Search NASASearch

SEARCH · Search NASA

Results for “Argumentation”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Implications of lunar aseismicity.

The aseismicity of the moon has been interpreted by Latham et al. (1970) as an indication that the moon is relatively cold in the interior. An alternative argument is now presented. This argument suggests the reverse conclusion, that the moon is too warm to be seismic. The argument is based on known properties of materials, in particular their modes of failure under shear stress. A tentative conclusion is presented that the moon is largely aseismic because the lunar-therm lies in the stable-sliding field of rock failure. It is too warm, rather than too cold.

Thomsen, L.

Improved upper limit on the photon rest mass

It is shown that application of standard MHD arguments to hydromagnetic waves observed in the Crab Nebula dramatically improves the upper bound on photon rest mass. The standard argument that massive photons are governed by the Phoca field equations is outlined and applied to wisp features (identified as hydromagnetic waves) observed in the Crab. The results imply an upper limit for the photon rest mass of between 3 by 10 to the -54th power and 3 by 10 to the -53rd power gram, which is smaller than the best previous limits by a factor of 10,000 to 100,000. It is noted that although the present limit is probably valid in order of magnitude, some doubt remains since there are inconsistencies in the standard arguments.

Barnes, A.

On Al-26 and other short-lived interstellar radioactivity

Several authors have shown that massive stars exploding at a rate of about three per century can account for a large portion, if not all, of the observed interstellar Al-26. In a separate argument using models of Galactic chemical evolution, Clayton (1984) showed that the Al-26/Al-27 production ratio was not large enough to maintain enough Al-26 in the Galactic disk gas of about 10 exp 10 solar masses having solar composition. We present a resolution of those conflicting arguments. A past history of Galactic infall growing the Galactic disk so dilutes the stable Al-27 concentration that the two approaches can be brought into near agreement. If massive stars dominate the production of Al-26, we suggest that the apparent shortfall of their Al-26/Al-27 yield ratio is to be interpreted as evidence for significant growth of the Galactic disk. We also discuss the implications of these arguments for other extinct radioactivities in meteorites, using I-129 and Sm-146 as examples.

Clayton, Donald D.

A Safety Conundrum Illustrated: Logic, Mathematics, and Science Are Not Enough

In an ideal world, conversations about whether a particular system is safe, or whether a particular method or tool enhances safety, would be emotion-free discussions concentrating on the level of safety required, available evidence, and coherent logical, mathematical, or scientific arguments based on that evidence. In the real world, discussions about safety are often not emotion-free. Political and economic arguments may play a bigger role than logical, mathematical, and scientific arguments, and psychological factors may be as important, or even more important, than purely technical factors. This paper illustrates the conundrum that can result from this clash of the ideal and the real by means of an imagined conversation among a collection of fictional characters representing various types of people who may be participating in a safety discussion.

Holloway, C. M.

AdvoCATE - User Guide

The basic vision of AdvoCATE is to automate the creation, manipulation, and management of large-scale assurance cases based on a formal theory of argument structures. Its main purposes are for creating and manipulating argument structures for safety assurance cases using the Goal Structuring Notation (GSN), and as a test bed and proof-of-concept for the formal theory of argument structures. AdvoCATE is available for Windows 7, Macintosh OSX, and Linux. Eventually, AdvoCATE will serve as a dashboard for safety related information and provide an infrastructure for safety decisions and management.

Safety Case

The Eccentric Behavior of Nearly Frozen Orbits

Frozen orbits are orbits which have only short-period changes in their mean eccentricity and argument of periapse, so that they basically keep a fixed orientation within their plane of motion. Nearly frozen orbits are those whose eccentricity and argument of periapse have values close to those of a frozen orbit. We call them "nearly" frozen because their eccentricity vector (a vector whose polar coordinates are eccentricity and argument of periapse) will stay within a bounded distance from the frozen orbit eccentricity vector, circulating around it over time. For highly inclined orbits around the Earth, this distance is effectively constant over time. Furthermore, frozen orbit eccentricity values are low enough that these orbits are essentially eccentric (i.e., off center) circles, so that nearly frozen orbits around Earth are bounded above and below by frozen orbits.

spacecraft

The Theory of Artificial Satellites in Terms of the Orbital True Longitude

The author's previous theory of the artificial satellite is derived in terms of the. disturbed eccentric anomaly. The present development, in terms of the orbital true longitude, is a substantial improvement over the earlier work in that it leads to the faster convergence for large eccentricities and to a smaller number of terms in the series representing the perturbations. Moreover, each approximation of the radius vector and of the parameters determining the position of the orbit plane is obtained not in the form of a truncated infinite series but in the form of trigonometric polynomials in two arguments. These arguments are the mean true anomaly and the mean argument of the latitude. The present theory, like the previous one, permits the computation of perturbations of any desired order. Thus, any future information about earth's gravitational field can easily be included.

Musen, Peter

Understanding and Evaluating Assurance Cases

Assurance cases are a method for providing assurance for a system by giving an argument to justify a claim about the system, based on evidence about its design, development, and tested behavior. In comparison with assurance based on guidelines or standards (which essentially specify only the evidence to be produced), the chief novelty in assurance cases is provision of an explicit argument. In principle, this can allow assurance cases to be more finely tuned to the specific circumstances of the system, and more agile than guidelines in adapting to new techniques and applications. The first part of this report (Sections 1-4) provides an introduction to assurance cases. Although this material should be accessible to all those with an interest in these topics, the examples focus on software for airborne systems, traditionally assured using the DO-178C guidelines and its predecessors. A brief survey of some existing assurance cases is provided in Section 5. The second part (Section 6) considers the criteria, methods, and tools that may be used to evaluate whether an assurance case provides sufficient confidence that a particular system or service is fit for its intended use. An assurance case cannot provide unequivocal "proof" for its claim, so much of the discussion focuses on the interpretation of such less-than-definitive arguments, and on methods to counteract confirmation bias and other fallibilities in human reasoning.

Rushby, John

Formal Foundations for Hierarchical Safety Cases

Safety cases are increasingly being required in many safety-critical domains to assure, using structured argumentation and evidence, that a system is acceptably safe. However, comprehensive system-wide safety arguments present appreciable challenges to develop, understand, evaluate, and manage, partly due to the volume of information that they aggregate, such as the results of hazard analysis, requirements analysis, testing, formal verification, and other engineering activities. Previously, we have proposed hierarchical safety cases, hicases, to aid the comprehension of safety case argument structures. In this paper, we build on a formal notion of safety case to formalise the use of hierarchy as a structuring technique, and show that hicases satisfy several desirable properties. Our aim is to provide a formal, theoretical foundation for safety cases. In particular, we believe that tools for high assurance systems should be granted similar assurance to the systems to which they are applied. To this end, we formally specify and prove the correctness of key operations for constructing and managing hicases, which gives the specification for implementing hicases in AdvoCATE, our toolset for safety case automation. We motivate and explain the theory with the help of a simple running example, extracted from a real safety case and developed using AdvoCATE.

Hierarchy

Ancient Air Caught by Shooting Stars

It is a truth almost universally acknowledged that Earth’s atmosphere before about 2.5 billion years ago had little or no free oxygen. The classic argument for anoxia on ancient Earth is that a distinct change occurred in the oxidation state of many surface rocks and minerals around the end of the Archaean eon (which lasted from 4 billion to 2.5 billion years ago). A more recent argument is that a sudden, permanent change in the relative abundances of rare sulfur isotopes preserved in sediments also occurred at that time — a change that can be linked to differences in sulfur’s atmospheric chemistry in the presence or absence of oxygen. These arguments are strong. It therefore comes as a surprise that melted meteor fragments recovered from Archaean limestone indicate that the contemporaneous atmosphere above 75 kilometres was highly oxidized, as reported by Tomkins et al. on page 235.

ancient Earth's atmosphere

FUELEAP Model-Based System Safety Analysis

NASA researchers, in a partnership with Boeing, are investigating a fuel-cell powered variant of the X-57 “Maxwell” Mod-II electric propulsion aircraft, which is itself derived from a stock Tecnam P2006T. The “Fostering Ultra-Efficient Low-Emitting Aviation Power” (FUELEAP) project will replace the X-57 power subsystem with a hybrid Solid-Oxide Fuel Cell (SOFC) system to increase the potential range of the electric-propulsion aircraft while dramatically improving efficiency and emissions over stock internal-combustion engines. Our FUELEAP safety analysis faces two primary challenges. First, the Part 23 certificated Tecnam P2006T is undergoing significant modifications to host the hybrid electric-propulsion system, and the challenge is to assure that the safety inherent in the stock aircraft (and subsequently in X-57 Mod-II) is not compromised by changes in avionics, aircraft structural loading, weight and balance, or other considerations. Secondly, because the SOFC power system has little (if any) relevant in-service precedent, our challenge is to assure that we identify and mitigate all reasonably plausible hazards introduced by unique FUELEAP equipage. We are investigating and utilizing Model-Based Safety Analysis (MBSA) methods to help us address these FUELEAP safety challenges. We captured aircraft-level system hazard conditions using instances of a SysML hazard block via aircraft-level Functional Hazard Analysis (FHA). Then, using SysML models of the FUELEAP architecture, we related the hazard conditions to initiating system events and possible mitigations, such as design architecture modifications or operational constraints. We are continuing to define our approach to MBSA by developing a component-by-component inventory of local failure modes and tracing their possible contribution to hazard conditions. Finally, we are applying an argument-based approach to FUELEAP assurance. Through a FUELEAP “safety case,” we are providing an explicit argument for FUELEAP safety by associating assurance evidence with overarching safety claims through a structured argument.

Woodham, Kurt P.

IV&V Assurance Case Design for Artemis II

As human-rated missions like those in NASA’s Artemis program continue to grow in both size and complexity, and the role of software in achieving mission objectives expands dramatically, NASA’s Independent Verification and Validation (IV&V) Teams face evolving challenges in assuring the safety and performance of the safety- and mission-critical embedded software that is essential to landing astronauts on the surface of the Moon by 2024. Key among these challenges is IV&V’s desire to present a cohesive, integrated assurance statement to its stakeholders that encapsulates and summarizes our assurance positions across the integrated Artemis systems and their combined role in support of a safe and successful flight. In order to meet this challenge, the IV&V Teams have begun a transition to using formal assurance case concepts and documentation in the Goal Structuring Notation (GSN) to build an argument in support of software assurance. IV&V recognizes significant benefits to the logical argumentation structure provided by assurance cases and GSN over our current practices for documenting and managing assurance claims. In order to reap these benefits, IV&V is integrating the use of assurance case concepts with our paradigm of follow-the-risk capability based assurance. Because of this, assurance cases created and used by IV&V are distinct from the sort of assurance case created by a development project or embedded software assurance organization. IV&V’s assurance cases depend much less upon standards and regulations, and more on evidence captured by IV&V regarding the environment, requirements, design, and implementation. IV&V constructs an independent network of claims based on an independent decomposition of arguments. Based upon the risk posture of these claims and their associated software and software artifacts, IV&V then develops and executes engineering analyses and testing, which provide evidence to either support or refute the claim. This emerging risk-informed assurance case methodology is being put into practice as IV&V plans for support of the Artemis II mission, the first flight of the Orion capsule and Space Launch System with astronauts on board.

Gerek Whitman

IV&V Assurance Case Design for Artemis II

As human-rated missions like those in NASA's Artemis program continue to grow in both size and complexity, and the role of software in achieving mission objectives expands dramatically, NASA's Independent Verification and Validation (IV&V) Teams face evolving challenges in assuring the safety and performance of the safety- and mission-critical embedded software that is essential to landing astronauts on the surface of the Moon by 2024. Key among these challenges is IV&V's desire to present a cohesive, integrated assurance statement to its stakeholders that encapsulates and summarizes our assurance positions across the integrated Artemis systems and their combined role in support of a safe and successful flight. In order to meet this challenge, the IV&V Teams have begun a transition to using formal assurance case concepts and documentation in the Goal Structuring Notation (GSN) to build an argument in support of software assurance. IV&V recognizes significant benefits to the logical argumentation structure provided by assurance cases and GSN over our current practices for documenting and managing assurance claims. In order to reap these benefits, IV&V is integrating the use of assurance case concepts with our paradigm of follow-the-risk capability based assurance. Because of this, assurance cases created and used by IV&V are distinct from the sort of assurance case created by a development project or embedded software assurance organization. IV&V's assurance cases depend much less upon standards and regulations, and more on evidence captured by IV&V regarding the environment, requirements, design, and implementation. IV&V constructs an independent network of claims based on an independent decomposition of arguments. Based upon the risk posture of these claims and their associated software and software artifacts, IV&V then develops and executes engineering analyses and testing, which provide evidence to either support or refute the claim. This emerging risk-informed assurance case methodology is being put into practice as IV&V plans for support of the Artemis II mission, the first flight of the Orion capsule and Space Launch System with astronauts on board.

Whitman, Gerek

Overarching Properties as Means of Compliance: An Industrial Case Study

The Overarching Properties (OPs) have been created by an inter-national working group and are being evaluated by the National Aeronautics and Space Administration (NASA), the Federal Aviation Administration (FAA), industry, and other certifying agencies in an effort to streamline certification processes. Their intent is to facilitate the use of alternative approaches and to al-low flexibility to combine the system, software, and complex hardware certification. The hope is that the FAA may eventually establish an Advisory Circular that offers the OPs as a Means of Compliance (MoC) for software approval (and eventually systems and hardware) by showing the product possesses the three OPs: Intent (specification of the intended behavior), Correctness (implementation of the intended behavior) and Innocuity (safety of unintended behavior). In the certification community, there is still a concern about the practicability of using such high level properties in certification. This paper aims to address that concern by showing possession of the OPs in an industrial case study using assurance arguments. The two main contributions of this paper are: a certification process based on OPs as Means of Compliance, and a certification argument for an on-board physical model of an UAV, as industrial example. We pro-pose a hybrid approach for the certification process that combines OPs with existing certification standards. Thus, OPs can be used for parts of a system that uses technologies that are not supported by current standards or for which existing standards require additional effort without commensurate additional safety assurance.

certification

Does provable absence of barren plateaus imply classical simulability?

A large amount of effort has recently been put into understanding the barren plateau phenomenon. In this perspective article, we face the increasingly loud elephant in the room and ask a question that has been hinted at by many but not explicitly addressed: Can the structure that allows one to avoid barren plateaus also be leveraged to efficiently simulate the loss classically? We collect evidence-on a case-by-case basis-that many commonly used models whose loss landscapes avoid barren plateaus can also admit classical simulation, provided that one can collect some classical data from quantum devices during an initial data acquisition phase. This follows from the observation that barren plateaus result from a curse of dimensionality, and that current approaches for solving them end up encoding the problem into some small, classically simulable, subspaces. Thus, while stressing that quantum computers can be essential for collecting data, our analysis sheds doubt on the information processing capabilities of many parametrized quantum circuits with provably barren plateau-free landscapes. We end by discussing the (many) caveats in our arguments including the limitations of average case arguments, the role of smart initializations, models that fall outside our assumptions, the potential for provably superpolynomial advantages and the possibility that, once larger devices become available, parametrized quantum circuits could heuristically outperform our analytic expectations.

71 CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSIC

Comparing ICME simulations with scaled laboratory experiment

In stellar physics and astrophysics, numerical simulations and laboratory experiments are often compared to observational data to support their representation of the real world. However, there is also merit in comparing numerical simulations to properly scaled experiments, especially when the experiment and the simulation are both emulating the solar phenomena. Confirming the credibility of scaled experiments and their scaling with well-validated models is important to expand our knowledge of the associated physical phenomena. This is significant because experiments and simulations can be performed frequently, whereas observations may be limited by location, field of view, and missing data. In this work, we use the Alfvén Wave Solar atmosphere Model, a well-validated magnetohydrodynamic model, to simulate an interplanetary coronal mass ejection (ICME) and compare it to an experiment which provides a scaled analog to a physical ICME. The experiment was performed on the Big Red Ball facility and scaled using dimensionless parameters such as plasma β and magnetosonic Mach number to reproduce the main structure of an ICME. We compare the model-simulated temperature, density, and magnetic field to those from the experiment, as well as the scaling parameters used in the experiment, to those calculated from the simulation. This comparison is performed to further justify the scaling arguments made by the experiment. Additionally, the comparison would lead to the development of stronger scaling arguments for future experiments.

Bryant, K. [University of Michigan, Ann Arbor, MI

The universal thermodynamic properties of extremely compact objects

An extremely compact object (ECO) is defined as a quantum object without horizon, whose radius is just a small distance s outside its Schwarzschild radius. We show that any ECO of mass M in d + 1 dimensions with s << (M/m p ) 2/(d-2)(d+1) lp must have (at leading order) the same thermodynamic properties—temperature, entropy and radiation rates—as the corresponding semiclassical black hole of mass M. An essential aspect of the argument involves showing that the Tolman–Oppenheimer–Volkoff equation has no consistent solution in the region just outside the ECO surface, unless this region is filled with radiation at the (appropriately blueshifted) Hawking temperature. In string theory it has been found that black hole microstates are fuzzballs—objects with no horizon—which are expected to have a radius that is only a little larger than the horizon radius. Thus the arguments of this paper provide a nice closure to the fuzzball paradigm: the absence of a horizon removes the information paradox, and the thermodynamic properties of the semiclassical hole are nonetheless recovered to an excellent approximation.

79 ASTRONOMY AND ASTROPHYSICS

Daily modulations and broadband strategy in axion searches: An application with the CAST-CAPP detector

It has been previously advocated that the presence of the daily and annual modulations of the axion flux on the Earth’s surface may dramatically change the strategy of the axion searches. The arguments were based on the so-called Axion Quark Nugget (AQN) dark matter model which was originally put forward to explain the similarity of the dark and visible cosmological matter densities Ω dark ∼ Ω visible . In this framework, the population of galactic axions with mass 10 − 6 eV ≲ m a ≲ 10 − 3 eV and velocity ⟨ v a ⟩ ∼ 10 − 3 c will be accompanied by axions with typical velocities ⟨ v a ⟩ ∼ 0.6 c emitted by AQNs. Furthermore, in this framework, it has also been argued that the AQN-induced axion daily modulation (in contrast with the conventional weakly interactive massive particle paradigm) could be as large as (10–20)%, representing the main motivation for the present investigation. We argue that the daily modulations along with the broadband detection strategy can be very useful tools for the discovery of such relativistic axions. The data from the CAST-CAPP detector have been used following such arguments. Unfortunately, due to the dependence of the amplifier chain on temperature-dependent gain drifts and other factors, we could not conclusively show the presence or absence of a dark sector-originated daily modulation. However, this proof of principle analysis procedure can serve as a reference for future studies. Published by the American Physical Society 2025

Caspers, F.