Engineering PapersSearch

Engineering topics

Dunn, William R.

Publications and source records attributed to Dunn, William R..

How Safe Is Control Software

Paper examines issue of software safety. Presents four case histories of software-safety analysis. Concludes that, to be safe, software, for all practical purposes, must be free of errors. Backup systems still needed to prevent catastrophic software failures.

Dunn, William R.

Latent-failure risk estimates for computer control

It is shown that critical computer controls employing unmonitored safety circuits are unsafe. Analysis supporting this result leads to two additional, important conclusions: (1) annual maintenance checks of safety circuit function do not, as widely believed, eliminate latent failure risk; (2) safety risk remains even if multiple, series-connected protection circuits are employed. Finally, it is shown analytically that latent failure risk is eliminated when continuous monitoring is employed.

Dunn, William R.

Software safety - A user's practical perspective

Software safety assurance philosophy and practices at the NASA Ames are discussed. It is shown that, to be safe, software must be error-free. Software developments on two digital flight control systems and two ground facility systems are examined, including the overall system and software organization and function, the software-safety issues, and their resolution. The effectiveness of safety assurance methods is discussed, including conventional life-cycle practices, verification and validation testing, software safety analysis, and formal design methods. It is concluded (1) that a practical software safety technology does not yet exist, (2) that it is unlikely that a set of general-purpose analytical techniques can be developed for proving that software is safe, and (3) that successful software safety-assurance practices will have to take into account the detailed design processes employed and show that the software will execute correctly under all possible conditions.

Dunn, William R.

RSRA/X-Wing flight control system development - Lessons learned

The X-Wing, in concept, marries the efficiencies of a helicopter and fixed wing aircraft through the use of a four-bladed wing/rotor that can be rotated or stopped in flight. The RSRA/X-Wing flight test program was a technology demonstration of this concept which, after three successful flights, was discontinued in late 1987. In spite of many technical challenges in this program, such as the use of circulation control, the fabrication of a large all-composite rotor, the development of an advanced, quadruplex digital flight control system, and the need for higher harmonic control, no major technical problems had been encountered at the time of the stop-work order. This paper addresses the issues of flight control system development and focuses on lessons learned. As with other such programs, software development was the most consuming issue. Other subjects of discussion include the problems of balancing program goals with technical goals, software- and hard-ware-related problems, safety issues, and system testing.

Corliss, Lloyd D.

Software reliability - Measures and effects in flight critical digital avionics systems

The paper discusses software reliability as it applies particularly to design and evaluation of flight-critical digital avionics systems. Measures of software reliability, measurement methods and reliability (macro-) models are discussed. Recent work assessing their accuracy in predicting software errors in 'fly-by-wire' Newtonian applications is presented. Additional, detailed topics are discussed including software error distributions (e.g. catastrophic vs. noncatastrophic) and the effects of system growth/maturity on reliability improvement. In practical flight-critical digital applications, software reliability improvement is sought through use of parallel, redundant software (i.e. N-version programming) or backup software that can be invoked in the event of (primary) software failure. Achievable reliability levels are however highly sensitive to common-mode specification and programming errors. Recent data correlating these errors with net software reliability are discussed.

Dunn, William R.