Search NASA⌕ Search

SEARCH · Search NASA

Results for “Development assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Run Time Assurance as an Alternate Concept to Contemporary Development Assurance Processes

NASA and the FAA sought industry research to identify and evaluate alternate concepts for assuring safety of airborne systems. This report documents a research effort focused on the evaluation of Run Time Assurance (RTA) as applied to a novel, airborne system architecture. The RTA pattern is applied to a case study focused on a notional integrated flight and propulsion control system for a DEP VTOL aircraft. During flight, while the high-automation algorithms are operating, the RTA system will monitor the aircraft state for any impending violation of safety requirements. When necessary, it will switch to the low-automation software to prevent such violations. Assurance practices for both baseline industry activities and the RTA approach were captured and compared to illustrate the required engineering design considerations, and possible advantages and disadvantages of each approach as part of this case study.

Eric M. Peterson↗

Run Time Assurance for Electric Vertical Takeoff and Landing Aircraft

NASA is conducting research to demonstrate and evaluate the application of Run Time Assurance (RTA) as a means to assure safety in Electric Vertical Takeoff and Landing (eVTOL) aircraft with highly automated or autonomous flight capability supervised by a single onboard pilot. The work described in this report demonstrates an application of RTA and examines the implications for design and analysis of aircraft functions and systems; aircraft safety hazards; safety assurance; development assurance; and pilot tasks and performance. This research effort also seeks to assess the efficacy of the combined application of traditional Functional Hazard Analysis (FHA) and the more modern System Theoretic Process Analysis (STPA) techniques to perform hazard analyses on aircraft with complex automated and autonomous systems and an onboard pilot. During the research effort we developed architectural designs of two alternate eVTOL aircraft, generally following the process characterized in the SAE standards ARP4754 and ARP4761. The design has focused on the control architectures of these aircraft, which are identical except that one incorporates RTA techniques to reduce the criticality of some key software components. Artifacts of this process include a taxonomy of aircraft-level functions, aircraft-level architecture diagrams, aircraft-level functional hazard assessments (AFHA), function allocations onto aircraft systems and subsystems, functional block diagrams for a select set of control-related functions, and system-level functional hazard assessments (SFHA) for those functions. This project has highlighted the notion that DAL D is something of a sweet spot for low-confidence controllers in an RTA-based design. Among the many activities described in DO-178C, the activities related to requirement verifiability, algorithmic accuracy, and test coverage can be the most challenging for the kinds of advanced control techniques that may be desirable in novel UAM designs, such as adaptive control, machine-learning, artificial intelligence, numerical search, and Monte Carlo based algorithms. Moreover, the standard requires that development teams demonstrate that errors leading to unacceptable failure conditions have been removed from the software. The RTA architecture, which cordons off the low-confidence function, makes it much easier to show this for these kinds of algorithms. With regard to the use of STPA and FHA as complementary hazard analysis techniques, our research effort led us to the conclusion that STPA should be used to derive requirements for hardware and software systems and/or components. Also, STPA is a natural complement to other processes in ARP4754A involving design studies and iteration.

Run-time assurance↗

Development of quality assurance methods for epoxy graphite prepreg

Quality assurance methods for graphite epoxy/prepregs were developed. Liquid chromatography, differential scanning calorimetry, and gel permeation chromatography were investigated. These methods were applied to a second prepreg system. The resin matrix formulation was correlated with mechanical properties. Dynamic mechanical analysis and fracture toughness methods were investigated. The chromatography and calorimetry techniques were all successfully developed as quality assurance methods for graphite epoxy prepregs. The liquid chromatography method was the most sensitive to changes in resin formulation. The were also successfully applied to the second prepreg system.

Chen, J. S.↗

Institutional and environmental problems in geothermal resource development

A number of regulatory and institutional impediments to the development of geothermal energy exist. None of these seem likely to prevent the development of this energy source, but in the aggregate they will pace its growth as certainly as the technological issues. The issues are associated with the encouragement of exploration and development, assuring a market for geothermal steam or hot water, and accomplishing the required research and development in a timely manner. The development of geothermal energy in the United States at a high level is apt to cause both favorable and unfavorable, though manageable, impacts in eight major areas, which are discussed.

Maslan, F.↗

Formal Methods in the Development of Highly Assured Software for Unmanned Aircraft Systems

In traditional software development methodologies, operational and functional requirements of systems are often specified in structured natural language notations. These restricted notations provide good documentation support, but only provide limited support for semantic analysis. These notations are generally not rich enough to unambiguously specify the requirements of safety-critical systems that, for example, involve complex numerical computations or that interact with the physical environment. Examples of these safety-critical systems are autonomous vehicles such as unmanned aircraft systems. This talk advocates the use of expressive formal logics, such as higher-order logic, to specify the operational and functional requirement of unmanned systems and to prove the correctness of these requirements. Semantic analysis of requirements written in higher-order logic is supported through the use of interactive theorem provers. Formal models serve as ideal reference implementations of functional requirements. Hence, formal logics enable software validation techniques where software implementations can be checked against functional requirements in a mechanical way. The Formal Methods group in the Safety-Critical Avionics Systems Branch at NASA Langley Research Center has conducted research on the development and application of formal verification techniques to safety-critical applications of interest to NASA for more than 30 years. This talk illustrates the use of formal methods in the development of highly-assured autonomous unmanned aircraft systems.

Formal Methods↗

Development and demonstration of manufacturing processes for fabricating graphite/PMR-15 polyimide structural elements

The processing requirements for graphite/PMR-15 polyimide composites developed to demonstrate the structural integrity of polyimide composite structural elements at temperatures up to 589K (600 F) are described. Major tasks included: quality assurance development; materials and process development; specification verification; flat panel fabrication; stiffened panel fabrication; honeycomb panel fabrication; chopped fiber moldings; and demonstration component fabrication. Materials, processing, and quality assurance documents were prepared from experimentally derived data. Structural elements consisting of flat panels, corrugated stiffeners, I-beams, hat stiffeners, honeycomb panels, and chopped fiber moldings were made and tested. Property data from 219K (-65 F) to 589K (600 F) were obtained. All elements were made in a production environment. The size of each element was sufficient to insure production capability and structural component applicability. Problems associated with adhesive bonding, laminate and structural element analysis, material variability, and test methods were addressed.

Sheppard, C. H.↗

International Space Station (ISS) Accommodation of a Single US Assured Crew Return Vehicle (ACRV)

The following report was generated to give the International Space Station (ISS) Program some additional insight into the operations and issues associated with accommodating a single U.S. developed Assured Crew Return Vehicle (ACRV). During the generation of this report, changes in both the ISS and ACRV programs were factored into the analysis with the realization that most of the work performed will eventually need to be repeated once the two programs become more integrated. No significant issues associated with the ISS accommodating the ACRV were uncovered. Kinematic analysis of ACRV installation showed that there are viable methods of using Shuttle and Station robotic manipulators. Separation analysis demonstrated that the ACRV departure path clears the Station structure for all likely contingency scenarios. The payload bay packaging analysis identified trades that can be made between payload bay location, Shuttle Remote Manipulator System (SRMS) reach and eventual designs of de-orbit stages and docking adapters.

Mazanek, Daniel D.↗

Software assurance of autonomous spacecraft control

The work described addresses assurance of a planning and execution software system being added to an in-orbit CubeSat to demonstrate autonomous control of that spacecraft. Our focus was on how to develop assurance of the correct operation of the added software in its operational context, our approach to which was to use an assurance case to guide and organize the information involved.

Bocchino, Robert↗

Advanced composite elevator for Boeing 727 aircraft

Detail design activities are reported for a program to develop an advanced composites elevator for the Boeing 727 commercial transport. Design activities include discussion and results of the ancillary test programs, sustaining efforts, weight status, manufacturing producibility studies, quality assurance development, and production status.

Source record↗

NeuroSymbolic Approaches as a Vector for Assured Artificial Intelligence

The deployment of artificial intelligence systems in critical applications requires higher levels of assurance for safety, security, and interpretability. While neurosymbolic (NESY) approaches combining neural networks with symbolic reasoning offer potential advantages for assured AI, existing differentiable neurosymbolic frameworks face significant limitations including computational overhead and performance constraints. This report investigates the ISED (InferSampleEstimateDescend) framework as an alternative approach that enables neurosymbolic learning without requiring endtoend differentiability. We evaluate ISED’s utility for geointelligence applications by comparing neurosymbolic models against standard neural networks on aircraft classification tasks using the RarePlanes and MTARSI imagery datasets. Our results demonstrate that while ISEDbased models achieve slightly lower accuracy (89.7% vs 92.1% on RarePlanes; 91.1% vs 92.5% on MTARSI), they provide critical explainability capabilities that enable tracing incorrect predictions back to specific attribute misclassifications. We also present an automated pipeline that generates both attributeclass mappings and neurosymbolic model architectures from natural language descriptions, significantly reducing the manual effort required for NESY model deployment. These findings suggest that ISED offers a promising direction for developing assured AI systems where interpretability and reasoning transparency are prioritized alongside performance.

97 MATHEMATICS AND COMPUTING↗

Bosch CO2 Reduction System Development

Refinements in the design of a Bosch CO2 reduction unit for spacecraft O2 production are described. Sealing of the vacuum insulation jacket was simplified so that high vacuum and high insulation performance are easily maintained. The device includes a relatively simple concentric shell recuperative heat exchanger which operates at approximately 95% temperature effectiveness and helps lower power consumption. The influence of reactor temperature, pressure, and recycle gas composition on power consumption was investigated. In general, precise control is not required since power consumption is not very sensitive to moderate variations of these parameters near their optimum values. There are two process rate control modes which match flow rate to process demand. Catalyst conditioning, support, and packing pattern developments assure consistent starts, reduced energy consumption, and extended cartridge life. Operation levels for four or five men were maintained with overall power input values of 50 to 60 watts per man.

Holmes, R. F.↗

Spacelab Data Processing Facility (SLDPF) quality assurance expert systems development

Spacelab Data Processing Facility (SLDPF) expert system prototypes have been developed to assist in the quality assurance of Spacelab and/or Attached Shuttle Payload (ASP) processed telemetry data. SLDPF functions include the capturing, quality monitoring, processing, accounting, and forwarding of mission data to various user facilities. Prototypes for the two SLDPF functional elements, the Spacelab Output Processing System and the Spacelab Input Processing Element, are described. The prototypes have produced beneficial results including an increase in analyst productivity, a decrease in the burden of tedious analyses, the consistent evaluation of data, and the providing of concise historical records.

Kelly, Angelita C.↗

Spacelab Data Processing Facility (SLDPF) quality assurance expert systems development

Spacelab Data Processing Facility (SLDPF) expert system prototypes were developed to assist in the quality assurance of Spacelab and/or Attached Shuttle Payload (ASP) processed telemetry data. The SLDPF functions include the capturing, quality monitoring, processing, accounting, and forwarding of mission data to various user facilities. Prototypes for the two SLDPF functional elements, the Spacelab Output Processing System and the Spacelab Input Processing Element, are described. The prototypes have produced beneficial results including an increase in analyst productivity, a decrease in the burden of tedious analyses, the consistent evaluation of data, and the providing of concise historical records.

Kelly, Angelita C.↗

Application of SAE ARP4754A to Flight Critical Systems

This report documents applications of ARP4754A to the development of modern computer-based (i.e., digital electronics, software and network-based) aircraft systems. This study is to offer insight and provide educational value relative to the guidelines in ARP4754A and provide an assessment of the current state-of-the- practice within industry and regulatory bodies relative to development assurance for complex and safety-critical computer-based aircraft systems.

Peterson, Eric M.↗

Electrified Aircraft Propulsion Systems: Potential Failure Modes and Failure Mitigation Strategies

Electrified aircraft propulsion (EAP) systems hold great potential for the reduction of aircraft fuel burn, emissions, and noise. Currently, NASA and other organizations are actively working to identify and mature technologies necessary to bring EAP designs to reality. A requirement for the development of any civil aircraft and its systems is to ensure that potential hazards in the design are identified and appropriately mitigated to ensure that the system is safe. During aircraft development, a system safety assessment that consists of a functional hazard assessment is conducted to identify all potential failure conditions of each function, and classify those failures according to the severity of their effects on the aircraft or its occupants. The more severe a function's failure condition classification, the greater the development assurance level required for the function to ensure that the probability of the hazard is acceptably low. Today, aircraft engines and their control systems receive type certificate approval as a stand-alone system to signify their airworthiness. However, the complex coupling and distributed nature of EAP designs are expected to place added challenges on the certification of these systems. This presentation will provide an initial high-level review of the potential failure modes and hazards posed by a generic EAP system along with potential mitigation strategies for those failures. The EAP system is assumed to be a hybrid design consisting of gas turbine engines, mechanical drives, electric machines, power electronics and distribution systems, energy storage devices, and motor driven propulsors. The functionality provided by each of these EAP subsystems will be discussed along with the potential failure modes they may encounter. This will include a discussion of coupled failure effects, where a fault in one EAP subsystem effects the operation of other subsystems in the architecture. Next, potential failure mitigation strategies are discussed including both software-based and hardware-based mitigation strategies. The presentation will conclude with an example evaluation of the potential failure modes and mitigation strategies for a concept EAP system proposed by NASA.

Simon, Donald L.↗

Spacelab Data Processing Facility (SLDPF) quality assurance expert systems development

The Spacelab Data Processing Facility (SLDPF) is an integral part of the Space Shuttle data network for missions that involve attached scientific payloads. Expert system prototypes were developed to aid in the performance of the quality assurance function of the Spacelab and/or Attached Shuttle Payloads processed telemetry data. The Spacelab Input Processing System (SIPS) and the Spacelab Output Processing System (SOPS), two expert systems, were developed to determine their feasibility and potential in the quality assurance of processed telemetry data. The capabilities and performance of these systems are discussed.

Basile, Lisa R.↗