Search NASA⌕ Search

SEARCH · Search NASA

Results for “Integrated formal methods”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Safer Systems: A NextGen Aviation Safety Strategic Goal

The Joint Planning and Development Office (JPDO), is charged by Congress with developing the concepts and plans for the Next Generation Air Transportation System (NextGen). The National Aviation Safety Strategic Plan (NASSP), developed by the Safety Working Group of the JPDO, focuses on establishing the goals, objectives, and strategies needed to realize the safety objectives of the NextGen Integrated Plan. The three goal areas of the NASSP are Safer Practices, Safer Systems, and Safer Worldwide. Safer Practices emphasizes an integrated, systematic approach to safety risk management through implementation of formalized Safety Management Systems (SMS) that incorporate safety data analysis processes, and the enhancement of methods for ensuring safety is an inherent characteristic of NextGen. Safer Systems emphasizes implementation of safety-enhancing technologies, which will improve safety for human-centered interfaces and enhance the safety of airborne and ground-based systems. Safer Worldwide encourages coordinating the adoption of the safer practices and safer systems technologies, policies and procedures worldwide, such that the maximum level of safety is achieved across air transportation system boundaries. This paper introduces the NASSP and its development, and focuses on the Safer Systems elements of the NASSP, which incorporates three objectives for NextGen systems: 1) provide risk reducing system interfaces, 2) provide safety enhancements for airborne systems, and 3) provide safety enhancements for ground-based systems. The goal of this paper is to expose avionics and air traffic management system developers to NASSP objectives and Safer Systems strategies.

Darr, Stephen T.↗

Stabilization by modification of the Lagrangian

In order to reduce the error growth during a numerical integration, a method for stabilizing the differential equations of Keplerian motion is offered. It is characterized by the use of the eccentric anomaly as independent variable in such a way that the time transformation is given by a generalized Lagrange formalism. The control terms in the equations of motion obtained by this modified Lagrangian give immediately a completely Lyapunov-stable set of differential equations. The equation of time integration is modified by a control term which leads to an integral which defined the time element for the perturbed Keplerian motion.

Baumgarte, J. W.↗

Validation and Verification of LADEE Models and Software

The Lunar Atmosphere Dust Environment Explorer (LADEE) mission will orbit the moon in order to measure the density, composition and time variability of the lunar dust environment. The ground-side and onboard flight software for the mission is being developed using a Model-Based Software methodology. In this technique, models of the spacecraft and flight software are developed in a graphical dynamics modeling package. Flight Software requirements are prototyped and refined using the simulated models. After the model is shown to work as desired in this simulation framework, C-code software is automatically generated from the models. The generated software is then tested in real time Processor-in-the-Loop and Hardware-in-the-Loop test beds. Travelling Road Show test beds were used for early integration tests with payloads and other subsystems. Traditional techniques for verifying computational sciences models are used to characterize the spacecraft simulation. A lightweight set of formal methods analysis, static analysis, formal inspection and code coverage analyses are utilized to further reduce defects in the onboard flight software artifacts. These techniques are applied early and often in the development process, iteratively increasing the capabilities of the software and the fidelity of the vehicle models and test beds.

Gundy-Burlet, Karen↗

MBSE Validation and Verification: Case Study for LADEE

The Lunar Atmosphere Dust Environment Explorer (LADEE) mission orbited the moon in order to measure the density, composition, and time variability of the lunar dust environment. The successful mission launched September 7, 2013 and was de-orbited and impacted the moon's surface on April 17, 2014. The ground-side and onboard flight software for the mission was developed using a “Model-Based Software Engineering” (MBSE) methodology combined with strong reuse of Government and Commercial Off-The Shelf (G/COTS) components. Models of the spacecraft and flight software were developed in a graphical dynamics modeling package. Flight Software requirements were prototyped and refined using the simulated models. After the model was shown to work as desired in the simulation framework, C-code software was automatically generated from the models. The auto-generated software was then tested in real-time Processor-in-the-Loop and Hardware-in-the-Loop test beds. “Traveling Road Show” test beds were used for early integration tests with payloads and other subsystems. Traditional techniques for verifying computational sciences models were used to characterize the spacecraft simulation. A lightweight set of formal methods analysis, static analysis, formal inspection, and code coverage analyses were utilized to further reduce defects in the onboard flight software artifacts. These techniques were applied early and often in the development process, iteratively increasing the capabilities of software and fidelity of vehicle models and test beds.

Model-Based Software Engineering, Validation and V↗

ICAROUS: Integrated Configurable Architecture for Unmanned Systems

NASA's Unmanned Aerial System (UAS) Traffic Management (UTM) project aims at enabling near-term, safe operations of small UAS vehicles in uncontrolled airspace, i.e., Class G airspace. A far-term goal of UTM research and development is to accommodate the expected rise in small UAS traffic density throughout the National Airspace System (NAS) at low altitudes for beyond visual line-of-sight operations. This video describes a new capability referred to as ICAROUS (Integrated Configurable Algorithms for Reliable Operations of Unmanned Systems), which is being developed under the auspices of the UTM project. ICAROUS is a software architecture comprised of highly assured algorithms for building safety-centric, autonomous, unmanned aircraft applications. Central to the development of the ICAROUS algorithms is the use of well-established formal methods to guarantee higher levels of safety assurance by monitoring and bounding the behavior of autonomous systems. The core autonomy-enabling capabilities in ICAROUS include constraint conformance monitoring and autonomous detect and avoid functions. ICAROUS also provides a highly configurable user interface that enables the modular integration of mission-specific software components.

Consiglio, Maria C.↗

Aerodynamics via acoustics - Application of acoustic formulas for aerodynamic calculations

Prediction of aerodynamic loads on bodies in arbitrary motion is considered from an acoustic point of view, i.e., in a frame of reference fixed in the undisturbed medium. An inhomogeneous wave equation which governs the disturbance pressure is constructed and solved formally using generalized function theory. When the observer is located on the moving body surface there results a singular linear integral equation for surface pressure. Two different methods for obtaining such equations are discussed. Both steady and unsteady aerodynamic calculations are considered. Two examples are presented, the more important being an application to propeller aerodynamics. Of particular interest for numerical applications is the analytical behavior of the kernel functions in the various integral equations.

Farassat, F.↗

Aerodynamics Via Acoustics: Application of Acoustic Formulas for Aerodynamic Calculations

Prediction of aerodynamic loads on bodies in arbitrary motion is considered from an acoustic point of view, i.e., in a frame of reference fixed in the undisturbed medium. An inhomogeneous wave equation which governs the disturbance pressure is constructed and solved formally using generalized function theory. When the observer is located on the moving body surface there results a singular linear integral equation for surface pressure. Two different methods for obtaining such equations are discussed. Both steady and unsteady aerodynamic calculations are considered. Two examples are presented, the more important being an application to propeller aerodynamics. Of particular interest for numerical applications is the analytical behavior of the kernel functions in the various integral equations.

Farassat, F.↗

Simulated Data for High Temperature Composite Design

The paper describes an effective formal method that can be used to simulate design properties for composites that is inclusive of all the effects that influence those properties. This effective simulation method is integrated computer codes that include composite micromechanics, composite macromechanics, laminate theory, structural analysis, and multi-factor interaction model. Demonstration of the method includes sample examples for static, thermal, and fracture reliability for a unidirectional metal matrix composite as well as rupture strength and fatigue strength for a high temperature super alloy. Typical results obtained for a unidirectional composite show that the thermal properties are more sensitive to internal local damage, the longitudinal properties degrade slowly with temperature, the transverse and shear properties degrade rapidly with temperature as do rupture strength and fatigue strength for super alloys.

Chamis, Christos C.↗

Stabilization by modification of the Lagrangian

In order to reduce the error growth during a numerical integration, a method of stabilization of the differential equations of the Keplerian motion is offered. It is characterized by the use of the eccentric anomaly as an independent variable in such a way that the time transformation is given by a generalized Lagrange formalism. The control terms in the equations of motion obtained by this modified Lagrangian give immediately a completely Liapunov-stable set of differential equations. In contrast to other publications, here the equation of time integration is modified by a control term which leads to an integral which defined the time element for the perturbed Keplerian motion.

Baumgarte, J. W.↗

Orbital stability of the unseen solar companion linked to periodic extinction events

Evidence from three-dimensional numerical modelling is presented that only cometary orbits with a limited range in inclination with respect to the galactic plane are formally stable for the length of time required to cause periodic extinction events. The calculations were done using Cowell's method employing a fourth-order Runge-Kutta integration scheme in an inertial reference frame in orbit about the Galaxy. Tidal perturbations in the radial direction due to the Galaxy and the Coriolis forces are included. The vertical component of the gravitational field of the galactic disk is superimposed on these forces. The results indicate that orbits for Nemesis that are inclined at more than 30 deg to the galactic plane are not allowed and suggests that the search for Nemesis should be concentrated toward the plane of the Galaxy. Perturbations by passing stars or molecular clouds may make even the low-inclination orbits unstable.

Torbett, M. V.↗

NASA Astronauts on Soyuz: Experience and Lessons for the Future

The U. S., Russia, and, China have each addressed the question of human-rating spacecraft. NASA's operational experience with human-rating primarily resides with Mercury, Gemini, Apollo, Space Shuttle, and International Space Station. NASA s latest developmental experience includes Constellation, X38, X33, and the Orbital Space Plane. If domestic commercial crew vehicles are used to transport astronauts to and from space, Soyuz is another example of methods that could be used to human-rate a spacecraft and to work with commercial spacecraft providers. For Soyuz, NASA's normal assurance practices were adapted. Building on NASA's Soyuz experience, this report contends all past, present, and future vehicles rely on a range of methods and techniques for human-rating assurance, the components of which include: requirements, conceptual development, prototype evaluations, configuration management, formal development reviews (safety, design, operations), component/system ground-testing, integrated flight tests, independent assessments, and launch readiness reviews. When constraints (cost, schedule, international) limit the depth/breadth of one or more preferred assurance means, ways are found to bolster the remaining areas. This report provides information exemplifying the above safety assurance model for consideration with commercial or foreign-government-designed spacecraft. Topics addressed include: U.S./Soviet-Russian government/agency agreements and engineering/safety assessments performed with lessons learned in historic U.S./Russian joint space ventures

Source record↗

Towards a Theory for Integration of Mathematical Verification and Empirical Testing

From the viewpoint of a project manager responsible for the V&V (verification and validation) of a software system, mathematical verification techniques provide a possibly useful orthogonal dimension to otherwise standard empirical testing. However, the value they add to an empirical testing regime both in terms of coverage and in fault detection has been difficult to quantify. Furthermore, potential cost savings from replacing testing with mathematical verification techniques cannot be realized until the tradeoffs and synergies can be formulated. Integration of formal verification with empirical testing is also difficult because the idealized view of mathematical verification providing a correctness proof with total coverage is unrealistic and does not reflect the limitations imposed by computational complexity of mathematical techniques. This paper first describes a framework based on software reliability and formalized fault models for a theory of software design fault detection - and hence the utility of various tools for debugging. It then describes a utility model for integrating mathematical and empirical techniques with respect to fault detection and coverage analysis. It then considers the optimal combination of black-box testing, white-box (structural) testing, and formal methods in V&V of a software system. Using case studies from NASA software systems, it then demonstrates how this utility model can be used in practice.

Lowry, Michael↗

Design Methods and Practices for Fault Prevention and Management in Spacecraft

Integrated Systems Health Management (ISHM) is intended to become a critical capability for all space, lunar and planetary exploration vehicles and systems at NASA. Monitoring and managing the health state of diverse components, subsystems, and systems is a difficult task that will become more challenging when implemented for long-term, evolving deployments. A key technical challenge will be to ensure that the ISHM technologies are reliable, effective, and low cost, resulting in turn in safe, reliable, and affordable missions. To ensure safety and reliability, ISHM functionality, decisions and knowledge have to be incorporated into the product lifecycle as early as possible, and ISHM must be considered as an essential element of models developed and used in various stages during system design. During early stage design, many decisions and tasks are still open, including sensor and measurement point selection, modeling and model-checking, diagnosis, signature and data fusion schemes, presenting the best opportunity to catch and prevent potential failures and anomalies in a cost-effective way. Using appropriate formal methods during early design, the design teams can systematically explore risks without committing to design decisions too early. However, the nature of ISHM knowledge and data is detailed, relying on high-fidelity, detailed models, whereas the earlier stages of the product lifecycle utilize low-fidelity, high-level models of systems and their functionality. We currently lack the tools and processes necessary for integrating ISHM into the vehicle system/subsystem design. As a result, most existing ISHM-like technologies are retrofits that were done after the system design was completed. It is very expensive, and sometimes futile, to retrofit a system health management capability into existing systems. Last-minute retrofits result in unreliable systems, ineffective solutions, and excessive costs (e.g., Space Shuttle TPS monitoring which was considered only after 110 flights and the Columbia disaster). High false alarm or false negative rates due to substandard implementations hurt the credibility of the ISHM discipline. This paper presents an overview of the current state of ISHM design,and a review of formal design methods to make recommendations about possible approaches to enable the ISHM capabilities to be designed-in at the system-level, from the very beginning of the vehicle design process.

Tumer, Irem Y.↗

The Density Matrix of H20 - N2 In the Coordinate Representation: A Monte Carlo Calculation of the Far-Wing Line Shape

The far-wing line shape theory within the binary collision and quasistatic framework has been developed using the coordinate representation. Within this formalism, the main computational task is the evaluation of multidimensional integrals whose variables are the orientational angles needed to specify the initial and final positions of the system during transition processes. Using standard methods, one is able to evaluate the 7-dimensional integrations required for linear molecular systems, or the 7-dimensional integrations for more complicated asymmetric-top (or symmetric-top) molecular systems whose interaction potential contains cyclic coordinates. In order to obviate this latter restriction on the form of the interaction potential, a Monte Carlo method is used to evaluate the 9-dimensional integrations required for systems consisting of one asymmetric-top (or symmetric-top) and one linear molecule, such as H20-N2. Combined with techniques developed previously to deal with sophisticated potential models, one is able to implement realistic potentials for these systems and derive accurate, converged results for the far-wing line shapes and the corresponding absorption coefficients. Conversely, comparison of the far-wing absorption with experimental data can serve as a sensitive diagnostic tool in order to obtain detailed information on the short-range anisotropic dependence of interaction potentials.

Ma, Q.↗

Thermostructural tailoring of fiber composite structures

A significant area of interest in design of complex structures involves the study of multidisciplined problems. The coordination of several different intricate areas of study to obtain a particular design of a structure is a new and pressing area of research. In the past, each discipline would perform its task consecutively using the appropriate inputs from the other disciplines. This process usually required several time-consuming iterations to obtain a satisfactory design. The alternative pursued here is combining various participating disciplines and specified design requirements into a formal structural computer code. The main focus of this research is to develop a multidiscipline structural tailoring method for select composite structures and to demonstrate its application to specific areas. The development of an integrated computer program involves the coupling of three independent computer programs using an excutive module. This module will be the foundation for integrating a structural optimizer, a composites analyzer and a thermal analyzer. With the completion of the executive module, the first step was taken toward the evolution of multidiscipline software in the field of composite mechanics. Through the use of an array of cases involving a variety of objective functions/constraints and thermal-mechanical load conditions, it became evident that simple composite structures can be designed to a combined loads environment.

Acquaviva, Thomas H.↗

Addressing software security and mitigations in the life cycle

Traditionally, security is viewed as an organizational and Information Technology (IIJ systems function comprising of Firewalls, intrusion detection systems (IDS), system security settings and patches to the operating system (OS) and applications running on it. Until recently, little thought has been given to the importance of security as a formal approach in the software life cycle. The Jet Propulsion Laboratory has approached the problem through the development of an integrated formal Software Security Assessment Instrument (SSAI) with six foci for the software life cycle.

formal methods↗

Simultaenous Retrieval of Surface Roughness Parameters from Combined Active-Passive SMAP Observations

Soil roughness strongly influences processes like erosion, infiltration, moisture and evaporation of soils as well as growth of agricultural plants. An approach to soil roughness based on active-passive microwave covariation is proposed in order to simultaneously retrieve the vertical RMS height (s) and horizontal correlation length (l) of soil surfaces from simultaneously measured radar and radiometer microwave signatures. The approach is based on a retrieval algorithm for active-passive covariation including the improved Integral Equation Method (I2EM). The algorithm is tested with the global active-passive microwave observations of the SMAP mission. The developed roughness retrieval algorithm shows independence of permittivity for > 10 [-] due to the covariation formalism. Results reveal that s and l can be estimated simultaneously by the proposed approach since surface patterns of non-vegetated areas become evident on global scale. In regions with sandy deserts, like the Sahara or the outback in Australia, determined and confirm rather smooth to semi-rough surface roughness patterns with small vertical RMS heights and corresponding higher horizontal correlation lengths.

correlation length↗

Dynamic Gate Product and Artifact Generation from System Models

Model Based Systems Engineering (MBSE) is gaining acceptance as a way to formalize systems engineering practice through the use of models. The traditional method of producing and managing a plethora of disjointed documents and presentations ("Power-Point Engineering") has proven both costly and limiting as a means to manage the complex and sophisticated specifications of modern space systems. We have developed a tool and method to produce sophisticated artifacts as views and by-products of integrated models, allowing us to minimize the practice of "Power-Point Engineering" from model-based projects and demonstrate the ability of MBSE to work within and supersede traditional engineering practices. This paper describes how we have created and successfully used model-based document generation techniques to extract paper artifacts from complex SysML and UML models in support of successful project reviews. Use of formal SysML and UML models for architecture and system design enables production of review documents, textual artifacts, and analyses that are consistent with one-another and require virtually no labor-intensive maintenance across small-scale design changes and multiple authors. This effort thus enables approaches that focus more on rigorous engineering work and less on "PowerPoint engineering" and production of paper-based documents or their "office-productivity" file equivalents.

XML↗