor environment. Test results show the heat flux sensors to be in good agreement with radiometer probes and the predicted data trends. In general, heat flux sensors have strong potential for use in combustor development programs.

Atkinson, W. H.↗

A Normal Incidence X-ray Telescope (NIXT) Sounding Rocket Payload

During the past year the changeover from the normal incidence X ray telescope (NIXT) program to the new TXI sounding rocket program was completed. The NIXT effort, aimed at evaluating the viability of the remaining portions of the NIXT hardware and design has been finished and the portions of the NIXT which are viable and flightworthy, such as filters, mirror mounting hardware, electronic and telemetry interface systems, are now part of the new rocket payload. The backup NIXT multilayer-coated X ray telescope and its mounting hardware have been completely fabricated and are being stored for possible future use in the TXI rocket. The h-alpha camera design is being utilized in the TXI program for real-time pointing verification and control via telemetry. Two papers, summarizing scientific results from the NIXT rocket program were published this year.

Golub, Leon↗

C Language Integrated Production System (CLIPS)

Ideal for developing expert systems, CLIPS language easy to use and called from or make calls to other programs. Advanced features include cross-reference, style, and verification facility catching logic errors in large systems. Program machine independent.

Riley, G.↗

Estimating Delays In ASIC's

Verification is important aspect of process of designing application-specific integrated circuit (ASIC). Design must not only be functionally accurate, but must also maintain correct timing. IFA, Intelligent Front Annotation program, assists in verifying timing of ASIC early in design process. This program speeds design-and-verification cycle by estimating delays before layouts completed. Written in C language.

Burke, Gary↗

Magnetic cleanliness verification approach on tethered satellite

Magnetic cleanliness testing was performed on the Tethered Satellite as the last step of an articulated verification campaign aimed at demonstrating the capability of the satellite to support its TEMAG (TEthered MAgnetometer) experiment. Tests at unit level and analytical predictions/correlations using a dedicated mathematical model (GANEW program) are also part of the verification activities. Details of the tests are presented, and the results of the verification are described together with recommendations for later programs.

Messidoro, Piero↗

A Verification Framework for Runtime Assurance of Autonomous UAS

Runtime Assurance (RTA) is a design-time architecture for safety-critical systems where an internal monitor acts upon detecting a violation of a property. The simplex architecture is an instance of RTA, where the action taken is to hand control of the overall system to a trusted controller when an untrusted one violates a safety property. Simplex RTA is emerging as a method for allowing AI/ML and other unverified software to be integrated into safety-critical applications like aircraft. To this end, the American Society for Testing and Materials (ASTM) and NASA have each published guidelines on the use of RTA in such systems. In the simplex RTA framework, a system has an advanced controller (AC) and a reversionary controller (RC). The system is allowed to operate with the AC until a runtime monitor detects that some property has been violated and then the RC takes over. Assuming that the sample rate of the monitor will detect improper functioning with enough time for the RC to correct the impending problem, and that the RC is trusted, the system will operate as intended. This use of the simplex RTA framework can allow for the integration of untrusted, but possibly more performant, controllers in a safe way. This paper presents a formalization of a simplex RTA framework in the Prototype Verification System (PVS) theorem prover using an embedding of differential dynamic logic (DDL) called Plaidypvs. A novel feature of this framework is that it can be instantiated at different levels of abstraction. This feature allows for the formal verification of a system with an untrusted black box component, such as an AI/ML controller. This paper does not address the many difficulties in deploying RTA in an industrial-level system. Instead, the focus is on the formal verification of the simplex RTA framework in the language of hybrid programs. Hybrid programs are programs that include both discrete and continuous dynamics and can be used to model complex cyber-physical systems. Plaidypvs is a tool that enables formalization of hybrid programs in the PVS theorem prover. Plaidypvs enables the verification of the general simplex RTA framework and then, by specializing some components of the hybrid program, verifying instances of the framework while treating the untrusted component as a black box. A selection of Unmanned Aircraft Systems (UAS) operations are shown as instances of the general RTA framework in PVS. This offers the benefit of design time verification of relevant safety properties to the system, and it also gives requirements on the sample rate of sensors that determine the time interval in which the ‘switch’ property of the RTA framework is checked.

PVS↗

International Space Station Requirement Verification for Commercial Visiting Vehicles

The COTS program demonstrated NASA could rely on commercial providers for safe, reliable, and cost-effective cargo delivery to ISS. The ISS Program has developed a streamlined process to safely integrate commercial visiting vehicles and ensure requirements are met Levy a minimum requirement set (down from 1000s to 100s) focusing on the ISS interface and safety, reducing the level of NASA oversight/insight and burden on the commercial Partner. Partners provide a detailed verification and validation plan documenting how they will show they've met NASA requirements. NASA conducts process sampling to ensure that the established verification processes is being followed. NASA participates in joint verification events and analysis for requirements that require both parties verify. Verification compliance is approved by NASA and launch readiness certified at mission readiness reviews.

Garguilo, Dan↗