Search NASA⌕ Search

SEARCH · Search NASA

Results for “Design verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Evaluation of AI-enabled Digital Documented Safety Analysis

The National Reactor Innovation Center (NRIC) is leading a transformative initiative to accelerate advanced reactor deployment by fundamentally reimagining how nuclear safety basis documentation is developed, reviewed, and maintained. Traditional Documented Safety Analysis (DSA) processes for DOE-authorized facilities rely on static, document-centric workflows that consume significant time and resources, exemplified by recent major licensing efforts requiring hundreds of thousands of staff hours and millions of pages of documentation review. These conventional approaches create barriers to the rapid, cost-effective deployment of advanced reactors that America's future energy needs demand. NRIC's DOE Authorization Digital Transformation Project addresses these challenges through an innovative framework that integrates artificial intelligence (AI), digital engineering, and systems-based data management into a cohesive digital ecosystem. This white paper presents NRIC's methodology for evaluating AI-enabled document generation capabilities within this broader digital infrastructure, using the Demonstration of Microreactor Experiments (DOME) facility as a pilot case study. The evaluation will assess an AI tool's ability to generate a Preliminary Documented Safety Analysis (PDSA) through progressive integration stages—from standalone document processing to full digital thread connectivity—while maintaining rigorous verification, validation, and regulatory acceptance standards. By establishing dynamic, traceable connections between design data and safety documentation, NRIC's approach has the potential to reduce both document development time and regulatory review cycles by as much as 50%, while simultaneously improving accuracy, consistency, and traceability. This initiative represents a critical step toward establishing reusable digital infrastructure that reactor developers can leverage to accelerate their path from concept to commercial operation, directly supporting NRIC's mission to demonstrate and deploy advanced nuclear energy technologies.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Evaporator Temperature Transient Testing of a High-Performance Sodium Filled Heat Pipe

Heat pipes are two-phase heat transfer devices that enable passive removal of heat from the reactor core to the power conversion system in heat pipe-cooled microreactor designs. Experimental investigations of heat pipe transients are needed for technology demonstration, verification and validation of numerical codes, and the establishment of regulatory requirements. The Single Primary Heat Extraction and Removal Emulator (SPHERE) facility at Idaho National Laboratory (INL) serves as a platform for evaluating the dynamic response of high-temperature heat pipes under a variety of operating conditions. The present work details the experimental investigation of a high-performance, defined as over 2 kW sodium heat pipe subjected to rapid input power fluctuations induced by sudden changes in the evaporator temperature setpoint. In addition, the heat pipe was subjected to an asymmetrical heat load where a subset of heaters operated at 30% and 70% below their nominal power. These experimental conditions were chosen to simulate thermal and operational stresses expected to be encountered in microreactors to provide data on heat pipe behavior during such important transient events. Key data and performance metrics, including time series of temperatures and strains, axial temperature profiles, thermal response times, and heat transfer capabilities, the thermal output over thermal input, were reported and discussed. The results highlight the resilience of heat pipes, revealing their potential to maintain thermal stability and efficiency under varying power loads. Lastly, the paper concludes with a discussion on the significance of the results and their implications for future research.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Presentation on the INL Remote-Handled Low-Level Waste Disposal Facility FY-2024 Annual Summary Report

The abstract below is from the report INL/RPT-24-82600. The powerpoint presentation contains information taken from the report. This Fiscal Year (FY) 2024 annual summary report (ASR) documents the continued adequacy of the performance assessment (PA), the composite analysis (CA), and associated operating disposal authorization statement (ODAS) technical basis documents for the Remote Handled Low Level Waste (RHLLW) Disposal Facility at Idaho National Laboratory (INL). Annual review of the adequacy of the PA and CA for RHLLW Disposal Facility ensures that conclusions of the analyses remain valid in accordance with requirements of the U.S. Department of Energy (DOE) Order 435.1, “Radioactive Waste Management.” In FY 2024, no significant operational changes or other activities occurred that would cause deviation from the assumptions in the PA and CA pertaining to disposal geometry, verification of waste characteristics, tracking disposal inventories against total limits, facility closure design, or institutional controls. Nineteen waste canister shipments were received at the RHLLW Disposal Facility, and all nineteen waste canisters were emplaced in disposal vaults.

12 - MGMT OF RADIOACTIVE AND NON-RADIOACTIVE WASTE↗

Summary Report Of The FY25 Computational Fluid Dynamics Verification And Validation Exercises In The Advanced Reactor Technologies - Gas-cooled Reactor Program

Verification and Validation (V&V) of numerical tools is critical for ensuring reasonable predictions during design, safety analysis, and licensing. Recent work in the Advanced Reactor Technologies - Gas-cooled Reactor (ART-GCR) program has focused on V&V of common Computational Fluid Dynamics (CFD) tools that are used within the Untied States. This report presents an update on these CFD V&V activities. These Generation IV Forum (GIF) Very High Temperature Reactor (VHTR) Computational Methods, Validation, and Benchmarking (CMVB) is an international organization dedicated to the verification and validation of High Temperature Gas-Cooled Reactor (HTGR) simulation tools. Participation in the CMVB provides additional value to the V&V activities, as it allows for access to a wider range of data, and provides valuable benchmarking exercises. Three HTGR phenomena are targeted: Reactor Cavity Cooling System (RCCS) performance, core bypass flow, and lower plenum mixing. Simulations of the University of Wisconsin-Madison (UW-Madison) RCCS facilities are performed with Reynolds Averaged Navier-Stokes (RANS) in StarCCM+. Results are compared for both forced and natural convection conditions, with both exhibiting good agreement with experimental measurements. The Idaho National Laboratory (INL) matched index of refraction (MIR) and Korean Atomic Energy Research Institute (KAERI) bypass flow expeirments are used to validation CFD predictions of bypass flow. Simulations are performed with RANS in StarCCM+ and with Large Eddy Simulation (LES) in NekRS. Finally, preliminary simulations of the Institute of Nuclear and New Energy Technology (INET) lower plenum mixing facilities are presented. Initial work has developed models with LES, RANS, and porous media models. These preliminary models are presented and compared to each other to gauge differences in predictions with each of the three methods.

and Benchmarking (CMVB)↗

Validation and Verification of Python based Neutron Spectrum Unfolding Software

To validate and verify the python-based code (PySL), designed to replicate the programs used by STAYSL for Beam Correction Factor (BCF) and Self-Shielding Factor (SHIELD), a series of tests were performed. To test BCF a python script was written to generate a random flux history file and both versions of the code processed the data. The test verified matching values up to at least one decimal place, approximately 10,000 tests where run and each one passed. Isotopes began to fail the tests once neutron saturation was reached. To verify this the total time of exposure was varied the isotopes that failed were compared to a list of their half-lives. The test process for SHIELD was very similar but, in this case, the code began by producing an input file with varying thickness and device type/environment for the SHIELD input. The failure condition for this test was if any of the data points for an isotope had a difference above 3%. Approximately 40 of these tests were run and there were only 3 isotopes that had reoccurring failures but only 2% of their points were above the 3% difference. A visual comparison was conducted by plotting the results from both programs. Although the test failed, the differences between their values were minuscule, and the self-shielding factor’s shape was preserved when plotted. Next steps for this project will be validating and verifying the python-based SigPhi code and then reproducing and testing the least squares unfolding performed by STAYSL.

73 - NUCLEAR PHYSICS AND RADIATION PHYSICS↗

COnfirmation using Gamma-ray Non-Imaging Zero-knowledge ANti-mask Time-encoding (COGNIZANT) Final Summary Report

In potential future arms reduction treaties in which the numbers of nuclear warheads may approach small numbers, using delivery systems as a proxy for the warheads themselves may be insufficient. Therefore, a technical means of verifying the presence of a nuclear warhead may become necessary. Verifying that a declared item actually is a warhead is technically challenging within a verification regime: providing assurance to the monitoring party that a presented item is a warhead while protecting sensitive information about that warhead may be required. It is generally believed that strong assurance will require the confirmation of key attributes that may reveal closely-guarded critical design information. This provides high confidence to the monitoring party, but presents a risk of information loss to the host. A verification system must overcome this hurdle. Over the last several decades, systems have been developed that balance host and monitoring partner needs by using sensitive information to confirm treaty accountable items (TAI) as warheads while sequestering that information behind an information barrier (1). These are designed to meet the needs of the host but places the onus on the monitor to authenticate the hardware, firmware, and software. Authentication requires that the monitor confirm that all components of the system have not been modified and work as intended. In 2014, Glaser et al. proposed applying the concept of “zero knowledge protocols” (ZKP) from the field of cryptography to the problem of warhead verification (2). In mathematical cryptography, ZKP is accomplished by challenging one party to solve a problem that is only possible if that party possesses the information being authenticated. After repeated challenges, the party provides confidence that it possesses this information without revealing any details about the information itself. Systems have been in development based on this idea at both Princeton and MIT (2) (3) (4). The final measurement results produced by these systems can be viewed by both the host and the monitoring party without the worry of revealing sensitive information. However, in both of these physical implementations, there remains an information barrier within the system. The need for a digital information barrier to protect a measurement result is eliminated, but it has been replaced with the need to sequester physical components of the system, potentially obfuscating the measurement process itself. Both implementations physically insert information into the system that requires protection to prevent undesired disclosure of sensitive information: in the Princeton method, one must physically load the complement of the expected image of a true warhead into the system, and in the MIT technique, one loads a collection of spectator foils whose thicknesses physically encrypt a measured spectrum. This complicates authentication of the hardware and measurement process. The CONFIDANTE/COGNIZANT concept developed in this project do not load sensitive information into the system at any time, and could therefore open the possibility of allowing the inspector to not only view the final data but also the measurement as it is being performed and all associated equipment.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Annual Summary Report for the Remote-Handled Low-Level Waste Disposal Facility—FY 2024

This Fiscal Year (FY) 2024 annual summary report (ASR) documents the continued adequacy of the performance assessment (PA), the composite analysis (CA), and associated operating disposal- authorization statement (ODAS) technical-basis documents for the Remote-Handled (RH) Low-Level Waste (LLW) Disposal Facility at Idaho National Laboratory (INL). Annual review of the adequacy of the PA and CA for the Remote-Handled Low-Level Waste (RHLLW) Disposal Facility ensures that conclusions of the analyses remain valid in accordance with requirements of Department of Energy (DOE) Order 435.1, “Radioactive Waste Management.” In FY 2024, no significant operational changes or other activities occurred that would cause deviation from the assumptions in the PA and CA pertaining to disposal geometry, verification of waste characteristics, tracking disposal inventories against total limits, facility-closure design, or institutional controls. Nineteen waste canister shipments were received at the RHLLW Disposal Facility, and all nineteen waste canisters were emplaced in disposal vaults.

12 - MGMT OF RADIOACTIVE AND NON-RADIOACTIVE WASTE↗

Integrated Steady-State System Package for Nuclear Thermal Propulsion Analysis Using Multi-Dimensional Thermal Hydraulics and Dimensionless Turbopump Treatment

Nuclear thermal propulsion is an evolving technology that can be utilized for long-distance space travel. This technology yields the advantage of a high thrust and specific impulse, but requires an examination of the potential design adjustments necessary to enhance its feasibility. The development of nuclear thermal propulsion requires a comprehensive understanding of the system-level behavior during transient and steady-state operation. This paper extends our previous research by including the proper handling of turbomachinery with multi-channel thermal hydraulic simulations only for steady-state solutions. The system-level approach presented here enables the treatment of the turbopump components through non-dimensional analysis that eliminates the assumption of constant efficiencies. All the other components within the system (e.g., reflector and core) can be discretized to multiple channels and layers, in which the full thermal hydraulic solution is established. The approach chosen here enables the realistic modeling of the propellant flow within the expander cycle by capturing the pressure losses, mass flow rate splits, and enthalpy gain for various operational conditions. The verification of the package is completed through point comparisons of previous investigations into similar system designs. Furthermore, sensitivity studies are used to benchmark the capabilities of the package and investigate solution variations due to the perturbation of operational conditions and regimes. The sensitivity studies performed here are important to capture variation in flow characteristics (e.g., temperature, pressure, mass flow rates) for different design objectives such as the thrust and specific impulse. This work demonstrates that system-level simulations lacking multi-channel capability and proper turbomachinery treatment may yield higher uncertainties in understanding the engine’s response and characteristics to changing various requirements. This is extremely important when screening the design space of such propulsion systems and when transient simulations are required.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Enhancement of PyARC for Westinghouse Electric Company’s Lead Fast Reactor Design and Modeling (Final TCF Report)

Westinghouse Electric Company is a nuclear reactor vendor headquartered in the U.S. that is developing advanced reactor technology for the U.S. and global markets. Westinghouse has been relying on the neutronics Argonne Reactor Codes (ARC) executed through the NEAMS Workbench and its PyARC module that are developed under the DOE-NE Nuclear Energy Advanced Modeling and Simulation (NEAMS) and Advanced Reactor Technology (ART) – Fast Reactor programs. Through this user experience, Westinghouse identified several enhancements that would benefit the ARC codes’ usability by the US industry and therefore its commercialization potential. The enhancements were proposed to deliver both improvements in workflow and analysis capabilities to better support effective fast reactor core design and analysis to the nuclear industry. The PyARC workflow was extended in this project by integrating non-neutronic ARC codes DASSH and NUBOW-3D. The Ducted Assembly Steady-State Heat equation (DASSH) code is developed at ANL to perform steady-state thermal hydraulic sub-channel analysis in liquid metal fast reactor assemblies to determine optimized coolant flow and temperature distributions, which in this project was updated and validated for lead fast reactor (LFR) applications. The interface between REBUS and NUBOW-3D were improved in this project to assess the impact of the core restraint design and thermal induced expansion effects on the reactivity of the core, and to model the deformations of the fuel assemblies induced by temperature and irradiation. Finally, the ARC models that were extensively verified and validated through various SFR-based modeling benchmarks are extended in this project through code-to-code comparison on relevant LFR-specific neutronics benchmarks against Monte-Carlo neutronic solutions. Overall, this work enables verification of the capability of the ARC codes for a wide range of Generation-IV reactor designs. The outcome of this project is the release of a comprehensive modeling toolkit of validated, robust and efficient codes, as well as their user interface, that enables industry to perform a wide range of fast reactor analyses for design and licensing of their concepts.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

SAS4A/SASSYS-1 Verification Testing for Sodium Fast Reactor Application: Acceptance Testing Report

AS4A/SASSYS-1 (SAS) is a simulation tool used to perform deterministic analyses of anticipated events as well as design basis and beyond design basis accidents for advanced liquid-metal-cooled nuclear reactors. With its origin as SAS1A in the late 1960s, the SAS series of codes has been under continuous use and development for over sixty years and represents a critical investment in safety analysis capabilities for the U.S. Department of Energy. To support the dedication effort, this report has been generated to provide a detailed description of the available verification testing. The verification testing presented in this report captures functionality testing, focusing mainly on the testing of specific functions and algorithms for accuracy and precision of output, and interface testing, focusing mainly on the testing of critical input parameters and their valid ranges. Although SAS was developed to support the analysis of any liquid-metal-cooled nuclear reactor, the testing described in this document primarily focuses on the verification of SAS capabilities as they relate to a generic pool-type Sodium Fast Reactor (SFR).

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Flow instabilities in helical-coil steam generators for small modular reactors: A review

Here, this study covers the research and discoveries in two-phase flow-boiling instabilities available in the literature—specifically for a helical-coil steam generator (HCSG), including experimental findings, theoretical research, computational models, and system code analyses—supporting research and development of representative small modular reactors (SMRs). Like other new and advanced reactor systems, water-cooled SMRs require experimental data from both integral and separate thermal-hydraulics test facilities for the verification and validation (V&V) of the computational models and computer codes in order to design and obtain regulatory approval. The complex dynamics of two-phase flow-boiling instabilities includes flow regimes physics phenomena, flow-channel geometries, heat-transfer behavior, and interactions among the solid–liquid-gas within the system boundary, all of which are pivotal for understanding the design and operational challenges of SMRs. This study focuses on identifying the relevant knowledge gaps on boiling instabilities—specifically for a HCSG—and provides insights about future research direction optimizing the transport of thermal energy, mass-flow rates, and boundary conditions that ensure the adequate heat-transfer performance, operational stability, and safety associated with SMR systems.

20 FOSSIL-FUELED POWER PLANTS↗

Light monitoring system for the lead tungstate calorimeter in Hall D at Jefferson Lab

A new electromagnetic calorimeter composed of 1596 lead tungstate (PbWO 4 ) scintillating crystals has been constructed for the GlueX detector in Hall D at Jefferson Lab. The calorimeter is equipped with a light monitoring system that uses light-emitting diodes. The light monitoring system was fabricated, installed, and integrated into the GlueX trigger system. It was successfully operated during detector commissioning and data collection, providing monitoring of the detector response and verification of the calibration with a precision better than 1%. In conclusion, the paper describes the design, installation, and performance of the light monitoring system.

Lead tungstate calorimeter↗

MFANS 2024 - Formally Proving Characteristics of Cyber-Physical Systems

Cyber-physical systems (CPS) are engineered systems that rely on the smooth integration of computational algorithms and physical elements. This integration presents new challenges for verifying that systems will behave as expected. The goal of this presentation is to present current challenges and potential solutions for the formal verification of cyber-physical systems. For cyber systems, formal methods refer to systematically rigorous mathematical techniques employed in the specification, development, analysis, and verification of both software and hardware systems. Recent advancements in computer science have yielded sophisticated tools specifically designed to address challenges associated with formal methods in complex systems. These tools leverage various foundational concepts such as logic, formal languages, program semantics, type systems, type theory, and automata theory. A notable achievement in the application of formal methods is the seL4 microkernel, claimed to be the first general-purpose operating-system kernel to be verified. Its proof implies the absence of bugs and guarantees that the kernel meets specifications. For physical systems, dynamic and control theory has a history of using rigorous analytic techniques to prove functional correctness. Lyapunov, optimal, classical, modern, and robust control theories all provide rigorous mathematical methods both to analyze system performance and to design controller that can be guaranteed to meet certain objectives. Recent computational techniques like level set theory and reachability analysis provide assertions that a system's state will avoid unsafe regions. Even though success has been independently achieved for cyber systems and physical systems, the integration of such systems creates new challenges. In particular, there is an obvious discrepancy between finite-state machines and infinite-state systems, resulting in different approaches for modeling and analyzing these system. While it is possible to simulate hybrid systems, this provides only a demonstration of a performance and not proof. For hybrid systems, current formal methods and system analysis approaches typically require a workarounds to work on hybrid systems like CPS. This paper will outline the state of the art and limits of current practice for formally verifying CPS and will identify possible research directions that require attention.

97 MATHEMATICS AND COMPUTING↗

A Full-Induction Magnetohydrodynamics Solver for Liquid Metal Fusion Blankets in Vertex-CFD

Multiphysics modeling of liquid metal fusion blankets, which produce tritium and convert energy of neutrons created via fusion reactions into heat, is crucial for predicting performance, ensuring structural integrity, and optimizing energy production. While traditional blanket modeling of liquid metal flows during normal steady operating conditions commonly employs the inductionless approximation of the magnetohydrodynamics (MHD) equations, transient scenarios, when the plasma-confining magnetic field varies on millisecond time scales, require a full-induction MHD approach that dynamically evolves the magnetic field via the time-dependent induction equation. This paper presents the formulation, implementation, and initial verification of a full-induction MHD solver integrated within the open-source Vertex-CFD framework, which aims to achieve tight multiphysics coupling, a flexible software design enabling easy extension and addition of physics models, and performance portability across computing platforms. The solver utilizes finite element spatial discretization, implicit Runge–Kutta time integration, and an inexact Newton method to solve the resulting discrete nonlinear system, leveraging Trilinos packages for efficient computation. Verification against selected benchmark problems demonstrates accuracy and robustness of the solver. Furthermore, when the solver is applied to an idealized blanket model in 2.5D and full 3D, results obtained with Vertex-CFD are in good agreement with recently published quasi-2D simulations. These findings establish a computational foundation for future simulations of transient MHD phenomena in liquid metal blankets with Vertex-CFD, and open avenues for future extensions and performance optimizations.

Endeve, Eirik [ORNL] (ORCID:0000000312519507)↗

Puck and Puck/SAW Loop Seals (Final Report)

Tamper-indicating devices (TIDs), also known as seals, play a crucial role in various sectors including international nuclear safeguards, arms control, domestic security, and commercial products, by ensuring that monitored or high-value items are not accessed undetected. These devices do not block access but alert to unauthorized tampering. With adversaries' capabilities evolving, there's a pressing need for seals to advance in terms of effectiveness (e.g., better tamper indication and unique identification), and new technology can improve the efficiency of installation and verification. Passive loop seals, widely used in international nuclear safeguards to ensure that continuity of knowledge is maintained on declared items, face stringent International Atomic Energy Agency (IAEA) requirements that surpass those met by commercial products. The metal cup seal (Figure 1, left), a staple IAEA seal, is robust but requires significant resources for post-use verification – specifically, the seal’s unique identity can only be verified at IAEA headquarters after removal from facilities. Further, the seal has been in use for decades and seal types should periodically be replaced to counter adversarial efforts for defeating seals. In 2020, the IAEA outlined about 40 requirements for a new passive loop seal, aiming for in-situ verification, minimal external tool use, unique identification (UID), and clear tamper indication. In response, research and development efforts focused on creating a new passive loop seal that meets these criteria and in 2022 the IAEA announced the completion of the Field Verifiable Passive Loop Seal (FVPS) (Figure 1, right). Concurrently to the IAEA’s efforts, Sandia National Laboratories (SNL) and Oak Ridge National Laboratory (ORNL) designed, developed, and tested two seal versions – Puck and Puck/SAW, with Puck based on the IAEA’s requirements and including a novel visually-obvious tamper response, and Puck/SAW adding additional beneficial capabilities like the ability to receive a unique identifier from a standoff distance and monitoring the wire integrity. Puck/SAW was specifically designed and developed to address sealing applications in dry spent fuel storage facilities, where the number of sealed spent fuel containers results in heavy verification burden and inspector safety issues related to radiation exposure. These efforts are described in this Executive Summary.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

An Open-Source Python Package for CFD Solution Verification

Informed decision-making using computational fluid dynamics (CFD) results requires quantifying the errors and uncertainties of a simulation. Verification, validation, and uncertainty quantification (VVUQ) methods were developed to address this need and have matured. However, these VVUQ analyses are often non-trivial and require CFD analysts and practitioners to have specific skill sets. This has led to the uneven adoption of VVUQ analyses, in part, based on the availability of software tools to aid CFD analysts and practitioners. Solution verification, a procedure to evaluate the accuracy of a simulation by estimating potential errors arising from the computational model and computing the uncertainties without comparing to results from a physical system, is one of the lagging VVUQ analyses as the absence of software has forced CFD analysts and practitioners to develop their own codes or piece together incomplete software from across the internet. This work presents an opensource Python package, CFDverify, to lower the barrier of entry and fill in the technological gap in solution verification. CFDverify also provides a streamlined framework to remove some potential errors in post-processing CFD results. The hope is that CFDverify can improve the quality and quantity of CFD solution verification in scientific and research studies and attract interest in developing a communal tool. This paper describes the design, features, and an example use of CFDverify.

Weinmeister, Justin [ORNL] (ORCID:0000000160090237↗

Using Solid Particles as Heat Transfer Fluid-Use in CSP Plants (CRADA Final Report)

NREL assisted the BRIDGE project led by the University of Colorado (CU), Boulder, on developing granular flow and heat transfer simulation tool to serve for an enclosed particle-receiver design. NREL will provide the particle receiver design configuration and operating condition to assist the model setup and may provide certain testing results for model verifications. NREL will attend project reviewing meeting and provide application back-ground including concentrating solar energy technology to collaborate with CU researchers.

14 SOLAR ENERGY↗

Synthesis of Correct Digital Controller Models from Specifications by Model Transformation (21-0320)

The design of high consequence controllers (in weapons systems, autonomy, etc.) that do what they are supposed to do is a significant challenge. Testing simply does not come close to meeting the requirements for assurance. Today circuit designers at Sandia (and elsewhere) typically capture the core behavior of their components using state models in tools such as STATEFLOW. They then check that their models meet certain requirements (e.g. “The system bus must not deadlock” or “both traffic lights at an intersection must not be green at the same time”) using tools called model checkers. If the model checker returns “yes” then the property is guaranteed to be satisfied by the model. However, there are several drawbacks to this industry practice: (1) there is a lot of detail to get right, this is particularly challenging when there are multiple components requiring complex coordination (2) any errors returned by the model checker have to be traced back through the design and fixed, necessitating rework, (3) there are severe scalability problems with this approach, particularly when dealing with concurrency. All this places high demands on the designers who now face not only an accelerated schedule but also controllers of increasing complexity. This report describes a new and fundamentally different approach to the construction of safety-critical digital controllers. Instead of directly constructing a complete model and then trying to verify it, the designer can start with an initial abstract (think “sketch”) model plus the requirements, from which a correct concrete model is automatically synthesized. There is no need for post-hoc verification of required functional properties. Having tool to carry this out will significantly impact the nation’s ability to ensure the safety of high-consequence digital systems. The approach has been implemented in a prototype tool, along with a suite of examples, including ones that reflect actual problems faced by designers. Our approach operates on a variant of Statecharts developed at Sandia called Qspecs. Statecharts are a widely used formalism for developing concurrent reactive systems, supporting scalability through allowing state models containing composite states, which are the serial or parallel composition of substates which can themselves contain statecharts. Statecharts enable an incremental style of development, in which states are progressively refined to incorporate greater detail in an incremental model of software development. Our approach formulates a set of constraints from the structure of the models and the requirements and propagates these constraints to a fixpoint. The solution to the constraints is an inductive invariant along with guards on the transitions. We also show how our approach extends to implementation refinement, decomposition, composition, and elaboration. We currently handle safety requirements written in LTL (Linear Temporal Logic)

42 ENGINEERING↗