Search NASA⌕ Search

SEARCH · Search NASA

Results for “proof”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

An Empirical Evaluation of Automated Theorem Provers in Software Certification

We describe a system for the automated certification of safety properties of NASA software. The system uses Hoare-style program verification technology to generate proof obligations which are then processed by an automated first-order theorem prover (ATP). We discuss the unique requirements this application places on the ATPs, focusing on automation, proof checking, and usability. For full automation, however, the obligations must be aggressively preprocessed and simplified, and we demonstrate how the individual simplification stages, which are implemented by rewriting, influence the ability of the ATPs to solve the proof tasks. Our results are based on 13 certification experiments that lead to more than 25,000 proof tasks which have each been attempted by Vampire, Spass, e-setheo, and Otter. The proofs found by Otter have been proof-checked by IVY.

Denney, Ewen↗

Dynamic Stability and Gravitational Balancing of Multiple Extended Bodies

Feasibility of a non-invasive compensation scheme was analyzed for precise positioning of a massive extended body in free fall using gravitational forces influenced by surrounding source masses in close proximity. The N-body problem of classical mechanics is a paradigm used to gain insight into the physics of the equivalent N-body problem subject to control forces. The analysis addressed how a number of control masses move around the proof mass so that the proof mass position can be accurately and remotely compensated when exogenous disturbances are acting on it, while its sensitivity to gravitational waves remains unaffected. Past methods to correct the dynamics of the proof mass have considered active electrostatic or capacitive methods, but the possibility of stray capacitances on the surfaces of the proof mass have prompted the investigation of other alternatives, such as the method presented in this paper. While more rigorous analyses of the problem should be carried out, the data show that, by means of a combined feedback and feed-forward control approach, the control masses succeeded in driving the proof mass along the specified trajectory, which implies that the proof mass can, in principle, be balanced via gravitational forces only while external perturbations are acting on it. This concept involves the dynamic stability of a group of massive objects interacting gravitationally under active control, and can apply to drag-free control of spacecraft during missions, to successor gravitational wave space borne sensors, or to any application requiring flying objects to be precisely controlled in position and attitude relative to another body via gravitational interactions only.

Quadrelli, Marco↗

Applying Formal Methods to Safety-Critical Systems

How do you know a proof is correct? Traditionally, mathematical proofs are socially verified – at least one human, following a set of implicit rules of natural language and logic, determines if the proof is believable. If the proof becomes overly tedious and/or is essential to some safety- or mission-critical application, it becomes necessary to determine the soundness to a higher standard. 'Formal methods' refer to mathematically rigorous techniques and tools that enable specification, design, and verification of hardware and software systems. The specification used in formal methods are statements in a mathematical logic while the formal verifications are deductions in that logic. Formal methods can be difficult or time/resource intensive, but offer a higher level of assurance than standard verification through testing or handwritten proofs. This talk will introduce formal methods, motivated by applications of interest to NASA, including uncrewed aircraft operations in the national airspace, urban air environments, and wildfire areas. The audience will be given a crash course in mechanically verified proofs in the Prototype Verification System (PVS), an interactive theorem prover.

Formal Methods↗

Trapping - A control phenomenon of spinning drag-free satellites.

A drag-free satellite contains a proof mass in an internal cavity and is controlled in translation so that it never touches the proof mass. The satellite shields the proof mass from external forces thus allowing the proof mass to follow a drag-free orbit. Spinning the satellite is desirable because it attenuates the effect of proof mass disturbing forces and simplifies the attitude control. The design of a translation controller for a spinning drag-free satellite typically includes a deadspace to eliminate chatter. This design feature and the inability to locate precisely the mass center give rise to a phenomenon called trapping that potentially could waste significant amounts of propellant. A theory is developed and experimentally verified that explains the role of these factors and provides insight into the effect of other control parameters.

Powell, J. D.↗

Exospheric density measurements from the drag-free satellite Triad

The Triad satellite is maintained within 1 mm of its proof mass (a small metal ball) in a purely gravitational orbit, using a drag-free control system, named Discos, as the disturbance compensation system. The Discos proof mass is surrounded by an outer shell which holds fuel tanks and cold gas jets. The shell shields the proof mass from such nongravitational forces as radiation pressure, atmospheric drag, and micrometeorite impact. Whenever these forces displace the outer shell relative to the proof mass, an error signal is generated by a capacitive bridge sensor, and the satellite is propelled by gas jets to remain centered on the proof mass when the error reaches 1 mm. Local atmospheric densities near 800 km were measured, using ball position data, and the observed accelerations were corrected for the effects of solar radiation pressure. The measured densities reveal a greater dependence on latitude than that indicated by balloon satellites, and also a dependence on longitude. Only a small dependence on Kp, however, was observed in the region where the measurements were made.

Moe, K.↗

An extension to Schneider's general paradigm for fault-tolerant clock synchronization

In 1987, Schneider presented a general paradigm that provides a single proof of a number of fault tolerant clock synchronization algorithms. His proof was subsequently subjected to the rigor of mechanical verification by Shankar. However, both Schneider and Shankar assumed a condition Shankar refers to as a bounded delay. This condition states that the elapsed time between synchronization events (i.e., the time that the local process applies an adjustment to its logical clock) is bounded. This property is really a result of the algorithm and should not be assumed in a proof of correctness. This paper remedies this by providing a proof of this property in the context of the general paradigm proposed by Schneider. The argument given is a generalization of Welch and Lynch's proof of a related property for their algorithm.

Miner, Paul S.↗

AutoBayes/CC: Combining Program Synthesis with Automatic Code Certification: System Description

Code certification is a lightweight approach to formally demonstrate software quality. It concentrates on aspects of software quality that can be defined and formalized via properties, e.g., operator safety or memory safety. Its basic idea is to require code producers to provide formal proofs that their code satisfies these quality properties. The proofs serve as certificates which can be checked independently, by the code consumer or by certification authorities, e.g., the FAA. It is the idea underlying such approaches as proof-carrying code [6]. Code certification can be viewed as a more practical version of traditional Hoare-style program verification. The properties to be verified are fairly simple and regular so that it is often possible to use an automated theorem prover to automatically discharge all emerging proof obligations. Usually, however, the programmer must still splice auxiliary annotations (e.g., loop invariants) into the program to facilitate the proofs. For complex properties or larger programs this quickly becomes the limiting factor for the applicability of current certification approaches.

Whalen, Michael↗

Addendum to the User Manual for NASGRO Elastic-Plastic Fracture Mechanics Software Module

The elastic-plastic fracture mechanics modules in NASGRO have been enhanced by the addition of of the following: new J-integral solutions based on the reference stress method and finite element solutions; the extension of the critical crack and critical load modules for cracks with two degrees of freedom that tear and failure by ductile instability; the addition of a proof test analysis module that includes safe life analysis, calculates proof loads, and determines the flaw screening 1 capability for a given proof load; the addition of a tear-fatigue module for ductile materials that simultaneously tear and extend by fatigue; and a multiple cycle proof test module for estimating service reliability following a proof test.

Gregg, M. Wayne↗

A Study on the Effects of J2 Perturbations on a Drag-Free Control System for Spacecraft in Low Earth Orbit

Low Earth Orbit (LEO) missions provide a unique means of gathering information about many of Earth s aspects such as climate, atmosphere, and gravitational field. Among the greatest challenges of LEO missions are designing, predicting, and maintaining the spacecraft orbit. The predominant perturbative forces acting on a spacecraft in LEO are J2 and higher order gravitational components, the effects of which are fairly easy to predict, and atmospheric drag, which causes the greatest uncertainty in predicting spacecraft ephemeris. The continuously varying atmospheric drag requires increased spacecraft tracking in order to accurately predict spacecraft location. In addition, periodic propulsive maneuvers typically must be planned and performed to counteract the effects of drag on the spacecraft orbit. If the effects of drag could be continuously and autonomously counteracted, the uncertainty in ephemeris due to atmospheric drag would essentially be eliminated from the spacecraft dynamics. One method of autonomous drag compensation that has been implemented on some missions is drag-free control. Drag-free control of a spacecraft was initially proposed in the 1960's and is discussed extensively by Lange. His drag-free control architecture consists of a free-floating proof mass enclosed within a spacecraft, isolating it from external disturbance forces such as atmospheric drag and solar radiation pressure. Under ideal conditions, internal disturbance forces can be ignored or mitigated, and the orbit of the proof mass depends only on gravitational forces. A sensor associated with the proof mass senses the movement of the spacecraft relative to the proof mass. Using the sensor measurements, the spacecraft is forced to follow the orbit of the proof mass by using low thrust propulsion, thus counteracting any non-gravitational disturbance forces. If the non-gravitational disturbance forces are successfully removed, the spacecraft s orbit will be affected only by well-known gravitational forces and will thus be easier to predict.

Vess, Melissa Fleck↗

A Generic Software Safety Document Generator

Formal certification is based on the idea that a mathematical proof of some property of a piece of software can be regarded as a certificate of correctness which, in principle, can be subjected to external scrutiny. In practice, however, proofs themselves are unlikely to be of much interest to engineers. Nevertheless, it is possible to use the information obtained from a mathematical analysis of software to produce a detailed textual justification of correctness. In this paper, we describe an approach to generating textual explanations from automatically generated proofs of program safety, where the proofs are of compliance with an explicit safety policy that can be varied. Key to this is tracing proof obligations back to the program, and we describe a tool which implements this to certify code auto-generated by AutoBayes and AutoFilter, program synthesis systems under development at the NASA Ames Research Center. Our approach is a step towards combining formal certification with traditional certification methods.

Denney, Ewen↗

Privacy-Preserving Control of Partitioned Energy Resources

Distributed energy resources are an increasingly important part of the electric grid. We examine the problem of partitioning a distributed energy resource among many users while providing privacy to them. In this model, clients can send requests to a server, the server can verify that the requests are valid and aggregate them, but it cannot see the actual values in the requests. Without privacy, each user is forced to reveal their daily schedule or energy use. Energy resources add a novel challenge that prior systems do not address: they require verifying limits on private power (a rate over time) and energy (a sum) values. Furthermore, the cryptographic mechanisms must run on embedded energy control systems. We describe Weft, a novel cryptographic system that verifies both power (rate) and energy (integral) constraints on private client values and aggregates them. The key insight behind the approach is to rely on additively homomorphic secret shares, which allows servers to compute sums from rates. We present 3 cryptographic proof systems with different system trade-off for embedded systems: bit-splitting proofs minimize memory use, sorting proofs minimize computation, and commitment proofs minimize network communication. Using bit-splitting proofs, it takes an IoT client using a CortexM microcontroller 4 minutes of compute time to privately control its share of an energy resource for a day at 20s granularity.

Laufer, Evan↗

Deep flaws in weldments of aluminum and titanium

Surface flawed specimens of 2219-T87 and 6Al-4V STA titanium weldments were tested to determine static failure modes, failure strength, and fatigue flaw growth characteristics. Thicknesses selected for this study were purposely set at values where, for most test conditions, abrupt instability of the flaw at fracture would not be expected. Static tests for the aluminum weldments were performed at room, LN2 and LH2 temperatures. Titanium static tests for tests were performed at room and LH2 temperatures. Results of the static tests were used to plot curves relating initial flaw size to leakage- or failure-stresses (i.e. "failure" locus curves). Cyclic tests, for both materials, were then performed at room temperature, using initial flaws only slightly below the previously established failure locus for typical proof stress levels. Cyclic testing was performed on pairs of specimens, one with and one without a simulated proof test cycle. Comparisons were made then to determine the value and effect of proof testing as affected by the various variables of proof and operating stress, flaw shape, material thickness, and alloy.

Masters, J. N.↗

Acoustic emission testing of 12-nickel maraging steel pressure vessels

Acoustic emission data were obtained from three point bend fracture toughness specimens of 12-nickel maraging steel, and two pressure vessels of the same material. One of the pressure vessels contained a prefabricated flaw which was extended and sharpened by fatigue cycling. It is shown that the flawed vessel had similar characteristics to the fracture specimens, thereby allowing estimates to be made of its nearness to failure during a proof test. Both the flawed and unflawed pressure vessel survived the proof pressure and 5 cycles to the working pressure, but it was apparent from the acoustic emission response during the proof cycle and the 5 cycles to the working pressure that the flawed vessel was very near failure. The flawed vessel did not survive a second cycle to the proof pressure before failure due to flaw extension through the wall (causing a leak).

Dunegan, H. L.↗

Coupled orbiting inertial reference systems and Geopotential Research Mission (GRM) geodesy

Two spacecraft, one following the other with a separation of a few hundred kilometers and orbiting at an altitude of 160 km in a 90-degree polar orbit, are used to detect the minute variations in the earth's gravitational field. Housed in a capacitive cavity located at the centroid of the spacecraft is a free-floating metallic spherical proof-mass, which is the sensor controlling the thrusters that nullify all nongravitational forces on the spacecraft. The proof-mass in each spacecraft is the inertial-guidance reference for its host spacecraft, and the proof-masses are coupled together by a millimeter-wave link. This coupled system detects minute changes in the spacecraft's orbital positions and thus measures the anomalies present in the gravitational field of the earth. To derive a global geodetic model of the gravitational field with an amplitude resolution of 1 milligal and a spatial resolution of 100 km requires that the relative velocity between the proof-mass references be determined to within 1 micron/s.

Keating, T.↗

A validation methodology for fault-tolerant clock synchronization

A validation method for the synchronization subsystem of a fault-tolerant computer system is presented. The high reliability requirement of flight crucial systems precludes the use of most traditional validation methods. The method presented utilizes formal design proof to uncover design and coding errors and experimentation to validate the assumptions of the design proof. The experimental method is described and illustrated by validating an experimental implementation of the Software Implemented Fault Tolerance (SIFT) clock synchronization algorithm. The design proof of the algorithm defines the maximum skew between any two nonfaulty clocks in the system in terms of theoretical upper bounds on certain system parameters. The quantile to which each parameter must be estimated is determined by a combinatorial analysis of the system reliability. The parameters are measured by direct and indirect means, and upper bounds are estimated. A nonparametric method based on an asymptotic property of the tail of a distribution is used to estimate the upper bound of a critical system parameter. Although the proof process is very costly, it is extremely valuable when validating the crucial synchronization subsystem.

Johnson, S. C.↗

Design verification of SIFT

A SIFT reliable aircraft control computer system, designed to meet the ultrahigh reliability required for safety critical flight control applications by use of processor replications and voting, was constructed for SRI, and delivered to NASA Langley for evaluation in the AIRLAB. To increase confidence in the reliability projections for SIFT, produced by a Markov reliability model, SRI constructed a formal specification, defining the meaning of reliability in the context of flight control. A further series of specifications defined, in increasing detail, the design of SIFT down to pre- and post-conditions on Pascal code procedures. Mechanically checked mathematical proofs were constructed to demonstrate that the more detailed design specifications for SIFT do indeed imply the formal reliability requirement. An additional specification defined some of the assumptions made about SIFT by the Markov model, and further proofs were constructed to show that these assumptions, as expressed by that specification, did indeed follow from the more detailed design specifications for SIFT. This report provides an outline of the methodology used for this hierarchical specification and proof, and describes the various specifications and proofs performed.

Moser, Louise↗

Drag-free satellite control

A drag-free satellite cancels the effect of external disturbances. Although the forces may be small, a satellite is disturbed by residual air drag, radiation pressure, micrometeorite impact, and other small forces that act on its surface disturbing its orbit, which is principally determined by the gravity field. In some missions, these small perturbations that make the satellite deviate from its purely gravitational orbit are limiting. An internal unsupported proof mass is shielded by the satellite from the external disturbances. The position of the shield (or the main part of the satellite) is measured with respect to the internal proof mass, and this information is used to actuate a propulsion system which moves the satellite to follow the proof mass. A drag-free control system is illustrated. Since the proof mass is shielded it follows a purely gravitational orbit - as does the satellite following it - hence the name drag-free satellite. The idea was conceived by Lange (1964) and has been applied to many mission studies since. In some cases, it is not necessary to cancel the disturbances, only to measure them so they may be taken into account. In such cases, an accelerometer may be a more suitable solution (for example, using the ONERA Cactus or the Bell Aerosystems MESA).

Debra, Daniel B.↗

Development of methodology for qualifying safety critical A286 threaded fasteners

A test program was initiated at the Jet Propulsion Laboratory to experimentally determine the cyclic fatigue life of pre-cracked A286 stainless steel fasteners which just survived a proof test to a prescribed fraction of their ultimate tensile strength. The functional dependency of the cyclic fatigue life of a fastener on the fatigue stress (mean and alternating stresses), fastener size, material tensile strength, and proof load was formulated using the NASA/FLAGRO computer program. It was found that proof load has the strongest effect on fatigue life, while the mean stress has the least effect. The fastener size only has a minor effect, but the alternating stress range has a strong influence on the fatigue life of fasteners. Limited experimental verification of the hypothesized functional relationship is provided in this program for the effect of proof load and fastener size in addition to the analytic verification.

Hsieh, Cheng↗