Search NASA⌕ Search

SEARCH · Search NASA

Results for “proof”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 343 records · Page 19

A Microseismometer for Terrestrial and Extraterrestrial Applications

The scientific and technical requirements of extraterrestrial seismology place severe demands on instrumentation. Performance in terms of sensitivity, stability, and frequency band must match that of the best terrestrial instruments, at a fraction of the size, mass, and power. In addition, this performance must be realized without operator intervention in harsh temperature, shock, and radiation environments. These constraints have forced us to examine some fundamental limits of accelerometer design in order to produce a small, rugged, sensitive seismometer. Silicon micromachined sensor technology offers techniques for the fabrication of monolithic, robust, compact, low-power and -mass accelerometers. However, currently available sensors offer inadequate sensitivity and bandwidth. Our implementation of an advanced silicon micro machined seismometer is based on principles developed at JPL for high-sensitivity position sensor technology. The use of silicon micro machining technology with these new principles should enable the fabrication of a 10(exp -11) g sensitivity seismometer with a bandwidth of at least 0.01 to 20 Hz. The low Q properties of pure single-crystal silicon are essential in order to minimize the Brownian thermal noise limitations generally characteristic of seismometers with small proof masses. A seismometer consists of a spring-supported proof mass and a transducer for measuring its motion. For long period motion a position sensor is generally used, for which the displacement is proportional to the ground acceleration. The mechanical sensitivity can be increased either by increasing the proof mass or decreasing the spring stiffness, neither of which is desirable for planetary applications. Our approach has been to use an ultra sensitive capacitive position sensor with a sensitivity of better than 10(exp -13) m/Hz(exp 1/2). This allows the use of a stiffer suspension and a smaller proof mass. We have built several prototypes using these principles, and tests show that these devices can exhibit performance comparable to state-of-the-art instruments.

Banerdt, W.↗

Lunar exploration rover program developments

The Robotic All Terrain Lunar Exploration Rover (RATLER) design concept began at Sandia National Laboratories in late 1991 with a series of small, proof-of-principle, working scale models. The models proved the viability of the concept for high mobility through mechanical simplicity, and eventually received internal funding at Sandia National Laboratories for full scale, proof-of-concept prototype development. Whereas the proof-of-principle models demonstrated the mechanical design's capabilities for mobility, the full scale proof-of-concept design currently under development is intended to support field operations for experiments in telerobotics, autonomous robotic operations, telerobotic field geology, and advanced man-machine interface concepts. The development program's current status is described, including an outline of the program's work over the past year, recent accomplishments, and plans for follow-on development work.

Klarer, P. R.↗

Single-Crystal Springs For Accelerometers

Thermal noise reduced, enabling use of smaller proof masses. Spring-and-mass accelerometers in which springs made of single-crystal material being developed. In spring-and-mass accelerometer, proof mass attached to one end of spring, and acceleration of object at other end of spring measured in terms of deflection of spring, provided frequency spectrum of acceleration lies well below resonant frequency of spring-and-proof-mass system. Use of single-crystal spring materials instead of such polycrystalline spring materials as ordinary metals makes possible to construct highly sensitive accelerometers (including seismometers) with small proof masses.

Vanzandt, Thomas R.↗

The AAMP5/AAMP-FV project

This presentation describes a project, formal verification of the microcode in the AAMP5 microprocessor, conducted to explore how formal techniques for specification and verification could be introduced into an industrial process. Sponsored by the Systems Validation Branch of NASA Langley and by Collins Commercial Avionics, a division of Rockwell International, it was conducted by Collins and the SRI International Computer Science Laboratory. The project consisted of specifying in the PVS language developed by SRI a portion of a Rockwell proprietary microprocessor, the AAMP5, at both the instruction set and register-transfer levels and using the PVS theorem prover to prove the microcode correct for a representative subset of instructions. While this presentation includes a brief technical overview, its emphasis is on the lessons learned in using PVS for an example of this size and the implications for using formal methods in an industrial setting. The central result of this project was to demonstrate the feasibility of formally specifying a commercial microprocessor and the use of mechanical proofs of correctness to verify microcode. This is particularly significant since the AAMP5 was not designed for formal verification, but to provide a more than three fold performance improvement, by pipelining instruction execution, while remaining object code compatible with the earlier AAMP2. As a consequence, the AAMP5 is one of the most complex microprocessors to which formal methods have been applied. Another key result was the discovery of both actual and seeded errors. Two actual microcode errors were discovered and corrected during development of the formal specification, illustrating the value of simply creating a precise specification. Two seeded errors were systematically uncovered while doing correctness proofs. One of these was an actual error that had been discovered after first fabrication but left in the microcode provided to SRI. The other error was designed to be unlikely to be detected by walkthroughs, testing, or simulation. Several other results emerged during the project, including the ease with which practicing engineers became comfortable with PVS, the need for libraries of general purpose theories, the usefulness of formal specification in revealing errors, the natural fit between formal specification and inspections, the difficulty of selecting the best style of specification for a new problem domain, the high level of assurance provided by proofs of correctness, and the need to engineer proof strategies for reuse.

Miller, Steven P.↗

Abstract Datatypes in PVS

PVS (Prototype Verification System) is a general-purpose environment for developing specifications and proofs. This document deals primarily with the abstract datatype mechanism in PVS which generates theories containing axioms and definitions for a class of recursive datatypes. The concepts underlying the abstract datatype mechanism are illustrated using ordered binary trees as an example. Binary trees are described by a PVS abstract datatype that is parametric in its value type. The type of ordered binary trees is then presented as a subtype of binary trees where the ordering relation is also taken as a parameter. We define the operations of inserting an element into, and searching for an element in an ordered binary tree; the bulk of the report is devoted to PVS proofs of some useful properties of these operations. These proofs illustrate various approaches to proving properties of abstract datatype operations. They also describe the built-in capabilities of the PVS proof checker for simplifying abstract datatype expressions.

Owre, Sam↗

Hiproofs

We introduce a hierarchical notion of formal proof, useful in the implementation of theorem provers, which we call highproofs. Two alternative definitions are given, motivated by existing notations used in theorem proving research. We define transformations between these two forms of hiproof, develop notions of underlying proof, and give a suitable definition of refinement in order to model incremental proof development. We show that our transformations preserve both underlying proofs and refinement. The relationship of our theory to existing theorem proving systems is discussed, as is its future extension.

Denney, Ewen↗

Synthesizing Certified Code

Code certification is a lightweight approach to demonstrate software quality on a formal level. Its basic idea is to require producers to provide formal proofs that their code satisfies certain quality properties. These proofs serve as certificates which can be checked independently. Since code certification uses the same underlying technology as program verification, it also requires many detailed annotations (e.g., loop invariants) to make the proofs possible. However, manually adding theses annotations to the code is time-consuming and error-prone. We address this problem by combining code certification with automatic program synthesis. We propose an approach to generate simultaneously, from a high-level specification, code and all annotations required to certify generated code. Here, we describe a certification extension of AUTOBAYES, a synthesis tool which automatically generates complex data analysis programs from compact specifications. AUTOBAYES contains sufficient high-level domain knowledge to generate detailed annotations. This allows us to use a general-purpose verification condition generator to produce a set of proof obligations in first-order logic. The obligations are then discharged using the automated theorem E-SETHEO. We demonstrate our approach by certifying operator safety for a generated iterative data classification program without manual annotation of the code.

Whalen, Michael↗

Self-Gravity Modeling for LISA

The Laser Interferometer Space Antenna (LISA) mission, a space based gravitational wave detector, uses laser metrology to measure distance fluctuations between proof masses aboard three spacecraft. The total acceleration disturbance to each proof mass is required to be below 3 x 10(exp 15) m/sq square root of Hz. Self-gravity noise due to spacecraft distortion and spacecraft motion is expected to be a significant contributor to the acceleration noise budget. To minimize these effects, the gravitational field at each proof mass must be kept as small, flat, and constant as possible. It is estimated that the static field must be kept below 5 x 10(exp -10) m/sq s with a gradient below 3 x 10(exp -8)/sq s in order to meet the required noise levels. Most likely it will not be possible to directly verify by measurements that the LISA spacecraft meets these requirements; they must be verified by models. The LISA Integrated Modeling team developed a new self-gravity tool that calculates the gravitational forces and moments on the proof masses to aid in the design and verification of the LISA spacecraft. We present here an overview of&e tool and the latest self-gravity results calculated using the current baseline design of LISA. We also present results of a self-gravity analysis of the ST-7 DRS package that will fly on the LISA Pathfinder mission.

Merkowitz, Stephen↗

Formalization of the Integral Calculus in the PVS Theorem Prover

The PVS Theorem prover is a widely used formal verification tool used for the analysis of safety-critical systems. The PVS prover, though fully equipped to support deduction in a very general logic framework, namely higher-order logic, it must nevertheless, be augmented with the definitions and associated theorems for every branch of mathematics and Computer Science that is used in a verification. This is a formidable task, ultimately requiring the contributions of researchers and developers all over the world. This paper reports on the formalization of the integral calculus in the PVS theorem prover. All of the basic definitions and theorems covered in a first course on integral calculus have been completed.The theory and proofs were based on Rosenlicht's classic text on real analysis and follow the traditional epsilon-delta method. The goal of this work was to provide a practical set of PVS theories that could be used for verification of hybrid systems that arise in air traffic management systems and other aerospace applications. All of the basic linearity, integrability, boundedness, and continuity properties of the integral calculus were proved. The work culminated in the proof of the Fundamental Theorem Of Calculus. There is a brief discussion about why mechanically checked proofs are so much longer than standard mathematics textbook proofs.

Butler, Ricky W.↗

Formal Methods Tool Qualification

Formal methods tools have been shown to be effective at finding defects in safety-critical digital systems including avionics systems. The publication of DO-178C and the accompanying formal methods supplement DO-333 allows applicants to obtain certification credit for the use of formal methods without providing justification for them as an alternative method. This project conducted an extensive study of existing formal methods tools, identifying obstacles to their qualification and proposing mitigations for those obstacles. Further, it interprets the qualification guidance for existing formal methods tools and provides case study examples for open source tools. This project also investigates the feasibility of verifying formal methods tools by generating proof certificates which capture proof of the formal methods tool's claim, which can be checked by an independent, proof certificate checking tool. Finally, the project investigates the feasibility of qualifying this proof certificate checker, in the DO-330 framework, in lieu of qualifying the model checker itself.

Wagner, Lucas G.↗

Surge Pressure Testing of Flight-Like Components

This project studies the transient surge pressure effects (such as those observed during propulsion system priming) on flight components. A water flow setup was used to impart transient surge pressures on flight-like components. The project compared the point of component failure for transient surge pressures versus static proof pressures. Results showed that designing to keep surge pressures below component proof pressures is overly conservative, because the components can handle higher transient pressures. The tests performed on burst discs showed that the rupture pressure under a transient surge pressure was at least 20% above the static rupture pressure. A tested pressure transducer remained fully functional and accurate after surge pressures 60% above its specified proof pressure. A thruster valve was exposed to transient surge pressures four times its specified proof pressure and showed no indications of damage.

propulsion components↗

A retrospective review of von Neumann’s analysis of hidden variables in quantum mechanics

This article reviews the history of J. von Neumann’s analysis of hidden variables in quantum mechanics and the subsequent analysis by others. In his book The Mathematical Foundations of Quantum Mechanics , published in 1932, von Neumann performed an analysis of the consequences of introducing hidden parameters (hidden variables) into quantum mechanics. He arrived at two principal conclusions: first, hidden variables cannot be incorporated into the existing theory of quantum mechanics without major modifications, and second, if they did exist, the theory would have already failed in situations where it has been successfully applied. This analysis has been taken as an “incorrect proof” against the existence of hidden variables, possibly due to a mistranslation of the German word prufen . von Neumann’s so-called proof isn’t even wrong as such a proof does not exist, but it is an examination of the limitations imposed by internal consistency of the Hilbert space formulation of the theory. One of the earliest attempts to eliminate uncertainty, by D. Bohm, requires a major modification of quantum mechanics (observables are not represented by Hermitian operators), which supports von Neumann’s first principal conclusion. However, testing the Bohm theory requires constructing a physically impossible initial state. As such, the theory has no experimental consequences, so W. Pauli referred to it as an “uncashable check”. As there are no observable consequences, the Bohm theory is possibly a counterexample to von Neumann’s second conclusion that hidden variables in particular would have already led to a failure of the theory.

density matrix↗

Determination of Flaw Growth Characteristics of Ti-6Al-4V Sheet in the Solution-Treated and Aged Condition

The specific experimental investigation undertaken was designed to answer these questions on Ti-6Al-4V in the solution treated and aged condition. The defect growth and fracture characteristics were studied in parent (unwelded) and welded sheet material. The results of the study indicate that cryogenic proof testing will screen smaller size defects than proof testing at ambient conditions. However some unusual crack growth behavior during the proof test simulation suggests that some further study be made of stress and time duration effects.

Hoeppner, David W.↗

Minimum thrust levels for spinning drag-free satellites

A drag-free satellite, which contains an internal unsupported proof mass, is shielded from external forces such as solar pressure. Thrustors force the satellite to follow the proof mass and hence the satellite follows an almost purely gravitational orbit. The dominant internal disturbing force is the mass attraction of the satellite on the proof mass. Spinning the satellite reduces this force and it has been investigated what the size of the thrustors must be in this case. This size is much smaller than originally thought. Its impact on some other features is shown.

Olsder, G. J.↗

Studies of orbital Eoetvoes experiments

A direct force-balance technique was analyzed for carrying out the Eoetvoes experiment in space, which is intended to give sufficient sensitivity to allow investigation of the gravitational interactions of energy stored in the weak interaction. The heart of experiment is an exceedingly sensitive dual accelerometer, containing two proof masses constructed of the materials whose Eoetvoes ratio is to be compared. For use in development of the accelerometer, a magnetic microbalance is proposed in which the weight of the proof mass is supported by magnetic forces which vary very slowly with the proof mass position. It is shown that at least two different mechanizations of the magnetic suspension may be feasible.

Chapman, P. K.↗

Variabilities detected by acoustic emission from filament-wound Aramid fiber/epoxy composite pressure vessels

Two hundred and fifty Aramid fiber/epoxy pressure vessels were filament-wound over spherical aluminum mandrels under controlled conditions typical for advanced filament-winding. A random set of 30 vessels was proof-tested to 74% of the expected burst pressure; acoustic emission data were obtained during the proof test. A specially designed fixture was used to permit in situ calibration of the acoustic emission system for each vessel by the fracture of a 4-mm length of pencil lead (0.3 mm in diameter) which was in contact with the vessel. Acoustic emission signatures obtained during testing showed larger than expected variabilities in the mechanical damage done during the proof tests. To date, identification of the cause of these variabilities has not been determined.

Hamstad, M. A.↗

The SIFT computer and its development

Software Implemented Fault Tolerance (SIFT) is an aircraft control computer designed to allow failure probability of less than 10 to the -10th/hour. The system is based on advanced fault-tolerance computing and validation methodology. Since confirmation of reliability by observation is essentially impossible, system reliability is estimated by a Markov model. A mathematical proof is used to justify the validity of the Markov model. System design is represented by a hierarchy of abstract models, and the design proof comprises mathematical proofs that each model is, in fact, an elaboration of the next more abstract model.

Goldberg, J.↗

Acoustic emission monitoring of Space Shuttle tiles

Late in the development of the Space Shuttle thermal protection system (TPS), a major problem was encountered with the attachment of the tiles to the spacecraft's exterior skin. To insure an adequate margin, each tile had to be proof tested. The risk of damaging a tile during proof test was quite high. For this reason, an acoustic emission system was developed and used in conjunction with the proof test to insure no significant damage occurred.

Castner, W. L.↗