Search NASA⌕ Search

SEARCH · Search NASA

Results for “system-level effects”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 163 records · Page 9

The ICARE Method

The ICARE method is a flexible, widely applicable method for systems engineers to solve problems and resolve issues in a complete and comprehensive manner. The method can be tailored by diverse users for direct application to their function (e.g. system integrators, design engineers, technical discipline leads, analysts, etc.). The clever acronym, ICARE, instills the attitude of accountability, safety, technical rigor and engagement in the problem resolution: Identify, Communicate, Assess, Report, Execute (ICARE). This method was developed through observation of Space Shuttle Propulsion Systems Engineering and Integration (PSE&I) office personnel approach in an attempt to succinctly describe the actions of an effective systems engineer. Additionally it evolved from an effort to make a broadly-defined checklist for a PSE&I worker to perform their responsibilities in an iterative and recursive manner. The National Aeronautics and Space Administration (NASA) Systems Engineering Handbook states, engineering of NASA systems requires a systematic and disciplined set of processes that are applied recursively and iteratively for the design, development, operation, maintenance, and closeout of systems throughout the life cycle of the programs and projects. ICARE is a method that can be applied within the boundaries and requirements of NASA s systems engineering set of processes to provide an elevated sense of duty and responsibility to crew and vehicle safety. The importance of a disciplined set of processes and a safety-conscious mindset increases with the complexity of the system. Moreover, the larger the system and the larger the workforce, the more important it is to encourage the usage of the ICARE method as widely as possible. According to the NASA Systems Engineering Handbook, elements of a system can include people, hardware, software, facilities, policies and documents; all things required to produce system-level results, qualities, properties, characteristics, functions, behavior and performance. The ICARE method can be used to improve all elements of a system and, consequently, the system-level functional, physical and operational performance. Even though ICARE was specifically designed for a systems engineer, any person whose job is to examine another person, product, or process can use the ICARE method to improve effectiveness, implementation, usefulness, value, capability, efficiency, integration, design, and/or marketability. This paper provides the details of the ICARE method, emphasizing the method s application to systems engineering. In addition, a sample of other, non-systems engineering applications are briefly discussed to demonstrate how ICARE can be tailored to a variety of diverse jobs (from project management to parenting).

Henke, Luke↗

Vehicle Integrated Prognostic Reasoner (VIPR) Metric Report

This document outlines a set of metrics for evaluating the diagnostic and prognostic schemes developed for the Vehicle Integrated Prognostic Reasoner (VIPR), a system-level reasoner that encompasses the multiple levels of large, complex systems such as those for aircraft and spacecraft. VIPR health managers are organized hierarchically and operate together to derive diagnostic and prognostic inferences from symptoms and conditions reported by a set of diagnostic and prognostic monitors. For layered reasoners such as VIPR, the overall performance cannot be evaluated by metrics solely directed toward timely detection and accuracy of estimation of the faults in individual components. Among other factors, overall vehicle reasoner performance is governed by the effectiveness of the communication schemes between monitors and reasoners in the architecture, and the ability to propagate and fuse relevant information to make accurate, consistent, and timely predictions at different levels of the reasoner hierarchy. We outline an extended set of diagnostic and prognostics metrics that can be broadly categorized as evaluation measures for diagnostic coverage, prognostic coverage, accuracy of inferences, latency in making inferences, computational cost, and sensitivity to different fault and degradation conditions. We report metrics from Monte Carlo experiments using two variations of an aircraft reference model that supported both flat and hierarchical reasoning.

Cornhill, Dennis↗

Goal-Function Tree Modeling for Systems Engineering and Fault Management

The draft NASA Fault Management (FM) Handbook (2012) states that Fault Management (FM) is a "part of systems engineering", and that it "demands a system-level perspective" (NASAHDBK- 1002, 7). What, exactly, is the relationship between systems engineering and FM? To NASA, systems engineering (SE) is "the art and science of developing an operable system capable of meeting requirements within often opposed constraints" (NASA/SP-2007-6105, 3). Systems engineering starts with the elucidation and development of requirements, which set the goals that the system is to achieve. To achieve these goals, the systems engineer typically defines functions, and the functions in turn are the basis for design trades to determine the best means to perform the functions. System Health Management (SHM), by contrast, defines "the capabilities of a system that preserve the system's ability to function as intended" (Johnson et al., 2011, 3). Fault Management, in turn, is the operational subset of SHM, which detects current or future failures, and takes operational measures to prevent or respond to these failures. Failure, in turn, is the "unacceptable performance of intended function." (Johnson 2011, 605) Thus the relationship of SE to FM is that SE defines the functions and the design to perform those functions to meet system goals and requirements, while FM detects the inability to perform those functions and takes action. SHM and FM are in essence "the dark side" of SE. For every function to be performed (SE), there is the possibility that it is not successfully performed (SHM); FM defines the means to operationally detect and respond to this lack of success. We can also describe this in terms of goals: for every goal to be achieved, there is the possibility that it is not achieved; FM defines the means to operationally detect and respond to this inability to achieve the goal. This brief description of relationships between SE, SHM, and FM provide hints to a modeling approach to provide formal connectivity between the nominal (SE), and off-nominal (SHM and FM) aspects of functions and designs. This paper describes a formal modeling approach to the initial phases of the development process that integrates the nominal and off-nominal perspectives in a model that unites SE goals and functions of with the failure to achieve goals and functions (SHM/FM). This methodology and corresponding model, known as a Goal-Function Tree (GFT), provides a means to represent, decompose, and elaborate system goals and functions in a rigorous manner that connects directly to design through use of state variables that translate natural language requirements and goals into logical-physical state language. The state variable-based approach also provides the means to directly connect FM to the design, by specifying the range in which state variables must be controlled to achieve goals, and conversely, the failures that exist if system behavior go out-of-range. This in turn allows for the systems engineers and SHM/FM engineers to determine which state variables to monitor, and what action(s) to take should the system fail to achieve that goal. In sum, the GFT representation provides a unified approach to early-phase SE and FM development. This representation and methodology has been successfully developed and implemented using Systems Modeling Language (SysML) on the NASA Space Launch System (SLS) Program. It enabled early design trade studies of failure detection coverage to ensure complete detection coverage of all crew-threatening failures. The representation maps directly both to FM algorithm designs, and to failure scenario definitions needed for design analysis and testing. The GFT representation provided the basis for mapping of abort triggers into scenarios, both needed for initial, and successful quantitative analyses of abort effectiveness (detection and response to crew-threatening events).

Patterson, Jonathan D.↗

Control and Non-Payload Communications Generation 1 Prototype Radio Flight Test Report

Unmanned aircraft (UA) represent a new capability that will provide a variety of services in the Government (public) and commercial (civil) aviation sectors. The growth of this potential industry has not yet been realized because of the lack of a common understanding of what is required to safely operate Unmanned Aircraft Systems in the National Airspace System (UAS in the NAS). The desire and ability to fly UA is of increasing urgency. The application of UA to perform national security, defense, scientific, and emergency management are driving the critical need for less restrictive access by UA to the NAS. Existing Federal Aviation Regulations, procedures, and technologies do not allow routine UA access to the NAS. Access to the NAS is hampered by challenges such as the lack of an onboard pilot to see and avoid other aircraft; the ability of a single pilot or operator to control multiple UA; the reliance on command and control (C2) links; the altitudes, speeds, and duration at which the aircraft fly; and the wide variation in UA size and performance. NASA is working with other Government agencies to provide solutions that reduce technical barriers and make access to the NAS routine. This goal will be accomplished through system-level integration of key concepts, technologies, or procedures and through demonstrations of these integrated capabilities in an operationally relevant environment. This project provides an opportunity to transition the acquired empirical data and knowledge to the Federal Aviation Administration and other stakeholders to help them define the requirements for routine UA access to the NAS.Radio communications channels for UA are currently managed through exceptions and use either Department of Defense frequencies for line-of-sight (LOS) and satellite-based communications links, low-power LOS links in amateur bands, or unlicensed Industrial/Scientific/Medical (ISM) frequencies. None of these frequency bands are designated for safety and regularity of flight. Only recently has radiofrequency (RF) spectrum been allocated by the International Telecommunications Union specifically for commercial UA C2, LOS communication (L-Band: 960 to 1164 MHz, and C-Band: 5030 to 5091 MHz). The safe and efficient integration of UA into the NAS requires the use of protected RF spectrum allocations and a new data communications system that is both secure and scalable to accommodate the potential growth of these new aircraft. Data communications for UA-referred to as control and non-payload communications (CNPC)-will be used to exchange information between a UA and a ground station (GS) to ensure safe, reliable, and effective UA flight operation. The focus of this effort is on validating and allocating new RF spectrum and data link communications to enable civil UA integration into the NAS. Through a cost-sharing cooperative agreement with Rockwell Collins, Inc., the NASA Glenn Research Center is exploring and performing the necessary development steps to realize a prototype UA CNPC system. These activities include investigating signal waveforms and access techniques, developing representative CNPC radio hardware, and executing relevant testing and validation activities. There is no intent to manufacture the CNPC end product, rather the goals are to study, demonstrate, and validate a typical CNPC system that will allow safe and efficient communications within the L-Band and C-Band spectrum allocations. The system is addressing initial "seed" requirements from RTCA, Inc., Special Committee 203 (SC-203) and is on a path to Federal Aviation Administration certification. This report provides results from the flight testing campaign of the Rockwell Collins Generation 1 prototype radio, referred hereafter as the "radio." The radio sets operate within the 960- to 977-MHz frequency band with both air and ground radios using identical hardware. Flight tests involved one aircraft and one GS. Results include discussion of aircraft flight paths and associated radio performance.

Shalkhauser, Kurt A.↗

Affordable Electro-Magnetic Interference (EMI) Testing on Large Space Vehicles

Objective: Perform System-Level EMI testing of the Orion Exploration Flight Test-1 (EFT-1) spacecraft in situ in the Kennedy Space Center's Neil Armstrong Operations & Checkout (O&C) Facility in 6 days. The only way to execute the system-level EMI testing and meet this schedule challenge was to perform the EMI testing in situ in the Final Assembly & System Test (FAST) Cell in a reverberant mode, not the direct illumination mode originally planned. This required the unplanned construction of a Faraday Cage around the vehicle and FAST Cell structure. The presence of massive steel platforms created many challenges to developing an efficient screen room to contain the RF energy and yield an effective reverberant chamber. An initial effectiveness test showed marginal performance, but improvements implemented afterward resulted in the final test performing surprisingly well! The paper will explain the design, the challenges, and the changes that made the difference in performance!

Aldridge, Edward↗

Nano-ADEPT Aeroloads Wind Tunnel Test

Analysis completed since the test suggests that all test objectives were met– This claim will be verified in the coming weeks as the data is examined further– Final disposition of test objective success will be documented in a final reportsubmitted to NASA stakeholders (early August 2015)– Expect conference paper in early 2016• Data products and observations made during testing will be used to refinecomputational models of Nano-ADEPT• Carbon fabric relaxed from its pre-test state during the test– System-level tolerance for relaxation will be driven by destination-specific andmission-specific aerothermal and aerodynamic requirements• Bonus experiment of asymmetric shape demonstrates that an asymmetricdeployable blunt body can be used to generate measureable lift– With a strut actuation system and a robust GN&C algorithm, this effect could beused to steer a blunt body at hypersonic speeds to aid precision landing

atmospheric entry↗

SLS-SPEC-159 Cross-Program Design Specification for Natural Environments (DSNE) Revision D

This document is derived from the former National Aeronautics and Space Administration (NASA) Constellation Program (CxP) document CxP 70023, titled "The Design Specification for Natural Environments (DSNE), Revision C." The original document has been modified to represent updated Design Reference Missions (DRMs) for the NASA Exploration Systems Development (ESD) Programs. The DSNE completes environment-related specifications for architecture, system-level, and lower-tier documents by specifying the ranges of environmental conditions that must be accounted for by NASA ESD Programs. To assure clarity and consistency, and to prevent requirements documents from becoming cluttered with extensive amounts of technical material, natural environment specifications have been compiled into this document. The intent is to keep a unified specification for natural environments that each Program calls out for appropriate application. This document defines the natural environments parameter limits (maximum and minimum values, energy spectra, or precise model inputs, assumptions, model options, etc.), for all ESD Programs. These environments are developed by the NASA Marshall Space Flight Center (MSFC) Natural Environments Branch (MSFC organization code: EV44). Many of the parameter limits are based on experience with previous programs, such as the Space Shuttle Program. The parameter limits contain no margin and are meant to be evaluated individually to ensure they are reasonable (i.e., do not apply unrealistic extreme-on-extreme conditions). The natural environments specifications in this document should be accounted for by robust design of the flight vehicle and support systems. However, it is understood that in some cases the Programs will find it more effective to account for portions of the environment ranges by operational mitigation or acceptance of risk in accordance with an appropriate program risk management plan and/or hazard analysis process. The DSNE is not intended as a definition of operational models or operational constraints, nor is it adequate, alone, for ground facilities which may have additional requirements (for example, building codes and local environmental constraints). "Natural environments," as the term is used here, refers to the environments that are not the result of intended human activity or intervention. It consists of a variety of external environmental factors (most of natural origin and a few of human origin) which impose restrictions or otherwise impact the development or operation of flight vehicles and destination surface systems. These natural environments include the following types of environments: Terrestrial environments at launch, abort, and normal landing sites (winds, temperatures, pressures, surface roughness, sea conditions, etc.); Space environments (ionizing radiation, orbital debris, meteoroids, thermosphere density, plasma, solar, Earth, and lunar-emitted thermal radiation, etc.); Destination environments (Lunar surface and orbital, Mars atmosphere and surface, near Earth asteroids, etc.). Many of the environmental specifications in this document are based on models, data, and environment descriptions contained in the CxP 70044, Constellation Program Natural Environment Definition for Design (NEDD). The NEDD provides additional detailed environment data and model descriptions to support analytical studies for ESD Programs. For background information on specific environments and their effects on spacecraft design and operations, the environment models, and the data used to generate the specifications contained in the DSNE, the reader is referred to the NEDD paragraphs listed in each section of the DSNE. Also, most of the environmental specifications in this document are tied specifically to the ESD DRMs in ESD-10012, Revision B, Exploration Systems Development Concept of Operations (ConOps). Coordination between these environment specifications and the DRMs must be maintained. This document should be compatible with the current ESD DRMs, but updates to the mission definitions and variations in interpretation may require adjustments to the environment specifications.

Roberts, Barry C.↗

Optical Telescope System-Level Design Considerations for a Space-Based Gravitational Wave Mission

The study of the Universe through gravitational waves will yield a revolutionary new perspective on the Universe, which has been intensely studied using electromagnetic signals in many wavelength bands. A space-based gravitational wave observatory will enable access to a rich array of astrophysical sources in the measurement band from 0.1 to 100 mHz, and nicely complement observations from ground-based detectors as well as pulsar timing arrays by sampling a different range of compact object masses and astrophysical processes. The observatory measures gravitational radiation by precisely monitoring the tiny change in the proper distance between pairs of freely falling proof masses. These masses are separated by millions of kilometers and, using a laser heterodyne interferometric technique, the change in their proper separation is detected to approx. 10 pm over timescales of 1000 seconds, a fractional precision of better than one part in 10(exp 19). Optical telescopes are essential for the implementation of this precision displacement measurement. In this paper we describe some of the key system level design considerations for the telescope subsystem in a mission context. The reference mission for this purpose is taken to be the enhanced Laser Interferometry Space Antenna mission (eLISA), a strong candidate for the European Space Agency's Cosmic Visions L3 launch opportunity in 2034. We will review the flow-down of observatory level requirements to the telescope subsystem, particularly pertaining to the effects of telescope dimensional stability and scattered light suppression, two performance specifications which are somewhat different from the usual requirements for an image forming telescope.

LISA↗

SLS-SPEC-159 Cross-Program Design Specification for Natural Environments (DSNE) Revision E

The DSNE completes environment-related specifications for architecture, system-level, and lower-tier documents by specifying the ranges of environmental conditions that must be accounted for by NASA ESD Programs. To assure clarity and consistency, and to prevent requirements documents from becoming cluttered with extensive amounts of technical material, natural environment specifications have been compiled into this document. The intent is to keep a unified specification for natural environments that each Program calls out for appropriate application. This document defines the natural environments parameter limits (maximum and minimum values, energy spectra, or precise model inputs, assumptions, model options, etc.), for all ESD Programs. These environments are developed by the NASA Marshall Space Flight Center (MSFC) Natural Environments Branch (MSFC organization code: EV44). Many of the parameter limits are based on experience with previous programs, such as the Space Shuttle Program. The parameter limits contain no margin and are meant to be evaluated individually to ensure they are reasonable (i.e., do not apply unrealistic extreme-on-extreme conditions). The natural environments specifications in this document should be accounted for by robust design of the flight vehicle and support systems. However, it is understood that in some cases the Programs will find it more effective to account for portions of the environment ranges by operational mitigation or acceptance of risk in accordance with an appropriate program risk management plan and/or hazard analysis process. The DSNE is not intended as a definition of operational models or operational constraints, nor is it adequate, alone, for ground facilities which may have additional requirements (for example, building codes and local environmental constraints). "Natural environments," as the term is used here, refers to the environments that are not the result of intended human activity or intervention. It consists of a variety of external environmental factors (most of natural origin and a few of human origin) which impose restrictions or otherwise impact the development or operation of flight vehicles and destination surface systems.

Roberts, Barry C.↗

Evaluating the Assumptions in an Empirical Jet-Surface Interaction Noise Model

A set of empirical jet-surface interaction noise models, developed for single-stream round nozzles exhausting over a simple surface in a static ambient, are evaluated for use in more realistic applications that include multi-stream nozzle systems, multi-plane surface geometries, and a flight-stream. The simple-single-stream models have several advantages when used in system-level noise studies: they are robust, they are quickly computed, and they are generally applicable to a wide range of configurations. However, these models require simplifying assumptions when applied to more complex jet exhaust systems; for example, previous work on multi-stream jets used an empirical formula to compute a single-stream equivalent jet potential core length that could be used to predict the noise using simple-single-stream jet-surface interaction models. This paper considers the effect of flight and multi-plane surfaces using a similar approach: introducing assumptions to simplify the complex system, applying the simple-single-stream models, and evaluating the uncertainty.

Jet Noise↗

Evaluating the Assumptions in an Empirical Jet-Surface Interaction Noise Model

A set of empirical jet-surface interaction noise models, developed for single-stream round nozzles exhausting over a simple surface in a static ambient, are evaluated for use in more realistic applications that include multi-stream nozzle systems, multi-plane surface geometries, and a flight-steam. The simple-single-stream models have several advantages when used in system-level noise studies: they are robust, they are quickly computed, and they are generally applicable to a wide range of configurations. However, these models require simplifying assumptions when applied to more complex jet exhaust systems; for example, previous work on multi-stream jets used an empirical formula to compute a single-stream equivalent jet potential core length that could be used to predict the noise using simple-single-stream jet-surface interaction models. This paper considers the effect of flight and multi-plane surfaces using a similar approach: introducing assumptions to simplify the complex system, applying the simple-single-stream models, and evaluating the uncertainty.

Jet Noise↗

GT SUITE Fuel Cell Model Validation with Power Module Test Data

The AES Modular Power Systems (AMPS) Fuel Cell team at the NASA Glenn Research Center (GRC) has created a Microsoft Excel model of a regenerative fuel cell (RFC) system for potential lunar and Martian applications. Due to some limitations of this model, including the ability to predict transient effects in the thermal and fluidic performance of the system, a system-level transient thermal/fluids model was desired. GT-SUITE is a transient multi-physics simulation tool that is popular in the automotive industry and has a built in template for proton exchange membrane (PEM) fuel cells. However, terrestrial fuel cells used in the automotive industry vary significantly from aerospace fuel cells. A validation effort was undertaken to compare GT SUITE model results to actual data collected during the 2015 AMPS Power Module Demonstration in which the AMPS team used a PEM fuel cell system to power a 478 kg rover assembly at the Dunes test site located at GRC. The purpose of the model was to evaluate the efficacy of using GT SUITE to model a non-flow through PEM fuel cell system. The validation effort examined electrochemical performance including fuel cell stack voltage and power supplied, the thermal performance of the stack namely stack temperature and heat rejection rates, and the fluidic performance of the system including pressures, reactant consumption, and water production rates.

Gilligan, Ryan↗

Fuel Cell Model Validation with Power Module Test Data

The AES Modular Power Systems (AMPS) Fuel Cell team at the NASA Glenn Research Center (GRC) has created a Microsoft Excel model of a regenerative fuel cell (RFC) system for potential lunar and Martian applications. Due to some limitations of this model, including the ability to predict transient effects in the thermal and fluidic performance of the system, a system-level transient thermal/fluids model was desired. GT-SUITE is a transient multi-physics simulation tool that is popular in the automotive industry and has a built-in template for proton exchange membrane (PEM) fuel cells. However, terrestrial fuel cells used in the automotive industry vary significantly from aerospace fuel cells. A validation effort was undertaken to compare GT SUITE model results to actual data collected during the 2015 AMPS (Advanced Exploration Systems (AES) Modular Power Systems) Power Module Demonstration in which the AMPS team used a PEM fuel cell system to power a 478 kilogram rover assembly at the Dunes test site located at GRC. The purpose of the model was to evaluate the efficacy of using GT SUITE to model a non-flow through PEM fuel cell system. The validation effort examined electrochemical performance including fuel cell stack voltage and power supplied, the thermal performance of the stack namely stack temperature and heat rejection rates, and the fluidic performance of the system including pressures, reactant consumption, and water production rates.

Model Validation↗

Flight-Test Evaluation of Airframe Noise Mitigation Technologies

A series of flight tests targeting airframe noise reduction was planned and executed under the NASA Flight Demonstrations and Capabilities project. The objectives of the tests were two-fold: to evaluate the aeroacoustic performance of several noise reduction technologies in a relevant environment and to generate a comprehensive database for advancing the state of the art in simulation-based airframe noise prediction methodologies. These technologies – an Adaptive Compliant Trailing Edge flap, main landing gear fairings, and gear cavity treatments – were integrated on a NASA Gulfstream G-III aircraft to determine their effectiveness, both on a component-level (individually) and a system-level (combined) basis. With the aircraft flying an approach pattern and the engines set at ground idle, extensive acoustic measurements were acquired using a phased microphone array system. Detailed analyses of the gathered acoustic data clearly demonstrate that significant noise reduction was achieved for the flap and main landing gear components.

Khorrami, Mehdi R.↗

Variational Coupled Loads Analysis using the Hybrid Parametric Variation Method

Time-domain coupled loads analysis (CLA)is used to determine the response of a launch vehicle and payload system to transient forces, such as liftoff, engine ignitions and shutdowns, jettison events, and atmospheric flight loads, such as buffet. CLA, using Hurty/Craig-Bampton (HCB)component models, is the accepted method for the establishment of design-level loads for launch systems. However, uncertainty in the component models flows into uncertainty in predicted system results. Uncertainty in the structural responses during launch is a significant concern because small variations in launch vehicle and payload mode shapes and their interactions can result in significant variations in system loads. Uncertainty quantification (UQ)is used to determine statistical bounds on prediction accuracy based on model uncertainty. In this paper uncertainty is treated at the HCB component-model level. In an effort to account for model uncertainties and statistically bound their effect on CLA predictions, this work combines CLA with UQ in a process termed variational coupled loads analysis (VCLA). The modeling of uncertainty using a parametric approach, in which input parameters are represented by random variables, is common, but its major drawback is the resulting uncertainty is limited to the form of the nominal model. Uncertainty in model form is one of the biggest contributors to uncertainty in complex built-up structures. Model-form uncertainty can be represented using a nonparametric approach based on random matrix theory (RMT). In this work, UQ is performed using the hybrid parametric variation (HPV)method, which combines parametric with nonparametric uncertainty at the HCB component model level. The HPV method requires the selection of dispersion values for the HCB fixed-interface (FI)eigenvalues, and the HCB mass and stiffness matrices. The dispersions are based upon component test-analysis modal correlation results. During VCLA, random component models are assembled into an ensemble of random systems using a Monte Carlo (MC)approach. CLA is applied to each of the ensemble members to produce an ensemble of system-level responses for statistical analysis. The proposed methodology is demonstrated through its application to a buffet loads analysis of NASA’s Space Launch System (SLS)during the transonic regime fifty seconds after liftoff. Core stage (CS)section shears and moments are recovered, and statistics are computed.

Uncertainty Quantification↗

Threats to Resiliency of Redundant Systems Due to Destructive SEE

Destructive SEE pose serious challenges for the reliable use of COTS devices in space systems. We used system-level modeling to determine SEL rates that would likely compromise system reliability, resilience and capabilities. We then assembled a representative dataset of COTS CMOS parts and used nonparametric statistical techniques to assess the threat posed to redundant systems by destructive SEE.

single-event effects↗

Architectural Modeling and Analysis for Safety Engineering

Model-based development tools are increasingly being used for system-level development of safety-critical systems. Architectural and behavioral models provide important information that can be leveraged to improve the system safety analysis process. Model-based design artifacts produced in early stage development activities can be used to perform system safety analysis, reducing costs and providing accurate results throughout the system life-cycle. In this report we describe an extension to the Architecture Analysis and Design Language (AADL) that supports modeling of system behavior under failure conditions. This Safety Annex enables the independent modeling of component failures and allows safety engineers to weave various types of fault behavior into the nominal system model. The accompanying tool support uses model checking to propagate errors from their source to their effect on safety properties without the need to add separate propagation specifications. The tool also captures all minimal set of fault combinations that can cause violation of the safety properties, that can be compared to qualitative and quantitative objectives as part of the safety assessment process. We describe the Safety Annex, illustrate its use with a representative example, and discuss and demonstrate the tool support enabling an analyst to investigate the system behavior under failure conditions.

FTA↗