Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Formal Methods”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 253 records · Page 14

HDL to verification logic translator

The increasingly higher number of transistors possible in VLSI circuits compounds the difficulty in insuring correct designs. As the number of possible test cases required to exhaustively simulate a circuit design explodes, a better method is required to confirm the absence of design faults. Formal verification methods provide a way to prove, using logic, that a circuit structure correctly implements its specification. Before verification is accepted by VLSI design engineers, the stand alone verification tools that are in use in the research community must be integrated with the CAD tools used by the designers. One problem facing the acceptance of formal verification into circuit design methodology is that the structural circuit descriptions used by the designers are not appropriate for verification work and those required for verification lack some of the features needed for design. We offer a solution to this dilemma: an automatic translation from the designers' HDL models into definitions for the higher-ordered logic (HOL) verification system. The translated definitions become the low level basis of circuit verification which in turn increases the designer's confidence in the correctness of higher level behavioral models.

Gambles, J. W.↗

Scatter in Carbon/Silicon Carbide (C/SiC) Composites Quantified

Carbon-fiber-reinforced silicon carbide matrix (C/SiC) composites processed by chemical vapor infiltration are candidate materials for aerospace thermal structures. Carbon fibers can retain properties at very high temperatures, but they are known to have poor oxidation resistance in adverse, high-temperature environments. Nevertheless, the combination of CVI-SiC matrix with higher stiffness and oxidation resistance, the interfacial coating, and additional surface-seal coating provides the necessary protection to the carbon fibers, and makes the material viable for high-temperature space applications operating under harsh environments. Furthermore, C/SiC composites, like other ceramic matrix composites (CMCs), exhibit graceful non-catastrophic failure because of various inherent energy dissipating mechanisms. The material exhibits nonlinearity in deformation even at very low stress levels. This is the result of the severe matrix microcracking present in the as processed composite because of large differences between the coefficients of thermal expansion of the fiber and the matrix. Utilization of these advanced composites in next generation space vehicles will require innovative structural configurations, updated materials, and refined analyses. Structural safety issues for these vehicles are in direct competition with performance and cost. One would have to quantify the uncertainties associated with the design using formal probabilistic methods. Specifically four fundamental aspects on which analyses are based-- (1) loading conditions, (2) material behavior, (3) geometrical configurations, and (4) structural connections between the composite components and baseline structure--are stochastic in nature. A direct way to formally account for uncertainties is to develop probabilistic structural analysis methods where all participating variables are described by appropriate probability density functions. The present work, however, focuses on analyzing the stochastic material behavior of these advanced composites using formal probabilistic analysis methods. Often, some of the desirable property characteristics that allow composites to offer advantages over conventional structural materials (like tailoring of composite properties) and the complexity are in fact responsible for their greater statistical variability and the requirements for more characterization tests. Composite properties are anisotropic as well, having different properties in different directions. This means that characterization of a property such as stiffness--which will vary greatly depending on the orientation of the fiber relative to the direction of the testing--must be repeated for several different directions and loading conditions. The fabrication process for composites also introduces statistical variations in properties and geometry. A composite part is produced in a number of steps, each of which introduces statistical variability. The matrix is usually produced from a combination of raw materials; and the fiber, which has its own set of properties, is often coated or surface treated, introducing yet another source of variability.

Murthy, Pappu L. N.↗

Tidal Energy Available for Deep Ocean Mixing: Bounds from Altimetry Data

Maintenance of the large-scale thermohaline circulation has long presented a problem to oceanographers. Observed mixing rates in the pelagic ocean are an order of magnitude too small to balance the rate at which dense bottom water is created at high latitudes. Recent observational and theoretical work suggests that much of this mixing may occur in hot spots near areas of rough topography (e.g., mid-ocean ridges and island arcs). Barotropic tidal currents provide a very plausible source of energy to maintain these mixing processes. Topex/Poseidon (T/P) satellite altimetry data have made precise mapping of open ocean tidal elevations possible for the first time. We can thus obtain empirical, spatially localized, estimates of barotropic tidal dissipation. These provide an upper bound on the amount of tidal energy that is dissipated in the deep ocean, and hence is available for deep mixing. We will present and compare maps of open ocean tidal energy flux divergence, and estimates of tidal energy flux into shallow seas, derived from T/P altimetry data using both formal data assimilation methods and empirical approaches. With the data assimilation methods we can place formal error bars on the fluxes. Our results show that 20-25% of tidal energy dissipation occurs outside of the shallow seas, the traditional sink for tidal energy. This suggests that up to 1 TW of energy may be available from the tides (lunar and solar) for mixing the deep ocean. The dissipation indeed appears to be concentrated over areas of rough topography.

Egbert, Gary D.↗

Tidal Energy Available for Deep Ocean Mixing: Bounds from Altimetry Data

Maintenance of the large-scale thermohaline circulation has long presented an interesting problem. Observed mixing rates in the pelagic ocean are an order of magnitude too small to balance the rate at which dense bottom water is created at high latitudes. Recent observational and theoretical work suggests that much of this mixing may occur in hot spots near areas of rough topography (e.g., mid-ocean ridges and island arcs). Barotropic tidal currents provide a very plausible source of energy to maintain these mixing processes. Topex/Poseidon satellite altimetry data have made precise mapping of open ocean tidal elevations possible for the first time. We can thus obtain empirical, spatially localized, estimates of barotropic tidal dissipation. These provide an upper bound on the amount of tidal energy that is dissipated in the deep ocean, and hence is available for deep mixing. We will present and compare maps of open ocean tidal energy flux divergence, and estimates of tidal energy flux into shallow seas, derived from T/P altimetry data using both formal data assimilation methods and empirical approaches. With the data assimilation methods we can place formal error bars on the fluxes. Our results show that 20-25% of tidal energy dissipation occurs outside of the shallow seas, the traditional sink for tidal energy. This suggests that up to 1 TW of energy may be available from the tides (lunar and solar) for mixing the deep ocean. The dissipation indeed appears to be concentrated over areas of rough topography.

Ray, Richard D.↗

Tidal Energy Available for Deep Ocean Mixing: Bounds From Altimetry Data

Maintenance of the large-scale thermohaline circulation has long presented a problem to oceanographers. Observed mixing rates in the pelagic ocean are an order of magnitude too small to balance the rate at which dense bottom water is created at high latitudes. Recent observational and theoretical work suggests that much of this mixing may occur in hot spots near areas of rough topography (e.g., mid-ocean ridges and island arcs). Barotropic tidal currents provide a very plausible source of energy to maintain these mixing processes. Topex/Poseidon satellite altimetry data have made precise mapping of open ocean tidal elevations possible for the first time. We can thus obtain empirical, spatially localized, estimates of barotropic tidal dissipation. These provide an upper bound on the amount of tidal energy that is dissipated in the deep ocean, and hence is available for deep mixing. We will present and compare maps of open ocean tidal energy flux divergence, and estimates of tidal energy flux into shallow seas, derived from T/P altimetry data using both formal data assimilation methods and empirical approaches. With the data assimilation methods we can place formal error bars on the fluxes. Our results show that 20-25% of tidal energy dissipation occurs outside of the shallow seas, the traditional sink for tidal energy. This suggests that up to 1 TW of energy may be available from the tides (lunar and solar) for mixing the deep ocean. The dissipation indeed appears to be concentrated over areas of rough topography.

Egbert, Gary D.↗

Experimental validation of structural optimization methods

The topic of validating structural optimization methods by use of experimental results is addressed. The need for validating the methods as a way of effecting a greater and an accelerated acceptance of formal optimization methods by practicing engineering designers is described. The range of validation strategies is defined which includes comparison of optimization results with more traditional design approaches, establishing the accuracy of analyses used, and finally experimental validation of the optimization results. Examples of the use of experimental results to validate optimization techniques are described. The examples include experimental validation of the following: optimum design of a trussed beam; combined control-structure design of a cable-supported beam simulating an actively controlled space structure; minimum weight design of a beam with frequency constraints; minimization of the vibration response of helicopter rotor blade; minimum weight design of a turbine blade disk; aeroelastic optimization of an aircraft vertical fin; airfoil shape optimization for drag minimization; optimization of the shape of a hole in a plate for stress minimization; optimization to minimize beam dynamic response; and structural optimization of a low vibration helicopter rotor.

Adelman, Howard M.↗

Aerodynamic Optimization of Rocket Control Surface Geometry Using Cartesian Methods and CAD Geometry

Aerodynamic design is an iterative process involving geometry manipulation and complex computational analysis subject to physical constraints and aerodynamic objectives. A design cycle consists of first establishing the performance of a baseline design, which is usually created with low-fidelity engineering tools, and then progressively optimizing the design to maximize its performance. Optimization techniques have evolved from relying exclusively on designer intuition and insight in traditional trial and error methods, to sophisticated local and global search methods. Recent attempts at automating the search through a large design space with formal optimization methods include both database driven and direct evaluation schemes. Databases are being used in conjunction with surrogate and neural network models as a basis on which to run optimization algorithms. Optimization algorithms are also being driven by the direct evaluation of objectives and constraints using high-fidelity simulations. Surrogate methods use data points obtained from simulations, and possibly gradients evaluated at the data points, to create mathematical approximations of a database. Neural network models work in a similar fashion, using a number of high-fidelity database calculations as training iterations to create a database model. Optimal designs are obtained by coupling an optimization algorithm to the database model. Evaluation of the current best design then gives either a new local optima and/or increases the fidelity of the approximation model for the next iteration. Surrogate methods have also been developed that iterate on the selection of data points to decrease the uncertainty of the approximation model prior to searching for an optimal design. The database approximation models for each of these cases, however, become computationally expensive with increase in dimensionality. Thus the method of using optimization algorithms to search a database model becomes problematic as the number of design variables is increased.

Nelson, Andrea↗

Probabilistic Unsteady Aerodynamic Analysis

Probabilistic CFD design is needed because we are asked to do more with less. To cost effectively accomplish the design task, we need to formally quantify the effect of uncertainties (variables) in the design. Probabilistic design is one effective method to formally quantify the effect of uncertainties. Our objective is to establish a revolutionary new early design process, by developing non-deterministic physics-based probabilistic design tools, which will include all the life cycle processes. This work was concerned with the usefulness of parametric optimization method coupled with a Navier-Stokes analysis code for the aero-thermodynamic design of turbomachinery combustor liner. The interconnection between the CFD code and NESSUS codes will facilitate the coupling between the thermal profiles and structural design. We have developed new concepts for reducing the computational cost of unsteady, three-dimensional, compressible aerodynamic analyses for multistage turbomachinery flows. The flow was modeled by the three-dimensional Favre-Reynolds-averaged Navier-Stokes equations using the k-E turbulence closure, which was integrated using an implicit third-order upwind solver. The methodology developed in this work is expected to lead to the design optimization of turbomachinery blades.

Gorla, Rama S. R.↗

Probabilistic Study of Fluid Structure Interaction

Probabilistic CFD design is needed because we are asked to do more with less. To cost effectively accomplish the design task, we need to formally quantify the effect of uncertainties (variables) in the design. Probabilistic design is one effective method to formally quantify the effect of uncertainties. Our objective is to establish a revolutionary new early design process, by developing non-deterministic physics-based probabilistic design tools, which will include all the life cycle processes. Breakthroughs will be sought in speed, accuracy, intelligence, and usability of the system. This paper is concerned with the usefulness of parametric optimization method coupled with a Navier-Stokes analysis code for the aero-thermodynamic design of turbomachinery combustor liner. The interconnection between the CFD code and NESSUS codes facilitated the coupling between the thermal profiles and structural design. We have developed new concepts for reducing the computational cost of unsteady, three-dimensional, compressible aerodynamic analyses for multistage turbomachinery flows. The flow was modeled by the three-dimensional Favre-Reynolds-averaged Navier-Stokes equations using the k-epsilon turbulence closure, which was integrated using an implicit third-order upwind solver. The methodology developed in this paper is expected to lead to the design optimization of turbomachinery blades.

Gorla, Rama S. R.↗

Fuzzy Logic Controller Stability Analysis Using a Satisfiability Modulo Theories Approach

While many widely accepted methods and techniques exist for validation and verification of traditional controllers, at this time no solutions have been accepted for Fuzzy Logic Controllers (FLCs). Due to the highly nonlinear nature of such systems, and the fact that developing a valid FLC does not require a mathematical model of the system, it is quite difficult to use conventional techniques to prove controller stability. Since safety-critical systems must be tested and verified to work as expected for all possible circumstances, the fact that FLC controllers cannot be tested to achieve such requirements poses limitations on the applications for such technology. Therefore, alternative methods for verification and validation of FLCs needs to be explored. In this study, a novel approach using formal verification methods to ensure the stability of a FLC is proposed. Main research challenges include specification of requirements for a complex system, conversion of a traditional FLC to a piecewise polynomial representation, and using a formal verification tool in a nonlinear solution space. Using the proposed architecture, the Fuzzy Logic Controller was found to always generate negative feedback, but inconclusive for Lyapunov stability.

Fuzzy Logic Controller↗

Fuzzy Logic Controller Stability Analysis Using a Satisfiability Modulo Theories Approach

While many widely accepted methods and techniques exist for validation and verification of traditional controllers, at this time no solutions have been accepted for Fuzzy Logic Controllers (FLCs). Due to the highly nonlinear nature of such systems, and the fact that developing a valid FLC does not require a mathematical model of the system, it is quite difficult to use conventional techniques to prove controller stability. Since safety-critical systems must be tested and verified to work as expected for all possible circumstances, the fact that FLC controllers cannot be tested to achieve such requirements poses limitations on the applications for such technology. Therefore, alternative methods for verification and validation of FLCs needs to be explored. In this study, a novel approach using formal verification methods to ensure the stability of a FLC is proposed. Main research challenges include specification of requirements for a complex system, conversion of a traditional FLC to a piecewise polynomial representation, and using a formal verification tool in a nonlinear solution space. Using the proposed architecture, the Fuzzy Logic Controller was found to always generate negative feedback, but inconclusive for Lyapunov stability.

Fuzzy Logic Controller↗

Formal Assurance for Cognitive Architecture Based Autonomous Agent

Autonomous systems are designed and deployed in different modeling paradigms. These environments focus on specific concepts in designing the system. We focus our effort in the use of cognitive architectures to design autonomous agents to collaborate with humans to accomplish tasks in a mission. Our research focuses on introducing formal assurance methods to verify the behavior of agents designed in Soar, by translating the agent to the formal verification environment Uppaal.

Bhattacharyya, Siddhartha↗

Software safety - A user's practical perspective

Software safety assurance philosophy and practices at the NASA Ames are discussed. It is shown that, to be safe, software must be error-free. Software developments on two digital flight control systems and two ground facility systems are examined, including the overall system and software organization and function, the software-safety issues, and their resolution. The effectiveness of safety assurance methods is discussed, including conventional life-cycle practices, verification and validation testing, software safety analysis, and formal design methods. It is concluded (1) that a practical software safety technology does not yet exist, (2) that it is unlikely that a set of general-purpose analytical techniques can be developed for proving that software is safe, and (3) that successful software safety-assurance practices will have to take into account the detailed design processes employed and show that the software will execute correctly under all possible conditions.

Dunn, William R.↗

Reliability and risk assessment of structures

Development of reliability and risk assessment of structural components and structures is a major activity at Lewis Research Center. It consists of five program elements: (1) probabilistic loads; (2) probabilistic finite element analysis; (3) probabilistic material behavior; (4) assessment of reliability and risk; and (5) probabilistic structural performance evaluation. Recent progress includes: (1) the evaluation of the various uncertainties in terms of cumulative distribution functions for various structural response variables based on known or assumed uncertainties in primitive structural variables; (2) evaluation of the failure probability; (3) reliability and risk-cost assessment; and (4) an outline of an emerging approach for eventual certification of man-rated structures by computational methods. Collectively, the results demonstrate that the structural durability/reliability of man-rated structural components and structures can be effectively evaluated by using formal probabilistic methods.

Chamis, C. C.↗

Formal verification of mathematical software

Methods are investigated for formally specifying and verifying the correctness of mathematical software (software which uses floating point numbers and arithmetic). Previous work in the field was reviewed. A new model of floating point arithmetic called the asymptotic paradigm was developed and formalized. Two different conceptual approaches to program verification, the classical Verification Condition approach and the more recently developed Programming Logic approach, were adapted to use the asymptotic paradigm. These approaches were then used to verify several programs; the programs chosen were simplified versions of actual mathematical software.

Sutherland, D.↗

Exploring the Use of Computer Simulations in Unraveling Research and Development Governance Problems

Understanding Research and Development (R&D) enterprise relationships and processes at a governance level is not a simple task, but valuable decision-making insight and evaluation capabilities can be gained from their exploration through computer simulations. This paper discusses current Modeling and Simulation (M&S) methods, addressing their applicability to R&D enterprise governance. Specifically, the authors analyze advantages and disadvantages of the four methodologies used most often by M&S practitioners: System Dynamics (SO), Discrete Event Simulation (DES), Agent Based Modeling (ABM), and formal Analytic Methods (AM) for modeling systems at the governance level. Moreover, the paper describes nesting models using a multi-method approach. Guidance is provided to those seeking to employ modeling techniques in an R&D enterprise for the purposes of understanding enterprise governance. Further, an example is modeled and explored for potential insight. The paper concludes with recommendations regarding opportunities for concentration of future work in modeling and simulating R&D governance relationships and processes.

Balaban, Mariusz A.↗

MOS 2.0: Modeling the Next Revolutionary Mission Operations System

Designed and implemented in the 1980's, the Advanced Multi-Mission Operations System (AMMOS) was a breakthrough for deep-space NASA missions, enabling significant reductions in the cost and risk of implementing ground systems. By designing a framework for use across multiple missions and adaptability to specific mission needs, AMMOS developers created a set of applications that have operated dozens of deep-space robotic missions over the past 30 years. We seek to leverage advances in technology and practice of architecting and systems engineering, using model-based approaches to update the AMMOS. We therefore revisit fundamental aspects of the AMMOS, resulting in a major update to the Mission Operations System (MOS): MOS 2.0. This update will ensure that the MOS can support an increasing range of mission types, (such as orbiters, landers, rovers, penetrators and balloons), and that the operations systems for deep-space robotic missions can reap the benefits of an iterative multi-mission framework.12 This paper reports on the first phase of this major update. Here we describe the methods and formal semantics used to address MOS 2.0 architecture and some early results. Early benefits of this approach include improved stakeholder input and buy-in, the ability to articulate and focus effort on key, system-wide principles, and efficiency gains obtained by use of well-architected design patterns and the use of models to improve the quality of documentation and decrease the effort required to produce and maintain it. We find that such methods facilitate reasoning, simulation, analysis on the system design in terms of design impacts, generation of products (e.g., project-review and software-delivery products), and use of formal process descriptions to enable goal-based operations. This initial phase yields a forward-looking and principled MOS 2.0 architectural vision, which considers both the mission-specific context and long-term system sustainability.

ground support systems↗

Understanding the Impact of Unobservable Variables on the Performance of Predictive Models: The Need for Feature Space Partitioning and Fusion

When developing predictive models over a dataset, the model is globally optimized across the entire feature space to learn a decision boundary. However, when unobservable variables—which cannot be measured or estimated—interact with the observable variables, this can negatively impact the optimization applied to the decision boundary since the data samples introduced by unobservable variables may have little to no association with the applied global optimization. This, consequently, penalizes the entire decision boundary and model performance. This paper examines some of the detrimental effects of unobservable variables, particularly their role in creating new modes in the distribution of observable variables and reducing the separability of class distributions. Such challenges result in skewed or warped decision boundaries and decreased accuracy of model predictions, particularly for interpretable models like logistic regression and decision trees. Through two illustrative case examples, we highlight the need to address the challenges imposed by unobservable variables. We propose a strategy to mitigate these challenges by creating local regions within the feature space through partitioning. This enables the optimization of local models within the regions to overcome the impact of unobservability in different feature space localities. Research into a more sophisticated partitioning strategy and where the partition should be relative to the sample of interest is left as future work. Through the analysis of the impact of unobservability and the development of a partitioning method, we demonstrate the clear need for a partitioning strategy that integrates knowledge from multiple local models to estimate risk factors using information fusion. Thus, we establish the foundation and motivation for using partitioning and information fusion to overcome the effects of unobservability in predictive models. Formal fusion methods, such as Dempster-Shafer theory, can better leverage the information from local regions to improve the performance of interpretable predictive models in the presence of unobservable variables.

Time Series Data↗