Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 415 records · Page 23

Statechart Analysis with Symbolic PathFinder

We report here on our on-going work that addresses the automated analysis and test case generation for software systems modeled using multiple Statechart formalisms. The work is motivated by large programs such as NASA Exploration, that involve multiple systems that interact via safety-critical protocols and are designed with different Statechart variants. To verify these safety-critical systems, we have developed Polyglot, a framework for modeling and analysis of model-based software written using different Statechart formalisms. Polyglot uses a common intermediate representation with customizable Statechart semantics and leverages the analysis and test generation capabilities of the Symbolic PathFinder tool. Polyglot is used as follows: First, the structure of the Statechart model (expressed in Matlab Stateflow or Rational Rhapsody) is translated into a common intermediate representation (IR). The IR is then translated into Java code that represents the structure of the model. The semantics are provided as "pluggable" modules.

Pasareanu, Corina S.↗

Risk Management Implementation Tool

Continuous Risk Management (CM) is a software engineering practice with processes, methods, and tools for managing risk in a project. It provides a controlled environment for practical decision making, in order to assess continually what could go wrong, determine which risk are important to deal with, implement strategies to deal with those risk and assure the measure effectiveness of the implemented strategies. Continuous Risk Management provides many training workshops and courses to teach the staff how to implement risk management to their various experiments and projects. The steps of the CRM process are identification, analysis, planning, tracking, and control. These steps and the various methods and tools that go along with them, identification, and dealing with risk is clear-cut. The office that I worked in was the Risk Management Office (RMO). The RMO at NASA works hard to uphold NASA s mission of exploration and advancement of scientific knowledge and technology by defining and reducing program risk. The RMO is one of the divisions that fall under the Safety and Assurance Directorate (SAAD). I worked under Cynthia Calhoun, Flight Software Systems Engineer. My task was to develop a help screen for the Continuous Risk Management Implementation Tool (RMIT). The Risk Management Implementation Tool will be used by many NASA managers to identify, analyze, track, control, and communicate risks in their programs and projects. The RMIT will provide a means for NASA to continuously assess risks. The goals and purposes for this tool is to provide a simple means to manage risks, be used by program and project managers throughout NASA for managing risk, and to take an aggressive approach to advertise and advocate the use of RMIT at each NASA center.

Wright, Shayla L.↗

Evolution of safety-critical requirements post-launch

This paper reports the results of a small study of requirements changes to the onboard software of three spacecraft subsequent to launch. Only those requirement changes that resulted from post-launch anoma-lies (i.e., during operations) were of interest here, since the goal was to better understand the relation-ship between critical anomalies during operations and how safety-critical requirements evolve. The results of the study were surprising in that anomaly-driven, post-launch requirements changes were rarely due to previous requirements having been incorrect. Instead, changes involved new requirements (1) for the software to handle rare events or (2) for the software to compensate for hardware failures or limitations. The prevalence of new requirements as a result of post-launch anomalies suggests a need for increased requirements-engineering support of maintenance activities in these systems. The results also confirm both the difficulty and the benefits of pursuing requirements completeness, especially in terms of fault tolerance, during development of critical systems.

Software requirements↗

Software and System Health Management with R2U2

R2U2 (Realizable, Responsive, Unobtrusive Unit) is a hardware-supported tool and framework for the real-time system and software health management of cyber-physical systems. R2U2 continuously monitors properties about safety, performance, and security of the vehicle and can perform diagnostic reasoning. Efficient observers for past-time and future-time Metric Temporal Logic, reasoners for Bayesian Networks, and model-based prognostics algorithms are major components of R2U2. Their combination makes it possible to design powerful models for system runtime monitoring, diagnostics, software health management, prognostics, and security monitoring. The R2U2 monitoring engine is designed for minimal runtime overhead and is available as Simulink block or as a software component for integration into the flight software stack, and enables R2U2 to monitor complex cyber-physical systems without any instrumentation of the flight software. In this presentation, we give an overview of R2U2 architecture and reasoning algorithms, present its features, and give a life demo of the tool.

Schumann, Johann↗

Element Load Data Processor (ELDAP) Users Manual

Often, the shear and tensile forces and moments are extracted from finite element analyses to be used in off-line calculations for evaluating the integrity of structural connections involving bolts, rivets, and welds. Usually the maximum forces and moments are desired for use in the calculations. In situations where there are numerous structural connections of interest for numerous load cases, the effort in finding the true maximum force and/or moment combinations among all fasteners and welds and load cases becomes difficult. The Element Load Data Processor (ELDAP) software described herein makes this effort manageable. This software eliminates the possibility of overlooking the worst-case forces and moments that could result in erroneous positive margins of safety and/or selecting inconsistent combinations of forces and moments resulting in false negative margins of safety. In addition to forces and moments, any scalar quantity output in a PATRAN report file may be evaluated with this software. This software was originally written to fill an urgent need during the structural analysis of the Ares I-X Interstage segment. As such, this software was coded in a straightforward manner with no effort made to optimize or minimize code or to develop a graphical user interface.

Ramsey, John K., Jr.↗

Novel technology of non-contact real-time radiation damage sensors for high power targets.

This report summarizes the contributions of an intern participating in the Community College Internship (CCI) program at Fermilab, focusing on the development of a novel, non-contact, real-time radiation damage sensor technology. The core objective is to create a reliable sensor capable of measuring radiation-induced degradation on high-power targets without physical contact. The experiment involves using a Class 3B supercontinuum laser directed toward a single material sample placed within a vacuum test chamber. The laser beam reflects off the sample's surface, with changes in reflectivity, indicative of radiation damage, measured by a spectrometer positioned at the chamber’s output port. The intern’s primary responsibilities included designing an interlock system to ensure laser operational safety, developing a camera-based monitoring system using Raspberry Pi devices, and creating structural supports using 3D modeling and printing techniques. Components for the interlock and camera systems were successfully designed and ordered, with preliminary 3D models printed and refined through iterative testing. Challenges encountered in the 3D printing process, such as fragile initial prototypes and difficult support removal, were overcome by adjusting printer settings and incorporating design enhancements like chamfered edges. Future activities, pending component delivery, involve installing and configuring the interlock and camera systems, as well as further improving the structural supports. Overall, the internship significantly enhanced the intern’s technical proficiency in hardware design, software integration, and advanced 3D printing, contributing directly to Fermilab’s operational safety standards and experimental effectiveness in high-energy physics research.

Pumarino Meza, Rafael [Unlisted; Fermilab]↗

Evolution of safety-critical requirements post-launch

This paper reports the results of a small study of requirements changes to the onboard software of three spacecraft subsequent to launch. Only those requirement changes that resulted from post-launch anomalies (i.e., durring operations) were of interest here, since the goal was to better understand the relationship between critical anomolies during operations and how safety-critical requirements evolve.

requirements↗

Autonomous Aerobraking Development Software: Phase 2 Summary

NASA has used aerobraking at Mars and Venus to reduce the fuel required to deliver a spacecraft into a desired orbit compared to an all-propulsive solution. Although aerobraking reduces the propellant, it does so at the expense of mission duration, large staff, and DSN coverage. These factors make aerobraking a significant cost element in the mission design. By moving on-board the current ground-based tasks of ephemeris determination, atmospheric density estimation, and maneuver sizing and execution, a flight project would realize significant cost savings. The NASA Engineering and Safety Center (NESC) sponsored Phase 1 and 2 of the Autonomous Aerobraking Development Software (AADS) study, which demonstrated the initial feasibility of moving these current ground-based functions to the spacecraft. This paper highlights key state-of-the-art advancements made in the Phase 2 effort to verify that the AADS algorithms are accurate, robust and ready to be considered for application on future missions that utilize aerobraking. The advancements discussed herein include both model updates and simulation and benchmark testing. Rigorous testing using observed flight atmospheres, operational environments and statistical analysis characterized the AADS operability in a perturbed environment.

Cianciolo, Alicia D.↗

Modular Software Interfaces for Revolutionary Flexibility in Space Operations

To make revolutionary improvements in exploration, space systems need to be flexible, realtime reconfigurable, and able to trade data transparently among themselves and mission operations. Onboard operations systems, space assembly coordination and EVA systems in exploration and construction all require real-time modular reconfigurability and data sharing. But NASA's current exploration systems are still largely legacies from hastily-developed, one-off Apollo-era practices. Today's rovers, vehicles, spacesuits, space stations, and instruments are not able to plug-and-play, Lego-like: into different combinations. Point-to-point dominates - individual suit to individual vehicle, individual instrument to rover. All are locally optimized, all unique, each of the data interfaces has been recoded for each possible combination. This will be an operations and maintenance nightmare in the much larger Project Constellation system of systems. This legacy approach does not scale to the hundreds of networked space components needed for space construction and for new, space-based approaches to Earth-Moon operations. By comparison, battlefield information management systems, which are considered critical to military force projection, have long since abandoned a point-to-point approach to systems integration. From a system-of-systems viewpoint, a clean-sheet redesign of the interfaces of all exploration systems is a necessary prerequisite before designing the interfaces of the individual exploration systems. Existing communications and Global Information Grid and middleware technologies are probably sufficient for command and control and information interfaces, with some hardware and time-delay modifications for space environments. NASA's future advanced space operations must also be information and data compatible with aerospace operations and surveillance systems being developed by other US Government agencies such as the Department of Homeland Security, Federal Aviation Administration and Department of Defense. This paper discusses fundamental system-of-systems infrastructure: approaches and architectures for modular plug-and-play software interfaces for revolutionary improvements in flexibility, modularity, robustness, ease of maintenance, reconfigurability, safety and productivity. Starting with middleware, databases, and mobile communications technologies, our technical challenges will be to apply these ideas to the requirements of constellations of space systems and to implement them initially on prototype space hardware. This is necessary to demonstrate an integrated information sharing architecture and services. It is a bottom-up approach, one that solves the problem of space operations data integration. Exploration demands uniform software mechanisms for application information interchange, and the corresponding uniformly available software services to enhance these mechanisms. We will examine the issues in plug-and-play, real-time-configurable systems, including common definition and management and tracking of data and information among many different space systems. Different field test approaches are discussed, including the use of the International Space Station and terrestrial analog mission operations at field sites.

Glass, Brian↗

Decision Engines for Software Analysis Using Satisfiability Modulo Theories Solvers

The area of software analysis, testing and verification is now undergoing a revolution thanks to the use of automated and scalable support for logical methods. A well-recognized premise is that at the core of software analysis engines is invariably a component using logical formulas for describing states and transformations between system states. The process of using this information for discovering and checking program properties (including such important properties as safety and security) amounts to automatic theorem proving. In particular, theorem provers that directly support common software constructs offer a compelling basis. Such provers are commonly called satisfiability modulo theories (SMT) solvers. Z3 is a state-of-the-art SMT solver. It is developed at Microsoft Research. It can be used to check the satisfiability of logical formulas over one or more theories such as arithmetic, bit-vectors, lists, records and arrays. The talk describes some of the technology behind modern SMT solvers, including the solver Z3. Z3 is currently mainly targeted at solving problems that arise in software analysis and verification. It has been applied to various contexts, such as systems for dynamic symbolic simulation (Pex, SAGE, Vigilante), for program verification and extended static checking (Spec#/Boggie, VCC, HAVOC), for software model checking (Yogi, SLAM), model-based design (FORMULA), security protocol code (F7), program run-time analysis and invariant generation (VS3). We will describe how it integrates support for a variety of theories that arise naturally in the context of the applications. There are several new promising avenues and the talk will touch on some of these and the challenges related to SMT solvers. Proceedings

Bjorner, Nikolaj↗

A Vision of the Future Air Traffic Control System

The air transportation system is on the verge of gridlock, with delays and cancelled flights this summer reaching all time highs. As demand for air transportation continues to increase, the capacity needed to accommodate the growth in traffic is falling farther and farther behind. Moreover, it has become increasingly apparent that the present system cannot be scaled up to provide the capacity increases needed to meet demand over the next 25 years. NASA, working with the Federal Aviation Administration and industry, is pursuing a major research program to develop air traffic management technologies that have the ultimate goal of doubling capacity while increasing safety and efficiency. This seminar will describe how the current system operates, what its limitations are and why a revolutionary "shift in paradigm" is needed to overcome fundamental limitations in capacity and safety. For the near term, NASA has developed a portfolio of software tools for air traffic controllers, called the Center-TRACON Automation System (CTAS), that provides modest gains in capacity and efficiency while staying within the current paradigm. The outline of a concept for the long term, with a deployment date of 2015 at the earliest, has recently been formulated and presented by NASA to a select group of industry and government stakeholders. Automated decision making software, combined with an Internet in the sky that enables sharing of information and distributes control between the cockpit and the ground, is key to this concept. However, its most revolutionary feature is a fundamental change in the roles and responsibilities assigned to air traffic controllers.

Erzberger, Heinz↗

Center Director's Discretionary Fund 2005 Annual Report

The FY 2005 CDDF projects were selected from the following spaceport and range technology and science areas: fluid system technologies; spaceport structures and materials; command, control, and monitoring technologies; and biological sciences (including support for environmental stewardship). The FY 2005 CDDF research projects involved development of the following: a) Capacitance-based moisture sensors to optimize plant growth in reduced gravity; b) Commodity-free calibration methods; c) Application of atmospheric plasma glow discharge to alter the surface properties of polymers for improved electrostatic dissipation characteristics; d) A wipe-on, wipe-off chemical process to remove lead oxides found in paint; e) A robust metabolite profiling platform for better understanding the "law" of biological regulation; f) An explanation of the excavation processes that occur when a jet of gas impinges on a bed of sand; g) "Smart coatings" to detect and control corrosion at an early stage to prevent further corrosion h) A model that can produce a reliable diagnosis of the quality of a software product; i) The formulation of advanced materials to meet system safety needs to minimize electrostatic charges, flammability, and radiation exposure; j) A lab-based instrument that uses the electro-optic Pockels effect to make static electric fields visible; k) A passive volatile organic compound (VOC) cartridge to filter, identify, and quantify VOCs flowing into or emanating from plant flight experiments.

Nurge, Mark↗

Promoted-Combustion Chamber with Induction Heating Coil

An improved promoted-combustion system has been developed for studying the effects of elevated temperatures on the flammability of metals in pure oxygen. In prior promoted-combustion chambers, initial temperatures of metal specimens in experiments have been limited to the temperatures of gas supplies, usually near room temperature. Although limited elevated temperature promoted-combustion chambers have been developed using water-cooled induction coils for preheating specimens, these designs have been limited to low-pressure operation due to the hollow induction coil. In contrast, the improved promoted-combustion chamber can sustain a pressure up to 10 kpsi (69 MPa) and, through utilization of a solid induction coil, is capable of preheating a metal specimen up to its melting point [potentially in excess of 2,000 F (approximately equal to 1,100 C)]. Hence, the improved promoted combustion chamber makes a greater range of physical conditions and material properties accessible for experimentation. The chamber consists of a vertical cylindrical housing with an inner diameter of 8 in. (20.32 cm) and an inner height of 20.4 in. (51.81 cm). A threaded, sealing cover at one end of the housing can be unscrewed to gain access for installing a specimen. Inlet and outlet ports for gases are provided. Six openings arranged in a helical pattern in the chamber wall contain sealed sapphire windows for viewing an experiment in progress. The base of the chamber contains pressure-sealed electrical connectors for supplying power to the induction coil. The connectors feature a unique design that prevents induction heating of the housing and the pressure sealing surfaces; this is important because if such spurious induction heating were allowed to occur, chamber pressure could be lost. The induction coil is 10 in. (25.4 cm) long and is fitted with a specimen holder at its upper end. At its lower end, the induction coil is mounted on a ceramic base, which affords thermal insulation to prevent heating of the base of the chamber during use. A sapphire cylinder protects the coil against slag generated during an experiment. The induction coil is energized by a 6-kW water-cooled power supply operating at a frequency of 400 kHz. The induction coil is part of a parallel-tuned circuit, the tuning of which is used to adjust the coupling of power to the specimen. The chamber is mounted on a test stand along with pumps, valves, and plumbing for transferring pressurized gas into and out of the chamber. In addition to multiple video cameras aimed through the windows encircling the chamber, the chamber is instrumented with gauges for monitoring the progress of an experiment. One of the gauges is a dual-frequency infrared temperature transducer aimed at the specimen through one window. Chamber operation is achieved via a console that contains a computer running apparatus-specific software, a video recorder, and real-time video monitors. For safety, a blast wall separates the console from the test stand.

Richardson, Erin↗

Linguistic Preprocessing and Tagging for Problem Report Trend Analysis

Mr. Robert Beil, Systems Engineer at Kennedy Space Center (KSC), requested the NASA Engineering and Safety Center (NESC) develop a prototype tool suite that combines complementary software technology used at Johnson Space Center (JSC) and KSC for problem report preprocessing and semantic tag extraction, to improve input to data mining and trend analysis. This document contains the outcome of the assessment and the Findings, Observations and NESC Recommendations.

Beil, Robert J.↗

Portable Laser Guided Robotic Metrology System

This paper introduces the new Portable Laser Guided Robotic antenna range (PLGR) at the National Aeronautics and Space Administration's (NASA) Glenn Research Center. Previous work used industrial robots in fixed facilities to characterize antennas and required fixtures that do not lend themselves to portable applications.NASA's PLGR system is designed for in-situ antenna measurements at a remote site. The system consists of a robot arm mounted on a vertical lift and a laser tracker, each on a portable base. The lift and laser tracker enable scanning a surface larger than the robot's reach. To accomplish this the robot first collects all points within its reach, then the system is moved and the laser tracker is used to relocate the robot before additional points are captured.The PLGR architecture will be discussed including how safety systems and path planning are combined to effectively characterize antennas. Software was written in high level languages for flexible integration of vector network analyzers and antenna controllers. Lastly, data will be shown to demonstrate the system functionality and accuracy.

Slater, Peter A.↗

Human Systems Integration: Managing Risk in Anesthesia

The practice of anesthesia relies on clinicians’ ability to safely manage increasingly complex equipment. Devices such as ventilators, drug infusion pumps, and physiologic monitors use sophisticated algorithms to deliver care, but most clinicians are only trained to manage automated systems during normal operation. Few if any receive training on how to manage system failures. Although manufacturers are required to consult with human factors engineers as part of the equipment design process, most pieces of equipment are ultimately brought to market without extensive input from clinicians. Systems in the operating room can be as simple as an oxygen tank, or as complex as a multi-institutional healthcare organization. Humans are also a complex system, and play a critical role in the domains of operations, design, fabrication, maintenance, repair, and ultimately, dismantling and closeout. HSI seeks to provide a means for advocating the human side of the system. Human Systems Integration (HSI) is the cross disciplinary process used as part of the Systems Engineering process to reduce risk in systems. HSI professionals consider the human, hardware, and software elements of system design to optimize system performance and improve safety. HSI professionals work in domains of study that include training, management, human factors engineering, safety, and occupational health, among others. This article discusses the role of systems in the practice of anesthesia, and how consideration of the human during all phases of the system life cycle helps manage risks and promote a better patient outcome.

Human Factors↗

Expert system decision support for low-cost launch vehicle operations

Progress in assessing the feasibility, benefits, and risks associated with AI expert systems applied to low cost expendable launch vehicle systems is described. Part one identified potential application areas in vehicle operations and on-board functions, assessed measures of cost benefit, and identified key technologies to aid in the implementation of decision support systems in this environment. Part two of the program began the development of prototypes to demonstrate real-time vehicle checkout with controller and diagnostic/analysis intelligent systems and to gather true measures of cost savings vs. conventional software, verification and validation requirements, and maintainability improvement. The main objective of the expert advanced development projects was to provide a robust intelligent system for control/analysis that must be performed within a specified real-time window in order to meet the demands of the given application. The efforts to develop the two prototypes are described. Prime emphasis was on a controller expert system to show real-time performance in a cryogenic propellant loading application and safety validation implementation of this system experimentally, using commercial-off-the-shelf software tools and object oriented programming techniques. This smart ground support equipment prototype is based in C with imbedded expert system rules written in the CLIPS protocol. The relational database, ORACLE, provides non-real-time data support. The second demonstration develops the vehicle/ground intelligent automation concept, from phase one, to show cooperation between multiple expert systems. This automated test conductor (ATC) prototype utilizes a knowledge-bus approach for intelligent information processing by use of virtual sensors and blackboards to solve complex problems. It incorporates distributed processing of real-time data and object-oriented techniques for command, configuration control, and auto-code generation.

Szatkowski, G. P.↗

Runtime Monitoring with R2U2 for Aircraft Systems with Neural Networks

R2U2 (Realizable, Responsive, Unobtrusive Unit) is a hardware-supported tool and framework for real-time system monitoring and software health management of cyber-physical systems. During system operation, R2U2 continuously monitors properties about safety, performance, and security of the vehicle and its vital components and can perform diagnostic reasoning. Efficient observers for past-time and future-time Metric Temporal Logic, fast reasoners for Bayesian Networks, and model-based prognostics algorithms are key components of R2U2 and designed for minimal computational footprint. R2U2 has been implemented in software supporting ROS, NASA's cFS/cFE, and Simulink and as an FPGA configuration. The synergistic combination of monitors and observers in R2U2 makes it possible to design powerful models for system runtime monitoring, diagnostics, software health management, prognostics, and security monitoring. In this presentation, I will give a detailed overview of the R2U2 architecture and its features and will discuss the application of R2U2 for safety-monitoring of a neural-network based autonomous centerline tracking system (ACT) for autonomous aircraft.

Runtime Monitoring↗