Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20

Lessons Learned on Mega-Constellation Deployments and Impact to Space Domain Awareness

The breakneck expansion of multi-payload launches in low Earth orbit (LEO) has seen significant escalation over the last three years in the Space Domain Awareness (SDA) enterprise. The uptick in satellite deployment frequency, gradation of Mega-constellation deployments utilizing electric propulsion, and surge in metric observation density from the Space Surveillance Network (SSN) have imposed major system enhancements to ensure spaceflight safety. Beginning with the launch phase, new tactics, software, and procedures have been developed over the last few years to optimize the tasking of the SSN and ensure custody of all recently launched satellites that are added to the space catalog. Ensuring appropriate tasking levels were pivotal during the satellite separation phase, which necessitated updates to the mission systems for improved delineation between clustered satellites in a short window of time. The improved incorporation of utilizing owner operator provided ephemeris coupled with critical code improvements have now revolutionized how we maintain custody of earth orbiting objects. The exponential population growth of low-Earth orbiting satellites have also increased the quantity of Conjunction Data Messages sent out to partners such as the Trajectory Operations Group (TOPO) in Johnson Space Center. We will discuss the need for continued collaboration between the National Aeronautics and Space Administration (NASA) and other Mega-Constellation Satellite Operators to safeguard Human Space Flight operations. Lastly, we will discuss the increase in reentry reporting for satellites falling back to Earth’s atmosphere, and the challenges associated with these events.

Christian C Ramos↗

Lessons Learned on Mega-Constellation Deployments and Impact to Space Domain Awareness

The breakneck expansion of multi-payload launches in low Earth orbit (LEO) has seen significant escalation over the last three years in the Space Domain Awareness (SDA) enterprise. The uptick in satellite deployment frequency, gradation of mega-constellation deployments utilizing electric propulsion, and surge in metric observation density from the Space Surveillance Network (SSN) have driven major system enhancements to ensure spaceflight safety. Beginning with the launch phase, new tactics, software, and procedures have been developed over the last few years to optimize the tasking of the SSN and ensure custody of all recently launched satellites that are added to the space catalog. Ensuring appropriate tasking levels were pivotal during the satellite separation phase, which necessitated updates to the mission systems for improved delineation between clustered satellites in a short window of time. The improved incorporation of utilizing satellite owner/operator-provided ephemeris coupled with critical code improvements have revolutionized how we maintain custody of Earth orbiting objects. The exponential population growth of Low-Earth orbiting satellites have also increased the quantity of Conjunction Data Messages sent out to partners such as the Trajectory Operations Group (TOPO) in Johnson Space Center. We will discuss the need for continued collaboration between the National Aeronautics and Space Administration (NASA) and other mega-constellation satellite operators to safeguard human spaceflight operations. Lastly, we will discuss how mega-constellations are driving best practices for safe operations across the space community.

Christian Ramos↗

Artemis Status Tracker for Real-time Awareness

Providers of Verification evidence for the Space Launch System (SLS) Program include Element Offices (SPIE, Stages, Engines, Booster) as well as Disciplines (Vehicle Management / GN&C, Loads & Environments, Safety and Mission Assurance, Systems Engineering, Integrated Avionics Software). These Elements and Disciplines rely on myriad inputs for their compliance evidence, from NASA and contractors alike, spanning testing and analysis to inspection and validation of records such as drawings and reports.

Braxton Lovett↗

Review of Ground Systems Development and Operations (GSDO) Tools for Verifying Command and Control Software

The Exploration Systems Development (ESD) Standing Review Board (SRB) requested the NASA Engineering and Safety Center (NESC) conduct an independent review of the plan developed by Ground Systems Development and Operations (GSDO) for identifying models and emulators to create a tool(s) to verify their command and control software. The NESC was requested to identify any issues or weaknesses in the GSDO plan. This document contains the outcome of the NESC review.

Aguilar, Michael L.↗

Certifying Domain-Specific Policies

Proof-checking code for compliance to safety policies potentially enables a product-oriented approach to certain aspects of software certification. To date, previous research has focused on generic, low-level programming-language properties such as memory type safety. In this paper we consider proof-checking higher-level domain -specific properties for compliance to safety policies. The paper first describes a framework related to abstract interpretation in which compliance to a class of certification policies can be efficiently calculated Membership equational logic is shown to provide a rich logic for carrying out such calculations, including partiality, for certification. The architecture for a domain-specific certifier is described, followed by an implemented case study. The case study considers consistency of abstract variable attributes in code that performs geometric calculations in Aerospace systems.

Lowry, Michael↗

Aerospace Safety Advisory Panel

This report covers the activities of the Aerospace Safety Advisory Panel (ASAP) for calendar year 1998-a year of sharp contrasts and significant successes at NASA. The year opened with the announcement of large workforce cutbacks. The slip in the schedule for launching the International Space Station (ISS) created a five-month hiatus in Space Shuttle launches. This slack period ended with the successful and highly publicized launch of the STS-95 mission. As the year closed, ISS assembly began with the successful orbiting and joining of the Functional Cargo Block (FGB), Zarya, from Russia and the Unity Node from the United States. Throughout the year, the Panel maintained its scrutiny of NASA's safety processes. Of particular interest were the potential effects on safety of workforce reductions and the continued transition of functions to the Space Flight Operations Contractor. Attention was also given to the risk management plans of the Aero-Space Technology programs, including the X-33, X-34, and X-38. Overall, the Panel concluded that safety is well served for the present. The picture is not as clear for the future. Cutbacks have limited the depth of talent available. In many cases, technical specialties are 'one deep.' The extended hiring freeze has resulted in an older workforce that will inevitably suffer significant departures from retirements in the near future. The resulting 'brain drain' could represent a future safety risk unless appropriate succession planning is started expeditiously. This and other topics are covered in the section addressing workforce. The major NASA programs are also limited in their ability to plan property for the future. This is of particular concern for the Space Shuttle and ISS because these programs are scheduled to operate well into the next century. In the case of the Space Shuttle, beneficial and mandatory safety and operational upgrades are being delayed because of a lack of sufficient present funding. Likewise, the ISS has little flexibility to begin long lead-time items for upgrades or contingency planning. For example, the section on computer hardware and software contains specific findings related to required longer range safety-related actions. NASA can be proud of its accomplishments this past year, but must remain ever vigilant, particularly as ISS assembly begins to accelerate. The Panel will continue to focus on both the short- and long-term aspects of risk management and safety planning. This task continues to be made manageable and productive by the excellent cooperation the Panel receives from both NASA and its contractors. Particular emphasis will continue to be directed to longer term workforce and program planning issues as well as the immediate risks associated with ISS assembly and the initial flights of the X-33 and X-34. Section 2 of this report presents specific findings and recommendations generated by ASAP activities during 1998. Section 3 contains more detailed information in support of these findings and recommendations. Appendix A is a current roster of Panel members, consultants, and staff. Appendix B contains NASA's response to the findings and recommendations from the 1997 ASAP Annual Report. Appendix C details the fact-finding activities of the Panel in 1998. During the year, Mr. Richard D. Blomberg was elected chair of the Panel and Vice Admiral (VADM) Robert F Dunn was elected deputy chair. VADM Bernard M. Kauderer moved from consultant to member. Mr. Charles J. Donlan retired from the Panel after many years of meritorious service. Ms. Shirley C. McCarty and Mr. Robert L. ('Hoot') Gibson joined the Panel as consultants.

Source record↗

Bootstrapping Multi-Agent Unmanned Aerial Vehicle (UAV) System Integration Using Ground-Based Assets: Lessons Learned

In support of the Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR) project, a fleet of unmanned ground vehicles (UGVs) was developed as a test and evaluation (T\&E) platform to reduce system integration gaps between simulation and live flight hardware. While simulation and hardware-in-the-loop bench testing provide adequate environments for preliminary validation, differences in system deployment architecture, software interfaces, and hardware infrastructure increase the risks to safety, property, and the project. Given ATTRACTOR’s goal of establishing a basis of certification of trust and trustworthiness in multi-agent autonomous systems, bridging these gaps was critical to successful project execution and feasibility assessment. In this paper we present the UGV fleet and its role in speeding up system integration, smoothing the transition from simulation to flight, and providing researchers an easy-to-use hardware test bed. An overview of the hardware and software on-board the vehicles is provided along with supporting infrastructure. The system integration process is documented including results in supporting both the overarching design reference mission (DRM) of ATTRACTOR and individual research efforts conducted since the creation of the fleet. Finally, we discuss the practical lessons learned regarding the testing, deployment, and operation of multi-agent autonomous systems.

Matthew P. Vaughan↗

ICAROUS - Integrated Configurable Algorithms for Reliable Operations Of Unmanned Systems

NASA's Unmanned Aerial System (UAS) Traffic Management (UTM) project aims at enabling near-term, safe operations of small UAS vehicles in uncontrolled airspace, i.e., Class G airspace. A far-term goal of UTM research and development is to accommodate the expected rise in small UAS traffic density throughout the National Airspace System (NAS) at low altitudes for beyond visual line-of-sight operations. This paper describes a new capability referred to as ICAROUS (Integrated Configurable Algorithms for Reliable Operations of Unmanned Systems), which is being developed under the UTM project. ICAROUS is a software architecture comprised of highly assured algorithms for building safety-centric, autonomous, unmanned aircraft applications. Central to the development of the ICAROUS algorithms is the use of well-established formal methods to guarantee higher levels of safety assurance by monitoring and bounding the behavior of autonomous systems. The core autonomy-enabling capabilities in ICAROUS include constraint conformance monitoring and contingency control functions. ICAROUS also provides a highly configurable user interface that enables the modular integration of mission-specific software components.

Consiglio, María↗

ICAROUS: Integrated Configurable Architecture for Unmanned Systems

NASA's Unmanned Aerial System (UAS) Traffic Management (UTM) project aims at enabling near-term, safe operations of small UAS vehicles in uncontrolled airspace, i.e., Class G airspace. A far-term goal of UTM research and development is to accommodate the expected rise in small UAS traffic density throughout the National Airspace System (NAS) at low altitudes for beyond visual line-of-sight operations. This video describes a new capability referred to as ICAROUS (Integrated Configurable Algorithms for Reliable Operations of Unmanned Systems), which is being developed under the auspices of the UTM project. ICAROUS is a software architecture comprised of highly assured algorithms for building safety-centric, autonomous, unmanned aircraft applications. Central to the development of the ICAROUS algorithms is the use of well-established formal methods to guarantee higher levels of safety assurance by monitoring and bounding the behavior of autonomous systems. The core autonomy-enabling capabilities in ICAROUS include constraint conformance monitoring and autonomous detect and avoid functions. ICAROUS also provides a highly configurable user interface that enables the modular integration of mission-specific software components.

Consiglio, Maria C.↗

Power, Avionics and Software - Phase 1.0:

This report describes Power, Avionics and Software (PAS) 1.0 subsystem integration testing and test results that occurred in August and September of 2013. This report covers the capabilities of each PAS assembly to meet integration test objectives for non-safety critical, non-flight, non-human-rated hardware and software development. This test report is the outcome of the first integration of the PAS subsystem and is meant to provide data for subsequent designs, development and testing of the future PAS subsystems. The two main objectives were to assess the ability of the PAS assemblies to exchange messages and to perform audio testing of both inbound and outbound channels. This report describes each test performed, defines the test, the data, and provides conclusions and recommendations.

Communiocations↗

A case study of a system engineered for control by humans

Alternatives to the traditional concepts for real time health and safety operations were examined. The pitfalls of the conventional contingency planning for health and safety are highlighted. The Solar Maximum Mission (SMM) contingency planning and operations provides the evolution from the conventional people intensive health and safety operation, toward a night watchman mode of operations. The SMM spacecraft health and safety operations were budget constrained to the point that one operator was responsible for the health and safety of the entire spacecraft one week after launch. The spacecraft was a protoflight with brand new subsystem configurations, software and procedures. To manage the risks associated with this one man SMM health and safety operation, the real time contingency planning and operations centered around unambiguously identifying a system level problem, and reactively safing components susceptible to unrecoverable damage. The methodology applied to both analyzing and implementing this approach of SMM is shown.

Rothenberg, J.↗

Certification Considerations for Adaptive Systems

Advanced capabilities planned for the next generation of aircraft, including those that will operate within the Next Generation Air Transportation System (NextGen), will necessarily include complex new algorithms and non-traditional software elements. These aircraft will likely incorporate adaptive control algorithms that will provide enhanced safety, autonomy, and robustness during adverse conditions. Unmanned aircraft will operate alongside manned aircraft in the National Airspace (NAS), with intelligent software performing the high-level decision-making functions normally performed by human pilots. Even human-piloted aircraft will necessarily include more autonomy. However, there are serious barriers to the deployment of new capabilities, especially for those based upon software including adaptive control (AC) and artificial intelligence (AI) algorithms. Current civil aviation certification processes are based on the idea that the correct behavior of a system must be completely specified and verified prior to operation. This report by Rockwell Collins and SIFT documents our comprehensive study of the state of the art in intelligent and adaptive algorithms for the civil aviation domain, categorizing the approaches used and identifying gaps and challenges associated with certification of each approach.

Bhattacharyya, Siddhartha↗

Coupled Multiphysics Modeling of Lithium-Ion Batteries for Automotive Crashworthiness Applications

Considerable advances have been made in battery safety models, but achieving predictive accuracy across a wide range of conditions continues to be challenging. Interactions between dynamically evolving mechanical, electrical, and thermal state variables make model prediction difficult during mechanical abuse scenarios. In this study, we develop a physics-based modeling approach that allows for choosing between different mechanical and electrochemical models depending on the required level of analysis. We demonstrate the use of this approach to connect cell-level abuse response to electrode-level and particle-level transport phenomena. A pseudo-two-dimensional model and simplified single-particle models are calibrated to electrical-thermal cycling data and applied to mechanically induced short-circuit scenarios to understand how the choice of electrochemical model affects the model prediction under abuse scenarios. These models are implemented using user-defined subroutines on ls-dyna finite element software and can be coupled with existing automotive crash safety models.

analysis and design of components↗

The Need for V&V in Reuse-Based Software Engineering

V&V is currently performed during application development for many systems, especially safety-critical and mission-critical systems. The V&V process is intended to discover errors, especially errors related to entire' domain or product line rather than a critical processing, as early as possible during the development process. The system application provides the context under which the software artifacts are validated. engineering. This paper describes a framework that extends V&V from an individual application system to a product line of systems that are developed within an architecture-based software engineering environment. This framework includes the activities of traditional application-level V&V, and extends these activities into the transition between domain engineering and application engineering. The framework includes descriptions of the types of activities to be performed during each of the life-cycle phases, and provides motivation for activities.

Addy, Edward A.↗

A Verification-Driven Approach to Traceability and Documentation for Auto-Generated Mathematical Software

Model-based development and automated code generation are increasingly used for production code in safety-critical applications, but since code generators are typically not qualified, the generated code must still be fully tested, reviewed, and certified. This is particularly arduous for mathematical and control engineering software which requires reviewers to trace subtle details of textbook formulas and algorithms to the code, and to match requirements (e.g., physical units or coordinate frames) not represented explicitly in models or code. Both tasks are complicated by the often opaque nature of auto-generated code. We address these problems by developing a verification-driven approach to traceability and documentation. We apply the AUTOCERT verification system to identify and then verify mathematical concepts in the code, based on a mathematical domain theory, and then use these verified traceability links between concepts, code, and verification conditions to construct a natural language report that provides a high-level structured argument explaining why and how the code uses the assumptions and complies with the requirements. We have applied our approach to generate review documents for several sub-systems of NASA s Project Constellation.

Denney, Ewen W.↗

Resilient Space Habitat Design Using Safety Controls

Space habitats will involve a complex and tightly coupled combination of hardware, software, and humans, while operating in challenging environments that pose many risks, both known and unknown. It will not be possible to design habitats that are immune to failure, nor will it be possible to foresee all possible failures. Rather than aiming for designs where ―failure is not an option,‖ habitats must be resilient to disruptions. We propose an approach to resilient design for space habitats based on the concept of safety controls from system safety engineering. We model disruptions using a state-and-trigger approach, where the space habitat is in one of three distinct states at each time instance: nominal, hazardous, or accident. We use safety controls as ways of preventing a system from entering or remaining in a hazardous or accident state. We develop a safety control option space for the habitat, from which designers can select the set of safety controls that best meet resilience, performance, and other system goals. The safety control option space is likely to be large, accordingly, we design a database that links safety controls to the applicable states and triggers. We demonstrate our approach on the early design stage of a Martian space habitat.

Safety↗

Implementation and Simulation Results using Autonomous Aerobraking Development Software

An Autonomous Aerobraking software system is currently under development with support from the NASA Engineering and Safety Center (NESC) that would move typically ground-based operations functions to onboard an aerobraking spacecraft, reducing mission risk and mission cost. The suite of software that will enable autonomous aerobraking is the Autonomous Aerobraking Development Software (AADS) and consists of an ephemeris model, onboard atmosphere estimator, temperature and loads prediction, and a maneuver calculation. The software calculates the maneuver time, magnitude and direction commands to maintain the spacecraft periapsis parameters within design structural load and/or thermal constraints. The AADS is currently tested in simulations at Mars, with plans to also evaluate feasibility and performance at Venus and Titan.

Maddock, Robert W.↗

NASA's Aviation Safety and Modeling Project

The Aviation Safety Monitoring and Modeling (ASMM) Project of NASA's Aviation Safety program is cultivating sources of data and developing automated computer hardware and software to facilitate efficient, comprehensive, and accurate analyses of the data collected from large, heterogeneous databases throughout the national aviation system. The ASMM addresses the need to provide means for increasing safety by enabling the identification and correcting of predisposing conditions that could lead to accidents or to incidents that pose aviation risks. A major component of the ASMM Project is the Aviation Performance Measuring System (APMS), which is developing the next generation of software tools for analyzing and interpreting flight data.

Chidester, Thomas R.↗