Search NASA⌕ Search

SEARCH · Search NASA

Results for “prototyped verification system”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 127 records · Page 7

Air-liquid solar collector for solar heating, combined heating and cooling, and hot water subsystems

A collection of quarterly reports consisting of the installation and layout design of the air collector system for commercial applications, completion of the preliminary design review, detailed design efforts, and preparation of the verification test plan are given. Performance specifications and performance testing of a prototype model of a two manifold, 144 tube air collector array is presented.

Source record↗

Preliminary Application of Formal Verification to An Autonomy Architecture for Unmanned Aircraft

There is a desire to design autonomous systems in such a way that capabilities can be easily added or re- combined to produce new behaviors while preserving their safety properties. ICAROUS, a prototype software architecture for building safety-centric autonomous unmanned aircraft applications, is designed to support this type of extensibility and re-configurability. In ICAROUS, core capabilities are implemented as individual soft- ware services, so that enabling access to new capabilities simply requires adding new services. To make use of these capabilities, ICAROUS includes a specialized service that provides a general framework for config- uring the relative priorities, conditions, and rules that govern how different modules should be engaged and disengaged during flight. The inherent complexity of coordinating multiple modules under changing conditions makes it difficult to determine whether a particular configuration could have erroneous behaviors in certain circumstances. A robust set of integration tests can help discover errors, but testing can only realistically cover a relatively small proportion of total system behaviors. Developing good tests and interpreting the results to pinpoint the cause of errors when they arise can also be very time-consuming. To supplement testing, formal methods can be used to model and analyze complex systems, achieving better coverage and simplifying the process of finding, understanding, and fixing errors. To demonstrate these benefits, this paper explores the ap- plication of formal methods to ICAROUS. In particular, the Spin model checker is used to specify requirements for and model portions of the system, then verify whether the model satisfies the requirements and find and fix errors when it does not.

Formal Methods↗

GPS and Galileo Developments on Board the International Space Station With the Space Communications and Navigation (SCaN) Testbed

The Space Communications and Navigation (SCaN) is a facility developed by NASA and hosted on board the International Space Station (ISS) on an external truss since 2013.It has the objective of testing navigation and communication experimentations with a Software Defined Radio (SDR) approach, which permits software updates for testing new experimentations.NASA has developed the Space Telecommunications Radio System (STRS) architecture standard for SDRs used in space and ground-based platforms to provide commonality among radio developments to provide enhanced capability. The hardware is equipped with both L band front-end radios and the NASA space network communicates with it using S-band, Ku-band and Ka-band links.In May 2016 Qascom started GARISS (GPS and Galileo Receiver for the ISS), an activity of experimentation in collaboration with ESA and NASA that has the objective to develop and validate the acquisition and processing of combined GPS and Galileo signals on board the ISS SCaN testbed. This paper has the objective to present the mission, and provide preliminary details about the challenges in the design, development and verification of the waveform that will be installed on equipment with limited resources. GARISS is also the first attempt to develop a waveform for the ISS as part of an international collaboration between US and Europe. Although the final mission objective is to target dual frequency processing, initial operations will foresee a single frequency processing. Initial results and trade-off between the two options, as well as the final decision will be presented and discussed. The limited resources on board the SCaN with respect to the challenging requirements to acquire and track contemporaneously two satellite navigation systems, with different modulations and data structure, led to the need to assess the possibility of aiding from ground through the S-band. This option would allow assistance to the space receiver in order to provide knowledge of GNSS orbits and reduce the processing on board. Trade off and various options for telemetry and uplink data are presented and discussed. Finally, integration and validation of the waveform are one of the major challenges of GARISS: The Experiment Development System (EDS) and the the Ground Integration Unit (GIU) for VV will be used prior to conducting the experiment on the ISS. The EDS can be used in lab environment and allows prototyping and verification activities with the simulator, but does not include all hardware components. The GIU on the other side is the flight model which replicates the flying equipment, but has limited flexibility for testing.As conclusion, the project is now approaching the Preliminary Design Review (PDR) and indeed only preliminary results are available. This paper is an opportunity to present the GARISS mission as part of an International cooperation between ESA, NASA and Qascom. The preliminary results include GPS and Galileo processing from space signals, the challenges and trade off decisions, the high level STRS architecture and foreseen experimentation campaign. Detailed results from the test campaigns are expected in 2017.

space navigation↗

Preliminary Application of Formal Verification to An Autonomy Architecture for Unmanned Aircraft

There is a desire to design autonomous systems in such a way that capabilities can be easily added or re-combined to produce new behaviors while preserving their safety properties. ICAROUS, a prototype software architecture for building safety-centric autonomous unmanned aircraft applications, is designed to support this type of extensibility and re-configurability. In ICAROUS, core capabilities are implemented as individual soft- ware services, so that enabling access to new capabilities simply requires adding new services. To make use of these capabilities, ICAROUS includes a specialized service that provides a general framework for config- uring the relative priorities, conditions, and rules that govern how different modules should be engaged and disengaged during flight. The inherent complexity of coordinating multiple modules under changing conditions makes it difficult to determine whether a particular configuration could have erroneous behaviors in certain circumstances. A robust set of integration tests can help discover errors, but testing can only realistically cover a relatively small proportion of total system behaviors. Developing good tests and interpreting the results to pinpoint the cause of errors when they arise can also be very time-consuming. To supplement testing, formal methods can be used to model and analyze complex systems, achieving better coverage and simplifying the process of finding, understanding, and fixing errors. To demonstrate these benefits, this paper explores the ap- plication of formal methods to ICAROUS. In particular, the Spin model checker is used to specify requirements for and model portions of the system, then verify whether the model satisfies the requirements and find and fix errors when it does not.

Formal Methods↗

SAFE50 Reference Design Study for Large-Scale High-Density Low-Altitude UAS Operations in Urban Areas

Enabling safe, routine, and high-density flight operations of small UAS at low-altitude over heavily populated urban centers presents a difficult challenge for emerging UAS Traffic Management (UTM) system concepts. Urban operations by definition involve flight over people, property, and infrastructure. Low-altitude urban environments - such as urban canyons – are one of the most difficult areas for UTM to consider. Mission concepts require routine operations in a cluttered radio-frequency (RF) environment with degraded or denied Global Positioning System (GPS) reception. Flights with any appreciable distance will be beyond visual and communications line-of-sight from ground operators. Timely detection and response to emergencies and onboard failures, which is critical for safe aircraft operation, will be difficult. This work seeks to establish a feasible reference autonomy architecture for autonomous vehicles in an urban UTM system, then verifying and validating this architecture within a complete UTM concept point-design and systems analysis study. In this paper, we present the results from the NASA SAFE50 conceptual design and systems study that investigates the trade-space of urban UTM operations. This advanced conceptual design study develops a feasible, verified, validated point-design solution. The SAFE50 point-design concept places emphasis on advanced, highly-autonomous, and highly-capable vehicles that favors intelligent onboard autonomy over direct human control with today's technologies and operating in today's urban environments. This paper focuses on an general overview of the design study, highlighting decisions made in the architectural solution. This paper will presents a summary of the study, architectures, and requirements. We present an overview of the architecture designs as derived from the top-level UTM system. The point-design has been implemented in both simulation and through flight testing of hardware design prototypes. The results from simulation and flight testing as part of the verification and validation process of the reference design study.

Ippolito, Corey A.↗

Validating Protection System Behavior with Machine Learning in a Master State Overseer

As power system protection devices continue the widespread transition from analog to digital, they become increasingly intricate. The internal functions and communication between critical grid components must now be significantly more complex to keep up with the demands of the modern smart grid. This brings increased difficulty in maintenance and monitoring, making it harder to identify potential misoperation, power anomalies, and cyber threats. Such issues are often only pinpointed after an exhaustive and costly post-mortem analysis, when a major outage or damage has already occurred. A solution is needed for validating protection systems as they operate, independently evaluating grid state and confirming whether the protection system is behaving accordingly. As opposed to incident response, this acts as a constant verification mechanism that raises a flag when subtler issues are noticed, catching them earlier and preventing larger incidents. This work presents the implementation of such a system, expanding on the prototype developed by the authors in a previous paper. This is accomplished with a machine learning (ML) system capable of validating the performance of protection systems by classifying anomalous events and characterizing protection system responses based solely on available current and voltage measurements. Additionally, this system is contextualized within a larger, modular Master State awareness Overseer (MSO) framework, responsible for monitoring, analyzing, and managing an electric grid.

24 - POWER TRANSMISSION AND DISTRIBUTION↗

Preliminary design review package on air flat plate collector for solar heating and cooling system

Guidelines to be used in the development and fabrication of a prototype air flat plate collector subsystem containing 320 square feet (10-4 ft x 8 ft panels) of collector area are presented. Topics discussed include: (1) verification plan; (2) thermal analysis; (3) safety hazard analysis; (4) drawing list; (5) special handling, installation and maintenance tools; (6) structural analysis; and (7) selected drawings.

Source record↗

A Low Temperature, Reverse Brayton Cryocooler

This status report covers the fifty-second month of a project to develop a low temperature, reverse-Brayton cryocooler using turbomachines. This program consists of a Basic Phase and four Option Phases. Each of the Phases is directed to a particular load/temperature combination. The technology and fundamental design features of the components used in these systems are related but differ somewhat in size, speed, and some details in physical geometry. Each of the Phases can be carried out independently of the others, except that all of the Phases rely on the technology developed and demonstrated during the Basic Phase. The Basic Phase includes the demonstration of a critical component and the production of a prototype model cryocooler. The critical technology demonstration will be the test of a small turboalternator over a range of conditions at temperatures down to 6 K. These tests will provide design verification data useful for the further design of the other coolers. The prototype model cooler will be designed to provide at least 5 mW of cooling at 6 K. The heat rejection temperature for this requirement is 220 K or greater. The input power to the system at these conditions is to be less than 60 W.

Swift, Walter L.↗

Orion Crew Module Landing System Simulation and Verification

NASA Langley Research Center (LaRC) has developed a comprehensive test and analysis program to evaluate the ability of LS-DYNA to model the materials and the phenomena involved in soil and water landing impacts of the Orion crew module. Elemental, scale boilerplate, and full-scale prototype testing is being conducted in support of the simulation verification and validation approach. Aspects of the simulations evaluated against test data include soil constitutive properties, water equations of state, and contact algorithms. Subsystems tested include airbags, crushable energy absorbing honeycomb materials, and energy absorbing seat support struts. The procedures, instrumentation, and general observations from each test series are presented. Plans for a series of swing tests of a full-scale boilerplate into a purpose-built water basin are described. Further plans for swing tests of flight-like prototypes into the water basin are noted.

Vassilakos, Gregory J.↗

RESOLVE Projects: Lunar Water Resource Demonstration and Regolith Volatile Characterization

To sustain affordable human and robotic space exploration, the ability to live off the land at the exploration site will be essential. NASA calls this ability in situ resource utilization (ISRU) and is focusing on finding ways to sustain missions first on the Moon and then on Mars. The ISRU project aims to develop capabilities to technology readiness level 6 for the Robotic Lunar Exploration Program and early human missions returning to the Moon. NASA is concentrating on three primary areas of ISRU: (1) excavating, handling, and moving lunar regolith, (2) extracting oxygen from lunar regolith, and (3) finding, characterizing, extracting, separating, and storing volatile lunar resources, especially in the permanently shadowed polar craters. To meet the challenges related to technology development for these three primary focus areas, the Regolith and Environment Science and Oxygen and Lunar Volatile Extraction (RESOLVE) project was initiated in February 2005, through funding by the Exploration Systems Mission Directorate. RESOLVE's objectives are to develop requirements and conceptual designs and to perform breadboard concept verification testing of each experiment module. The final goal is to deliver a flight prototype unit that has been tested in a relevant lunar polar environment. Here we report progress toward the third primary area creating ways to find, characterize, extract, separate, and store volatile lunar resources. The tasks include studying thermal, chemical, and electrical ways to collect such volatile resources as hydrogen, water, nitrogen, methane, and ammonia. We approached this effort through two subtasks: lunar water resource demonstration (LWRD) and regolith volatile characterization (RVC).

Source record↗

Comparison of ISRU Excavation System Model Blade Force Methodology and Experimental Results

An Excavation System Model has been written to simulate the collection and transportation of regolith on the Moon. The calculations in this model include an estimation of the forces on the digging tool as a result of excavation into the regolith. Verification testing has been performed and the forces recorded from this testing were compared to the calculated theoretical data. A prototype lunar vehicle built at the NASA Johnson Space Center (JSC) was tested with a bulldozer type blade developed at the NASA Kennedy Space Center (KSC) attached to the front. This is the initial correlation of actual field test data to the blade forces calculated by the Excavation System Model and the test data followed similar trends with the predicted values. This testing occurred in soils developed at the NASA Glenn Research Center (GRC) which are a mixture of different types of sands and whose soil properties have been well characterized. Three separate analytical models are compared to the test data.

Gallo, Christopher A.↗

Flight Testing ALHAT Precision Landing Technologies Integrated Onboard the Morpheus Rocket Vehicle

A suite of prototype sensors, software, and avionics developed within the NASA Autonomous precision Landing and Hazard Avoidance Technology (ALHAT) project were terrestrially demonstrated onboard the NASA Morpheus rocket-propelled Vertical Testbed (VTB) in 2014. The sensors included a LIDAR-based Hazard Detection System (HDS), a Navigation Doppler LIDAR (NDL) velocimeter, and a long-range Laser Altimeter (LAlt) that enable autonomous and safe precision landing of robotic or human vehicles on solid solar system bodies under varying terrain lighting conditions. The flight test campaign with the Morpheus vehicle involved a detailed integration and functional verification process, followed by tether testing and six successful free flights, including one night flight. The ALHAT sensor measurements were integrated into a common navigation solution through a specialized ALHAT Navigation filter that was employed in closed-loop flight testing within the Morpheus Guidance, Navigation and Control (GN&C) subsystem. Flight testing on Morpheus utilized ALHAT for safe landing site identification and ranking, followed by precise surface-relative navigation to the selected landing site. The successful autonomous, closed-loop flight demonstrations of the prototype ALHAT system have laid the foundation for the infusion of safe, precision landing capabilities into future planetary exploration missions.

Carson, John M. III↗

The Environmental Control and Life Support System (ECLSS) advanced automation project

The objective of the environmental control and life support system (ECLSS) Advanced Automation Project is to influence the design of the initial and evolutionary Space Station Freedom Program (SSFP) ECLSS toward a man-made closed environment in which minimal flight and ground manpower is needed. Another objective includes capturing ECLSS design and development knowledge future missions. Our approach has been to (1) analyze the SSFP ECLSS, (2) envision as our goal a fully automated evolutionary environmental control system - an augmentation of the baseline, and (3) document the advanced software systems, hooks, and scars which will be necessary to achieve this goal. From this analysis, prototype software is being developed, and will be tested using air and water recovery simulations and hardware subsystems. In addition, the advanced software is being designed, developed, and tested using automation software management plan and lifecycle tools. Automated knowledge acquisition, engineering, verification and testing tools are being used to develop the software. In this way, we can capture ECLSS development knowledge for future use develop more robust and complex software, provide feedback to the knowledge based system tool community, and ensure proper visibility of our efforts.

Dewberry, Brandon S.↗

Certification Considerations for Adaptive Stress Testing of Airborne Software

eduAdaptive Stress Testing (AST) has shown promise in identifying errant corner cases in complex software used in aerospace applications including Flight Management Systems (FMS). The strength of AST is performing test-based verification of complex aerospace software intensive systems at scale in simulated operational environments.Simulating and capturing the realistic operational complexities in integrated verification environments may exposeflaws in the softwareprior to field deployment, whereas the software may perform just fine to traditional requirements-basedunit and component level testing.AST can be used to test the whole system.Individual components may behave safely, but together can result in complex interactions and emergent failures, so it is important to test at the integrated system level.Motivated by the observed benefitsat the prototype proof of concept scale, this paper considers how AST may be integrated into a production workflow and used to generate objective evidence in a processthat delivers certified aerospace software.The research includes evaluation of alignment with both DO-178C and Overarching Properties(OP). The paper addresses questions such as “where should AST fit in the Plan for Software Aspects of Certification (PSAC) and Software Verification Plan (SVP), what aspects of AST do not fit, and what objectives does it satisfy?” The paper concludes that AST is in fact useful at locating errors in complex airborne application software and in doing so provides benefits to suppliers and end users. Furthermore, AST appears appropriate to add value in both DO-178Cbased and Overarching Properties based certification approaches.

certification↗

Synthesis of Correct Digital Controller Models from Specifications by Model Transformation (21-0320)

The design of high consequence controllers (in weapons systems, autonomy, etc.) that do what they are supposed to do is a significant challenge. Testing simply does not come close to meeting the requirements for assurance. Today circuit designers at Sandia (and elsewhere) typically capture the core behavior of their components using state models in tools such as STATEFLOW. They then check that their models meet certain requirements (e.g. “The system bus must not deadlock” or “both traffic lights at an intersection must not be green at the same time”) using tools called model checkers. If the model checker returns “yes” then the property is guaranteed to be satisfied by the model. However, there are several drawbacks to this industry practice: (1) there is a lot of detail to get right, this is particularly challenging when there are multiple components requiring complex coordination (2) any errors returned by the model checker have to be traced back through the design and fixed, necessitating rework, (3) there are severe scalability problems with this approach, particularly when dealing with concurrency. All this places high demands on the designers who now face not only an accelerated schedule but also controllers of increasing complexity. This report describes a new and fundamentally different approach to the construction of safety-critical digital controllers. Instead of directly constructing a complete model and then trying to verify it, the designer can start with an initial abstract (think “sketch”) model plus the requirements, from which a correct concrete model is automatically synthesized. There is no need for post-hoc verification of required functional properties. Having tool to carry this out will significantly impact the nation’s ability to ensure the safety of high-consequence digital systems. The approach has been implemented in a prototype tool, along with a suite of examples, including ones that reflect actual problems faced by designers. Our approach operates on a variant of Statecharts developed at Sandia called Qspecs. Statecharts are a widely used formalism for developing concurrent reactive systems, supporting scalability through allowing state models containing composite states, which are the serial or parallel composition of substates which can themselves contain statecharts. Statecharts enable an incremental style of development, in which states are progressively refined to incorporate greater detail in an incremental model of software development. Our approach formulates a set of constraints from the structure of the models and the requirements and propagates these constraints to a fixpoint. The solution to the constraints is an inductive invariant along with guards on the transitions. We also show how our approach extends to implementation refinement, decomposition, composition, and elaboration. We currently handle safety requirements written in LTL (Linear Temporal Logic)

42 ENGINEERING↗

NASA Ames Research Center R and D Services Directorate Biomedical Systems Development

The Ames Research Center R&D Services Directorate teams with NASA, other government agencies and/or industry investigators for the development, design, fabrication, manufacturing and qualification testing of space-flight and ground-based experiment hardware for biomedical and general aerospace applications. In recent years, biomedical research hardware and software has been developed to support space-flight and ground-based experiment needs including the E 132 Biotelemetry system for the Research Animal Holding Facility (RAHF), E 100 Neurolab neuro-vestibular investigation systems, the Autogenic Feedback Systems, and the Standard Interface Glove Box (SIGB) experiment workstation module. Centrifuges, motion simulators, habitat design, environmental control systems, and other unique experiment modules and fixtures have also been developed. A discussion of engineered systems and capabilities will be provided to promote understanding of possibilities for future system designs in biomedical applications. In addition, an overview of existing engineered products will be shown. Examples of hardware and literature that demonstrate the organization's capabilities will be displayed. The Ames Research Center R&D Services Directorate is available to support the development of new hardware and software systems or adaptation of existing systems to meet the needs of academic, commercial/industrial, and government research requirements. The Ames R&D Services Directorate can provide specialized support for: System concept definition and feasibility Mathematical modeling and simulation of system performance Prototype hardware development Hardware and software design Data acquisition systems Graphical user interface development Motion control design Hardware fabrication and high-fidelity machining Composite materials development and application design Electronic/electrical system design and fabrication System performance verification testing and qualification.

Pollitt, J.↗

Exploration Exercise System (EES) Development

Exploration class missions will be required to have an exercise device that is lightweight, has a small footprint, and is capable of providing enough physical stimulus and exercise variability to be an effective countermeasure against muscle and bone loss that results from the microgravity environment. Exploration exercise device prototypes should be evaluated on the ground and in-orbit for feasibility of use in microgravity for long and short duration exploration missions and efficacy of the device to maintain multi-system health and performance. The European Enhanced Exploration Exercise Device (E4D) was selected as the exploration prototype device to be evaluated on ISS for efficacy and feasibility of use as a single multi-modality device for the exercise system for exploration missions. This effort supports the continued development, testing, and verification of E4D hardware and software, internal NASA integration (Human Health and Performance, ISS Vehicle Office, Engineering, and Flight Operations), and external integration across NASA, ESA, and the Danish Aerospace Company (DAC). Providing a feasibility and acceptability assessment from a physiological efficacy and hardware durability standpoint are critical for informing use and risk associated with use on exploration missions. Clearly defined objectives from end users, stakeholders, and Subject Matter Experts (SMEs) will be tested by crewmembers during acute use sessions and long duration use of the exercise device while on ISS. This effort will include a flight study where crewmembers will be asked to exercise using only the E4D during the duration of their mission and participate in a battery of physiological testing to evaluate the efficacy. Hardware is scheduled to launch in FY25 followed by 2 years of operational use after activation and checkout. A final recommendation will be provided to the Artemis program on acceptability of the device for exploration missions. The E4D needs a vibration isolation stabilization (VIS) system that serves as a platform for the exercise hardware to protect the vehicle from loads imparted during exercise. Exploration forward VIS systems will need to protect the vehicle and provide sufficient stabilization for the exerciser during performance of all critical exercises. These enabling capabilities need to be achieved within exploration vehicle power, thermal, mass, and volume limitations.

Kent Lawrence Kalogera↗

System design package for IBM system one: solar heating and domestic hot water

This report is a collation of documents and drawings that describe a prototype solar heating and hot water system using air as the collector fluid and a pebble bed for heat storage. The system was designed for installation into a single family dwelling. The description, performance specification, subsystem drawings, verification plan/procedure, and hazard analysis of the system was packaged for evaluation of the system with information sufficient to assemble a similar system.

Source record↗