Search NASA⌕ Search

SEARCH · Search NASA

Results for “certification by analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Sound Quality Metric Indicators of Rotorcraft Noise Annoyance Using Multilevel Regression Analysis

Although every helicopter in operation has to go through a noise certification process, annoyance due to helicopters still persists within various communities. This implies that certification metrics do not capture the full range of human response and that predicted reactions could be supplemented with other information, which could be acoustic or non-acoustic in nature. The rotorcraft sound quality metric (RoQM) psychoacoustic experiment was designed to determine the relative importance of sound quality metrics (SQMs), such as sharpness, tonality, loudness, fluctuation strength and impulsiveness, on human annoyance to rotorcraft sounds. Starting from a baseline helicopter recording, SQMs were varied synthetically and presented to subjects who responded with an annoyance rating. The RoQM test took place in 2017 at the NASA Langley Research Center in the Exterior Effects Room. A total of 105 sounds were played to 40 subjects. The relationship between helicopter noise sound quality and annoyance is modeled using multilevel regression in this work, which takes into account the variability of responses across subjects. Previous analyses did not consider such a grouping of the data.

Matthew Boucher↗

Develop advanced nonlinear signal analysis topographical mapping system

The Space Shuttle Main Engine (SSME) has been undergoing extensive flight certification and developmental testing, which involves some 250 health monitoring measurements. Under the severe temperature, pressure, and dynamic environments sustained during operation, numerous major component failures have occurred, resulting in extensive engine hardware damage and scheduling losses. To enhance SSME safety and reliability, detailed analysis and evaluation of the measurements signal are mandatory to assess its dynamic characteristics and operational condition. Efficient and reliable signal detection techniques will reduce catastrophic system failure risks and expedite the evaluation of both flight and ground test data, and thereby reduce launch turn-around time. The basic objective of this contract are threefold: (1) develop and validate a hierarchy of innovative signal analysis techniques for nonlinear and nonstationary time-frequency analysis. Performance evaluation will be carried out through detailed analysis of extensive SSME static firing and flight data. These techniques will be incorporated into a fully automated system; (2) develop an advanced nonlinear signal analysis topographical mapping system (ATMS) to generate a Compressed SSME TOPO Data Base (CSTDB). This ATMS system will convert tremendous amount of complex vibration signals from the entire SSME test history into a bank of succinct image-like patterns while retaining all respective phase information. High compression ratio can be achieved to allow minimal storage requirement, while providing fast signature retrieval, pattern comparison, and identification capabilities; and (3) integrate the nonlinear correlation techniques into the CSTDB data base with compatible TOPO input data format. Such integrated ATMS system will provide the large test archives necessary for quick signature comparison. This study will provide timely assessment of SSME component operational status, identify probable causes of malfunction, and indicate feasible engineering solutions. The final result of this program will yield an ATMS system of nonlinear and nonstationary spectral analysis software package integrated with the Compressed SSME TOPO Data Base (CSTDB) on the same platform. This system will allow NASA engineers to retrieve any unique defect signatures and trends associated with different failure modes and anomalous phenomena over the entire SSME test history across turbo pump families.

Source record↗

Fusion of Test and Analysis: Artemis I Booster to Mobile Launcher Interface Validation

NASA is in the midst of bold and exciting next steps in human exploration and spaceflight. The designs of the new Space Launch System (SLS), the Orion spacecraft and the Exploration Ground Systems (EGS) for vehicle processing and launch are essentially complete and there has been significant progress in manufacturing and assembly of specific hardware for the Artemis I and Artemis II missions. Equally as important, the program level and integrated system level testing and analyses are also well underway to support integrated verification, validation, and Certificate of Flight Readiness (CoFR) for Artemis I. Testing and analysis are key to addressing technical challenges faced by the Artemis missions. Building block approaches are required that provide the right balance between component, element, and/or system level testing that satisfies verification and validation objectives where uncertainties are quantified and minimized. Artemis I is a system of systems that requires a fusion of test and analysis that adeptly characterizes critical interfaces between major program elements. An example of this fusion involves characterizing the interface between the SLS booster and the Mobile Launcher (ML) Vertical Support Post (VSP) interfaces. Proper characterization of this interface represents a number of challenges beginning with the fact that it is a mating of ground support structure in the form of a civil structure to flight hardware. Both sides of the interface are built to different construction standards, but are governed by interface requirements to ensure compatibility when mated. From past program experience, the flexibility at the booster to ML interface is critical in developing accurate prelaunch stacking and cryogenic preloads, squat loads, and pad separation release of preloads and squat loads. This same premise holds for Artemis I. To characterize the asymmetric characteristics at this interface, careful consideration of static forces due to gravity loading with the commensurate effects due to leveling during booster stacking (i.e., spacing and shimming) and nonlinear geometric forces are necessary for inclusion in pre-test assessments. This paper will look at these issues for the upcoming Booster Pull Test in which two boosters will be installed on the ML and one of these boosters will undergo static lateral loading followed afterwards with dynamic excitation into resonance and free-decay. This paper evaluates the booster to ML interface characteristics by characterizing the interface flexibility between the booster aft skirt and the ML VSP interfaces. Furthermore, this paper methodically evaluates the effect of the following on the test outcome: gravitational effects on the booster and ML, the effects of VSP leveling, spacing, and shimming under gravitational loading during booster stacking, the effect of geometric nonlinear follower force due to cg offset as booster is laterally displaced, and the system coupling between the booster under test, ML, and the second booster. Simulated results for a static load pull and dynamic excitation provide insight into the differences in measurement responses when boundary conditions and geometric conditions are included and not included.

Joel W Sills Jr.↗

PCC Framework for Program-Generators

In this paper, we propose a proof-carrying code framework for program-generators. The enabling technique is abstract parsing, a static string analysis technique, which is used as a component for generating and validating certificates. Our framework provides an efficient solution for certifying program-generators whose safety properties are expressed in terms of the grammar representing the generated program. The fixed-point solution of the analysis is generated and attached with the program-generator on the code producer side. The consumer receives the code with a fixed-point solution and validates that the received fixed point is indeed a fixed point of the received code. This validation can be done in a single pass.

Kong, Soonho↗

Certification of damage tolerant composite structure

A reliability based certification testing methodology for impact damage tolerant composite structure was developed. Cocured, adhesively bonded, and impact damaged composite static strength and fatigue life data were statistically analyzed to determine the influence of test parameters on the data scatter. The impact damage resistance and damage tolerance of various structural configurations were characterized through the analysis of an industry wide database of impact test results. Realistic impact damage certification requirements were proposed based on actual fleet aircraft data. The capabilities of available impact damage analysis methods were determined through correlation with experimental data. Probabilistic methods were developed to estimate the reliability of impact damaged composite structures.

Rapoff, Andrew J.↗

Adding Assurance to Automatically Generated Code

Code to estimate position and attitude of a spacecraft or aircraft belongs to the most safety-critical parts of flight software. The complex underlying mathematics and abundance of design details make it error-prone and reliable implementations costly. AutoFilter is a program synthesis tool for the automatic generation of state estimation code from compact specifications. It can automatically produce additional safety certificates which formally guarantee that each generated program individually satisfies a set of important safety policies. These safety policies (e.g.. array-bounds, variable initialization) form a core of properties which are essential for high-assurance software. Here we describe the AutoFilter system and its certificate generator and compare our approach to the static analysis tool PolySpace.

Denney, Ewen↗

Sextant Navigation on the International Space Station: A Human Space Exploration Demo

Astronauts on board the International Space Station (ISS) tested a hand-held sextant to demonstrate potential use on future human exploration missions such as Orion and Gateway. The investigation, designed to aid in the development of emergency navigation methods for future crewed spacecraft, took place from June-December 2018. A sextant provides manual capability to perform star/planet-limb sightings and estimate vehicle state during loss of communication or other contingencies. Its simplicity and independence from primary systems make it useful as an emergency survival backup or confirming measurement source. The concept of using a sextant has heritage in Gemini, Apollo, and Skylab. This paper discusses the instrument selection, flight certification, crew training, product development, experiment execution, and data analysis. Preflight training consisted of a hands-on session with the instrument and practice in a Cupola mock-up with star field projector dome. The experiment itself consisted of several sessions with sextant sightings in the ISS Cupola module by two crew members. Sightings were taken on star pairs, star/moon limb, and moon diameter. The sessions were designed to demonstrate star identification and acquisition, sighting stability, accuracy, and lunar sights. Results are presented which demonstrate sightings within the accuracy goal of 60 arcseconds, even in the presence of window refraction effects and minimal crew training. The crew members provided valuable feedback on sighting products and microgravity stability techniques.

Exploration↗

Nearfield Summary and Analysis of the Third AIAA Sonic Boom Prediction Workshop C608 Low Boom Demonstrator

A summary and statistical analysis of the nearfield Computational Fluid Dynamics (CFD)submissions for the Third AIAA Sonic Boom Prediction Workshop is provided with a focus onthe C608 Low Boom Flight Test Demonstrator. The C608 is more complex in terms of geometryand propulsion boundary conditions than previous workshop cases and is more representativeof vehicles with lower ground loudness and the potential for lower annoyance. The nearfieldsignatures submitted by the participants are propagated to the ground to compute statisticsof loudness measures over the vehicle sonic boom carpet. Principle component analysis isused to extract the primary variation modes. Context from previous sonic boom workshopsindicates that this workshop has the lowest variation even though the case is more challengingbecause it is quieter and more complex. The results documented in this summary indicate thatthe international state-of-the-art for nearfield CFD has a variation that is small enough formeaningful low-boom design and analysis. Low-boom configuration analysis methods with lowvariation are important tools to develop certification processes for addressing the prohibitionon overland supersonic commercial flight.

sonic boom CFD workshop c608↗

The Test Analysis Retrieval System (TARS): Meeting the challenges of the network's test processes

The Networks Systems Test Section (GSFC 531.4) is responsible for managing a variety of engineering and operational tests used to assess the status of the Network elements relative to readiness certification for new and ongoing mission support and for performance trending. To conduct analysis of data collected during these tests, to disseminate and share the information, and to catalog and create reports based on the analysis is currently a cumbersome and inefficient task due primarily to the manual handling of paper products and the inability to easily exchange information between the various Networks elements. The Test Analysis and Retrieval System (TARS) is being implemented to promote concise data analysis, intelligible reporting of test results, to minimize test duplication by fostering a broad sharing of test data, and perhaps most importantly, to provide significantly improved response to the Network's internal and external customers. This paper outlines the intended application, architecture, and benefits of the TARS.

Stelmaszek, Robert L.↗

Preparing GMAT for Operational Maneuver Planning of the Advanced Composition Explorer (ACE)

The General Mission Analysis Tool (GMAT) is an open-source space mission design, analysis and trajectory optimization tool. GMAT is developed by a team of NASA, private industry, public and private contributors. GMAT is designed to model, optimize and estimate spacecraft trajectories in flight regimes ranging from low Earth orbit to lunar applications, interplanetary trajectories and other deep space missions. GMAT has also been flight qualified to support operational maneuver planning for the Advanced Composition Explorer (ACE) mission. ACE was launched in August, 1997 and is orbiting the Sun-Earth L1 libration point. The primary science objective of ACE is to study the composition of both the solar wind and the galactic cosmic rays. Operational orbit determination, maneuver operations and product generation for ACE are conducted by NASA Goddard Space Flight Center (GSFC) Flight Dynamics Facility (FDF). This paper discusses the entire engineering lifecycle and major operational certification milestones that GMAT successfully completed to obtain operational certification for the ACE mission. Operational certification milestones such as gathering of the requirements for ACE operational maneuver planning, gap analysis, test plans and procedures development, system design, pre-shadow operations, training to FDF ACE maneuver planners, shadow operations, Test Readiness Review (TRR) and finally Operational Readiness Review (ORR) are discussed. These efforts have demonstrated that GMAT is flight quality software ready to support ACE mission operations in the FDF.

Trajectory analysis↗

L(sub 1) Adaptive Flight Control System: Flight Evaluation and Technology Transition

Certification of adaptive control technologies for both manned and unmanned aircraft represent a major challenge for current Verification and Validation techniques. A (missing) key step towards flight certification of adaptive flight control systems is the definition and development of analysis tools and methods to support Verification and Validation for nonlinear systems, similar to the procedures currently used for linear systems. In this paper, we describe and demonstrate the advantages of L(sub l) adaptive control architectures for closing some of the gaps in certification of adaptive flight control systems, which may facilitate the transition of adaptive control into military and commercial aerospace applications. As illustrative examples, we present the results of a piloted simulation evaluation on the NASA AirSTAR flight test vehicle, and results of an extensive flight test program conducted by the Naval Postgraduate School to demonstrate the advantages of L(sub l) adaptive control as a verifiable robust adaptive flight control system.

Xargay, Enric↗

Conversion-Integration of MSFC Nonlinear Signal Diagnostic Analysis Algorithms for Realtime Execution of MSFC's MPP Prototype System

NASA's advanced propulsion system Small Scale Magnetic Disturbances/Advanced Technology Development (SSME/ATD) has been undergoing extensive flight certification and developmental testing, which involves large numbers of health monitoring measurements. To enhance engine safety and reliability, detailed analysis and evaluation of the measurement signals are mandatory to assess its dynamic characteristics and operational condition. Efficient and reliable signal detection techniques will reduce the risk of catastrophic system failures and expedite the evaluation of both flight and ground test data, and thereby reduce launch turn-around time. During the development of SSME, ASRI participated in the research and development of several advanced non- linear signal diagnostic methods for health monitoring and failure prediction in turbomachinery components. However, due to the intensive computational requirement associated with such advanced analysis tasks, current SSME dynamic data analysis and diagnostic evaluation is performed off-line following flight or ground test with a typical diagnostic turnaround time of one to two days. The objective of MSFC's MPP Prototype System is to eliminate such 'diagnostic lag time' by achieving signal processing and analysis in real-time. Such an on-line diagnostic system can provide sufficient lead time to initiate corrective action and also to enable efficient scheduling of inspection, maintenance and repair activities. The major objective of this project was to convert and implement a number of advanced nonlinear diagnostic DSP algorithms in a format consistent with that required for integration into the Vanderbilt Multigraph Architecture (MGA) Model Based Programming environment. This effort will allow the real-time execution of these algorithms using the MSFC MPP Prototype System. ASRI has completed the software conversion and integration of a sequence of nonlinear signal analysis techniques specified in the SOW for real-time execution on MSFC's MPP Prototype. This report documents and summarizes the results of the contract tasks; provides the complete computer source code; including all FORTRAN/C Utilities; and all other utilities/supporting software libraries that are required for operation.

Jong, Jen-Yi↗

Shock response spectra variational analysis for pyrotechnic qualification testing of flight hardware

Shock response spectra data from flight certification tests were analyzed to determine envelope variation with respect to mean values in each axis. An overall variation of + or - 8.61 dB or 169 percent exists for the data. This large variation may be attributed to one or more of the following: (1) Instrumentation problems may exist. (2) Variations in the source charge (blasting caps) such as shape or explosive load may exist. (3) Two blasting caps were used to excite the pyrotechnic plate tester. Delay time between charge firings may have varied. The cause or causes of the variations need to be identified and researched to prevent future pyroshock problems.

Smith, J. L.↗

Safety Assessment of a Machine Learning-Based Aircraft Emergency Braking System: A Case Study

Machine Learning (ML) is revolutionizing many technological fields, but its use in aviation remains restricted due to stringent certification requirements. Efforts by the aviation community to establish standards for certifying ML-based systems are progressing, yet challenges persist, particularly with safety assessment methods for ML-based systems. This research addresses these challenges through a case study of an autonomous emergency braking system utilizing a computer vision deep neural network (DNN). We demonstrate a safety assessment process tailored to ML-specific concerns, such as low integrity and performance variability in quantitative safety analysis. This study can serve as an illustrative example to facilitate the discussion and convergence on certification aspects for ML-based systems within the aviation community.

Safety certification↗

An experimental evaluation of software redundancy as a strategy for improving reliability

The strategy of using multiple versions of independently developed software as a means to tolerate residual software design faults is suggested by the success of hardware redundancy for tolerating hardware failures. Although, as generally accepted, the independence of hardware failures resulting from physical wearout can lead to substantial increases in reliability for redundant hardware structures, a similar conclusion is not immediate for software. The degree to which design faults are manifested as independent failures determines the effectiveness of redundancy as a method for improving software reliability. Interest in multi-version software centers on whether it provides an adequate measure of increased reliability to warrant its use in critical applications. The effectiveness of multi-version software is studied by comparing estimates of the failure probabilities of these systems with the failure probabilities of single versions. The estimates are obtained under a model of dependent failures and compared with estimates obtained when failures are assumed to be independent. The experimental results are based on twenty versions of an aerospace application developed and certified by sixty programmers from four universities. Descriptions of the application, development and certification processes, and operational evaluation are given together with an analysis of the twenty versions.

Eckhardt, Dave E., Jr.↗

An experimental evaluation of software redundancy as a strategy for improving reliability

The strategy of using multiple versions of independently developed software as a means to tolerate residual software design faults is suggested by the success of hardware redundancy for tolerating hardware failires. Although, as generally accepted, the independence of hardware failures resulting from physical wearout can lead to substantial increases in reliability for redundant hardware structures, a similar conclusion is not immediate for software. The degree to which design faults are manifested as independent failures determines the effectiveness of redundancy as a method for improving software reliability. Interest in multi-version software centers on whether it provides an adequate measure of increased reliability to warrant its use in critical applications. The effectiveness of multi-version software is studied by comparing estimates of the failure probabilities of these systems with the failure probabilities of single versions. The estimates are obtained under a model of dependent failures and compared with the estimates obtained when failures are assumed to be independent. The experimental results are based on twenty versions of an aerospace application developed and certified by sixty programmers from four universities. Descriptions of the application, development and certifications processes, and operational evaluation are given together with an analysis of the twenty versions.

Eckhardt, Dave E.↗

Handling Qualities Flight Testing of the Stratospheric Observatory for Infrared Astronomy (SOFIA)

Airborne infrared astronomy has a long successful history, albeit relatively unknown outside of the astronomy community. A major problem with ground based infrared astronomy is the absorption and scatter of infrared energy by water in the atmosphere. Observing the universe from above 40,000 ft puts the observation platform above 99% of the water vapor in the atmosphere, thereby addressing this problem at a fraction of the cost of space based systems. The Stratospheric Observatory For Infrared Astronomy (SOFIA) aircraft is the most ambitious foray into the field of airborne infrared astronomy in history. Using a 747SP (The Boeing Company, Chicago, Illinois) aircraft modified with a 2.5m telescope located in the aft section of the fuselage, the SOFIA endeavors to provide views of the universe never before possible and at a fraction of the cost of space based systems. The modification to the airplane includes moveable doors and aperture that expose the telescope assembly. The telescope assembly is aimed and stabilized using a multitude of on board systems. This modification has the potential to cause aerodynamic anomalies that could induce undesired forces either at the cavity itself or indirectly due to interference with the empennage, both of which could cause handling qualities issues. As a result, an extensive analysis and flight test program was conducted from December 2009 through March 2011. Several methods, including a Lower Order Equivalent Systems analysis and pilot assessment, were used to ascertain the effects of the modification. The SOFIA modification was found to cause no adverse handling qualities effects and the aircraft was cleared for operational use. This paper discusses the history and modification to the aircraft, development of test procedures and analysis, results of testing and analysis, lessons learned for future projects and justification for operational certification.

Glaser, Scott T.↗