Search NASASearch

SEARCH · Search NASA

Results for “certification coding”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Mock Certification Basis for an Unmanned Rotorcraft for Precision Agricultural Spraying

This technical report presents the results of a case study using a hazard-based approach to develop preliminary design and performance criteria for an unmanned agricultural rotorcraft requiring airworthiness certification. This case study is one of the first in the public domain to examine design and performance criteria for an unmanned aircraft system (UAS) in tandem with its concept of operations. The case study results are intended to support development of airworthiness standards that could form a minimum safety baseline for midsize unmanned rotorcraft performing precision agricultural spraying operations under beyond visual line-of-sight conditions in a rural environment. This study investigates the applicability of current methods, processes, and standards for assuring airworthiness of conventionally piloted (manned) aircraft to assuring the airworthiness of UAS. The study started with the development of a detailed concept of operations for precision agricultural spraying with an unmanned rotorcraft (pp. 5-18). The concept of operations in conjunction with a specimen unmanned rotorcraft were used to develop an operational context and a list of relevant hazards (p. 22). Minimum design and performance requirements necessary to mitigate the hazards provide the foundation of a proposed (or mock) type certification basis. A type certification basis specifies the applicable standards an applicant must show compliance with to receive regulatory approval. A detailed analysis of the current airworthiness regulations for normal-category rotorcraft (14 Code of Federal Regulations, Part 27) was performed. Each Part 27 regulation was evaluated to determine whether it mitigated one of the relevant hazards for the specimen UAS. Those regulations that did were included in the initial core of the type certification basis (pp. 26-31) as written or with some simple modifications. Those regulations that did not mitigate a recognized hazard were excluded from the certification basis. The remaining regulations were applicable in intent, but the text could not be easily tailored. Those regulations were addressed in separate issue papers. Exploiting established regulations avoids the difficult task of generating and interpreting novel requirements, through the use of acceptable, standardized language. The rationale for the disposition of the regulations was assessed and captured (pp. 58-115). The core basis was then augmented by generating additional requirements (pp. 38-47) to mitigate hazards for an unmanned sprayer that are not covered in Part 27.

Hayhurst, Kelly J.

Preparation of the Ice Certification of the Dornier 328 Regional Airliner By Numerical Simulation and By Ground Test

The Dornier 328, a new regional airliner, is to be qualified to FAR25/JAR25 requirements for operation into known icing conditions. All lifting surfaces are pneumatically deiced. Impingement limits were determined using a validated computational fluid dynamic (CFD) code. Wind tunnel tests with a model of the whole aircraft and the isolated empennage equipped with artificial ice shapes showed a degradation of handling characteristics due to ice accretion. Extensive two and three dimensional CFD calculations evaluated ice accretion at the deflection elevator horn. Icing tunnel tests were performed with a model of the horizontal tail with icing similitude fulfilled. The Dornier Do328 powerplant air induction system has successfully completed a program of icing tests in support of aircraft certification for operation into known icing conditions. Potential flight icing conditions were extensively analyzed using a CFD potential flow code and 3-D particle tracking routine to identify critical flight icing conditions. The tunnel test program verified the analytically predicted critical ice accretion surfaces of the air induction system, the adequacy of the ice protection provisions and demonstrated compliance with the applicable (JAR25) regulatory material.

D Welte

Fermilab s Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All of the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility but some experiments are beginning to transition to stop using them. There have been some glitches and learning curve issues but in general the system has been performing well and is being improved as operational problems are addressed.

Dykstra, David

Fermilab's Transition to Token Authentication

Fermilab is the first High Energy Physics institution to transition from X.509 user certificates to authentication tokens in production systems. All the experiments that Fermilab hosts are now using JSON Web Token (JWT) access tokens in their grid jobs. Many software components have been either updated or created for this transition, and most of the software is available to others as open source. The tokens are defined using the WLCG Common JWT Profile. Token attributes for all the tokens are stored in the Fermilab FERRY system which generates the configuration for the CILogon token issuer. High security-value refresh tokens are stored in Hashicorp Vault configured by htvault-config, and JWT access tokens are requested by the htgettoken client through its integration with HTCondor. The Fermilab job submission system jobsub was redesigned to be a lightweight wrapper around HTCondor. The grid workload management system GlideinWMS which is also based on HTCondor was updated to use tokens for pilot job submission. For automated job submissions a managed tokens service was created to reduce duplication of effort and knowledge of how to securely keep tokens active. The existing Fermilab file transfer tool ifdh was updated to work seamlessly with tokens, as well as the Fermilab POMS (Production Operations Management System) which is used to manage automatic job submission and the RCDS (Rapid Code Distribution System) which is used to distribute analysis code via the CernVM FileSystem. The dCache storage system was reconfigured to accept tokens for authentication in place of X.509 proxy certificates. As some services and sites have not yet implemented token support, proxy certificates are still sent with jobs for backwards compatibility, but some experiments are beginning to transition to stop using them.

Dykstra, Dave [Fermilab] (ORCID:0000000326539015)

A Program Certification Assistant Based on Fully Automated Theorem Provers

We describe a certification assistant to support formal safety proofs for programs. It is based on a graphical user interface that hides the low-level details of first-order automated theorem provers while supporting limited interactivity: it allows users to customize and control the proof process on a high level, manages the auxiliary artifacts produced during this process, and provides traceability between the proof obligations and the relevant parts of the program. The certification assistant is part of a larger program synthesis system and is intended to support the deployment of automatically generated code in safety-critical applications.

Denney, Ewen

Guidance and Control Software Project Data - Volume 1: Planning Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes the planning documents from the GCS project. Volume 1 contains five appendices: A. Plan for Software Aspects of Certification for the Guidance and Control Software Project; B. Software Development Standards for the Guidance and Control Software Project; C. Software Verification Plan for the Guidance and Control Software Project; D. Software Configuration Management Plan for the Guidance and Control Software Project; and E. Software Quality Assurance Activities.

Hayhurst, Kelly J.

Progress toward the development of an airfoil icing analysis capability

The NASA-Lewis aircraft icing analysis program is composed of three major sub-programs. These sub-programs are ice accretion simulation, performance degradation evaluation, and ice protection system evaluation. These topics cover all areas of concern related to the simulation of aircraft icing and its consequences. The motivation for these activities is twofold, reduction of time and effort required in experimental programs and the ability to provide reliable information for aircraft certification in icing, over the complete range of environmental conditions. In addition to the analytical activities associated with development of these codes, several experimental programs are underway to provide verification information for existing codes. These experimental programs are also used to investigate the physical processes associated with ice accretion and removal for improvement of present analytical models. The NASA-Lewis icing analysis program is thus striving to provide a full range of analytical tools necessary for evaluation of the consequences of icing and of ice protection systems.

Potapczuk, Mark G.

Best Practices for Crash Modeling and Simulation

Aviation safety can be greatly enhanced by the expeditious use of computer simulations of crash impact. Unlike automotive impact testing, which is now routine, experimental crash tests of even small aircraft are expensive and complex due to the high cost of the aircraft and the myriad of crash impact conditions that must be considered. Ultimately, the goal is to utilize full-scale crash simulations of aircraft for design evaluation and certification. The objective of this publication is to describe "best practices" for modeling aircraft impact using explicit nonlinear dynamic finite element codes such as LS-DYNA, DYNA3D, and MSC.Dytran. Although "best practices" is somewhat relative, it is hoped that the authors' experience will help others to avoid some of the common pitfalls in modeling that are not documented in one single publication. In addition, a discussion of experimental data analysis, digital filtering, and test-analysis correlation is provided. Finally, some examples of aircraft crash simulations are described in several appendices following the main report.

Fasanella, Edwin L.

Compliance with High-Intensity Radiated Fields Regulations - Emitter's Perspective

NASA's Deep Space Network (DSN) uses high-power transmitters on its large antennas to communicate with spacecraft of NASA and its partner agencies. The prime reflectors of the DSN antennas are parabolic, at 34m and 70m in diameter. The DSN transmitters radiate Continuous Wave (CW) signals at 20 kW - 500 kW at X-band and S-band frequencies. The combination of antenna reflector size and high frequency results in a very narrow beam with extensive oscillating near-field pattern. Another unique feature of the DSN antennas is that they (and the radiated beam) move mostly at very slow sidereal rate, essentially identical in magnitude and at the opposite direction of Earth rotation.The DSN is in the process of revamping its documentation to provide analysis of the High Intensity Radiation Fields (HIRF) environment resulting from radio frequency radiation from DSN antennas for comparison to FAA regulations regarding certification of HIRF protection as outlined in the FAA regulations on HIRF protection for aircraft electrical and electronic systems (Title 14, Code of Federal Regulations (14 CFR) [section sign][section sign] 23.1308, 25.1317, 27.1317, and 29.1317).This paper presents work done at JPL, in consultation with the FAA. The work includes analysis of the radiated field structure created by the unique DSN emitters (combination of transmitters and antennas) and comparing it to the fields defined in the environments in the FAA regulations. The paper identifies areas that required special attention, including the implications of the very narrow beam of the DSN emitters and the sidereal rate motion. The paper derives the maximum emitter power allowed without mitigation and the mitigation zones, where required.Finally, the paper presents summary of the results of the analyses of the DSN emitters and the resulting DSN process documentation.

DSN emitters

A Generic Software Safety Document Generator

Formal certification is based on the idea that a mathematical proof of some property of a piece of software can be regarded as a certificate of correctness which, in principle, can be subjected to external scrutiny. In practice, however, proofs themselves are unlikely to be of much interest to engineers. Nevertheless, it is possible to use the information obtained from a mathematical analysis of software to produce a detailed textual justification of correctness. In this paper, we describe an approach to generating textual explanations from automatically generated proofs of program safety, where the proofs are of compliance with an explicit safety policy that can be varied. Key to this is tracing proof obligations back to the program, and we describe a tool which implements this to certify code auto-generated by AutoBayes and AutoFilter, program synthesis systems under development at the NASA Ames Research Center. Our approach is a step towards combining formal certification with traditional certification methods.

Denney, Ewen

Advanced Manufactured Home Case Study: A Collaboration for High-Efficiency, Affordable Housing

The introduction of Zero Energy Ready Home Manufactured Homes (ZERH MH) qualification for manufactured homes has generated significant attention and interest in the industry to employ advanced manufacturing techniques. VEIC engaged with Titan Homes to create an advanced manufactured home design that employs ZERH standards, other client-driven above-code standards, and manufacturing processes improvements. This case study identifies specific energy-efficient and quality improvement measures that were implemented to achieve certification and take advantage of incentives for home manufacturers.

14 SOLAR ENERGY

Automated optical navigation with application to Galileo

This paper presents an overview of an automated optical navigation (AON) system, a lower-cost, faster, earth-based stepping stone to onboard systems. AON provides estimation (orbit determination) and maneuver subsystems which are automatically linked to provide the fast response required by the Galileo mission, AON's first user. A real-time interactive executive schedules the subsystems to run concurrently or sequentially and enables interactive computer-graphics displays designed to speed evaluation and certification of navigation solutions. A compact trajectory integrator provides a favorable combination of speed and accuracy. Resident on a low-cost minicomputer and coded primarily in HAL/S, the NASA standard language for flight software, AON approaches a prototype for autonomous onboard navigation systems of the future.

Klumpp, A. R.

Magnetic Tape Recording for the Eighties

The practical and theoretical aspects of state-of-the-art magnetic tape recording technology are reviewed. Topics covered include the following: (1) analog and digital magnetic tape recording, (2) tape and head wear, (3) wear testing, (4) magnetic tape certification, (5) care, handling, and management of magnetic tape, (6) cleaning, packing, and winding of magnetic tape, (7) tape reels, bands, and packaging, (8) coding techniques for high-density digital recording, and (9) tradeoffs of coding techniques.

Kalil, Ford

Guidance and Control Software Project Data - Volume 2: Development Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes the development documents from the GCS project. Volume 2 contains three appendices: A. Guidance and Control Software Development Specification; B. Design Description for the Pluto Implementation of the Guidance and Control Software; and C. Source Code for the Pluto Implementation of the Guidance and Control Software

Hayhurst, Kelly J.

Guidance and Control Software Project Data - Volume 3: Verification Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes the verification documents from the GCS project. Volume 3 contains four appendices: A. Software Verification Cases and Procedures for the Guidance and Control Software Project; B. Software Verification Results for the Pluto Implementation of the Guidance and Control Software; C. Review Records for the Pluto Implementation of the Guidance and Control Software; and D. Test Results Logs for the Pluto Implementation of the Guidance and Control Software.

Hayhurst, Kelly J.

Guidance and Control Software Project Data - Volume 4: Configuration Management and Quality Assurance Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes configuration management and quality assurance documents from the GCS project. Volume 4 contains six appendices: A. Software Accomplishment Summary for the Guidance and Control Software Project; B. Software Configuration Index for the Guidance and Control Software Project; C. Configuration Management Records for the Guidance and Control Software Project; D. Software Quality Assurance Records for the Guidance and Control Software Project; E. Problem Report for the Pluto Implementation of the Guidance and Control Software Project; and F. Support Documentation Change Reports for the Guidance and Control Software Project.

Hayhurst, Kelly J.

Performance, Loads and Stability of Heavy Lift Tiltrotors

Summaries of rotor performance are presented for a 124,000-lb Large Civil Tilt Rotor (LCTR) design, along with isolated-rotor and fully-coupled wing/rotor aeroelastic stability. A major motivation of the present research is the effect of size on rotor dynamics. Simply scaling up existing rotor designs to the vehicle size under study would result in unacceptable rotor weight. The LCTR was the most promising of several large rotorcraft concepts produced by the NASA Heavy Lift Rotorcraft Systems Investigation. It was designed to carry 120 passengers for 1200 nm, with performance of 350 knots at 30,000 ft altitude. Design features included a low-mounted wing and hingeless rotors, with a very low cruise tip speed of 350 ft/sec. The LCTR was sized by the'RC code developed by the U. S. Army Aeroflightdynamics Directorate. The rotor was then optimized using the CAMRAD II comprehensive analysis code. The blade and wing structures were designed by Pennsylvania State University to meet the rotor loads calculated by CAMRAD II and wing loads required for certification. Aeroelastic stability was confirmed by further CAMRAD II analysis, based on the optimized rotor and wing designs.

Acree, Cecil W., Jr.

Assurance Cases for Proofs as Evidence

Proof-carrying code (PCC) provides a 'gold standard' for establishing formal and objective confidence in program behavior. However, in order to extend the benefits of PCC - and other formal certification techniques - to realistic systems, we must establish the correspondence of a mathematical proof of a program's semantics and its actual behavior. In this paper, we argue that assurance cases are an effective means of establishing such a correspondence. To this end, we present an assurance case pattern for arguing that a proof is free from various proof hazards. We also instantiate this pattern for a proof-based mechanism to provide evidence about a generic medical device software.

Chaki, Sagar