Search NASA⌕ Search

SEARCH · Search NASA

Results for “specification logic”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Experimental Evaluation of a Planning Language Suitable for Formal Verification

The marriage of model checking and planning faces two seemingly diverging alternatives: the need for a planning language expressive enough to capture the complexity of real-life applications, as opposed to a language simple, yet robust enough to be amenable to exhaustive verification and validation techniques. In an attempt to reconcile these differences, we have designed an abstract plan description language, ANMLite, inspired from the Action Notation Modeling Language (ANML) [17]. We present the basic concepts of the ANMLite language as well as an automatic translator from ANMLite to the model checker SAL (Symbolic Analysis Laboratory) [7]. We discuss various aspects of specifying a plan in terms of constraints and explore the implications of choosing a robust logic behind the specification of constraints, rather than simply propose a new planning language. Additionally, we provide an initial assessment of the efficiency of model checking to search for solutions of planning problems. To this end, we design a basic test benchmark and study the scalability of the generated SAL models in terms of plan complexity.

Butler, Rick W.↗

Investigation of several proxies to estimate sulfuric acid concentration in volcanic plume conditions

Sulfuric acid (H2SO4) is commonly accepted as a key precursor for atmospheric new particle formation (NPF). However, direct measurements of [H2SO4] remain challenging, thus preventing the determination of this important quantity, and, consequently, a complete understanding of its contribution to the NPF process. Several proxies have been developed to bridge the gaps, but their ability to predict [H2SO4] in very specific conditions such as those encountered in volcanic plumes (including in particular high sulphur dioxide mixing ratios) has not been evaluated so far. In this context, the main objective of the present study was to develop new proxies for daytime [H2SO4] in volcanic plume conditions and compare their performance to that of the proxies available in the literature. In specific, the data collected at Maïdo during the OCTAVE 2018 campaign, in the volcanic eruption plume of the Piton de la Fournaise, were first used to derive seven proxies based on the knowledge of sulphur dioxide (SO2) mixing ratio, global radiation, condensation sink (CS) and relative humidity (RH). In three of the seven proxies (F1–F3), all variables were given equal weight in the prediction of [H2SO4], while adjusted powers were allowed for the different variables in the other four proxies (A1–A4). Proxies A1–A4 were overall found to perform better compared to F1–F3, with, in specific, improved predictive ability for [H2SO4] > 2 × 108 per cu.cm. The CS was observed to play an important role in regulating [H2SO4], while, in contrast, the inclusion of RH did not improve the predictions. A last expression accounting for an additional sink term related to cluster formation, S1, was also tested and showed a very good predictive ability over the whole range of measured [H2SO4]. The newly developed proxies were in a second step further evaluated using airborne measurements performed in the passive degassing plume of Etna during the STRAP 2016 campaign. Increased correlations between observed and predicted [H2SO4] were obtained when the dependence of predicted [H2SO4] over CS was the lowest, and when the dependence over [SO2] was concurrently the highest. The best predictions were finally retrieved by the simple formulation of F2 (in which [SO2] and radiation alone were assumed to explain the variations of [H2SO4] with equal contributions), with a pre factor adapted to the STRAP data. All in all, our results illustrate the fairly good capacity of the proxy available in the literature to describe [H2SO4] in volcanic plume conditions, but highlight at the same time the benefit of the newly developed proxies for the prediction of the highest concentrations ([H2SO4] > 2–3 × 108 per cu.cm). Also, the contrasting behaviours of the new proxies in the two investigated datasets indicate that in volcanic plumes like in other environments, the relevance of a proxy can be affected by changes in environmental conditions, and that location specific coefficients do logically improve the predictions.

new particle formation↗

The Formal Semantics of PVS

A specification language is a medium for expressing what is computed rather than how it is computed. Specification languages share some features with programming languages but are also different in several important ways. For our purpose, a specification language is a logic within which the behavior of computational systems can be formalized. Although a specification can be used to simulate the behavior of such systems, we mainly use specifications to state and prove system properties with mechanical assistance. We present the formal semantics of the specification language of SRI's Prototype Verification System (PVS). This specification language is based on the simply typed lambda calculus. The novelty in PVS is that it contains very expressive language features whose static analysis (e.g., typechecking) requires the assistance of a theorem prover. The formal semantics illuminates several of the design considerations underlying PVS, the interaction between theorem proving and typechecking.

Owre, Sam↗

Towards the formal specification of the requirements and design of a processor interface unit

Work to formally specify the requirements and design of a Processor Interface Unit (PIU), a single-chip subsystem providing memory interface, bus interface, and additional support services for a commercial microprocessor within a fault-tolerant computer system, is described. This system, the Fault-Tolerant Embedded Processor (FTEP), is targeted towards applications in avionics and space requiring extremely high levels of mission reliability, extended maintenance free operation, or both. The approaches that were developed for modeling the PIU requirements and for composition of the PIU subcomponents at high levels of abstraction are described. These approaches were used to specify and verify a nontrivial subset of the PIU behavior. The PIU specification in Higher Order Logic (HOL) is documented in a companion NASA contractor report entitled 'Towards the Formal Specification of the Requirements and Design of a Processor Interfacs Unit - HOL Listings.' The subsequent verification approach and HOL listings are documented in NASA contractor report entitled 'Towards the Formal Verification of the Requirements and Design of a Processor Interface Unit' and NASA contractor report entitled 'Towards the Formal Verification of the Requirements and Design of a Processor Interface Unit - HOL Listings.'

Fura, David A.↗

Resistance exercise countermeasures for space flight: implications of training specificity

While resistance exercise should be a logical choice for prevention of strength loss during unloading, the principle of training specificity cannot be overlooked. Our purpose was to explore training specificity in describing the effect of our constant load exercise countermeasure on isokinetic strength performance. Twelve healthy men (mean +/- SD: 28.0 +/- 5.2 years, 179.4 +/- 3.9 cm, 77.5 +/- 13.6 kg) were randomly assigned to no exercise or resistance exercise (REX) during 14 days of bed rest. REX performed five sets of leg press exercise to volitional fatigue (6-10 repetitions) every other day. Unilateral isokinetic concentric-eccentric knee extension testing performed before and on day 15 prior to reambulation included torque-velocity and power-velocity relationships at four velocities (0.52, 1.75, 2.97, and 4.19 rad s-1), torque-position relationship, and contractile work capacity (10 repetitions at 1.05 rad s-1). Two (group) x 2 (time) ANOVA revealed no group x time interactions; thus, groups were combined. Across velocities, angle-specific torque fell 18% and average power fell 20% (p < 0.05). No velocity x time or mode (concentric/eccentric) x time interactions were noted. Torque x position decreased on average 24% (p < 0.05). Total contractile work dropped 27% (p < 0.05). Results indicate bed rest induces rapid and marked reductions in strength and our constant load resistance training protocol did not prevent isokinetic strength losses. Differences between closed-chain training and open-chain testing may explain the lack of protection.

Randomized Controlled Trial↗

Army/NASA small turboshaft engine digital controls research program

The emphasis of a program to conduct digital controls research for small turboshaft engines is on engine test evaluation of advanced control logic using a flexible microprocessor based digital control system designed specifically for research on advanced control logic. Control software is stored in programmable memory. New control algorithms may be stored in a floppy disk and loaded directly into memory. This feature facilitates comparative evaluation of different advanced control modes. The central processor in the digital control is an Intel 8086 16 bit microprocessor. Control software is programmed in assembly language. Software checkout is accomplished prior to engine test by connecting the digital control to a real time hybrid computer simulation of the engine. The engine currently installed in the facility has a hydromechanical control modified to allow electrohydraulic fuel metering and VG actuation by the digital control. Simulation results are presented which show that the modern control reduces the transient rotor speed droop caused by unanticipated load changes such as cyclic pitch or wind gust transients.

Sellers, J. F.↗

High-Speed, High-Resolution Time-to-Digital Conversion

This innovation is a series of time-tag pulses from a photomultiplier tube, featuring short time interval between pulses (e.g., 2.5 ns). Using the previous art, dead time between pulses is too long, or too much hardware is required, including a very-high-speed demultiplexer. A faster method is needed. The goal of this work is to provide circuits to time-tag pulses that arrive at a high rate using the hardwired logic in an FPGA - specifically the carry chain - to create what is (in effect) an analog delay line. High-speed pulses travel down the chain in a "wave." For instance, a pulse train has been demonstrated from a 1- GHz source reliably traveling down the carry chain. The size of the carry chain is over 10 ns in the time domain. Thus, multiple pulses will travel down the carry chain in a wave simultaneously. A register clocked by a low-skew clock takes a "snapshot" of the wave. Relatively simple logic can extract the pulses from the snapshot picture by detecting the transitions between logic states. The propagation delay of CMOS (complementary metal oxide semiconductor) logic circuits will differ and/or change as a result of temperature, voltage, age, radiation, and manufacturing variances. The time-to-digital conversion circuits can be calibrated with test signals, or the changes can be nulled by a separate on-die calibration channel, in a closed loop circuit.

Katz, Richard↗

Aiding Vertical Guidance Understanding

A two-part study was conducted to evaluate modern flight deck automation and interfaces. In the first part, a survey was performed to validate the existence of automation surprises with current pilots. Results indicated that pilots were often surprised by the behavior of the automation. There were several surprises that were reported more frequently than others. An experimental study was then performed to evaluate (1) the reduction of automation surprises through training specifically for the vertical guidance logic, and (2) a new display that describes the flight guidance in terms of aircraft behaviors instead of control modes. The study was performed in a simulator that was used to run a complete flight with actual airline pilots. Three groups were used to evaluate the guidance display and training. In the training, condition, participants went through a training program for vertical guidance before flying the simulation. In the display condition, participants ran through the same training program and then flew the experimental scenario with the new Guidance-Flight Mode Annunciator (G-FMA). Results showed improved pilot performance when given training specifically for the vertical guidance logic and greater improvements when given the training and the new G-FMA. Using actual behavior of the avionics to design pilot training and FMA is feasible, and when the automated vertical guidance mode of the Flight Management System is engaged, the display of the guidance mode and targets yields improved pilot performance.

Feary, Michael↗

A Self-Tuning Kalman Filter for Autonomous Spacecraft Navigation

Most navigation systems currently operated by NASA are ground-based, and require extensive support to produce accurate results. Recently developed systems that use Kalman Filter and Global Positioning System (GPS) data for orbit determination greatly reduce dependency on ground support, and have potential to provide significant economies for NASA spacecraft navigation. Current techniques of Kalman filtering, however, still rely on manual tuning from analysts, and cannot help in optimizing autonomy without compromising accuracy and performance. This paper presents an approach to produce a high accuracy autonomous navigation system fully integrated with the flight system. The resulting system performs real-time state estimation by using an Extended Kalman Filter (EKF) implemented with high-fidelity state dynamics model, as does the GPS Enhanced Orbit Determination Experiment (GEODE) system developed by the NASA Goddard Space Flight Center. Augmented to the EKF is a sophisticated neural-fuzzy system, which combines the explicit knowledge representation of fuzzy logic with the learning power of neural networks. The fuzzy-neural system performs most of the self-tuning capability and helps the navigation system recover from estimation errors. The core requirement is a method of state estimation that handles uncertainties robustly, capable of identifying estimation problems, flexible enough to make decisions and adjustments to recover from these problems, and compact enough to run on flight hardware. The resulting system can be extended to support geosynchronous spacecraft and high-eccentricity orbits. Mathematical methodology, systems and operations concepts, and implementation of a system prototype are presented in this paper. Results from the use of the prototype to evaluate optimal control algorithms implemented are discussed. Test data and major control issues (e.g., how to define specific roles for fuzzy logic to support the self-learning capability) are also discussed. In addition, architecture of a complete end-to-end candidate flight system that provides navigation with highly autonomous control using data from GPS is presented.

Truong, Son H.↗

Verifying PLC Programs via Monitors: Extending the Integration of FRET and PLCverif

Verification of Programmable Logic Controller (PLC) programs requires reasoning about propositions qualified in terms of time. CERN’s PLCverif, an open-source tool for the analysis of safety-critical PLC systems, uses Linear Temporal Logic (LTL) for the specification of properties. Until now, PLCverif depended on third-party tools that accept LTL specifications to perform verification. However, our experience with industrial PLC programs shows that, to overcome analysis limitations, a wide range of techniques are needed to successfully verify complex properties. In this paper, we extend PLCverif to enable PLC program verification of pure-past LTL (PLTL) safety properties with assertion-based verification tools. To this end, we take an algorithm from the runtime-monitoring domain, apply it to bounded model checking of PLC programs, and implement it in PLCverif. We extend the integration of NASA’s Formal Requirements Elicitation Tool (FRET) into PLCverif to use PLTL properties generated with FRET. In addition, we leverage the program structure induced by the PLC scan-cycle for a state-space reduction. Finally, we expose the algorithm to a real-world case study of critical systems at CERN.

Formal verification↗

Model Checking - My 27-Year Quest to Overcome the State Explosion Problem

Model Checking is an automatic verification technique for state-transition systems that are finite=state or that have finite-state abstractions. In the early 1980 s in a series of joint papers with my graduate students E.A. Emerson and A.P. Sistla, we proposed that Model Checking could be used for verifying concurrent systems and gave algorithms for this purpose. At roughly the same time, Joseph Sifakis and his student J.P. Queille at the University of Grenoble independently developed a similar technique. Model Checking has been used successfully to reason about computer hardware and communication protocols and is beginning to be used for verifying computer software. Specifications are written in temporal logic, which is particularly valuable for expressing concurrency properties. An intelligent, exhaustive search is used to determine if the specification is true or not. If the specification is not true, the Model Checker will produce a counterexample execution trace that shows why the specification does not hold. This feature is extremely useful for finding obscure errors in complex systems. The main disadvantage of Model Checking is the state-explosion problem, which can occur if the system under verification has many processes or complex data structures. Although the state-explosion problem is inevitable in worst case, over the past 27 years considerable progress has been made on the problem for certain classes of state-transition systems that occur often in practice. In this talk, I will describe what Model Checking is, how it works, and the main techniques that have been developed for combating the state explosion problem.

Clarke, Ed↗

Future planetary missions - The options

The present paper describes the National Aeronautics and Space Administration's plan for the exploration of the solar system during the next decade. The scientific and technological aspects of the overall strategy are discussed. The logic that defines the specific science investigations and the selection of the exploration targets is outlined.

Herman, D. H.↗

ISyCL technical report

The Air Force Integrated Information Systems Evolution Environment (IISEE) is a program focused on the development of technology for enabling the planning definition development and maintenance of evolutionary integrated information systems. This program has studied the representational needs of this knowledge base from the point of view of the needs of engineering, manufacturing, and logistics Evolutionary Information Systems (EIS). The definition of the concepts for a suite of automated tools and environments to support the pursuit of such engineering, manufacturing, and logistics EIS's has also required examination of languages and representation schemes for the knowledge base of these integrated systems. To accomplish this purpose, the language must be very rich, and must support object orientation, relational orientation, persistent storage, process transaction specification, and first order logic. The task of designing a unified language which supports these paradigms is a challenge. The Information Systems Constraint Language (ISyCL) is described. It was designed to meet the definitional and knowledge representation needs of three perspectives. It supports users from the area expert to the data base designer.

Decker, Louis P.↗

Improve SSME power balance model

Effort was dedicated to development and testing of a formal strategy for reconciling uncertain test data with physically limited computational prediction. Specific weaknesses in the logical structure of the current Power Balance Model (PBM) version are described with emphasis given to the main routing subroutines BAL and DATRED. Selected results from a variational analysis of PBM predictions are compared to Technology Test Bed (TTB) variational study results to assess PBM predictive capability. The motivation for systematic integration of uncertain test data with computational predictions based on limited physical models is provided. The theoretical foundation for the reconciliation strategy developed in this effort is presented, and results of a reconciliation analysis of the Space Shuttle Main Engine (SSME) high pressure fuel side turbopump subsystem are examined.

Karr, Gerald R.↗

Meeting the Deadline: Why, When and How

A normative system is defined as any set of interacting agents whose behavior can usefully be regarded as norm-directed. Most organizations, and more specifically institutions, fall under this definition. Interactions in these normative systems are regulated by normative templates that describe desired behavior in terms of deontic concepts (obligations, prohibitions and permissions), deadlines, violations and sanctions. Agreements between agents, and between an agent and the society, can then be specified by means of contracts. Contracts provide flexible but verifiable means to integrate society requirements and agent autonomy. and are an adequate means for the explicit specification of interactions. From the society perspective, it is important that these contracts adhere to the specifications described in the model of the organization. If we want to automate such verifications, we have to formalize the languages used for contracts and for the specification of organizations. The logic LCR is based on deontic temporal logic. LCR is an expressive language for describing interaction in multi-agent systems, including obligations with deadlines. Deadlines are important norms in most interactions between agents. Intuitively, a deadline states that an agent should perform an action before a certain point in time. The obligation to perform the action starts at the moment the deadline becomes active. E.g. when a contract is signed or approved. If the action is not performed in time a violation of the deadline occurs. It can be specified independently what measure has to be taken in this case. In this paper we investigate the deadline concept in more detail. The paper is organized as follows. Section 2 defines the variant of CTL we use. In section 3, we discuss the basic intuitions of deadlines. Section 4 presents a first intuitive formalization for deadlines. In section 5, we look at a more complex model for deadlines trying to catch some more practical aspects. Finally, in section 6 we present issues for future work and our conciusions.

Dignum, Frank↗

Universal Reconfigurable Translator Module (URTM) Final Report

This report describes the Universal Reconfigurable Translation Module, or URTM. The URTM was developed by Sigma Space Corporation for NASA in order to translate specific serial protocols, both logically and physically. At present, the prototype configuration has targeted MIL-STD-1553B (RT and BC), IEEE 1394b (Firewire), and ECSS-E-50-12A (SpaceWire). The objectives of this program were to study the feasibility of a configurable URTM to translate serial link data as might be used in a space-flight mission and to design, develop, document, and deliver an engineering prototype model of the URTM with a path to spaceflight. By simply connecting two of the three Physical Interface Modules (PIM) on either end of the RPTM (Reconfigurable Protocol Translator Module), the URTM then self configures via a library of interface translation functions, thereby allowing the two data links to communicate seamlessly.

Leventhal, Edward↗

Decentralized Control Synthesis for Air Traffic Management in Urban Air Mobility

Urban air mobility (UAM) refers to air transportation services within an urban area, often in an on-demand fashion. We study air traffic management (ATM) for vehicles in a UAM fleet, while guaranteeing system safety requirements such as traffic separation. Existing ATM methods for unmanned aerial systems, such as UAS traffic management, utilize alternative approaches which do not provide strict safety guarantees. No established infrastructure exists for providing ATM at scale for UAM. We provide a decentralized, hierarchical approach for UAM ATM that allows for scalability to high traffic densities as well as providing theoretical guarantees of correctness with respect to user-provided safety specifications. Our main contributions are two-fold. First, we propose a novel UAM ATM architecture that divides the control authority between vertihubs that are each in charge of all UAM vehicles in their local airspace. Each vertihub also contains a number of vertiports that are in charge of UAM vehicle takeoffs and landings. The resulting architecture is decentralized and hierarchical, which not only enables scalability, but also robustness in the event of any individual vertihub or vertiport no longer being operational. Second, we provide a contract-based correct-by-construction reactive synthesis approach that provably guarantees safety properties with respect to user-provided specifications in linear temporal logic. We demonstrate the approach on large-volume UAM air traffic data.

Urban Air Mobility↗

Marin County Wildland Fires: Examining Fuel Load and Land Cover Change to Inform Fire Prevention and Suppression Decisions in Marin County, CA

Heightened occurrence of severe wildfires in the Western United States is increasing the need to better understand regions of high potential wild fire severity and develop methodologies for identifying the best locations for fuels reduction and active wildfire suppression, especially in populated regions such as Marin County, California. Marin County, located in the San Francisco Bay Area, has had significant development in the wildland-urban interface and periods of highly wildfire-prone conditions. The NASA DEVELOP team collaborated with Fire Foundry, a Marin-based fire service work force development program, to develop new models to assist with fire management. Using data from Sentinel-2A, Planet Scope, ECOSTRESS, a county-wide LiDAR mapping effort, Landsat 7 Enhanced Thematic Mapper (ETM+), and Landsat 8 Operational Land Imager (OLI), the team developed several input data layers to three models evaluating wild fire severity. One model performed a suitability analysis with weights based on scientific literature, another utilized machine learning based on past fires in Marin and neighboring Sonoma County to predict the difference normalized burn ratio, and the third inputted data layers into the Flam Map tool, which outputs risk categories. The team compared model outputs and, using the best-fit model, performed fuzzy logic analysis to identify specific locations where a fire break could be constructed to interrupt the progress of an active fire. These tools were proven useful and will assist partners in preparing for and managing an active wildfire event.

Suhani Dalal↗