Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Fan Acoustic Issues in the NASA Space Flight Experience

Emphasis needs to be placed on choosing quiet fans compatible with systems design and specifications that control spec levels: a) Sound power; b) Choose quiet fan or plan to quiet it, early in program; c) Plan early verification that fan source allocations are met. Airborne noise: a) System design should function/play together with fans used (flow passages, restrictions, bends, expansions & contractions, and acoustics) vs. fan speed understood (nominal, worst case, & unplanned variances); b) Fan inlets treated, as required; c) Fan Outlets treated, as required; d) Ducted system inlets are outlets designed for acoustic compliance compatibility & designed so some late required modifications can be made without significant impacts. Structure Borne Noise: a) Structure borne noise dealt with as part of fan package or installation; b) Duct attachments and lines isolated. Case Radiated Noise: - Treatment added as much as possible to fan package (see example).

Allen, Christopher S.↗

Design of lightning protection for a full-authority digital engine control

The steps and procedures are described which are necessary to achieve a successful lightning-protection design for a state-of-the-art Full-Authority Digital Engine Control (FADEC) system. The engine and control systems used as examples are fictional, but the design and verification methods are real. Topics discussed include: applicable airworthiness regulation, selection of equipment transient design and control levels for the engine/airframe and intra-engine segments of the system, the use of cable shields, terminal-protection devices and filter circuits in hardware protection design, and software approaches to minimize upset potential. Shield terminations, grounding, and bonding are also discussed, as are the important elements of certification and test plans, and the role of tests and analyses. Also included are examples of multiple-stroke and multiple-burst testing. A review of design pitfalls and challenges, and status of applicable test standards such as RTCA DO-160, Section 22, are presented.

Dargi, M.↗

Real Time Nitrogen Monitoring and Quality Control System for NASA Astromaterials Collection

The Nitrogen system is a vital utility supporting the curation office within NASA's Astromaterials Re-search and Exploration Science (ARES) Division at the Johnson Space center (JSC). Since the Apollo samples were returned in 1969. It has played an essential role in preserving NASA’s astromaterial collections (now nine collections) by maintaining contamination-free, controlled environments required for long term curation and advanced scientific research. To meet the stringent purity requirements for contamination control, high purity modified Grade C Liquid Nitrogen (LN2) is delivered weekly by an industrial gas vendor to a 15,000-gallon tank located outside at NASA JSC near the ARES facility. This nitrogen is vital for creating an inert atmosphere to store the collection in, ensuring they are continuously shielded from contaminants and alterations through a constant N2purge. For most of the past 65 years deliveries of LN2 have required a CoA (Certificate of Analysis) prior to delivery. If those were not available, then LN2 deliver were sent to third-party laboratories for verification, creating an operational bottleneck and quality gap. To address this challenge and maintain rigorous quality control, NASA JSC Infrastructure and Astromaterials Acquisition & Curation Office initiated the development of an on-site Analytical Gas Sampling (AGS) Laboratory. Designed to streamline quality verification if a CoA unavailable, the AGS lab was constructed by a subcontractor in Newton, NJ. After a successful factory acceptance test conducted by the NASA ARES Infrastructure team, the lab was trans-ported to NASA JSC, where it was anchored and integrated into the site’s nitrogen pressure system using stainless steel, oxygen-cleaned tubing. The ARES nitrogen system was modified to provide parallel flows to the AGS lab for quality control and to the astromaterials collection labs for maintaining an inert environment. The AGS lab features two operational modes: (1)Primary: Gaseous Nitrogen (GN2) Quality Monitoring –The AGS system continuously samples the site’s GN2 supply every 15 minutes to ensure compliance with required purity levels. (2) Secondary: LN2 Quality Verification when a comprehensive CoA is not available, a cryogenic vaporizer converts LN2 to GN2, which is then analyzed for impurities: H₂, Ar, O₂, CO, CO₂, H₂O, and total hydrocarbons (THC). By significantly enhancing on-site analytical capabilities, the AGS lab eliminates reliance on external testing, ensures uninterrupted quality monitoring of the nitrogen pressure system, and reinforces NASA’s commitment to preserving pristine astromaterials under the highest standards of curation and research integrity.

glove box↗

Space construction system analysis. Part 2: Platform definition

The top level system requirements are summarized and the accompanying conceptual design for an engineering and technology verification platform (ETVP) system is presented. An encompassing statement of the system objectives which drive the system requirements is presented and the major mission and subsystem requirements are described with emphasis on the advanced communications technology mission payload. The platform design is defined and used as a reference configuration for an end to space construction analyses. The preferred construction methods and processes, the important interactions between the platform design and the construction system design and operation, and the technology development efforts required to support the design and space construction of the ETVP are outlined.

Hart, R. J.↗

Space Telescope precision pointing control system

The Hubble Space Telescope has the most stringent pointing requirements imposed on any spacecraft to date. The overall HST stability shall not exceed 0.007 arc-seconds rms. The Pointing Control System utilizes fine guidance sensors and rate gyros for attitude reference and rate information. Control torques are provided by reaction wheels. A digital computer collects the sensor data, performs the control law computations, and sends torque commands to the reaction wheels. To attain this precision pointing, improvements were made to the rate gyros to lower their noise characteristics and to the reaction wheels to reduce their emitted vibration levels. The control system design was validated in a test sequence which progressed from model verification tests on an air-bearing to operations-oriented, closed loop testing on the assembled vehicle. A test system is described which allowed the simultaneous production of test case command loads for the flight computer and plots of predicted profiles to assist in test data analysis. Workarounds were required during system test to accommodate gyro biases and noise introduced into the closed loop system. Testing and analysis indicate that the HST will provide the capability to meet the requirements for precision pointing.

Beals, G. A.↗

Robust Stability Analysis of the Space Launch System Control Design: A Singular Value Approach

Classical stability analysis consists of breaking the feedback loops one at a time and determining separately how much gain or phase variations would destabilize the stable nominal feedback system. For typical launch vehicle control design, classical control techniques are generally employed. In addition to stability margins, frequency domain Monte Carlo methods are used to evaluate the robustness of the design. However, such techniques were developed for Single-Input-Single-Output (SISO) systems and do not take into consideration the off-diagonal terms in the transfer function matrix of Multi-Input-Multi-Output (MIMO) systems. Robust stability analysis techniques such as H(sub infinity) and mu are applicable to MIMO systems but have not been adopted as standard practices within the launch vehicle controls community. This paper took advantage of a simple singular-value-based MIMO stability margin evaluation method based on work done by Mukhopadhyay and Newsom and applied it to the SLS high-fidelity dynamics model. The method computes a simultaneous multi-loop gain and phase margin that could be related back to classical margins. The results presented in this paper suggest that for the SLS system, traditional SISO stability margins are similar to the MIMO margins. This additional level of verification provides confidence in the robustness of the control design.

Pei, Jing↗

Heatshield for Extreme Entry Environment Technology (HEEET) Thermal Protection System (TPS)

Starting in 2013 and completing in 2019, the Heatshield for Extreme Entry Environment Technology (HEEET) project has been working to mature a 3-D Woven Thermal Protection System (TPS) to Technical Readiness Level (TRL) 6 to support future NASA missions to destinations with extreme entry environments such as Venus, Saturn, Uranus, Neptune and high-speed sample return missions to Earth. A key aspect of the project has been the building and testing of a 1-meter base diameter Engineering Test Unit (ETU) representative of what could be used for a Saturn probe. This paper provides a high-level overview of the HEEET project including manufacturing and testing of the ETU for structural model verification, establish system capability and verify manufacturing workmanship.

Extreme Entry Environment↗

Towards the Formal Verification of a Distributed Real-Time Automotive System

We present the status of a project which aims at building, formally and pervasively verifying a distributed automotive system. The target system is a gate-level model which consists of several interconnected electronic control units with independent clocks. This model is verified against the specification as seen by a system programmer. The automotive system is implemented on several FPGA boards. The pervasive verification is carried out using combination of interactive theorem proving (Isabelle/HOL) and model checking (LTL).

Endres, Erik↗

Hierarchical Design and Verification for VLSI

The specification and verification work is described in detail, and some of the problems and issues to be resolved in their application to Very Large Scale Integration VLSI systems are examined. The hierarchical design methodologies enable a system architect or design team to decompose a complex design into a formal hierarchy of levels of abstraction. The first step inprogram verification is tree formation. The next step after tree formation is the generation from the trees of the verification conditions themselves. The approach taken here is similar in spirit to the corresponding step in program verification but requires modeling of the semantics of circuit elements rather than program statements. The last step is that of proving the verification conditions using a mechanical theorem-prover.

Shostak, R. E.↗

DRS: Derivational Reasoning System

The high reliability requirements for airborne systems requires fault-tolerant architectures to address failures in the presence of physical faults, and the elimination of design flaws during the specification and validation phase of the design cycle. Although much progress has been made in developing methods to address physical faults, design flaws remain a serious problem. Formal methods provides a mathematical basis for removing design flaws from digital systems. DRS (Derivational Reasoning System) is a formal design tool based on advanced research in mathematical modeling and formal synthesis. The system implements a basic design algebra for synthesizing digital circuit descriptions from high level functional specifications. DRS incorporates an executable specification language, a set of correctness preserving transformations, verification interface, and a logic synthesis interface, making it a powerful tool for realizing hardware from abstract specifications. DRS integrates recent advances in transformational reasoning, automated theorem proving and high-level CAD synthesis systems in order to provide enhanced reliability in designs with reduced time and cost.

Bose, Bhaskar↗

James Webb Space Telescope (JWST) Integrated Science Instruments Module (ISIM) Cryo-Vacuum (CV) Test Campaign Summary

JWST Integrated Science Instruments Module (ISIM) has completed its system-level testing program at the NASA Goddard Space Flight Center (GSFC). In March 2016, ISIM was successfully delivered for integration with the Optical Telescope Element (OTE) after the successful verification of the system through a series of three cryo-vacuum (CV) tests. The first test served as a risk reduction test; the second test provided the initial verification of the fully-integrated flight instruments; and the third test verified the system in its final flight configuration. The complexity of the mission has generated challenging requirements that demand highly reliable system performance and capabilities from the Space Environment Simulator (SES) vacuum chamber. As JWST progressed through its CV testing campaign, deficiencies in the test configuration and support equipment were uncovered from one test to the next. Subsequent upgrades and modifications were implemented to improve the facility support capabilities required to achieve test requirements. This paper: (1) provides an overview of the integrated mechanical and thermal facility systems required to achieve the objectives of JWST ISIM testing, (2) compares the overall facility performance and instrumentation results from the three ISIM CV tests, and (3) summarizes lessons learned from the ISIM testing campaign.

Yew, Calinda↗

Supportability Technologies for Future Exploration Missions

Future long-duration human exploration missions will be challenged by resupply limitations and mass and volume constraints. Consequently, it will be essential that the logistics footprint required to support these missions be minimized and that capabilities be provided to make them highly autonomous from a logistics perspective. Strategies to achieve these objectives include broad implementation of commonality and standardization at all hardware levels and across all systems, repair of failed hardware at the lowest possible hardware level, and manufacture of structural and mechanical replacement components as needed. Repair at the lowest hardware levels will require the availability of compact, portable systems for diagnosis of failures in electronic systems and verification of system functionality following repair. Rework systems will be required that enable the removal and replacement of microelectronic components with minimal human intervention to minimize skill requirements and training demand for crews. Materials used in the assembly of electronic systems (e.g. solders, fluxes, conformal coatings) must be compatible with the available repair methods and the spacecraft environment. Manufacturing of replacement parts for structural and mechanical applications will require additive manufacturing systems that can generate near-net-shape parts from the range of engineering alloys employed in the spacecraft structure and in the parts utilized in other surface systems. These additive manufacturing processes will need to be supported by real-time non-destructive evaluation during layer-additive processing for on-the-fly quality control. This will provide capabilities for quality control and may serve as an input for closed-loop process control. Additionally, non-destructive methods should be available for material property determination. These nondestructive evaluation processes should be incorporated with the additive manufacturing process - providing an in-process capability to ensure that material deposited during layer-additive processing meets required material property criteria.

Watson, Kevin↗

Advanced Extravehicular Activity Pressure Garment Requirements Development

The NASA Johnson Space Center advanced pressure garment technology development team is addressing requirements development for exploration missions. Lessons learned from the Z‐2 high fidelity prototype development have reiterated that clear low‐level requirements and verification methods reduce risk to the government, improve efficiency in pressure garment design efforts, and enable the government to be a smart buyer. The expectation is to provide requirements at the specification level that are validated so that their impact on pressure garment design is understood. Additionally, the team will provide defined verification protocols for the requirements. However, in reviewing exploration space suit high level requirements there are several gaps in the team's ability to define and verify related lower level requirements. This paper addresses the efforts in requirement areas such as mobility/fit/comfort and environmental protection (dust, radiation, plasma, secondary impacts) to determine the by what method the requirements can be defined and use of those methods for verification. Gaps exist at various stages. In some cases component level work is underway, but no system level effort has begun, in other cases no effort has been initiated to close the gap. Status of ongoing efforts and potential approaches to open gaps are discussed.

Ross, Amy↗

Advanced Extra-Vehicular Activity Pressure Garment Requirements Development

The NASA Johnson Space Center advanced pressure garment technology development team is addressing requirements development for exploration missions. Lessons learned from the Z-2 high fidelity prototype development have reiterated that clear low-level requirements and verification methods reduce risk to the government, improve efficiency in pressure garment design efforts, and enable the government to be a smart buyer. The expectation is to provide requirements at the specification level that are validated so that their impact on pressure garment design is understood. Additionally, the team will provide defined verification protocols for the requirements. However, in reviewing exploration space suit high level requirements there are several gaps in the team's ability to define and verify related lower level requirements. This paper addresses the efforts in requirement areas such as mobility/fit/comfort and environmental protection (dust, radiation, plasma, secondary impacts) to determine the method by which the requirements can be defined and use of those methods for verification. Gaps exist at various stages. In some cases component level work is underway, but no system level effort has begun; in other cases no effort has been initiated to close the gap. Status of on-going efforts and potential approaches to open gaps are discussed.

Ross, Amy↗

Space Station module Power Management And Distribution (PMAD) system

This project consists of several tasks which are unified toward experimentally demonstrating the operation of a highly autonomous, user-supportive power management and distribution system for Space Station Freedom (SSF) habitation/laboratory modules. This goal will be extended to a demonstration of autonomous, cooperative power system operation for the whole SSF power system through a joint effort with NASA's Lewis Research Center, using their Autonomous Power System. Short term goals for the space station module power management and distribution include having an operational breadboard reflecting current plans for SSF, improving performance of the system communications, and improving the organization and mutability of the artificial intelligence (AI) systems. In the middle term, intermediate levels of autonomy will be added, user interfaces will be modified, and enhanced modeling capabilities will be integrated in the system. Long term goals involve conversion of all software into Ada, vigorous verification and validation efforts and, finally, seeing an impact of this research on the operation of SSF. Conversion of the system to a DC Star configuration is now in progress, and should be completed by the end of October, 1989. This configuration reflects the latest SSF module architecture. Hardware is now being procured which will improve system communications significantly. The Knowledge-Based Management System (KBMS) is initially developed and the rules from FRAMES have been implemented in the KBMS. Rules in the other two AI systems are also being grouped modularly, making them more tractable, and easier to eventually move into the KBMS. Adding an intermediate level of autonomy will require development of a planning utility, which will also be built using the KBMS. These changes will require having the user interface for the whole system available from one interface. An Enhanced Model will be developed, which will allow exercise of the system through the interface without requiring all of the power hardware to be operational. The functionality of the AI systems will continue to be advanced, including incipient failure detection. Ada conversion will begin with the lowest level processor (LLP) code. Then selected pieces of the higher level functionality will be recorded in Ada and, where possible, moved to the LLP level. Validation and verification will be done on the Ada code, and will complete sometimes after completion of the Ada conversion.

Walls, Bryan↗

Analysis of Complexity Evolution Management and Human Performance Issues in Commercial Aircraft Automation Systems

Autoflight systems in the current generation of aircraft have been implicated in several recent incidents and accidents. A contributory aspect to these incidents may be the manner in which aircraft transition between differing behaviours or 'modes.' The current state of aircraft automation was investigated and the incremental development of the autoflight system was tracked through a set of aircraft to gain insight into how these systems developed. This process appears to have resulted in a system without a consistent global representation. In order to evaluate and examine autoflight systems, a 'Hybrid Automation Representation' (HAR) was developed. This representation was used to examine several specific problems known to exist in aircraft systems. Cyclomatic complexity is an analysis tool from computer science which counts the number of linearly independent paths through a program graph. This approach was extended to examine autoflight mode transitions modelled with the HAR. A survey was conducted of pilots to identify those autoflight mode transitions which airline pilots find difficult. The transitions identified in this survey were analyzed using cyclomatic complexity to gain insight into the apparent complexity of the autoflight system from the perspective of the pilot. Mode transitions which had been identified as complex by pilots were found to have a high cyclomatic complexity. Further examination was made into a set of specific problems identified in aircraft: the lack of a consistent representation of automation, concern regarding appropriate feedback from the automation, and the implications of physical limitations on the autoflight systems. Mode transitions involved in changing to and leveling at a new altitude were identified across multiple aircraft by numerous pilots. Where possible, evaluation and verification of the behaviour of these autoflight mode transitions was investigated via aircraft-specific high fidelity simulators. Three solution approaches to concerns regarding autoflight systems, and mode transitions in particular, are presented in this thesis. The first is to use training to modify pilot behaviours, or procedures to work around known problems. The second approach is to mitigate problems by enhancing feedback. The third approach is to modify the process by which automation is designed. The Operator Directed Process forces the consideration and creation of an automation model early in the design process for use as the basis of the software specification and training.

Vakil, Sanjay S.↗

Regulatory and Technical Issues Concerning the Detection and Treatment of NDMA-Contaminated Groundwater at NASA WSTF

The National Aeronautics and Space Administration (NASA) White Sands Test Facility (WSTF) was established in 1963 primarily to provide rocket engine testing services for several NASA programs. The groundwater underlying the site has been contaminated as a result of historical operations. Groundwater contaminants include several volatile organic compounds (VOCs) and two semi-volatile compounds: N-nitrosodimethylamine (NDMA) and N-nitrodimethylamine (DMN). This paper discusses some of the technical, analytical, regulatory, and health risk issues associated with the contaminant plume. The plume has moved approximately 2.5 miles downgradient of the facility industrial boundary, with evidence of continued migration. As a result, NASA has proposed a pump and treat system using air strippers and ultraviolet (UV) oxidation to stabilize future movement of the contaminant plume. The system has been designed to treat 1,076 gallons (4,073 liters) per minute, with provisions for future expansion. The UV oxidation process was selected to treat NDMA-contaminated groundwater based on successes at other NDMA-contaminated sites. Bench- and pilot-scale testing of WSTF groundwater confirmed the ability of UV oxidation to destroy NDMA and generated sufficient data to design the proposed full-scale treatment system. NDMA is acutely toxic and is a probable human carcinogen. EPA-recommended health risk criteria for the residential consumption of NDMA/DMN-contaminated groundwater was used to determine that a 1.0 x 10(exp -6) excess cancer risk corresponds to 1.7 parts per trillion (ppt). EPA analytical methods are unable to detect NDMA and DMN in the low ppt range. EPA's current Appendix IX analytical method used to screen for NDMA, Method 8270, can detect NDMA only at levels that are orders of magnitude greater than the recommended health risk level. Additionally, EPA Method 607, the most sensitive EPA approved method, has a detection limit of 150 ppt. This corresponds to an excess cancer risk of 9.0 x 10(exp -5), which exceeds the State of New Mexico's water quality standard of a cancer risk less than 1 x 10(exp -5). The treatment system has been engineered to treat contaminated groundwater to levels significantly below the New Mexico standard. However, the inability of EPA-approved analytical methods to detect NDMA and DMN at low ppt levels, and to provide verification of compliance with the 1 x 10(exp -5) cancer risk, introduces a notable risk to the long-term operation of the system. WSTF has been working with Southwest Research Institute to develop a non-EPA analytical method that can achieve a reporting limit of 1 ppt, which corresponds to an excess cancer risk of 7.6 x 10(exp -7). WSTF is currently developing a proposal to obtain approval from the New Mexico Environment Department (NMED) of this non-EPA method.

Wiebe, D. T.↗

Model-Based Verification and Validation of the SMAP Uplink Processes

This case study stands as an example of how a project can validate a system-level design earlier in the project life cycle than traditional V&V processes by using simulation on a system model. Specifically, this paper describes how simulation was added to a system model of the Soil Moisture Active-Passive (SMAP) mission's uplink process.Also discussed are the advantages and disadvantages of the methods employed and the lessons learned; which are intended to benefit future model-based and simulation-based V&V development efforts.

verification and validation (V&V)↗