Search NASA⌕ Search

SEARCH · Search NASA

Results for “System Level Verification”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

System level verification applying the Space Shuttle experience to the Space Station

The applicability of the verification process for the Shuttle guidance, navigation and control (GNC) and data management system (DMS) for the development of the Space Station are described. Shuttle avionics hardware/software integration was delayed to finalize the hardware design before detailed definition and testing of the software. A block diagram is provided of the flight simulation laboratory used to test the GNC programs before flight data were available. The Station will have distributed computers, unlike the Orbiter, and will only be assembled fully in space. Standardized integration simulation test equipment are being defined to guide the development of hardware and software. The simulation capability may become part of nominal in-flight operations to initiate new capabilities as they are added to the Station. The Station GNC and DMS systems development will be somewhat simplified relative to those of the Shuttle because ascent and reentry will not be considered for the Station.

Gilbert, David W.↗

Real-Time Embedded Software Verification and Validation 2001

As the space applications become more complex and timing constraints on control actions are more stringent, the task of integrating and testing NASA's real-time systems (such as X-38 Crew Return Vehicle, and certain International Space Station autonomous systems) has become a great challenge. A testing environment where can preserve consistent temporal behaviors as in the target execution must be established for system-level verification and software quality assurance. Our goal is to develop an analysis suite for validation and verification of real-time systems that are used to perform human- in-the-loop control operations during safety-critical missions. The suite will be able to carry out quantitative approaches of coverage diagnostic and temporal behavior evaluation in order to measure test coverage, to optimize test utilization, and to verify timing correctness.

Lee, Yann-Hang↗

An Update on the Role of Systems Modeling in the Design and Verification of the James Webb Space Telescope

The James Web Space Telescope (JWST) is a large, infrared-optimized space telescope scheduled for launch in 2014. System-level verification of critical performance requirements will rely on integrated observatory models that predict the wavefront error accurately enough to verify that allocated top-level wavefront error of 150 nm root-mean-squared (rms) through to the wave-front sensor focal plane is met. The assembled models themselves are complex and require the insight of technical experts to assess their ability to meet their objectives. This paper describes the systems engineering and modeling approach used on the JWST through the detailed design phase.

Muheim, Danniella↗

The Role of Integrated Modeling in the Design and Verification of the James Webb Space Telescope

The James Web Space Telescope (JWST) is a large, infrared-optimized space telescope scheduled for launch in 2011. System-level verification of critical optical performance requirements will rely on integrated modeling to a considerable degree. In turn, requirements for accuracy of the models are significant. The size of the lightweight observatory structure, coupled with the need to test at cryogenic temperatures, effectively precludes validation of the models and verification of optical performance with a single test in 1-g. Rather, a complex series of steps are planned by which the components of the end-to-end models are validated at various levels of subassembly, and the ultimate verification of optical performance is by analysis using the assembled models. This paper describes the critical optical performance requirements driving the integrated modeling activity, shows how the error budget is used to allocate and track contributions to total performance, and presents examples of integrated modeling methods and results that support the preliminary observatory design. Finally, the concepts for model validation and the role of integrated modeling in the ultimate verification of observatory are described.

Mosier, Gary E.↗

Crew Exploration Vehicle (CEV) Avionics Integration Laboratory (CAIL) Independent Analysis

Two approaches were compared to the Crew Exploration Vehicle (CEV) Avionics Integration Laboratory (CAIL) approach: the Flat-Sat and Shuttle Avionics Integration Laboratory (SAIL). The Flat-Sat and CAIL/SAIL approaches are two different tools designed to mitigate different risks. Flat-Sat approach is designed to develop a mission concept into a flight avionics system and associated ground controller. The SAIL approach is designed to aid in the flight readiness verification of the flight avionics system. The approaches are complimentary in addressing both the system development risks and mission verification risks. The following NESC team findings were identified: The CAIL assumption is that the flight subsystems will be matured for the system level verification; The Flat-Sat and SAIL approaches are two different tools designed to mitigate different risks. The following NESC team recommendation was provided: Define, document, and manage a detailed interface between the design and development (EDL and other integration labs) to the verification laboratory (CAIL).

Davis, Mitchell L.↗

Modeling the TPF interferometer

The Terrestrial Planet Finder interferometer design concepts are large and complex systems that must operate in environments that are impractical to reproduce in preflight testing. The structurally-connected design is 36 meters long - longer than all but one thermal vacuum chamber in existence. The formation flying design will be comprised of up to five separate spacecraft, each with a sunshield over 15 meters on a side, and is designed to operate with formation sizes spanning over 100 meters to very close formations. System-level verification of the performance of the designs will need to rely on analytical modeling. The effort to model the many physical aspects of the designs under study is under way*. This paper describes the program of modeling for the TPF-I concepts. The program includes a number of types of models, such as the standard stand-alone optics, thermal, and structural models, as well as an end-to-end performance model of the project system called the Observatory Simulation. Aspects of each model are discussed including the purpose, methods of implementation (software applications), and approaches to validation. Program-level considerations (such as model-to-model integration and configuration management) are also discussed. Given that there are at least seven different organizations contributing to model developments and more than twenty separate models, these are special challenges.

Henry, Curt↗

Systems Engineering on the James Webb Space Telescope

The James Web Space Telescope (JWST) is a large, infrared-optimized space telescope scheduled for launch in 2014. System-level verification of critical performance requirements will rely on integrated observatory models that predict the wavefront error accurately enough to verify that allocated top-level wavefront error of 150 nm root-mean-squared (rms) through to the wave-front sensor focal plane is met. This paper describes the systems engineering approach used on the JWST through the detailed design phase.

Menzel, Michael T.↗

Formally Verified ZTA Requirements for OT/ICS Environments with Isabelle/HOL

The clean energy transformation includes the integration of distributed energy resources with the power grid, which has led to a substantial increase in the complexity of power grids infrastructure and the underlying operational technology environment. Power grids infrastructure represents an operational technology environment that has become a system of systems, integrating heterogeneous devices which are both software-and hardware-intensive; as a result, there are increasing demands to exploit advances in the commodity of software-hardware infrastructures to improve energy systems requirements such as cybersecurity and resilience. In such a setting, system requirements at different levels mix, which leads to vulnerabilities and undesirable outcomes. The use of formal methods to characterize and prove system requirements removes ambiguity, increases automation, and provides high levels of assurance and reliability. In this paper, we contribute a methodology and a framework for the system-level verification of zero trust architecture requirements in operational technology environments. We define a formal specification for the core functionalities of operational technology environments, the corresponding invariants, and security proofs. Of particular note is our modular approach for the formal verification of asynchronous interactions in operational technology environments. The formal specification and the proofs have been mechanized using the interactive theorem proving environment Isabelle/HOL.

formal methods↗

Cooperative GN&C development in a rapid prototyping environment

The Navigation, Control and Aeronautics Division (NCAD) at NASA-JSC is exploring ways of producing Guidance, Navigation and Control (GN&C) flight software faster, better, and cheaper. To achieve these goals NCAD established two hardware/software facilities that take an avionics design project from initial inception through high fidelity real-time hardware-in-the-loop testing. Commercially available software products are used to develop the GN&C algorithms in block diagram form and then automatically generate source code from these diagrams. A high fidelity real-time hardware-in-the-loop laboratory provides users with the capability to analyze mass memory usage within the targeted flight computer, verify hardware interfaces, conduct system level verification, performance, acceptance testing, as well as mission verification using reconfigurable and mission unique data. To evaluate these concepts and tools, NCAD embarked on a project to build a real-time 6 DOF simulation of the Soyuz Assured Crew Return Vehicle flight software. To date, a productivity increase of 185 percent has been seen over traditional NASA methods for developing flight software.

Bordano, Aldo↗

Towards Formalization of Advanced Linear Algebra with Applications to Dynamical Systems using PVS

Linear Algebra is essential for numerous aerospace problems of interest. Formal reasoning about hybrid systems that contain variables modeled by differential equations rely on concepts from Linear Algebra such as eigenvalues, matrix decompositions, and matrix valued functions. For example, the long-term dynamics of a system of differential equations depend on the stability/instability of its equilibrium points, which often reduces to an eigenvalue problem. This talk will embark on a quest to formalize theorems and results about eigenvalues and eigenvectors using PVS. We shall start our journey with 2 x 2 complex matrices, where we will apply our PVS code to a simple example of a dynamical system. Since it can be difficult or impossible to give simple expressions of eigenvalues for larger matrices (i.e. 5 x 5 or higher), we then move towards specifying the power method for verified computation of eigenvalue approximations in PVS. This effort requires development of multivariate complex arithmetic. At the end of the day, having such additions to the PVS NASA libraries will help move towards the use of formal methods to verify concepts of control theory and system level verification.

Linear Algebra↗

Manager's Role in Electromagnetic Interference (EMI) Control

This presentation captures the essence of electromagnetic compatibility (EMC) engineering from a project manager's perspective. It explains the basics of EMC and the benefits to the project of early incorporation of EMC best practices. The EMC requirement products during a project life cycle are identified, along with the requirement verification methods that should be utilized. The goal of the presentation is to raise awareness and simplify the mystique surrounding electromagnetic compatibility for managers that have little or no electromagnetics background

Safety↗

Apollo experience report: Electronic systems test program accomplishments and results

A chronological record is presented of the Electronic Systems Test Program from its conception in May 1963 to December 1969. The original concept of the program, which was primarily a spacecraft/Manned Space Flight Network communications system compatibility and performance evaluation, is described. The evolution of these concepts to include various levels of test detail, as well as systems level design verification testing, is discussed. Actual implementation of these concepts is presented, and the facility to support the program is described. Test results are given, and significant contributions to the lunar landing mission are underlined. Plans for modifying the facility and the concepts, based on Apollo experience, are proposed.

Ohnesorge, T. E.↗

Use of a Passive Reaction Wheel Jitter Isolation System to Meet the Advanced X-Ray Astrophysics Facility Imaging Performance Requirements

Third in the series of NASA great observatories, the Advanced X-Ray Astrophysics Facility (AXAF) is scheduled for launch from the Space Shuttle in November of 1998. Following in the path of the Hubble Space Telescope and the Compton Gamma Ray Observatory, this observatory will image light at X-ray wavelengths, facilitating the detailed study of such phenomena as supernovae and quasars. The AXAF project is sponsored by the Marshall Space Flight Center in Huntsville, Alabama. Because of exacting requirements on the performance of the AXAF optical system, it was necessary to reduce the transmission of reaction wheel jitter disturbances to the observatory. This reduction was accomplished via use of a passive mechanical isolation system to interface the reaction wheels with the spacecraft central structure. In addition to presenting a description of the spacecraft, the isolation system, and the key image quality requirement flowdown, this paper details the analyses performed in support of system-level imaging performance requirement verification. These analyses include the identification of system-level requirement suballocations, quantification of imaging and pointing performance, and formulation of unit-level isolation system transmissibility requirements. Given in comparison to the non-isolated system imaging performance, the results of these analyses clearly illustrate the effectiveness of an innovative reaction wheel passive isolation system.

Pendergast, Karl J.↗

Recommendations on the Use of Commercial-Off-The-Shelf (COTS) Electrical, Electronic, and Electromechanical (EEE) Parts for NASA Missions - Phase II

This assessment had two Phases. Phase I captured NASA Centers’ current practices for commercial-off-the-shelf (COTS) Electrical, Electronic, and Electromechanical (EEE) parts 1 used in spaceflight systems and ground support equipment (available at https://ntrs.nasa.gov/citations/20205011579) [ref. 1]. The Phase II report provides guidance for selecting and using COTS parts in NASA missions. The approaches proposed in this report differ from current agency practices. This top-level executive summary touches on these new approaches for using COTS parts but does not provide the detailed information that is critical in understanding the rationale behind these new approaches. Readers will need to read the entire report to gain full understanding and effectively use the recommendations herein. NASA’s historical approach to selecting and applying parts has been to define certain parts, primarily specific classes of military specification (MIL-SPEC) parts, as “standard”, leaving all others, including COTS parts, as nonstandard. Standard parts typically are used without further testing (“use-as-is”). Nonstandard parts are subjected to initial screening and subsequent lot acceptance testing of representative samples from each procured lot per MIL-SPEC or similar requirements. Decades later, top-tier commercial part manufacturers have evolved significant manufacturing, statistical control, and technological improvements that can now provide parts as reliable or more reliable than MIL-SPEC parts, when used within their datasheet limits. Concurrently, the space science and exploration community’s needs demand technological advances unavailable with MIL-SPEC parts. This ongoing change necessitates using COTS parts for space missions. Properly selected COTS parts in appropriate applications can offer performance and supply availability advantages compared to MIL-SPEC parts. Their utility and demonstrated reliability result from large volumes and automated production and testing processes. However, careful review and a thorough understanding of their specifications (i.e., datasheet limitations) is needed, and verifying that manufacturer specifications and reliability meet space hardware application needs are necessary. This report recommends MIL-SPEC screening and non-radiation-related lot acceptance testing be reduced or eliminated in cases where evidence of sufficient quality and reliability exists for COTS parts. The extent of NASA's insight into COTS manufacturers and the amount and nature of the needed evidence will differ by mission and will likely be driven by a mission's resources and associated risk posture. To facilitate this goal, two new terminologies have been defined and described: “Industry Leading Parts Manufacturer (ILPM)” and “Established COTS parts.” An ILPM is a COTS manufacturer that produces high quality and reliable parts. Some parts produced by ILPMs, defined as Established COTS parts, do not need any additional MIL-SPEC or NASA screening and lot acceptance testing to be used in space applications. This report provides guidance for selecting, procuring, and applying COTS parts and for performing part-, board-, and system-level COTS parts verification. The recommendation to select Established COTS parts from ILPMs will assure those COTS parts will have comparable quality to corresponding MIL-SPEC parts. Selecting, applying, and verifying Established COTS parts from ILPMs requires a holistic team approach, engaging parts engineers, circuit designers, quality, reliability, and systems engineers, procurement specialists, radiation specialists, avionics leads, and program/project managers. A mission-specific approach tailored to a project’s Mission, Environment, Applications and Lifetime (MEAL) [ref. 2] requirements should be developed and approved by program/project managers. Any associated risks should be clearly identified, quantified, mitigated, and/or accepted. Different approaches are recommended according to program/project Risk Classes A, B, C, and D [ref. 3] and human-rated missions [ref. 4]: 1. Recommend Classes A and B and human-rated missions consider a “MIL-SPEC parts- based design” approach. ”MIL-SPEC parts-based design” approach is one in which most parts are MIL-SPEC parts and Established COTS parts from ILPMs are used only when an equivalent MIL-SPEC part does not meet functional or size, weight, and power (SWaP) or performance requirements, or is not available. 2. Recommend Classes D and Sub-D missions consider a “System of COTS” approach. “System of COTS” approach is one which most parts are Established COTS parts from ILPMs. 3. Recommend Class C missions determine which approach is the best for their projects; that is, use either a “MIL-SPEC parts-based design” approach, “System of COTS” approach, or a combined approach utilizing elements of both. This report intends to provide guidance in using COTS parts for NASA missions with risk classifications of A through D and human-rated missions; but it does not address the costs of using COTS parts. Costs of using COTS parts in different NASA mission classes can vary significantly even if the same parts are used in different risk postures, due to differing verification levels needed. The guidance does not distinguish between critical or non-critical systems, and a given project will need to apply the appropriate guidance based on their risk posture. The intended audience of this report are NASA personnel and commercial practitioners who support NASA’s spaceflight missions, including spaceflight program or project managers, parts engineers, parts manufacturers, radiation engineers, avionics engineers, system engineers, circuit design engineers, reliability engineers, safety and mission assurance (SMA) personnel, and parts procurement specialists. The NEPP Program will perform a pathfinder study to explore implementing the guidance in this NESC report. An ILPM verification process is not the same as conventional vendor qualification processes performed according to military standards and specifications. This NESC report intends to provide guidance in utilizing available parts data from ILPM manufacturers for parts assurance assessments needed for NASA missions. The report also captured the current practices from DoD and Federal Aviation Administration (FAA) in Section 10. Note each DoD and FAA report was provided by the corresponding agencies regarding their practices, which are independent from the NESC recommendations in the report.

Commercial-Off-The-Shelf↗

Protoflight photovoltaic power module system-level tests in the space power facility

Work Package Four, which includes the NASA-Lewis and Rocketdyne, has selected an approach for the Space Station Freedom Photovoltaic (PV) Power Module flight certification that combines system level qualification and acceptance testing in the thermal vacuum environment: The protoflight vehicle approach. This approach maximizes ground test verification to assure system level performance and to minimize risk of on-orbit failures. The preliminary plans for system level thermal vacuum environmental testing of the protoflight PV Power Module in the NASA-Lewis Space Power Facility (SPF), are addressed. Details of the facility modifications to refurbish SPF, after 13 years of downtime, are briefly discussed. The results of an evaluation of the effectiveness of system level environmental testing in screening out incipient part and workmanship defects and unique failure modes are discussed. Preliminary test objectives, test hardware configurations, test support equipment, and operations are presented.

Rivera, Juan C.↗

Protoflight photovoltaic power module system-level tests in the Space Power Facility

Work Package Four, which includes the NASA-Lewis and Rocketdyne, has selected an approach for the Space Station Freedom Photovoltaic (PV) Power Module flight certification that combines system level qualification and acceptance testing in the thermal vacuum environment: the 'protoflight' vehicle approach. This approach maximizes ground test verification to assure system level performance and to minimize risk of on-orbit failures. The preliminary plans for system level thermal vacuum environmental testing of the protoflight PV Power Module in the NASA-Lewis Space Power Facility (SPF) are addressed. Details of the facility modifications to refurbish SPF, after 13 years of downtime, are briefly discussed. The results of an evaluation of the effectiveness of system level environmental testing in screening out incipient part and workmanship defects and unique failure modes are discussed. Preliminary test objectives, test hardware configurations, test support equipment, and operations, are presented.

Rivera, Juan C.↗

Assume-Guarantee Verification of Source Code with Design-Level Assumptions

Model checking is an automated technique that can be used to determine whether a system satisfies certain required properties. To address the 'state explosion' problem associated with this technique, we propose to integrate assume-guarantee verification at different phases of system development. During design, developers build abstract behavioral models of the system components and use them to establish key properties of the system. To increase the scalability of model checking at this level, we have developed techniques that automatically decompose the verification task by generating component assumptions for the properties to hold. The design-level artifacts are subsequently used to guide the implementation of the system, but also to enable more efficient reasoning at the source code-level. In particular we propose to use design-level assumptions to similarly decompose the verification of the actual system implementation. We demonstrate our approach on a significant NASA application, where design-level models were used to identify; and correct a safety property violation, and design-level assumptions allowed us to check successfully that the property was presented by the implementation.

Giannakopoulou, Dimitra↗