Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20

Challenges in verification and validation of autonomous systems for space exploration

Space exploration applications offer a unique opportunity for the development and deployment of autonomous systems, due to limited communications, large distances, and great expense of direct operation. At the same time, the risk and cost of space missions leads to reluctance to taking on new, complex and difficult-to-understand technology. A key issue in addressing these concerns is the validation of autonomous systems. In recent years, higher-level autonomous systems have been applied in space applications. In this presentation, we will highlight those autonomous systems, and discuss issues in validating these systems. We will then look to future demands on validating autonomous systems for space, identify promising technologies and open issues.

Brat, Guillaume↗

Use of multiple gauges and microwave attenuation of precipitation for satellite verification

In this paper both a microwave attenuation measurement along a horizontal line and multiple point gauge measurements are analyzed as possible ground-truth designs to validate satellite precipitation retrieval algorithms at the field of view spatial level (typically about 20 km). The design consists of comparing a sequence of pairs of contemporaneous measurements taken from the ground and from space. The authors examine theoretically the variance of expected differences between the two systems. The line average measurement leads to a smaller mean-square error compared to the case of a single point gauge, since some of the small-scale variability of the rain field is smoothed away by the line integration. The multiple point gauge measurements also give smaller mean-square error than that of a single point gauge. The centroid of the line and point gauge configurations are considered to be located randomly inside the field of view for different overpasses. A space-time spectral formalism is used with a noise-forced diffusive rain field to find the mean-square error. By considering instantaneous ground and satellite measurement pairs over about 50 visits when raining, we can reduce the expected error to approximately 10% of the standard deviation of climatological variability. This is considered to be a useful level of tolerance for identifying biases in the retrieval algorithms. It is found that the multiple point gauges (especially two gauges) are the economical ground-truth design compared to the microwave attenuation based on the mean-square error comparison. The major finding of this study is that a significant improvement over the point gauge is obtained by adding a single additional piece of information; adding more gauges or extending the line of attenuation is not an important improvement.

Ha, Eunho↗

Submicrosecond comparison of international clock synchronization by VLBI and the NTS satellite

The intercontinental clock synchronization capabilities of Very Long Baseline Interferometry (VLBI) and the Navigation Technology Satellite (NTS) were compared using both methods to synchronize the Cesium clocks at the NASA Deep Space Net complexes at Madrid, Spain and Goldstone, California. Verification of the accuracy of both systems was examined. The VLBI experiments used the Wideband VLBI Data Acquisition System developed at the NASA Jet Propulsion Laboratory. The NTS Satellites were designed and built by the Naval Research Laboratory used with NTS Timing Receivers developed by the Goddard Space Flight Center. The two methods agreed at about the one-half microsecond level.

Hurd, W. J.↗

Navigating United States Standards and Regulation for Digital Energy Systems

This report provides an analysis of the U.S. standards and regulatory landscape for digital energy systems, focusing on cybersecurity, safety, and reliability requirements. It examines the interplay between federal mandates, state regulations, voluntary industry standards, and utility-specific policies, highlighting critical gaps between compliance and real-world risk mitigation. While NERC CIP standards enforce cybersecurity for Bulk Electric System assets, distribution-level infrastructure and emerging technologies often fall outside mandatory oversight, creating vulnerabilities. The report identifies systemic challenges such as reliance on self-attestation, uneven state adoption of safety codes, and lagging standards for advanced technologies like battery energy storage and inverter-based resources. Through a detailed gap analysis, it underscores the urgency of proactive risk-based approaches, independent verification, and strategic engagement with state and federal entities. Recommendations include adopting tiered security frameworks, strengthening procurement practices, and addressing emerging technology risks to ensure resilient and secure digital energy infrastructure. This guidance is intended for utilities, regulators, and stakeholders navigating compliance obligations and seeking to enhance cybersecurity and safety beyond minimum standards.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Precise and Scalable Static Program Analysis of NASA Flight Software

Recent NASA mission failures (e.g., Mars Polar Lander and Mars Orbiter) illustrate the importance of having an efficient verification and validation process for such systems. One software error, as simple as it may be, can cause the loss of an expensive mission, or lead to budget overruns and crunched schedules. Unfortunately, traditional verification methods cannot guarantee the absence of errors in software systems. Therefore, we have developed the CGS static program analysis tool, which can exhaustively analyze large C programs. CGS analyzes the source code and identifies statements in which arrays are accessed out of bounds, or, pointers are used outside the memory region they should address. This paper gives a high-level description of CGS and its theoretical foundations. It also reports on the use of CGS on real NASA software systems used in Mars missions (from Mars PathFinder to Mars Exploration Rover) and on the International Space Station.

Brat, G.↗

Microthruster Propulsion for the Space Technology 7 (ST7) Technology Demonstration Mission

For future applications to precision formation flying missions, NASA's New Millennium Program is scheduled to test colloid micro-Newton thrusters (CMNTs) on the ST7 technology demonstration mission. These CMNTs are part of a disturbance reduction system (DRS) on the ESA SMART-2 Spacecraft or LISA Pathfinder. The goal of the ST7 DRS is to demonstrate technologies necessary to meet the nanometer precision positioning control requirements of the LISA mission. In order to achieve these goals, the CMNTs are required to demonstrate a thrust resolution of less than 0.1 micro-N and a thrust noise of less than 0.1 micro-N/[square root]Hz for thrust levels between 5 and 30 micro-N. Developed by Busek Co. with support from JPL in testing an design, the CMNT has been developed over the last four years into a flight-ready microthrust system. The development, validation testing, and flight unit production of the CMNTs are described. Development tests and analysis include preliminary wear tests, propellant loading process verification, flow testing, and performance verification. Validation and flight unit verification includes thermal and structural analysis, life testing, thermal and dynamic load testing, and performance verification. Final delivery of the units is planned in 2007 with and planned launch and flight demonstration 2009.

microthruster↗

Requirement Development Process and Tools

Requirements capture the system-level capabilities in a set of complete, necessary, clear, attainable, traceable, and verifiable statements of need. Requirements should not be unduly restrictive, but should set limits that eliminate items outside the boundaries drawn, encourage competition (or alternatives), and capture source and reason of requirement. If it is not needed by the customer, it is not a requirement. They establish the verification methods that will lead to product acceptance. These must be reproducible assessment methods.

Tools↗

Handling Qualities of Model Reference Adaptive Controllers with Varying Complexity for Pitch-Roll Coupled Failures

Three model reference adaptive controllers (MRAC) with varying levels of complexity were evaluated on a high performance jet aircraft and compared along with a baseline nonlinear dynamic inversion controller. The handling qualities and performance of the controllers were examined during failure conditions that induce coupling between the pitch and roll axes. Results from flight tests showed with a roll to pitch input coupling failure, the handling qualities went from Level 2 with the baseline controller to Level 1 with the most complex MRAC tested. A failure scenario with the left stabilator frozen also showed improvement with the MRAC. Improvement in performance and handling qualities was generally seen as complexity was incrementally added; however, added complexity usually corresponds to increased verification and validation effort required for certification. The tradeoff between complexity and performance is thus important to a controls system designer when implementing an adaptive controller on an aircraft. This paper investigates this relation through flight testing of several controllers of vary complexity.

Schaefer, Jacob↗

Structural Element Testing in Support of the Design of the NASA Composite Crew Module

In January 2007, the NASA Administrator and Associate Administrator for the Exploration Systems Mission Directorate chartered the NASA Engineering and Safety Center (NESC) to design, build, and test a full-scale Composite Crew Module (CCM). For the design and manufacturing of the CCM, the team adopted the building block approach where design and manufacturing risks were mitigated through manufacturing trials and structural testing at various levels of complexity. Following NASA's Structural Design Verification Requirements, a further objective was the verification of design analysis methods and the provision of design data for critical structural features. Test articles increasing in complexity from basic material characterization coupons through structural feature elements and large structural components, to full-scale structures were evaluated. This paper discusses only four elements tests three of which include joints and one that includes a tapering honeycomb core detail. For each test series included are specimen details, instrumentation, test results, a brief analysis description, test analysis correlation and conclusions.

Kellas, Sotiris↗

Cryogenic propellant management: Integration of design, performance and operational requirements

The integration of the design features of the Shuttle elements into a cryogenic propellant management system is described. The implementation and verification of the design/operational changes resulting from design deficiencies and/or element incompatibilities encountered subsequent to the critical design reviews are emphasized. Major topics include: subsystem designs to provide liquid oxygen (LO2) tank pressure stabilization, LO2 facility vent for ice prevention, liquid hydrogen (LH2) feedline high point bleed, pogo suppression on the Space Shuttle Main Engine (SSME), LO2 low level cutoff, Orbiter/engine propellant dump, and LO2 main feedline helium injection for geyser prevention.

Worlund, A. L.↗

Thermal Expansion of Polyurethane Foam

Closed cell foams are often used for thermal insulation. In the case of the Space Shuttle, the External Tank uses several thermal protection systems to maintain the temperature of the cryogenic fuels. A few of these systems are polyurethane, closed cell foams. In an attempt to better understand the foam behavior on the tank, we are in the process of developing and improving thermal-mechanical models for the foams. These models will start at the microstructural level and progress to the overall structural behavior of the foams on the tank. One of the key properties for model characterization and verification is thermal expansion. Since the foam is not a material, but a structure, the modeling of the expansion is complex. It is also exacerbated by the anisoptropy of the material. During the spraying and foaming process, the cells become elongated in the rise direction and this imparts different properties in the rise direction than in the transverse directions. Our approach is to treat the foam as a two part structure consisting of the polymeric cell structure and the gas inside the cells. The polymeric skeleton has a thermal expansion of its own which is derived from the basic polymer chemistry. However, a major contributor to the thermal expansion is the volume change associated with the gas inside of the closed cells. As this gas expands it exerts pressure on the cell walls and changes the shape and size of the cells. The amount that this occurs depends on the elastic and viscoplastic properties of the polymer skeleton. The more compliant the polymeric skeleton, the more influence the gas pressure has on the expansion. An additional influence on the expansion process is that the polymeric skeleton begins to breakdown at elevated temperatures and releases additional gas species into the cell interiors, adding to the gas pressure. The fact that this is such a complex process makes thermal expansion ideal for testing the models. This report focuses on the thermal expansion tests and the response of the microstructure. A novel optical method is described which is appropriate for measuring thermal expansion at high temperatures without influencing the thermal expansion measurement. Detailed microstructural investigations will also be described which show cell expansion as a function of temperature. Finally, a phenomenological model on thermal expansion will be described.

Lerch, Bradley A.↗

Application Agreement and Integration Services

Application agreement and integration services are required by distributed, fault-tolerant, safety critical systems to assure required performance. An analysis of distributed and hierarchical agreement strategies are developed against the backdrop of observed agreement failures in fielded systems. The documented work was performed under NASA Task Order NNL10AB32T, Validation And Verification of Safety-Critical Integrated Distributed Systems Area 2. This document is intended to satisfy the requirements for deliverable 5.2.11 under Task 4.2.2.3. This report discusses the challenges of maintaining application agreement and integration services. A literature search is presented that documents previous work in the area of replica determinism. Sources of non-deterministic behavior are identified and examples are presented where system level agreement failed to be achieved. We then explore how TTEthernet services can be extended to supply some interesting application agreement frameworks. This document assumes that the reader is familiar with the TTEthernet protocol. The reader is advised to read the TTEthernet protocol standard [1] before reading this document. This document does not re-iterate the content of the standard.

Driscoll, Kevin R.↗

Detector power linearity requirements and verification techniques for TMI direct detection receivers

A system (36, 98) for determining the linearity of an RF detector (46, 106). A first technique involves combining two RF signals from two stable local oscillators (38, 40) to form a modulated RF signal having a beat frequency, and applying the modulated RF signal to a detector (46) being tested. The output of the detector (46) is applied to a low frequency spectrum analyzer (48) such that a relationship between the power levels of the first and second harmonics generated by the detector (46) of the beat frequency of the modulated RF signal are measured by the spectrum analyzer (48) to determine the linearity of the detector (46). In a second technique, an RF signal from a local oscillator (100) is applied to a detector (106) being tested through a first attenuator (102) and a second attenuator (104). The output voltage of the detector (106) is measured when the first attenuator (102) is set to a particular attenuation value and the second attenuator (104) is switched between first and second attenuation values. Further, the output voltage of the detector (106) is measured when the first attenuator (102) is set to another attenuation value, and the second attenuator (104) is again switched between the first and second attenuation values. A relationship between the voltage outputs determines the linearity of the detector (106).

Reinhardt, Victor S.↗

Adopting an Objectives-Driven Assurance Case Approach for Achieving Space Flight Mission Planetary Protection Objectives

Traditionally, the National Aeronautics and Space Administration (NASA) has utilized prescriptive technical and process requirements to ensure safety and mission assurance performance objectives for planetary protection are achieved during space flight missions. While prescriptive requirements may be easier to communicate and manage throughout the systems engineering process, the highly constrained nature of prescriptive requirements can limit the ability to take advantage of cost-saving opportunities and offer limited ability to explore other options or alternative designs, processes, and methods. It can also be difficult to develop prescriptive requirements for objectives that are probabilistic in nature or that cannot be satisfied by direct verification. In contrast, the development of an assurance case allows for a compelling, comprehensible, and valid argument to be developed with supporting evidence that shows safety and mission assurance objectives have been satisfied. Analogous to how patent applications are constructed for inventions, an assurance case has a high-level claim of meeting a safety and mission assurance objective, followed by a more specific set of sub-claims and technical evidence which supports the claims. The objectives-driven assurance case approach allows for a better understanding and exploration of the trade space, more flexibility to balance trades, and the ability to realize and implement technical and process innovations for resource, time, and cost savings. The assurance case is a living case that evolves over the entire program life cycle. Recently, NASA’s Office of Planetary Protection (OPP) has adopted the assurance case approach as an acceptable methodology for demonstrating avoidance of contamination of target solar system bodies explored by NASA space flight missions. This methodology has been incorporated into NASA’s new technical standard for planetary protection and is currently being utilized by the Mars Sample Return campaign for safe sample containment during sample return.

Assurance Case↗

Motion simulator study of longitudinal stability requirements for large delta wing transport airplanes during approach and landing with stability augmentation systems failed

A ground-based simulator investigation was conducted in preparation for and correlation with an-flight simulator program. The objective of these studies was to define minimum acceptable levels of static longitudinal stability for landing approach following stability augmentation systems failures. The airworthiness authorities are presently attempting to establish the requirements for civil transports with only the backup flight control system operating. Using a baseline configuration representative of a large delta wing transport, 20 different configurations, many representing negative static margins, were assessed by three research test pilots in 33 hours of piloted operation. Verification of the baseline model to be used in the TIFS experiment was provided by computed and piloted comparisons with a well-validated reference airplane simulation. Pilot comments and ratings are included, as well as preliminary tracking performance and workload data.

Snyder, C. T.↗

External Contamination Control of Attached Payloads on the International Space Station

The International Space Station (ISS) is an on-orbit platform for science utilization in low Earth orbit with multiple sites for external payloads with exposure to the natural and induced environments. Contamination is one of the induced environments that can impact performance, mission success and science utilization on the vehicle. This paper describes the external contamination control requirements and integration process for externally mounted payloads on the ISS. The external contamination control requirements are summarized and a description of the integration and verification process is detailed to guide payload developers in the certification process of attached payloads on the vehicle. A description of the required data certification deliverables covers the characterization of contamination sources. Such characterization includes identification, usage and operational data for each class of contamination source. Classes of external contamination sources covered are vacuum exposed materials, sources of leakage, vacuum venting and thrusters. ISS system level analyses are conducted by the ISS Space Environments Team to certify compliance with external contamination control requirements. This paper also addresses the ISS induced contamination environment at attached payload sites, both at the requirements level as well as measurements made on ISS.

Soares, Carlos E.↗

Synthetic Vision Systems - Operational Considerations Simulation Experiment

Synthetic vision is a computer-generated image of the external scene topography that is generated from aircraft attitude, high-precision navigation information, and data of the terrain, obstacles, cultural features, and other required flight information. A synthetic vision system (SVS) enhances this basic functionality with real-time integrity to ensure the validity of the databases, perform obstacle detection and independent navigation accuracy verification, and provide traffic surveillance. Over the last five years, NASA and its industry partners have developed and deployed SVS technologies for commercial, business, and general aviation aircraft which have been shown to provide significant improvements in terrain awareness and reductions in the potential for Controlled-Flight-Into-Terrain incidents/accidents compared to current generation cockpit technologies. It has been hypothesized that SVS displays can greatly improve the safety and operational flexibility of flight in Instrument Meteorological Conditions (IMC) to a level comparable to clear-day Visual Meteorological Conditions (VMC), regardless of actual weather conditions or time of day. An experiment was conducted to evaluate SVS and SVS-related technologies as well as the influence of where the information is provided to the pilot (e.g., on a Head-Up or Head-Down Display) for consideration in defining landing minima based upon aircraft and airport equipage. The "operational considerations" evaluated under this effort included reduced visibility, decision altitudes, and airport equipage requirements, such as approach lighting systems, for SVS-equipped aircraft. Subjective results from the present study suggest that synthetic vision imagery on both head-up and head-down displays may offer benefits in situation awareness; workload; and approach and landing performance in the visibility levels, approach lighting systems, and decision altitudes tested.

Kramer, Lynda J.↗

Progress Towards the Validation of a new RELAP5-3D model of the High Temperature Test Facility

Validation is a key step in the development of any type of systems model. As the next generation of reactors approaches, the need for codes that have been validated for these new types of systems continues to grow. An example of a prominent option is the Reactor Excursion Leak Analysis Program (RELAP5-3D), developed by Idaho National Laboratory. This code was developed for the purpose of systems level thermal-hydraulic modeling of light water reactors (LWRS) and postulated transients that can occur in LWRS.RELAP5-3D has been substantially validated against LWR data. Due to its long history as a reactor safety analysis tool, there has been an effort to adapt RELAP5-3D for the purposes of advanced reactor concepts such as prismatic high-temperature gas-cooled reactors (HTGRs). However, RELAP5-3D has not nearly been validated and verified for HTGRs to the degree of LWRs, warranting verification and validation opportunities with computational benchmarks and existing experimental facilities. Examples of such facilities include the modular high-temperature gas-cooled reactor (MHTGR) 350 and the high temperature engineering test reactor (HTTR) from Japan. The MHTGR 350 is a benchmark design concept for code-to-code verification purposes; therefore, it does not provide any experimental data for validation opportunities The HTTR provides useful multiphysics validation data but does not have the in-core instruments to generate thermal-hydraulic experimental data to help with RELAP5-3D validation. Consequently, a facility that could provide key in-core temperatures for thermal-hydraulic validation was still needed. The High Temperature Test Facility (HTTF) is an integral effects facility for HTGR thermal hydraulics developed and operated by Oregon State University. HTTF represents ¼ length scale of the General Atomics MHTGR and is rated for a total power of 2.2 MW. Axially, the core consists of an upper and lower reflector and 10 blocks, numbered from bottom to top (Block 1 is right above lower reflector). The core is heated via graphite resistive heater rods, with respective channels distributed throughout the core. The primary coolant is helium and heat can radiate out of the core to the reactor cavity cooling system (RCCS), which is cooled by water. The primary purpose of the facility is to investigate pressurized conduction cooldown (PCC) and depressurized conduction cooldown (DCC) transients, which are also referred to as the pressurized and depressurized loss of forced cooling respectively. Two experiments were chosen to perform the validation study with a RELAP5-3D model of HTTF. These experiments are PG-27 (PCC) and PG-29 (DCC). These were chosen based off of the quality of available experimental data before and during the experiment which led to their inclusion in the HTGR Thermal Hydraulics Benchmark.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗