Search NASA⌕ Search

SEARCH · Search NASA

Results for “proof”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 361 records · Page 20

Fault-tolerant clock synchronization validation methodology

A validation method for the synchronization subsystem of a fault-tolerant computer system is presented. The high reliability requirement of flight-crucial systems precludes the use of most traditional validation methods. The method presented utilizes formal design proof to uncover design and coding errors and experimentation to validate the assumptions of the design proof. The experimental method is described and illustrated by validating the clock synchronization system of the Software Implemented Fault Tolerance computer. The design proof of the algorithm includes a theorem that defines the maximum skew between any two nonfaulty clocks in the system in terms of specific system parameters. Most of these parameters are deterministic. One crucial parameter is the upper bound on the clock read error, which is stochastic. The probability that this upper bound is exceeded is calculated from data obtained by the measurement of system parameters. This probability is then included in a detailed reliability analysis of the system.

Computer systems↗

Superconducting six-axis accelerometer

A new superconducting accelerometer, capable of measuring both linear and angular accelerations, is under development at the University of Maryland. A single superconducting proof mass is magnetically levitated against gravity or any other proof force. Its relative positions and orientations with respect to the platform are monitored by six superconducting inductance bridges sharing a single amplifier, called the Superconducting Quantum Interference Device (SQUID). The six degrees of freedom, the three linear acceleration components and the three angular acceleration components, of the platform are measured simultaneously. In order to improve the linearity and the dynamic range of the instrument, the demodulated outputs of the SQUID are fed back to appropriate levitation coils so that the proof mass remains at the null position for all six inductance bridges. The expected intrinsic noise of the instrument is 4 x 10(exp -12)m s(exp -2) Hz(exp -1/2) for linear acceleration and 3 x 10(exp -11) rad s(exp -2) Hz(exp -1/2) for angular acceleration in 1-g environment. In 0-g, the linear acceleration sensitivity of the superconducting accelerometer could be improved by two orders of magnitude. The design and the operating principle of a laboratory prototype of the new instrument is discussed.

Paik, H. J.↗

A HOL theory for voting

Central to fault-tolerant computing is redundancy management, and common to proofs of fault-tolerance is a maximum fault assumption. Typically a maximum fault assumption is rather restrictive. Usually, this is necessary to avoid assumptions about the behavior of faulty channels. A maximum fault assumption is useful because it allows reasoning about fault tolerance in the presence of arbitrarily malicious fault behavior. However, analysis of the architecture may establish certain scenarios in which the assumption may be weakened. Proofs comparing majority and plurality and proofs of simple reconfiguration strategies are presented in viewgraph form.

Miner, Paul S.↗

Mechanical verification of a schematic Byzantine clock synchronization algorithm

Schneider generalizes a number of protocols for Byzantine fault tolerant clock synchronization and presents a uniform proof for their correctness. The authors present a machine checked proof of this schematic protocol that revises some of the details in Schneider's original analysis. The verification was carried out with the EHDM system developed at the SRI Computer Science Laboratory. The mechanically checked proofs include the verification that the egocentric mean function used in Lamport and Melliar-Smith's Interactive Convergence Algorithm satisfies the requirements of Schneider's protocol.

Shankar, Natarajan↗

Report on the formal specification and partial verification of the VIPER microprocessor

The VIPER microprocessor chip is partitioned into four levels of abstractions. At the highest level, VIPER is described with decreasingly abstract sets of functions in LCF-LSM. At the lowest level are the gate-level models in proprietary CAD languages. The block-level and gate-level specifications are also given in the ELLA simulation language. Among VIPER's deficiencies are the fact that there is no notion of external events in the top-level specification, and it is impossible to use the top-level specifications to prove abstract properties of programs running on VIPER computers. There is no complete proof that the gate-level specifications implement the top-level specifications. Cohn's proof that the major-state machine correctly implements the top-level specifications has no formal connection with any of the other proof attempts. None of the latter address resetting the machine, memory timeout, forced error, or single step modes.

Brock, Bishop↗

Formal verification of a microcoded VIPER microprocessor using HOL

The Royal Signals and Radar Establishment (RSRE) and members of the Hardware Verification Group at Cambridge University conducted a joint effort to prove the correspondence between the electronic block model and the top level specification of Viper. Unfortunately, the proof became too complex and unmanageable within the given time and funding constraints, and is thus incomplete as of the date of this report. This report describes an independent attempt to use the HOL (Cambridge Higher Order Logic) mechanical verifier to verify Viper. Deriving from recent results in hardware verification research at UC Davis, the approach has been to redesign the electronic block model to make it microcoded and to structure the proof in a series of decreasingly abstract interpreter levels, the lowest being the electronic block level. The highest level is the RSRE Viper instruction set. Owing to the new approach and some results on the proof of generic interpreters as applied to simple microprocessors, this attempt required an effort approximately an order of magnitude less than the previous one.

Levitt, Karl↗

Development of airborne eddy-correlation flux measurement capabilities for reactive oxides of nitrogen

This research is aimed at producing a fundamental new research tool for characterizing the source strength of the most important compound controlling the hemispheric and global scale distribution of tropospheric ozone. Specifically, this effort seeks to demonstrate the proof-of-concept of a new general purpose laser-induced fluorescence based spectrometer for making airborne eddy-correlation flux measurements of nitric oxide (NO) and other reactive nitrogen compounds. The new all solid-state laser technology being used in this advanced sensor will produce a forerunner of the type of sensor technology that should eventually result in highly compact operational systems. The proof-of-concept sensor being developed will have over two orders-of-magnitude greater sensitivity than present-day instruments. In addition, this sensor will offer the possibility of eventual extension to airborne eddy-correlation flux measurements of nitrogen dioxide (NO2) and possibly other compounds, such as ammonia (NH3), peroxyradicals (HO2), nitrateradicals (NO3) and several iodine compounds (e.g., I and IO). Demonstration of the new sensor's ability to measure NO fluxes will occur through a series of laboratory and field tests. This proof-of-concept demonstration will show that not only can airborne fluxes of important ultra-trace compounds be made at the few parts-per-trillion level, but that the high accuracy/precision measurements currently needed for predictive models can also. These measurement capabilities will greatly enhance our current ability to quantify the fluxes of reactive nitrogen into the troposphere and significantly impact upon the accuracy of predictive capabilities to model O3's distribution within the remote troposphere. This development effort also offers a timely approach for producing the reactive nitrogen flux measurement capabilities that will be needed by future research programs such as NASA's planned 1999 Amazon Biogeochemistry and Atmospheric Chemistry Experimental portion of LBA.

Bradshaw, John↗

Defect Characterization in a Thin Walled Composite RP-1 Tank: A Case Study

A full scale thin walled composite tank, designed and fabricated for the storage of pressurized RP- I rocket fuel, was fully inspected with digital infrared thermography (IR) during assembly and prior to proof testing. The tank featured a "pill capsule" design with the equatorial bondline being overwrapped on both the inner and outer surfaces. A composite skirt was bonded to the aft dome of the tank to serve as a structural support when the tank was stood on end in service. Numerous anomalies were detected and mapped prior to proof testing, some along bondlines and some scattered throughout the acreage. After the tank was intentionally burst, coupons were cut from the regions including thermographic anomalies. These coupons were again inspected thermographically to document the growth of any indications due to proof testing. Ultrasonic inspections (UT) were also performed on the coupons for comparison to thermography. Several coupons were dissected and micrographed. Relationships between IR and UT indications and the physical nature of the dissected material are presented.

Langsing, Matthew D.↗

LISA Optics Model: Early Results

The Laser Interferometer Space Antenna (LISA) optics model is used to generate a synthetic data stream in the absence of gravitational waves. The simulation has the spacecraft in moving in their respective Keplerian orbits. The pointing of the spacecraft and station keeping about the proof masses is accomplished using a control scheme, which minimizes the disturbance on the proof masses in the sensitive direction. The resulting data stream gives an indication of the magnitude of instrumental noise due to pointing jitter and motions of the spacecraft with respect to the proof masses. Computational details are presented and the results discussed.

Waluschka, Eugene↗

NASA Ultra-Sensitive Miniature Accelerometer

Using micro-machined silicon technology, an ultra-sensitive miniature acce.,rometer can be constructed which meets the requirements for microgravity experiments in the space environment.Such an accelerometer will have a full scale sensitivity of 1C2 g a resolution of lC8 g, low cross axis sensitivity, and low temperature sensitivity. Mass of the device is approximately five grams and its footprint is 2 cm x 2 cm. Innovative features of the accelerometer, which are patented, are: electrostatic caging to withstand handling shock up to 150 g, in-situ calibration, in situ performance characterization, and both static and dynamic compensation. The transducer operates on a force balance principle wherein the displacement of the proof mass is monitored by measuring tunneling electron current flow between a conductive tip, and a fixed platen. The four major parts of the accelerometer are tip die, incorporating the tunneling tip and four field plates for controlling pitch and roll of the proof mass; two proof mass dies, attached to the surrounding frame by sets of four leg" springs; and a force plate die. The four parts are fuse-bonded into a complete assembly. External electrical connections are made at bond pads on the front surface of the force plate die. Materials and processes used in the construction of the transducer are compatible with volume production.

Zavracky, Paul M.↗

LISA Thermal Design

The Laser Interferometer Space Antenna (LISA) mission, a space based gravitational wave detector, uses laser metrology to measure distance fluctuations between proof masses aboard three spacecraft. The total acceleration disturbance to each proof mass is required to be below 3 x 10(exp -15) meters per second squared per the square root of Hertz. Optical path length variations on each optical bench must be kept below about 3 pm per the square root of Hertz. Noise due to spacecraft thermal distortions, temperature difference variations across proof mass housing, and other thermal effects are expected to be a significant contributors to these noise budgets. The LISA Integrated Modeling team developed a detailed thermal model that is currently being used to drive the design of LISA. Several new thermal analysis techniques are also being developed in order to achieve model accuracies to LISA levels. We present here an overview of the LISA thermal design and modeling efforts. The latest thermal results calculated using the current baseline design of LISA are also discussed.

Merkowitz, Stephen↗

Creep Strain and Strain Rate Response of 2219 Al Alloy at High Stress Levels

As a result of high localized plastic deformation experienced during proof testing in an International Space Station connecting module, a study was undertaken to determine the deformation response of a 2219-T851 roll forging. After prestraining 2219-T851 Al specimens to simulate strains observed during the proof testing, creep tests were conducted in the temperature range from ambient temperature to 107 C (225 F) at stress levels approaching the ultimate tensile strength of 2219-T851 Al. Strain-time histories and strain rate responses were examined. The strain rate response was extremely high initially, but decayed rapidly, spanning as much as five orders of magnitude during primary creep. Select specimens were subjected to incremental step loading and exhibited initial creep rates of similar magnitude for each load step. Although the creep rates decreased quickly at all loads, the creep rates dropped faster and reached lower strain rate levels for lower applied loads. The initial creep rate and creep rate decay associated with primary creep were similar for specimens with and without prestrain; however, prestraining (strain hardening) the specimens, as in the aforementioned proof test, resulted in significantly longer creep life.

Taminger, Karen M. B.↗

An all-silicon single-wafer micro-g accelerometer with a combined surface and bulk micromachining process

This paper reports an all-silicon fully symmetrical z-axis micro-g accelerometer that is fabricated on a single-silicon wafer using a combined surface and bulk fabrication process. The microaccelerometer has high device sensitivity, low noise, and low/controllable damping that are the key factors for attaining micro g and sub-micro g resolution in capacitive accelerometers. The microfabrication process produces a large proof mass by using the whole wafer thickness and a large sense capacitance by utilizing a thin sacrificial layer. The sense/feedback electrodes are formed by a deposited 2-3 microns polysilicon film with embedded 25-35 microns-thick vertical stiffeners. These electrodes, while thin, are made very stiff by the thick embedded stiffeners so that force rebalancing of the proof mass becomes possible. The polysilicon electrodes are patterned to create damping holes. The microaccelerometers are batch-fabricated, packaged, and tested successfully. A device with a 2-mm x 1-mm proof mass and a full bridge support has a measured sensitivity of 2 pF/g. The measured sensitivity of a 4-mm x 1-mm accelerometer with a cantilever support is 19.4 pF/g. The calculated noise floor of these devices at atmosphere are 0.23 micro g/sqrt(Hz) and 0.16 micro g/sqrt(Hz), respectively.

Non-NASA Center↗

A Program Certification Assistant Based on Fully Automated Theorem Provers

We describe a certification assistant to support formal safety proofs for programs. It is based on a graphical user interface that hides the low-level details of first-order automated theorem provers while supporting limited interactivity: it allows users to customize and control the proof process on a high level, manages the auxiliary artifacts produced during this process, and provides traceability between the proof obligations and the relevant parts of the program. The certification assistant is part of a larger program synthesis system and is intended to support the deployment of automatically generated code in safety-critical applications.

Denney, Ewen↗

Software Certification for Temporal Properties With Affordable Tool Qualification

It has been recognized that a framework based on proof-carrying code (also called semantic-based software certification in its community) could be used as a candidate software certification process for the avionics industry. To meet this goal, tools in the "trust base" of a proof-carrying code system must be qualified by regulatory authorities. A family of semantic-based software certification approaches is described, each different in expressive power, level of automation and trust base. Of particular interest is the so-called abstraction-carrying code, which can certify temporal properties. When a pure abstraction-carrying code method is used in the context of industrial software certification, the fact that the trust base includes a model checker would incur a high qualification cost. This position paper proposes a hybrid of abstraction-based and proof-based certification methods so that the model checker used by a client can be significantly simplified, thereby leading to lower cost in tool qualification.

Xia, Songtao↗

Formal Safety Certification of Aerospace Software

In principle, formal methods offer many advantages for aerospace software development: they can help to achieve ultra-high reliability, and they can be used to provide evidence of the reliability claims which can then be subjected to external scrutiny. However, despite years of research and many advances in the underlying formalisms of specification, semantics, and logic, formal methods are not much used in practice. In our opinion this is related to three major shortcomings. First, the application of formal methods is still expensive because they are labor- and knowledge-intensive. Second, they are difficult to scale up to complex systems because they are based on deep mathematical insights about the behavior of the systems (t.e., they rely on the "heroic proof"). Third, the proofs can be difficult to interpret, and typically stand in isolation from the original code. In this paper, we describe a tool for formally demonstrating safety-relevant aspects of aerospace software, which largely circumvents these problems. We focus on safely properties because it has been observed that safety violations such as out-of-bounds memory accesses or use of uninitialized variables constitute the majority of the errors found in the aerospace domain. In our approach, safety means that the program will not violate a set of rules that can range for the simple memory access rules to high-level flight rules. These different safety properties are formalized as different safety policies in Hoare logic, which are then used by a verification condition generator along with the code and logical annotations in order to derive formal safety conditions; these are then proven using an automated theorem prover. Our certification system is currently integrated into a model-based code generation toolset that generates the annotations together with the code. However, this automated formal certification technology is not exclusively constrained to our code generator and could, in principle, also be integrated with other code generators such as RealTime Workshop or even applied to legacy code. Our approach circumvents the historical problems with formal methods by increasing the degree of automation on all levels. The restriction to safety policies (as opposed to arbitrary functional behavior) results in simpler proof problems that can generally be solved by fully automatic theorem proves. An automated linking mechanism between the safety conditions and the code provides some of the traceability mandated by process standards such as DO-178B. An automated explanation mechanism uses semantic markup added by the verification condition generator to produce natural-language explanations of the safety conditions and thus supports their interpretation in relation to the code. It shows an automatically generated certification browser that lets users inspect the (generated) code along with the safety conditions (including textual explanations), and uses hyperlinks to automate tracing between the two levels. Here, the explanations reflect the logical structure of the safety obligation but the mechanism can in principle be customized using different sets of domain concepts. The interface also provides some limited control over the certification process itself. Our long-term goal is a seamless integration of certification, code generation, and manual coding that results in a "certified pipeline" in which specifications are automatically transformed into executable code, together with the supporting artifacts necessary for achieving and demonstrating the high level of assurance needed in the aerospace domain.

Denney, Ewen↗

Methods and apparatus for improving sensor performance

Methods and apparatus for improving performance of a sensor having a sensor proof mass elastically suspended at an initial equilibrium position by a suspension force, provide a tunable force opposing that suspension force and preset the proof mass with that tunable force to a second equilibrium position less stable than the initial equilibrium position. The sensor is then operated from that preset second equilibrium position of the proof mass short of instability. The spring constant of the elastic suspension may be continually monitored, and such continually monitored spring constant may be continually adjusted to maintain the sensor at a substantially constant sensitivity during its operation.

Kaiser, William J.↗

Dual-mass vibratory rate gyroscope with suppressed translational acceleration response and quadrature-error correction capability

A microfabricated vibratory rate gyroscope to measure rotation includes two proof-masses mounted in a suspension system anchored to a substrate. The suspension has two principal modes of compliance, one of which is driven into oscillation. The driven oscillation combined with rotation of the substrate about an axis perpendicular to the substrate results in Coriolis acceleration along the other mode of compliance, the sense-mode. The sense-mode is designed to respond to Coriolis accelerationwhile suppressing the response to translational acceleration. This is accomplished using one or more rigid levers connecting the two proof-masses. The lever allows the proof-masses to move in opposite directions in response to Coriolis acceleration. The invention includes a means for canceling errors, termed quadrature error, due to imperfections in implementation of the sensor. Quadrature-error cancellation utilizes electrostatic forces to cancel out undesired sense-axis motion in phase with drive-mode position.

Clark, William A.↗