Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 145 records · Page 8

Design of a modular digital computer system DRL 4 and 5

Design and development efforts for a spaceborne modular computer system are reported. An initial baseline description is followed by an interface design that includes definition of the overall system response to all classes of failure. Final versions for the register level designs for all module types were completed. Packaging, support and control executive software, including memory utilization estimates and design verification plan, were formalized to insure a soundly integrated design of the digital computer system.

Source record↗

Reliability Quantification of Advanced Stirling Convertor (ASC) Components

The Advanced Stirling Convertor, is intended to provide power for an unmanned planetary spacecraft and has an operational life requirement of 17 years. Over this 17 year mission, the ASC must provide power with desired performance and efficiency and require no corrective maintenance. Reliability demonstration testing for the ASC was found to be very limited due to schedule and resource constraints. Reliability demonstration must involve the application of analysis, system and component level testing, and simulation models, taken collectively. Therefore, computer simulation with limited test data verification is a viable approach to assess the reliability of ASC components. This approach is based on physics-of-failure mechanisms and involves the relationship among the design variables based on physics, mechanics, material behavior models, interaction of different components and their respective disciplines such as structures, materials, fluid, thermal, mechanical, electrical, etc. In addition, these models are based on the available test data, which can be updated, and analysis refined as more data and information becomes available. The failure mechanisms and causes of failure are included in the analysis, especially in light of the new information, in order to develop guidelines to improve design reliability and better operating controls to reduce the probability of failure. Quantified reliability assessment based on fundamental physical behavior of components and their relationship with other components has demonstrated itself to be a superior technique to conventional reliability approaches based on utilizing failure rates derived from similar equipment or simply expert judgment.

Shah, Ashwin R.↗

Looking to the Future: A Call to Action for Advanced GNC Algorithm Verification and Validation

Future space systems will rely on autonomous Guidance, Navigation, and Control (GNC) functions to efficiently manage safe and precise self-directed operations in uncertain complex environments. Fundamentally, the GNC system plays a key role in mission performance and safety because it computes the ideal trajectory (Guidance), determines the actual trajectory (Navigation), and executes the ideal trajectory (Control) of a vehicle’s position and attitude. Our current GNC systems are highly automated and already have a high degree of complexity. As missions become more ambitious, GNC systems for launch vehicles and space platforms (e.g., spacecraft, probes, and landers) will require higher levels of performance and autonomous operation than previously encountered, for example, this includes GNC for optimizing aerodynamic and/or propulsion performance during planetary entry. This GNC Verification and Validation (V&V) paper highlights concerns with what undoubtedly will be a trend towards increased complexity as fully autonomous GNC systems are developed for future space missions. Clearly, complex GNC systems pose challenges in the prelaunch V&V phase, which is a relatively expensive part of a mission’s life cycle. Essentially the V&V phase is focused on checking that the system effectively meets all the design and operational requirements for the mission. The authors of this paper (i.e., the Inter-Agency Working Group of GNC subject matter experts) focused on this fundamental question over the past few years: Will the GNC engineering community of practice be sufficiently prepared to perform the necessary V&V on evolving GNC architectures that are driven by very demanding requirements for autonomy, resiliency, reconfigurability, adaptability, and mission cost-benefit balance? It is the viewpoint of our Inter-Agency team that the GNC V&V approaches and processes needed to address the next generation of complex GNC systems, which likely will employ various forms of modern GNC technology, are not currently established to the level the community will need in the future. While researchers and practitioners have made some progress in developing new GNC V&V methods for modern GNC systems, a good deal of work remains to be done to codify such methods in a comprehensive and systematic manner. Thus, the Inter-Agency team’s partner organizations [the National Aeronautics and Space Administration (NASA), the European Space Agency (ESA), the National Centre for Space Studies (CNES), the German Aerospace Center (DLR), the French Aerospace Lab (ONERA), and ISAE-SUPAERO] have conducted preliminary investigations into advancing GNC V&V techniques, which resulted in the identification of the need for education, new V&V tools, and benchmark problems for the GNC community. The necessary proactive steps to be taken to meet the challenges and fill the gaps in GNC V&V are summarized in this paper. The first steps include identifying advanced analysis tools, developing a GNC V&V roadmap, and expanding education and training programs for GNC practitioners. This paper is a call to action and proposes a comprehensive set of recommended actions for all our stakeholders: space agencies, researchers, and industry.

Samir Bennani↗

System test approach for the SAX satellite

SAX satellite verification is based on a protoflight approach, in which only one system model is realized at flight standard level, taking into account the utilization of hardware already qualified for other space programs and the necessity to respect the schedule constraints for a scientific objective. In any case, this approach was tailored with some deviations in order to reduce risks inherent in such a choice. The protoflight approach was also pursued at subsystem/unit level in particular for those subsystems and units considered critical from the schedule point of view. Payload Instruments followed the same approach but complete spare units were developed to reduce the risks associated with such an approach. A description of the model philosophy is provided and then, at satellite level, the testing approach and rationale for each model is presented. Finally, a brief description of each test will be given, highlighting objectives, methodologies, and test configurations. Moreover, for the major tests, problems encountered and solutions applied in establishing a correct approach are described.

Giordano, Pietro↗

Automated Storm Tracking and the Lightning Jump Algorithm Using GOES-R Geostationary Lightning Mapper (GLM) Proxy Data

This study develops a fully automated lightning jump system encompassing objective storm tracking, Geostationary Lightning Mapper proxy data, and the lightning jump algorithm (LJA), which are important elements in the transition of the LJA concept from a research to an operational based algorithm. Storm cluster tracking is based on a product created from the combination of a radar parameter (vertically integrated liquid, VIL), and lightning information (flash rate density). Evaluations showed that the spatial scale of tracked features or storm clusters had a large impact on the lightning jump system performance, where increasing spatial scale size resulted in decreased dynamic range of the system's performance. This framework will also serve as a means to refine the LJA itself to enhance its operational applicability. Parameters within the system are isolated and the system's performance is evaluated with adjustments to parameter sensitivity. The system's performance is evaluated using the probability of detection (POD) and false alarm ratio (FAR) statistics. Of the algorithm parameters tested, sigma-level (metric of lightning jump strength) and flash rate threshold influenced the system's performance the most. Finally, verification methodologies are investigated. It is discovered that minor changes in verification methodology can dramatically impact the evaluation of the lightning jump system.

lightning jump↗

Space Telescope performance and verification

The verification philosophy for the Space Telescope (ST) has evolved from years of experience with multispacecraft programs modified by the new factors introduced by the Space Transportation System. At the systems level of test, the ST will undergo joint qualification/acceptance tests with environment simulation using Lockheed's large spacecraft test facilities. These tests continue the process of detecting workmanship defects and module interface incompatibilities. The test program culminates in an 'all up' ST environmental test verification program resulting in a 'ready to launch' ST.

Wright, W. F.↗

USB environment measurements based on full-scale static engine ground tests

Flow turning parameters, static pressures, surface temperatures, surface fluctuating pressures and acceleration levels were measured in the environment of a full-scale upper surface blowing (USB) propulsive lift test configuration. The test components included a flightworthy CF6-50D engine, nacelle, and USB flap assembly utilized in conjunction with ground verification testing of the USAF YC-14 Advanced Medium STOL Transport propulsion system. Results, based on a preliminary analysis of the data, generally show reasonable agreement with predicted levels based on model data. However, additional detailed analysis is required to confirm the preliminary evaluation, to help delineate certain discrepancies with model data, and to establish a basis for future flight test comparisons.

Sussman, M. B.↗

Verification approach for the Shuttle/Payload Contamination Evaluation computer program - Spacelab induced environment

The paper presents a compilation of the results of a systems level Shuttle/payload contamination analysis and related computer modeling activities. The current technical assessment of the contamination problems anticipated during the Spacelab program are discussed and recommendations are presented on contamination abatement designs and operational procedures based on experience gained in the field of contamination analysis and assessment, dating back to the pre-Skylab era. The ultimate test of the Shuttle/Payload Contamination Evaluation program will be through comparison of predictions with measured levels of contamination during actual flight.

Bareiss, L. E.↗

USB environment measurements based on full-scale static engine ground tests

Flow turning parameters, static pressures, surface temperatures, surface fluctuating pressures and acceleration levels were measured in the environment of a full-scale upper surface blowing (USB) propulsive-lift test configuration. The test components included a flightworthy CF6-50D engine, nacelle and USB flap assembly utilized in conjunction with ground verification testing of the USAF YC-14 Advanced Medium STOL Transport propulsion system. Results, based on a preliminary analysis of the data, generally show reasonable agreement with predicted levels based on model data. However, additional detailed analysis is required to confirm the preliminary evaluation, to help delineate certain discrepancies with model data and to establish a basis for future flight test comparisons.

Sussman, M. B.↗

Considerations in STS payload environmental verification

Considerations regarding the Space Transportation System (STS) payload environmental verification are reviewed. It is noted that emphasis is placed on testing at the subassembly level and that the basic objective of structural dynamic payload verification is to ensure reliability in a cost-effective manner. Structural analyses consist of: (1) stress analysis for critical loading conditions, (2) model analysis for launch and orbital configurations, (3) flight loads analysis, (4) test simulation analysis to verify models, (5) kinematic analysis of deployment/retraction sequences, and (6) structural-thermal-optical program analysis. In addition to these approaches, payload verification programs are being developed in the thermal-vacuum area. These include the exposure to extreme temperatures, temperature cycling, thermal-balance testing and thermal-vacuum testing.

Keegan, W. B.↗

Pupil Alignment Measuring Technique and Alignment Reference for Instruments or Optical Systems

A technique was created to measure the pupil alignment of instruments in situ by measuring calibrated pupil alignment references (PARs) in instruments. The PAR can also be measured using an alignment telescope or an imaging system. PAR allows the verification of the science instrument (SI) pupil alignment at the integrated science instrument module (ISIM) level of assembly at ambient and cryogenic operating temperature. This will allow verification of the ISIM+SI alignment, and provide feedback to realign the SI if necessary.

Hagopian, John G.↗

High Accuracy Coronagraph Flight Model For WFIRST–CGI Raw Contrast Sensitivity Analysis

A high-accuracy high-fidelity flight wavefront control (WFC) model is developed for detailed raw contrast sensitivity analysis of WFIRST-CGI. Built upon features of recently testbed validated model, it is further refined to combine a full Fresnel propagation diffraction model for high accuracy contrast truth evaluation, and an economical compact model for WFC purposes. Extensive individual raw contrast error sensitivities are evaluated systematically, both as known imperfections and as unknown calibration errors, for both spectroscopy mode and wide field-of-view mode with shaped pupil coronagraph. More than 90 distinct error items were identified, including system aberrations, optical misalignment, component manufacturing error, telescope interface related errors, etc. The result forms the basis for raw contrast error budget flow down to a sub-system level, where detailed specifications needed to aid in component design and manufacturing, mechanical alignment and instrument integration, and verification and validation operations. Evaluations are mostly automated, making it relatively easy for repeat runs of revised design or at new desired error quantity. Top error sensitivities and contrast floor contributors are discussed and several observations are noted.

Poberezhskiy, Ilya↗

Actuator and Motor Control End-to-End V&V on the Mars 2020 Rover

The Mars 2020 Perseverance rover is the most advanced robotic exploration system ever sent to another planet. To support the complex scientific and mobility needs of the mission, the rover utilizes 33 actuators, three multi-degree-of-freedom force-torque sensors, fifteen single or dual-speed resolvers, two solenoid valves, and twelve contact switches. The control for these actuators and sensors is achieved by several levels of flight software, coordinated between two computers with varying bandwidth control loops. Furthermore, the actuators and sensors were integrated into multiple larger robotic mechanisms that were delivered by different organizations at various points in the Integration and Test (I&T) timeline. All of this created a very complex Verification and Validation (V&V) scenario involving multiple subsystems and teams, several hardware and software testbeds with varying levels of fidelity, and significant systems engineering to ensure the overall I&T schedule could be maintained while ensuring system hardware safety.This paper details the integrated V&V effort across multiple teams and venues to provide full coverage of all necessary functionality, performance, and fault protection. First, it provides an overview of how the V&V campaign was subdivided among teams and venues and provides descriptions of the various hardware configurations used to support the testing. The Mars 2020 implementation of the plan incorporates many of the lessons learned from Mars Science Laboratory’s test campaign, and these value-added modifications are discussed here. Also included in this section is the system-level environmental testing approach used for mechanisms. Second, the paper describes the phased approach used by the teams to support new hardware and software deliveries to testbed and Systems I&T. In this approach the test campaign was built upon higher-level mechanism needs for performance, functionality, and safety at specific times in the campaign. Finally, the paper discusses lessons learned from the V&V campaign that should be applied to future large-scale motion control testing efforts.

Borne, Davis↗

A Survey of Formal Methods for Intelligent Swarms

Swarms of intelligent autonomous spacecraft, involving complex behaviors and interactions, are being proposed for future space exploration missions. Such missions provide greater flexibility and offer the possibility of gathering more science data than traditional single spacecraft missions. The emergent properties of swarms make these missions powerful, but simultaneously far more difficult to design, and to assure that the proper behaviors will emerge. These missions are also considerably more complex than previous types of missions, and NASA, like other organizations, has little experience in developing or in verifying and validating these types of missions. A significant challenge when verifying and validating swarms of intelligent interacting agents is how to determine that the possible exponential interactions and emergent behaviors are producing the desired results. Assuring correct behavior and interactions of swarms will be critical to mission success. The Autonomous Nano Technology Swarm (ANTS) mission is an example of one of the swarm types of missions NASA is considering. The ANTS mission will use a swarm of picospacecraft that will fly from Earth orbit to the Asteroid Belt. Using an insect colony analogy, ANTS will be composed of specialized workers for asteroid exploration. Exploration would consist of cataloguing the mass, density, morphology, and chemical composition of the asteroids, including any anomalous concentrations of specific minerals. To perform this task, ANTS would carry miniaturized instruments, such as imagers, spectrometers, and detectors. Since ANTS and other similar missions are going to consist of autonomous spacecraft that may be out of contact with the earth for extended periods of time, and have low bandwidths due to weight constraints, it will be difficult to observe improper behavior and to correct any errors after launch. Providing V&V (verification and validation) for this type of mission is new to NASA, and represents the cutting edge in system correctness, and requires higher levels of assurance than other (traditional) missions that use a single or small number of spacecraft that are deterministic in nature and have near continuous communication access. One of the highest possible levels of assurance comes from the application of formal methods. Formal methods are mathematics-based tools and techniques for specifying and verifying (software and hardware) systems. They are particularly useful for specifying complex parallel systems, such as exemplified by the ANTS mission, where the entire system is difficult for a single person to fully understand, a problem that is multiplied with multiple developers. Once written, a formal specification can be used to prove properties of a system (e.g., the underlying system will go from one state to another or not into a specific state) and check for particular types of errors (e.g., race or livelock conditions). A formal specification can also be used as input to a model checker for further validation. This report gives the results of a survey of formal methods techniques for verification and validation of space missions that use swarm technology. Multiple formal methods were evaluated to determine their effectiveness in modeling and assuring the behavior of swarms of spacecraft using the ANTS mission as an example system. This report is the first result of the project to determine formal approaches that are promising for formally specifying swarm-based systems. From this survey, the most promising approaches were selected and are discussed relative to their possible application to the ANTS mission. Future work will include the application of an integrated approach, based on the selected approaches identified in this report, to the formal specification of the ANTS mission.

Truszkowski, Walt↗

Formal specification and verification of Ada software

The use of formal methods in software development achieves levels of quality assurance unobtainable by other means. The Larch approach to specification is described, and the specification of avionics software designed to implement the logic of a flight control system is given as an example. Penelope is described which is an Ada-verification environment. The Penelope user inputs mathematical definitions, Larch-style specifications and Ada code and performs machine-assisted proofs that the code obeys its specifications. As an example, the verification of a binary search function is considered. Emphasis is given to techniques assisting the reuse of a verification effort on modified code.

Hird, Geoffrey R.↗

Space shuttle thermal scale modeling application study

The critical thermal control problems and verification of thermal mathematical model results for the space shuttle concept are discussed. The use of a small scale thermal model of the space shuttle is proposed. It was determined that a one-third scale model of the space shuttle would serve as a useful tool throughout the entire thermal design and verification program. The major considerations in modeling the conduction-radiation-convection fields, the level of detail for modeling various systems, preliminary test requirements, and potential applications of the thermal scale model are summarized.

Marshall, K. N.↗

Interpretive computer simulator for the NASA Standard Spacecraft Computer-2 (NSSC-2)

An Interpretive Computer Simulator (ICS) for the NASA Standard Spacecraft Computer-II (NSSC-II) was developed as a code verification and testing tool for the Annular Suspension and Pointing System (ASPS) project. The simulator is written in the higher level language PASCAL and implented on the CDC CYBER series computer system. It is supported by a metal assembler, a linkage loader for the NSSC-II, and a utility library to meet the application requirements. The architectural design of the NSSC-II is that of an IBM System/360 (S/360) and supports all but four instructions of the S/360 standard instruction set. The structural design of the ICS is described with emphasis on the design differences between it and the NSSC-II hardware. The program flow is diagrammed, with the function of each procedure being defined; the instruction implementation is discussed in broad terms; and the instruction timings used in the ICS are listed. An example of the steps required to process an assembly level language program on the ICS is included. The example illustrates the control cards necessary to assemble, load, and execute assembly language code; the sample program to to be executed; the executable load module produced by the loader; and the resulting output produced by the ICS.

Smith, R. S.↗

Extraction-Separation Performance and Dynamic Modeling of Orion Test Vehicles with Adams Simulation: 3rd Edition

NASA's Orion Capsule Parachute Assembly System (CPAS) Project is now in the qualification phase of testing, and the Adams simulation has continued to evolve to model the complex dynamics experienced during the test article extraction and separation phases of flight. The ability to initiate tests near the upper altitude limit of the Orion parachute deployment envelope requires extractions from the aircraft at 35,000 ft-MSL. Engineering development phase testing of the Parachute Test Vehicle (PTV) carried by the Carriage Platform Separation System (CPSS) at altitude resulted in test support equipment hardware failures due to increased energy caused by higher true airspeeds. As a result, hardware modifications became a necessity requiring ground static testing of the textile components to be conducted and a new ground dynamic test of the extraction system to be devised. Force-displacement curves from static tests were incorporated into the Adams simulations, allowing prediction of loads, velocities and margins encountered during both flight and ground dynamic tests. The Adams simulation was then further refined by fine tuning the damping terms to match the peak loads recorded in the ground dynamic tests. The failure observed in flight testing was successfully replicated in ground testing and true safety margins of the textile components were revealed. A multi-loop energy modulator was then incorporated into the system level Adams simulation model and the effect on improving test margins be properly evaluated leading to high confidence ground verification testing of the final design solution.

Varela, Jose G.↗