Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software errors”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 559 records · Page 31

Development of Human System Integration at NASA

Human Systems Integration seeks to design systems around the capabilities and limitations of the humans which use and interact with the system, ensuring greater efficiency of use, reduced error rates, and less rework in the design, manufacturing and operational deployment of hardware and software. One of the primary goals of HSI is to get the human factors practitioner involved early in the design process. In doing so, the aim is to reduce future budget costs and resources in redesign and training. By the preliminary design phase of a project nearly 80% of the total cost of the project is locked in. Potential design changes recommended by evaluations past this point will have little effect due to lack of funding or a huge cost in terms of resources to make changes. Three key concepts define an effective HSI program. First, systems are comprised of hardware, software, and the human, all of which operate within an environment. Too often, engineers and developers fail to consider the human capacity or requirements as part of the system. This leads to poor task allocation within the system. To promote ideal task allocation, it is critical that the human element be considered early in system development. Poor design, or designs that do not adequately consider the human component, could negatively affect physical or mental performance, as well as, social behavior. Second, successful HSI depends upon integration and collaboration of all the domains that represent acquisition efforts. Too often, these domains exist as independent disciplines due to the location of expertise within the service structure. Proper implementation of HSI through participation would help to integrate these domains and disciplines to leverage and apply their interdependencies to attain an optimal design. Via this process domain interests can be integrated to perform effective HSI through trade-offs and collaboration. This provides a common basis upon which to make knowledgeable decisions. Finally, HSI must be considered early in the requirements development phase of system design and acquisition. This will provide the best opportunity to maximize return on investment (ROI) and system performance. HSI requirements must be developed in conjunction with capability ]based requirements generation through functional. HSI requirements will drive HSI metrics and embed HSI issues within the system design. After a system is designed, implementation of HSI oversights can be very expensive. An HSI program should be included as an integral part of a total system approach to vehicle and habitat development. This would include, but not limited to, workstation design, D&C development, volumetric analysis, training, operations, and human -robotic interaction. HSI is a necessary process for Human Space Flight programs to meet the Agency Human ]System standards and thus mitigate human risks to acceptable levels. NASA has been involved in HSI planning, procedures development, process, and implementation for many years, and has been building several internal and publicly accessible products to facilitate HSI fs inclusion in the NASA Systems Engineering Lifecycle. Some of these products include: NASA STD 3001 Volumes 1 and 2, Human Integration Design Handbook, NASA HSI Implementation Plan, NASA HSI Implementation Plan Templates, NASA HSI Implementation Handbook, and a 2 ]hour short course on HSI delivered as part of the NASA Space and Life Sciences Directorate Academy. These products have been created leveraging industry best practices and lessons learned from other Federal Government agencies.

Whitmore, Mihriban↗

Development of the Resource Prospector Planetary Rover

The Resource Prospector (RP) is an In-­‐Situ Resource Utilization (ISRU) lunar rover mission under study by NASA. RP is planned to launch in 2020 to prospect for subsurface volatiles and to extract oxygen from lunar regolith. The mission will address several of NASA's "Strategic Knowledge Gaps" for lunar exploration. The mission will also address the Global Exploration Roadmap's strategic goal of using local resources for human exploration. The distribution of lunar subsurface volatiles drives the mission requirement for mobility. The spatial distribution is hypothesized to be governed by impact cratering with the top 0.5 m being patchy at scales of 100 m. The mixing time scale increases with depth (less frequent larger impacts). Consequently, increased mobility reduces the depth requirement for sampling. The target RP traverse will extend 1 km radially from the landing site to sample craters of varying sizes. Sampling craters with different ages will reveal possible volatile emplacement history. In 1 Ga, approximately 60-­70 craters of 10 m diameter form per km2. Thus, the rover will need to sample at least ten of these craters, which may require a total traverse path length of 2-­‐3 km. During 2014-­2015, we developed an initial prototype rover for RP. The current design is a solar powered, four-­wheeled vehicle, with hub motor drive, offset four wheel steering, and active suspension. Active suspension provides capabilities including changing vehicle ride height, traversing comparatively large obstacles, and controlling load on the wheels. All-­wheel steering enables the vehicle to point arbitrarily while roving, e.g., to keep the solar array pointed at the sun while in motion. The offset steering combined with active suspension improves driving in soft soil. The rover's on-­board software utilizes NASA's Core Flight Software, which is a reusable flight software environment. During 2015, we completed the initial rover software build, which provides low-­level hardware interfaces, basic mobility control, waypoint driving, odometry, basic error checking, and camera services. Development of the prototype rover has enabled maturation of many of the subsystems to TRL 5. During the next year, we will conduct integrated testing of concepts of operation, navigation, and remote driving tools. In addition, we will perform environmental tests including radiation (avionics), thermal and thermal/vacuum (mechanisms), and gravity offload (mobility).

robotics↗

TPSAS-NF1676L-32967-DND

The Stratospheric Aerosol and Gas Experiment III (SAGE III) was delivered to the International Space Station (ISS) on 23 February 2017. The SAGE III payload was robotically installed on Ex-PRESS Logistics Carrier-4 (ELC-4) on the S3 Truss and began acquiring science measurements on 17 March 2017. The SAGE III telescope and instrument assembly employs the methods of solar occultation and lunar occultation to retrieve near-global vertical profiles of atmospheric ozone, water vapor, nitrogen dioxide, multiwavelength aerosol extinctions, and other gaseous species and atmospheric state parameters. The activities on the ISS contribute to a dynamic operational environment. The attitude changes, EVAs, and the arrival and departure of vehicles require continual consideration when operating. After operating for two years, the SAGE III payload has planned over 20,000 occultation events and acquired approximately 17,000. A significant number of the missed events were because of visiting vehicles blocking the field of view. Using instrument data from these blocked events, the SAGE III team has mapped the structure of the ISS from the perspective of the instrument. Error Correction and Detection (EDAC) methods are necessary to preserve the functionality of the instrument software. On SAGE III the Hexapod Electrical Unit (HEU), which controls the orientation of the telescope, reports whenever an EDAC occurs. By analyzing the EDAC messages in the HEU telemetry, information concerning the orbital environment of the ISS can be obtained. To be presented is a summary of operational considerations when working on ISS along with how instrument data can be used to map the structural and electromagnetic environment of ISS.

Andrew J Peterson↗

Creating and Testing Simulation Software

The goal of this project is to learn about the software development process, specifically the process to test and fix components of the software. The paper will cover the techniques of testing code, and the benefits of using one style of testing over another. It will also discuss the overall software design and development lifecycle, and how code testing plays an integral role in it. Coding is notorious for always needing to be debugged due to coding errors or faulty program design. Writing tests either before or during program creation that cover all aspects of the code provide a relatively easy way to locate and fix errors, which will in turn decrease the necessity to fix a program after it is released for common use. The backdrop for this paper is the Spaceport Command and Control System (SCCS) Simulation Computer Software Configuration Item (CSCI), a project whose goal is to simulate a launch using simulated models of the ground systems and the connections between them and the control room. The simulations will be used for training and to ensure that all possible outcomes and complications are prepared for before the actual launch day. The code being tested is the Programmable Logic Controller Interface (PLCIF) code, the component responsible for transferring the information from the models to the model Programmable Logic Controllers (PLCs), basic computers that are used for very simple tasks.

Heinich, Christina M.↗

A Software Architecture for Semiautonomous Robot Control

A software architecture has been developed to increase the safety and effectiveness with which tasks are performed by robots that are capable of functioning autonomously but sometimes are operated under control by humans. The control system of such a robot designed according to a prior software architecture has no way of taking account of how the environment has changed or what parts of a task were performed during an interval of control by a human, so that errors can occur (and, hence, safety and effectiveness jeopardized) when the human relinquishes control. The present architecture incorporates the control, task-planning, and sensor-based-monitoring features of typical prior autonomous-robot software architectures, plus features for updating information on the environment and planning of tasks during control by a human operator in order to enable the robot to track the actions taken by the operator and to be ready to resume autonomous operation with minimal error. The present architecture also provides a user interface that presents, to the operator, a variety of information on the internal state of the robot and the status of the task.

Kortenkamp, David↗

Experiments in software reliability - Life-critical applications

The paper discusses four reliability data gathering experiments which were conducted using a small sample of programs for two problems having ultrareliability requirements, n-version programming for fault detection, and repetitive run modeling for failure and fault rate estimation. The experimental results agree with those of Nagel and Skrivan in that the program error rates suggest an approximate log-linear pattern and the individual faults occurred with significantly different error rates. Additional analysis of the experimental data raises new questions concerning the phenomenon of interacting faults. This phenomenon may provide one explanation for software reliability decay. The fourth experiment underscored the difficulty in distinguishing between observations of deficiencies in the design of the algorithm and observations of software faults for real-time process control software. These experiments are a part of a program of serial experiments being pursued by the System Validation Methods of NASA-Langley Research Center to find a means of credibly performing reliability evaluations of flight control software.

Dunham, J. R.↗

Shuttle avionics and the goal language including the impact of error detection and redundancy management

The relationship is examined between the space shuttle onboard avionics and the ground test computer language GOAL when used in the onboard computers. The study is aimed at providing system analysis support to the feasibility analysis of a GOAL to HAL translator, where HAL is the language used to program the onboard computers for flight. The subject is dealt with in three aspects. First, the system configuration at checkout, the general checkout and launch sequences, and the inventory of subsystems are described. Secondly, the hierarchic organization of onboard software and different ways of introducing GOAL-derived software onboard are described. Also the flow of commands and test data during checkout is diagrammed. Finally, possible impact of error detection and redundancy management on the GOAL language is discussed.

Flanders, J. H.↗

IBM system/360 assembly language interval arithmetic software

Computer software designed to perform interval arithmetic is described. An interval is defined as the set of all real numbers between two given numbers including or excluding one or both endpoints. Interval arithmetic consists of the various elementary arithmetic operations defined on the set of all intervals, such as interval addition, subtraction, union, etc. One of the main applications of interval arithmetic is in the area of error analysis of computer calculations. For example, it has been used sucessfully to compute bounds on sounding errors in the solution of linear algebraic systems, error bounds in numerical solutions of ordinary differential equations, as well as integral equations and boundary value problems. The described software enables users to implement algorithms of the type described in references efficiently on the IBM 360 system.

Phillips, E. J.↗

Projected Impact of Compositional Verification on Current and Future Aviation Safety Risk

The projected impact of compositional verification research conducted by the National Aeronautic and Space Administration System-Wide Safety and Assurance Technologies on aviation safety risk was assessed. Software and compositional verification was described. Traditional verification techniques have two major problems: testing at the prototype stage where error discovery can be quite costly and the inability to test for all potential interactions leaving some errors undetected until used by the end user. Increasingly complex and nondeterministic aviation systems are becoming too large for these tools to check and verify. Compositional verification is a "divide and conquer" solution to addressing increasingly larger and more complex systems. A review of compositional verification research being conducted by academia, industry, and Government agencies is provided. Forty-four aviation safety risks in the Biennial NextGen Safety Issues Survey were identified that could be impacted by compositional verification and grouped into five categories: automation design; system complexity; software, flight control, or equipment failure or malfunction; new technology or operations; and verification and validation. One capability, 1 research action, 5 operational improvements, and 13 enablers within the Federal Aviation Administration Joint Planning and Development Office Integrated Work Plan that could be addressed by compositional verification were identified.

Reveley, Mary S.↗

A monitor for the laboratory evaluation of control integrity in digital control systems operating in harsh electromagnetic environments

This paper presents a strategy for dynamically monitoring digital controllers in the laboratory for susceptibility to electromagnetic disturbances that compromise control integrity. The integrity of digital control systems operating in harsh electromagnetic environments can be compromised by upsets caused by induced transient electrical signals. Digital system upset is a functional error mode that involves no component damage, can occur simultaneously in all channels of a redundant control computer, and is software dependent. The motivation for this work is the need to develop tools and techniques that can be used in the laboratory to validate and/or certify critical aircraft controllers operating in electromagnetically adverse environments that result from lightning, high-intensity radiated fields (HIRF), and nuclear electromagnetic pulses (NEMP). The detection strategy presented in this paper provides dynamic monitoring of a given control computer for degraded functional integrity resulting from redundancy management errors, control calculation errors, and control correctness/effectiveness errors. In particular, this paper discusses the use of Kalman filtering, data fusion, and statistical decision theory in monitoring a given digital controller for control calculation errors.

Belcastro, Celeste M.↗

Error propagation in a digital avionic mini processor

A methodology is introduced and demonstrated for the study of error propagation from the gate to the chip level. The importance of understanding error propagation derives from its close tie with system activity. In this system the target system is BDX-930, a digital avionic multiprocessor. The simulator used was developed at NASA-Langley, and is a gate level, event-driven, unit delay, software logic simulator. An approach is highly structured and easily adapted to other systems. The analysis shows the nature and extent of the dependency of error propagation on microinstruction type, assembly level instruction, and fault-free gate activity.

Lomelino, Dale L.↗

The Integrated Hazard Analysis Integrator

Hazard analysis addresses hazards that arise in the design, development, manufacturing, construction, facilities, transportation, operations and disposal activities associated with hardware, software, maintenance, operations and environments. An integrated hazard is an event or condition that is caused by or controlled by multiple systems, elements, or subsystems. Integrated hazard analysis (IHA) is especially daunting and ambitious for large, complex systems such as NASA s Constellation program which incorporates program, systems and element components that impact others (International Space Station, public, International Partners, etc.). An appropriate IHA should identify all hazards, causes, controls and verifications used to mitigate the risk of catastrophic loss of crew, vehicle and/or mission. Unfortunately, in the current age of increased technology dependence, there is the tendency to sometimes overlook the necessary and sufficient qualifications of the integrator, that is, the person/team that identifies the parts, analyzes the architectural structure, aligns the analysis with the program plan and then communicates/coordinates with large and small components, each contributing necessary hardware, software and/or information to prevent catastrophic loss. As viewed from both Challenger and Columbia accidents, lack of appropriate communication, management errors and lack of resources dedicated to safety were cited as major contributors to these fatalities. From the accident reports, it would appear that the organizational impact of managers, integrators and safety personnel contributes more significantly to mission success and mission failure than purely technological components. If this is so, then organizations who sincerely desire mission success must put as much effort in selecting managers and integrators as they do when designing the hardware, writing the software code and analyzing competitive proposals. This paper will discuss the necessary and sufficient requirements of one of the significant contributors to mission success, the IHA integrator. Discussions will be provided to describe both the mindset required as well as deleterious assumptions/behaviors to avoid when integrating within a large scale system.

Morris, A. Terry↗

Applying Generative-AI to NASA Documentation and Processes

This research and development project leverages generative-AI to assist in the generation of software process documentation based on NASA standards. By utilizing fine-tuned AI models, the proposed system will analyze NASA's software guidelines, helping to translate them into well-structured, compliant process documents. This assistance can reduce the manual effort required to produce such documentation, enhance consistency, and assure alignment with NASA's stringent software development and operational requirements. In addition to assisting in the generation of software process documentation, the project explores how generative-AI can help create audit checklists as well as assess the compliance of NASA provider documentation against applicable NASA standards. This approach would support the compliance auditing process, providing real-time insights and assessments. The intended result will be a streamlined process, potentially including a Python-based tool and database, that improves audit efficiency, reduces human error, lowers manpower costs and required manhours, and assures continuous compliance with NASA and industry evolving standards for safety-critical software development. Future task might be to investigate the software industry approach and standards for potential collaboration.

NASA Standards↗

Mariner 9 television calibration - Revisited

Mariner 9 TV data from the 1971-1972 encounter with Mars, which contain good synoptic coverage of of the planet as well as the highest-resolution images thus far obtained for the south polar region, can lead to more accurate photometric analysis if subjected to improved processing methods. While calibration errors are rather greater than those of the Viking Orbiter cameras, both calibration data and processing software applicable to an improvement program have become available through the USGS's Planetary Image Cartography System.

Herkenhoff, Ken E.↗

Pipeline Time- And Transform-Domain Reed-Solomon Decoders

Modification of decoding algorithms leads to simplified conceptual designs for time- and transform-domain Reed-Soloman (RS) decoders suitable for implementation as very-large-scale integrated (VLSI) circuits. New conceptual decoders determine simultaneously errata-locator and errata-evaluator polynomials as part of simplified scheme for corrections of errors and erasures in RS codes. Highly suitable for implementation in both VLSI circuitry and in software on general-purpose computer.

Hsu, In-Shek↗

DSS-13 26-meter antenna upgraded radiometer system

The Deep Space Station (DSS)-13 26-m antenna radiometer system was upgraded with an IBM-compatible computer-controlled configuration with improved supporting hardware and software. Software was generated to analyze results and correct for antenna mispointing, tropospheric loss, and other observing errors. This total power radiometer configuration provides a prototype for the new DSS-13 34-m antenna. The radiometer system is described in terms of the theory, instrumentation hardware, computer configuration, and operational features and performance. The system is used to obtain antenna efficiency and pointing model data and is useful for radio source calibrations required for radio astronomy. Some recent results are given.

Stelzried, C. T.↗

Specification-based software sizing: An empirical investigation of function metrics

For some time the software industry has espoused the need for improved specification-based software size metrics. This paper reports on a study of nineteen recently developed systems in a variety of application domains. The systems were developed by a single software services corporation using a variety of languages. The study investigated several metric characteristics. It shows that: earlier research into inter-item correlation within the overall function count is partially supported; a priori function counts, in themself, do not explain the majority of the effort variation in software development in the organization studied; documentation quality is critical to accurate function identification; and rater error is substantial in manual function counting. The implication of these findings for organizations using function based metrics are explored.

Jeffery, Ross↗

Analyzing Tabular and State-Transition Requirements Specifications in PVS

We describe PVS's capabilities for representing tabular specifications of the kind advocated by Parnas and others, and show how PVS's Type Correctness Conditions (TCCs) are used to ensure certain well-formedness properties. We then show how these and other capabilities of PVS can be used to represent the AND/OR tables of Leveson and the Decision Tables of Sherry, and we demonstrate how PVS's TCCs can expose and help isolate errors in the latter. We extend this approach to represent the mode transition tables of the Software Cost Reduction (SCR) method in an attractive manner. We show how PVS can check these tables for well-formedness, and how PVS's model checking capabilities can be used to verify invariants and reachability properties of SCR requirements specifications, and inclusion relations between the behaviors of different specifications. These examples demonstrate how several capabilities of the PVS language and verification system can be used in combination to provide customized support for specific methodologies for documenting and analyzing requirements. Because they use only the standard capabilities of PVS, users can adapt and extend these customizations to suit their own needs. Those developing dedicated tools for individual methodologies may find these constructions in PVS helpful for prototyping purposes, or as a useful adjunct to a dedicated tool when the capabilities of a full theorem prover are required. The examples also illustrate the power and utility of an integrated general-purpose system such as PVS. For example, there was no need to adapt or extend the PVS model checker to make it work with SCR specifications described using the PVS TABLE construct: the model checker is applicable to any transition relation, independently of the PVS language constructs used in its definition.

Owre, Sam↗