Search NASA⌕ Search

SEARCH · Search NASA

Results for “Design verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

An Update on the Role of Systems Modeling in the Design and Verification of the James Webb Space Telescope

The James Web Space Telescope (JWST) is a large, infrared-optimized space telescope scheduled for launch in 2014. System-level verification of critical performance requirements will rely on integrated observatory models that predict the wavefront error accurately enough to verify that allocated top-level wavefront error of 150 nm root-mean-squared (rms) through to the wave-front sensor focal plane is met. The assembled models themselves are complex and require the insight of technical experts to assess their ability to meet their objectives. This paper describes the systems engineering and modeling approach used on the JWST through the detailed design phase.

Muheim, Danniella↗

Development and verification of design methods for ducts in a space nuclear shield

A practical method for computing the effectiveness of a space nuclear shield perforated by small tubing and cavities is reported. Performed calculations use solutions for a two dimensional transport code and evaluate perturbations of that solution using last flight estimates and other kernel integration techniques. In general, perturbations are viewed as a change in source strength of scattered radiation and a change in attenuation properties of the region.

Cerbone, R. J.↗

Design and verification of a multiple fault tolerant control system for STS applications using computer simulation

General Dynamics/Convair is under NASA contract to integrate the Centaur upper stage into the space transportation system for future planetary missions. This requires that control of all safety critical functions be two-failure tolerant. The control system developed consists of five asynchronous computers, each contributing at their outputs to a 3-out-of-5 voting plane. Subsystem control is based on an end function redundancy management scheme. Analysis of multiple component failures and worst-case time-phase asynchrony among the computers is performed by a real-time computer simulation. The simulation emulates the hardware and subsystem interfaces, wire by wire, providing assessibility to any component for the insertion of preprogrammed failures. Observability is provided via a graphics system and diagnostic software. The simulation provides an engineering tool where the integrity of control system hardware and imbedded software can be demonstrated.

Szatkowski, G. P.↗

DDL system: Design systhesis of digital systems

Digital Systems Design Language was integrated into the CADAT system environment of NASA-MSFC. The major technical aspects of this integration are summarized. Automatic hardware synthesis is now possible starting with a high level description of the system to be synthesized. The DDL system provides a high level design verification capability, thereby minimizing design changes in the later stages of the design cycle. An overview of the DDL system covering the translation, simulation and synthesis capabilities is provided. Two companion documents (the user's and programmer's manuals) are to be consulted for detailed discussions.

Shiva, S. G.↗

External tank aerothermal design criteria verification

If a Space Shuttle Main Engine (SSME) fails during the initial 160 seconds of the Shuttle flight, a return-to-launch-site maneuver will be implemented. The period of concern for this task is the pitch-around maneuver when the vehicle is flying backward. The intent of this report is to identify and define the flowfield at the most critical locations from an environment perspective. The solution procedure used to predict the plume heating rates involves both computational analysis and engineering modeling.

Praharaj, Sarat C.↗

Using formal specification in the Guidance and Control Software (GCS) experiment. Formal design and verification technology for life critical systems

The goal of this task was to investigate how formal methods could be incorporated into a software engineering process for flight-control systems under DO-178B and to demonstrate that process by developing a formal specification for NASA's Guidance and Controls Software (GCS) Experiment. GCS is software to control the descent of a spacecraft onto a planet's surface. The GCS example is simplified from a real example spacecraft, but exhibits the characteristics of realistic spacecraft control software. The formal specification is written in Larch.

Weber, Doug↗

An Integrated Environment for Efficient Formal Design and Verification

The general goal of this project was to improve the practicality of formal methods by combining techniques from model checking and theorem proving. At the time the project was proposed, the model checking and theorem proving communities were applying different tools to similar problems, but there was not much cross-fertilization. This project involved a group from SRI that had substantial experience in the development and application of theorem-proving technology, and a group at Stanford that specialized in model checking techniques. Now, over five years after the proposal was submitted, there are many research groups working on combining theorem-proving and model checking techniques, and much more communication between the model checking and theorem proving research communities. This project contributed significantly to this research trend. The research work under this project covered a variety of topics: new theory and algorithms; prototype tools; verification methodology; and applications to problems in particular domains.

Source record↗

A Methodology for the Design and Verification of Globally Asynchronous/Locally Synchronous Architectures

Recent advanced in model-checking have made it practical to formally verify the correctness of many complex synchronous systems (i.e., systems driven by a single clock). However, many computer systems are implemented by asynchronously composing several synchronous components, where each component has its own clock and these clocks are not synchronized. Formal verification of such Globally Asynchronous/Locally Synchronous (GA/LS) architectures is a much more difficult task. In this report, we describe a methodology for developing and reasoning about such systems. This approach allows a developer to start from an ideal system specification and refine it along two axes. Along one axis, the system can be refined one component at a time towards an implementation. Along the other axis, the behavior of the system can be relaxed to produce a more cost effective but still acceptable solution. We illustrate this process by applying it to the synchronization logic of a Dual Fight Guidance System, evolving the system from an ideal case in which the components do not fail and communicate synchronously to one in which the components can fail and communicate asynchronously. For each step, we show how the system requirements have to change if the system is to be implemented and prove that each implementation meets the revised system requirements through modelchecking.

Miller, Steven P.↗

Automated Verification of Design Patterns with LePUS3

Specification and [visual] modelling languages are expected to combine strong abstraction mechanisms with rigour, scalability, and parsimony. LePUS3 is a visual, object-oriented design description language axiomatized in a decidable subset of the first-order predicate logic. We demonstrate how LePUS3 is used to formally specify a structural design pattern and prove ( verify ) whether any JavaTM 1.4 program satisfies that specification. We also show how LePUS3 specifications (charts) are composed and how they are verified fully automatically in the Two-Tier Programming Toolkit.

Nicholson, Jonathan↗

Design and Verification of External Occulters for Direct Imaging of Extrasolar Planets

An occulter is an optical element which is placed in front of the telescope to block most of the light from a star before it reaches the optics inside, without blocking the planet.In our case, we use two spacecraft ying in formation: First has its edge shaped to cancel the starlight Second is the telescope which images the star and planet

starshades↗

Trace Contaminant Control for the International Space Station's Node 1- Analysis, Design, and Verification

Trace chemical contaminant generation inside crewed spacecraft cabins is a technical and medical problem that must be continuously evaluated. Although passive control through materials selection and active control by adsorption and catalytic oxidation devices is employed during normal operations of a spacecraft, contaminant buildup can still become a problem. Buildup is particularly troublesome during the stages between the final closure of a spacecraft during ground processing and the time that a crewmember enters for the first time during the mission. Typically, the elapsed time between preflight closure and first entry on orbit for spacecraft such as Spacelab modules was 30 days. During that time, the active contamination control systems are not activated and contaminants can potentially build up to levels which exceed the spacecraft maximum allowable concentrations (SMACs) specified by NASA toxicology experts. To prevent excessively high contamination levels at crew entry, the Spacelab active contamination control system was operated for 53 hours just before launch.

Perry, J. L.↗

Ionizing Radiation Environment on the International Space Station: Performance vs. Expectations for Avionics and Material

The role of structural shielding mass in the design, verification, and in-flight performance of International Space Station (ISS), in both the natural and induced orbital ionizing radiation (IR) environments, is reported. Detailed consideration of the effects of both the natural and induced ionizing radiation environment during ISS design, development, and flight operations has produced a safe, efficient manned space platform that is largely immune to deleterious effects of the LEO ionizing radiation environment. The assumption of a small shielding mass for purposes of design and verification has been shown to be a valid worst-case approximation approach to design for reliability, though predicted dependences of single event effect (SEE) effects on latitude, longitude, SEP events, and spacecraft structural shielding mass are not observed. The Figure of Merit (FOM) method over predicts the rate for median shielding masses of about 10g/cm(exp 2) by only a factor of 3, while the Scott Effective Flux Approach (SEFA) method overestimated by about one order of magnitude as expected. The Integral Rectangular Parallelepiped (IRPP), SEFA, and FOM methods for estimating on-orbit (Single Event Upsets) SEU rates all utilize some version of the CREME-96 treatment of energetic particle interaction with structural shielding, which has been shown to underestimate the production of secondary particles in heavily shielded manned spacecraft. The need for more work directed to development of a practical understanding of secondary particle production in massive structural shielding for SEE design and verification is indicated. In contrast, total dose estimates using CAD based shielding mass distributions functions and the Shieldose Code provided a reasonable accurate estimate of accumulated dose in Grays internal to the ISS pressurized elements, albeit as a result of using worst-on-worst case assumptions (500 km altitude x 2) that compensate for ignoring both GCR and secondary particle production in massive structural shielding.

Koontz, Steven L.↗

Validation of a fault-tolerant clock synchronization system

A validation method for the synchronization subsystem of a fault tolerant computer system is investigated. The method combines formal design verification with experimental testing. The design proof reduces the correctness of the clock synchronization system to the correctness of a set of axioms which are experimentally validated. Since the reliability requirements are often extreme, requiring the estimation of extremely large quantiles, an asymptotic approach to estimation in the tail of a distribution is employed.

Butler, R. W.↗

Manipulator design and development for the Ranger satellite servicing vehicle

The Ranger program is a planned series of low cost telerobotics flight experiments, based on the use of Pegasus launch vehicles. As the first step towards this goal, the Space Systems Lab was developing a neutral buoyancy version of Ranger for use in design verification and operations testing. The design approach and results of the Ranger manipulator development program is related. Ranger is designed to incorporate four appendages: a pair of dexterous, seven degree of freedom manipulators for general manipulation; a six DOF grappling arm for securing the vehicle to the local work site; and a five DOF positioning manipulator for the stereo camera pair that provide feedback to the remote operator. Each of these manipulators incorporate unique approaches to satisfying design requirements. The numerical and operational requirements are given for Ranger manipulators, and the evolution is discussed of the differing design approaches based on similarities and differences in the requirements. Testing results for individual joints and manipulator assemblies are presented, followed by initial results of operational testing on satellite servicing tasks with the integrated Ranger neutral buoyancy vehicle.

Howard, Russell D.↗

Integrated design of the CSI evolutionary structure: A verification of the design methodology

One of the main objectives of the Controls-Structures Interaction (CSI) program is to develop and evaluate integrated controls-structures design methodology for flexible space structures. Thus far, integrated design methodologies for a class of flexible spacecraft, which require fine attitude pointing and vibration suppression with no payload articulation, have been extensively investigated. Various integrated design optimization approaches, such as single-objective optimization, and multi-objective optimization, have been implemented with an array of different objectives and constraints involving performance and cost measures such as total mass, actuator mass, steady-state pointing performance, transient performance, control power, and many more. These studies have been performed using an integrated design software tool (CSI-DESIGN CODE) which is under development by the CSI-ADM team at the NASA Langley Research Center. To date, all of these studies, irrespective of the type of integrated optimization posed or objectives and constraints used, have indicated that integrated controls-structures design results in an overall spacecraft design which is considerably superior to designs obtained through a conventional sequential approach. Consequently, it is believed that validation of some of these results through fabrication and testing of a structure which is designed through an integrated design approach is warranted. The objective of this paper is to present and discuss the efforts that have been taken thus far for the validation of the integrated design methodology.

Maghami, Peiman G.↗

Novel Test and Analysis Methodology for the Assessment of Joint under Re-entry Environment

Spacecraft thermal protection systems require unique approaches for design verification due to the extreme environments seen during space travel and atmospheric re-entry. In this work, unique considerations for design, analysis, and verification of a tiled heatshield design with material nonlinearity, material property temperature-dependency, material property rate-dependency, and geometric stress concentrations are presented. Such designs require a thorough application of the building block approach to derive appropriate material property datasets, and a novel application of analysis models to aid in the structural verification with testing. The custom application of material rate-dependency in finite element analysis software is presented as a means of leveraging the rate-dependent test data for the material property dataset. Because bonded tile heatshields contain so many design considerations and nonlinearities which often preclude the ability to easily achieve the requisite test factors in qualification testing, a novel sub-element test was developed that amplifies the stress singularity beyond flight conditions. The test achieves an over-test over flight stress conditions. The approach for sub-element coupon design can be extended to other bonded joint designs and can be used in aiding a qualification program.

Pavel Babuska↗