Search NASA⌕ Search

SEARCH · Search NASA

Results for “Software engineering safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Automated Translation of Safety Critical Application Software Specifications into PLC Ladder Logic

The numerous benefits of automatic application code generation are widely accepted within the software engineering community. A few of these benefits include raising the abstraction level of application programming, shorter product development time, lower maintenance costs, and increased code quality and consistency. Surprisingly, code generation concepts have not yet found wide acceptance and use in the field of programmable logic controller (PLC) software development. Software engineers at the NASA Kennedy Space Center (KSC) recognized the need for PLC code generation while developing their new ground checkout and launch processing system. They developed a process and a prototype software tool that automatically translates a high-level representation or specification of safety critical application software into ladder logic that executes on a PLC. This process and tool are expected to increase the reliability of the PLC code over that which is written manually, and may even lower life-cycle costs and shorten the development schedule of the new control system at KSC. This paper examines the problem domain and discusses the process and software tool that were prototyped by the KSC software engineers.

Leucht, Kurt W.↗

Sensor Validation Software

Under a Small Business Innovation Research contract from Lewis Research Center, Expert Microsystems, Inc. developed SureSense, real-time sensor data validation software. This ultra-reliable control and sensing system product was produced through a partnership in 1994 between Expert Microsystems and Intelligent Software Associates, Inc. SureSense was created in response to a NASA need for verifying the reliability of sensor input that operated advanced automation and control systems. The immediate applications included improving the safety and reliability of Space Shuttle Main Engine operations. The company has structured the software to enable application to virtually any process control environment, such as computer integrated manufacturing, power plants, and hazardous gas sensing and control systems.

Source record↗

V & V Within Reuse-Based Software Engineering

Verification and validation (V&V) is used to increase the level of assurance of critical software, particularly that of safety-critical and mission critical software. This paper describes the working group's success in identifying V&V tasks that could be performed in the domain engineering and transition levels of reuse-based software engineering. The primary motivation for V&V at the domain level is to provide assurance that the domain requirements are correct and that the domain artifacts correctly implement the domain requirements. A secondary motivation is the possible elimination of redundant V&V activities at the application level. The group also considered the criteria and motivation for performing V&V in domain engineering.

Addy, Edward A.↗

Trades, Architecture, and Design of the Joint Augmented Reality Visual Informatics System (Joint AR) Product

Future expeditions will enable exploration and study of the planetary surfaces of the Moon and Mars by performing extravehicular activity (EVA) operations. Present-day International Space Station (ISS) EVA operations require an intricate choreography of crew, space suits, tools, systems, and flight teams to plan, train, and execute with limited advanced informatics. In this paper, the Joint Augmented Reality Visual Informatics System (Joint AR) project team at NASA Johnson Space Center (JSC) characterizes the design space for developing a modular augmented reality (AR) device for a spacesuit form factor that can support crew decision-making for EVA. The Joint AR product was defined via trade studies and market analysis of previous EVA display efforts, various AR components such as optics, commercial AR systems, light engines, data interfaces, and graphics engine software. This paper outlines the defining architectural design decisions, including safety criticality considerations, interfaces, and computer architectures. The outcomes of these studies result in a prototype design which is defined here as the Joint AR product. This work aims to enable a community-wide discussion toward realizing necessary suit-compatible AR features and capabilities for future missions.

Paromita Mitra↗

Trades, Architecture, and Design of the Joint Augmented Reality Visual Informatics System (Joint AR) Product

Future expeditions will enable exploration and study of the planetary surfaces of the Moon and Mars by performing extravehicular activity (EVA) operations. Present-day International Space Station (ISS) EVA operations require an intricate choreography of crew, space suits, tools, systems, and flight teams to plan, train, and execute with limited advanced informatics. In this paper, the Joint Augmented Reality Visual Informatics System (Joint AR) project team at NASA Johnson Space Center (JSC) characterizes the design space for developing a modular augmented reality (AR) device for a spacesuit form factor that can support crew decision-making for EVA. The Joint AR product was defined via trade studies and market analysis of previous EVA display efforts, various AR components such as optics, commercial AR systems, light engines, data interfaces, and graphics engine software. This paper outlines the defining architectural design decisions, including safety criticality considerations, interfaces, and computer architectures. The outcomes of these studies result in a prototype design which is defined here as the Joint AR product. This work aims to enable a community-wide discussion toward realizing necessary suit-compatible AR features and capabilities for future missions.

Paromita Mitra↗

Software assurance standard

This standard specifies the software assurance program for the provider of software. It also delineates the assurance activities for the provider and the assurance data that are to be furnished by the provider to the acquirer. In any software development effort, the provider is the entity or individual that actually designs, develops, and implements the software product, while the acquirer is the entity or individual who specifies the requirements and accepts the resulting products. This standard specifies at a high level an overall software assurance program for software developed for and by NASA. Assurance includes the disciplines of quality assurance, quality engineering, verification and validation, nonconformance reporting and corrective action, safety assurance, and security assurance. The application of these disciplines during a software development life cycle is called software assurance. Subsequent lower-level standards will specify the specific processes within these disciplines.

Source record↗

Risk Management Implementation Tool

Continuous Risk Management (CM) is a software engineering practice with processes, methods, and tools for managing risk in a project. It provides a controlled environment for practical decision making, in order to assess continually what could go wrong, determine which risk are important to deal with, implement strategies to deal with those risk and assure the measure effectiveness of the implemented strategies. Continuous Risk Management provides many training workshops and courses to teach the staff how to implement risk management to their various experiments and projects. The steps of the CRM process are identification, analysis, planning, tracking, and control. These steps and the various methods and tools that go along with them, identification, and dealing with risk is clear-cut. The office that I worked in was the Risk Management Office (RMO). The RMO at NASA works hard to uphold NASA s mission of exploration and advancement of scientific knowledge and technology by defining and reducing program risk. The RMO is one of the divisions that fall under the Safety and Assurance Directorate (SAAD). I worked under Cynthia Calhoun, Flight Software Systems Engineer. My task was to develop a help screen for the Continuous Risk Management Implementation Tool (RMIT). The Risk Management Implementation Tool will be used by many NASA managers to identify, analyze, track, control, and communicate risks in their programs and projects. The RMIT will provide a means for NASA to continuously assess risks. The goals and purposes for this tool is to provide a simple means to manage risks, be used by program and project managers throughout NASA for managing risk, and to take an aggressive approach to advertise and advocate the use of RMIT at each NASA center.

Wright, Shayla L.↗

Autonomous Aerobraking Development Software: Phase 2 Summary

NASA has used aerobraking at Mars and Venus to reduce the fuel required to deliver a spacecraft into a desired orbit compared to an all-propulsive solution. Although aerobraking reduces the propellant, it does so at the expense of mission duration, large staff, and DSN coverage. These factors make aerobraking a significant cost element in the mission design. By moving on-board the current ground-based tasks of ephemeris determination, atmospheric density estimation, and maneuver sizing and execution, a flight project would realize significant cost savings. The NASA Engineering and Safety Center (NESC) sponsored Phase 1 and 2 of the Autonomous Aerobraking Development Software (AADS) study, which demonstrated the initial feasibility of moving these current ground-based functions to the spacecraft. This paper highlights key state-of-the-art advancements made in the Phase 2 effort to verify that the AADS algorithms are accurate, robust and ready to be considered for application on future missions that utilize aerobraking. The advancements discussed herein include both model updates and simulation and benchmark testing. Rigorous testing using observed flight atmospheres, operational environments and statistical analysis characterized the AADS operability in a perturbed environment.

Cianciolo, Alicia D.↗

A Holistic Approach to Systems Development

Introduces a Holistic and Iterative Design Process. Continuous process but can be loosely divided into four stages. More effort spent early on in the design. Human-centered and Multidisciplinary. Emphasis on Life-Cycle Cost. Extensive use of modeling, simulation, mockups, human subjects, and proven technologies. Human-centered design doesn t mean the human factors discipline is the most important Disciplines should be involved in the design: Subsystem vendors, configuration management, operations research, manufacturing engineering, simulation/modeling, cost engineering, hardware engineering, software engineering, test and evaluation, human factors, electromagnetic compatibility, integrated logistics support, reliability/maintainability/availability, safety engineering, test equipment, training systems, design-to-cost, life cycle cost, application engineering etc. 9

Wong, Douglas T.↗

Linguistic Preprocessing and Tagging for Problem Report Trend Analysis

Mr. Robert Beil, Systems Engineer at Kennedy Space Center (KSC), requested the NASA Engineering and Safety Center (NESC) develop a prototype tool suite that combines complementary software technology used at Johnson Space Center (JSC) and KSC for problem report preprocessing and semantic tag extraction, to improve input to data mining and trend analysis. This document contains the outcome of the assessment and the Findings, Observations and NESC Recommendations.

Beil, Robert J.↗

Cyclomatic Complexity and Basis Path Testing Study

The NASA Chief Engineer requested the NASA Engineering and Safety Center (NESC) to conduct a study to determine the benefits of cyclomatic complexity and basis path testing (BPT) for software and whether they should be required. The principal focus of the assessment was to assess the use of cyclomatic complexity and BPT on safety-critical software. The purpose was to ensure that safety-critical software is not overly complicated to the point of increasing coding errors and that verification is more robust than for non-safety-critical software. This document contains the outcome of the assessment.

Cyclomatic Complexity; NASA Engineering and Safety↗

RICIS research

The principle focus of one of the RICIS (Research Institute for Computing and Information Systems) components is computer systems and software engineering in-the-large of the lifecycle of large, complex, distributed systems which: (1) evolve incrementally over a long time; (2) contain non-stop components; and (3) must simultaneously satisfy a prioritized balance of mission and safety critical requirements at run time. This focus is extremely important because of the contribution of the scaling direction problem to the current software crisis. The Computer Systems and Software Engineering (CSSE) component addresses the lifestyle issues of three environments: host, integration, and target.

Mckay, Charles W.↗

Demonstration of a Safety Analysis on a Complex System

For the past 17 years, Professor Leveson and her graduate students have been developing a theoretical foundation for safety in complex systems and building a methodology upon that foundation. The methodology includes special management structures and procedures, system hazard analyses, software hazard analysis, requirements modeling and analysis for completeness and safety, special software design techniques including the design of human-machine interaction, verification, operational feedback, and change analysis. The Safeware methodology is based on system safety techniques that are extended to deal with software and human error. Automation is used to enhance our ability to cope with complex systems. Identification, classification, and evaluation of hazards is done using modeling and analysis. To be effective, the models and analysis tools must consider the hardware, software, and human components in these systems. They also need to include a variety of analysis techniques and orthogonal approaches: There exists no single safety analysis or evaluation technique that can handle all aspects of complex systems. Applying only one or two may make us feel satisfied, but will produce limited results. We report here on a demonstration, performed as part of a contract with NASA Langley Research Center, of the Safeware methodology on the Center-TRACON Automation System (CTAS) portion of the air traffic control (ATC) system and procedures currently employed at the Dallas/Fort Worth (DFW) TRACON (Terminal Radar Approach CONtrol). CTAS is an automated system to assist controllers in handling arrival traffic in the DFW area. Safety is a system property, not a component property, so our safety analysis considers the entire system and not simply the automated components. Because safety analysis of a complex system is an interdisciplinary effort, our team included system engineers, software engineers, human factors experts, and cognitive psychologists.

Leveson, Nancy↗

Trades, Architecture, and Design of the Joint Augmented Reality Visual Informatics (Joint AR) Product

Future expeditions will enable exploration and study of the planetary surfaces of the Moon and Mars by performing extravehicular activity (EVA) operations. Present-day International Space Station (ISS) EVA operations require an intricate and tight choreography of crew, space suits, tools, systems, and flight teams to plan, train, and execute with limited advanced informatics. Additionally, EVA operations, aside from the Apollo Lunar surface missions, have predominately focused on maintenance and construction tasks where success criteria are clearly measurable. However, future exploration missions expect to enable crew to carry out scientific objectives in increasingly Earth-independent ways. In this paper, the Joint Augmented Reality Visual Informatics System (Joint AR) characterizes the design space for developing a modular augmented reality (AR) device for a spacesuit form factor that can support crew decision-making for EVA. This paper highlights the project’s experience with a product-focused management style and use-case centered systems engineering approach to iteratively design, build, and test. The Joint AR product features were defined via trade studies and market analysis of previous EVA display efforts, various AR components such as optics, commercial AR systems, light engines, data interfaces, graphics engine software and analog test beds. We outline the defining architectural design decisions, including safety criticality considerations, suit mounting interfaces, computer architectures, and partnership contracting mechanisms. The outcomes of these studies, architecture decisions, and management requirements result in a recommended design which is the Joint AR product. We discuss the evolution, development of these system components, and what work remains. We hope to share a unified understanding of various design decisions and how they impact the future of crew members’ access to data during Lunar and Martian EVAs. This ongoing effort can enable a community-wide discovery process toward realizing necessary AR features and capabilities for future missions.

Augmented Reality↗

Timing analysis by model checking

The safety of modern avionics relies on high integrity software that can be verified to meet hard real-time requirements. The limits of verification technology therefore determine acceptable engineering practice. To simplify verification problems, safety-critical systems are commonly implemented under the severe constraints of a cyclic executive, which make design an expensive trial-and-error process highly intolerant of change. Important advances in analysis techniques, such as rate monotonic analysis (RMA), have provided a theoretical and practical basis for easing these onerous restrictions. But RMA and its kindred have two limitations: they apply only to verifying the requirement of schedulability (that tasks meet their deadlines) and they cannot be applied to many common programming paradigms. We address both these limitations by applying model checking, a technique with successful industrial applications in hardware design. Model checking algorithms analyze finite state machines, either by explicit state enumeration or by symbolic manipulation. Since quantitative timing properties involve a potentially unbounded state variable (a clock), our first problem is to construct a finite approximation that is conservative for the properties being analyzed-if the approximation satisfies the properties of interest, so does the infinite model. To reduce the potential for state space explosion we must further optimize this finite model. Experiments with some simple optimizations have yielded a hundred-fold efficiency improvement over published techniques.

Naydich, Dimitri↗

Using computer graphics to enhance astronaut and systems safety

Computer graphics is being employed at the NASA Johnson Space Center as a tool to perform rapid, efficient and economical analyses for man-machine integration, flight operations development and systems engineering. The Operator Station Design System (OSDS), a computer-based facility featuring a highly flexible and versatile interactive software package, PLAID, is described. This unique evaluation tool, with its expanding data base of Space Shuttle elements, various payloads, experiments, crew equipment and man models, supports a multitude of technical evaluations, including spacecraft and workstation layout, definition of astronaut visual access, flight techniques development, cargo integration and crew training. As OSDS is being applied to the Space Shuttle, Orbiter payloads (including the European Space Agency's Spacelab) and future space vehicles and stations, astronaut and systems safety are being enhanced. Typical OSDS examples are presented. By performing physical and operational evaluations during early conceptual phases. supporting systems verification for flight readiness, and applying its capabilities to real-time mission support, the OSDS provides the wherewithal to satisfy a growing need of the current and future space programs for efficient, economical analyses.

Computer Simulation↗

Applying formal methods and object-oriented analysis to existing flight software

Correctness is paramount for safety-critical software control systems. Critical software failures in medical radiation treatment, communications, and defense are familiar to the public. The significant quantity of software malfunctions regularly reported to the software engineering community, the laws concerning liability, and a recent NRC Aeronautics and Space Engineering Board report additionally motivate the use of error-reducing and defect detection software development techniques. The benefits of formal methods in requirements driven software development ('forward engineering') is well documented. One advantage of rigorously engineering software is that formal notations are precise, verifiable, and facilitate automated processing. This paper describes the application of formal methods to reverse engineering, where formal specifications are developed for a portion of the shuttle on-orbit digital autopilot (DAP). Three objectives of the project were to: demonstrate the use of formal methods on a shuttle application, facilitate the incorporation and validation of new requirements for the system, and verify the safety-critical properties to be exhibited by the software.

Cheng, Betty H. C.↗

SOAREX-8 Suborbital Experiments 2015 - A New Paradigm for Small Spacecraft Communication

In 2015 NASA plans to launch a payload to 280 Km altitude on a sounding rocket from the Wallops Flight Facility. This payload will contain several novel technologies that work together to demonstrate methodologies for space sample return missions and for nanosatellite communications in general. The payload will deploy and test an Exo-Brake, which slows the payload aerodynamically, providing eventual de-orbit and recovery of future ISS samples through a Small Payload Quick Return project. In addition, this flight addresses future Mars mission entry technology, space-to-space communications using the Iridium Short Messaging Service (SMS), GPS tracking, and wireless sensors using the ZigBee protocol. SOAREX-8 is being assembled and tested at Ames Research Center (ARC) and the NASA Engineering and Safety Center (NESC) is funding sensor and communications work. Open source Arduino technology and software are used for system control. The ZigBee modules used are XBee units that connect analog sensors for temperature, air pressure and acceleration measurement wirelessly to the payload telemetry system. Our team is developing methods for power distribution and module mounting, along with software for sensor integration, data assembly and downlink. We have demonstrated relaying telemetry to the ground using the Iridium satellite constellation on a previous flight, but the upcoming flight will be the first time we integrate useful flight test data from a ZigBee wireless sensor network. Wireless sensor data will measure the aerodynamic efficacy of the Exo-Brake permitting further on orbit flight tests of improved designs. The Exo-Brake is 5 sq m in area and will be stored in a container and deployed during ascent once the payload is jettisoned from the launch vehicle. We intend to further refine the hardware and continue testing on balloon launches, future sounding rocket flights and on nanosatellite missions. The use of standards-based and open source hardware/software has allowed for this project to be completed with a very modest budget and a challenging schedule. There is a wealth of hardware and software available for both the Arduino platform and the XBee, all low-cost or open-source. Along with the Exo-Brake hardware and deployment discussion, this paper will describe in detail the system architecture emphasizing the successful use of open source hardware and software to minimize effort and cost. Testing procedures, radio frequency interference (RFI) mitigation, success criteria and expected results will also be discussed. The use of Iridium short messaging capability for space-to-space links, standards-based wireless sensor networks, and other innovative communications technology are also presented.

aerobrake↗