Search NASA⌕ Search

SEARCH · Search NASA

Results for “Program verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 451 records · Page 25

Roman Space Telescope Optical System: Status and Test

A conference presentation providing an overview of the Roman Space Telescope optical system. Details on the optical system verification plan and Spacecraft Bus + Integrated Payload Assembly (SCIPA) thermal vacuum optical test program are provided.

space telescope↗

Propel: Tools and Methods for Practical Source Code Model Checking

The work reported here is an overview and snapshot of a project to develop practical model checking tools for in-the-loop verification of NASA s mission-critical, multithreaded programs in Java and C++. Our strategy is to develop and evaluate both a design concept that enables the application of model checking technology to C++ and Java, and a model checking toolset for C++ and Java. The design concept and the associated model checking toolset is called Propel. It builds upon the Java PathFinder (JPF) tool, an explicit state model checker for Java applications developed by the Automated Software Engineering group at NASA Ames Research Center. The design concept that we are developing is Design for Verification (D4V). This is an adaption of existing best design practices that has the desired side-effect of enhancing verifiability by improving modularity and decreasing accidental complexity. D4V, we believe, enhances the applicability of a variety of V&V approaches; we are developing the concept in the context of model checking. The model checking toolset, Propel, is based on extending JPF to handle C++. Our principal tasks in developing the toolset are to build a translator from C++ to Java, productize JPF, and evaluate the toolset in the context of D4V. Through all these tasks we are testing Propel capabilities on customer applications.

Mansouri-Samani, Massoud↗

Automated Environment Generation for Software Model Checking

A key problem in model checking open systems is environment modeling (i.e., representing the behavior of the execution context of the system under analysis). Software systems are fundamentally open since their behavior is dependent on patterns of invocation of system components and values defined outside the system but referenced within the system. Whether reasoning about the behavior of whole programs or about program components, an abstract model of the environment can be essential in enabling sufficiently precise yet tractable verification. In this paper, we describe an approach to generating environments of Java program fragments. This approach integrates formally specified assumptions about environment behavior with sound abstractions of environment implementations to form a model of the environment. The approach is implemented in the Bandera Environment Generator (BEG) which we describe along with our experience using BEG to reason about properties of several non-trivial concurrent Java programs.

Tkachuk, Oksana↗

Execution-Based Model Checking of Interrupt-Based Systems

Execution-based model checking (EMC) is a verification technique based on executing a multi-threaded/multiprocess program repeatedly in a systematic manner in order to explore the different interleavings of the program. This is in contrast to traditional model checking, where a model of a system is analyzed Several execution-based model-checking tools exist at this point, such as for example Verisoft and Java PathFinder. The most common formal specification languages used by EMC tools are un- timed, either just assertions, or linear-time temporal logic (LTL). An alternative verification technique is Runtime Execution Monitoring (REM), which is based on monitor- ing the execution of a program, checking that the execution trace conforms to a requirement specification. The Temporal Rover and DBRover are such tools. They provide a very rich specification language, being an extension of LTL with real-time constraints and time-series. We show how execution-based model checking, combined with runtime execution monitoring, can be used for the verification of a large class of safety critical systems commonly known as interrupt-based systems. The proposed approach is novel in that: (i) it supports model checking of a large class of applications not practically verifiable using conventional EMC tools, (ii) it supports verification of LTL assertions extended with real-time and time-series constraints, and (iii) it supports the verification of custom schedulers.

Drusinsky, Doron↗

From Livingstone to SMV: Formal Verification for Autonomous Spacecrafts

To fulfill the needs of its deep space exploration program, NASA is actively supporting research and development in autonomy software. However, the reliable and cost-effective development and validation of autonomy systems poses a tough challenge. Traditional scenario-based testing methods fall short because of the combinatorial explosion of possible situations to be analyzed, and formal verification techniques typically require a tedious, manual modelling by formal method experts. This paper presents the application of formal verification techniques in the development of autonomous controllers based on Livingstone, a model-based health-monitoring system that can detect and diagnose anomalies and suggest possible recovery actions. We present a translator that converts the models used by Livingstone into specifications that can be verified with the SMV model checker. The translation frees the Livingstone developer from the tedious conversion of his design to SMV, and isolates him from the technical details of the SMV program. We describe different aspects of the translation and briefly discuss its application to several NASA domains.

Pecheur, Charles↗

A Rewriting-Based Approach to Trace Analysis

We present a rewriting-based algorithm for efficiently evaluating future time Linear Temporal Logic (LTL) formulae on finite execution traces online. While the standard models of LTL are infinite traces, finite traces appear naturally when testing and/or monitoring red applications that only run for limited time periods. The presented algorithm is implemented in the Maude executable specification language and essentially consists of a set of equations establishing an executable semantics of LTL using a simple formula transforming approach. The algorithm is further improved to build automata on-the-fly from formulae, using memoization. The result is a very efficient and small Maude program that can be used to monitor program executions. We furthermore present an alternative algorithm for synthesizing probably minimal observer finite state machines (or automata) from LTL formulae, which can be used to analyze execution traces without the need for a rewriting system, and can hence be used by observers written in conventional programming languages. The presented work is part of an ambitious runtime verification and monitoring project at NASA Ames, called PATHEXPLORER, and demonstrates that rewriting can be a tractable and attractive means for experimenting and implementing program monitoring logics.

Havelund, Klaus↗

Orion Crew Module Landing System Simulation and Verification

NASA Langley Research Center (LaRC) has developed a comprehensive test and analysis program to evaluate the ability of LS-DYNA to model the materials and the phenomena involved in soil and water landing impacts of the Orion crew module. Elemental, scale boilerplate, and full-scale prototype testing is being conducted in support of the simulation verification and validation approach. Aspects of the simulations evaluated against test data include soil constitutive properties, water equations of state, and contact algorithms. Subsystems tested include airbags, crushable energy absorbing honeycomb materials, and energy absorbing seat support struts. The procedures, instrumentation, and general observations from each test series are presented. Plans for a series of swing tests of a full-scale boilerplate into a purpose-built water basin are described. Further plans for swing tests of flight-like prototypes into the water basin are noted.

Vassilakos, Gregory J.↗

Space Station Freedom avionics technology

The Space Station Freedom Program (SSFP) encompasses the design, development, test, evaluation, verification, launch, assembly, and operation and utilization of a set of spacecraft in low earth orbit (LEO) and their supporting facilities. The spacecraft set includes: the Space Station Manned Base (SSMB), a European Space Agency (ESA) provided Man-Tended Free Flyer (MTFF) at an inclination of 28.5 degrees and nominal attitude of 410 km, a USA provided Polar Orbiting Platform (POP), and an ESA provided POP in sun-synchronous, near polar orbits at a nominal altitude of 822 km. The SSMB will be assembled using the National Space Transportation System (NSTS). The POPs and the MTFF will be launched by Expendable Launch Vehicles (ELVs): a Titan 4 for the US POP and an Ariane for the ESA POP and MTFF. The US POP will for the most part use derivatives of systems flown on unmanned LEO spacecraft. The SSMB portion of the overall program is presented.

Edwards, A.↗

RighTime: A real time clock correcting program for MS-DOS-based computer systems

A computer program is described which effectively eliminates the misgivings of the DOS system clock in PC/AT-class computers. RighTime is a small, sophisticated memory-resident program that automatically corrects both the DOS system clock and the hardware 'CMOS' real time clock (RTC) in real time. RighTime learns what corrections are required without operator interaction beyond the occasional accurate time set. Both warm (power on) and cool (power off) errors are corrected, usually yielding better than one part per million accuracy in the typical desktop computer with no additional hardware, and RighTime increases the system clock resolution from approximately 0.0549 second to 0.01 second. Program tools are also available which allow visualization of RighTime's actions, verification of its performance, display of its history log, and which provide data for graphing of the system clock behavior. The program has found application in a wide variety of industries, including astronomy, satellite tracking, communications, broadcasting, transportation, public utilities, manufacturing, medicine, and the military.

Becker, G. Thomas↗

Experimental verification of the energy dissipation mechanism in acoustic dampers.

An experimental program is described which verifies the theoretical model that acoustic damping devices undergoing high intensity oscillations dissipate energy via jet kinetic losses. Pressure measurements within the damping devices and flow duct together with detailed surveys of the jet velocities provide the experimental confirmation. The theory accounts for duct flow effects, both steady and unsteady, as well as the jet dissipation. Discrepancies between theory and experiment can be traced to neglect of higher order terms or ignoring the difficult wall friction term in the case of the quarter-wave tube.

Tang, P. K.↗

Runtime Verification - 17 Years Later

Runtime verification is the discipline of analyzing program executions using rigorous methods. The discipline covers such topics as specification-based monitoring, where single executions are checked against formal specifications; predictive runtime analysis, where properties about a system are predicted/inferred from single (good) executions; specification mining from execution traces; visualization of execution traces; and to be fully general: computation of any interesting information from execution traces. Finally, runtime verification also includes fault protection, where monitors actively protect a running system against errors. The paper is written as a response to the ‘Test of Time Award’ attributed to the authors for their 2001 paper [45]. The present paper provides a brief overview of what lead to that paper, what has happened since, and some perspectives on the future of the field.

Rosu, Grigore↗

Space Shuttle Main Engine program status

Performance, weight, and reusability of the Space Shuttle Main Engine, the next generation rocket engine, are important factors in achieving the Space Shuttle mission. The design features of the engine contributing to the achievement of these engine demands are discussed. Many new fabrication methods, material applications, and innovations incorporated into the engine are presented. The engine program is now in the second year of the 47 months development period. The current status of activities in engineering, manufacturing, and test are reviewed. The Design Verification Specification approach to engine development is compared to the development programs for Saturn/Apollo engines.

Kirby, F. M.↗

Integration by parts

This paper describes the unique integration and verification challenges associated with the Space Station Freedom and an approach to solve these problems using Data Management Systems (DMS) Kits. These DMS Kits will help alleviate the complex integration problems inherent in building, assembling and testing the Space Station. Particular emphasis has been placed on utilizing the capabilities and services of the on-board DMS to provide the integration and verification tools, not only for the DMS but for the other on-board distributed systems as well. DMS Kits are provided to system/software developers across the program. These DMS Kits provide a common set of integration and verification tools and hardware. Each system developer can then utilize, through the kits, a simulation of the complete data processing environment which will be available on orbit. The paper describes the evolution of the integration process from the system level to the final integration of multiple launch packages. DMS Kits are used throughout this process, which addresses both the ground and on-orbit aspects of the problem.

Barry, Thomas↗

Space Shuttle External Tank Project status

The External Tank Project is reviewed with emphasis on the DDT&E and production phases and the lightweight tank development. It is noted that the DDT&E phase is progressing well with the structural and ground vibration test article programs complete, the propulsion test article program progressing well, and the component qualification and verification testing 92% complete. New tools and facilities are being brought on line to support the increased build rate for the production phase. The lightweight tank, which will provide additional payload in orbit, is progressing to schedule with first delivery in early 1982.

Davis, R. M.↗

Extended frequency turbofan model

The fan model was developed using two dimensional modeling techniques to add dynamic radial coupling between the core stream and the bypass stream of the fan. When incorporated into a complete TF-30 engine simulation, the fan model greatly improved compression system frequency response to planar inlet pressure disturbances up to 100 Hz. The improved simulation also matched engine stability limits at 15 Hz, whereas the one dimensional fan model required twice the inlet pressure amplitude to stall the simulation. With verification of the two dimensional fan model, this program formulated a high frequency F-100(3) engine simulation using row by row compression system characteristics. In addition to the F-100(3) remote splitter fan, the program modified the model fan characteristics to simulate a proximate splitter version of the F-100(3) engine.

Mason, J. R.↗

Evaluation of propellant tank insulation concepts for low-thrust chemical propulsion systems

An analytical evaluation of cryogenic propellant tank insulations for liquid oxygen/liquid hydrogen low-thrust 2224N (500 lbf) propulsion systems (LTPS) was conducted. The insulation studied consisted of combinations of N2-purged foam and multilayer insulation (MLI) as well as He-purged MLI-only. Heat leak and payload performance predictions were made for three Shuttle-launched LTPS designed for Shuttle bay packaged payload densities of 56 kg/cu m, 40 kg/cu m and 24 kg/cu m. Foam/MLI insulations were found to increase LTPS payload delivery capability when compared with He-purged MLI-only. An additional benefit of foam/MLI was reduced operational complexity because Orbiter cargo bay N2 purge gas could be used for MLI purging. Maximum payload mass benefit occurred when an enhanced convection, rather than natural convection, heat transfer was specified for the insulation purge enclosure. The enhanced convection environment allowed minimum insulation thickness to be used for the foam/MLI interface temperature selected to correspond to the moisture dew point in the N2 purge gas. Experimental verification of foam/MLI benefits was recommended. A conservative program cost estimate for testing a MLI-foam insulated tank was 2.1 million dollars. It was noted this cost could be reduced significantly without increasing program risk.

Kramer, T.↗

Evaluation of propellent tank insulation concepts for low-thrust chemical propulsion systems: Executive summary

Cryogenic propellant tank insulations or liquid oxygen/liquid hydrogen low-thrust 2224N (500 lbf) propulsion systems (LTPS) were assessed. The insulation studied consisted of combinations of N2-purged foam and multilayer insulation (MLI) as well as He-purged MLI-only. Heat leak and payload performance predictions were made for three shuttle-launched LTPS designed for shuttle bay packaged payload densities of 56 kg cu/m (3.5 lbm/cu ft), 40 kg/cu m (2.5 lbm/cu ft) and 24 kg/cu m (1.5 lbm/cu ft). Foam/MLI insulations were found to increase LTPS payload delivery capability when compared with He-purged MLI-only. An additional benefit of foam/MLI was reduced operational complexity because orbiter cargo bay N2 purge gas could be used for MLI purging. Maximum payload mass benefit occurred when an enhanced convection, rather than natural convection, heat transfer was specified for the insulation purge enclosure. The enhanced convection environment allowed minimum insulation thickness to be used for the foam/MLI interface temperature selected to correspond to the moisture dew point in the N2 purge gas. Experimental verification of foam/MLI benefits was recommended. A conservative program cost estimate for testing a MLI-foam insulated tank was 2.1 million dollars. This cost could be reduced significantly without increasing program risk.

Kramer, T.↗