Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “assurance”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Long life assurance study for manned spacecraft long life hardware. Volume 5: Long life assurance test and study recommendations

A study was conducted to establish the guidelines to be applied to the selection of equipment for manned spacecraft systems. Recommendations for expansion of the original study are submitted. The subjects considered are: (1) designing to severe dynamic requirements; (2) analysis of in-space failures due to life limitations; (3) accelerated testing of semiconductors; (4) fan life verification; (5) testing of solid tantalum capacitors; (6) testing of teflon valve seats; and (7) electromigration model verification.

Source record↗

Program Environmental Assurance: Shuttle Environmental Assurance and the Future

Material availability continues to be impacted by domestic and international environmental health and safety (EH&S) regulations, industrial pollution prevention goals and related vendor economics. SEA is an integrated team that works to identify, communicate and address safety and environmentally driven materials obsolescence issues and pollution prevention opportunities.

Glover, Steve E.↗

Formal Assurance Certifiable Tooling Formal Assurance Certifiable Tooling Strategy Final Report

This is the Final Report of a research project to investigate issues and provide guidance for the qualification of formal methods tools under the DO-330 qualification process. It consisted of three major subtasks spread over two years: 1) an assessment of theoretical soundness issues that may affect qualification for three categories of formal methods tools, 2) a case study simulating the DO-330 qualification of two actual tool sets, and 3) an investigation of risk mitigation strategies that might be applied to chains of such formal methods tools in order to increase confidence in their certification of airborne software.

Bush, Eric↗

Workshop on the Role of Design Assurance in System-Wide Safety’s Safety Demonstrator Series

This report summarizes a three-hour hybrid in-person/online workshop on June 7, 2024 on the topic of design assurance and the Safety Demonstrator Series (SDS), which was held at NASA Ames Research Center. The SDS provides an operational demonstration of, and recommendations for, requirements and standards necessary to monitor, assess, and mitigate risks to assure safety in disaster-oriented operations. Over sixty NASA personnel participated in the workshop. Four main topics were discussed: (1) assurance needs for the Safety Demonstrator Series, (2) assurance and the In-Time Aviation Safety Management System (IASMS), (3) in-time assurance: existing efforts and future opportunities, and (4) demonstrating assurance tools in the Safety Demonstrators. Key takeaways are as follows: 1. Design assurance tools can be used to assure an In-Time Aviation Safety Management System, the systems that comprise it, and other systems or missions. Assurance must consider both systems and components and include the interactions between elements in both a systems/aircraft context and a systems-of-systems/airspace context. 2. Design-time assurance activities can support the identification of monitors needed for operational assurance activities (i.e., the “monitor” function in the monitor-assess-mitigate paradigm at the heart of the IASMS concept). 3. A major opportunity for design-time assurance tools to contribute to the IASMS concept is to support rapid re-validation of systems. This will be particularly important for (1) supporting novel operations in the IASMS, where operational data may disprove design-time assumptions (motivating re-analysis of system safety) and (2) adapting technologies (e.g., AI/ML for autonomous operations) to new operational domains, where there may be new or different safety considerations not included in the initial scope of operations. 4. There are several design assurance tools under development in the System-Wide Safety project that can support assurance of Services, Functions, and Capabilities (SFCs) in the Safety Demonstrators. Transitioning these tools from one-off research projects into a functioning part of IASMS assurance will require closer integration between these tools. 5. It is not clear whether the role of design assurance tools is primarily as a part of IASMS architecture or as an external check on IASMS. The workshop consisted of four discussion topics initiated via four lightning talks by System-Wide Safety researchers. Discussions utilized Mural to engage both in-person and online participants in the hybrid format. Polls and surveys were also utilized to gather participant input. The workshop closed with a reflection activity for participants, as well as new ideas for collaboration and coordination of ongoing System-Wide Safety research.

design assurance↗

IV&V Assurance Case Design for Artemis II

As human-rated missions like those in NASA’s Artemis program continue to grow in both size and complexity, and the role of software in achieving mission objectives expands dramatically, NASA’s Independent Verification and Validation (IV&V) Teams face evolving challenges in assuring the safety and performance of the safety- and mission-critical embedded software that is essential to landing astronauts on the surface of the Moon by 2024. Key among these challenges is IV&V’s desire to present a cohesive, integrated assurance statement to its stakeholders that encapsulates and summarizes our assurance positions across the integrated Artemis systems and their combined role in support of a safe and successful flight. In order to meet this challenge, the IV&V Teams have begun a transition to using formal assurance case concepts and documentation in the Goal Structuring Notation (GSN) to build an argument in support of software assurance. IV&V recognizes significant benefits to the logical argumentation structure provided by assurance cases and GSN over our current practices for documenting and managing assurance claims. In order to reap these benefits, IV&V is integrating the use of assurance case concepts with our paradigm of follow-the-risk capability based assurance. Because of this, assurance cases created and used by IV&V are distinct from the sort of assurance case created by a development project or embedded software assurance organization. IV&V’s assurance cases depend much less upon standards and regulations, and more on evidence captured by IV&V regarding the environment, requirements, design, and implementation. IV&V constructs an independent network of claims based on an independent decomposition of arguments. Based upon the risk posture of these claims and their associated software and software artifacts, IV&V then develops and executes engineering analyses and testing, which provide evidence to either support or refute the claim. This emerging risk-informed assurance case methodology is being put into practice as IV&V plans for support of the Artemis II mission, the first flight of the Orion capsule and Space Launch System with astronauts on board.

Gerek Whitman↗

IV&V Assurance Case Design for Artemis II

As human-rated missions like those in NASA's Artemis program continue to grow in both size and complexity, and the role of software in achieving mission objectives expands dramatically, NASA's Independent Verification and Validation (IV&V) Teams face evolving challenges in assuring the safety and performance of the safety- and mission-critical embedded software that is essential to landing astronauts on the surface of the Moon by 2024. Key among these challenges is IV&V's desire to present a cohesive, integrated assurance statement to its stakeholders that encapsulates and summarizes our assurance positions across the integrated Artemis systems and their combined role in support of a safe and successful flight. In order to meet this challenge, the IV&V Teams have begun a transition to using formal assurance case concepts and documentation in the Goal Structuring Notation (GSN) to build an argument in support of software assurance. IV&V recognizes significant benefits to the logical argumentation structure provided by assurance cases and GSN over our current practices for documenting and managing assurance claims. In order to reap these benefits, IV&V is integrating the use of assurance case concepts with our paradigm of follow-the-risk capability based assurance. Because of this, assurance cases created and used by IV&V are distinct from the sort of assurance case created by a development project or embedded software assurance organization. IV&V's assurance cases depend much less upon standards and regulations, and more on evidence captured by IV&V regarding the environment, requirements, design, and implementation. IV&V constructs an independent network of claims based on an independent decomposition of arguments. Based upon the risk posture of these claims and their associated software and software artifacts, IV&V then develops and executes engineering analyses and testing, which provide evidence to either support or refute the claim. This emerging risk-informed assurance case methodology is being put into practice as IV&V plans for support of the Artemis II mission, the first flight of the Orion capsule and Space Launch System with astronauts on board.

Whitman, Gerek↗

Gateway Program Safety and Mission Assurance Integration - the Future of Safe Deep Space Human Exploration

As a foundational element of the National Aeronautics and Space Administration (NASA) Artemis Campaign, the Gateway is an incrementally built cislunar spacecraft that will serve as a platform for deep space human exploration, science, and technology demonstration. The Gateway will be a unifying catalyst for international partners around the world to establish sustained deep space scientific investigations, lunar surface access, and missions to Mars. As human exploration moves farther away from Earth, spacecraft designs must prioritize and optimize mass and volume allocations, while minimizing human and spacecraft risk. To accomplish this objective, the Gateway Program Safety and Mission Assurance functions develop, implement, and ensure compliance with requirements, in concert with the accurate characterization and transparent communication of residual hazard risks, for integrated safety, reliability and maintainability and quality assurance. Safety and Mission Assurance was a key contributor during Gateway program pre-formulation and formulation activities where safety and reliability analysis was embedded in the Gateway Systems Engineering and Integration team. During these early program stages, a preliminary Gateway Integrated Hazard Analysis and Preliminary Gateway Probabilistic Risk Assessment assisted in Gateway architectural and operational definition as part of a risk-informed design process. As the deep space architecture has matured, the integrated Safety and Mission Assurance analyses have matured, new safety review processes have been developed, and requirements have been refined to ensure compliance with integrated safety and mission assurance objectives. The Gateway Program is currently concluding the preliminary design review informed milestone, where the primary objectives included: - Ensured completeness and consistency of the preliminary design, including the meeting of all requirements within appropriate margins and acceptable risk posture. - Identification of any major issues moving forward to the Critical Design phase. At this milestone, Safety and Mission Assurance provided numerous products, including Gateway Top Risks and Risk Mitigation Plans, updated integrated hazard analyses, updated probabilistic risk assessment, Crew Survival Analysis Report, and updated Safety and Mission Assurance Requirements and Plans. These products provide a many-faceted perspective on the inherent risk and available mitigations involved in flying the current proposed vehicle design and anticipated stack configurations. In addition, Safety and Mission Assurance identified top technical, process and workforce concerns to be addressed as the program progresses toward the critical design phase. This paper will detail the evolution of the Gateway Program Safety and Mission Assurance integration functions, provide its current status and lessons learned for future human spaceflight programs. Throughout this paper the key tenets of the Gateway Program Safety and Mission Assurance will be discussed: - Application of a risk-informed approach to identify and mitigate areas of highest risk. - Leverage of valuable processes and lessons learned from earlier spaceflight programs. - Development of Safety and Mission Assurance products to inform design risk trades. - Utilization of common Safety and Mission Assurance practices to identify safety risks for multiple perspectives: top-down, bottom-up, and across lines of integration. - Approval of safety hazards at the appropriate level of authority, keeping most deliberation closest to design expertise and elevating risks of greatest concern for program-level consideration. - Championing of Safety and Mission Assurance processes and forums to foster a pervasive safety culture that is transparent, inclusive, and collaborative between all partners. These tenets have allowed the Gateway Safety and Mission Assurance function to play a key role in optimized vehicle design evolution, and early identification and mitigation of Gateway program and Artemis mission risk.

Helen Vaccaro↗

Flight Dynamics Mission Support and Quality Assurance Process

This paper summarizes the method of the Computer Sciences Corporation Flight Dynamics Operation (FDO) quality assurance approach to support the National Aeronautics and Space Administration Goddard Space Flight Center Flight Dynamics Support Branch. Historically, a strong need has existed for developing systematic quality assurance using methods that account for the unique nature and environment of satellite Flight Dynamics mission support. Over the past few years FDO has developed and implemented proactive quality assurance processes applied to each of the six phases of the Flight Dynamics mission support life cycle: systems and operations concept, system requirements and specifications, software development support, operations planing and training, launch support, and on-orbit mission operations. Rather than performing quality assurance as a final step after work is completed, quality assurance has been built in as work progresses in the form of process assurance. Process assurance activities occur throughout the Flight Dynamics mission support life cycle. The FDO Product Assurance Office developed process checklists for prephase process reviews, mission team orientations, in-progress reviews, and end-of-phase audits. This paper will outline the evolving history of FDO quality assurance approaches, discuss the tailoring of Computer Science Corporations's process assurance cycle procedures, describe some of the quality assurance approaches that have been or are being developed, and present some of the successful results.

Oh, InHwan↗

Technology and Tool Development to Support Safety and Mission Assurance

The Assurance Case approach is being adopted in a number of safety-mission-critical application domains in the U.S., e.g., medical devices, defense aviation, automotive systems, and, lately, civil aviation. This paradigm refocuses traditional, process-based approaches to assurance on demonstrating explicitly stated assurance goals, emphasizing the use of structured rationale, and concrete product-based evidence as the means for providing justified confidence that systems and software are fit for purpose in safely achieving mission objectives. NASA has also been embracing assurance cases through the concepts of Risk Informed Safety Cases (RISCs), as documented in the NASA System Safety Handbook, and Objective Hierarchies (OHs) as put forth by the Agency's Office of Safety and Mission Assurance (OSMA). This talk will give an overview of the work being performed by the SGT team located at NASA Ames Research Center, in developing technologies and tools to engineer and apply assurance cases in customer projects pertaining to aviation safety. We elaborate how our Assurance Case Automation Toolset (AdvoCATE) has not only extended the state-of-the-art in assurance case research, but also demonstrated its practical utility. We have successfully developed safety assurance cases for a number of Unmanned Aircraft Systems (UAS) operations, which underwent, and passed, scrutiny both by the aviation regulator, i.e., the FAA, as well as the applicable NASA boards for airworthiness and flight safety, flight readiness, and mission readiness. We discuss our efforts in expanding AdvoCATE capabilities to support RISCs and OHs under a project recently funded by OSMA under its Software Assurance Research Program. Finally, we speculate on the applicability of our innovations beyond aviation safety to such endeavors as robotic, and human spaceflight.

Mission Assuranc↗

Understanding and Evaluating Assurance Cases

Assurance cases are a method for providing assurance for a system by giving an argument to justify a claim about the system, based on evidence about its design, development, and tested behavior. In comparison with assurance based on guidelines or standards (which essentially specify only the evidence to be produced), the chief novelty in assurance cases is provision of an explicit argument. In principle, this can allow assurance cases to be more finely tuned to the specific circumstances of the system, and more agile than guidelines in adapting to new techniques and applications. The first part of this report (Sections 1-4) provides an introduction to assurance cases. Although this material should be accessible to all those with an interest in these topics, the examples focus on software for airborne systems, traditionally assured using the DO-178C guidelines and its predecessors. A brief survey of some existing assurance cases is provided in Section 5. The second part (Section 6) considers the criteria, methods, and tools that may be used to evaluate whether an assurance case provides sufficient confidence that a particular system or service is fit for its intended use. An assurance case cannot provide unequivocal "proof" for its claim, so much of the discussion focuses on the interpretation of such less-than-definitive arguments, and on methods to counteract confirmation bias and other fallibilities in human reasoning.

Rushby, John↗

Adopting an Objectives-Driven Assurance Case Approach for Achieving Space Flight Mission Planetary Protection Objectives

Traditionally, NASA has utilized prescriptive technical and process requirements to ensure safety and mission assurance performance objectives for space flight missions are achieved. While prescriptive re-quirements may be easier to communicate and manage throughout the systems engineering process, the highly-constrained nature of prescriptive requirements can limit the ability to take advantage of cost-saving opportunities and offer limited ability to explore other options or alternative designs, processes, and methods. It can also be difficult to develop prescriptive requirements for objectives that are prob-abilistic in nature or that cannot be satisfied by direct verification. In contrast, the development of an assurance case allows for a compelling, comprehensible, and valid argument to be developed with support-ing evidence that shows safety and mission assurance objectives have been satisfied. Analogous to how patent applications are constructed for inventions, an assurance case has a high-level claim of meeting a safety and mission assurance objective, followed by a more specific set of sub-claims and technical evidence which supports the claims. The objectives-driven assurance case approach allows for a better understand-ing and exploration of the trade space, more flexibility to balance trades, and the ability to realize and implement technical and process innovations for resource, time, and cost savings. The assurance case is a living case that evolves over the entire program life cycle. Recently, NASA’s Office of Planetary Pro-tection (OPP) has adopted the assurance case approach as an acceptable methodology for demonstrating avoidance of contamination of target solar system bodies explored by NASA space flight missions. This methodology has been incorporated into NASA’s new technical standard for planetary protection and is currently being utilized by the Mars Sample Return campaign for safe sample containment during sample return. This presentation will explore the development and implementation of an assurance case approach in the context of planetary protection, the shift from prescriptive requirements and the ongoing culture change in the technical community, and the support and guidance from NASA’s OPP in adopting the assurance case approach for achieving planetary protection objectives on NASA’s space flight missions.

Elaine Seasly↗

Modernizing NASA’s Space Flight Safety and Mission Success (S&MS) Assurance Framework In Line With Evolving Acquisition Strategies and Systems Engineering Practices

This paper presents the objectives-driven, case-based safety and mission success (S&MS) assurance framework being developed by the NASA Office of Safety and Mission Assurance (OSMA), including its motivations and its implementation via a S&MS Assurance Standard that is under development, supplemented by supporting standards including an S&MS Analysis Management Standard that is also under development. A need to evolve NASA’s S&MS assurance framework has emerged in recent years, resulting from the need to accommodate new acquisition models; the need to accommodate evolving systems engineering (SE) practices; the need to stipulate acceptable levels of S&MS risk; the need for improved integration of S&MS into SE; and the need for clearer risk acceptance accountability. The objectives-driven, case-based S&MS assurance framework proposed here is responsive to that need. Its key features include: • The establishment, by NASA Acquirers, of fundamental S&MS performance objectives that define limits of acceptability for the likelihoods that mission technical objectives will be accomplished and that people, assets, and environments put at risk by the mission will not be adversely affected; • The development and approval of Providers’ S&MS plans for meeting Acquirers’ S&MS performance objectives, including commitments to support Acquirer audit, investigation, and reporting needs; • The development, by Providers, of S&MS assurance cases that argue, supported by evidence, that the Provider has met, or is on track to meeting, the fundamental S&MS objectives; • The evaluation, throughout the program/project life cycle, of Provider S&MS assurance cases as the primary S&MS-related technical basis for Acquirer risk acceptance and the granting to the Provider of authority to proceed through the program/project life cycle. This proposed S&MS assurance framework is notable for its lack of prescription of traditional S&MS requirements and strategies such as defined failure tolerances, margins, or analysis requirements. Instead, Providers are given latitude to propose their own strategies for meeting the fundamental S&MS performance objectives, subject to independent review and Acquirer approval. The result is a framework for S&MS assurance that is at once both rigorous and flexible.

Assurance Case↗

Software assurance standard

This standard specifies the software assurance program for the provider of software. It also delineates the assurance activities for the provider and the assurance data that are to be furnished by the provider to the acquirer. In any software development effort, the provider is the entity or individual that actually designs, develops, and implements the software product, while the acquirer is the entity or individual who specifies the requirements and accepts the resulting products. This standard specifies at a high level an overall software assurance program for software developed for and by NASA. Assurance includes the disciplines of quality assurance, quality engineering, verification and validation, nonconformance reporting and corrective action, safety assurance, and security assurance. The application of these disciplines during a software development life cycle is called software assurance. Subsequent lower-level standards will specify the specific processes within these disciplines.

Source record↗

Tool Use Within NASA Software Quality Assurance

As space mission software systems become larger and more complex, it is increasingly important for the software assurance effort to have the ability to effectively assess both the artifacts produced during software system development and the development process itself. Conceptually, assurance is a straightforward idea - it is the result of activities carried out by an organization independent of the software developers to better inform project management of potential technical and programmatic risks, and thus increase management's confidence in the decisions they ultimately make. In practice, effective assurance for large, complex systems often entails assessing large, complex software artifacts (e.g., requirements specifications, architectural descriptions) as well as substantial amounts of unstructured information (e.g., anomaly reports resulting from testing activities during development). In such an environment, assurance engineers can benefit greatly from appropriate tool support. In order to do so, an assurance organization will need accurate and timely information on the tool support available for various types of assurance activities. In this paper, we investigate the current use of tool support for assurance organizations within NASA, and describe on-going work at JPL for providing assurance organizations with the information about tools they need to use them effectively.

software assurance↗

Guiding Integration of Formal Verification in Assurance Cases

Assurance cases are being increasingly acknowledged as away to build trust in complex systems with autonomous capabilities. An assurance case is a comprehensive, defensible, and valid justification that a system will function as intended for a specific mission and operating environment. Formal verification is often reserved for the most critical components of such systems. However, formal verification tools are often complex, and their usage is subject to many constraints and contextual dependencies. This can raise challenges both for performing the verification as well as reflecting the verification results appropriately in the assurance case, especially for non-expert users of the verification tool. To address these challenges, we present a tool-supported methodology for integrating formal verification results in an assurance case by capturing key verification method information in a rigorously constructed assurance case. In particular, we capture the tool specification in terms of its inputs, outputs, and assurance constraints as assumptions over inputs and guarantees provided over its outputs. The tool specification is parametrized over the inputs and outputs to both guide the intended application of the tool, as well as to check that the tool has been applied following the stated assumptions and that the guarantees hold. We define a generic tool assurance argument pattern that enables integration of the verification results in the assurance case by allowing custom refinement and automated instantiation for each tool use. We demonstrate our methodology on two formal verification tools and their applications to the verification of neural network properties for the aircraft domain.

Assurance Cases↗

Implementing an Objectives-Driven, Risk-Informed, and Case-Assured Approach to Safety and Mission Success at NASA

NASA is developing a “Standard for Assurance of Space Flight Safety and Mission Success” that implements an objectives-driven, risk-informed, and case-assured approach to safety and mission success (S&MS) for NASA space flight programs and projects. The standard aligns with the philosophy of risk leadership that has recently been established in NASA policy to assure acceptable levels of flight crew safety and mission success risk. It is consistent with existing NASA risk management requirements and is compatible with NASA program management and systems engineering requirements. The methodology described in the standard is presented in terms of an S&MS assurance framework that is designed to allow substantial flexibility in the specific means by which programs and projects achieve acceptable mission S&MS risk. Such flexibility is necessary to accommodate the increasingly broad range of acquisition strategies employed by NASA, including commercial transportation services, as well as to accommodate the increasingly rapid evolution of space flight-related technologies and practices. A key feature of the S&MS assurance framework is the specification of S&MS success criteria for each life-cycle review (LCR). The S&MS assurance case is structured around these criteria, the satisfaction of which indicates that the program/project is adhering to the S&MS risk posture. This enables the evolving S&MS assurance case to be used as a fundamental program/project submittal at each LCR, where its inherent structure of argument, supported by evidence, directly supports the evaluation of the program/project with respect to the S&MS success criteria, and by extension, the S&MS risk posture. As such, the S&MS assurance case is integral to program/project systems engineering, risk management, and S&MS oversight activities, and provides the principal basis for S&MS risk acceptance by the Decision Authority throughout the program/project life cycle.

Risk Posture↗

Adopting an Objectives-Driven Assurance Case Approach for Achieving Space Flight Mission Planetary Protection Objectives

Traditionally, the National Aeronautics and Space Administration (NASA) has utilized prescriptive technical and process requirements to ensure safety and mission assurance performance objectives for planetary protection are achieved during space flight missions. While prescriptive requirements may be easier to communicate and manage throughout the systems engineering process, the highly constrained nature of prescriptive requirements can limit the ability to take advantage of cost-saving opportunities and offer limited ability to explore other options or alternative designs, processes, and methods. It can also be difficult to develop prescriptive requirements for objectives that are probabilistic in nature or that cannot be satisfied by direct verification. In contrast, the development of an assurance case allows for a compelling, comprehensible, and valid argument to be developed with supporting evidence that shows safety and mission assurance objectives have been satisfied. Analogous to how patent applications are constructed for inventions, an assurance case has a high-level claim of meeting a safety and mission assurance objective, followed by a more specific set of sub-claims and technical evidence which supports the claims. The objectives-driven assurance case approach allows for a better understanding and exploration of the trade space, more flexibility to balance trades, and the ability to realize and implement technical and process innovations for resource, time, and cost savings. The assurance case is a living case that evolves over the entire program life cycle. Recently, NASA’s Office of Planetary Protection (OPP) has adopted the assurance case approach as an acceptable methodology for demonstrating avoidance of contamination of target solar system bodies explored by NASA space flight missions. This methodology has been incorporated into NASA’s new technical standard for planetary protection and is currently being utilized by the Mars Sample Return campaign for safe sample containment during sample return.

Assurance Case↗