Towards an Implementation of Differential Dynamic Logic in PVS
Explore the source record for details and available documents.
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Explore the source record for details and available documents.
Multi-agent systems have become important recently in computer science, especially in artificial intelligence (AI). We allow a broad sense of agent, but require at least that an agent has some measure of autonomy and interacts with other agents via some kind of agent communication language. We are concerned in this paper with formal modeling of multi-agent systems, with emphasis on communication. We propose for this purpose to use the pi-calculus, an extension of the process algebra CCS. Although the literature on the pi-calculus refers to agents, the term is used there in the sense of a process in general. It is our contention, however, that viewing agents in the AI sense as agents in the pi-calculus sense affords significant formal insight. One formalism that has been applied to agents in the AI sense is epistemic logic, the logic of knowledge. The success of epistemic logic in computer science in general has come in large part from its ability to handle concepts of knowledge that apply to groups. We maintain that the pi-calculus affords a natural yet rigorous means by which groups that are significant to epistemic logic may be identified, encapsulated, structured into hierarchies, and restructured in a principled way. This paper is organized as follows: Section 2 introduces the pi-calculus; Section 3 takes a scenario from the classical paper on agent-oriented programming [Sh93] and translates it into a very simple subset of the n-calculus; Section 4 then shows how more sophisticated features of the pi-calculus may bc brought into play; Section 5 discusses how the pi-calculus may be used to define groups for epistemic logic; and Section 6 is the conclusion.
Software Defined Radio (SDR) technology has been proven in the commercial sector since the early 1990's. Today's rapid advancement in mobile telephone reliability and power management capabilities exemplifies the effectiveness of the SDR technology for the modern communications market. In contrast, the foundations of transponder technology presently qualified for satellite applications were developed during the early space program of the 1960's. Conventional transponders are built to a specific platform and must be redesigned for every new bus while the SDR is adaptive in nature and can fit numerous applications with no hardware modifications. A SDR uses a minimum amount of analog / Radio Frequency (RF) components to up/down-convert the RF signal to/from a digital format. Once the signal is digitized, all processing is performed using hardware or software logic. Typical SDR digital processes include; filtering, modulation, up/down converting and demodulation. NASA Marshall Space Flight Center (MSFC) Programmable Ultra Lightweight System Adaptable Radio (PULSAR) leverages existing MSFC SDR designs and commercial sector enhanced capabilities to provide a path to a radiation tolerant SDR transponder. These innovations (1) reduce the cost of NASA Low Earth Orbit (LEO) and Deep Space standard transponders, (2) decrease power requirements, and (3) commensurately reduce volume. A second pay-off is the increased SDR flexibility by allowing the same hardware to implement multiple transponder types simply by altering hardware logic - no change of hardware is required - all of which will ultimately be accomplished in orbit. Development of SDR technology for space applications will provide a highly capable, low cost transponder to programs of all sizes. The MSFC PULSAR Project results in a Technology Readiness Level (TRL) 7 low-cost telemetry system available to Smallsat and CubeSat missions, as well as other platforms. This paper documents the continued development and verification/validation of the MSFC SDR, called PULSAR, which contributes to advancing the state-of-the-art in transponder design - directly applicable to the SmallSat and CubeSat communities. This paper focuses on lessons learned on the first sub-orbital flight (high altitude balloon) and the follow-on steps taken to validate PULSAR. A sounding rocket launch, currently planned for 03/2015, will further expose PULSAR to the high dynamics of sub-orbital flights. Future opportunities for orbiting satellite incorporation reside in the small satellite missions (FASTSat, CubeSat. etc.).
The benefits of automatic-application code generation are widely accepted within the software engineering community. These benefits include raised abstraction level of application programming, shorter product development time, lower maintenance costs, and increased code quality and consistency. Surprisingly, code generation concepts have not yet found wide acceptance and use in the field of programmable logic controller (PLC) software development. Software engineers at Kennedy Space Center recognized the need for PLC code generation while developing the new ground checkout and launch processing system, called the Launch Control System (LCS). Engineers developed a process and a prototype software tool that automatically translates a high-level representation or specification of application software into ladder logic that executes on a PLC. All the computer hardware in the LCS is planned to be commercial off the shelf (COTS), including industrial controllers or PLCs that are connected to the sensors and end items out in the field. Most of the software in LCS is also planned to be COTS, with only small adapter software modules that must be developed in order to interface between the various COTS software products. A domain-specific language (DSL) is a programming language designed to perform tasks and to solve problems in a particular domain, such as ground processing of launch vehicles. The LCS engineers created a DSL for developing test sequences of ground checkout and launch operations of future launch vehicle and spacecraft elements, and they are developing a tabular specification format that uses the DSL keywords and functions familiar to the ground and flight system users. The tabular specification format, or tabular spec, allows most ground and flight system users to document how the application software is intended to function and requires little or no software programming knowledge or experience. A small sample from a prototype tabular spec application is shown.
Combined integrated and discrete circuit breadboard model for redundant multiple logic version of Mariner C spacecraft central computer and sequencer
The Moon can be on the pathway to the exploration of other planets in the solar system in three distinct ways: science, systems and technology experience, and as a fuel depot. The most important of these from the point of view of near term potential is to provide systems and technology development that increases capability and reduces the cost and risk of Mars exploration. The development of capability for a lunar program, if planned properly, can significantly influence strategies for sending humans to Mars. In conclusion, the exploration of the Moon should come before the exploration of Mars. This is a statement of developmental and operational logic that is almost self evident. Technological advancement could, however, make a different strategy reasonable. Principally, the development of a propulsion capability that could substantially reduce round trip mission times to Mars (to say 6 to 12 months) could eliminate much of the argument that the Moon is an essential stepping stone. This would reduce the problem to one of similitude with current space station program concepts. However, for any reasonably near term program, such technology does not appear likely to be available. Thus, the answer remains that lunar exploration should come first, and the expectation that it will make Mars exploration much more affordable and safe. The use of lunar propellant in an Earth-Mars transportation system is not practical with current propulsion systems; however, the discovery of caches of water ice at a lunar pole could change considerably the strategy for utilization of lunar resources in planetary exploration.
The QL module of the Performance Analysis and Design Synthesis (PADS) computer program is described. Execution of this module is initiated when and if subroutine PADSI calls subroutine GROPE. Subroutine GROPE controls the high level logical flow of the QL module. The purpose of the module is to determine a trajectory that satisfies the necessary variational conditions for optimal performance. The module achieves this by solving a nonlinear multi-point boundary value problem. The numerical method employed is described. It is an iterative technique that converges quadratically when it does converge. The three basic steps of the module are: (1) initialization, (2) iteration, and (3) culmination. For Volume 1 see N73-13199.
IBM-compatible personal computer used instead of logic analyzer or other special instrument to monitor IEEE-488 interface data bus that interconnects various pieces of laboratory equipment. Needed is short program for computer, commercial general-purpose interface bus circuit card, and adapter cable to link card to bus. Software available in Ada or Quick Basic language.
Automatic formal verification methods for finite-state systems, also known as model-checking, successfully reduce labor costs since they are mostly automatic. Model checkers explicitly or implicitly enumerate the reachable state space of a system, whose behavior is described implicitly, perhaps by a program or a collection of finite automata. Simple properties, such as mutual exclusion or absence of deadlock, can be checked by inspecting individual states. More complex properties, such as lack of starvation, require search for cycles in the state graph with particular properties. Specifications to be checked may consist of built-in properties, such as deadlock or 'unspecified receptions' of messages, another program or implicit description, to be compared with a simulation, bisimulation, or language inclusion relation, or an assertion in one of several temporal logics. Finite-state verification tools are beginning to have a significant impact in commercial designs. There are many success stories of verification tools finding bugs in protocols or hardware controllers. In some cases, these tools have been incorporated into design methodology. Research in finite-state verification has been advancing rapidly, and is showing no signs of slowing down. Recent results include probabilistic algorithms for verification, exploitation of symmetry and independent events, and the use symbolic representations for Boolean functions and systems of linear inequalities. One of the most exciting areas for further research is the combination of model-checking with theorem-proving methods.
Improved autoassociative neural networks, denoted nexi, have been proposed for use in controlling autonomous robots, including mobile exploratory robots of the biomorphic type. In comparison with conventional autoassociative neural networks, nexi would be more complex but more capable in that they could be trained to do more complex tasks. A nexus would use bit weights and simple arithmetic in a manner that would enable training and operation without a central processing unit, programs, weight registers, or large amounts of memory. Only a relatively small amount of memory (to hold the bit weights) and a simple logic application- specific integrated circuit would be needed. A description of autoassociative neural networks is prerequisite to a meaningful description of a nexus. An autoassociative network is a set of neurons that are completely connected in the sense that each neuron receives input from, and sends output to, all the other neurons. (In some instantiations, a neuron could also send output back to its own input terminal.) The state of a neuron is completely determined by the inner product of its inputs with weights associated with its input channel. Setting the weights sets the behavior of the network. The neurons of an autoassociative network are usually regarded as comprising a row or vector. Time is a quantized phenomenon for most autoassociative networks in the sense that time proceeds in discrete steps. At each time step, the row of neurons forms a pattern: some neurons are firing, some are not. Hence, the current state of an autoassociative network can be described with a single binary vector. As time goes by, the network changes the vector. Autoassociative networks move vectors over hyperspace landscapes of possibilities.
Howard University, under the auspices of the Center for Energy Systems and Controls runs the Energy Expert Systems Institute (EESI) summer outreach program for high school/pre-college minority students. The main objectives are to introduce precollege minority students to research in the power industry using modern state-of-the-art technology such as Expert Systems, Fuzzy Logic and Artificial Neural Networks; to involve minority students in space power management, systems and failure diagnosis; to generate interest in career options in electrical engineering; and to experience problem-solving in a teamwork environment consisting of faculty, senior research associates and graduate students. For five weeks the students are exposed not only to the exciting experience of college life, but also to the inspiring field of engineering, especially electrical engineering. The program consists of lectures in the fundamentals of engineering, mathematics, communication skills and computer skills. The projects are divided into mini and major. Topics for the 1995 mini projects were Expert Systems for the Electric Bus and Breast Cancer Detection. Topics on the major projects include Hybrid Electric Vehicle, Solar Dynamics and Distribution Automation. On the final day, designated as 'EESI Day' the students did oral presentations of their projects and prizes were awarded to the best group. The program began in the summer of 1993. The reaction from the students has been very positive. The program also arranges field trips to special places of interest such as the NASA Goddard Space Center.
The control system designed under the Multivariable Control Synthesis (MVCS) program for the F100 turbofan engine is described. The MVCS program, applied the linear quadratic regulator (LQR) synthesis methods in the design of a multivariable engine control system to obtain enhanced performance from cross-coupled controls, maximum use of engine variable geometry, and a systematic design procedure that can be applied efficiently to new engine systems. Basic components of the control system, a reference value generator for deriving a desired equilibrium state and an approximate control vector, a transition model to produce compatible reference point trajectories during gross transients, gain schedules for producing feedback terms appropriate to the flight condition, and integral switching logic to produce acceptable steady-state performance without engine operating limit exceedance are described and the details of the F100 implementation presented. The engine altitude test phase of the MVCS program, and engine responses in a variety of test operating points and power transitions are presented.
This paper picks up where EVA Space Suit Architecture: Low Earth Orbit Vs. Moon Vs. Mars (Hill, Johnson, IEEEAC paper #1209) left off in the development of a space suit architecture that is modular in design and interfaces and could be reconfigured to meet the mission or during any given mission depending on the tasks or destination. This paper will walk though the continued development of a space suit system architecture, and how it should evolve to meeting the future exploration EVA needs of the United States space program. In looking forward to future US space exploration and determining how the work performed to date in the CxP and how this would map to a future space suit architecture with maximum re-use of technology and functionality, a series of thought exercises and analysis have provided a strong indication that the CxP space suit architecture is well postured to provide a viable solution for future exploration missions. Through the destination environmental analysis that is presented in this paper, the modular architecture approach provides the lowest mass, lowest mission cost for the protection of the crew given any human mission outside of low Earth orbit. Some of the studies presented here provide a look and validation of the non-environmental design drivers that will become every-increasingly important the further away from Earth humans venture and the longer they are away. Additionally, the analysis demonstrates a logical clustering of design environments that allows a very focused approach to technology prioritization, development and design that will maximize the return on investment independent of any particular program and provide architecture and design solutions for space suit systems in time or ahead of being required for any particular manned flight program in the future. The new approach to space suit design and interface definition the discussion will show how the architecture is very adaptable to programmatic and funding changes with minimal redesign effort required such that the modular architecture can be quickly and efficiently honed into a specific mission point solution if required.
Correspondence between logical relations of Boolean function implicants and numerical relations between identifiers
Applied research and technology development is often characterized by uncertainty, risk, and significant delays before tangible returns are obtained. Decision making regarding which technologies to advance and what resources to devote to them is a challenging but essential task. In the application of life support technology to future manned space flight, new technology concepts typically are characterized by nonexistent data and rough approximations of technology performance, uncertain future flight program needs, and a complex, time-intensive process to develop technology to a flight-ready status. Decision analysis is a quantitative, logic-based discipline that imposes formalism and structure to complex problems. It also accounts for the limits of knowledge that may be available at the time a decision is needed. The utility of decision analysis to life support technology R & D was evaluated by applying it to two case studies. The methodology was found to provide insight that is not possible from more traditional analysis approaches.
Shuttle-Derived Launch Vehicle (SDLV) concepts have been developed by a collaborative team comprising the Johnson Space Center, Marshall Space Flight Center, Kennedy Space Center, ATK-Thiokol, Lockheed Martin Space Systems Company, The Boeing Company, and United Space Alliance. The purpose of this study was to provide timely information on a full spectrum of low-risk, cost-effective options for STS-Derived Launch Vehicle concepts to support the definition of crew and cargo launch requirements for the Space Exploration Vision. Since the SDLV options use high-reliability hardware, existing facilities, and proven processes, they can provide relatively low-risk capabilities to launch extremely large payloads to low Earth orbit. This capability to reliably lift very large, high-dollar-value payloads could reduce mission operational risks by minimizing the number of complex on-orbit operations compared to architectures based on multiple smaller launchers. The SDLV options also offer several logical spiral development paths for larger exploration payloads. All of these development paths make practical and cost-effective use of existing Space Shuttle Program (SSP) hardware, infrastructure, and launch and flight operations systems. By utilizing these existing assets, the SDLV project could support the safe and orderly transition of the current SSP through the planned end of life in 2010. The SDLV concept definition work during 2004 focused on three main configuration alternatives: a side-mount heavy lifter (approximately 77 MT payload), an in-line medium lifter (approximately 22 MT Crew Exploration Vehicle payload), and an in-line heavy lifter (greater than 100 MT payload). This paper provides an overview of the configuration, performance capabilities, reliability estimates, concept of operations, and development plans for each of the various SDLV alternatives. While development, production, and operations costs have been estimated for each of the SDLV configuration alternatives, these proprietary data have not been included in this paper.
Structure composed of standardized-circuit arrays reduces cost and complexity of fabricating special integrated circuits. Desired circuits are formed from basic mask, custom cuts, and contact points. Interactive computer program speeds design.
This paper describes an ongoing effort to embed and verify differential dynamic logic (dL) in the Prototype Verification System (PVS). dL is a logic for specifying and formally reasoning about hybrid systems, which employ both continuous and discrete dynamics. There are several benefits of this effort. First, the embedding of dL in PVS offers an independent formal verification of the semantics and rules of dL. Second, the embedding is fully operational within PVS, giving PVS practitioners the ability to use dL in the formal specification and verification process. Third, the rich specification language, type system, and powerful interactive prover of PVS can be used on dL objects. In addition to the embedding and verification of dL, a custom extension for Visual Studio Code has been developed, so that a stylized dL syntax can be used to specify hybrid programs and their properties.