Search NASA⌕ Search

SEARCH · Search NASA

Results for “Requirements Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

An Integrated Reliability and Physics-Based Risk Modeling Approach for Assessing Human Spaceflight Systems

This paper presents an integrated reliability and physics-based risk modeling approach for assessing human spaceflight systems. The approach is demonstrated using an example, end-to-end risk assessment of a generic-crewed space transportation system during a reference mission to the International Space Station. The behavior of the system is modeled using analysis techniques from multiple disciplines in order to properly capture the dynamic time- and state- dependent consequences of failures encountered in different mission phases. We discuss how to combine traditional reliability analyses with Monte Carlo simulation methods and physics-based engineering models to produce loss-of- mission and loss-of-crew risk estimates supporting risk-based decision-making and requirement verification. This approach facilitates risk-informed design by providing more realistic representation of system failures and interactions; identifying key risk-driving sensitivities, dependencies, and assumptions; and tracking multiple figures of merit within a single, responsive assessment framework that can readily incorporate evolving design information throughout system development.

Risk assessment↗

Comparative Analysis of Static and Dynamic Probabilistic Risk Assessment

This study examines three different methodologies for producing loss-of-mission (LOM) and loss-of-crew (LOC) risks estimates for probabilistic risk assessments (PRA) of crewed spacecraft. The three bottom-up, component-based PRA approaches examined are a traditional static fault tree, a dynamic Monte Carlo simulation, and a fault tree hybrid that incorporates some dynamic elements. These approaches were used to model the reaction control system thruster pod of a generic crewed spacecraft and mission, and a comparative analysis of the methods is presented. The methodologies are assessed in terms of the process of modeling a system, the actionable information produced for the design team, and the overall fidelity of the quantitative risk evaluation generated. The system modeling process is compared in terms of the effort required to generate the initial model, update the model in response to design changes, and support mass-versus-risk trade studies. The results are compared by examining the top-level LOM/LOC estimates and the relative risk driver rankings at the failure mode level. The fidelity of each modeling methodology is discussed in terms of its capability to handle real-world system dynamics such as cold-sparing, changes in mission operations due to loss of redundancy, and common cause failure modes. The paper also discusses the applicability of each methodology to different phases of system development and shows that a single methodology may not be suitable for all of the many purposes of a spacecraft PRA. The fault tree hybrid approach is shown to be best suited to the needs of early assessments during conceptual design phases. As the design begins to mature, the level of detail represented in the risk model must go beyond redundancy and nominal mission operations to include dynamic, time- and state-dependent system responses as well as diverse system capabilities. This is best accomplished using the dynamic simulation approach, since these phenomena are not easily captured by static methods. Ultimately, once the design has been finalized and the goal of the PRA is to provide design validation and requirement verification, more traditional, static fault tree approaches may become as appropriate as the simulation method.

Mattenberger, Christopher J.↗

Recurring Causes of Human Spaceflight Mishaps during Flight Tests and Early Operations

n analysis of recurring causes underlying human spaceflight mishaps that occurred during flight tests and early operations was performed. Eight mishaps from the Apollo, Soyuz, Skylab, Space Shuttle, and Constellation Programs (i.e., the Ares-1X test flight) and commercial suborbital systems were included in the study. Detailed event analyses were performed for the historical mishaps and aggregate data analyses conducted to identify recurring issues. The nine most frequent issues were inadequate technical controls or risk management practices, incomplete procedures, system design and development issues, inadequate inspection or secondary verification requirements, failures of organizations to learn from previous incidents, inadequate schedule controls, inadequate task analyses or design processes, flaws in the design of organizations, and issues with organizational safety cultures.

Timothy S Barth↗

Recurring Causes of Human Spaceflight Mishaps During Flight Tests and Early Operations

An analysis of recurring causes underlying human spaceflight mishaps that occurred during flight tests and early operations was performed. Eight mishaps from the Apollo, Soyuz, Skylab, Space Shuttle, and Constellation Programs (i.e., the Ares-1X test flight) and early commercial suborbital operations were included in the study. Detailed event analyses were performed for the historical mishaps and aggregate data analyses conducted to identify recurring issues. The nine most frequent issues were inadequate technical controls or risk management practices, incomplete procedures, system design and development issues, inadequate inspection or secondary verification requirements, failures of organizations to learn from previous incidents, inadequate schedule controls, inadequate task analyses or design processes, flaws in the design of organizations, and issues with organizational safety cultures.

Human Spaceflight↗

Ka-band Phase Measurement System for SWOT Mission

The KaRIn (Ka-band radar interferometer) instrument for SWOT (surface water ocean topography) mission faces unique challenges in terms of phase stability and group delay stability requirements to achieve centimeter level accuracy for height measurements. Conventional altimetry assumes nadir point return and measures a single range. SWOT will require additional angle of arrival information to provide swath coverage. Errors in differential phase and common group delay can both act as primary sources of systematic errors in determining the height using interferometric data. The ground support equipment (GSE) necessary for the performance requirements verification gets a fraction of the error allocation from the instrument. A phase measurement system capable of measuring millidegrees and working with pulsed excitation is developed and the preliminary results are described in this paper.

Esteban-Fernandez, Daniel↗

The OpenSE Cookbook: A Practical, Recipe Based Collection of Patterns, Procedures, and Best Practices for Executable Systems Engineering for the Thirty Meter Telescope

The OpenSE Cookbook is an open-sourced collection of patterns, procedures, and best practices targeted for systems engineers who seek guidance on applying model-based and executable systems engineering (MBSE) using SysML. Its content has emerged from the system level modeling effort on the European Framework Program 6 (FP6) and the Thirty Meter Telescope (TMT). The TMT MBSE approach applied the Executable Systems Engineering Method (ESEM) and the open-source Engineering Environment (OpenMBEE) to specify, analyze, and verify requirements of TMT’s Alignment and Phasing System (APS) and the Narrow Field Infrared Adaptive Optics System (NFIRAOS). In these applications, implicit dependencies are made explicit in a formal model through the use of ESEM, OpenMBEE, and SysML modeling constructs. The value proposition for applying this MBSE approach was to establish precise requirements and fine-grained traceability to system designs, and to verify key requirements beginning early in development. The integration of ESEM and the OpenMBEE tooling infrastructure (providing linked-data and web-operability) is a significant added value for the MBSE approach. The APS is responsible for the overall pre-adaptive optics wavefront quality, using starlight to measure wavefront errors and align the TMT optics. In the formally integrated and executable SysML model, simulations are performed to analyze the impact of changed requirements and verify specified constraints for various operational scenarios. The APS team used several modeling patterns to capture information such as the requirements, the operational scenarios, involved subsystems and their interaction points, the estimated or required time durations, and the mass and power consumption. Adaptive optics systems are designed to sense real-time atmospheric turbulence and correct the telescope’s optical beam to remove its effect. The system model for the adaptive optics operational modes was developed to capture sequence behaviors and operational scenarios to run Monte-Carlo simulations for verifying acquisition time, observing efficiency, and operational behavior requirements. The model is particularly useful for investigating the effect of parallelization, identifying interface issues, and re-ordering sequence acquisition tasks. A former version of the Cookbook (which is now updated to MBSE challenges, goals, and lessons learned) included modeling guidelines and conventions for all system aspects, hierarchy levels, and views, which were developed during for the Active Phasing Experiment (APE), an opto-mechatronical system technology demonstrator for the Extremely Large Telescope (ELT). The Cookbook utilizes the above mentioned system models as real-world case-studies to demonstrate and document the applications of the recipes, providing also instructional examples and addressing the available tooling support. The Cookbook is accompanied by a number of SysML models and aodel libraries which facilitate model authoring and maintenance. The Cookbook covers the different aspects of Systems Engineering such as management of Requirements, Design (behavior and structure), Interfaces, Interdisciplinary Integration, Analysis, Trade Studies, and Technical Resources. This paper presents the background, motivation, architecture, and highlights some key content of the Cookbook. For example, interface management, error budget management, requirements verification, Monte Carlo driven analysis, and timing analysis of operational scenarios. The paper discusses how the capabilities of OpenMBEE contributed significantly to the adoption of executable systems engineering.

Brower, Eric↗

A Reinforcement Learning Framework for Space Missions in Unknown Environments

A land-and-traverse mission to icy worlds such as Europa and Enceladus is challenging due to lack of prior knowledge regarding the terrain conditions. Previous work [1] showed that rovers with high degrees of freedom (DoF) can achieve robust traversal by leveraging redundant modes for mobility to counter terrain uncertainty (e.g. walking, driving, or inch-worming). This paper presents a generic and scalable reinforcement learning scheme for enabling on-board decision making on rovers to automatically switch between modes of traversal based on online performance feedback. The objective is to maximize energy efficiency, minimize operator input and successfully negotiate unstructured terrain conditions without relying on exhaustive prior knowledge. The proposed methodology is well grounded in the literature on reinforcement learning and has been adapted to address conformance to validation and verification requirements and JPL flight operations history of using per-sol prescribed sequences for a space mission.

Tavallali, Peyman↗

SWOT and NISAR Boom Ground Deployment Test Challenges & Resolution

NASA’s Jet Propulsion Laboratory is developing two new spacecraft that use radar instruments to characterize temporal changes in the Earth’s surface with unprecedented precision (Figure 1). Both the Surface Water Ocean Topography (SWOT) and the NASA-ISRO Synthetic Aperture Radar (NISAR) spacecraft utilize large, precision flight deployable booms to properly position and support their instrument reflectors. The SWOT spacecraft includes two nearly identical reflector booms, each of which have similar flight deployable hinge designs. The NISAR spacecraft has a single reflector boom, with four unique hinge designs. These booms each undergo a multi-staged flight deployment sequence on orbit to transition from the launch stowed configuration to the science configuration within days of launch (Figure 2). The SWOT and NISAR Projects faced significant challenges relevant to requirement verification as well as hardware safety in their approach to ground testing these large flight deployables. This report summarizes flight deployable system design decisions that contributed to ground testing challenges. The report also summarizes the architecture trade study conducted for ground deployment testing. A summary of key issues encountered during flight deployable ground testing with the chosen common gravity offload system ensues, with discussion of the issues and mitigation measures implemented by both Projects that ultimately enabled successful flight subsystem-level full range of motion ground tests. Recommendations and lessons learned are offered to facilitate ground testability of future analogous large scale flight deployables.

Waters, Kyle C.↗

Guidelines for mission integration, a summary report

Guidelines are presented for instrument/experiment developers concerning hardware design, flight verification, and operations and mission implementation requirements. Interface requirements between the STS and instruments/experiments are defined. Interface constraints and design guidelines are presented along with integrated payload requirements for Spacelab Missions 1, 2, and 3. Interim data are suggested for use during hardware development until more detailed information is developed when a complete mission and an integrated payload system are defined. Safety requirements, flight verification requirements, and operations procedures are defined.

Source record↗

From Natural Language Requirements to the Verification of Programmable Logic Controllers: Integrating FRET into PLCverif

PLCverif is an actively developed project at CERN, enabling the formal verification of Programmable Logic Controller (PLC) programs in critical systems. In this paper, we present our work on improving the formal requirements specification experience in PLCverif through the use of natural language. To this end, we integrate NASA’s FRET, a formal requirement elicitation and authoring tool, into PLCverif. FRET is used to specify formal requirements in structured natural language, which automatically translates into temporal logic formulae. FRET’s output is then directly used by PLCverif for verification purposes. We discuss practical challenges that PLCverif users face when authoring requirements and the FRET features that help alleviate these problems. We present the new requirement formalization workflow and report our experience using it on two critical CERN case studies.

FRET↗

From Natural Language Requirements to the Verification of Programmable Logic Controllers: Integrating FRET into PLCverif

PLCverif is an actively developed project at CERN, enabling the formal verification of Programmable Logic Controller (PLC) programs in critical systems. In this paper, we present our work on improving the formal requirements specification experience in PLCverif through the use of natural language. To this end, we integrate NASA’s FRET, a formal requirement elicitation and authoring tool, into PLCverif. FRET is used to specify formal requirements in structured natural language, which automatically translates into temporal logic formulae. FRET’s output is then directly used by PLCverif for verification purposes. We discuss practical challenges that PLCverif users face when authoring requirements and the FRET features that help alleviate these problems. We present the new requirement formalization workflow and report our experience using it on two critical CERN case studies.

FRET↗

The NASA Space Launch System Program Systems Engineering Approach for Affordability

The National Aeronautics and Space Administration is currently developing the Space Launch System to provide the United States with a capability to launch large Payloads into Low Earth orbit and deep space. One of the development tenets of the SLS Program is affordability. One initiative to enhance affordability is the SLS approach to requirements definition, verification and system certification. The key aspects of this initiative include: 1) Minimizing the number of requirements, 2) Elimination of explicit verification requirements, 3) Use of certified models of subsystem capability in lieu of requirements when appropriate and 4) Certification of capability beyond minimum required capability. Implementation of each aspect is described and compared to a "typical" systems engineering implementation, including a discussion of relative risk. Examples of each implementation within the SLS Program are provided.

Hutt, John J.↗

ASRDI Oxygen Technology Survey. Volume 2: Cleaning Requirements, Procedures, and Verification Techniques

The oxygen system cleaning specifications drawn from 23 industrial and government sources are presented along with cleaning processes employed for meeting these specifications, and recommended postcleaning inspection procedures for establishing the cleanliness achieved. Areas of agreement and difference in the specifications, procedures, and inspection are examined. Also, the lack of clarity or specificity will be discussed. This absence of clarity represents potential safety hazards due to misinterpretation. It can result in exorbitant expenditures of time and money in satisfying unnecessary requirements.

Bankaitis, H.↗

Spacecraft Requirements Development and Tailoring

Spacecraft design is managed through the use of design requirements. Requirements are flowed from the highest level, the overall spacecraft, to systems, subsystems and ultimately individual components. Through the use of requirements, each part of the spacecraft will perform the functions that are required of it and will interface to the rest of the spacecraft. Functional requirements are used to make sure every component performs as expected and interface requirements ensure that each component works within the larger design environment where it operates. Writing good requirements is difficult and the verification of requirements can be expensive and time consuming. Because of this difficulty and expense, it is important that each requirement truly be “required” and critical to the overall performance of the vehicle. It is also important that requirements can be changed or eliminated as the system matures to minimize verification cost and schedule. The Capsule Parachute Assembly System (CPAS) Project is developing the parachute system for the NASA Multi-Purpose Crew Vehicle (MPCV) Orion Spacecraft. Throughout the development and qualification cycle for CPAS, requirements have been evaluated, added, eliminated, or more generically, “tailored”, to ensure that the system performs as required while minimizing the verification cost to the Program. One facet of this tailoring has been to delete requirements that do not add value to the overall spacecraft or are not needed. A second approach to minimize the cost of requirement verification has been to evaluate requirements based on the actual design as it has matured. As the design of the parachute system has become better understood, requirements that are not applicable have been eliminated. This paper will outline the evolution of CPAS requirements over time and will show how careful and considered changes to requirements can benefit the technical solution for the overall system design while allowing a Project to control costs.

Mcmichael, James H.↗