Search NASA⌕ Search

SEARCH · Search NASA

Results for “Integrated formal methods”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 91 records · Page 5

Dynamic Gate Product and Artifact Generation from System Models

Model Based Systems Engineering (MBSE) is gaining acceptance as a way to formalize systems engineering practice through the use of models. The traditional method of producing and managing a plethora of disjointed documents and presentations ("Power-Point Engineering") has proven both costly and limiting as a means to manage the complex and sophisticated specifications of modern space systems. We have developed a tool and method to produce sophisticated artifacts as views and by-products of integrated models, allowing us to minimize the practice of "Power-Point Engineering" from model-based projects and demonstrate the ability of MBSE to work within and supersede traditional engineering practices. This paper describes how we have created and successfully used model-based document generation techniques to extract paper artifacts from complex SysML and UML models in support of successful project reviews. Use of formal SysML and UML models for architecture and system design enables production of review documents, textual artifacts, and analyses that are consistent with one-another and require virtually no labor-intensive maintenance across small-scale design changes and multiple authors. This effort thus enables approaches that focus more on rigorous engineering work and less on "PowerPoint engineering" and production of paper-based documents or their "office-productivity" file equivalents.

engineering paradigm↗

An analytic method to account for drag in the Vinti satellite theory

A quadrature algorithm is presented which employs analytical expressions for the variations of satellite orbital elements caused by air drag. The Hamiltonian is formally preserved and the Jacobi constants of the motion are advanced with time through the variational equations. The atmospheric density profile is written as a fitted exponential function of the eccentric anomaly, which adheres to tabulated data at all altitudes and simultaneously reduces the variational equations to definite integrals with closed form evaluations, whose limits are in terms of the eccentric anomaly. Results are given for two intense air drag satellites and indicate that the satellite ephemerides produced by this method in conjunction with the Vinti program are of very high accuracy.

Watson, J. S.↗

A case study for the real-time experimental evaluation of the VIPER microprocessor

An experiment to evaluate the applicability of the Verifiable Integrated Processor for Enhanced Reliability (VIPER) microprocessor to real time control is described. The VIPER microprocessor was invented by the Royal Signals and Radar Establishment (RSRE), U.K., and is an example of the use of formal mathematical methods for developing electronic digital systems with a high degree of assurance on the system design and implementation correctness. The experiment consisted of selecting a control law, writing the control law algorithm for the VIPER processor, and providing real time, dynamic inputs into the processor and monitoring the outputs. The control law selected and coded for the VIPER processor was the yaw damper function of an automatic landing program for a 737 aircraft. The mechanisms for interfacing the VIPER Single Board Computer to the VAX host are described. Results include run time experiences, performance evaluation, and comparison of VIPER and FORTRAN yaw damper algorithm output for accuracy estimation.

Carreno, Victor A.↗

Assessment of the Orion-SLS Interface Management Process in Achieving the EIA 731.1 Systems Engineering Capability Model Generic Practices Level 3 Criteria

NASA is currently developing the next generation crewed spacecraft and launch vehicle for exploration beyond earth orbit including returning to the Moon and making the transit to Mars. Managing the design integration of major hardware elements of a space transportation system is critical for overcoming both the technical and programmatic challenges in taking a complex system from concept to space operations. An established method of accomplishing this is formal interface management. In this paper we set forth an argument that the interface management process implemented by NASA between the Orion Multi-Purpose Crew Vehicle (MPCV) and the Space Launch System (SLS) achieves the Level 3 tier of the EIA 731.1 System Engineering Capability Model (SECM) for Generic Practices. We describe the relevant NASA systems and associated organizations, and define the EIA SECM Level 3 Generic Practices. We then provide evidence for our compliance with those practices. This evidence includes discussions of: NASA Systems Engineering Interface (SE) Management standard process and best practices; the tailoring of that process for implementation on the Orion to SLS interface; changes made over time to improve the tailored process, and; the opportunities to take the resulting lessons learned and propose improvements to our institutional processes and best practices. We compare this evidence against the practices to form the rationale for the declared SECM maturity level.

Jellicorse, John J.↗

Directionality effects in the transfer of X-rays from a magnetized atmosphere: Beam pulse shape

A formalism is presented for radiation transfer in two normal polarization modes in finite and semiinfinite plane parallel uniform atmospheres with a magnetic field perpendicular to the surface and arbitrary propagation angles. This method is based on the coupled integral equations of transfer, including emission, absorption, and scattering. Calculations are performed for atmosphere parameters typical of X-ray pulsars. The directionality of the escaping radiation is investigated for several cases, varying the input distributions. Theoretical pencil beam profiles and X-ray pulse shapes are obtained assuming the radiation is emitted from the polar caps of spinning neutron stars. Implications for realistic models of accreting magnetized X-ray sources are briefly discussed.

Meszaros, P.↗

Modeling Broadband X-Ray Absorption of Massive Star Winds

We present a method for computing the net transition of X-rays emitted by shock-heated plasma distributed throughout a partially optically thick stellar wind from a massive star. We find the transmission by an exact integration of the formal solution, assuming the emitting plasma and absorbing plasma are mixed at a constant mass ratio above some minimum radius, below which there is assumed to be no emission. This model is more realistic than either the slab absorption associated with a corona at the base of the wind or the exospheric approximation that assumes all observed X-rays are emitted without attenuation from above the radius of optical depth unity. Our model is implemented in XSPEC as a pre-calculated table that can be coupled to a user-defined table of the wavelength dependent wind opacity. We provide a default wind opacity model that is more representative of real wind opacities than the commonly used neutral ISM tabulation. Preliminary modeling of Chandra grating data indicates that the X-ray hardness trend of OB stars with spectral subtype cars largely be understood as a wind absorption effect.

Leutenegger, Maurice A.↗

Recommendations on Evidence and Process for Certification of Learning-enabled Components in Aerospace Systems

This report primarily identifies a collection of relevant and necessary evidence for assurance of machine learnt components (MLCs)—also known as learning-enabled components—integrated into aircraft systems, and gives preliminary suggestions on the elements of a certification process that invoke the identified evidence. The main focus is on feedforward neural networks that are static and trained offline through supervised learning. A brief background on the generic elements of the lifecycle of an MLC is given to contextualize the assurance considerations and, consequently, the evidence that is relevant and necessary to support certification. At the level of an MLC, those considerations relate to: (i) the consistency and correctness of MLC contributions to system functions in the context of a validated functional intent; and (ii) the absence of MLC contributions to aircraft-level failure conditions. At an ML model level, confidence in model and data properties contribute to assurance of the containing MLC, in particular: (a) generalizability and robustness of models, in the presence of inputs not previously seen during training, disturbances to inputs, and unexpected inputs; and (b) valid data, i.e., data that are at least representative, relevant, complete, and accurate. Evidence for the above span the elements of the ML lifecycle, and includes, at a minimum, lifecycle artifacts that pertain to: (1) properties of requirements capturing functional intent, safety constraints, and aspects of the intended use and operating environment; (2) model performance, model complexity and design, and algorithm choice; (3) achievement of required performance at the levels of a trained model during model development, a trained model after model development is complete, and a trained model that is transformed into an executable equivalent; (4) model implementation aspects necessary for transforming a trained model into the executable equivalent; (5) integration of the executable trained model into the containing MLC, and eventually the larger system; and, (6) lastly, the verification and validation (V&V) of each of the above. Such V&V lifecycle artifacts themselves include: aspects of coverage, e.g., of various levels of requirements by the input space of the model and the data; traceability (where applicable); application of formal methods for property specification, analysis, and checking. Examples of evidence generation methods and tools further ground the discussion on what constitutes evidence, and the contribution to assurance during certification. The identified assurance considerations and supporting evidence is not a comprehensive set. Additionally, neither what should be considered as sufficient evidence relative to the assigned criticality of an MLC, nor how criticality ought to be determined and adjusted, have been considered in this report. However, suggestions are made for potential activities of the ML lifecycle that are aimed at providing confidence that an MLC can be relied upon when integrated into its containing (aircraft) system. Those activities are proposed as candidate elements of a certification process for MLCs. The main purpose of this report to inform regulatory guidance and consensus standards that may be used to meet the safety intent of the applicable regulations.

Aviation safety↗

Operator split methods in the numerical solution of the finite deformation elastoplastic dynamic problem

The spatial formulation of the elastoplastic dynamic problem for finite deformations is considered. A thermodynamic argument leads to an additive decomposition of the spatial rate of deformation tensor and allows an operator split of the evolutionary equations of the problem into elastic and plastic parts. This operator split is taken as the basis for the definition of a global product algorithm. In the context of finite element discretization the product algorithm entails, for every time step, the solution of a nonlinear elastodynamic problem followed by the application of plastic algorithms that operate on the stresses and internal variables at the integration points and bring in the plastic constitutive equations. Suitable plastic algorithms are discussed for the cases of perfect and hardening plasticity and viscoplasticity. The proposed formalism does not depend on any notion of smoothness of the yield surface and is applicable to arbitrary convex elastic regions, with or without corners. The stabiity properties of the global product algorithm are shown to be identical to those of the algorithm used for the integration of the nonlinear elastodynamic problem. Numerical examples illustrate the accuracy of the method.

Pinsky, P. M.↗

Radiative transfer in spherical atmospheres

A method for defining spherical model atmospheres in radiative/convective and hydrostatic equilibrium is presented. A finite difference form is found for the transfer equation and a matrix operator is developed as the discrete space analog (in curvilinear coordinates) of a formal integral in plane geometry. Pressure is treated as a function of temperature. Flux conservation is maintained within the energy equation, although the correct luminosity transport must be assigned for any given level of the atmosphere. A perturbed integral operator is used in a complete linearization of the transfer and constraint equations. Finally, techniques for generating stable solutions in economical computer time are discussed.

Kalkofen, W.↗

New directions for Artificial Intelligence (AI) methods in optimum design

Developments and applications of artificial intelligence (AI) methods in the design of structural systems is reviewed. Principal shortcomings in the current approach are emphasized, and the need for some degree of formalism in the development environment for such design tools is underscored. Emphasis is placed on efforts to integrate algorithmic computations in expert systems.

Hajela, Prabhat↗

Methods for design and evaluation of integrated hardware-software systems for concurrent computation

Research activities and publications are briefly summarized. The major tasks reviewed are: (1) VAX implementation of the PISCES parallel programming environment; (2) Apollo workstation network implementation of the PISCES environment; (3) FLEX implementation of the PISCES environment; (4) sparse matrix iterative solver in PSICES Fortran; (5) image processing application of PISCES; and (6) a formal model of concurrent computation being developed.

Pratt, T. W.↗

Crack Turning Mechanics of Composite Wing Skin Panels

The safety of future composite wing skin integral stiffener panels requires a full understanding of failure mechanisms of these damage tolerance critical structures under both in-plane and bending loads. Of primary interest is to derive mathematical models using fracture mechanics in anisotropic cracked plate structures, to assess the crack turning mechanisms, and thereby to enhance the residual strength in the integral stiffener composite structures. The use of fracture mechanics to assess the failure behavior in a cracked structure requires the identification of critical fracture parameters which govern the severity of stress and deformation field ahead of the flaw, and which can be evaluated using information obtained from the flaw tip. In the three-year grant, the crack-tip fields under plane deformation, crack-tip fields for anisotropic plates and anisotropic shells have been obtained. In addition, methods for determining the stress intensity factors, energy release rate, and the T-stresses have been proposed and verified. The research accomplishments can be summarized as follows: (1) Under plane deformation in anisotropic solids, the asymptotic crack-tip fields have been obtained using Stroh formalism; (2) The T-stress and the coefficient of the second term for sigma(sub y), g(sub 32), have been obtained using path-independent integral, the J-integral and Betti's reciprocal theorem together with auxiliary fields; (3) With experimental data performed by NASA, analyses indicated that the mode-I critical stress intensity factor K(sub Q) provides a satisfactory characterization of fracture initiation for a given laminate thickness, provided the failure is fiber-dominated and crack extends in a self-similar manner; (4) The high constraint specimens, especially for CT specimens, due to large T-stress and large magnitude of negative g(sub 32) term may be expected to inhibit the crack extension in the same plane and promote crack turning; (5) Crack turning out of crack plane in generally anisotropic solids under plane deformation has been studied; (6) The role of T-stress and the higher-order term of sigma(sub y) on the crack turning and stability of the kinked crack has been quantified; (7) Asymptotic crack-tip fields including the effect of transverse shear deformation (Reissner plate theory) in an anisotropic plate under bending, twisting moments, and transverse shear loads has been presented; (8) The expression of the path-independent J-integral in terms of the generalized stress and strain has been derived; (9) Asymptotic crack-tip fields including the effect of transverse shear deformation (Reissner shallow shell theory) in a general anisotropic shell has been developed; (10) The Stroh formalism was used to characterize the crack tip fields in shells up to the second term and the energy release rate was expressed in a very compact form.

Yuan, F. G.↗

Chemical Thermodynamics and the Mathematical Integration of Reaction Kinetics

Key advances in the development of numerical methods for non-reacting compressible flows have been enabled by translating physical requirements into concrete numerical guidelines, such as the satisfaction of entropy inequalities for shock-capturing techniques [Lax, Contributions to Nonlinear Functional Analysis (1971) 603-634]. In the present work, we present nonlinear numerical analysis tools that draw from Chemical Thermodynamics , the branch of Nonequilibrium Thermodynamics that deals with chemical reactions. Through Gibbs formalism, chemical thermodynamics provides a well-known theoretical expression for the chemical equilibrium constant of a reaction in terms of reduced chemical potentials. A less-known, yet extremely valuable result, due to [Krambeck, Arch. Ration. Mech. Anal. , 38 (1970) 317], states that when this expression is implemented, mass-action kinetic models are consistent with the dynamical prescriptions of the 2nd law of thermodynamics. For fixed-temperature ordinary differential equations modeling constant-volume reacting gas mixtures, this leads to a decreasing Helmholtz free energy. If the temperature is allowed to vary in accordance with conservation of energy (1st law), this leads to the statement of increasing entropy. These nonlinear prescriptions can, and should be, used to further develop temporal integration techniques for reaction kinetics. We demonstrate that Krambeck's result holds even when the equilibrium constants are approximated from data. We prove this result by constructing the implicit free energy and the implicit entropy inherent to a given approximation. This is first done for a 5-species, 17-reaction model problem for air. With this structure established, elements of discrete entropy-stability theory [Tadmor, Acta Numer. , 12 (2003) 451] are leveraged to examine the consistency of time-integration schemes with these prescriptions. Using chemical potentials, one can compute the respective contributions of the kinetics model and of the temporal scheme to free energy/entropy variations. We introduce a nonlinear-stable version of the Discontinuous-Galerkin (DG) scheme in time which shows robustness improvements over the standard linearly-stable version. Most notably, the maximum timestep that can be resolved with the nonlinearly-stable variant tends to grow with polynomial order, in contrast to the linearly-stable variant. We generalize our constructions to arbitrary systems of reversible chemical reactions, ultimately showing that the compressible reacting Euler system admits the opposite of the implicitly constructed thermodynamic entropy as a mathematical entropy . This lays important theoretical foundations towards robust scheme development [Harten, J. Comput. Phys. 49 (1983) 151-164].

STMD↗

Formalization of the Integral Calculus in the PVS Theorem Prover

The PVS Theorem prover is a widely used formal verification tool used for the analysis of safety-critical systems. The PVS prover, though fully equipped to support deduction in a very general logic framework, namely higher-order logic, it must nevertheless, be augmented with the definitions and associated theorems for every branch of mathematics and Computer Science that is used in a verification. This is a formidable task, ultimately requiring the contributions of researchers and developers all over the world. This paper reports on the formalization of the integral calculus in the PVS theorem prover. All of the basic definitions and theorems covered in a first course on integral calculus have been completed.The theory and proofs were based on Rosenlicht's classic text on real analysis and follow the traditional epsilon-delta method. The goal of this work was to provide a practical set of PVS theories that could be used for verification of hybrid systems that arise in air traffic management systems and other aerospace applications. All of the basic linearity, integrability, boundedness, and continuity properties of the integral calculus were proved. The work culminated in the proof of the Fundamental Theorem Of Calculus. There is a brief discussion about why mechanically checked proofs are so much longer than standard mathematics textbook proofs.

Butler, Ricky W.↗

Preliminary Application of Formal Verification to An Autonomy Architecture for Unmanned Aircraft

There is a desire to design autonomous systems in such a way that capabilities can be easily added or re- combined to produce new behaviors while preserving their safety properties. ICAROUS, a prototype software architecture for building safety-centric autonomous unmanned aircraft applications, is designed to support this type of extensibility and re-configurability. In ICAROUS, core capabilities are implemented as individual soft- ware services, so that enabling access to new capabilities simply requires adding new services. To make use of these capabilities, ICAROUS includes a specialized service that provides a general framework for config- uring the relative priorities, conditions, and rules that govern how different modules should be engaged and disengaged during flight. The inherent complexity of coordinating multiple modules under changing conditions makes it difficult to determine whether a particular configuration could have erroneous behaviors in certain circumstances. A robust set of integration tests can help discover errors, but testing can only realistically cover a relatively small proportion of total system behaviors. Developing good tests and interpreting the results to pinpoint the cause of errors when they arise can also be very time-consuming. To supplement testing, formal methods can be used to model and analyze complex systems, achieving better coverage and simplifying the process of finding, understanding, and fixing errors. To demonstrate these benefits, this paper explores the ap- plication of formal methods to ICAROUS. In particular, the Spin model checker is used to specify requirements for and model portions of the system, then verify whether the model satisfies the requirements and find and fix errors when it does not.

Formal Methods↗

Preliminary Application of Formal Verification to An Autonomy Architecture for Unmanned Aircraft

There is a desire to design autonomous systems in such a way that capabilities can be easily added or re-combined to produce new behaviors while preserving their safety properties. ICAROUS, a prototype software architecture for building safety-centric autonomous unmanned aircraft applications, is designed to support this type of extensibility and re-configurability. In ICAROUS, core capabilities are implemented as individual soft- ware services, so that enabling access to new capabilities simply requires adding new services. To make use of these capabilities, ICAROUS includes a specialized service that provides a general framework for config- uring the relative priorities, conditions, and rules that govern how different modules should be engaged and disengaged during flight. The inherent complexity of coordinating multiple modules under changing conditions makes it difficult to determine whether a particular configuration could have erroneous behaviors in certain circumstances. A robust set of integration tests can help discover errors, but testing can only realistically cover a relatively small proportion of total system behaviors. Developing good tests and interpreting the results to pinpoint the cause of errors when they arise can also be very time-consuming. To supplement testing, formal methods can be used to model and analyze complex systems, achieving better coverage and simplifying the process of finding, understanding, and fixing errors. To demonstrate these benefits, this paper explores the ap- plication of formal methods to ICAROUS. In particular, the Spin model checker is used to specify requirements for and model portions of the system, then verify whether the model satisfies the requirements and find and fix errors when it does not.

Formal Methods↗

Quantum theory of an optical maser. VI - Transient behavior.

The transient behavior of a laser is discussed using the quantum theory as did Scully and Lamb. The formal solution of the density-matrix equation is expressed in terms of exponentially decaying eigenmodes. Some of the lower decay constants are obtained numerically. The equations for the moments of the density matrix are then derived and solved by a truncation method. The equations of motion are integrated numerically for the case where the average number of photons in a laser cavity has the realistically large value 1.3 x 100,000. An alternative Fokker-Planck-equation approach is discussed.

Wang, Y. K.↗

Principles for Integrating Mars Analog Science, Operations, and Technology Research

During the Apollo program, the scientific community and NASA used terrestrial analog sites for understanding planetary features and for training astronauts to be scientists. Human factors studies (Harrison, Clearwater, & McKay 1991; Stuster 1996) have focused on the effects of isolation in extreme environments. More recently, with the advent of wireless computing, we have prototyped advanced EVA technologies for navigation, scheduling, and science data logging (Clancey 2002b; Clancey et al., in press). Combining these interests in a single expedition enables tremendous synergy and authenticity, as pioneered by Pascal Lee's Haughton-Mars Project (Lee 2001; Clancey 2000a) and the Mars Society s research stations on a crater rim on Devon Island in the High Canadian Arctic (Clancey 2000b; 2001b) and the Morrison Formation of southeast Utah (Clancey 2002a). Based on this experience, the following principles are proposed for conducting an integrated science, operations, and technology research program at analog sites: 1) Authentic work; 2) PI-based projects; 3) Unencumbered baseline studies; 4) Closed simulations; and 5) Observation and documentation. Following these principles, we have been integrating field science, operations research, and technology development at analog sites on Devon Island and in Utah over the past five years. Analytic methods include work practice simulation (Clancey 2002c; Sierhuis et a]., 2000a;b), by which the interaction of human behavior, facilities, geography, tools, and procedures are formalized in computer models. These models are then converted into the runtime EVA system we call mobile agents (Clancey 2002b; Clancey et al., in press). Furthermore, we have found that the Apollo Lunar Surface Journal (Jones, 1999) provides a vast repository or understanding astronaut and CapCom interactions, serving as a baseline for Mars operations and quickly highlighting opportunities for computer automation (Clancey, in press).

Clancey, William J.↗