Search NASASearch

SEARCH · Search NASA

Results for “certification coding”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

A Program Certification Assistant Based on Fully Automated Theorem Provers

We describe a certification assistant to support formal safety proofs for programs. It is based on a graphical user interface that hides the low-level details of first-order automated theorem provers while supporting limited interactivity: it allows users to customize and control the proof process on a high level, manages the auxiliary artifacts produced during this process, and provides traceability between the proof obligations and the relevant parts of the program. The certification assistant is part of a larger program synthesis system and is intended to support the deployment of automatically generated code in safety-critical applications.

Denney, Ewen

Guidance and Control Software Project Data - Volume 1: Planning Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes the planning documents from the GCS project. Volume 1 contains five appendices: A. Plan for Software Aspects of Certification for the Guidance and Control Software Project; B. Software Development Standards for the Guidance and Control Software Project; C. Software Verification Plan for the Guidance and Control Software Project; D. Software Configuration Management Plan for the Guidance and Control Software Project; and E. Software Quality Assurance Activities.

Hayhurst, Kelly J.

Progress toward the development of an airfoil icing analysis capability

The NASA-Lewis aircraft icing analysis program is composed of three major sub-programs. These sub-programs are ice accretion simulation, performance degradation evaluation, and ice protection system evaluation. These topics cover all areas of concern related to the simulation of aircraft icing and its consequences. The motivation for these activities is twofold, reduction of time and effort required in experimental programs and the ability to provide reliable information for aircraft certification in icing, over the complete range of environmental conditions. In addition to the analytical activities associated with development of these codes, several experimental programs are underway to provide verification information for existing codes. These experimental programs are also used to investigate the physical processes associated with ice accretion and removal for improvement of present analytical models. The NASA-Lewis icing analysis program is thus striving to provide a full range of analytical tools necessary for evaluation of the consequences of icing and of ice protection systems.

Potapczuk, Mark G.

Best Practices for Crash Modeling and Simulation

Aviation safety can be greatly enhanced by the expeditious use of computer simulations of crash impact. Unlike automotive impact testing, which is now routine, experimental crash tests of even small aircraft are expensive and complex due to the high cost of the aircraft and the myriad of crash impact conditions that must be considered. Ultimately, the goal is to utilize full-scale crash simulations of aircraft for design evaluation and certification. The objective of this publication is to describe "best practices" for modeling aircraft impact using explicit nonlinear dynamic finite element codes such as LS-DYNA, DYNA3D, and MSC.Dytran. Although "best practices" is somewhat relative, it is hoped that the authors' experience will help others to avoid some of the common pitfalls in modeling that are not documented in one single publication. In addition, a discussion of experimental data analysis, digital filtering, and test-analysis correlation is provided. Finally, some examples of aircraft crash simulations are described in several appendices following the main report.

Fasanella, Edwin L.

Compliance with High-Intensity Radiated Fields Regulations - Emitter's Perspective

NASA's Deep Space Network (DSN) uses high-power transmitters on its large antennas to communicate with spacecraft of NASA and its partner agencies. The prime reflectors of the DSN antennas are parabolic, at 34m and 70m in diameter. The DSN transmitters radiate Continuous Wave (CW) signals at 20 kW - 500 kW at X-band and S-band frequencies. The combination of antenna reflector size and high frequency results in a very narrow beam with extensive oscillating near-field pattern. Another unique feature of the DSN antennas is that they (and the radiated beam) move mostly at very slow sidereal rate, essentially identical in magnitude and at the opposite direction of Earth rotation.The DSN is in the process of revamping its documentation to provide analysis of the High Intensity Radiation Fields (HIRF) environment resulting from radio frequency radiation from DSN antennas for comparison to FAA regulations regarding certification of HIRF protection as outlined in the FAA regulations on HIRF protection for aircraft electrical and electronic systems (Title 14, Code of Federal Regulations (14 CFR) [section sign][section sign] 23.1308, 25.1317, 27.1317, and 29.1317).This paper presents work done at JPL, in consultation with the FAA. The work includes analysis of the radiated field structure created by the unique DSN emitters (combination of transmitters and antennas) and comparing it to the fields defined in the environments in the FAA regulations. The paper identifies areas that required special attention, including the implications of the very narrow beam of the DSN emitters and the sidereal rate motion. The paper derives the maximum emitter power allowed without mitigation and the mitigation zones, where required.Finally, the paper presents summary of the results of the analyses of the DSN emitters and the resulting DSN process documentation.

DSN emitters

A Generic Software Safety Document Generator

Formal certification is based on the idea that a mathematical proof of some property of a piece of software can be regarded as a certificate of correctness which, in principle, can be subjected to external scrutiny. In practice, however, proofs themselves are unlikely to be of much interest to engineers. Nevertheless, it is possible to use the information obtained from a mathematical analysis of software to produce a detailed textual justification of correctness. In this paper, we describe an approach to generating textual explanations from automatically generated proofs of program safety, where the proofs are of compliance with an explicit safety policy that can be varied. Key to this is tracing proof obligations back to the program, and we describe a tool which implements this to certify code auto-generated by AutoBayes and AutoFilter, program synthesis systems under development at the NASA Ames Research Center. Our approach is a step towards combining formal certification with traditional certification methods.

Denney, Ewen

Automated optical navigation with application to Galileo

This paper presents an overview of an automated optical navigation (AON) system, a lower-cost, faster, earth-based stepping stone to onboard systems. AON provides estimation (orbit determination) and maneuver subsystems which are automatically linked to provide the fast response required by the Galileo mission, AON's first user. A real-time interactive executive schedules the subsystems to run concurrently or sequentially and enables interactive computer-graphics displays designed to speed evaluation and certification of navigation solutions. A compact trajectory integrator provides a favorable combination of speed and accuracy. Resident on a low-cost minicomputer and coded primarily in HAL/S, the NASA standard language for flight software, AON approaches a prototype for autonomous onboard navigation systems of the future.

Klumpp, A. R.

Magnetic Tape Recording for the Eighties

The practical and theoretical aspects of state-of-the-art magnetic tape recording technology are reviewed. Topics covered include the following: (1) analog and digital magnetic tape recording, (2) tape and head wear, (3) wear testing, (4) magnetic tape certification, (5) care, handling, and management of magnetic tape, (6) cleaning, packing, and winding of magnetic tape, (7) tape reels, bands, and packaging, (8) coding techniques for high-density digital recording, and (9) tradeoffs of coding techniques.

Kalil, Ford

Guidance and Control Software Project Data - Volume 2: Development Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes the development documents from the GCS project. Volume 2 contains three appendices: A. Guidance and Control Software Development Specification; B. Design Description for the Pluto Implementation of the Guidance and Control Software; and C. Source Code for the Pluto Implementation of the Guidance and Control Software

Hayhurst, Kelly J.

Guidance and Control Software Project Data - Volume 3: Verification Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes the verification documents from the GCS project. Volume 3 contains four appendices: A. Software Verification Cases and Procedures for the Guidance and Control Software Project; B. Software Verification Results for the Pluto Implementation of the Guidance and Control Software; C. Review Records for the Pluto Implementation of the Guidance and Control Software; and D. Test Results Logs for the Pluto Implementation of the Guidance and Control Software.

Hayhurst, Kelly J.

Guidance and Control Software Project Data - Volume 4: Configuration Management and Quality Assurance Documents

The Guidance and Control Software (GCS) project was the last in a series of software reliability studies conducted at Langley Research Center between 1977 and 1994. The technical results of the GCS project were recorded after the experiment was completed. Some of the support documentation produced as part of the experiment, however, is serving an unexpected role far beyond its original project context. Some of the software used as part of the GCS project was developed to conform to the RTCA/DO-178B software standard, "Software Considerations in Airborne Systems and Equipment Certification," used in the civil aviation industry. That standard requires extensive documentation throughout the software development life cycle, including plans, software requirements, design and source code, verification cases and results, and configuration management and quality control data. The project documentation that includes this information is open for public scrutiny without the legal or safety implications associated with comparable data from an avionics manufacturer. This public availability has afforded an opportunity to use the GCS project documents for DO-178B training. This report provides a brief overview of the GCS project, describes the 4-volume set of documents and the role they are playing in training, and includes configuration management and quality assurance documents from the GCS project. Volume 4 contains six appendices: A. Software Accomplishment Summary for the Guidance and Control Software Project; B. Software Configuration Index for the Guidance and Control Software Project; C. Configuration Management Records for the Guidance and Control Software Project; D. Software Quality Assurance Records for the Guidance and Control Software Project; E. Problem Report for the Pluto Implementation of the Guidance and Control Software Project; and F. Support Documentation Change Reports for the Guidance and Control Software Project.

Hayhurst, Kelly J.

Performance, Loads and Stability of Heavy Lift Tiltrotors

Summaries of rotor performance are presented for a 124,000-lb Large Civil Tilt Rotor (LCTR) design, along with isolated-rotor and fully-coupled wing/rotor aeroelastic stability. A major motivation of the present research is the effect of size on rotor dynamics. Simply scaling up existing rotor designs to the vehicle size under study would result in unacceptable rotor weight. The LCTR was the most promising of several large rotorcraft concepts produced by the NASA Heavy Lift Rotorcraft Systems Investigation. It was designed to carry 120 passengers for 1200 nm, with performance of 350 knots at 30,000 ft altitude. Design features included a low-mounted wing and hingeless rotors, with a very low cruise tip speed of 350 ft/sec. The LCTR was sized by the'RC code developed by the U. S. Army Aeroflightdynamics Directorate. The rotor was then optimized using the CAMRAD II comprehensive analysis code. The blade and wing structures were designed by Pennsylvania State University to meet the rotor loads calculated by CAMRAD II and wing loads required for certification. Aeroelastic stability was confirmed by further CAMRAD II analysis, based on the optimized rotor and wing designs.

Acree, Cecil W., Jr.

Assurance Cases for Proofs as Evidence

Proof-carrying code (PCC) provides a 'gold standard' for establishing formal and objective confidence in program behavior. However, in order to extend the benefits of PCC - and other formal certification techniques - to realistic systems, we must establish the correspondence of a mathematical proof of a program's semantics and its actual behavior. In this paper, we argue that assurance cases are an effective means of establishing such a correspondence. To this end, we present an assurance case pattern for arguing that a proof is free from various proof hazards. We also instantiate this pattern for a proof-based mechanism to provide evidence about a generic medical device software.

Chaki, Sagar

Structural dynamics: Probabilistic structural analysis methods. Program overview

A brief description is provided of the fundamental aspects of a quantification process. Progress since the last structural durability conference in 1989 is summarized. The methodology to date and that to be developed during the life of the program is presented. The uncertain factors are presented. The approach is outlined that is required to achieve component and/or system certification in the shortest possible time for affordable reliability risk. Two new elements appear in a block diagram: (1) uncertainties in human factor, and (2) uncertainties in the computer code. Research to quantify the uncertainties in the human factor was initiated and is discussed.

Chamis, Christos C.

Simulation of Aircraft Engine Blade-Out Structural Dynamics

A primary concern of aircraft structure designers is the accurate simulation of the blade-out event and the subsequent windmilling of the engine. Reliable simulations of the blade-out event are required to insure structural integrity during flight as well as to guarantee successful blade-out certification testing. The system simulation includes the lost blade loadings and the interactions between the rotating turbomachinery and the remaining aircraft structural components. General-purpose finite element structural analysis codes such as MSC NASTRAN are typically used and special provisions are made to include transient effects from the blade loss and rotational effects resulting from the engine's turbomachinery. The present study provides the equations of motion for rotordynamic response including the effect of spooldown speed and rotor unbalance and examines the effects of these terms on a cantilevered rotor. The effect of spooldown speed is found to be greater with increasing spooldown rate. The parametric term resulting from the mass unbalance has a more significant effect on the rotordynamic response than does the spooldown term. The parametric term affects both the peak amplitudes as well as the resonant frequencies of the rotor.

Lawrence, Charles

Simulation of Aircraft Engine Blade-Out Structural Dynamics

A primary concern of aircraft structure designers is the accurate simulation of the blade-out event and the subsequent windmilling of the engine. Reliable simulations of the blade-out event are required to insure structural integrity during flight as well as to guarantee successful blade-out certification testing. The system simulation includes the lost blade loadings and the interactions between the rotating turbomachinery and the remaining aircraft structural components. General-purpose finite element structural analysis codes such as MSC NASTRAN are typically used and special provisions are made to include transient effects from the blade loss and rotational effects resulting from the engine's turbomachinery. The present study provides the equations of motion for rotordynamic response including the effect of spooldown speed and rotor unbalance and examines the effects of these terms on a cantilevered rotor. The effect of spooldown speed is found to be greater with increasing spooldown rate. The parametric term resulting from the mass unbalance has a more significant effect on the rotordynamic response than does the spooldown term. The parametric term affects both the peak amplitudes as well as the resonant frequencies of the rotor.

Lawrence, Charles

Group Capability Model

The Group Capability Model (GCM) is a software tool that allows an organization, from first line management to senior executive, to monitor and track the health (capability) of various groups in performing their contractual obligations. GCM calculates a Group Capability Index (GCI) by comparing actual head counts, certifications, and/or skills within a group. The model can also be used to simulate the effects of employee usage, training, and attrition on the GCI. A universal tool and common method was required due to the high risk of losing skills necessary to complete the Space Shuttle Program and meet the needs of the Constellation Program. During this transition from one space vehicle to another, the uncertainty among the critical skilled workforce is high and attrition has the potential to be unmanageable. GCM allows managers to establish requirements for their group in the form of head counts, certification requirements, or skills requirements. GCM then calculates a Group Capability Index (GCI), where a score of 1 indicates that the group is at the appropriate level; anything less than 1 indicates a potential for improvement. This shows the health of a group, both currently and over time. GCM accepts as input head count, certification needs, critical needs, competency needs, and competency critical needs. In addition, team members are categorized by years of experience, percentage of contribution, ex-members and their skills, availability, function, and in-work requirements. Outputs are several reports, including actual vs. required head count, actual vs. required certificates, CGI change over time (by month), and more. The program stores historical data for summary and historical reporting, which is done via an Excel spreadsheet that is color-coded to show health statistics at a glance. GCM has provided the Shuttle Ground Processing team with a quantifiable, repeatable approach to assessing and managing the skills in their organization. They now have a common frame of reference across NASA/contractor lines to communicate and mitigate any critical skills concerns.

Olejarski, Michael

Development of Advanced Verification and Validation Procedures and Tools for the Certification of Learning Systems in Aerospace Applications

Adaptive control technologies that incorporate learning algorithms have been proposed to enable automatic flight control and vehicle recovery, autonomous flight, and to maintain vehicle performance in the face of unknown, changing, or poorly defined operating environments. In order for adaptive control systems to be used in safety-critical aerospace applications, they must be proven to be highly safe and reliable. Rigorous methods for adaptive software verification and validation must be developed to ensure that control system software failures will not occur. Of central importance in this regard is the need to establish reliable methods that guarantee convergent learning, rapid convergence (learning) rate, and algorithm stability. This paper presents the major problems of adaptive control systems that use learning to improve performance. The paper then presents the major procedures and tools presently developed or currently being developed to enable the verification, validation, and ultimate certification of these adaptive control systems. These technologies include the application of automated program analysis methods, techniques to improve the learning process, analytical methods to verify stability, methods to automatically synthesize code, simulation and test methods, and tools to provide on-line software assurance.

Jacklin, Stephen