Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 109 records · Page 6

Swarm Mentality: Toward Automatic Swarm State Awareness with Runtime Verification

Cyber-Physical Systems (CPSs) already exhibit impressive performance in all areas of human life, and swarms of CPSs promise to increase their capabilities even further. However, to effectively utilize CPS swarms their complexity of operation has to scale sub-linearly with the number of swarm members. Presenting the swarm to an operator as a single entity almost eliminates the additional per-member overhead entirely. To operate a swarm as one entity, and/or to increase the swarm’s autonomy, the operator and the swarm members need to reason and communicate at the same level of abstraction, i.e. the swarm needs a sense of “self.” Therefore, we require the ability to specify whole swarm properties yet monitor them at the member level. We examine one architecture for achieving this awareness by: 1) Defining a taxonomy for comparing techniques that synthesize this belief-state 2) Propose use of the Runtime Verification formal method to fill this role 3) Present preliminary designs for extending and embedding such a system in the Distributed Spacecraft Autonomy architecture to generate per-member monitors from swarm level specification.

Runtime Verification↗

Software Fault Tolerance: A Tutorial

Because of our present inability to produce error-free software, software fault tolerance is and will continue to be an important consideration in software systems. The root cause of software design errors is the complexity of the systems. Compounding the problems in building correct software is the difficulty in assessing the correctness of software for highly complex systems. After a brief overview of the software development processes, we note how hard-to-detect design faults are likely to be introduced during development and how software faults tend to be state-dependent and activated by particular input sequences. Although component reliability is an important quality measure for system level analysis, software reliability is hard to characterize and the use of post-verification reliability estimates remains a controversial issue. For some applications software safety is more important than reliability, and fault tolerance techniques used in those applications are aimed at preventing catastrophes. Single version software fault tolerance techniques discussed include system structuring and closure, atomic actions, inline fault detection, exception handling, and others. Multiversion techniques are based on the assumption that software built differently should fail differently and thus, if one of the redundant versions fails, it is expected that at least one of the other versions will provide an acceptable output. Recovery blocks, N-version programming, and other multiversion techniques are reviewed.

Torres-Pomales, Wilfredo↗

Space Station battery system design and development

The Space Station Electric Power System will rely on nickel-hydrogen batteries in its photovoltaic power subsystem for energy storage to support eclipse and contingency operations. These 81-Ah batteries will be designed for a 5-year life capability and are configured as orbital replaceable units (ORUs), permitting replacement of worn-out batteries over the anticipated 30-year Station life. This paper describes the baseline design and the development plans for the battery assemblies, the battery ORUs and the battery system. Key elements reviewed are the cells, mechanical and thermal design of the assembly, the ORU approach and interfaces, and the electrical design of the battery system. The anticipated operational approach is discussed, covering expected performance as well as the processor-controlled charge management and discharge load allocation techniques. Development plans cover verification of materials, cells, assemblies and ORUs, as well as system-level test and analyses.

Haas, R. J.↗

Formal verification of an avionics microprocessor

Formal specification combined with mechanical verification is a promising approach for achieving the extremely high levels of assurance required of safety-critical digital systems. However, many questions remain regarding their use in practice: Can these techniques scale up to industrial systems, where are they likely to be useful, and how should industry go about incorporating them into practice? This report discusses a project undertaken to answer some of these questions, the formal verification of the AAMPS microprocessor. This project consisted of formally specifying in the PVS language a rockwell proprietary microprocessor at both the instruction-set and register-transfer levels and using the PVS theorem prover to show that the microcode correctly implemented the instruction-level specification for a representative subset of instructions. Notable aspects of this project include the use of a formal specification language by practicing hardware and software engineers, the integration of traditional inspections with formal specifications, and the use of a mechanical theorem prover to verify a portion of a commercial, pipelined microprocessor that was not explicitly designed for formal verification.

Srivas, Mandayam, K.↗

TOPEX/POSEIDON mission overview

TOPEX/POSEIDON is the first space mission specifically designed and conducted for studying the circulation of the world's oceans. A state-of-the-art radar altimetry system is used to measure the precise height of sea level, from which information on the ocean circulation is obtained. The satellite, launched on August 10, 1992, has been making observations of the global oceans with unprecedented accuracy since late September 1992. To meet the stringent measurement accuracy required for ocean circulation studies, a number of innovative improvements have been made to the mission design, including the first dual-frequency space-borne radar altimeter capable of retrieving the ionospheric delay of the radar signal, a three-frequency microwave radiometer for retrieving the signal delay caused by the water vapor in the troposphere, an optimal model of the Earth's gravity field and multiple satellite tracking systems for precision orbit determination. Additionally, the satellite also carries two experimental instruments to demonstrate new technologies: a single-frequency solid-state altimeter for the technology of low-power, low-weight altimeter and a Global Positioning System receiver for continuous,precise satellite tracking. The performance of the mission's measurement system has been tested by numerous verification studies. The results indicate that the root-sum-square accuracy of a single-pass sea level measurement is 4.7 cm for the TOPEX system and 5.1 cm for the POSEIDON system; both are more than a factor of 2 better than the requirement of 13.7 cm. This global data set is being analyzed to improve understanding of the global ocean circulation as well as the ocean tides, geodesy, and geodynamics, and ocean wind and waves. The mission is designed to last for at least 3 years with a possible extension to 6 years. The multiyear global data set will go a long way toward understanding the ocean circulation and its variability in relation to climate change. A summary of the mission's systems and their performance as well as the mission's science team is presented.

Fu, Lee-Lueng↗

Automatic documentation system extension to multi-manufacturers' computers and to measure, improve, and predict software reliability

The DOMONIC system has been modified to run on the Univac 1108 and the CDC 6600 as well as the IBM 370 computer system. The DOMONIC monitor system has been implemented to gather data which can be used to optimize the DOMONIC system and to predict the reliability of software developed using DOMONIC. The areas of quality metrics, error characterization, program complexity, program testing, validation and verification are analyzed. A software reliability model for estimating program completion levels and one on which to base system acceptance have been developed. The DAVE system which performs flow analysis and error detection has been converted from the University of Colorado CDC 6400/6600 computer to the IBM 360/370 computer system for use with the DOMONIC system.

Simmons, D. B.↗

An Integrated Approach to Exploration Launch Office Requirements Development

The proposed paper will focus on the Project Management and Systems Engineering approach utilized to develop a set of both integrated and cohesive requirements for the Exploration Launch Office, within the Constellation Program. A summary of the programmatic drivers which influenced the approach along with details of the resulting implementation will be discussed as well as metrics evaluating the efficiency and accuracy of the various requirements development activities. Requirements development activities will focus on the procedures utilized to ensure that technical content was valid and mature in preparation for the Crew Launch Vehicle and Constellation System s Requirements Reviews. This discussion will begin at initial requirements development during the Exploration Systems Architecture Study and progress through formal development of the program structure. Specific emphasis will be given to development and validation of the requirements. This discussion will focus on approaches to garner the appropriate requirement owners (or customers), project infrastructure utilized to emphasize proper integration, and finally the procedure to technically mature, verify and validate the requirements. Examples of requirements being implemented on the Launch Vehicle (systems, interfaces, test & verification) will be utilized to demonstrate the various processes and also provide a top level understanding of the launch vehicle(s) performance goals. Details may also be provided on the approaches for verification, which range from typical aerospace hardware development (qualification/acceptance) through flight certification (flight test, etc.). The primary intent of this paper is to provide a demonstrated procedure for the development of a mature, effective, integrated set of requirements on a complex system, which also has the added intricacies of both heritage and new hardware development integration. Ancillary focus of the paper will include discussion of Test and Verification approaches along with top level systems/elements performance capabilities.

Holladay, Jon B.↗

Space station definition and preliminary design, WP-01. Volume 1: Executive summary

System activities are summarized and an overview of the system level engineering tasks performed are provided. Areas discussed include requirements, system test and verification, the advanced development plan, customer accommodations, software, growth, productivity, operations, product assurance and metrication. The hardware element study results are summarized. Overviews of recommended configurations are provided for the core module, the USL, the logistics elements, the propulsion subsystems, reboost, vehicle accommodations, and the smart front end. A brief overview is provided for costing activities.

Lenda, J. A.↗

Mars Exploration Rover Entry, Descent, and Landing: A Thermal Perspective

Perhaps the most challenging mission phase for the Mars Exploration Rovers was the Entry, Descent, and Landing (EDL). During this phase, the entry vehicle attached to its cruise stage was transformed into a stowed tetrahedral Lander that was surrounded by inflated airbags through a series of complex events. There was only one opportunity to successfully execute an automated command sequence without any possible ground intervention. The success of EDL was reliant upon the system thermal design: 1) to thermally condition EDL hardware from cruise storage temperatures to operating temperature ranges; 2) to maintain the Rover electronics within operating temperature ranges without the benefit of the cruise single phase cooling loop, which had been evacuated in preparation for EDL; and 3) to maintain the cruise stage propulsion components for the critical turn to entry attitude. Since the EDL architecture was inherited from Mars Pathfinder (MPF), the initial EDL thermal design would be inherited from MPF. However, hardware and implementation differences from MPF ultimately changed the MPF inheritance approach for the EDL thermal design. With the lack of full inheritance, the verification and validation of the EDL thermal design took on increased significance. This paper will summarize the verification and validation approach for the EDL thermal design along with applicable system level thermal testing results as well as appropriate thermal analyses. In addition, the lessons learned during the system-level testing will be discussed. Finally, the in-flight EDL experiences of both MER-A and -B missions (Spirit and Opportunity, respectively) will be presented, demonstrated how lessons learned from Spirit were applied to Opportunity.

thermal↗

GPM Solar Array Gravity Negated Deployment Testing

NASA Goddard Space Flight Center (GSFC) successfully developed a g-negation support system for use on the solar arrays of the Global Precipitation Measurement (GPM) Satellite. This system provides full deployment capability at the subsystem and observatory levels. In addition, the system provides capability for deployed configuration first mode frequency verification testing. The system consists of air pads, a support structure, an air supply, and support tables. The g-negation support system was used to support all deployment activities for flight solar array deployment testing.

Penn, Jonathan↗

Overview of the TOPEX/Poseidon Platform Harvest Verification Experiment

An overview is given of the in situ measurement system installed on Texaco's Platform Harvest for verification of the sea-level measurement from the TOPEX/POSEIDON satellite. The pre-launch error budget suggested that the total root mean square (RMS) error due to measurements made at this verification site would be less than four centimeters.

satellite↗

Functional Fault Model Development Process to Support Design Analysis and Operational Assessment

A functional fault model (FFM) is an abstract representation of the failure space of a given system. As such, it simulates the propagation of failure effects along paths between the origin of the system failure modes and points within the system capable of observing the failure effects. As a result, FFMs may be used to diagnose the presence of failures in the modeled system. FFMs necessarily contain a significant amount of information about the design, operations, and failure modes and effects. One of the important benefits of FFMs is that they may be qualitative, rather than quantitative and, as a result, may be implemented early in the design process when there is more potential to positively impact the system design. FFMs may therefore be developed and matured throughout the monitored system's design process and may subsequently be used to provide real-time diagnostic assessments that support system operations. This paper provides an overview of a generalized NASA process that is being used to develop and apply FFMs. FFM technology has been evolving for more than 25 years. The FFM development process presented in this paper was refined during NASA's Ares I, Space Launch System, and Ground Systems Development and Operations programs (i.e., from about 2007 to the present). Process refinement took place as new modeling, analysis, and verification tools were created to enhance FFM capabilities. In this paper, standard elements of a model development process (i.e., knowledge acquisition, conceptual design, implementation & verification, and application) are described within the context of FFMs. Further, newer tools and analytical capabilities that may benefit the broader systems engineering process are identified and briefly described. The discussion is intended as a high-level guide for future FFM modelers.

Verification↗

Proportional and Integral Thermal Control System for Large Scale Heating Tests

The National Aeronautics and Space Administration Armstrong Flight Research Center (Edwards, California) Flight Loads Laboratory is a unique national laboratory that supports thermal, mechanical, thermal/mechanical, and structural dynamics research and testing. A Proportional Integral thermal control system was designed and implemented to support thermal tests. A thermal control algorithm supporting a quartz lamp heater was developed based on the Proportional Integral control concept and a linearized heating process. The thermal control equations were derived and expressed in terms of power levels, integral gain, proportional gain, and differences between thermal setpoints and skin temperatures. Besides the derived equations, user's predefined thermal test information generated in the form of thermal maps was used to implement the thermal control system capabilities. Graphite heater closed-loop thermal control and graphite heater open-loop power level were added later to fulfill the demand for higher temperature tests. Verification and validation tests were performed to ensure that the thermal control system requirements were achieved. This thermal control system has successfully supported many milestone thermal and thermal/mechanical tests for almost a decade with temperatures ranging from 50 F to 3000 F and temperature rise rates from -10 F/s to 70 F/s for a variety of test articles having unique thermal profiles and test setups.

Thermal Control System↗

Species Transport Framework Development in SAM for System-Level Tritium Source Term Analysis

The SAM code is under development as a modern system-level modeling and simulation tool for advanced non–light water reactor safety analyses, with recent efforts to add capabilities to evaluate radiological source term risks in these novel reactor concepts. By leveraging the established system-level multiphysics thermal-hydraulic models in SAM, a framework for tightly coupled species transport modeling has been integrated into the code for engineering-scale source term evaluation. This species transport framework was first applied to the simulation of tritium, which is a well-known source term in conventional light water reactors. Tritium poses a unique risk in salt-cooled reactors, especially those with lithium-bearing salts such as the fluoride salt–cooled high-temperature reactor (FHR) concept, as tritium is generated in the salt coolant in significant quantities due to neutron interactions. A compounding factor is the increased mobility of tritium at high temperatures, which is able to permeate through metals while also potentially being retained in graphite pebbles and structures. Engineering-scale models for the tritium transport pathways in a FHR have been developed using the new species transport framework in SAM. The capabilities are assessed through analytical verification problems and validated with data from a graphite retention experiment. In conclusion, the system-level model is demonstrated by performing an initial estimate of baseline tritium generation and flows in a generic reference SAM FHR model, setting a foundation for future studies of source term transient analysis with the potential for further multiscale and multiphysics integration.

SAM↗

The CHANDRA X-Ray Observatory: Thermal Design, Verification, and Early Orbit Experience

The CHANDRA X-ray Observatory (formerly AXAF), one of NASA's "Great Observatories" was launched aboard the Shuttle in July 1999. CHANDRA comprises a grazing-incidence X-ray telescope of unprecedented focal-length, collecting area and angular resolution -- better than two orders of magnitude improvement in imaging performance over any previous soft X-ray (0.1-10 keV) mission. Two focal-plane instruments, one with a 150 K passively-cooled detector, provide celestial X-ray images and spectra. Thermal control of CHANDRA includes active systems for the telescope mirror and environment and the optical bench, and largely passive systems for the focal plans instruments. Performance testing of these thermal control systems required 1-1/2 years at increasing levels of integration, culminating in thermal-balance testing of the fully-configured observatory during the summer of 1998. This paper outlines details of thermal design tradeoffs and methods for both the Observatory and the two focal-plane instruments, the thermal verification philosophy of the Chandra program (what to test and at what level), and summarizes the results of the instrument, optical system and observatory testing.

Boyd, David A.↗

Formal design and verification of a reliable computing platform for real-time control (phase 3 results)

In this paper the design and formal verification of the lower levels of the Reliable Computing Platform (RCP), a fault-tolerant computing system for digital flight control applications, are presented. The RCP uses NMR-style redundancy to mask faults and internal majority voting to flush the effects of transient faults. Two new layers of the RCP hierarchy are introduced: the Minimal Voting refinement (DA_minv) of the Distributed Asynchronous (DA) model and the Local Executive (LE) Model. Both the DA_minv model and the LE model are specified formally and have been verified using the Ehdm verification system. All specifications and proofs are available electronically via the Internet using anonymous FTP or World Wide Web (WWW) access.

Butler, Ricky W.↗

SAFEGUARD: An Assured Safety Net Technology for UAS

As demands increase to use unmanned aircraft systems (UAS) for a broad spectrum of commercial applications, regulatory authorities are examining how to safely integrate them without loss of safety or major disruption to existing airspace operations. This work addresses the development of the Safeguard system as an assured safety net technology for UAS. The Safeguard system monitors and enforces conformance to a set of rules defined prior to flight (e.g., geospatial stay-out or stay-in regions, speed limits, altitude limits). Safeguard operates independently of the UAS autopilot and is strategically designed in a way that can be realized by a small set of verifiable functions to simplify compliance with regulatory standards for commercial aircraft. A framework is described that decouples the system from any other devices on the UAS as well as introduces complementary positioning source(s) for applications that require integrity and availability beyond what the Global Positioning System (GPS) can provide. Additionally, the high level logic embedded within the software is presented, as well as the steps being taken toward verification and validation (V&V) of proper functionality. Next, an initial prototype implementation of the described system is disclosed. Lastly, future work including development, testing, and system V&V is summarized.

Dill, Evan T.↗

The Space Shuttle's testing gauntlet

The Space Shuttle verification program is detailed, with verification network flowcharts. Performance qualification tests, life endurance tests, structural verification tests, and vibration/dynamic tests of components, subsystems, and major systems at various test levels are dealt with. Ground tests, static firings of the Shuttle main engine, external-tank separation tests, ground vibration tests of vehicle mated to external tank, and main propulsion tests and test scheduling are described. Functions of the Shuttle avionics integration laboratory and electronic systems test laboratory are discussed. Test preparations and procedures for orbital flight testing, launch pad tests, and Shuttle approach- and landing-tests are described.

Mcintosh, G. P.↗