Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Copilot 3

Ultra-critical systems require high-level assurance, which cannot always be guaranteed in compile time. The use of runtime verification (RV) enables monitoring these systems in runtime, to detect property violations early and limit their potential consequences. The introduction of monitors in ultra-critical systems poses a challenge, as failures and delays in the RV subsystem could affect other subsystems and threaten the mission as a whole. This paper presents Copilot 3, a runtime verification framework for real-time embedded systems. Copilot monitors are written in a compositional, stream-based language with support for a variety of Temporal Logics (TL), which results in robust, high-level specifications that are easier to understand than their traditional counterparts. The framework translates monitor specifications into C code with static memory requirements, which can be compiled to run on embedded hardware. This paper presents version 3 of the Copilot language, demonstrates its suitability with a number of examples, and discusses its use in larger applications. Additionally, it describes the framework?s architecture, its implementation as a Domain Specific Language (DSL) embedded in Haskell, and the progress of the project over the years.

Ivan Perez↗

On-board fault-tolerant SAR processor for spaceborne imaging radar systems

A real-time high-performance and fault-tolerant FPGA-based hardware architecture for the processing of synthetic aperture radar (SAR) images has been developed for advanced spaceborne radar imaging systems. In this paper, we present the integrated design approach, from top-level algorithm specifications, system architectures, design methodology, functional verification, performance validation, down to hardware design and implementation.

imaging Radar↗

MESA: Message-Based System Analysis Using Runtime Verification

In this paper, we present a novel approach and framework for run-time verication of large, safety critical messaging systems. This work was motivated by verifying the System Wide Information Management (SWIM) project of the Federal Aviation Administration (FAA). SWIM provides live air traffic, site and weather data streams for the whole National Airspace System (NAS), which can easily amount to several hundred messages per second. Such safety critical systems cannot be instrumented, therefore, verification and monitoring has to happen using a nonintrusive approach, by connecting to a variety of network interfaces. Due to a large number of potential properties to check, the verification framework needs to support efficient formulation of properties with a suitable Domain Specific Language (DSL). Our approach is to utilize a distributed system that is geared towards connectivity and scalability and interface it at the message queue level to a powerful verification engine. We implemented our approach in the tool called MESA: Message-Based System Analysis, which leverages the open source projects RACE (Runtime for Airspace Concept Evaluation) and TraceContract. RACE is a platform for instantiating and running highly concurrent and distributed systems and enables connectivity to SWIM and scalability. TraceContract is a runtime verication tool that allows for checking traces against properties specified in a powerful DSL. We applied our approach to verify a SWIM service against several requirements.We found errors such as duplicate and out-of-order messages.

Message-based System↗

The Planetary Protection Strategy of the Earth Return Orbiter–Capture, Containment & Return System in the Context of the Mars Sample Return Campaign

The Mars Sample Return Campaign aims at bringing back to Earth the rock and atmospheric samples that the rover Perseverance has started to collect on the surface of Mars with the goal of analyzing them in a facility built specifically for this purpose to answer questions about the habitability of Mars. The Campaign consists of several missions, including the Earth Return Orbiter–Capture, Containment & Return System (ERO-CCRS), which will capture the samples previously put in Martian orbit, contain them in redundant containers to ensure that no unsterilized particles are released, and return them to Earth through a parachute-less entry vehicle. Both NASA and ESA policies address the United Nations’ Outer Space Treaty by addressing potential harm from material returned from solar system bodies beyond the Earth-Moon system. In the conduct of Mars Sample Return, the two agencies have agreed to apply approaches consistent with their own standards to campaign elements each provides. This work presents the overall strategy for both forward and backward planetary protection for the ERO-CCRS mission. Specifically, for forward planetary protection, CCRS is not required to meet specific bioburden requirements as a Category III mission provided the ERO (1) meets orbital lifetime requirements during orbiter operations and (2) any elements jettisoned at Mars meet orbital lifetime requirements. CCRS is required to be built in ISO-8 or better cleanrooms and, by agreement with ERO, be compatible with direct bioburden verification methods. For backward planetary protection, the overall approach includes building robust, highly reliable systems to prevent inadvertent release of unsterilized Mars material through redundant containment vessels and particle transport analyses. Ongoing work to define verification approaches and quantify containment assurance levels for specific sample return systems will also be discussed, along with how those data will inform launch approval for ERO-CCRS.

Giuseppe Cataldo↗

A Post-Flight Comparison Between GPS Signal Generator and On-Orbit Testing Results from the STS-101 and STS-106 SOAR Shuttle Flight Experiment

The use of a GPS Signal Generator (GPSSG) prior to launch for verification of a GPS subsystem and GN&C system on a spacecraft is becoming a very common practice. The level of confidence in the verification created by running a receiver with a GPSSG can greatly impact both schedule and cost of spacecraft development. This paper addresses the comparison of the Space Shuttle STS-101 and STS-106 Space Integrated GPS/INS (SIGI) Orbital Attitude Readiness (SOAR) flight experiments on-orbit performance with the performance from the same receiver on a Global Simulation Systems (GSS) GPSSG. The SOAR flight experiment was designed to demonstrate on-orbit performance of the International Space Station Force-19 GPS receiver. This paper discusses the process involved in getting the post-flight Best Estimate of Trajectory and Best Estimate of Attitude into the GPSSG such that the Force-19 receiver will experience the same trajectory and environmental conditions as observed during the SOAR flight experiment. Results of the comparison conclude with recommendations of how better to construct and interpret results from receiver tests using a GSS GPSSG.

Simpson, James↗

Design, Build, and Testing of the Roman Space Telescope’s Wide Field Instrument Optical Stimulus System (SORC)

The Stimulus Of Ray Cones (SORC) is an optical stimulus system developed to verify, characterize, and calibrate the Roman Space Telescope’s (RST) Wide Field Instrument (WFI) under simulated operational conditions. SORC provides several critical test modes, the primary being point-source mode, which projects an image anywhere on the Focal Plane Assembly (FPA) detectors. This mode provides precise position knowledge of the FPA within WFI. Additional modes enable capturing WFI pupil alignment, evaluation of WFI’s selectable optical elements, and verification of focal plane fiber operation for higher-level system testing. The light source system incorporates a suite of narrowband and broadband fiber fed sources spanning the visible to near-infrared range, with options for pulsed or continuous wave illumination. SORC was designed and built at NASA’s Goddard Spaceflight Center (GSFC). Initial system-level testing occurred under ambient conditions in GSFC’s Spacecraft Systems Development and Integration Facility (SSDIF), followed by vacuum testing at operational temperatures (SORC at 214-222 K) in the Space Environment Simulator (SES). The system was then shipped to BAE Systems in Boulder, CO for post-shipment ambient and cryogenic testing before integration with WFI for two thermal vacuum test campaigns at cryogenic temperatures. This presentation will focus on design, development, and performance of SORC. Details of WFI verification and calibration using SORC, along with test results, have been published previously and will be referenced only as needed to describe SORC. The SORC ground test capability is critical to ensuring WFI meets stringent optical performance requirements, directly supporting the mission’s science objectives.

Stimulus of Ray Cones↗

Space station WP-04 power system preliminary analysis and design document, volume 3

Rocketdyne plans to generate a system level specification for the Space Station Electric Power System (EPS) in order to facilitate the usage, accountability, and tracking of overall system level requirements. The origins and status of the verification planning effort are traced and an overview of the Space Station program interactions are provided. The work package level interfaces between the EPS and the other Space Station work packages are outlined. A trade study was performed to determine the peaking split between PV and SD, and specifically to compare the inherent total peaking capability with proportionally shared peaking. In order to determine EPS cost drivers for the previous submittal of DRO2, the life cycle cost (LCC) model was run to identify the more significant costs and the factors contributing to them.

Source record↗

Design verification test matrix development for the STME thrust chamber assembly

This report presents the results of the test matrix development for design verification at the component level for the National Launch System (NLS) space transportation main engine (STME) thrust chamber assembly (TCA) components including the following: injector, combustion chamber, and nozzle. A systematic approach was used in the development of the minimum recommended TCA matrix resulting in a minimum number of hardware units and a minimum number of hot fire tests.

Dexter, Carol E.↗

Interpreter composition issues in the formal verification of a processor-memory module

This report describes interpreter composition techniques suitable for the formal specification and verification of a processor-memory module using the HOL theorem proving system. The processor-memory module is a multichip subsystem within a fault-tolerant embedded system under development within the Boeing Defense and Space Group. Modeling and verification methods were developed that permit provably secure composition at the transaction-level of specification, significantly reducing the complexity of the hierarchical verification of the system.

Fura, David A.↗

Onboard FPGA-based SAR processing for future spaceborne systems

We present a real-time high-performance and fault-tolerant FPGA-based hardware architecture for the processing of synthetic aperture radar (SAR) images in future spaceborne system. In particular, we will discuss the integrated design approach, from top-level algorithm specifications and system requirements, design methodology, functional verification and performance validation, down to hardware design and implementation.

spaceborne systems↗

Prototype test article verification of the Space Station Freedom active thermal control system microgravity performance

To verify the on-orbit operation of the Space Station Freedom (SSF) two-phase external Active Thermal Control System (ATCS), a test and verification program will be performed prior to flight. The first system level test of the ATCS is the Prototype Test Article (PTA) test that will be performed in early 1994. All ATCS loops will be represented by prototypical components and the line sizes and lengths will be representative of the flight system. In this paper, the SSF ATCS and a portion of its verification process are described. The PTA design and the analytical methods that were used to quantify the gravity effects on PTA operation are detailed. Finally, the gravity effects are listed, and the applicability of the 1-g PTA test results to the validation of on-orbit ATCS operation is discussed.

Chen, I. Y.↗

New potentials of NIICHIMMASH's thermal vacuum facilities

The potentialities of existing test facilities as to simulating space environment governing factors for spacecraft successful development thermal vacuum testing are analyzed, ways of modernizing existing test facilities and specific proposals on their redesign are considered. The problem of spacecraft (S/C) ground development in simulated external environments, the solution of which started more than 30 years ago, has not lost its urgency today. Stringent requirements on S/C active lifetime under space conditions, module large dimensions, great number of extension elements and complicated mode of their interaction in long mission do not allow S/C designers to abandon ground tests. S/C thermal modes development is a combination of calculations, thermal vacuum tests and actions on improving S/C design and its thermal control system. Traditionally, tests are carried out by stages from component and end unit level verifications to complex tests of modules and S/C as a whole. In our opinion, sufficient correctness of calculated models and experience gained in organizations designing space systems allow to reduce cost and time of autonomous tests. Unfortunately, this is not true for complex (integrated) thermal vacuum tests. More than that, their recent programs include tasks of verifying other (than thermal control system) systems if S/C for operation under space simulated conditions. The outlined circumstances are the main reason for critical review of the potentialities of the existing test base, and of NIICHIMMASH's two large thermal vacuum chambers, first of all. The reasons for and ways of enlargement of these facilities potentially are analyzed and the results attained are described.

Afanassiev, N. A.↗

Simulation of Landing and Take-Off Noise for Supersonic Transport Aircraft at a Conceptual Design Fidelity Level

The German Aerospace Center has launched an internal project to assess the noise impact associated with supersonic transport aircraft during approach and departure. A dedicated simulation process is established to cover all relevant disciplines, i.e., aircraft and engine design, engine installation effects, flight simulation, and system noise prediction. The core of the simulation process is comprised of methods at the complexity and fidelity level of conceptual aircraft design, i.e., typical overall aircraft design methods and a semi-empirical approach for the noise modeling. Dedicated interfaces allow to process data from high fidelity simulation that will support or even replace initial low fidelity results in the long run. All of the results shown and discussed in this study are limited to the fidelity level of conceptual design. The application of the simulation process to the NASA 55t Supersonic Technology Concept Aeroplane, i.e., based on non-proprietary data for this vehicle, yields similar noise level predictions when compared to the published NASA results. This is used as an initial feasibility check of the new process and confirms the underlying methods and models. Such an initial verification of the process is understood as an essential step due to the lack of available noise data for supersonic transport aircraft in general. The advantageous effect of engine noise shielding on the resulting system noise is demonstrated based on predicted level time histories and certification noise levels. After this initial verification, the process is applied to evaluate a conceptual supersonic transport design based on a PhD thesis with two engines mounted under the wing, which is referred to as aircraft TWO. Full access to this vehicle’s design and performance data allows to investigate the influence of flight procedures on the resulting noise impact along approach and departure. These noise results are then assembled according to proposed Federal Aviation Agency regulations in their Notice of Proposed Rulemaking, e.g., speed limitations, for Supersonic transport noise certification and the regulations from Noise Chapters of the Annex 16 from the International Civil Aviation Organization in order to evaluate the resulting levels as a function of the flight procedure.

noise↗

Options and Risk for Qualification of Electric Propulsion System

Electric propulsion vehicle systems envelop a wide range of propulsion alternatives including solar and nuclear, which present unique circumstances for qualification. This paper will address the alternatives for qualification of electric propulsion spacecraft systems. The approach taken will be to address the considerations for qualification at the various levels of systems definition. Additionally, for each level of qualification the system level risk implications will be developed. Also, the paper will explore the implications of analysis verses test for various levels of systems definition, while retaining the objectives of a verification program. The limitations of terrestrial testing will be explored along with the risk and implications of orbital demonstration testing. The paper will seek to develop a template for structuring of a verification program based on cost, risk and value return. A successful verification program should establish controls and define objectives of the verification compliance program. Finally the paper will seek to address the political and programmatic factors, which may impact options for system verification.

Bailey, Michelle↗

Synthetic and Enhanced Vision Systems for NextGen (SEVS) Simulation and Flight Test Performance Evaluation

The Synthetic and Enhanced Vision Systems for NextGen (SEVS) simulation and flight tests are jointly sponsored by NASA's Aviation Safety Program, Vehicle Systems Safety Technology project and the Federal Aviation Administration (FAA). The flight tests were conducted by a team of Honeywell, Gulfstream Aerospace Corporation and NASA personnel with the goal of obtaining pilot-in-the-loop test data for flight validation, verification, and demonstration of selected SEVS operational and system-level performance capabilities. Nine test flights (38 flight hours) were conducted over the summer and fall of 2011. The evaluations were flown in Gulfstream.s G450 flight test aircraft outfitted with the SEVS technology under very low visibility instrument meteorological conditions. Evaluation pilots flew 108 approaches in low visibility weather conditions (600 ft to 2400 ft visibility) into various airports from Louisiana to Maine. In-situ flight performance and subjective workload and acceptability data were collected in collaboration with ground simulation studies at LaRC.s Research Flight Deck simulator.

Shelton, Kevin J.↗