Search NASA⌕ Search

SEARCH · Search NASA

Results for “Design verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

Crewed Space Vehicle Battery Safety Requirements

This requirements document is applicable to all batteries on crewed spacecraft, including vehicle, payload, and crew equipment batteries. It defines the specific provisions required to design a battery that is safe for ground personnel and crew members to handle and/or operate during all applicable phases of crewed missions, safe for use in the enclosed environment of a crewed space vehicle, and safe for use in launch vehicles, as well as in unpressurized spaces adjacent to the habitable portion of a space vehicle. The required provisions encompass hazard controls, design evaluation, and verification. The extent of the hazard controls and verification required depends on the applicability and credibility of the hazard to the specific battery design and applicable missions under review. Evaluation of the design and verification program results shall be completed prior to certification for flight and ground operations. This requirements document is geared toward the designers of battery systems to be used in crewed vehicles, crew equipment, crew suits, or batteries to be used in crewed vehicle systems and payloads (or experiments). This requirements document also applies to ground handling and testing of flight batteries. Specific design and verification requirements for a battery are dependent upon the battery chemistry, capacity, complexity, charging, environment, and application. The variety of battery chemistries available, combined with the variety of battery-powered applications, results in each battery application having specific, unique requirements pertinent to the specific battery application. However, there are basic requirements for all battery designs and applications, which are listed in section 4. Section 5 includes a description of hazards and controls and also includes requirements.

Jeevarajan, Judith A.↗

Range 7 Scanner Integration with PaR Robot Scanning System

An interface bracket and coordinate transformation matrices were designed to allow the Range 7 scanner to be mounted on the PaR Robot detector arm for scanning the heat shield or other object placed in the test cell. A process was designed for using Rapid Form XOR to stitch data from multiple scans together to provide an accurate 3D model of the object scanned. An accurate model was required for the design and verification of an existing heat shield. The large physical size and complex shape of the heat shield does not allow for direct measurement of certain features in relation to other features. Any imaging devices capable of imaging the entire heat shield in its entirety suffers a reduced resolution and cannot image sections that are blocked from view. Prior methods involved tools such as commercial measurement arms, taking images with cameras, then performing manual measurements. These prior methods were tedious and could not provide a 3D model of the object being scanned, and were typically limited to a few tens of measurement points at prominent locations. Integration of the scanner with the robot allows for large complex objects to be scanned at high resolution, and for 3D Computer Aided Design (CAD) models to be generated for verification of items to the original design, and to generate models of previously undocumented items. The main components are the mounting bracket for the scanner to the robot and the coordinate transformation matrices used for stitching the scanner data into a 3D model. The steps involve mounting the interface bracket to the robot's detector arm, mounting the scanner to the bracket, and then scanning sections of the object and recording the location of the tool tip (in this case the center of the scanner's focal point). A novel feature is the ability to stitch images together by coordinates instead of requiring each scan data set to have overlapping identifiable features. This setup allows models of complex objects to be developed even if the object is large and featureless, or has sections that don't have visibility to other parts of the object for use as a reference. In addition, millions of points can be used for creation of an accurate model [i.e. within 0.03 in. (=0.8 mm) over a span of 250 in. (=635 mm)].

Schuler, Jason↗

Automated biowaste sampling system urine subsystem operating model, part 1

The urine subsystem automatically provides for the collection, volume sensing, and sampling of urine from six subjects during space flight. Verification of the subsystem design was a primary objective of the current effort which was accomplished thru the detail design, fabrication, and verification testing of an operating model of the subsystem.

Fogal, G. L.↗

High heat transfer oxidizer heat exchanger design and analysis

The RL10-2B engine, a derivative of the RL10, is capable of multimode thrust operation. This engine operates at two low thrust levels: tank head idle (THI), which is approximately 1 to 2% of full thrust, and pumped idle (PI), which is 10% of full thrust. Operation at THI provides vehicle propellant settling thrust and efficient engine thermal conditioning; PI operation provides vehicle tank pre-pressurization and maneuver thrust for low-g deployment. Stable combustion of the RL10-2B engine during the low thrust operating modes can be accomplished by using a heat exchanger to supply gaseous oxygen to the propellant injector. The oxidizer heat exchanger (OHE) vaporizes the liquid oxygen using hydrogen as the energy source. The design, concept verification testing and analysis for such a heat exchanger is discussed. The design presented uses a high efficiency compact core to vaporize the oxygen, and in the self-contained unit, attenuates any pressure and flow oscillations which result from unstable boiling in the core. This approach is referred to as the high heat transfer design. An alternative approach which prevents unstable boiling of the oxygen by limiting the heat transfer is referred to as the low heat transfer design and is reported in Pratt & Whitney report FR-19135-2.

Kmiec, Thomas D.↗

Test bed design for evaluating the Space Station ECLSS Water Recovery System

The design of the Phase III Environmental Control and Life Support System (ECLSS) Water Recovery System (WRS) test bed is in progress at the Marshall Space Flight Center (MSFC), building 4755, in Huntsville, Alabama. The overall design for the ECLSS WRS test bed will be discussed. Described within this paper are the design, fabrication, placement, and testing of the supporting facility which will provide the test bed for the ECLSS subsystems. Topics to be included are sterilization system design, component selection, microbial design considerations, and verification of test bed design prior to initiating WRS testing.

Ezell, Timothy G.↗

Program Model Checking as a New Trend

This paper introduces a special section of STTT (International Journal on Software Tools for Technology Transfer) containing a selection of papers that were presented at the 7th International SPIN workshop, Stanford, August 30 - September 1, 2000. The workshop was named SPIN Model Checking and Software Verification, with an emphasis on model checking of programs. The paper outlines the motivation for stressing software verification, rather than only design and model verification, by presenting the work done in the Automated Software Engineering group at NASA Ames Research Center within the last 5 years. This includes work in software model checking, testing like technologies and static analysis.

Havelund, Klaus↗

Robotics System Process and Concept for On-orbit Assembly for Potential Mars Sample Return

Proposed Mars Sample Return (MSR) missions would require on-orbit assembly of containment vessels to meet backward Planetary Protection requirements and transfer of the sample container through various stations and positions. Some operations would have to be performed autonomously, and others would require ground-in-loop decision-making stages and verification processes. One concept design for an Earth Return Orbiter (ERO) Capture, Contain, and Return System (CCRS) Transfer Mechanism (TM) is a multi-Degree of Freedom (DOF) manipulator that utilizes a passive End Effector (EE) to assist in containment vessel assembly. To converge on a feasible design, a robotic system process has been instantiated. This process is composed of three main phases: robotic problem definition (operating environment, operations/functions, system goals), robotic solution selection (trade studies on the number of degrees of freedom, number of mechanisms, types of mechanisms), robotic solution design, implementation, and verification and validation (kinematic configuration, robotic and kinematic analysis and topology optimization of components). As a final product of this process, a half-scale functional prototype of the TM was developed to demonstrate the end-to-end operation capability.

Strahle, Jackson W↗

Terminal Descent Radar System Testbed for Future Planetary Landers

Terminal Descent Radars (TDR), or landing radars, have been an integral element of Guidance, Navigation and Control (GN\&C) sensor suites of robotic exploration missions to the Moon and Mars. As plans for new, exciting exploration missions to the Moon, Mars and other planetary bodies are being developed, there is a need for a new generation of TDRs that are smaller, consume less power and are less expensive than previous sensors. The challenge of designing such a landing sensor is twofold: the first is to have well-vetted software tools that allow us to explore the design space for a particular mission scenario and analyze performance of relevant radar architectures. The second challenge is to reduce mass and power requirements of a landing radar without compromising reliability and performance. New design approaches that address these challenges need to be tested and demonstrated in realistic Entry-Descent-Landing (EDL)/Deorbit-Descent-Landing (DDL) scenarios. In this paper, we describe a TDR testbed developed at the Jet Propulsion Laboratory. The testbed is a closed-loop design, analysis and verification capability used to design and evaluate the next generation of landing radars for a variety of EDL/DDL scenarios.

Tope, Michael↗

Terminal Descent Radar System Testbed for Future Planetary Landers

Terminal Descent Radars (TDR), or landing radars, have been an integral element of Guidance, Navigation and Control (GN\&C) sensor suites of robotic exploration missions to the Moon and Mars. As plans for new, exciting exploration missions to the Moon, Mars and other planetary bodies are being developed, there is a need for a new generation of TDRs that are smaller, consume less power and are less expensive than previous sensors. The challenge of designing such a landing sensor is twofold: the first is to have well-vetted software tools that allow us to explore the design space for a particular mission scenario and analyze performance of relevant radar architectures. The second challenge is to reduce mass and power requirements of a landing radar without compromising reliability and performance. New design approaches that address these challenges need to be tested and demonstrated in realistic Entry-Descent-Landing (EDL)/Deorbit-Descent-Landing (DDL) scenarios. In this paper, we describe a TDR testbed developed at the Jet Propulsion Laboratory. The testbed is a closed-loop design, analysis and verification capability used to design and evaluate the next generation of landing radars for a variety of EDL/DDL scenarios.

Tope, Michael↗

Even Higher-Level Synthesis: An Exploration of AI Hardware Accelerators using HLS4ML

With the rise of artificial intelligence, the popularization of deep learning, and a constantly evolving industry, the demand for flexible and efficient tools has never been greater. As algorithms grow more complex, their runtime and energy consumption increase exponentially. Customized hardware accelerators, long used for specific mathematical operations, remain essential for managing modern applications' computational and power demands. Hardware accelerators can speed up complex computations by orders of magnitude, but their manual design and verification processes are often challenging and time-consuming. High-Level Synthesis (HLS) provides a solution by transforming high-level algorithm descriptions, typically written in C++ or SystemC, into synthesizable RTL suitable for hardware implementation. This approach reduces development time for RTL engineers while offering flexibility beyond what traditional handwritten RTL can provide. We extended this capability to the machine-learning domain with the open-source framework hls4ml, which allows neural networks trained in Python frameworks like Tensorflow or PyTorch to be synthesized into efficient hardware representations for the traditional FPGA and ASIC flows. This breakthrough addresses the growing need for reduced design turnaround and easy verification of ML hardware accelerators with low latency and power efficiency constraints. During this tutorial, we will demonstrate how Python complements HLS by simplifying the ML design process, bridging the gap between software and hardware development. Attendees will explore how we translate neural networks modeled in Python into fixed-point C++ models suitable for HLS workflows. We will dive into strategies like Value-Range Analysis and Quantization-Aware Training, which optimize these designs for deployment and evaluate their accuracy, power consumption, and energy efficiency. To exemplify these concepts, experts from Fermilab will share their experiences applying this technology to high-energy physics experiments, where real-time, low-latency processing is critical. Over the years, Fermilab engineers have demonstrated how deep neural networks, optimized for hardware using hls4ml, can meet the stringent requirements of trigger systems at the CERN Large Hadron Collider. These systems rely on rapid decision-making to process immense data volumes while retaining only the most relevant events for further analysis. The application of hls4ml has also been extended to innovative technologies like smart pixel arrays. These smart pixels integrate ML inference capabilities directly into sensor devices, enabling localized data processing at the pixel level. This approach drastically reduces the need to transmit raw data to external processing units, significantly decreasing power consumption and latency. By embedding neural networks within the pixel architecture, the smart pixels can identify and prioritize relevant data in real time, providing a highly efficient solution for edge computing in scenarios such as particle detectors and imaging systems. Fermilab's work highlights the potential of hardware-accelerated ML in scenarios where both speed and power efficiency are mission-critical. Through this tutorial, attendees will gain valuable insights into the challenges and solutions of deploying ML in hardware. Understanding how HLS and hls4ml streamline the development of neural network-based hardware accelerators is fundamental for the industry's future. Participants will learn how these technologies are shaping the future of AI and scientific computing.

Di Guglielmo, Giuseppe [Fermilab]↗

HDL to verification logic translator

The increasingly higher number of transistors possible in VLSI circuits compounds the difficulty in insuring correct designs. As the number of possible test cases required to exhaustively simulate a circuit design explodes, a better method is required to confirm the absence of design faults. Formal verification methods provide a way to prove, using logic, that a circuit structure correctly implements its specification. Before verification is accepted by VLSI design engineers, the stand alone verification tools that are in use in the research community must be integrated with the CAD tools used by the designers. One problem facing the acceptance of formal verification into circuit design methodology is that the structural circuit descriptions used by the designers are not appropriate for verification work and those required for verification lack some of the features needed for design. We offer a solution to this dilemma: an automatic translation from the designers' HDL models into definitions for the higher-ordered logic (HOL) verification system. The translated definitions become the low level basis of circuit verification which in turn increases the designer's confidence in the correctness of higher level behavioral models.

Gambles, J. W.↗

Propel: Tools and Methods for Practical Source Code Model Checking

The work reported here is an overview and snapshot of a project to develop practical model checking tools for in-the-loop verification of NASA s mission-critical, multithreaded programs in Java and C++. Our strategy is to develop and evaluate both a design concept that enables the application of model checking technology to C++ and Java, and a model checking toolset for C++ and Java. The design concept and the associated model checking toolset is called Propel. It builds upon the Java PathFinder (JPF) tool, an explicit state model checker for Java applications developed by the Automated Software Engineering group at NASA Ames Research Center. The design concept that we are developing is Design for Verification (D4V). This is an adaption of existing best design practices that has the desired side-effect of enhancing verifiability by improving modularity and decreasing accidental complexity. D4V, we believe, enhances the applicability of a variety of V&V approaches; we are developing the concept in the context of model checking. The model checking toolset, Propel, is based on extending JPF to handle C++. Our principal tasks in developing the toolset are to build a translator from C++ to Java, productize JPF, and evaluate the toolset in the context of D4V. Through all these tasks we are testing Propel capabilities on customer applications.

Mansouri-Samani, Massoud↗

Study of techniques for redundancy verification without disrupting systems, phases 1-3

The problem of verifying the operational integrity of redundant equipment and the impact of a requirement for verification on such equipment are considered. Redundant circuits are examined and the characteristics which determine adaptability to verification are identified. Mutually exclusive and exhaustive categories for verification approaches are established. The range of applicability of these techniques is defined in terms of signal characteristics and redundancy features. Verification approaches are discussed and a methodology for the design of redundancy verification is developed. A case study is presented which involves the design of a verification system for a hypothetical communications system. Design criteria for redundant equipment are presented. Recommendations for the development of technological areas pertinent to the goal of increased verification capabilities are given.

Source record↗

Coupled dynamics analysis of wind energy systems

A qualitative description of all key elements of a complete wind energy system computer analysis code is presented. The analysis system addresses the coupled dynamics characteristics of wind energy systems, including the interactions of the rotor, tower, nacelle, power train, control system, and electrical network. The coupled dynamics are analyzed in both the frequency and time domain to provide the basic motions and loads data required for design, performance verification and operations analysis activities. Elements of the coupled analysis code were used to design and analyze candidate rotor articulation concepts. Fundamental results and conclusions derived from these studies are presented.

Hoffman, J. A.↗

Design of lightning protection for a full-authority digital engine control

The steps and procedures are described which are necessary to achieve a successful lightning-protection design for a state-of-the-art Full-Authority Digital Engine Control (FADEC) system. The engine and control systems used as examples are fictional, but the design and verification methods are real. Topics discussed include: applicable airworthiness regulation, selection of equipment transient design and control levels for the engine/airframe and intra-engine segments of the system, the use of cable shields, terminal-protection devices and filter circuits in hardware protection design, and software approaches to minimize upset potential. Shield terminations, grounding, and bonding are also discussed, as are the important elements of certification and test plans, and the role of tests and analyses. Also included are examples of multiple-stroke and multiple-burst testing. A review of design pitfalls and challenges, and status of applicable test standards such as RTCA DO-160, Section 22, are presented.

Dargi, M.↗

RD53 pixel readout integrated circuits for ATLAS and CMS HL-LHC upgrades

The RD53 collaboration has since 2013 developed new hybrid pixel detector chips with 50 × 50 μm2 pixels for the HL-LHC upgrades of the ATLAS and CMS experiments at CERN. A common architecture, design and verification framework has been developed to enable final pixel chips of different sizes to be designed, verified and tested to handle extreme hit rates of 3 GHz/cm2 (up to 12 GHz per chip) together with an increased trigger rate of 1 MHz and efficient readout of up to 5.12 Gbits/s per pixel chip. Tolerance to an extremely hostile radiation environment with 1 Grad over 10 years and induced SEU (Single Event Upset) rates of up to 100 upsets per second per chip have been major challenges to make reliable pixel chips. Three generations of pixel chips, and many specific mixed signal building blocks and radiation test chips, have been submitted and extensively tested to get to final production chips. The large, complex and high rate pixel chips have been developed with a strong emphasis on low power consumption together with a concurrent development and qualification of novel serial powering at chip, module and system level, to minimize detector material budget.

Alimonti, G↗

Apollo experience report: Spacecraft structural windows

The window structural design and verification experience is presented for the Apollo command and lunar modules. This report presents window design philosophy, design criteria, hardware description, and qualification and acceptance test programs and discusses the problems encountered and solutions developed in these areas. The structural characteristics of glass are not generally well understood by designers. The optics and instrument glass covers were not considered to be structural components and thus were not normally subjected to the design, qualification, and acceptance standards necessary to preclude failures. These two factors contributed significantly to window problems on both Apollo spacecraft.

Pigg, O. E.↗

System Engineering on the Use for Ares I,V - the Simpler, the Better

The Ares I and Ares V Vehicles will utilize the J-2X rocket engine developed for NASA by the Pratt & Whitney Rocketdyne Company. The J-2X is an improved higher power version of the original J-2 engine used during the Apollo program. With higher power and updated requirements for safety and performance, the J-2X becomes a new engine using state-of-the-art design methodology, materials and manufacturing processes. The implementation of Systems Engineering (SE) principles enables the rapid J-2X development program to remain aligned with the ARES I and V vehicle programs, Meeting the aggressive development schedule is a challenge. Coordinating the best expertise thai NASA and PWR have to offer requires effectively utilizing resources at multiple sites. This presents formidable communication challenges. SE allows honest and open discussions of issues and problems. This simple idea is often overlooked in large and complex SE programs. Regular and effective meetings linking SE objectives to component designs are used to voice differences of opinions with customer and contractor in attendance so that the best mutual decisions can be made on the shortest possible schedule. Regular technical interchange meetings on secure program wide computer networks and CM processes are effective,in the "Controlled Change" process that exemplifies good SE. Good communication is a key effective SE implementation. The System of Systems approach is the vision of the Orion program which facilitates the establishment of dynamic SE processes at all levels including the engine. SE enables requirements evolution by facilitating organizational and process agility. Flow down and distribution of requirements is controlled by Allocation Reports which breakdown numerical design objectives (weight, reliability, etc.) into quanta goals for each component area. Linked databases of design and verification requirements helps eliminate redundancy and potential mistakes inherent m separated systems. Another tool, the Architecture Design Description, is being used to control J-2X system architecture and effectively communicate configuration changes to those involved in the design process. But the proof is in successful program accomplishment. The SE is the methodology being used to meet the challenge of completing J-2X engine certification 2 years ahead of any engine program ever developed at PWR. The Ares I SE system of systems has delivered according to expectations thus far. All major design reviews (SRR. PDR, CDR) have been successfully conducted to satisfy overall program objectives using SE as the basis for accomplishment. The paper describes SE tools and techniques utilized to achieve this success.

Kelly, William↗