Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Control structural interaction testbed: A model for multiple flexible body verification

Conventional end-to-end ground tests for verification of control system performance become increasingly complicated with the development of large, multiple flexible body spacecraft structures. The expense of accurately reproducing the on-orbit dynamic environment and the attendant difficulties in reducing and accounting for ground test effects limits the value of these tests. TRW has developed a building block approach whereby a combination of analysis, simulation, and test has replaced end-to-end performance verification by ground test. Tests are performed at the component, subsystem, and system level on engineering testbeds. These tests are aimed at authenticating models to be used in end-to-end performance verification simulations: component and subassembly engineering tests and analyses establish models and critical parameters, unit level engineering and acceptance tests refine models, and subsystem level tests confirm the models' overall behavior. The Precision Control of Agile Spacecraft (PCAS) project has developed a control structural interaction testbed with a multibody flexible structure to investigate new methods of precision control. This testbed is a model for TRW's approach to verifying control system performance. This approach has several advantages: (1) no allocation for test measurement errors is required, increasing flight hardware design allocations; (2) the approach permits greater latitude in investigating off-nominal conditions and parametric sensitivities; and (3) the simulation approach is cost effective, because the investment is in understanding the root behavior of the flight hardware and not in the ground test equipment and environment.

Chory, M. A.↗

Copilot 3

Ultra-critical systems require high-level assurance, which cannot always be guaranteed in compile time. The use of runtime verification (RV) enables monitoring these systems in runtime, to detect property violations early and limit their potential consequences. The introduction of monitors in ultra-critical systems poses a challenge, as failures and delays in the RV subsystem could affect other subsystems and threaten the mission as a whole. This paper presents Copilot 3, a runtime verification framework for real-time embedded systems. Copilot monitors are written in a compositional, stream-based language with support for a variety of Temporal Logics (TL), which results in robust, high-level specifications that are easier to understand than their traditional counterparts. The framework translates monitor specifications into C code with static memory requirements, which can be compiled to run on embedded hardware. This paper presents version 3 of the Copilot language, demonstrates its suitability with a number of examples, and discusses its use in larger applications. Additionally, it describes the framework?s architecture, its implementation as a Domain Specific Language (DSL) embedded in Haskell, and the progress of the project over the years.

Ivan Perez↗

On-board fault-tolerant SAR processor for spaceborne imaging radar systems

A real-time high-performance and fault-tolerant FPGA-based hardware architecture for the processing of synthetic aperture radar (SAR) images has been developed for advanced spaceborne radar imaging systems. In this paper, we present the integrated design approach, from top-level algorithm specifications, system architectures, design methodology, functional verification, performance validation, down to hardware design and implementation.

imaging Radar↗

MESA: Message-Based System Analysis Using Runtime Verification

In this paper, we present a novel approach and framework for run-time verication of large, safety critical messaging systems. This work was motivated by verifying the System Wide Information Management (SWIM) project of the Federal Aviation Administration (FAA). SWIM provides live air traffic, site and weather data streams for the whole National Airspace System (NAS), which can easily amount to several hundred messages per second. Such safety critical systems cannot be instrumented, therefore, verification and monitoring has to happen using a nonintrusive approach, by connecting to a variety of network interfaces. Due to a large number of potential properties to check, the verification framework needs to support efficient formulation of properties with a suitable Domain Specific Language (DSL). Our approach is to utilize a distributed system that is geared towards connectivity and scalability and interface it at the message queue level to a powerful verification engine. We implemented our approach in the tool called MESA: Message-Based System Analysis, which leverages the open source projects RACE (Runtime for Airspace Concept Evaluation) and TraceContract. RACE is a platform for instantiating and running highly concurrent and distributed systems and enables connectivity to SWIM and scalability. TraceContract is a runtime verication tool that allows for checking traces against properties specified in a powerful DSL. We applied our approach to verify a SWIM service against several requirements.We found errors such as duplicate and out-of-order messages.

Message-based System↗

The Planetary Protection Strategy of the Earth Return Orbiter–Capture, Containment & Return System in the Context of the Mars Sample Return Campaign

The Mars Sample Return Campaign aims at bringing back to Earth the rock and atmospheric samples that the rover Perseverance has started to collect on the surface of Mars with the goal of analyzing them in a facility built specifically for this purpose to answer questions about the habitability of Mars. The Campaign consists of several missions, including the Earth Return Orbiter–Capture, Containment & Return System (ERO-CCRS), which will capture the samples previously put in Martian orbit, contain them in redundant containers to ensure that no unsterilized particles are released, and return them to Earth through a parachute-less entry vehicle. Both NASA and ESA policies address the United Nations’ Outer Space Treaty by addressing potential harm from material returned from solar system bodies beyond the Earth-Moon system. In the conduct of Mars Sample Return, the two agencies have agreed to apply approaches consistent with their own standards to campaign elements each provides. This work presents the overall strategy for both forward and backward planetary protection for the ERO-CCRS mission. Specifically, for forward planetary protection, CCRS is not required to meet specific bioburden requirements as a Category III mission provided the ERO (1) meets orbital lifetime requirements during orbiter operations and (2) any elements jettisoned at Mars meet orbital lifetime requirements. CCRS is required to be built in ISO-8 or better cleanrooms and, by agreement with ERO, be compatible with direct bioburden verification methods. For backward planetary protection, the overall approach includes building robust, highly reliable systems to prevent inadvertent release of unsterilized Mars material through redundant containment vessels and particle transport analyses. Ongoing work to define verification approaches and quantify containment assurance levels for specific sample return systems will also be discussed, along with how those data will inform launch approval for ERO-CCRS.

Giuseppe Cataldo↗

A Post-Flight Comparison Between GPS Signal Generator and On-Orbit Testing Results from the STS-101 and STS-106 SOAR Shuttle Flight Experiment

The use of a GPS Signal Generator (GPSSG) prior to launch for verification of a GPS subsystem and GN&C system on a spacecraft is becoming a very common practice. The level of confidence in the verification created by running a receiver with a GPSSG can greatly impact both schedule and cost of spacecraft development. This paper addresses the comparison of the Space Shuttle STS-101 and STS-106 Space Integrated GPS/INS (SIGI) Orbital Attitude Readiness (SOAR) flight experiments on-orbit performance with the performance from the same receiver on a Global Simulation Systems (GSS) GPSSG. The SOAR flight experiment was designed to demonstrate on-orbit performance of the International Space Station Force-19 GPS receiver. This paper discusses the process involved in getting the post-flight Best Estimate of Trajectory and Best Estimate of Attitude into the GPSSG such that the Force-19 receiver will experience the same trajectory and environmental conditions as observed during the SOAR flight experiment. Results of the comparison conclude with recommendations of how better to construct and interpret results from receiver tests using a GSS GPSSG.

Simpson, James↗

Design, Build, and Testing of the Roman Space Telescope’s Wide Field Instrument Optical Stimulus System (SORC)

The Stimulus Of Ray Cones (SORC) is an optical stimulus system developed to verify, characterize, and calibrate the Roman Space Telescope’s (RST) Wide Field Instrument (WFI) under simulated operational conditions. SORC provides several critical test modes, the primary being point-source mode, which projects an image anywhere on the Focal Plane Assembly (FPA) detectors. This mode provides precise position knowledge of the FPA within WFI. Additional modes enable capturing WFI pupil alignment, evaluation of WFI’s selectable optical elements, and verification of focal plane fiber operation for higher-level system testing. The light source system incorporates a suite of narrowband and broadband fiber fed sources spanning the visible to near-infrared range, with options for pulsed or continuous wave illumination. SORC was designed and built at NASA’s Goddard Spaceflight Center (GSFC). Initial system-level testing occurred under ambient conditions in GSFC’s Spacecraft Systems Development and Integration Facility (SSDIF), followed by vacuum testing at operational temperatures (SORC at 214-222 K) in the Space Environment Simulator (SES). The system was then shipped to BAE Systems in Boulder, CO for post-shipment ambient and cryogenic testing before integration with WFI for two thermal vacuum test campaigns at cryogenic temperatures. This presentation will focus on design, development, and performance of SORC. Details of WFI verification and calibration using SORC, along with test results, have been published previously and will be referenced only as needed to describe SORC. The SORC ground test capability is critical to ensuring WFI meets stringent optical performance requirements, directly supporting the mission’s science objectives.

Stimulus of Ray Cones↗

SAM Code Enhancements for Fission Product Tracking of Noble Gases and Metals in MSRs

This report documents fiscal year 2026 enhancements to the System Analysis Module (SAM) for modeling fission product transport in liquid-fueled molten salt reactors (MSRs). The work advances three principal areas: noble gas transport, noble metal deposition, and user interface improvements. The noble gas transport capability integrates drift-flux gas transport, Henry’s law two-film interphase mass transfer with pressure-based nucleation suppression, Knudsen-regime pore diffusion into porous graphite with a conjugate salt-graphite interface constraint, built-in material properties, five Sherwood-number mass transfer correlations including three derived from high-fidelity NekRS simulations, and xenon-135 reactivity feedback through SAM’s point-kinetics model. This work also presents a comprehensive verification test suite, including new analytically verified cases for pressure-dependent onset of interphase gas transfer in a stagnant vertical pipe, a postulated FLiBe-graphite Xe extraction permeator, a gravity riser with a fission-product source, and a descending pipe with gas redissolution driven by hydrostatic pressure. A machine learning framework for bubble rise velocity prediction in molten salt systems is developed and benchmarked on molten-salt and diverse aqueous bubble datasets. The best-performing fine-tuned transfer-learning networks achieve an 82% reduction in RMSE relative to the Clift correlation, and is implemented directly in SAM. The noble metal transport capability is developed, including a liquid-wall deposition model and a gas-surface flotation mechanism that transfers insoluble particles entrained by sparging gas to wetted structures. Verification tests and demonstration cases cover the surface deposition, flotation efflux, and flotation shedding. Finally, a new [SpeciesTransport] input structure replaces positional global vectors with selfcontained, order-independent, named species blocks, simplifies the specification of multiphase species and decay chains, and remains fully compatible with existing SAM input files. Together, these developments improve the physical fidelity, verification basis, and usability of SAM for system-level analyses of fissionproduct behavior in MSRs.

Mui, Travis (ORCID:0000000303736470)↗

Space station WP-04 power system preliminary analysis and design document, volume 3

Rocketdyne plans to generate a system level specification for the Space Station Electric Power System (EPS) in order to facilitate the usage, accountability, and tracking of overall system level requirements. The origins and status of the verification planning effort are traced and an overview of the Space Station program interactions are provided. The work package level interfaces between the EPS and the other Space Station work packages are outlined. A trade study was performed to determine the peaking split between PV and SD, and specifically to compare the inherent total peaking capability with proportionally shared peaking. In order to determine EPS cost drivers for the previous submittal of DRO2, the life cycle cost (LCC) model was run to identify the more significant costs and the factors contributing to them.

Source record↗

Design verification test matrix development for the STME thrust chamber assembly

This report presents the results of the test matrix development for design verification at the component level for the National Launch System (NLS) space transportation main engine (STME) thrust chamber assembly (TCA) components including the following: injector, combustion chamber, and nozzle. A systematic approach was used in the development of the minimum recommended TCA matrix resulting in a minimum number of hardware units and a minimum number of hot fire tests.

Dexter, Carol E.↗

Interpreter composition issues in the formal verification of a processor-memory module

This report describes interpreter composition techniques suitable for the formal specification and verification of a processor-memory module using the HOL theorem proving system. The processor-memory module is a multichip subsystem within a fault-tolerant embedded system under development within the Boeing Defense and Space Group. Modeling and verification methods were developed that permit provably secure composition at the transaction-level of specification, significantly reducing the complexity of the hierarchical verification of the system.

Fura, David A.↗

Onboard FPGA-based SAR processing for future spaceborne systems

We present a real-time high-performance and fault-tolerant FPGA-based hardware architecture for the processing of synthetic aperture radar (SAR) images in future spaceborne system. In particular, we will discuss the integrated design approach, from top-level algorithm specifications and system requirements, design methodology, functional verification and performance validation, down to hardware design and implementation.

spaceborne systems↗

Multi-Rigor Agile Verification and Rapid Prototyping for Formally Verified Software

We propose a novel approach to developing formally verified systems through Multi-rigor Agile Verification. Multi-rigor Agile Verification is rooted in the hypothesis of Rigor Independence, that a system’s specification and verification architecture depend primarily on the system requirements to be verified, and they depend very little on the rigor level of the methods used to verify those requirements. Due to its iterative nature, Multi-rigor Agile Verification promises to mitigate many of the high upfront design costs experienced by formally verified systems and to deliver a better-architected, and thus better-trusted, system in the end. We then discuss the tooling needed to perform Multi-rigor Agile Verification and go in depth to build one of those tools, which directly generates executable prototype code from declarative formal specifications using the Maude rewrite-logic framework.

97 MATHEMATICS AND COMPUTING↗

Prototype test article verification of the Space Station Freedom active thermal control system microgravity performance

To verify the on-orbit operation of the Space Station Freedom (SSF) two-phase external Active Thermal Control System (ATCS), a test and verification program will be performed prior to flight. The first system level test of the ATCS is the Prototype Test Article (PTA) test that will be performed in early 1994. All ATCS loops will be represented by prototypical components and the line sizes and lengths will be representative of the flight system. In this paper, the SSF ATCS and a portion of its verification process are described. The PTA design and the analytical methods that were used to quantify the gravity effects on PTA operation are detailed. Finally, the gravity effects are listed, and the applicability of the 1-g PTA test results to the validation of on-orbit ATCS operation is discussed.

Chen, I. Y.↗

New potentials of NIICHIMMASH's thermal vacuum facilities

The potentialities of existing test facilities as to simulating space environment governing factors for spacecraft successful development thermal vacuum testing are analyzed, ways of modernizing existing test facilities and specific proposals on their redesign are considered. The problem of spacecraft (S/C) ground development in simulated external environments, the solution of which started more than 30 years ago, has not lost its urgency today. Stringent requirements on S/C active lifetime under space conditions, module large dimensions, great number of extension elements and complicated mode of their interaction in long mission do not allow S/C designers to abandon ground tests. S/C thermal modes development is a combination of calculations, thermal vacuum tests and actions on improving S/C design and its thermal control system. Traditionally, tests are carried out by stages from component and end unit level verifications to complex tests of modules and S/C as a whole. In our opinion, sufficient correctness of calculated models and experience gained in organizations designing space systems allow to reduce cost and time of autonomous tests. Unfortunately, this is not true for complex (integrated) thermal vacuum tests. More than that, their recent programs include tasks of verifying other (than thermal control system) systems if S/C for operation under space simulated conditions. The outlined circumstances are the main reason for critical review of the potentialities of the existing test base, and of NIICHIMMASH's two large thermal vacuum chambers, first of all. The reasons for and ways of enlargement of these facilities potentially are analyzed and the results attained are described.

Afanassiev, N. A.↗