Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 397 records · Page 22

PARET/ANL v7.7 Verification and Validation Report

This report documents the software testing which has been performed for the PARET/ANL version 7.7 software. The software testing is based on code capabilities identified by research reactor analysts as frequently used in their safety analyses. The verification and validation procedures have been performed and documented to address the steady-state capabilities of the software, as described in Chapter 2, and the transient capabilities, as described in Chapter 3. Testing based on the comparison between PARET/ANL calculations and analytical solutions, hand calculations, or other code calculations of the test cases confirms that all the identified capabilities of the software were implemented correctly. In addition, results from code comparisons against SPERT-I and SPERT-IV experiments for various flow rates are reported for the peak power, energy release and cladding surface temperature. The comparisons showed overall good agreement for the peak power and conservative predictions of the cladding surface temperature.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

The Application of V&V within Reuse-Based Software Engineering

Verification and Validation (V&V) is performed during application development for many systems, especially safety-critical and mission-critical systems. The V&V process is intended to discover errors as early as possible during the development process. Early discovery is important in order to minimize the cost and other impacts of correcting these errors. In reuse-based software engineering, decisions on the requirements, design and even implementation of domain assets can can be made prior to beginning development of a specific system. in order to bring the effectiveness of V&V to bear within reuse-based software engineering. V&V must be incorporated within the domain engineering process.

Addy, Edward↗

A Framework for Performing Verification and Validation in Reuse Based Software Engineering

Verification and Validation (V&V) is currently performed during application development for many systems, especially safety-critical and mission- critical systems. The V&V process is intended to discover errors, especially errors related to critical processing, as early as possible during the development process. The system application provides the context under which the software artifacts are validated. This paper describes a framework that extends V&V from an individual application system to a product line of systems that are developed within an architecture-based software engineering environment. This framework includes the activities of traditional application-level V&V, and extends these activities into domain engineering and into the transition between domain engineering and application engineering. The framework includes descriptions of the types of activities to be performed during each of the life-cycle phases, and provides motivation for the activities.

Addy, Edward A.↗

Airport Simulations Using Distributed Computational Resources

The Virtual National Airspace Simulation (VNAS) will improve the safety of Air Transportation. In 2001, using simulation and information management software running over a distributed network of super-computers, researchers at NASA Ames, Glenn, and Langley Research Centers developed a working prototype of a virtual airspace. This VNAS prototype modeled daily operations of the Atlanta airport by integrating measured operational data and simulation data on up to 2,000 flights a day. The concepts and architecture developed by NASA for this prototype are integral to the National Airspace Simulation to support the development of strategies improving aviation safety, identifying precursors to component failure.

McDermott, William J.↗

WMAP C&DH Software

The command-and-data-handling (C&DH) software of the Wilkinson Microwave Anisotropy Probe (WMAP) spacecraft functions as the sole interface between (1) the spacecraft and its instrument subsystem and (2) ground operations equipment. This software includes a command-decoding and -distribution system, a telemetry/data-handling system, and a data-storage-and-playback system. This software performs onboard processing of attitude sensor data and generates commands for attitude-control actuators in a closed-loop fashion. It also processes stored commands and monitors health and safety functions for the spacecraft and its instrument subsystems. The basic functionality of this software is the same of that of the older C&DH software of the Rossi X-Ray Timing Explorer (RXTE) spacecraft, the main difference being the addition of the attitude-control functionality. Previously, the C&DH and attitude-control computations were performed by different processors because a single RXTE processor did not have enough processing power. The WMAP spacecraft includes a more-powerful processor capable of performing both computations.

Cudmore, Alan↗

Sensor Validation Software

Under a Small Business Innovation Research contract from Lewis Research Center, Expert Microsystems, Inc. developed SureSense, real-time sensor data validation software. This ultra-reliable control and sensing system product was produced through a partnership in 1994 between Expert Microsystems and Intelligent Software Associates, Inc. SureSense was created in response to a NASA need for verifying the reliability of sensor input that operated advanced automation and control systems. The immediate applications included improving the safety and reliability of Space Shuttle Main Engine operations. The company has structured the software to enable application to virtually any process control environment, such as computer integrated manufacturing, power plants, and hazardous gas sensing and control systems.

Source record↗

ESAS Deliverable PS 1.1.2.3: Customer Survey on Code Generations in Safety-Critical Applications

Automated code generators (ACG) are tools that convert a (higher-level) model of a software (sub-)system into executable code without the necessity for a developer to actually implement the code. Although both commercially supported and in-house tools have been used in many industrial applications, little data exists on how these tools are used in safety-critical domains (e.g., spacecraft, aircraft, automotive, nuclear). The aims of the survey, therefore, were threefold: 1) to determine if code generation is primarily used as a tool for prototyping, including design exploration and simulation, or for fiight/production code; 2) to determine the verification issues with code generators relating, in particular, to qualification and certification in safety-critical domains; and 3) to determine perceived gaps in functionality of existing tools.

Schumann, Johann↗

Development of Risk Assessment Matrix for NASA Engineering and Safety Center

This paper describes a study, which had as its principal goal the development of a sufficiently detailed 5 x 5 Risk Matrix Scorecard. The purpose of this scorecard is to outline the criteria by which technical issues can be qualitatively and initially prioritized. The tool using this score card has been proposed to be one of the information resources the NASA Engineering and Safety Center (NESC) takes into consideration when making decisions with respect to incoming information on safety concerns across the entire NASA agency. The contents of this paper discuss in detail each element of the risk matrix scorecard, definitions for those elements and the rationale behind the development of those definitions. This scorecard development was performed in parallel with the tailoring of the existing Futron Corporation Integrated Risk Management Application (IRMA) software tool. IRMA was tailored to fit NESC needs for evaluating incoming safety concerns and was renamed NESC Assessment Risk Management Application (NAFMA) which is still in developmental phase.

Malone, Roy W., Jr.↗

Wireless Sensor Networks for Developmental and Flight Instrumentation

Wireless sensor networks (WSN) based on the IEEE 802.15.4 Personal Area Network and ZigBee Pro 2007 standards are finding increasing use in home automation and smart energy markets providing a framework for interoperable software. The Wireless Connections in Space Project, funded by the NASA Engineering and Safety Center, is developing technology, metrics and requirements for next-generation spacecraft avionics incorporating wireless data transport. The team from Stennis Space Center and Mobitrum Corporation, working under a NASA SBIR grant, has developed techniques for embedding plug-and-play software into ZigBee WSN prototypes implementing the IEEE 1451 Transducer Electronic Datasheet (TEDS) standard. The TEDS provides meta-information regarding sensors such as serial number, calibration curve and operational status. Incorporation of TEDS into wireless sensors leads directly to building application level software that can recognize sensors at run-time, dynamically instantiating sensors as they are added or removed. The Ames Research Center team has been experimenting with this technology building demonstration prototypes for on-board health monitoring. Innovations in technology, software and process can lead to dramatic improvements for managing sensor systems applied to Developmental and Flight Instrumentation (DFI) aboard aerospace vehicles. A brief overview of the plug-and-play ZigBee WSN technology is presented along with specific targets for application within the aerospace DFI market. The software architecture for the sensor nodes incorporating the TEDS information is described along with the functions of the Network Capable Gateway processor which bridges 802.15.4 PAN to the TCP/IP network. Client application software connects to the Gateway and is used to display TEDS information and real-time sensor data values updated every few seconds, incorporating error detection and logging to help measure performance and reliability in relevant target environments. Test results from our prototype WSN running the Mobitrum software system are summarized and the implications to the scalability and reliability for DFI applications are discussed. Our demonstration system, incorporating sensors for life support system and structural health monitoring is described along with test results obtained by running the demonstration prototype in relevant environments such as the Wireless Habitat Testbed at Johnson Space Center in Houston. An operations concept for improved sensor process flow from design to flight test is outlined specific to the areas of Environmental Control and Life Support System performance characterization and structural health monitoring of human-rated spacecraft. This operations concept will be used to highlight the areas where WSN technology, particularly plug-and-play software based on IEEE 1451, can improve the current process, resulting in significant reductions in the technical effort, overall cost and schedule for providing DFI capability for future spacecraft. RELEASED -

Alena, Richard↗

Reliability Analysis for AFTI-F16 SRFCS Using ASSIST and SURE

This paper reports the results of a study on reliability analysis of an AFTI-16 Self-Repairing Flight Control System (SRFCS) using software tools SURE (Semi-Markov Unreliability Range Evaluator and ASSIST (Abstract Semi-Markov Specification Interface to the SURE Tool). The purpose of the study is to investigate the potential utility of the software tools in the ongoing effort of the NASA Aviation Safety Program, where the class of systems must be extended beyond the originally intended serving class of electronic digital processors. The study concludes that SURE and ASSIST are applicable to reliability, analysis of flight control systems. They are especially efficient for sensitivity analysis that quantifies the dependence of system reliability on model parameters. The study also confirms an earlier finding on the dominant role of a parameter called a failure coverage. The paper will remark on issues related to the improvement of coverage and the optimization of redundancy level.

Wu, N. Eva↗

Analytical and Experimental Evaluation of Digital Control Systems for the Semi-Span Super-Sonic Transport (S4T) Wind Tunnel Model

An important objective of the Semi-Span Super-Sonic Transport (S4T) wind tunnel model program was the demonstration of Flutter Suppression (FS), Gust Load Alleviation (GLA), and Ride Quality Enhancement (RQE). It was critical to evaluate the stability and robustness of these control laws analytically before testing them and experimentally while testing them to ensure safety of the model and the wind tunnel. MATLAB based software was applied to evaluate the performance of closed-loop systems in terms of stability and robustness. Existing software tools were extended to use analytical representations of the S4T and the control laws to analyze and evaluate the control laws prior to testing. Lessons were learned about the complex windtunnel model and experimental testing. The open-loop flutter boundary was determined from the closed-loop systems. A MATLAB/Simulink Simulation developed under the program is available for future work to improve the CPE process. This paper is one of a series of that comprise a special session, which summarizes the S4T wind-tunnel program.

Wieseman, Carol D.↗

Orion Launch Abort System Performance on Exploration Flight Test 1

This paper will present an overview of the flight test objectives and performance of the Orion Launch Abort System during Exploration Flight Test-1. Exploration Flight Test-1, the first flight test of the Orion spacecraft, was managed and led by the Orion prime contractor, Lockheed Martin, and launched atop a United Launch Alliance Delta IV Heavy rocket. This flight test was a two-orbit, high-apogee, high-energy entry, low-inclination test mission used to validate and test systems critical to crew safety. This test included the first flight test of the Launch Abort System preforming Orion nominal flight mission critical objectives. NASA is currently designing and testing the Orion Multi-Purpose Crew Vehicle (MPCV). Orion will serve as NASA's new exploration vehicle to carry astronauts to deep space destinations and safely return them to earth. The Orion spacecraft is composed of four main elements: the Launch Abort System, the Crew Module, the Service Module, and the Spacecraft Adapter (Fig. 1). The Launch Abort System (LAS) provides two functions; during nominal launches, the LAS provides protection for the Crew Module from atmospheric loads and heating during first stage flight and during emergencies provides a reliable abort capability for aborts that occur within the atmosphere. The Orion Launch Abort System (LAS) consists of an Abort Motor to provide the abort separation from the Launch Vehicle, an Attitude Control Motor to provide attitude and rate control, and a Jettison Motor for crew module to LAS separation (Fig. 2). The jettison motor is used during a nominal launch to separate the LAS from the Launch Vehicle (LV) early in the flight of the second stage when it is no longer needed for aborts and at the end of an LAS abort sequence to enable deployment of the crew module's Landing Recovery System. The LAS also provides a Boost Protective Cover fairing that shields the crew module from debris and the aero-thermal environment during ascent. Although the Orion Program has tested a number of the critical systems of the Orion spacecraft on the ground, the launch environment cannot be replicated completely on Earth. A number of flight tests have been conducted and are planned to demonstrate the performance and enable certification of the Orion Spacecraft. Exploration Flight Test 1, the first flight test of the Orion spacecraft, was successfully flown on December 5, 2014 from Cape Canaveral Air Force Station's Space Launch Complex 37. Orion's first flight was a two-orbit, high-apogee, high-energy entry, low-inclination test mission used to validate and test systems critical to crew safety, such as heat shield performance, separation events, avionics and software performance, attitude control and guidance, parachute deployment and recovery operations. One of the key separation events tested during this flight was the nominal jettison of the LAS. Data from this flight will be used to verify the function of the jettison motor to separate the Launch Abort System from the crew module so it can continue on with the mission. The LAS nominal jettison event on Exploration Flight Test 1 occurred at six minutes and twenty seconds after liftoff (See Fig. 3). The abort motor and attitude control motors were inert for Exploration Flight Test 1, since the mission did not require abort capabilities. A suite of developmental flight instrumentation was included on the flight test to provide data on spacecraft subsystems and separation events. This paper will focus on the flight test objectives and performance of the LAS during ascent and nominal jettison. Selected LAS subsystem flight test data will be presented and discussed in the paper. Exploration Flight Test -1 will provide critical data that will enable engineering to improve Orion's design and reduce risk for the astronauts it will protect as NASA continues to move forward on its human journey to Mars. The lessons learned from Exploration Flight Test 1 and the other Flight Test Vehicles will certainly contribute to the vehicle architecture of a human-rated space launch vehicle.

McCauley, R.↗

Space Robot Operating System (Space ROS)

Space Robot Operating System (Space ROS) is an open-source software framework for flight-quality robotic and autonomous space systems. It combines the benefits of open-source software and flight software best-practices into a single framework. Space ROS is predicated on ROS2 and is therefore reusable, modular and adoptable. As an open-source framework, it is accessible to the global space community. Space ROS is intended to be compliant with NASA flight software engineering practices in order to facilitate meeting mission and safety standards. Space ROS has fault management and real-time capabilities at its core.

Will Chambers↗

Trades, Architecture, and Design of the Joint Augmented Reality Visual Informatics System (Joint AR) Product

Future expeditions will enable exploration and study of the planetary surfaces of the Moon and Mars by performing extravehicular activity (EVA) operations. Present-day International Space Station (ISS) EVA operations require an intricate choreography of crew, space suits, tools, systems, and flight teams to plan, train, and execute with limited advanced informatics. In this paper, the Joint Augmented Reality Visual Informatics System (Joint AR) project team at NASA Johnson Space Center (JSC) characterizes the design space for developing a modular augmented reality (AR) device for a spacesuit form factor that can support crew decision-making for EVA. The Joint AR product was defined via trade studies and market analysis of previous EVA display efforts, various AR components such as optics, commercial AR systems, light engines, data interfaces, and graphics engine software. This paper outlines the defining architectural design decisions, including safety criticality considerations, interfaces, and computer architectures. The outcomes of these studies result in a prototype design which is defined here as the Joint AR product. This work aims to enable a community-wide discussion toward realizing necessary suit-compatible AR features and capabilities for future missions.

Paromita Mitra↗

Trades, Architecture, and Design of the Joint Augmented Reality Visual Informatics System (Joint AR) Product

Future expeditions will enable exploration and study of the planetary surfaces of the Moon and Mars by performing extravehicular activity (EVA) operations. Present-day International Space Station (ISS) EVA operations require an intricate choreography of crew, space suits, tools, systems, and flight teams to plan, train, and execute with limited advanced informatics. In this paper, the Joint Augmented Reality Visual Informatics System (Joint AR) project team at NASA Johnson Space Center (JSC) characterizes the design space for developing a modular augmented reality (AR) device for a spacesuit form factor that can support crew decision-making for EVA. The Joint AR product was defined via trade studies and market analysis of previous EVA display efforts, various AR components such as optics, commercial AR systems, light engines, data interfaces, and graphics engine software. This paper outlines the defining architectural design decisions, including safety criticality considerations, interfaces, and computer architectures. The outcomes of these studies result in a prototype design which is defined here as the Joint AR product. This work aims to enable a community-wide discussion toward realizing necessary suit-compatible AR features and capabilities for future missions.

Paromita Mitra↗

Computing Q-D Relationships for Storage of Rocket Fuels

The Quantity Distance Measurement Tool is a GIS BASEP computer program that aids safety engineers by calculating quantity-distance (Q-D) relationships for vessels that contain explosive chemicals used in testing rocket engines. (Q-D relationships are standard relationships between specified quantities of specified explosive materials and minimum distances by which they must be separated from persons, objects, and other explosives to obtain specified types and degrees of protection.) The program uses customized geographic-information-system (GIS) software and calculates Q-D relationships in accordance with NASA's Safety Standard For Explosives, Propellants, and Pyrotechnics. Displays generated by the program enable the identification of hazards, showing the relationships of propellant-storage-vessel safety buffers to inhabited facilities and public roads. Current Q-D information is calculated and maintained in graphical form for all vessels that contain propellants or other chemicals, the explosiveness of which is expressed in TNT equivalents [amounts of trinitrotoluene (TNT) having equivalent explosive effects]. The program is useful in the acquisition, siting, construction, and/or modification of storage vessels and other facilities in the development of an improved test-facility safety program.

Jester, Keith↗

System for Centering a Turbofan in a Nacelle During Tests

A feedback position-control system has been developed for maintaining the concentricity of a turbofan with respect to a nacelle during acoustic and flow tests in a wind tunnel. The system is needed for the following reasons: Thermal and thrust loads can displace the fan relative to the nacelle; In the particular test apparatus (see Figure 1), denoted as a rotor-only nacelle (RAN), the struts, vanes, and other stator components of a turbofan engine that ordinarily maintain the required concentricity in the face of thermal and thrust loads are not present; and The struts and stator components are not present because it is necessary to provide a flow path that is acoustically clean in the sense that the measured noise can be attributed to the fan alone. The system is depicted schematically in Figure 2. The nacelle is supported by two struts attached to a two-axis traverse table located outside the wind-tunnel wall. Two servomotors acting through 100:1 gearboxes drive the table along the Y and Z axes, which are perpendicular to the axis of rotation. The Y and Z components of the deviation from concentricity are measured by four laser displacement sensors mounted on the nacelle and aimed at reflective targets on the center body, which is part of the fan assembly. The outputs of the laser displacement sensors are digitized and processed through a personal computer programmed with control software. The control output of the computer commands the servomotors to move the table as needed to restore concentricity. Numerous software and hardware travel limits and alarms are provided to maximize safety. A highly ablative rub strip in the nacelle minimizes the probability of damage in the event that a deviation from concentricity exceeds the radial clearance [<0.004 in. (<0.1 mm)] between the inner surface of the nacelle and the tips of the fan blades. To be able to prevent an excursion in excess of the tip clearance, the system must be accurate enough to control X and Y displacements to within 0.001 in. (.0.025 mm). One characteristic essential to such accuracy is sufficient rigidity in the mechanical components of the system to prevent excitation of vibrations in the strut/ nacelle subsystem. The need for such a high degree of accuracy prompted a comprehensive analysis of sources of measurement and control errors, followed by rigorous design efforts to minimize these errors. As a result, the design of the system incorporates numerous improvements in hardware, software, and operational procedures.

Cunningham, Cameron C.↗

A Framework for Performing V&V within Reuse-Based Software Engineering

Verification and validation (V&V) is performed during application development for many systems, especially safety-critical and mission-critical systems. The V&V process is intended to discover errors, especially errors related to critical processing, as early as possible during the development process. Early discovery is important in order to minimize the cost and other impacts of correcting these errors. In order to provide early detection of errors, V&V is conducted in parallel with system development, often beginning with the concept phase. In reuse-based software engineering, however, decisions on the requirements, design and even implementation of domain assets can be made prior to beginning development of a specific system. In this case, V&V must be performed during domain engineering in order to have an impact on system development. This paper describes a framework for performing V&V within architecture-centric, reuse-based software engineering. This framework includes the activities of traditional application-level V&V, and extends these activities into domain engineering and into the transition between domain engineering and application engineering. The framework includes descriptions of the types of activities to be performed during each of the life-cycle phases, and provides motivation for the activities.

Addy, Edward A.↗