Search NASA⌕ Search

SEARCH · Search NASA

Results for “Development assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Status of SPCA-ANL Software Development, Software Quality Assurance, and Application (FY2025)

SPCA-ANL is a simulation tool used to perform deterministic analyses of sodium spray and pool fires. Development of the SPCA-II (Spray Pool Combustion Analysis) code began in the mid- 1980s as part of the Clinch River Breeder Reactor (CRBR) Project. At that time, development of SPCA-II, which was led by Rockwell International, was focused on treatment of large-scale sodium spray, stream, and pool fires that were anticipated to be prototypic of the steam generator building cells in CRBR. Under more recent DOE NE programmatic activities, the SPCA-II code was recovered from existing literature and underwent minor modifications to generate a stable executable. This recovered version of the code was not formally released. As part of the Versatile Test Reactor (VTR) Project in the 2010s, the SPCA-II code underwent key modifications to improve stability, address modeling deficiencies, improve consistency between the code manual and software, and address numerous bugs. At this point, SPCA-II was renamed SPCA-ANL. Given that SPCA-II served as the original basis for SPCA-ANL, both codes share an integrated history. Following termination of the VTR Project, the DOE NE Fast Reactor Program resumed support of the software with the goal of building and maintaining software infrastructure that can enable commercial-grade dedication of SPCA-ANL by an end user. Version 1.0, the first external release of SPCA-ANL, was generated in June 2024. This report summarizes the development and maintenance activities completed for SPCAANL in FY2025. This year’s work was focused on improving quality and usability of the code. The provisional Software Quality Assurance (SQA) program has been established and was used to test the procedures for infrastructure improvements, code development, bug fixes, and code releases, as described in the following sections of this report. A code Version 1.0.1 was released in FY25, as described in Chapter 4.

97 MATHEMATICS AND COMPUTING↗

Assurance Issues in Developing AI/ML Components (and their Standards) for Civil Aviation

Standards development activities require a keen and deep understanding of the problem being solved by the standard as well as the technologies being deployed in any reference implementation of the solution. It is important to understand the mechanisms and limits of the fundamental, underlying science of implementation and verification technologies used to realize and assure systems. We need to understand the limits of what current process and metrics can provide with respect to new technologies. US leadership is important in this endeavor, and it is vital that we have a measured approach that yields sound results. We wish to start with simple, well-defined, non-safety critical applications and then progress to functions which have (1) clearly defined requirements, (2) means of checking the answer/output, and (3) means of intervention and mitigation of incorrect answers/outputs.

Aviation Safety↗

Product assurance policies and procedures for flight dynamics software development

The product assurance policies and procedures necessary to support flight dynamics software development projects for Goddard Space Flight Center are presented. The quality assurance and configuration management methods and tools for each phase of the software development life cycles are described, from requirements analysis through acceptance testing; maintenance and operation are not addressed.

Perry, Sandra↗

Development of TID Hardness Assurance Methodologies to Capitalize on Statistical Radiation Environment Models

We develop methods for bounding part-to-part variation in TID data. When used in conjunction with statistical radiation environment models, these methods allow development of RHA that deliver estimated piece part reliability for any desired confidence level, moving beyond risk avoidance methodologies based on radiation design margin. Two methods are developed, and their results compared for realistic data.

Total Ionizing Dose↗

Development of TID Hardness Assurance Methodologies to Capitalize on Statistical Radiation Environment Models

We develop methods for bounding part-to-part variation in TID data. When used in conjunction with statistical radiation environment models, these methods allow development of RHA that deliver estimated piece part reliability for any desired confidence level, moving beyond risk avoidance methodologies based on radiation design margin. Two methods are developed, and their results compared for realistic data.

Total ionizing dose↗

Application of Objectives-Driven Assurance Cases to System Development in an Evolving Acquisition Model

System properties such as “safety” and “dependability” cannot, in practice, be proven, and must be argued in an “assurance case” aimed at supporting risk-acceptance decisions that have to be made by system acquirers and/or regulatory authorities. The paper is concerned with applications of the “assurance case” idea early in design and development of new systems, when (apart from dedicated testing) the only available operating experience information derives from previous (non-identical) systems. Much of the discussion is based on an evolving acquisition model at the US National Aeronautics and Space Administration; previously, most major systems were developed in-house, but some major systems will now be developed by and acquired from commercial providers. Key points discussed include the following. (1) By promoting a particular kind of focused discussion between acquirers and providers, the use of assurance cases should be particularly valuable under the new acquisition model. (2) In principle, objectives-driven (sometimes called “performance-based”) approaches to assurance of performance have significant advantages in cases where they are applicable. (3) For truly novel systems, completeness of the safety analysis is a significant issue; it is important for the assurance case to include a commitment by the provider (or applicant) to seriously pursue analysis of operating experience, so that previously unrecognized hazards can be identified and addressed. (4) Inquiries into major accidents often point to deficiencies in management oversight in all parts of the life cycle; management processes need to be addressed in the formulation and the implementation of an assurance case. Under the new acquisition model, these considerations imply a serious reconsideration of the way in which the development process is managed by both providers and acquirers.

Objectives-driven↗

Developing a Nuclear Quality Assurance Compliant Design Methodology for Neutronic Analysis of Xe-100 Design

The primary objective of this work is to develop a design methodology compliant with nuclear quality assurance standards for the Xe-100 neutronic design verification studies. To achieve this, a Monte Carlo model of the Xe-100 reactor was constructed using the exclusion principle, transformation technique, and universe-based level specification following Idaho National Laboratory (INL) NQA level-1 compliant standards and an NQA-1 compliant version of MCNP6. The model encompasses the entire reactor core structures, including the upper plenum, core region, and lower plenum sections, along with all sub-components. The active core section was represented using the spectral regions, each comprising a particular fuel composition and temperature averaged over the considered zone, calculated by X-energy using Very Superior Old Programs (VSOP). Additionally, a component-wise temperature map was implemented into the model, not only for the core region but also for the structural components. Temperature-dependent cross-section libraries, along with thermal scattering law libraries, generated using INL NQA-1 compliant version of NJOY21, were utilized for each isotope in the burnt fuel and the structural materials. Furthermore, the volume of each modeled component was estimated using a stochastic approach with the ray tracing method in MCNP and criticality calculations were performed.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Demonstrating Assurance of Model-Based Fault Diagnosis Systems on an Operational Mission

Developers of robotic scientific and commercial spacecraft are trending towards use of onboard autonomous capabilities for responding quickly to dynamic environments and rapidly changing situations. These capabilities need to know the state of the spacecraft’s health. Model-based fault diagnosis (MBFD) is an approach to estimating health by continuously verifying accurate behavior and diagnosing off-nominal behavior. Proper functioning of MBFD depends on 1) the quality of the diagnostic system model that is analyzed and compared to commands and onboard measurements to estimate a system’s health state, and 2) the correct functionality of the diagnosis engine interrogating the model and comparing its analyses to observed system behavior. Our goal is to develop Verification and Validation (V&V) techniques for MBFD to provide future missions sufficient confidence in its functionality and performance to deploy it on the systems they develop. Our work has been focused on infusing the techniques we developed earlier to an operational mission. First, we are constructing diagnostic models of a spacecraft attitude control system and updating our diagnostic engine so they can be demonstrated aboard the Arcsecond Space Telescope Enabling Research in Astrophysics (ASTERIA) mission, an operational spacecraft for which experiments in autonomy are being planned and executed, using the V&V techniques we have previously developed to assure they are both correct and complete. Since it is nearing the end of its life, ASTERIA provides a unique opportunity to demonstrate MBFD since the monitored components are expected to fail. Our demonstration will give system developers additional confidence to make timely, informed MBFD deployment decisions. Second, we will be completing performance assessments of the diagnostic engine/diagnostic model ensemble both on the flight system and ground-based testbeds to gain confidence in MBFD’s ability to run successfully in a spacecraft’s resource-constrained environment without adversely affecting other on-board activities. Finally, we are capturing our experience in preparing this demonstration in a set of checklists and guidance documents. Current practice includes high-level institutional guidance documents and standards, but at a high level of abstraction that does not necessarily address specific MBFD concerns. The purpose of the new checklists is to provide future mission developers clear, unambiguous, procedure-oriented guidance on assuring MBFD. This paper describes our work in these areas. For the first area, we describe the diagnostic models and updated diagnostic engine that will be used for the on-board demonstration. We describe how the V&V techniques we developed earlier are used to assure model and engine correctness and completeness. For the second area, we identify the performance measurement and assessment techniques used to characterize the diagnostic engine and diagnostic models, and discuss the effect of measured performance on overall mission operation. Finally, we present the checklist and guidance documents and describe how they meet the goals of providing system developers with clear, unambiguous, procedure-oriented guidance on MBFD assurance. We show how the techniques we have developed map into those artifacts.

Nikora, Allen↗

Developing A Dependable Multi-Agent Rover Swarm Using cFS

The future of space exploration lies in cooperative autonomous systems. Ensuring their high integrity remains a challenge. The Robust Software Engineering group at NASA Ames Research Center has been developing the Troupe project to explore the challenges with developing and assuring high integrity of cooperative autonomous robotic systems. In particular, Troupe aims to develop a swarm of autonomous rovers capable of mapping unknown terrain and assure their high integrity using the advanced V&V tools developed in the group. In this paper, we present the evolution of the design of Troupe. We focus on the lessons learned in developing and assuring the rover swarm using core Flight System (cFS). In particular, we discuss the benefits and challenges in applying model-based development to develop the rover swarm.

space systems↗

Developing A Dependable Multi-Agent Rover Swarm Using cFS

The future of space exploration lies in cooperative autonomous systems. Ensuring their high integrity remains a challenge. The Robust Software Engineering group at NASA Ames Research Center has been developing the Troupe project to explore the challenges with developing and assuring high integrity of cooperative autonomous robotic systems. In particular, Troupe aims to develop a swarm of autonomous rovers capable of mapping unknown terrain and assure their high integrity using the advanced V&V tools developed in the group. In this paper, we present the evolution of the design of Troupe. We focus on the lessons learned in developing and assuring the rover swarm using core Flight System (cFS). In particular, we discuss the benefits and challenges in applying model-based development to develop the rover swarm.

space systems↗

Application of Risk Informed Decision Making to Highly Reliable Three Dimensionally Woven Thermal Protection System for Mars Sample Return

The NASA Risk Informed Decision Making process is used to assess a trade space of three dimensionally woven thermal protection systems for application to the Mars Sample Return Earth Entry Vehicle. Candidate architectures are assessed based on mission assurance, technical development, cost, and schedule risk. Assessment methodology differed between the architectures, utilizing a four-point quantitative scale for mission assurance and technical development and highly tailored PERT techniques for cost and schedule. Risk results are presented, in addition to a review of RIDM effectiveness for this application.

Needels, J.↗

Application of Risk Informed Decision Making to a Highly Reliable Three-Dimensionally Woven Thermal Protection System for Mars Sample Return

The NASA Risk Informed Decision Making process is used to assess a trade space of three dimensionally woven thermal protection systems for application to the Mars Sample Return Earth Entry Vehicle. Candidate architectures are assessed based on mission assurance, technical development, cost, and schedule risk. Assessment methodology differed between the architectures, utilizing a four-point quantitative scale for mission assurance and technical development and highly tailored PERT techniques for cost and schedule. Risk results are presented, in addition to a review of RIDM effectiveness for this application.

Needels, J.↗

New developments in NASA quality assurance

The purpose of this talk is to examine and discuss NASA's basic quality concept, the policy and procedures which define and implement this concept and subsequently explore the NASA-Industry quality relationships which are essential to the success of NASA's quality assurance concept. It is important to emphasize that NASA's Quality Assurance program is predicated on the concept of an individually tailored quality program for each significant NASA procurement - particularly, large space systems. As a result, NASA's Quality Assurance program - to be effective - must be responsive to various technologies, hardware systems, and space missions. In addition, the program must be responsive to changing policies and practices in research, engineering and procurement. Key issues in the NASA-Contractor quality relationships in the framework of an over all NASA-Industry partnership include: (1) the necessity for NASA to effectively discharge its responsibility for providing clear and complete definition of quality requirements at all phases of the procurement cycle; (2) the right of the contractor to expect an explicit definition of NASA quality requirements in each RFP and contract and to request same if it is not provided; (3) the necessity for the contractor to have a dynamic and responsive quality program which is directed towards assuring that the hardware meets all technical requirements and to accomplish this in an effective and efficient manner; and (4) the critical need for investigation and study of the economic aspects of quality and an evaluation of our policies and practices based upon the results of such a study.

Condon, John E.↗

Agile Approach to Assuring the Safety-Critical Embedded Software for NASA's Orion Spacecraft

Human-rated missions like NASA's Exploration Mission - 1 (EM-1) and the Orion Multi-Purpose Crew Vehicle are becoming exceedingly complex in terms of software's contribution to achieving mission objectives. The increasing complexity and inherent safety critical nature of the embedded flight software imposes a unique resource challenge to assurance providers responsible for affirming that the mission is going to fly safely. Another challenge NASA and other Government agencies are facing is that more and more software is being developed using an agile development methodology, which is divergent from the typical waterfall, iterative, and incremental development methodologies assurance providers generally observe in the development of safety-critical embedded software. Orion Independent Verification and Validation (IV&V) has addressed these challenges by providing focused assurance results of critical mission capabilities prioritized by a dynamic assessment of risk level. Prior to this approach, Orion IV&V evaluated areas of risk in much broader, and more static, terms. Due to the agile software development life cycle that Orion follows, IV&V findings were often reported months out of phase with the developer thereby imposing increased rework costs. As a result of evolving the approach to adding assurance on Orion, IV&V is able to incrementally deliver high-priority assurance conclusions and more impactful issues more in phase with the developer activities, thereby increasing the value of the findings to the project. The agile IV&V approach employed by the Orion IV&V team strives to achieve a cadence of delivery that matches the pace of development. This agile approach provides increased flexibility for the assurance provider to become more efficient in reporting assurance conclusions and issues. This paper and presentation will discuss the principles which drive the design of our approach, results to date, and stimulate thinking for groups looking to add assurance to software being developed using an agile methodology.

Justin Smith↗

Gateway Program Safety and Mission Assurance Integration - the Future of Safe Deep Space Human Exploration

As a foundational element of the National Aeronautics and Space Administration (NASA) Artemis Campaign, the Gateway is an incrementally built cislunar spacecraft that will serve as a platform for deep space human exploration, science, and technology demonstration. The Gateway will be a unifying catalyst for international partners around the world to establish sustained deep space scientific investigations, lunar surface access, and missions to Mars. As human exploration moves farther away from Earth, spacecraft designs must prioritize and optimize mass and volume allocations, while minimizing human and spacecraft risk. To accomplish this objective, the Gateway Program Safety and Mission Assurance functions develop, implement, and ensure compliance with requirements, in concert with the accurate characterization and transparent communication of residual hazard risks, for integrated safety, reliability and maintainability and quality assurance. Safety and Mission Assurance was a key contributor during Gateway program pre-formulation and formulation activities where safety and reliability analysis was embedded in the Gateway Systems Engineering and Integration team. During these early program stages, a preliminary Gateway Integrated Hazard Analysis and Preliminary Gateway Probabilistic Risk Assessment assisted in Gateway architectural and operational definition as part of a risk-informed design process. As the deep space architecture has matured, the integrated Safety and Mission Assurance analyses have matured, new safety review processes have been developed, and requirements have been refined to ensure compliance with integrated safety and mission assurance objectives. The Gateway Program is currently concluding the preliminary design review informed milestone, where the primary objectives included: - Ensured completeness and consistency of the preliminary design, including the meeting of all requirements within appropriate margins and acceptable risk posture. - Identification of any major issues moving forward to the Critical Design phase. At this milestone, Safety and Mission Assurance provided numerous products, including Gateway Top Risks and Risk Mitigation Plans, updated integrated hazard analyses, updated probabilistic risk assessment, Crew Survival Analysis Report, and updated Safety and Mission Assurance Requirements and Plans. These products provide a many-faceted perspective on the inherent risk and available mitigations involved in flying the current proposed vehicle design and anticipated stack configurations. In addition, Safety and Mission Assurance identified top technical, process and workforce concerns to be addressed as the program progresses toward the critical design phase. This paper will detail the evolution of the Gateway Program Safety and Mission Assurance integration functions, provide its current status and lessons learned for future human spaceflight programs. Throughout this paper the key tenets of the Gateway Program Safety and Mission Assurance will be discussed: - Application of a risk-informed approach to identify and mitigate areas of highest risk. - Leverage of valuable processes and lessons learned from earlier spaceflight programs. - Development of Safety and Mission Assurance products to inform design risk trades. - Utilization of common Safety and Mission Assurance practices to identify safety risks for multiple perspectives: top-down, bottom-up, and across lines of integration. - Approval of safety hazards at the appropriate level of authority, keeping most deliberation closest to design expertise and elevating risks of greatest concern for program-level consideration. - Championing of Safety and Mission Assurance processes and forums to foster a pervasive safety culture that is transparent, inclusive, and collaborative between all partners. These tenets have allowed the Gateway Safety and Mission Assurance function to play a key role in optimized vehicle design evolution, and early identification and mitigation of Gateway program and Artemis mission risk.

Helen Vaccaro↗