Search NASA⌕ Search

SEARCH · Search NASA

Results for “Design verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Design and Verification

As future space missions become longer, an important aspect to consider is the habitability of the spacecraft. The amount of habitable volume affects not only astronaut comfort, but safety and mission success as well. However, as the volume is increased to aid in task performance, the weight of the vehicle and cost of the mission escalates in proportion. Pressure to reduce mission cost is constant, but the risk to mission success and crew survival must remain the priorities. The Constellation Program's Altair Lunar Lander is designed for short duration surface operation missions of seven to ten days. For short duration missions, humans will tolerate fairly primitive environmental situations provided the basic physiological arrangements are acceptable. However, for long-duration lunar surface operations, the living and operational spaces within which the crew work must provide both the essentials of life, as well as the support necessary for the crew to be productive in accomplishing their mission. The Altair is still in the preliminary design phase, which is the optimal time for Human Factors data to be provided to designers and engineers. A Human Centered Design (HCD) approach is being taken with our Human Factors evaluations. Human-in-the-loop testing is conducted using low-medium fidelity mock-ups of proposed lunar architecture. Based on current ConOps (Concept of Operations) procedures, a task analysis is performed in which individual tasks are combined into larger operational scenarios. Subjective and objective performance measures are gathered at both the task and scenario level. These scores are used to determine the functionality of the vehicle in terms of task performance. Results from these evaluations will highlight areas for design or operational improvement.

Thompson, Shelby G.↗

An Update on the Role of Systems Modeling in the Design and Verification of the James Webb Space Telescope

The James Web Space Telescope (JWST) is a large, infrared-optimized space telescope scheduled for launch in 2014. System-level verification of critical performance requirements will rely on integrated observatory models that predict the wavefront error accurately enough to verify that allocated top-level wavefront error of 150 nm root-mean-squared (rms) through to the wave-front sensor focal plane is met. The assembled models themselves are complex and require the insight of technical experts to assess their ability to meet their objectives. This paper describes the systems engineering and modeling approach used on the JWST through the detailed design phase.

Muheim, Danniella↗

Development and verification of design methods for ducts in a space nuclear shield

A practical method for computing the effectiveness of a space nuclear shield perforated by small tubing and cavities is reported. Performed calculations use solutions for a two dimensional transport code and evaluate perturbations of that solution using last flight estimates and other kernel integration techniques. In general, perturbations are viewed as a change in source strength of scattered radiation and a change in attenuation properties of the region.

Cerbone, R. J.↗

Design and verification of a multiple fault tolerant control system for STS applications using computer simulation

General Dynamics/Convair is under NASA contract to integrate the Centaur upper stage into the space transportation system for future planetary missions. This requires that control of all safety critical functions be two-failure tolerant. The control system developed consists of five asynchronous computers, each contributing at their outputs to a 3-out-of-5 voting plane. Subsystem control is based on an end function redundancy management scheme. Analysis of multiple component failures and worst-case time-phase asynchrony among the computers is performed by a real-time computer simulation. The simulation emulates the hardware and subsystem interfaces, wire by wire, providing assessibility to any component for the insertion of preprogrammed failures. Observability is provided via a graphics system and diagnostic software. The simulation provides an engineering tool where the integrity of control system hardware and imbedded software can be demonstrated.

Szatkowski, G. P.↗

DDL system: Design systhesis of digital systems

Digital Systems Design Language was integrated into the CADAT system environment of NASA-MSFC. The major technical aspects of this integration are summarized. Automatic hardware synthesis is now possible starting with a high level description of the system to be synthesized. The DDL system provides a high level design verification capability, thereby minimizing design changes in the later stages of the design cycle. An overview of the DDL system covering the translation, simulation and synthesis capabilities is provided. Two companion documents (the user's and programmer's manuals) are to be consulted for detailed discussions.

Shiva, S. G.↗

External tank aerothermal design criteria verification

If a Space Shuttle Main Engine (SSME) fails during the initial 160 seconds of the Shuttle flight, a return-to-launch-site maneuver will be implemented. The period of concern for this task is the pitch-around maneuver when the vehicle is flying backward. The intent of this report is to identify and define the flowfield at the most critical locations from an environment perspective. The solution procedure used to predict the plume heating rates involves both computational analysis and engineering modeling.

Praharaj, Sarat C.↗

Using formal specification in the Guidance and Control Software (GCS) experiment. Formal design and verification technology for life critical systems

The goal of this task was to investigate how formal methods could be incorporated into a software engineering process for flight-control systems under DO-178B and to demonstrate that process by developing a formal specification for NASA's Guidance and Controls Software (GCS) Experiment. GCS is software to control the descent of a spacecraft onto a planet's surface. The GCS example is simplified from a real example spacecraft, but exhibits the characteristics of realistic spacecraft control software. The formal specification is written in Larch.

Weber, Doug↗

An Integrated Environment for Efficient Formal Design and Verification

The general goal of this project was to improve the practicality of formal methods by combining techniques from model checking and theorem proving. At the time the project was proposed, the model checking and theorem proving communities were applying different tools to similar problems, but there was not much cross-fertilization. This project involved a group from SRI that had substantial experience in the development and application of theorem-proving technology, and a group at Stanford that specialized in model checking techniques. Now, over five years after the proposal was submitted, there are many research groups working on combining theorem-proving and model checking techniques, and much more communication between the model checking and theorem proving research communities. This project contributed significantly to this research trend. The research work under this project covered a variety of topics: new theory and algorithms; prototype tools; verification methodology; and applications to problems in particular domains.

Source record↗

A Methodology for the Design and Verification of Globally Asynchronous/Locally Synchronous Architectures

Recent advanced in model-checking have made it practical to formally verify the correctness of many complex synchronous systems (i.e., systems driven by a single clock). However, many computer systems are implemented by asynchronously composing several synchronous components, where each component has its own clock and these clocks are not synchronized. Formal verification of such Globally Asynchronous/Locally Synchronous (GA/LS) architectures is a much more difficult task. In this report, we describe a methodology for developing and reasoning about such systems. This approach allows a developer to start from an ideal system specification and refine it along two axes. Along one axis, the system can be refined one component at a time towards an implementation. Along the other axis, the behavior of the system can be relaxed to produce a more cost effective but still acceptable solution. We illustrate this process by applying it to the synchronization logic of a Dual Fight Guidance System, evolving the system from an ideal case in which the components do not fail and communicate synchronously to one in which the components can fail and communicate asynchronously. For each step, we show how the system requirements have to change if the system is to be implemented and prove that each implementation meets the revised system requirements through modelchecking.

Miller, Steven P.↗

Automated Verification of Design Patterns with LePUS3

Specification and [visual] modelling languages are expected to combine strong abstraction mechanisms with rigour, scalability, and parsimony. LePUS3 is a visual, object-oriented design description language axiomatized in a decidable subset of the first-order predicate logic. We demonstrate how LePUS3 is used to formally specify a structural design pattern and prove ( verify ) whether any JavaTM 1.4 program satisfies that specification. We also show how LePUS3 specifications (charts) are composed and how they are verified fully automatically in the Two-Tier Programming Toolkit.

Nicholson, Jonathan↗

Design and Verification of External Occulters for Direct Imaging of Extrasolar Planets

An occulter is an optical element which is placed in front of the telescope to block most of the light from a star before it reaches the optics inside, without blocking the planet.In our case, we use two spacecraft ying in formation: First has its edge shaped to cancel the starlight Second is the telescope which images the star and planet

starshades↗

Trace Contaminant Control for the International Space Station's Node 1- Analysis, Design, and Verification

Trace chemical contaminant generation inside crewed spacecraft cabins is a technical and medical problem that must be continuously evaluated. Although passive control through materials selection and active control by adsorption and catalytic oxidation devices is employed during normal operations of a spacecraft, contaminant buildup can still become a problem. Buildup is particularly troublesome during the stages between the final closure of a spacecraft during ground processing and the time that a crewmember enters for the first time during the mission. Typically, the elapsed time between preflight closure and first entry on orbit for spacecraft such as Spacelab modules was 30 days. During that time, the active contamination control systems are not activated and contaminants can potentially build up to levels which exceed the spacecraft maximum allowable concentrations (SMACs) specified by NASA toxicology experts. To prevent excessively high contamination levels at crew entry, the Spacelab active contamination control system was operated for 53 hours just before launch.

Perry, J. L.↗

Ionizing Radiation Environment on the International Space Station: Performance vs. Expectations for Avionics and Material

The role of structural shielding mass in the design, verification, and in-flight performance of International Space Station (ISS), in both the natural and induced orbital ionizing radiation (IR) environments, is reported. Detailed consideration of the effects of both the natural and induced ionizing radiation environment during ISS design, development, and flight operations has produced a safe, efficient manned space platform that is largely immune to deleterious effects of the LEO ionizing radiation environment. The assumption of a small shielding mass for purposes of design and verification has been shown to be a valid worst-case approximation approach to design for reliability, though predicted dependences of single event effect (SEE) effects on latitude, longitude, SEP events, and spacecraft structural shielding mass are not observed. The Figure of Merit (FOM) method over predicts the rate for median shielding masses of about 10g/cm(exp 2) by only a factor of 3, while the Scott Effective Flux Approach (SEFA) method overestimated by about one order of magnitude as expected. The Integral Rectangular Parallelepiped (IRPP), SEFA, and FOM methods for estimating on-orbit (Single Event Upsets) SEU rates all utilize some version of the CREME-96 treatment of energetic particle interaction with structural shielding, which has been shown to underestimate the production of secondary particles in heavily shielded manned spacecraft. The need for more work directed to development of a practical understanding of secondary particle production in massive structural shielding for SEE design and verification is indicated. In contrast, total dose estimates using CAD based shielding mass distributions functions and the Shieldose Code provided a reasonable accurate estimate of accumulated dose in Grays internal to the ISS pressurized elements, albeit as a result of using worst-on-worst case assumptions (500 km altitude x 2) that compensate for ignoring both GCR and secondary particle production in massive structural shielding.

Koontz, Steven L.↗

A novel design optimization framework to sustain remanufacturability

The ever-increasing global carbon emissions have urged the need for environmentally conscious/sustainable product design, for which the design for remanufacturing (DfRem) is one potential approach. DfRem targets at designing products that have multiple life cycles, thus significantly reducing raw material usage, energy consumption, and carbon emissions. In this paper, we develop a three-stage framework that consists of (1) systematic design space exploration and a multi-objective optimization formulation to minimize the likelihood of failure causes (such as fatigue and wear) and environmental footprint, (2) topology optimization to further reduce material usage without significantly affecting the load-carrying capability of the product, and (3) post-topology optimization design verification to ensure the proposed design satisfies all design constraints. The environmental impact can be assessed at varying comprehensiveness levels (e.g., design and manufacturing phase, use phase) and in terms of carbon or GHG emission, energy use, and waste generation. Because the novel design framework predominantly adjusted the geometry, we focused on mass-based change and energy savings due to sustained remanufacturability. The multi-objective optimization formulation in the first step results in a Pareto optimal set of possible design solutions that the designer can use for the second step. Finally, we demonstrate the utility of this framework through a case study of an engine cylinder head subjected to thermo-mechanical loads, where we find that about 5% of the product mass can be conserved with only about a 3% increase in surface area that has a fatigue life less than 10,000 cycles.

42 ENGINEERING↗

Validation of a fault-tolerant clock synchronization system

A validation method for the synchronization subsystem of a fault tolerant computer system is investigated. The method combines formal design verification with experimental testing. The design proof reduces the correctness of the clock synchronization system to the correctness of a set of axioms which are experimentally validated. Since the reliability requirements are often extreme, requiring the estimation of extremely large quantiles, an asymptotic approach to estimation in the tail of a distribution is employed.

Butler, R. W.↗