Search NASASearch

SEARCH · Search NASA

Results for “Compositional verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Learning Assumptions for Compositional Verification

Compositional verification is a promising approach to addressing the state explosion problem associated with model checking. One compositional technique advocates proving properties of a system by checking properties of its components in an assume-guarantee style. However, the application of this technique is difficult because it involves non-trivial human input. This paper presents a novel framework for performing assume-guarantee reasoning in an incremental and fully automated fashion. To check a component against a property, our approach generates assumptions that the environment needs to satisfy for the property to hold. These assumptions are then discharged on the rest of the system. Assumptions are computed by a learning algorithm. They are initially approximate, but become gradually more precise by means of counterexamples obtained by model checking the component and its environment, alternately. This iterative process may at any stage conclude that the property is either true or false in the system. We have implemented our approach in the LTSA tool and applied it to the analysis of a NASA system.

Cobleigh, Jamieson M.

Projected Impact of Compositional Verification on Current and Future Aviation Safety Risk

The projected impact of compositional verification research conducted by the National Aeronautic and Space Administration System-Wide Safety and Assurance Technologies on aviation safety risk was assessed. Software and compositional verification was described. Traditional verification techniques have two major problems: testing at the prototype stage where error discovery can be quite costly and the inability to test for all potential interactions leaving some errors undetected until used by the end user. Increasingly complex and nondeterministic aviation systems are becoming too large for these tools to check and verify. Compositional verification is a "divide and conquer" solution to addressing increasingly larger and more complex systems. A review of compositional verification research being conducted by academia, industry, and Government agencies is provided. Forty-four aviation safety risks in the Biennial NextGen Safety Issues Survey were identified that could be impacted by compositional verification and grouped into five categories: automation design; system complexity; software, flight control, or equipment failure or malfunction; new technology or operations; and verification and validation. One capability, 1 research action, 5 operational improvements, and 13 enablers within the Federal Aviation Administration Joint Planning and Development Office Integrated Work Plan that could be addressed by compositional verification were identified.

Reveley, Mary S.

CoCoSim Tutorial: Contract-based Compositional Verification of Simulink Models

This tutorial presents CoCoSim, a verification framework for MATLAB Simulink and Stateflow models. We demonstrate CoCoSim’s architecture, designed to be compatible with Lustre-based verification tools, as well as easily extensible to other candidate backends. We focus on CoCoSim’s powerful compositional verification scheme, which allows for scalable verification through the usage of abstractions of subsystems, express ed in the form of Assume-Guarantee Contracts. We show CoCoSim’s interconnection with NASA’s Formal Requirements Tool (FRET), that enables a seamless transition between authoring and formally verifying requirements for Simulink/Stateflow models. Finally, we discuss work in progress with regards to test case generation options in CoCoSim, demonstrating the generation of MC/DC tests for Simulink artifacts.

Formal Verification

Proof Rules for Automated Compositional Verification through Learning

Compositional proof systems not only enable the stepwise development of concurrent processes but also provide a basis to alleviate the state explosion problem associated with model checking. An assume-guarantee style of specification and reasoning has long been advocated to achieve compositionality. However, this style of reasoning is often non-trivial, typically requiring human input to determine appropriate assumptions. In this paper, we present novel assume- guarantee rules in the setting of finite labelled transition systems with blocking communication. We show how these rules can be applied in an iterative and fully automated fashion within a framework based on learning.

Barringer, Howard

Interface Generation and Compositional Verification in JavaPathfinder

We present a novel algorithm for interface generation of software components. Given a component, our algorithm uses learning techniques to compute a permissive interface representing legal usage of the component. Unlike our previous work, this algorithm does not require knowledge about the component s environment. Furthermore, in contrast to other related approaches, our algorithm computes permissive interfaces even in the presence of non-determinism in the component. Our algorithm is implemented in the JavaPathfinder model checking framework for UML statechart components. We have also added support for automated assume-guarantee style compositional verification in JavaPathfinder, using component interfaces. We report on the application of the presented approach to the generation of interfaces for flight software components.

Giannakopoulou, Dimitra

Abstraction and Assume-Guarantee Reasoning for Automated Software Verification

Compositional verification and abstraction are the key techniques to address the state explosion problem associated with model checking of concurrent software. A promising compositional approach is to prove properties of a system by checking properties of its components in an assume-guarantee style. This article proposes a framework for performing abstraction and assume-guarantee reasoning of concurrent C code in an incremental and fully automated fashion. The framework uses predicate abstraction to extract and refine finite state models of software and it uses an automata learning algorithm to incrementally construct assumptions for the compositional verification of the abstract models. The framework can be instantiated with different assume-guarantee rules. We have implemented our approach in the COMFORT reasoning framework and we show how COMFORT out-performs several previous software model checking approaches when checking safety properties of non-trivial concurrent programs.

Chaki, S.

Compositional Verification of a Communication Protocol for a Remotely Operated Vehicle

This paper presents the specification and verification in the Prototype Verification System (PVS) of a protocol intended to facilitate communication in an experimental remotely operated vehicle used by NASA researchers. The protocol is defined as a stack-layered com- position of simpler protocols. It can be seen as the vertical composition of protocol layers, where each layer performs input and output message processing, and the horizontal composition of different processes concurrently inhabiting the same layer, where each process satisfies a distinct requirement. It is formally proven that the protocol components satisfy certain delivery guarantees. Compositional techniques are used to prove these guarantees also hold in the composed system. Although the protocol itself is not novel, the methodology employed in its verification extends existing techniques by automating the tedious and usually cumbersome part of the proof, thereby making the iterative design process of protocols feasible.

Goodloe, Alwyn E.

Wide-field Infrared Survey Telescope (WFIRST): Composite Structure Verification for Operational Temperatures

The Wide-Field Infrared Survey Telescope (WFIRST) mission is the next large astrophysics observatory for NASA after the James Webb Space Telescope and is the top priority mission from the 2010 National Academy of Sciences' decadal survey. The WFIRST Optical Telescope Assembly (OTA) includes inherited composite support structures that were originally designed and tested for room temperature operation; however, the WFIRST mission will require operation at colder temperatures to achieve sufficient sensitivity for the infrared wavelengths. We will present the results and conclusions of testing completed at the coupon and engineering model level to verify that the inherited composite structures will maintain mechanical integrity and performance over the required temperature range. The testing included: (1) characterization testing of constituent material coupons, (2) thermal cycling and static load testing of a representative aft metering structure (AMS) and forward metering structure (FMS), and (3) thermal cycling and dynamic testing of a representative secondary mirror assembly (SMA).

metering

An Update on the Mechanical and EM Performance of the Composite Dish Verification Antenna (DVA-1) for the SKA

This paper will give an overview of the unique mechanical and optical design of the DVA-1 telescope. The rim supported carbon fibre reflector surfaces are designed to be both low cost and have high performance under wind, gravity, and thermal loads. The shaped offset Gregorian optics offer low and stable side lobes along with a large area at the secondary focus for multiple feeds with no aperture blockage. Telescope performance under ideal conditions as well as performance under gravity, wind, and thermal loads will be compared directly using calculated radiation patterns for each of these operating conditions.

composite dish

Validation and Verification of Composite Pressure Vessel Design

Ten composite pressure vessels were instrumented with fiber Bragg grating sensors and pressure tested Through burst. This paper and presentation will discuss the testing methodology, the test results, compare the testing results to the analytical model, and also compare the fiber Bragg grating sensor data with data obtained against that obtained from foil strain gages.

Kreger, Stephen T.

Demonstration Testing for Ground Servicing of the Commercial Crew Vehicle Emergency Breathing Air Assembly

The new Commercial crew vehicle (CCV) Breathing Air Assembly (CEBAA) is a Composite Overwrapped Pressure Vessel (COPV) filled with high-pressure air, which is designed to provide portable emergency breathing air for up to five crew in the event of an ammonia leak aboard the International Space Station (ISS). Industrially, several common methods of delivering breathing air exist; however, ground processing constraints and flight requirements necessitate the more unusual approach of servicing a COPV with high purity gaseous nitrogen and oxygen serially to achieve a specific mixture of breathing air at approximately 4000 PSIA. A dwell period allows the gases to mix before sampling for composition verification. The novelty of this approach led to concerns about acceptable gas mixing and the ability to deliver accurate gas compositions. Tests examining mixing rate over a series of post-servicing dwell periods were conducted to determine the optimal time for achieving a homogeneous mixture. Further testing was conducted to examine process accuracy using temperature-pressure load criteria to target a specific concentration of oxygen and nitrogen. Test results show that while some stratification of nitrogen and oxygen was observed, a seven-day dwell is adequate time to achieve an acceptable level of mixing, and that existing ground support equipment can accurately service CEBAA COPVs to the required temperature, pressure and composition for flight.

Active Thermal

Demonstration Testing for Ground Servicing of the Commercial Crew Vehicle Emergency Breathing Air Assembly

The new Commercial crew vehicle (CCV) Emergency Breathing Air Assembly (CEBAA) is a Composite Overwrapped Pressure Vessel (COPV) filled with high-pressure air, which is designed to provide portable emergency breathing air for up to five crew in the event of an ammonia leak aboard the International Space Station (ISS). Industrially, several common methods of delivering breathing air exist; however, ground processing constraints and flight requirements necessitate the more unusual approach of servicing a COPV with high purity gaseous nitrogen and oxygen serially to achieve a specific mixture of breathing air at approximately 4000 PSIA. A dwell period allows the gases to mix before sampling for composition verification. The novelty of this approach led to concerns about acceptable gas mixing and the ability to deliver accurate gas compositions. Tests examining mixing rate over a series of post-servicing dwell periods were conducted to determine the optimal time for achieving a homogeneous mixture. Further testing was conducted to examine process accuracy using temperature-pressure load criteria to target a specific concentration of oxygen and nitrogen. Test results show that while some stratification of nitrogen and oxygen was observed, a seven-day dwell is adequate time to achieve an acceptable level of mixing, and that existing ground support equipment can accurately service CEBAA COPVs to the required temperature, pressure and composition for flight.

Active Thermal

Assume-Guarantee Abstraction Refinement Meets Hybrid Systems

Compositional verification techniques in the assume- guarantee style have been successfully applied to transition systems to efficiently reduce the search space by leveraging the compositional nature of the systems under consideration. We adapt these techniques to the domain of hybrid systems with affine dynamics. To build assumptions we introduce an abstraction based on location merging. We integrate the assume-guarantee style analysis with automatic abstraction refinement. We have implemented our approach in the symbolic hybrid model checker SpaceEx. The evaluation shows its practical potential. To the best of our knowledge, this is the first work combining assume-guarantee reasoning with automatic abstraction-refinement in the context of hybrid automata.

Reliability

Structural verification of an aged composite reflector

A structural verification program applied to qualifying two heritage composite antenna reflectors for flight on the TOPEX satellite is outlined. The verification requirements and an integrated analyses/test approach employed to meet these requirements are described. Structural analysis results and qualification vibration test data are presented and discussed. It was determined that degradation of the composite and bonding materials caused by long-term exposure to an uncontrolled environment had not severely impaired the integrity of the reflector structures. The reflectors were assessed to be structurally adequate for the intended TOPEX application.

Lou, Michael C.

Verification of Autonomous Systems for Space Applications

Autonomous software, especially if it is based on model, can play an important role in future space applications. For example, it can help streamline ground operations, or, assist in autonomous rendezvous and docking operations, or even, help recover from problems (e.g., planners can be used to explore the space of recovery actions for a power subsystem and implement a solution without (or with minimal) human intervention). In general, the exploration capabilities of model-based systems give them great flexibility. Unfortunately, it also makes them unpredictable to our human eyes, both in terms of their execution and their verification. The traditional verification techniques are inadequate for these systems since they are mostly based on testing, which implies a very limited exploration of their behavioral space. In our work, we explore how advanced V&V techniques, such as static analysis, model checking, and compositional verification, can be used to gain trust in model-based systems. We also describe how synthesis can be used in the context of system reconfiguration and in the context of verification.

Brat, G.

Hybrid Decompositional Verification for Discovering Failures in Adaptive Flight Control Systems

Adaptive flight control systems hold tremendous promise for maintaining the safety of a damaged aircraft and its passengers. However, most currently proposed adaptive control methodologies rely on online learning neural networks (OLNNs), which necessarily have the property that the controller is changing during the flight. These changes tend to be highly nonlinear, and difficult or impossible to analyze using standard techniques. In this paper, we approach the problem with a variant of compositional verification. The overall system is broken into components. Undesirable behavior is fed backwards through the system. Components which can be solved using formal methods techniques explicitly for the ranges of safe and unsafe input bounds are treated as white box components. The remaining black box components are analyzed with heuristic techniques that try to predict a range of component inputs that may lead to unsafe behavior. The composition of these component inputs throughout the system leads to overall system test vectors that may elucidate the undesirable behavior

Thompson, Sarah

Interpreter composition issues in the formal verification of a processor-memory module

This report describes interpreter composition techniques suitable for the formal specification and verification of a processor-memory module using the HOL theorem proving system. The processor-memory module is a multichip subsystem within a fault-tolerant embedded system under development within the Boeing Defense and Space Group. Modeling and verification methods were developed that permit provably secure composition at the transaction-level of specification, significantly reducing the complexity of the hierarchical verification of the system.

Fura, David A.