Establishing a Framework and Testbed for Evaluating and Infusing Software Assurance Tools
No abstract available
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
No abstract available
Portable, hand-held dimpling tool assures accurate brazed joints between tubes of different diameters. Prior to brazing, the tool performs precise dimpling and nipple forming and also provides control and accurate measuring of the height of nipples and depth of dimples so formed.
No abstract available
This is the Final Report of a research project to investigate issues and provide guidance for the qualification of formal methods tools under the DO-330 qualification process. It consisted of three major subtasks spread over two years: 1) an assessment of theoretical soundness issues that may affect qualification for three categories of formal methods tools, 2) a case study simulating the DO-330 qualification of two actual tool sets, and 3) an investigation of risk mitigation strategies that might be applied to chains of such formal methods tools in order to increase confidence in their certification of airborne software.
We investigate methods of estimating a background image frame for subtraction from a data frame for use when a more suitable measured background frame is not available. We define background as any signal component that is not attributable to the phenomenon currently under investigation. We describe a technique that is based on pixel-by-pixel least-squares regression of images for computing a background frame from available data. We argue that the same technique can be a useful quality-assurance tool for evaluating instrument performance. For example, it can help to separate image structure resulting from the reading process from structure resulting from the characteristics of the detector itself. We demonstrate that background estimation can be nontrivial by comparing the results of different background estimation procedures by using data obtained from a CCD array detector. We investigate the temperature-dependent contributions of the detector and readout electronics to the total signal as a demonstration of the diagnostic capabilities of least-squares image regression.
The “Watching the Watchers” project studied the problem of establishing assurance cases for tools that are used to assure other things. Specifically, we were interested in understanding the tools and techniques one could apply to software to build an assurance case to evaluate their applicability, difficulty, level of assurance provided, and scalability. To do so we chose a set of use cases of relevance to LLNL and our various DOE and non-DOE partners and developed demonstrators to perform this evaluation. Our key focal point was around additive manufacturing problems and assurance gaps that we identified in the additive manufacturing workflow from start to completion. We also explored other areas related to AI, data analysis, and concurrent programming. Follow-on research is planned to take our prototypes from this project and adapt and mature them to fit LLNL mission applications.
In a study, that introduced ground-based separation assurance automation through a series of envisioned transitional phases of concept maturity, it was found that subjective responses to scales of workload, situation awareness, and acceptability in a post run questionnaire revealed as-predicted results for three of the four study conditions but not for the third, Moderate condition. The trend continued for losses of separation (LOS) where the number of LOS events were far greater than expected in the Moderate condition. To offer an account of why the Moderate condition was perceived to be more difficult to manage than predicted, researchers examined the increase in amount and complexity of traffic, increase in communication load, and increased complexities as a result of the simulation's mix of aircraft equipage. Further analysis compared the tools presented through the phases, finding that controllers took advantage of the informational properties of the tools presented but shied away from using their decision support capabilities. Taking into account similar findings from other studies, it is suggested that the Moderate condition represented the first step into a "shared control" environment, which requires the controller to use the automation as a decision making partner rather than just a provider of information. Viewed in this light, the combination of tools offered in the Moderate condition was reviewed and some tradeoffs that may offset the identified complexities were suggested.
This report summarizes a three-hour hybrid in-person/online workshop on June 7, 2024 on the topic of design assurance and the Safety Demonstrator Series (SDS), which was held at NASA Ames Research Center. The SDS provides an operational demonstration of, and recommendations for, requirements and standards necessary to monitor, assess, and mitigate risks to assure safety in disaster-oriented operations. Over sixty NASA personnel participated in the workshop. Four main topics were discussed: (1) assurance needs for the Safety Demonstrator Series, (2) assurance and the In-Time Aviation Safety Management System (IASMS), (3) in-time assurance: existing efforts and future opportunities, and (4) demonstrating assurance tools in the Safety Demonstrators. Key takeaways are as follows: 1. Design assurance tools can be used to assure an In-Time Aviation Safety Management System, the systems that comprise it, and other systems or missions. Assurance must consider both systems and components and include the interactions between elements in both a systems/aircraft context and a systems-of-systems/airspace context. 2. Design-time assurance activities can support the identification of monitors needed for operational assurance activities (i.e., the “monitor” function in the monitor-assess-mitigate paradigm at the heart of the IASMS concept). 3. A major opportunity for design-time assurance tools to contribute to the IASMS concept is to support rapid re-validation of systems. This will be particularly important for (1) supporting novel operations in the IASMS, where operational data may disprove design-time assumptions (motivating re-analysis of system safety) and (2) adapting technologies (e.g., AI/ML for autonomous operations) to new operational domains, where there may be new or different safety considerations not included in the initial scope of operations. 4. There are several design assurance tools under development in the System-Wide Safety project that can support assurance of Services, Functions, and Capabilities (SFCs) in the Safety Demonstrators. Transitioning these tools from one-off research projects into a functioning part of IASMS assurance will require closer integration between these tools. 5. It is not clear whether the role of design assurance tools is primarily as a part of IASMS architecture or as an external check on IASMS. The workshop consisted of four discussion topics initiated via four lightning talks by System-Wide Safety researchers. Discussions utilized Mural to engage both in-person and online participants in the hybrid format. Polls and surveys were also utilized to gather participant input. The workshop closed with a reflection activity for participants, as well as new ideas for collaboration and coordination of ongoing System-Wide Safety research.
Previously, several research tasks have been conducted, some observations were obtained, and several possible suggestions have been contemplated involving software quality assurance engineering at NASA Johnson. These research tasks are briefly described. Also, a brief discussion is given on the role of software quality assurance in software engineering along with some observations and suggestions. A brief discussion on a training program for software quality assurance engineers is provided. A list of assurance factors as well as quality factors are also included. Finally, a process model which can be used for searching and collecting software quality assurance tools is presented.
Exploration Mission-1 (EM-1) is an uncrewed mission that is launching on the Space Launch System (SLS) Block 1 vehicle. This is a critical flight test for the agency's human deep space exploration goals. Exploration Ground Systems (EGS) Quality (SA-F2) is responsible for providing Quality Assurance Surveillance Plans (QASPs) for NASA contracts and facilities. A QASP assures products and services are provided to EGS in accordance with the contract requirements. In order to encapsulate the multiple KSC Safety and Mission Assurance surveillance and audit activities that need to be accomplished specifically for EM-1 Certificate of Flight Reediness (CoFR), a QASP tool needed to be implemented. This tool would be able to intuitively track Work Authorization Documents (WADs) under development by Test Operations Support Contract (TOSC), reviewed and accepted WADs, Government Mandatory Inspection Points (GMIPs), Nonconformances (NCs), Material Review Board (MRB) Status, Corrective Actions, Alterations, Deviations, and Waivers for flight hardware and Ground Support Equipment (GSE). This would help ensure that all SLS EM-1 flight hardware and related GSE surveillances and requirements are being recognized and completed with zero constraints identified for the mission.
Ares is an integral part of NASA s Constellation architecture that will provide crew and cargo access to the International Space Station as well as low earth orbit support for lunar missions. Ares replaces the Space Shuttle in the post 2010 time frame. Ares I is an in-line, two-stage rocket topped by the Orion Crew Exploration Vehicle, its service module, and a launch abort system. The Ares I first stage is a single, five-segment reusable solid rocket booster derived from the Space Shuttle Program's reusable solid rocket motor. The Ares second or upper stage is propelled by a J-2X main engine fueled with liquid oxygen and liquid hydrogen. This paper describes the advanced systems engineering and planning tools being utilized for the design, test, and qualification of the Ares I first stage element. Included are descriptions of the current first stage design, the milestone schedule requirements, and the marriage of systems engineering, detailed planning efforts, and roadmapping employed to achieve these goals.
Topics concerning the Common Lunar Lander for the Space Exploration Initiative are covered and include the following: product assurance tools and supports; project goals; and product assurance structured for optimal payback.
The INL TADA GETs Cohort Session 2, held on November 7, 2025, conducted in collaboration with ScottMadden, focused on two core Advanced Transmission Technologies (ATTs): Advanced Power Flow Control (APFC) and Transmission Topology Optimization (TTO). These technologies are pivotal in enhancing grid flexibility, reliability, and cybersecurity resilience. APFC, particularly through modular FACTS devices like Modular Static Synchronous Series Compensators (M-SSSCs), enables dynamic voltage injection to reroute power flows. The session highlighted the deployment benefits of APFC, such as rapid installation, minimal civil works, and re-deployability. Regulatory drivers like FERC Order 2023 mandate the inclusion of Grid-Enhancing Technologies (GETs) in interconnection studies. Case studies from Central Hudson, CAISO, and National Grid (UK) demonstrated APFC’s effectiveness in congestion relief and cost savings. The session also addressed cybersecurity concerns, including firmware vulnerabilities, SCADA integration risks, and supply chain dependencies. Participants engaged in interactive exercises to rank cybersecurity and supply chain risks, emphasizing the need for robust digital assurance strategies. TTO involves software-based reconfiguration of transmission networks to optimize power flow without new infrastructure. The session showcased its operational value, with examples from SPP, PJM, and MISO showing significant congestion cost reductions. Cybersecurity vulnerabilities were discussed, particularly in API security and software supply chains, referencing incidents like SolarWinds and attacks on Danish utilities. Digital assurance exercises explored worst-case scenarios, attack paths, and mitigation responsibilities between vendors and utilities. Reliability challenges such as algorithm stability, vendor dependency, and operator trust were also examined. Cross-cutting themes emphasized the importance of digital assurance tools, including Software Bills of Materials (SBOMs) and hardware-in-loop testing. Human performance, training, and operational confidence were identified as critical enablers of technology adoption. The session concluded with a preview of Session 3, which will focus on High Performance Conductors (HPCs) and risk-based cybersecurity tools. Session 2 of 3.
Wind prediction errors are known to affect the performance of automated air traffic management tools that rely on aircraft trajectory predictions. In particular, automated separation assurance tools, planned as part of the NextGen concept of operations, must be designed to account and compensate for the impact of wind prediction errors and other system uncertainties. In this paper we describe a high fidelity batch simulation study designed to estimate the separation distance required to compensate for the effects of wind-prediction errors throughout increasing traffic density on an airborne separation assistance system. These experimental runs are part of the Safety Performance of Airborne Separation experiment suite that examines the safety implications of prediction errors and system uncertainties on airborne separation assurance systems. In this experiment, wind-prediction errors were varied between zero and forty knots while traffic density was increased several times current traffic levels. In order to accurately measure the full unmitigated impact of wind-prediction errors, no uncertainty buffers were added to the separation minima. The goal of the study was to measure the impact of wind-prediction errors in order to estimate the additional separation buffers necessary to preserve separation and to provide a baseline for future analyses. Buffer estimations from this study will be used and verified in upcoming safety evaluation experiments under similar simulation conditions. Results suggest that the strategic airborne separation functions exercised in this experiment can sustain wind prediction errors up to 40kts at current day air traffic density with no additional separation distance buffer and at eight times the current day with no more than a 60% increase in separation distance buffer.
The DAHCS (pronounced “Dax”) MC is a 7-year, $\$$45 million research portfolio within Sandia’s Laboratory Directed Research and Development program. The DAHCS MC arose in response to a great need: to ensure that the use of digital technologies does not weaken our nation’s high consequence systems. Digital technologies offer many benefits in speed, cost, and flexibility, and we seek to reap those benefits without introducing new system failures. However, digital technologies cannot be evaluated the same way as analog technologies. Initiatives across the nation highlight the capability gap that prevents efficient, effective digital assurance. The Challenge Today’s digital assurance tools, techniques, and methods are inadequate to confidently characterize, assess, and manage digital risk; they are ad hoc, slow, costly, and rarely scalable to increasingly complex digital technologies. The rapidly evolving cyber threat landscape exacerbates this problem because digital assurance now must secure against digital risks now and in the future, including those introduced by rapidly evolving technologies, adversaries, and systems.
To test equipment, welded tubing joints may have to be disconnected and rewelded. To eliminate rewelding, a nonstandard welding sleeve permits the tubing to be welded and then disconnected by a specially designed sleeve cutter. Use of this tool assures that only the sleeve is cut.
Marketed as the "Software of the Future," Optimal Engineering Systems P.I. EXPERT(TM) technology offers statistical process control and optimization techniques that are critical to businesses looking to restructure or accelerate operations in order to gain a competitive edge. Kennedy Space Center granted Optimal Engineering Systems the funding and aid necessary to develop a prototype of the process monitoring and improvement software. Completion of this prototype demonstrated that it was possible to integrate traditional statistical quality assurance tools with robust optimization techniques in a user- friendly format that is visually compelling. Using an expert system knowledge base, the software allows the user to determine objectives, capture constraints and out-of-control processes, predict results, and compute optimal process settings.
In this paper, we describe our experience with the challenges thar we are currently facing in our effort to develop advanced software verification and validation tools. We categorize these challenges into several areas: cost benefits modeling, tool usability, customer application domain, and organizational issues. We provide examples of challenges in each area and identrfj, open research issues in areas which limit our ability to transfer high-assurance software engineering tools into practice.