Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Software Reliability Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 325 records · Page 18

Space Shuttle RTOS Bayesian Network

With shrinking budgets and the requirements to increase reliability and operational life of the existing orbiter fleet, NASA has proposed various upgrades for the Space Shuttle that are consistent with national space policy. The cockpit avionics upgrade (CAU), a high priority item, has been selected as the next major upgrade. The primary functions of cockpit avionics include flight control, guidance and navigation, communication, and orbiter landing support. Secondary functions include the provision of operational services for non-avionics systems such as data handling for the payloads and caution and warning alerts to the crew. Recently, a process to selection the optimal commercial-off-the-shelf (COTS) real-time operating system (RTOS) for the CAU was conducted by United Space Alliance (USA) Corporation, which is a joint venture between Boeing and Lockheed Martin, the prime contractor for space shuttle operations. In order to independently assess the RTOS selection, NASA has used the Bayesian network-based scoring methodology described in this paper. Our two-stage methodology addresses the issue of RTOS acceptability by incorporating functional, performance and non-functional software measures related to reliability, interoperability, certifiability, efficiency, correctness, business, legal, product history, cost and life cycle. The first stage of the methodology involves obtaining scores for the various measures using a Bayesian network. The Bayesian network incorporates the causal relationships between the various and often competing measures of interest while also assisting the inherently complex decision analysis process with its ability to reason under uncertainty. The structure and selection of prior probabilities for the network is extracted from experts in the field of real-time operating systems. Scores for the various measures are computed using Bayesian probability. In the second stage, multi-criteria trade-off analyses are performed between the scores. Using a prioritization of measures from the decision-maker, trade-offs between the scores are used to rank order the available set of RTOS candidates.

Morris, A. Terry↗

Holodeck: Telepresence Dome Visualization System Simulations

This paper explores the simulation and consideration of different image-projection strategies for the Holodeck, a dome that will be used for highly immersive telepresence operations in future endeavors of the National Aeronautics and Space Administration (NASA). Its visualization system will include a full 360 degree projection onto the dome's interior walls in order to display video streams from both simulations and recorded video. Because humans innately trust their vision to precisely report their surroundings, the Holodeck's visualization system is crucial to its realism. This system will be rigged with an integrated hardware and software infrastructure-namely, a system of projectors that will relay with a Graphics Processing Unit (GPU) and computer to both project images onto the dome and correct warping in those projections in real-time. Using both Computer-Aided Design (CAD) and ray-tracing software, virtual models of various dome/projector geometries were created and simulated via tracking and analysis of virtual light sources, leading to the selection of two possible configurations for installation. Research into image warping and the generation of dome-ready video content was also conducted, including generation of fisheye images, distortion correction, and the generation of a reliable content-generation pipeline.

Hite, Nicolas↗

Assessing Engine Hot Fire Data for Human Spaceflight Applications

Development and certification of liquid engine systems for human spaceflight missions requires exhaustive analysis to meet the NASA’s requirements for engine health, reliability, and performance. The techniques used to assess requirement conformance and test-to-test engine health pose many unique challenges including the unusually large scale of data, complex component and system analysis, and rigorous engineering judgement standards. To address these challenges, NASA Marshall Space Flight Center’s Engine Systems branch has developed and maintained a robust software suite and operational processes that satisfy programmatic requirements levied on engines and the 7 Elements of Flight Rationale. Analysis at a systems level includes subsystem assessment of components such as turbomachinery and combustion devices as well as structural and fluid dynamics and transient and steady-state assessment at a systems level. Some of the most important tools to accomplish this analysis are automated script databases, creation of historical and statistical comparisons, and parameters calculated at the full data rate. These tools greatly simplify the crucial processes of anomaly investigation, limit monitoring, health assessment, and timely communication of key conclusions drawn from hot fire testing and flight data analysis.

Data Assessment↗

Assessing Engine Hot Fire Data for Human Spaceflight Applications

Development and certification of liquid engine systems for human spaceflight missions requires exhaustive analysis to meet the NASA’s requirements for engine health, reliability, and performance. The techniques used to assess requirement conformance and test-to-test engine health pose many unique challenges including the unusually large scale of data, complex component and system analysis, and rigorous engineering judgement standards. To address these challenges, NASA Marshall Space Flight Center’s Engine Systems branch has developed and maintained a robust software suite and operational processes that satisfy programmatic requirements levied on engines and the 7 Elements of Flight Rationale. Analysis at a systems level includes subsystem assessment of components such as turbomachinery and combustion devices as well as structural and fluid dynamics and transient and steady-state assessment at a systems level. Some of the most important tools to accomplish this analysis are automated script databases, creation of historical and statistical comparisons, and parameters calculated at the full data rate. These tools greatly simplify the crucial processes of anomaly investigation, limit monitoring, health assessment, and timely communication of key conclusions drawn from hot fire testing and flight data analysis.

Data Assessment↗

Big Software for SmallSats: Adapting CFS to CubeSat Missions

Expanding capabilities and mission objectives for SmallSats and CubeSats is driving the need for reliable, reusable, and robust flight software. While missions are becoming more complicated and the scientific goals more ambitious, the level of acceptable risk has decreased. Design challenges are further compounded by budget and schedule constraints that have not kept pace. NASA's Core Flight Software System (cFS) is an open source solution which enables teams to build flagship satellite level flight software within a CubeSat schedule and budget. NASA originally developed cFS to reduce mission and schedule risk for flagship satellite missions by increasing code reuse and reliability. The Lunar Reconnaissance Orbiter, which launched in 2009, was the first of a growing list of Class B rated missions to use cFS. Large parts of cFS are now open source, which has spurred adoption outside of NASA. This paper reports on the experiences of two teams using cFS for current CubeSat missions. The performance overheads of cFS are quantified, and the reusability of code between missions is discussed. The analysis shows that cFS is well suited to use on CubeSats and demonstrates the portability and modularity of cFS code.

Open Source↗

Coupled Electro-Thermal Analysis of Permanent Magnet Synchronous Motor for Electric Vehicles

Permanent magnet synchronous motors (PMSM) are extensively used in electric vehicles. However, high internal heat generation and inefficient heat dissipation often limit the operational reliability, and longevity of the PMSM. Therefore, proper quantification of heat generation in electric motor and advanced embedded motor cooling techniques remain topics of immense interest. In order to accurately predict electro-magnetic performance, i.e., efficiency, component-wise heat losses and the corresponding temperature distribution of a jacket cooled machine, this paper presents a two-way iteratively coupled electro-thermal modeling framework. Finite element based software Motor-CAD has been utilized for electro-magnetic performance calculation of BMW i3 PMSM. Finite volume based computational fluid dynamics/heat transfer (CFD/HT) software ANSYS® FLUENT® has been employed to simulate the temperature distribution of the PMSM, using the electro-magnetic losses as heat input. Computed heat losses, stator, winding, rotor, and magnet temperatures are utilized as coupling parameters between the electro-magnetic and thermal models. A conventional one-way coupling algorithm has also been developed and compared to the newly proposed two-way coupling algorithm. Numerical results confirm that at high current density, one-way coupling algorithm significantly over-predicts the motor temperature compared to the two-way algorithm. A comprehensive analysis has been carried out to characterize the influences of current density, speed, and forced convection heat transfer coefficient on the heat losses, overall efficiency, and maximum temperature of the PMSM. Lastly, an efficiency map has been interpreted from the coupled electro-magnetic simulation.

42 ENGINEERING↗

Off-line data analysis and data reduction from digitally controlled random test systems.

This paper discusses the merits of employing the new computer-controlled random environment control systems for fast and efficient large-scale data analysis when they are not being used for test control. Hardware and software requirements are stated. Several of the more familiar frequency functions are defined from the Fourier coefficients, the main product of the Fourier processors used in these control systems. Another function, the probability density function, is defined and suggestions for its application are made. An analysis example is presented. Some programming tips are listed, and the accuracy and reliability of frequency analysis measurements are considered.

Chapman, C. P.↗

Development of software fault-tolerance techniques

As computers become more widely used, and in particular as they become used in more safety critical applications, the reliability of the computer system and its software becomes more important. There is also an increasing need for high levels of reliability in applications involving very large numbers of inexpensive units where recall of the units would be disproportionately expensive. The nature of faults and the assumptions made by different approaches to correct operation are considered. The recovery block approach is described and a probabilistic analysis of its effectiveness, with and without correlated design errors is provided. Mechanisms for generating acceptance tests from specifications, and for providing recovery in the presence of asynchrony, are described. An analysis of, and design for, the provision of recovery blocks in the microprogram of the Bendix BDX930 processor is provided. An example of the use of recovery blocks in a simple operating system is also provided.

Melliar-Smith, P. M.↗

Automated Test Environment for a Real-Time Control System

An automated environment with hardware-in-the-loop has been developed by Rocketdyne Huntsville for test of a real-time control system. The target system of application is the man-rated real-time system which controls the Space Shuttle Main Engines (SSME). The primary use of the environment is software verification and validation, but it is also useful for evaluation and analysis of SSME avionics hardware and mathematical engine models. It provides a test bed for the integration of software and hardware. The principles and skills upon which it operates may be applied to other target systems, such as those requiring hardware-in-the-loop simulation and control system development. Potential applications are in problem domains demanding highly reliable software systems requiring testing to formal requirements and verifying successful transition to/from off-nominal system states.

Hall, Ronald O.↗

Human-Rated Space Vehicle Backup Flight Systems

Human rated space vehicles have historically employed a Backup Flight System (BFS) for the main purpose of mitigating the loss of the primary avionics control system. Throughout these projects, however, the underlying philosophy and technical implementation vary greatly. This paper attempts to coalesce each of the past space vehicle program's BFS design and implementation methodologies with the accompanying underlining philosophical arguments that drove each program to such decisions. The focus will be aimed at Mercury, Gemini, Apollo, and Space Shuttle However, the ideologies and implementation of several commercial and military aircraft are incorporated as well to complete the full breadth view of BFS development across the varying industries. In particular to the non-space based vehicles is the notion of deciding not to utilize a BFS. A diverse analysis of BFS to primary system benefits in terms of reliability against all aspects of project development are reviewed and traded. The risk of engaging the BFS during critical stages of flight (e.g. ascent and entry), the level of capability of the BFS (subset capability of main system vs. equivalent system), and the notion of dissimilar hardware and software design are all discussed. Finally, considerations for employing a BFS on future human-rated space missions are reviewed in light of modern avionics architectures and mission scenarios implicit in exploration beyond low Earth orbit.

Davis, Jeffrey A.↗

Advanced Measurements for Resilient Integration of Inverter-Based Resources: PROGRESS MATRIX Final Report

As nearly every aspect of the electric power grid undergoes rapid change, measurement technologies that support grid operation and planning must evolve as well. The rapid large-scale deployment of inverter-based resources (IBRs) vital to achieving the nation’s clean energy goals has in some cases led to negative impacts on the reliability and security of the bulk power system (BPS). Advanced power system measurements, including synchronized phasor and waveform measurements, are key to making IBR integration secure and reliable. To this end, the Department of Energy (DOE) initiated the PROGRESS MATRIX project to develop advanced measurement capabilities and analytics that will accelerate adoption of IBRs while improving the reliability and resilience of the BPS. This report discusses the outcomes of the project, which was a joint effort between the Pacific Northwest National Laboratory (PNNL), Oak Ridge National Laboratory (ORNL), the National Renewable Energy Laboratory (NREL), and Lawrence Berkeley National Laboratory (LBNL). In the project’s first year, PNNL, NREL, and ORNL partnered with the Bonneville Power Administration (BPA), the Western Area Power Administration (WAPA), and Kauai Island Utility Cooperative (KIUC) to understand their existing measurement capabilities and the gaps limiting deployment of IBR-focused measurement systems and analytics. The other primary activity in the first year was deployment of GridSweep instruments, which provide unprecedented precision in waveform measurement while probing distribution systems. The instruments were deployed at Dominion Energy and the University of California, Riverside. In the project’s second year, the input from partner utilities and collected measurements were used to advance measurement capabilities. Twelve analytical methods spanning disturbance analysis, power plant evaluation, feeder evaluation, and modeling were developed. Two software tools were developed, one to analyze GridSweep measurements and another to automatically evaluate the control performance of power plants connected to the BPS. Testbeds at ORNL and NREL were augmented to better enable studies of IBR integration. The project culminated in demonstrations of these analytical methods, software tools, and testbeds, both in the field and in the laboratory. This report discusses these various accomplishments and documents the significant progress in developing advanced measurement capabilities to support the secure, reliable, and accelerated adoption of IBRs in the BPS.

24 POWER TRANSMISSION AND DISTRIBUTION↗

DER Digital Supply Chain Gap Analysis

Solar photovoltaic (PV) cybersecurity is a growing field of research. As deployments of solar PV have increased, cyber risk has also increased. Utility solar PV installations, however, are not required to comply with the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) plan unless they meet a minimum generation threshold of 75 MW. Individual residential-scale solar PV deployments will not meet that generation threshold and are therefore excluded from the NERC CIP requirements. With most solar installations less than 75 MW, solar PV has been deployed with minimal oversight and highly variable cybersecurity maturity. The resources that comprise the digital supply chain can include software, code, data, and other digital components. But as clean energy technologies advance, cybersecurity threats and vulnerabilities continue to evolve and grow in sophistication. Supply chain cybersecurity represents a critical area for ensuring safe operations as the U.S. moves toward a clean energy future.

cybersecurity↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

Trade Studies of Space Launch Architectures using Modular Probabilistic Risk Analysis

A top-down risk assessment in the early phases of space exploration architecture development can provide understanding and intuition of the potential risks associated with new designs and technologies. In this approach, risk analysts draw from their past experience and the heritage of similar existing systems as a source for reliability data. This top-down approach captures the complex interactions of the risk driving parts of the integrated system without requiring detailed knowledge of the parts themselves, which is often unavailable in the early design stages. Traditional probabilistic risk analysis (PRA) technologies, however, suffer several drawbacks that limit their timely application to complex technology development programs. The most restrictive of these is a dependence on static planning scenarios, expressed through fault and event trees. Fault trees incorporating comprehensive mission scenarios are routinely constructed for complex space systems, and several commercial software products are available for evaluating fault statistics. These static representations cannot capture the dynamic behavior of system failures without substantial modification of the initial tree. Consequently, the development of dynamic models using fault tree analysis has been an active area of research in recent years. This paper discusses the implementation and demonstration of dynamic, modular scenario modeling for integration of subsystem fault evaluation modules using the Space Architecture Failure Evaluation (SAFE) tool. SAFE is a C++ code that was originally developed to support NASA s Space Launch Initiative. It provides a flexible framework for system architecture definition and trade studies. SAFE supports extensible modeling of dynamic, time-dependent risk drivers of the system and functions at the level of fidelity for which design and failure data exists. The approach is scalable, allowing inclusion of additional information as detailed data becomes available. The tool performs a Monte Carlo analysis to provide statistical estimates. Example results of an architecture system reliability study are summarized for an exploration system concept using heritage data from liquid-fueled expendable Saturn V/Apollo launch vehicles.

Mathias, Donovan L.↗

Analytical redundancy management mechanization and flight data analysis for the F-8 digital fly-by-wire aircraft flight control sensors

The details are presented of an onboard digital computer algorithm designed to reliably detect and isolate the first failure in a duplex set of flight control sensors aboard the NASA F-8 digital fly-by-wire aircraft. The algorithm's successful flight test program is summarized, and specific examples are presented of algorithm behavior in response to software-induced signal faults, both with and without aircraft parameter modeling errors.

Deckert, J. C.↗

Advanced techniques in reliability model representation and solution

The current tendency of flight control system designs is towards increased integration of applications and increased distribution of computational elements. The reliability analysis of such systems is difficult because subsystem interactions are increasingly interdependent. Researchers at NASA Langley Research Center have been working for several years to extend the capability of Markov modeling techniques to address these problems. This effort has been focused in the areas of increased model abstraction and increased computational capability. The reliability model generator (RMG) is a software tool that uses as input a graphical object-oriented block diagram of the system. RMG uses a failure-effects algorithm to produce the reliability model from the graphical description. The ASSURE software tool is a parallel processing program that uses the semi-Markov unreliability range evaluator (SURE) solution technique and the abstract semi-Markov specification interface to the SURE tool (ASSIST) modeling language. A failure modes-effects simulation is used by ASSURE. These tools were used to analyze a significant portion of a complex flight control system. The successful combination of the power of graphical representation, automated model generation, and parallel computation leads to the conclusion that distributed fault-tolerant system architectures can now be analyzed.

Palumbo, Daniel L.↗

Assessing Hot Fire Data with WinPlot

Development and certification of liquid engine systems for human spaceflight missions requires exhaustive analysis to meet the NASA’s requirements for engine health, reliability, and performance. The techniques used to assess requirement conformance and test-to-test engine health and performance pose many unique challenges including the unusually large scale of data, complex component and system analysis, and rigorous engineering judgement standards. To address these challenges, NASA Marshall Space Flight Center’s Engine Systems branch has developed and maintained a robust software suite and operational processes that satisfy programmatic requirements levied on engines and the 7 Elements of Flight Rationale. Analysis at a systems level includes subsystem assessment of components such as turbomachinery and combustion devices as well as structural and fluid dynamics and transient and steady-state assessment at a systems level. Some of the most important tools to accomplish this analysis are automated script databases, creation of historical and statistical comparisons, and parameters calculated at the full data rate. These tools greatly simplify the crucial processes of anomaly investigation, limit monitoring, health assessment, and timely communication of key conclusions drawn from hot fire testing and flight data analysis.

J. Davis Hunter↗

Closed-Loop Evaluation of an Integrated Failure Identification and Fault Tolerant Control System for a Transport Aircraft

Formal robustness analysis of aircraft control upset prevention and recovery systems could play an important role in their validation and ultimate certification. Such systems developed for failure detection, identification, and reconfiguration, as well as upset recovery, need to be evaluated over broad regions of the flight envelope or under extreme flight conditions, and should include various sources of uncertainty. To apply formal robustness analysis, formulation of linear fractional transformation (LFT) models of complex parameter-dependent systems is required, which represent system uncertainty due to parameter uncertainty and actuator faults. This paper describes a detailed LFT model formulation procedure from the nonlinear model of a transport aircraft by using a preliminary LFT modeling software tool developed at the NASA Langley Research Center, which utilizes a matrix-based computational approach. The closed-loop system is evaluated over the entire flight envelope based on the generated LFT model which can cover nonlinear dynamics. The robustness analysis results of the closed-loop fault tolerant control system of a transport aircraft are presented. A reliable flight envelope (safe flight regime) is also calculated from the robust performance analysis results, over which the closed-loop system can achieve the desired performance of command tracking and failure detection.

Shin, Jong-Yeob↗