Search NASA⌕ Search

SEARCH · Search NASA

Results for “security verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

87 records · Page 5

Information Management Platform for Data Analytics and Aggregation (IMPALA) System Design Document

The System Design document tracks the design activities that are performed to guide the integration, installation, verification, and acceptance testing of the IMPALA Platform. The inputs to the design document are derived from the activities recorded in Tasks 1 through 6 of the Statement of Work (SOW), with the proposed technical solution being the completion of Phase 1-A. With the documentation of the architecture of the IMPALA Platform and the installation steps taken, the SDD will be a living document, capturing the details about capability enhancements and system improvements to the IMPALA Platform to provide users in development of accurate and precise analytical models. The IMPALA Platform infrastructure team, data architecture team, system integration team, security management team, project manager, NASA data scientists and users are the intended audience of this document. The IMPALA Platform is an assembly of commercial-off-the-shelf (COTS) products installed on an Apache-Hadoop platform. User interface details for the COTS products will be sourced from the COTS tools vendor documentation. The SDD is a focused explanation of the inputs, design steps, and projected outcomes of every design activity for the IMPALA Platform through installation and validation.

Carnell, Andrew↗

The DEEP2 Galaxy Redshift Survey: Design, Observations, Data Reduction, and Redshifts

We describe the design and data analysis of the DEEP2 Galaxy Redshift Survey, the densest and largest high-precision redshift survey of galaxies at z approx. 1 completed to date. The survey was designed to conduct a comprehensive census of massive galaxies, their properties, environments, and large-scale structure down to absolute magnitude MB = −20 at z approx. 1 via approx.90 nights of observation on the Keck telescope. The survey covers an area of 2.8 Sq. deg divided into four separate fields observed to a limiting apparent magnitude of R(sub AB) = 24.1. Objects with z approx. < 0.7 are readily identifiable using BRI photometry and rejected in three of the four DEEP2 fields, allowing galaxies with z > 0.7 to be targeted approx. 2.5 times more efficiently than in a purely magnitude-limited sample. Approximately 60% of eligible targets are chosen for spectroscopy, yielding nearly 53,000 spectra and more than 38,000 reliable redshift measurements. Most of the targets that fail to yield secure redshifts are blue objects that lie beyond z approx. 1.45, where the [O ii] 3727 Ang. doublet lies in the infrared. The DEIMOS 1200 line mm(exp −1) grating used for the survey delivers high spectral resolution (R approx. 6000), accurate and secure redshifts, and unique internal kinematic information. Extensive ancillary data are available in the DEEP2 fields, particularly in the Extended Groth Strip, which has evolved into one of the richest multiwavelength regions on the sky. This paper is intended as a handbook for users of the DEEP2 Data Release 4, which includes all DEEP2 spectra and redshifts, as well as for the DEEP2 DEIMOS data reduction pipelines. Extensive details are provided on object selection, mask design, biases in target selection and redshift measurements, the spec2d two-dimensional data-reduction pipeline, the spec1d automated redshift pipeline, and the zspec visual redshift verification process, along with examples of instrumental signatures or other artifacts that in some cases remain after data reduction. Redshift errors and catastrophic failure rates are assessed through more than 2000 objects with duplicate observations. Sky subtraction is essentially photon-limited even under bright OH sky lines; we describe the strategies that permitted this, based on high image stability, accurate wavelength solutions, and powerful B-spline modeling methods. We also investigate the impact of targets that appear to be single objects in ground-based targeting imaging but prove to be composite in Hubble Space Telescope data; they constitute several percent of targets at z approx. 1, approaching approx. 5%-10% at z > 1.5. Summary data are given that demonstrate the superiority of DEEP2 over other deep high-precision redshift surveys at z approx. 1 in terms of redshift accuracy, sample number density, and amount of spectral information. We also provide an overview of the scientific highlights of the DEEP2 survey thus far.

Galaxy↗

Advanced software integration: The case for ITV facilities

The array of technologies and methodologies involved in the development and integration of avionics software has moved almost as rapidly as computer technology itself. Future avionics systems involve major advances and risks in the following areas: (1) Complexity; (2) Connectivity; (3) Security; (4) Duration; and (5) Software engineering. From an architectural standpoint, the systems will be much more distributed, involve session-based user interfaces, and have the layered architectures typified in the layers of abstraction concepts popular in networking. Typified in the NASA Space Station Freedom will be the highly distributed nature of software development itself. Systems composed of independent components developed in parallel must be bound by rigid standards and interfaces, the clean requirements and specifications. Avionics software provides a challenge in that it can not be flight tested until the first time it literally flies. It is the binding of requirements for such an integration environment into the advances and risks of future avionics systems that form the basis of the presented concept and the basic Integration, Test, and Verification concept within the development and integration life cycle of Space Station Mission and Avionics systems.

Garman, John R.↗

Assurance Issues in Developing AI/ML Components (and their Standards) for Civil Aviation

Standards development activities require a keen and deep understanding of the problem being solved by the standard as well as the technologies being deployed in any reference implementation of the solution. It is important to understand the mechanisms and limits of the fundamental, underlying science of implementation and verification technologies used to realize and assure systems. We need to understand the limits of what current process and metrics can provide with respect to new technologies. US leadership is important in this endeavor, and it is vital that we have a measured approach that yields sound results. We wish to start with simple, well-defined, non-safety critical applications and then progress to functions which have (1) clearly defined requirements, (2) means of checking the answer/output, and (3) means of intervention and mitigation of incorrect answers/outputs.

Aviation Safety↗

Designing to Sample the Unknown: Lessons from OSIRIS-REx Project Systems Engineering

On September 8, 2016, the third NASA New Frontiers mission launched on an Atlas V 411. The Origins, Spectral Interpretation, Resource Identification, Security-Regolith Explorer (OSIRIS-REx) will rendezvous with asteroid Bennu in 2018, collect a sample in 2020, and return that sample to Earth in September 2023. The development team has overcome a number of challenges in order to design and build a system that will make contact with an unexplored, airless, low-gravity body. This paper will provide an overview of the mission, then focus in on the system-level challenges and some of the key system-level processes. Some of the lessons here are unique to the type of mission, like discussion of operating at a largely-unknown, low-gravity object. Other lessons, particularly from the build phase, have broad implications. The OSIRIS-REx risk management process was particularly effective in achieving an on-time and under-budget development effort. The systematic requirements management and verification and the system validation also helped identify numerous potential problems. The final assessment of the OSIRIS-REx performance will need to wait until the sample is returned in 2023, but this post-launch assessment will capture some of the key systems-engineering lessons from the development team.

Asteroid↗

NASA Tech Briefs, June 2014

Topics include: Real-Time Minimization of Tracking Error for Aircraft Systems; Detecting an Extreme Minority Class in Hyperspectral Data Using Machine Learning; KSC Spaceport Weather Data Archive; Visualizing Acquisition, Processing, and Network Statistics Through Database Queries; Simulating Data Flow via Multiple Secure Connections; Systems and Services for Near-Real-Time Web Access to NPP Data; CCSDS Telemetry Decoder VHDL Core; Thermal Response of a High-Power Switch to Short Pulses; Solar Panel and System Design to Reduce Heating and Optimize Corridors for Lower-Risk Planetary Aerobraking; Low-Cost, Very Large Diamond-Turned Metal Mirror; Very-High-Load-Capacity Air Bearing Spindle for Large Diamond Turning Machines; Elevated-Temperature, Highly Emissive Coating for Energy Dissipation of Large Surfaces; Catalyst for Treatment and Control of Post-Combustion Emissions; Thermally Activated Crack Healing Mechanism for Metallic Materials; Subsurface Imaging of Nanocomposites; Self-Healing Glass Sealants for Solid Oxide Fuel Cells and Electrolyzer Cells; Micromachined Thermopile Arrays with Novel Thermo - electric Materials; Low-Cost, High-Performance MMOD Shielding; Head-Mounted Display Latency Measurement Rig; Workspace-Safe Operation of a Force- or Impedance-Controlled Robot; Cryogenic Mixing Pump with No Moving Parts; Seal Design Feature for Redundancy Verification; Dexterous Humanoid Robot; Tethered Vehicle Control and Tracking System; Lunar Organic Waste Reformer; Digital Laser Frequency Stabilization via Cavity Locking Employing Low-Frequency Direct Modulation; Deep UV Discharge Lamps in Capillary Quartz Tubes with Light Output Coupled to an Optical Fiber; Speech Acquisition and Automatic Speech Recognition for Integrated Spacesuit Audio Systems, Version II; Advanced Sensor Technology for Algal Biotechnology; High-Speed Spectral Mapper; "Ascent - Commemorating Shuttle" - A NASA Film and Multimedia Project DVD; High-Pressure, Reduced-Kinetics Mechanism for N-Hexadecane Oxidation; Method of Error Floor Mitigation in Low-Density Parity-Check Codes; X-Ray Flaw Size Parameter for POD Studies; Large Eddy Simulation Composition Equations for Two-Phase Fully Multicomponent Turbulent Flows; Scheduling Targeted and Mapping Observations with State, Resource, and Timing Constraints;

Source record↗

Technical Reference Suite Addressing Challenges of Providing Assurance for Fault Management Architectural Design

Research into complexities of software systems Fault Management (FM) and how architectural design decisions affect safety, preservation of assets, and maintenance of desired system functionality has coalesced into a technical reference (TR) suite that advances the provision of safety and mission assurance. The NASA Independent Verification and Validation (IV&V) Program, with Software Assurance Research Program support, extracted FM architectures across the IV&V portfolio to evaluate robustness, assess visibility for validation and test, and define software assurance methods applied to the architectures and designs. This investigation spanned IV&V projects with seven different primary developers, a wide range of sizes and complexities, and encompassed Deep Space Robotic, Human Spaceflight, and Earth Orbiter mission FM architectures. The initiative continues with an expansion of the TR suite to include Launch Vehicles, adding the benefit of investigating differences intrinsic to model-based FM architectures and insight into complexities of FM within an Agile software development environment, in order to improve awareness of how nontraditional processes affect FM architectural design and system health management. The identification of particular FM architectures, visibility, and associated IV&V techniques provides a TR suite that enables greater assurance that critical software systems will adequately protect against faults and respond to adverse conditions. Additionally, the role FM has with regard to strengthened security requirements, with potential to advance overall asset protection of flight software systems, is being addressed with the development of an adverse conditions database encompassing flight software vulnerabilities. Capitalizing on the established framework, this TR suite provides assurance capability for a variety of FM architectures and varied development approaches. Research results are being disseminated across NASA, other agencies, and the software community. This paper discusses the findings and TR suite informing the FM domain in best practices for FM architectural design, visibility observations, and methods employed for IV&V and mission assurance.

Fitz, Rhonda↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification Validation (IVV) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASA's Office of Safety and Mission Assurance defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domaincomponent, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IVV enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

Fault management↗

Risk-Significant Adverse Condition Awareness Strengthens Assurance of Fault Management Systems

As spaceflight systems increase in complexity, Fault Management (FM) systems are ranked high in risk-based assessment of software criticality, emphasizing the importance of establishing highly competent domain expertise to provide assurance. Adverse conditions (ACs) and specific vulnerabilities encountered by safety- and mission-critical software systems have been identified through efforts to reduce the risk posture of software-intensive NASA missions. Acknowledgement of potential off-nominal conditions and analysis to determine software system resiliency are important aspects of hazard analysis and FM. A key component of assuring FM is an assessment of how well software addresses susceptibility to failure through consideration of ACs. Focus on significant risk predicted through experienced analysis conducted at the NASA Independent Verification & Validation (IV&V) Program enables the scoping of effective assurance strategies with regard to overall asset protection of complex spaceflight as well as ground systems. Research efforts sponsored by NASAs Office of Safety and Mission Assurance (OSMA) defined terminology, categorized data fields, and designed a baseline repository that centralizes and compiles a comprehensive listing of ACs and correlated data relevant across many NASA missions. This prototype tool helps projects improve analysis by tracking ACs and allowing queries based on project, mission type, domain/component, causal fault, and other key characteristics. Vulnerability in off-nominal situations, architectural design weaknesses, and unexpected or undesirable system behaviors in reaction to faults are curtailed with the awareness of ACs and risk-significant scenarios modeled for analysts through this database. Integration within the Enterprise Architecture at NASA IV&V enables interfacing with other tools and datasets, technical support, and accessibility across the Agency. This paper discusses the development of an improved workflow process utilizing this database for adaptive, risk-informed FM assurance that critical software systems will safely and securely protect against faults and respond to ACs in order to achieve successful missions.

IV&V↗

OSIRIS-REx Touch-and-Go (TAG) Mission Design for Asteroid Sample Collection

The Origins Spectral Interpretation Resource Identification Security Regolith Explorer (OSIRIS-REx) mission is a NASA New Frontiers mission launching in September 2016 to rendezvous with the near-Earth asteroid Bennu in October 2018. After several months of proximity operations to characterize the asteroid, OSIRIS-REx flies a Touch-And-Go (TAG) trajectory to the asteroid's surface to collect at least 60 g of pristine regolith sample for Earth return. This paper provides mission and flight system overviews, with more details on the TAG mission design and key events that occur to safely and successfully collect the sample. An overview of the navigation performed relative to a chosen sample site, along with the maneuvers to reach the desired site is described. Safety monitoring during descent is performed with onboard sensors providing an option to abort, troubleshoot, and try again if necessary. Sample collection occurs using a collection device at the end of an articulating robotic arm during a brief five second contact period, while a constant force spring mechanism in the arm assists to rebound the spacecraft away from the surface. Finally, the sample is measured quantitatively utilizing the law of conservation of angular momentum, along with qualitative data from imagery of the sampling device. Upon sample mass verification, the arm places the sample into the Stardust-heritage Sample Return Capsule (SRC) for return to Earth in September 2023.

OSIRIS-REX TOUCH-AND-GO (TAG) MISSION DESIGN FOR A↗

CropEx Web-Based Agricultural Monitoring and Decision Support

CropEx is a Web-based agricultural Decision Support System (DSS) that monitors changes in crop health over time. It is designed to be used by a wide range of both public and private organizations, including individual producers and regional government offices with a vested interest in tracking vegetation health. The database and data management system automatically retrieve and ingest data for the area of interest. Another stores results of the processing and supports the DSS. The processing engine will allow server-side analysis of imagery with support for image sub-setting and a set of core raster operations for image classification, creation of vegetation indices, and change detection. The system includes the Web-based (CropEx) interface, data ingestion system, server-side processing engine, and a database processing engine. It contains a Web-based interface that has multi-tiered security profiles for multiple users. The interface provides the ability to identify areas of interest to specific users, user profiles, and methods of processing and data types for selected or created areas of interest. A compilation of programs is used to ingest available data into the system, classify that data, profile that data for quality, and make data available for the processing engine immediately upon the data s availability to the system (near real time). The processing engine consists of methods and algorithms used to process the data in a real-time fashion without copying, storing, or moving the raw data. The engine makes results available to the database processing engine for storage and further manipulation. The database processing engine ingests data from the image processing engine, distills those results into numerical indices, and stores each index for an area of interest. This process happens each time new data is ingested and processed for the area of interest, and upon subsequent database entries, the database processing engine qualifies each value for each area of interest and conducts a logical processing of results indicating when and where thresholds are exceeded. Reports are provided at regular, operator-determined intervals that include variances from thresholds and links to view raw data for verification, if necessary. The technology and method of development allow the code base to easily be modified for varied use in the real-time and near-real-time processing environments. In addition, the final product will be demonstrated as a means for rapid draft assessment of imagery.

Harvey. Craig↗

Payload Performance of Third Generation TDRS and Future Services

NASA has accepted two of the 3rd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space & Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and G/T; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, G/T, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

RF↗

Payload Performance of TDRS KL and Future Services

NASA has accepted two of the 3nd generation Tracking and Data Relay Satellites, TDRS K, L, and M, designed and built by Boeing Defense, Space Security (DSS). TDRS K, L, and M provide S-band Multiple Access (MA) service and S-band, Ku-band and Ka-band Single Access (SA) services to near Earth orbiting satellites. The TDRS KLM satellites offer improved services relative to the 1st generation TDRS spacecraft, such as: an enhanced MA service featuring increased EIRPs and GT; and Ka-band SA capability which provides a 225 and 650 MHz return service (customer-to-TDRS direction) bandwidth and a 50 MHz forward service (TDRS-to-customer direction) bandwidth. MA services are provided through a 15 element forward phased array that forms up to two beams with onboard active beamforming and a 32 element return phased array supported by ground-based beamforming. SA services are provided through two 4.6m tri-band reflector antennas which support program track pointing and autotrack pointing. Prior to NASAs acceptance of the satellites, payload on-orbit testing was performed on each satellite to determine on-orbit compliance with design requirements. Performance parameters evaluated include: EIRP, GT, antenna gain patterns, SA antenna autotrack performance, and radiometric tracking performance. On-orbit antenna calibration and pointing optimization was also performed on the MA and SA antennas including 24 hour duration tests to characterize and calibrate out diurnal effects. Bit-Error-Rate (BER) tests were performed to evaluate the end-to-end link BER performance of service through a TDRS K and L spacecraft. The TDRS M is planned to be launched in August 2017. This paper summarizes the results of the TDRS KL communications payload on-orbit performance verification and end-to-end service characterization and compares the results with the performance of the 2nd generation TDRS J. The paper also provides a high-level overview of an optical communications application that will augment the data rates supported by the Space Network.

Laser↗

Design Evolution and Verification of the A-3 Chemical Steam Generator

Following is an overview of the Chemical Steam Generator system selected to provide vacuum conditions for a new altitude test facility, the A-3 Test Stand at Stennis Space Center (SSC) in Bay St. Louis, MS. A-3 will serve as NASA s primary facility for altitude testing of the J-2X rocket engine, to be used as the primary propulsion device for the upper stages of the Ares launch vehicles. The Chemical Steam Generators (CSGs) will produce vacuum conditions in the test cell through the production and subsequent supersonic ejection of steam into a diffuser downstream of the J-2X engine nozzle exit. The Chemical Steam Generators chosen have a rich heritage of operation at rocket engine altitude test facilities since the days of the Apollo program and are still in use at NASA White Sands Test Facility (WSTF) in New Mexico. The generators at WSTF have been modified to a degree, but are still very close to the heritage design. The intent for the A-3 implementation is to maintain this heritage design as much as possible, making minimal updates only where necessary to substitute for obsolete parts and to increase reliability. Reliability improvements are especially desired because the proposed system will require 27 generators, which is nine times the largest system installed in the 1960s. Improvements were suggested by the original design firm, Reaction Motors, by NASA SSC and NASA WSTF engineers, and by the A-3 test stand design contractor, Jacobs Technology, Inc. (JTI). This paper describes the range of improvements made to the design to date, starting with the heritage generator and the minor modifications made over time at WSTF, to the modernized configuration which will be used at A-3. The paper will discuss NASA s investment in modifications to SSC s E-2 test facility fire a full-scale Chemical Steam Generator in advance of the larger steam system installation at A-3. Risk mitigation testing will be performed in early 2009 at this test facility to verify that the CSGs operate as expected. The generator which will undergo this testing is of the most recent A-3 configuration, and will be instrumented far in excess of what is normally required for operation. The extra data will allow for easier troubleshooting and more complete knowledge of expected generator performance. In addition, the early testing will give SSC personnel experience in operating the CSG systems, which will expedite the process of installation and activation at A-3. Each Chemical Steam Generator is supported by a complement of valves, instruments, and flow control devices, with the entire assembly called a "module." The generators will be installed in groups of three, historically called "units". A module is so called because of its modular ability to be replaced or serviced without disturbing the other two modules installed on the same unit. A module is pictured in Figure 1, shown with its generator secured by white bands in its shipping (vs. installed) configuration. The heritage system at WSTF is composed of a single unit (three generator modules), pictured in Figure 2 as it was installed in 1965. In contrast, A-3 will have nine units operating in parallel to achieve vacuum conditions appropriate for testing the J-2X engine. Each of the combustors operates in two modes and achieves the so-called "full-steam" mode after all three of its stages ignite. Ignition of the first stage is achieved by exciting a spark plug; the second stage and main stage are lit by the flame front of the previous stage. The main stage burns approximately 97% of the total propellant flow and uses the heat energy to vaporize water into superheated steam. While the main stage remains unlit, the combustor is in so-called "idle" mode. In the WSTF system, this idle mode is not optimized for water usage, and does not need to be, as the water is pumped from a large reservoir. The water supply at A-3 will be contained in tanks with finite volume, so water optimization is preferred for the modnized configuration. Multiple solutions for this issue have been proposed, with the leading concept being a change to the operational definition of "idle mode," with the generator running in a lower heat flux condition.

Kirchner, Casey K.↗

R2U2 in Space: System and Software Health Management for Small Satellites

In order for small but complex systems like rovers, SmallSats, or Unmanned Aircraft (UAS) to operate autonomously, they must have a real-time solution for assessing their own system health. System and Software Health Management (SHM) enables better detection of faulty sensors and software problems, and enables better fault management including mitigation of unpredicted fault scenarios in the absence of a human on-board. In recent work, we have developed a Responsive, Realizable, Unobtrusive Unit (R2U2) for on-board SHM of autonomous UAS and demonstrated its ability to detect faults during flight time. These faults, from sensor failures, to software problems, to malicious security attacks, can present as transient temporal faults that even humans are challenged to find. An R2U2 congfiuration is a modular combination of multiple types of temporal logic runtime observers with fault-specic Bayesian Nets and sensor filters. R2U2 reasons about both on-board hardware and software components; R2U2 itself can be instantiated as an independent FPGA (Field-Programmable Gate Array)-based conguration or as a software component running independently from other software on-board. Small satellites, such as CubeSats, also require on-board SHM and failure mitigation, as limited telemetry bandwidth does not allow the transmission of the entire system state for ground-based health management. However, the autonomous operation of satellites brings a set of challenges different from UAS, including the effects of radiation on non-rad-hard, low-cost components, and the harsher environment of space. We surmise that a new extension of R2U2 could be adapted to help better detect, for example, radiation errors in cheaper COTS (Commercial Off the Shelf) (not rad-hard) components often used in small space systems. Since small satellites often operate in coordination, we will also examine new ways of distributed monitoring of their communication and cooperation and real-time detection of off-nominal situations utilizing multiple satellites. This talk will discuss preliminary work and ideas for building on terrestrial success of system and software health management for the harsher, and differently challenging, environment of space.

Runtime Verification & Validation↗