Search NASASearch

SEARCH · Search NASA

Results for “proof”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

A Machine-Checked Proof of A State-Space Construction Algorithm

This paper presents the correctness proof of Saturation, an algorithm for generating state spaces of concurrent systems, implemented in the SMART tool. Unlike the Breadth First Search exploration algorithm, which is easy to understand and formalise, Saturation is a complex algorithm, employing a mutually-recursive pair of procedures that compute a series of non-trivial, nested local fixed points, corresponding to a chaotic fixed point strategy. A pencil-and-paper proof of Saturation exists, but a machine checked proof had never been attempted. The key element of the proof is the characterisation theorem of saturated nodes in decision diagrams, stating that a saturated node represents a set of states encoding a local fixed-point with respect to firing all events affecting only the node s level and levels below. For our purpose, we have employed the Prototype Verification System (PVS) for formalising the Saturation algorithm, its data structures, and for conducting the proofs.

Catano, Nestor

Deriving Safety Cases from Machine-Generated Proofs

Proofs provide detailed justification for the validity of claims and are widely used in formal software development methods. However, they are often complex and difficult to understand, because they use machine-oriented formalisms; they may also be based on assumptions that are not justified. This causes concerns about the trustworthiness of using formal proofs as arguments in safety-critical applications. Here, we present an approach to develop safety cases that correspond to formal proofs found by automated theorem provers and reveal the underlying argumentation structure and top-level assumptions. We concentrate on natural deduction proofs and show how to construct the safety cases by covering the proof tree with corresponding safety case fragments.

Basir, Nurlida

Deriving Safety Cases from Machine-Generated Proofs

Proofs provide detailed justification for the validity of claims and are widely used in formal software development methods. However, they are often complex and difficult to understand, because they use machine-oriented formalisms; they may also be based on assumptions that are not justified. This causes concerns about the trustworthiness of using formal proofs as arguments in safety-critical applications. Here, we present an approach to develop safety cases that correspond to formal proofs found by automated theorem provers and reveal the underlying argumentation structure and top-level assumptions. We concentrate on natural deduction proofs and show how to construct the safety cases by covering the proof tree with corresponding safety case fragments.

Basir, Nurlida

Assurance Cases for Proofs as Evidence

Proof-carrying code (PCC) provides a 'gold standard' for establishing formal and objective confidence in program behavior. However, in order to extend the benefits of PCC - and other formal certification techniques - to realistic systems, we must establish the correspondence of a mathematical proof of a program's semantics and its actual behavior. In this paper, we argue that assurance cases are an effective means of establishing such a correspondence. To this end, we present an assurance case pattern for arguing that a proof is free from various proof hazards. We also instantiate this pattern for a proof-based mechanism to provide evidence about a generic medical device software.

Chaki, Sagar

ORION - Crew Module Side Hatch: Proof Pressure Test Anomaly Investigation

The Orion Multi-Purpose Crew Vehicle program was performing a proof pressure test on an engineering development unit (EDU) of the Orion Crew Module Side Hatch (CMSH) assembly. The purpose of the proof test was to demonstrate structural capability, with margin, at 1.5 times the maximum design pressure, before integrating the CMSH to the Orion Crew Module structural test article for subsequent pressure testing. The pressure test was performed at lower pressures of 3 psig, 10 psig and 15.75 psig with no apparent abnormal behavior or leaking. During pressurization to proof pressure of 23.32 psig, a loud 'pop' was heard at ~21.3 psig. Upon review into the test cell, it was noted that the hatch had prematurely separated from the proof test fixture, thus immediately ending the test. The proof pressure test was expected be a simple verification but has since evolved into a significant joint failure investigation from both Lockheed Martin and NASA.

Evernden, Brent A.

Reliability analysis of structures under periodic proof tests in service

A reliability analysis of structures subjected to random service loads and periodic proof tests treats gust loads and maneuver loads as random processes. Crack initiation, crack propagation, and strength degradation are treated as the fatigue process. The time to fatigue crack initiation and ultimate strength are random variables. Residual strength decreases during crack propagation, so that failure rate increases with time. When a structure fails under periodic proof testing, a new structure is built and proof-tested. The probability of structural failure in service is derived from treatment of all the random variables, strength degradations, service loads, proof tests, and the renewal of failed structures. Some numerical examples are worked out.

Yang, J.-N.

Some theoretical considerations of a stall proof airplane

For the stall proof airplane there should be a stabilizing pitching moment below the stall angle of attack of sufficient amount to prevent the attainment of the stall angle of attack which cannot be over-ridden by control deflections. This paper presents (1) a development of the moment equations to show the theoretical considerations of a stall proof airplane and (2) the nonlinear moment characteristics that must be obtained to satisfy the stall proof requirements. In addition, it is shown that an aerodynamic spoiler located on the under surface of the horizontal tail can be designed to meet these requirements of a stall proof airplane. Wind tunnel results are shown to validate assumptions and predictions.

Chevalier, H. L.

Stress rate and proof-testing of silicon wafers

Fracture mechanics test methods were applied to evaluate the proof-test characteristics of single-crystal silicon wafers. The results indicate that the strength distribution of silicon wafers is truncated by proof-testing. No subcritical crack growth occurred during proof-loading, as inferred from the lack of a stress-rate effect on strength. Mechanical proof-testing appears to be an effective method for eliminating weak samples before cell processing.

Chen, C. P.

Mechanical proof testing in cell processing

Fracture mechanics test methods are applied to evaluate the proof test characteristics of silicon Cz wafers. The results indicate that the strength distribution of silicon wafers is truncated by proof testing and no subcritical crack growth in silicon is observed during proof loading. Mechanical proof testing appears to be an effective method to eliminate weak samples before cell processing.

Chen, C. P.

A Comparison of Single-Cycle Versus Multiple-Cycle Proof Testing Strategies

Single-cycle and multiple-cycle proof testing (SCPT and MCPT) strategies for reusable aerospace propulsion system components are critically evaluated and compared from a rigorous elastic-plastic fracture mechanics perspective. Earlier MCPT studies are briefly reviewed. New J-integral estimation methods for semi-elliptical surface cracks and cracks at notches are derived and validated. Engineering methods are developed to characterize crack growth rates during elastic-plastic fatigue crack growth (FCG) and the tear-fatigue interaction near instability. Surface crack growth experiments are conducted with Inconel 718 to characterize tearing resistance, FCG under small-scale yielding and elastic-plastic conditions, and crack growth during simulated MCPT. Fractography and acoustic emission studies provide additional insight. The relative merits of SCPT and MCPT are directly compared using a probabilistic analysis linked with an elastic-plastic crack growth computer code. The conditional probability of failure in service is computed for a population of components that have survived a previous proof test, based on an assumed distribution of initial crack depths. Parameter studies investigate the influence of proof factor, tearing resistance, crack shape, initial crack depth distribution, and notches on the MCPT vs. SCPT comparison. The parameter studies provide a rational basis to formulate conclusions about the relative advantages and disadvantages of SCPT and MCPT. Practical engineering guidelines are proposed to help select the optimum proof test protocol in a given application.

McClung, R. C.

A Comparison of Single-Cycle Versus Multiple-Cycle Proof Testing Strategies

Single-cycle and multiple-cycle proof testing (SCPT and MCPT) strategies for reusable aerospace propulsion system components are critically evaluated and compared from a rigorous elastic-plastic fracture mechanics perspective. Earlier MCPT studies are briefly reviewed. New J-integral estimation methods for semi-elliptical surface cracks and cracks at notches are derived and validated. Engineering methods are developed to characterize crack growth rates during elastic-plastic fatigue crack growth (FCG) and the tear-fatigue interaction near instability. Surface crack growth experiments are conducted with Inconel 718 to characterize tearing resistance, FCG under small-scale yielding and elastic-plastic conditions, and crack growth during simulated MCPT. Fractography and acoustic emission studies provide additional insight. The relative merits of SCPT and MCPT are directly compared using a probabilistic analysis linked with an elastic-plastic crack growth computer code. The conditional probability of failure in service is computed for a population of components that have survived a previous proof test, based on an assumed distribution of initial crack depths. Parameter studies investigate the influence of proof factor, tearing resistance, crack shape, initial crack depth distribution, and notches on the MCPT vs. SCPT comparison. The parameter studies provide a rational basis to formulate conclusions about the relative advantages and disadvantages of SCPT and MCPT. Practical engineering guidelines are proposed to help select the optimum proof test protocol in a given application.

McClung, R. C.

Residual Stress Measurements After Proof and Flight: ETP-0403

The intent of this testing was to evaluate the residual stresses that occur in and around the attachment details of a case stiffener segment that has been subjected to flight/recovery followed by proof loading. Not measured in this test were stresses relieved at joint disassembly due to out-of-round and interference effects, and those released by cutting the specimens out of the case segment. The test article was lightweight case stiffener segment 1U50715, S/N L023 which was flown in the forward stiffener position on flight SRM 14A and in the aft position on flight SRM24A. Both of these flights were flown with the 3 stiffener ring configuration. Stiffener L023 had a stiffener ring installed only on the aft stub in its first flight, and it had both rings installed on its second flight. No significant post flight damage was found on either flight. Finally, the segment was used on the DM-8 static test motor in the forward position. No stiffener rings were installed. It had only one proof pressurization prior to assignment to its first use, and it was cleaned and proof tested after each flight. Thus, the segment had seen 3 proof tests, two flight pressurizations, and two low intensity water impacts prior to manufacturing for use on DM-8. On DM-8 it received one static firing pressurization in the horizontal configuration. Residual stresses at the surface and in depth were evaluated by both the x-ray diffraction and neutron beam diffraction methods. The x-ray diffraction evaluations were conducted by Technology for Energy Corporation (TEC) at their facilities in Knoxville, TN. The neutron beam evaluations were done by Atomic Energy of Canada Limited (AECL) at the Chalk River Nuclear Laboratories in Ontario. The results showed general agreement with relatively high compressive residual stresses on the surface and moderate to low subsurface tensile residual stresses.

Webster, Ronald L..

A Comparison of Single-Cycle Versus Multiple-Cycle Proof Testing Strategies

Single-cycle and multiple-cycle proof testing (SCPT and MCPT) strategies for reusable aerospace propulsion system components are critically evaluated and compared from a rigorous elastic-plastic fracture mechanics perspective. Earlier MCPT studies are briefly reviewed. New J-integral estimation methods for semielliptical surface cracks and cracks at notches are derived and validated. Engineering methods are developed to characterize crack growth rates during elastic-plastic fatigue crack growth (FCG) and the tear-fatigue interaction near instability. Surface crack growth experiments are conducted with Inconel 718 to characterize tearing resistance, FCG under small-scale yielding and elastic-plastic conditions, and crack growth during simulated MCPT. Fractography and acoustic emission studies provide additional insight. The relative merits of SCPT and MCPT are directly compared using a probabilistic analysis linked with an elastic-plastic crack growth computer code. The conditional probability of failure in service is computed for a population of components that have survived a previous proof test, based on an assumed distribution of initial crack depths. Parameter studies investigate the influence of proof factor, tearing resistance, crack shape, initial crack depth distribution, and notches on the MCPT versus SCPT comparison. The parameter studies provide a rational basis to formulate conclusions about the relative advantages and disadvantages of SCPT and MCPT. Practical engineering guidelines are proposed to help select the optimum proof test protocol in a given application.

McClung, R. C.

[ ] or SUCCESS is Not Enough: Current Technology and Future Directions in Proof Presentation

Automated theorem provers for first order logic are now around for several decades. Over the last few years, their deductive power to solve hard problems has increased tremendously. The annual CASC system competitions [Se97] give a clear picture of this situation. However, today's automated theorem provers are restricted "more by general usability than by raw deductive power." As a result of this, there are only very few serious applications of automated theorem provers. There are numerous features which a theorem prover lacks for real-world applicability. An automated theorem prover (as it is currently seen) is nothing more than a fast and elaborate search procedure. In that sense, an ATP can compared to a formulated race car, cool and fast, but virtually unusable for shopping groceries around the corner. Many important features are missing, or are optimized for speed rather than for applicability. [Schol] identifies important features which are needed for practical usability like detection of non-theorems, handling of modal/inductive proof tasks, control of the prover, and proof output. In this paper, we will focus solely on the last point, the presentation of the ATP's result to the user. In the rest of this paper, we will first discuss the general importance of providing feedback to the user, then we will describe the system ExplainIt!, a part of the deductive synthesis system AMPHION/NAV. In the conclusions we will relate proof presentation to other ways of post-processing a proof found by an ATP and stress their role in the future of automated deduction.

Schumann, Johann

Analysis and Test Correlation of Proof of Concept Box for Blended Wing Body-Low Speed Vehicle

The Low Speed Vehicle (LSV) is a 14.2% scale remotely piloted vehicle of the revolutionary Blended Wing Body concept. The design of the LSV includes an all composite airframe. Due to internal manufacturing capability restrictions, room temperature layups were necessary. An extensive materials testing and manufacturing process development effort was underwent to establish a process that would achieve the high modulus/low weight properties required to meet the design requirements. The analysis process involved a loads development effort that incorporated aero loads to determine internal forces that could be applied to a traditional FEM of the vehicle and to conduct detailed component analyses. A new tool, Hypersizer, was added to the design process to address various composite failure modes and to optimize the skin panel thickness of the upper and lower skins for the vehicle. The analysis required an iterative approach as material properties were continually changing. As a part of the material characterization effort, test articles, including a proof of concept wing box and a full-scale wing, were fabricated. The proof of concept box was fabricated based on very preliminary material studies and tested in bending, torsion, and shear. The box was then tested to failure under shear. The proof of concept box was also analyzed using Nastran and Hypersizer. The results of both analyses were scaled to determine the predicted failure load. The test results were compared to both the Nastran and Hypersizer analytical predictions. The actual failure occurred at 899 lbs. The failure was predicted at 1167 lbs based on the Nastran analysis. The Hypersizer analysis predicted a lower failure load of 960 lbs. The Nastran analysis alone was not sufficient to predict the failure load because it does not identify local composite failure modes. This analysis has traditionally been done using closed form solutions. Although Hypersizer is typically used as an optimizer for the design process, the failure prediction was used to help gain acceptance and confidence in this new tool. The correlated models and process were to be used to analyze the full BWB-LSV airframe design. The analysis and correlation with test results of the proof of concept box is presented here, including the comparison of the Nastran and Hypersizer results.

Spellman, Regina L.

CHP-PRA Proof-of-Concept [Simulation] Sensitivity Assessment

An effort is underway to establish a Crew Health and Performance system (CHP) tradespace tool using a Probabilistic Risk Assessment (PRA) modeling and simulation system. The goal of the CHP-PRA effort is to provide a means of quantifying the integrated influence of CHP functions and capabilities on risk outcome metrics associated with health, performance, and long-term health. These metrics can then be used to establish potential risk-based trades on CHP system designed functionality and capabilities. Previously, our team demonstrated a proof-of-concept PRA approach that estimated the integrated influence of exercise countermeasures on 8 human system risks (Figure 1a) with outcomes associated with health and medical risk metrics. We reported that the change in the integrated relative health risk was small (Figure 1b) and that the small change in overall risk resulted from compounding and competing contribution levels of the individual risks. This interesting observation illustrates the emergent complexity of even straightforward representations of the human health and performance risk space and the ability of PRA models to capture this balance of global risk concerns. A key question that is not addressed in the initial analysis is “even though the global risk is relatively nominal, do any of the local risks become unacceptable?” In essence, we seek to determine what relative change in the human system risks are contributing to the relatively muted sensitivity of the proof-of-concept model combined risk assessments. Evaluations at the component risk level should elucidate if any individual risk reaches a high level that is subsequentially balanced by reductions in other areas. To further understand the relative changes in the component risks in the proof-of-concept model, and to elucidate how future refinements can be targeted, a means of establishing the contributions of the robustness of the proof-of-concept approach will be demonstrated.

astronaut health

Optimum structural design based on reliability and proof-load testing

Proof-load test eliminates structures with strength less than the proof load and improves the reliability value in analysis. It truncates the distribution function of strength at the proof load, thereby alleviating verification of a fitted distribution function at the lower tail portion where data are usually nonexistent.

Shinozuka, M.

Proof test criteria for thin-walled 2219 aluminum pressure vessels. Volume 1: Program summary and data analysis

This experimental program was undertaken to investigate the crack growth behavior of deep surface flaws in 2219 aluminum. The program included tests of uniaxially loaded surface flaw and center crack panels at temperatures ranging from 20K (-423 F) to ambient. The tests were conducted on both the base metal and as-welded weld metal material. The program was designed to provide data on the mechanisms of failure by ligament penetration, and the residual cyclic life, after proof-testing, of a vessel which has been subjected to incipient penetration by the proof test. The results were compared and analyzed with previously developed data to develop guidelines for the proof testing of thin walled 2219 pressure vessels.

Finger, R. W.