Engineering PapersSearch

SEARCH · Engineering Papers

Results for “Software trust”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

The Orion GN and C Data-Driven Flight Software Architecture for Automated Sequencing and Fault Recovery

The Orion Crew Exploration Vehicle (CET) is being designed to include significantly more automation capability than either the Space Shuttle or the International Space Station (ISS). In particular, the vehicle flight software has requirements to accommodate increasingly automated missions throughout all phases of flight. A data-driven flight software architecture will provide an evolvable automation capability to sequence through Guidance, Navigation & Control (GN&C) flight software modes and configurations while maintaining the required flexibility and human control over the automation. This flexibility is a key aspect needed to address the maturation of operational concepts, to permit ground and crew operators to gain trust in the system and mitigate unpredictability in human spaceflight. To allow for mission flexibility and reconfrgurability, a data driven approach is being taken to load the mission event plan as well cis the flight software artifacts associated with the GN&C subsystem. A database of GN&C level sequencing data is presented which manages and tracks the mission specific and algorithm parameters to provide a capability to schedule GN&C events within mission segments. The flight software data schema for performing automated mission sequencing is presented with a concept of operations for interactions with ground and onboard crew members. A prototype architecture for fault identification, isolation and recovery interactions with the automation software is presented and discussed as a forward work item.

King, Ellis

A Verification Framework for Runtime Assurance of Autonomous UAS

Runtime Assurance (RTA) is a design-time architecture for safety-critical systems where an internal monitor acts upon detecting a violation of a property. The simplex architecture is an instance of RTA, where the action taken is to hand control of the overall system to a trusted controller when an untrusted one violates a safety property. Simplex RTA is emerging as a method for allowing AI/ML and other unverified software to be integrated into safety-critical applications like aircraft. To this end, the American Society for Testing and Materials (ASTM) and NASA have each published guidelines on the use of RTA in such systems. In the simplex RTA framework, a system has an advanced controller (AC) and a reversionary controller (RC). The system is allowed to operate with the AC until a runtime monitor detects that some property has been violated and then the RC takes over. Assuming that the sample rate of the monitor will detect improper functioning with enough time for the RC to correct the impending problem, and that the RC is trusted, the system will operate as intended. This use of the simplex RTA framework can allow for the integration of untrusted, but possibly more performant, controllers in a safe way. This paper presents a formalization of a simplex RTA framework in the Prototype Verification System (PVS) theorem prover using an embedding of differential dynamic logic (DDL) called Plaidypvs. A novel feature of this framework is that it can be instantiated at different levels of abstraction. This feature allows for the formal verification of a system with an untrusted black box component, such as an AI/ML controller. This paper does not address the many difficulties in deploying RTA in an industrial-level system. Instead, the focus is on the formal verification of the simplex RTA framework in the language of hybrid programs. Hybrid programs are programs that include both discrete and continuous dynamics and can be used to model complex cyber-physical systems. Plaidypvs is a tool that enables formalization of hybrid programs in the PVS theorem prover. Plaidypvs enables the verification of the general simplex RTA framework and then, by specializing some components of the hybrid program, verifying instances of the framework while treating the untrusted component as a black box. A selection of Unmanned Aircraft Systems (UAS) operations are shown as instances of the general RTA framework in PVS. This offers the benefit of design time verification of relevant safety properties to the system, and it also gives requirements on the sample rate of sensors that determine the time interval in which the ‘switch’ property of the RTA framework is checked.

PVS

Yet Another NLA Library: T-LAPACK

In recent years, Randomized numerical linear algebra (RandNLA) proved to be more than a theoretical novelty: projects like RandLAPACK demonstrate its practical value across architectures, and projects like RandBLAS build trust in randomization as a tool for high-performance NLA. This BoF considers two main questions. First, what are the pressing issues in software standards and implementation that need to be resolved for RandNLA to become a core component of HPC? Second, how can we mobilize a community effort to make progress on these issues? The BoF will engage the audience to discuss the idea of growing the role of RandNLA in high-performance computing and what it would take to scale from niche prototypes to robust, production-quality software libraries.

97 MATHEMATICS AND COMPUTING

Bootstrapping Multi-Agent Unmanned Aerial Vehicle (UAV) System Integration Using Ground-Based Assets: Lessons Learned

The highly dynamic nature of UAVs imposes significant challenges when conducting initial testing ranging from safety risks posed by high-capacity lithium batteries and spinning propellers to rigorous timing demands on controllers and the consequences of failures mid-air. Flight testing of a single vehicle is time and labor intensive due to these challenges and more, and the complexity increases exponentially with the number of vehicles. While simulations and hardware-in-the-loop bench testing can provide adequate environments for preliminary validation, differences in system deployment architecture, software interfaces, and hardware infrastructure between simulation and a fleet of real UAVs create a sizable gap that must be navigated carefully during system integration. In support of the Autonomy Teaming and TRAjectories for Complex Trusted Operational Reliability (ATTRACTOR) project, which had the goal of establishing a basis of certification of trust and trustworthiness in multi-agent autonomous systems, this gap was tackled from two directions. First, a novel mixed-reality simulation environment was engineered to blur the transition from simulation to flight hardware. Second, a fleet of Unmanned Surface Vehicles (USVs) was developed as a test and evaluation platform that more closely represented the final aerial fleet while eliminating many of the risks associated with air vehicles. This paper delves into the second element, analyzing the efficacy of the USV platform in performing system integration testing for the UAV system. In this paper we present the USV fleet and its role in reducing the aforementioned gaps in deployment architecture, software interfaces, and hardware infrastructure when moving from simulation to flight. An overview of the hardware and software onboard the vehicles will be provided along with supporting infrastructure. The system integration process will be documented including results in supporting both the overarching design reference mission (DRM) of ATTRACTOR and individual research efforts conducted during the project. Finally, we will discuss some of the practical lessons learned regarding the testing, deployment, and operation of multi-agent autonomous systems.

Matthew P Vaughan

Holodeck: Telepresence Dome Visualization System Simulations

This paper explores the simulation and consideration of different image-projection strategies for the Holodeck, a dome that will be used for highly immersive telepresence operations in future endeavors of the National Aeronautics and Space Administration (NASA). Its visualization system will include a full 360 degree projection onto the dome's interior walls in order to display video streams from both simulations and recorded video. Because humans innately trust their vision to precisely report their surroundings, the Holodeck's visualization system is crucial to its realism. This system will be rigged with an integrated hardware and software infrastructure-namely, a system of projectors that will relay with a Graphics Processing Unit (GPU) and computer to both project images onto the dome and correct warping in those projections in real-time. Using both Computer-Aided Design (CAD) and ray-tracing software, virtual models of various dome/projector geometries were created and simulated via tracking and analysis of virtual light sources, leading to the selection of two possible configurations for installation. Research into image warping and the generation of dome-ready video content was also conducted, including generation of fisheye images, distortion correction, and the generation of a reliable content-generation pipeline.

Hite, Nicolas

Code Coverage Status of the ARC Code DIF3D

The Argonne Reactor Code (ARC) software system supports users in their fast reactor design goals by providing neutronic, thermal-hydraulic, and structural analysis capabilities. DIF3D plays a pivotal role in the ARC system as the primary homogenized assembly neutronic calculation methodology for fast reactor problems. Over its 40 years history, ARC software usage with DIF3D has been applied to numerous fast and thermal spectrum reactor analysis projects with good to excellent comparison against experiments. With continued improvement of computation resources, many of the geometry modeling capabilities in DIF3D that were primarily used in low order schemes are not really needed anymore. Today, the diffusion and transport capabilities of DIF3D-VARIANT are primarily used in the reactor design process with some scattered usage of DIF3D-FD and DIF3D-Nodal. In recent work, the DIF3D software verification was completed for DIF3D-FD and DIF3D-VARIANT on the geometry options used in the Versatile Test Reactor project. While we can be confident that these capabilities of DIF3D are well used and thus trusted, it does not demonstrate that all possible input options of DIF3D are actually working, but just those that were tested as part of VTR are and that they are correct. Thus, the purpose of the present work is to identify a set of test problems for DIF3D and assess the code coverage of DIF3D for those test problems. The goal is to document what parts of the existing DIF3D code are touched by the set of test problems and which are not. Because the verification work done on DIF3D-VARIANT and DIF3D-FD was focused on the most common uses of DIF3D for fast reactor analysis, the code coverage assessment of those capabilities is the highest priority. This will ensure that nothing is being missed by the existing verification test problems that DIF3D relies upon. The DIF3D-Nodal capability will also be inspected for code coverage as part of this work to further ensure that regular regression testing of DIF3D will trap any likely errors the end user might experience with the DIF3D software. The code coverage analysis of DIF3D was performed with the Code Coverage Tool of the Intel Fortran compiler which requires modifications to the compilation of DIF3D. The detailed coverage tables are given for each submodule of DIF3D separately, and for the submodules which are primarily developed for DIF3D, most of the source files could be at least partially touched. Most of the uncovered parts/files could be easily ignored, because they are either for error message and debugging output or obviously not needed by DIF3D. Out of the entire source codes of DIF3D, only a few uncovered modules deserve further investigation.

22 GENERAL STUDIES OF NUCLEAR REACTORS

Data Assimilation Enhancements to Air Force Weather’s Land Information System

The United States Air Force (USAF) has a proud and storied tradition of enabling significant advancements in the area of characterizing and modeling land state information. 557th Weather Wing (557 WW; DoD’s Executive Agent for Land Information) provides routine geospatial intelligence information to warfighters, planners, and decision makers at all echelons and services of the U.S. military, government and intelligence community. 557 WW and its predecessors have been home to the DoD’s only operational regional and global land data analysis systems since January 1958. As a trusted partner since 2005, Air Force Weather (AFW) has relied on the Hydrological Sciences Laboratory at NASA/GSFC to lead the interagency scientific collaboration known as the Land Information System (LIS). LIS is an advanced software framework for high performance land surface modeling and data assimilation of geospatial intelligence (GEOINT) information.

Wegiel, Jerry

Braxton Marlatt Intern Poster

The Internet of Things (IoT) encompasses a vast network of interconnected devices embedded with software, sensors, and network connectivity, enabling data collection and exchange. While IoT technology revolutionizes various industries, it also introduces significant security challenges. This research focuses on enhancing IoT security through the implementation of Zero Trust Architecture concepts, specifically targeting the Network and Device pillars of the Cybersecurity and Infrastructure Security Agency’s Zero Trust Maturity Model. By generating Codified Attack Surfaces (CAS) using custom Structured Threat Information eXpression bundles, this project aims to provide enhanced visibility into network communications, detect vulnerabilities in device firmware, and improve the overall security posture for IoT devices and networks. The methodology involves defining custom STIX schema and objects, collecting data from intra-IoT traffic, external network traffic, and firmware analysis, and automating the conversion and correlation of this data into STIX bundles. The automated generation of attack surfaces offers comprehensive insights into activity, vulnerabilities, and anomalies within an IoT environment, enabling proactive threat identification and mitigation.

24 - POWER TRANSMISSION AND DISTRIBUTION

Developing a Vision for Heliophysics Infrastructure: The LIKED Resource and the DIARieS Ecosystem

Heliophysics data and computational infrastracture are not equipped for 21st science, suffering from holes in the know-how to build better systems. Without a clear vision, efforts to improve the infrastructure have been incremental and incoherent. This poster presents both the vision and the technology required: an online LIbrary KnowledgE and Discovery (LIKED) resource for discovering and implementing knowledge, data, and infrastructure resources; and an online analysis ecosystem to simplify Discovery, Implementation, Analysis, Reproducibility, and Sharing (DIARieS) of scientific results and environments. The LIKED and DIARieS solutions adopt FAIR data principles and the best practices from the budding field of open science. The proposed new infrastructure components will close many of the current gaps in heliophysics’ infrastructure, such as the ability to search for data and knowledge by phenomenon across domains, and to find software and examples relevant to the desired data set (including model data). Further, these components will enable community members to more efficiently use the resources already present and improve upon the content via a community-curated and trusted library. Combining these solutions lowers the barriers to heliophysics resources for all, increasing the return on our investments. Finally, the structure behind these ideas are topic-agnostic, so they are fully extensible to other fields, leading to invaluable connections to other disciplines. Just as with the development and construction of a long-term satellite mission, we must work together as a community to build a vision of the infrastructure that will most benefit the community, and then collaborate to construct, assemble, and test all the necessary pieces individually and as a unit. Our purpose in presenting this work is to not only describe the proposed vision, but also to gather feedback from the community on this topic.

infrastructure

The MCNP ® 6 code: A decade of progress

After several years of effort involved in merging the Los Alamos National Laboratory MCNP5 and MCNPX codes, in 2013 the first production release of version 6 of the Monte Carlo N-Particle ® , or MCNP ® , code MCNP6.1 was distributed publicly. Since then, three significant releases have been issued: MCNP6.1.1beta in 2014, MCNP6.2 in 2018, and MCNP6.3 in 2023. While each release always contains new features, code enhancements, and bug fixes, each version has had a different primary focus, ranging from improved calculational efficiency to new powerful utilities and tools, to software modernization of the code base. With all that has been learned over the first decade of the MCNP6 code, continuous progress is being made toward a modernized, general-purpose Monte Carlo radiation transport code that remains a trusted resource for the global community of practitioners. This paper describes these first 10+ years of the MCNP6 code and its continually improving data libraries, and gives some insight into how the next decade is expected to unfold.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS

Service-Oriented Architecture for NVO and TeraGrid Computing

The National Virtual Observatory (NVO) Extensible Secure Scalable Service Infrastructure (NESSSI) is a Web service architecture and software framework that enables Web-based astronomical data publishing and processing on grid computers such as the National Science Foundation's TeraGrid. Characteristics of this architecture include the following: (1) Services are created, managed, and upgraded by their developers, who are trusted users of computing platforms on which the services are deployed. (2) Service jobs can be initiated by means of Java or Python client programs run on a command line or with Web portals. (3) Access is granted within a graduated security scheme in which the size of a job that can be initiated depends on the level of authentication of the user.

Jacob, Joseph

Addressing Human Error in International Space Station Flight Control Teams: Advances in Ground Training for Science Operators

In flight control, as with any human in the loop system, operator error is an inevitable reality. On the International Space Station (ISS) where crew time and physical resources are precious and often irreplaceable, operator errors can result in significant, irreversible consequences. Flight controllers at the Payload Operations Integration Center (POIC) located at NASA’s Marshall Space Flight Center (MSFC) in Huntsville, Alabama know this reality well. At the POIC, operator errors can be caused by a variety of factors, from poor hardware or software design to environmental factors such as time pressure or fatigue. The most difficult errors to address, however, are those which result from ineffective teamwork.Academic research in teamwork has resulted in the identification of many factors which make cross-functional teaming difficult, including leadership, trust building, and communication challenges. These factors, especially when combined with the challenging environmental factors flight control teams must contend with daily, make the goal of minimizing operator errors in payload operations challenging to achieve. To address such teamwork errors, trainers at the POIC have drawn best practices from high reliability industries such as commercial aviation, healthcare, and nuclear power plants, as well as from our sister ISS control center in Houston, Texas, to develop and institute a new training program focused specifically on teamwork skills.This training program, called the Team Skills Curriculum, is based on the concept of Crew Resource Management (CRM) which was developed by NASA in the 1970s for the commercial aviation industry in response to a series of aviation disasters resulting from ineffective teamwork. CRM was later tailored by the Johnson Space Center (JSC) for use in astronaut and flight control training. The result, called Space Flight Resource Management (SFRM) was formally introduced into manned spaceflight training in the late 90s. SFRM has evolved over the years, but the focus has remained on helping operators develop the skills needed to work as part of an effective team. Using these concepts as well as the latest research in cross-functional teaming and data on specific errors occurring at the POIC, trainers in the integrated flight control training branch created a custom training program for both new and certified payload operations specialists.

Harris, Samantha S.

Prognostics As-A-Service (PaaS)

Deep awareness of aircraft system health-state is critical for maintaining safe, efficient growth in global operations and enabling autonomy. Maintainers, operators, controllers, dispatchers, pilots, and autonomous systems must have reliable real-time predictions of vehicle health to preserve safety and efficiency. We will explore the feasibility and challenges of cloud enhanced prognostics. Aircraft request PaaS in flight to supplement onboard systems or provide complete health awareness. We will explore and demonstrate the ability to address six major challenges of PaaS: Generality, Environmental Complexity, Utility, Trust, Communications, and Security. We will also explore the factors in the decision to host prognostics onboard vs As-A-Service.

Prognostics As A Service

Testing First-Order Logic Axioms in AutoCert

AutoCert [2] is a formal verification tool for machine generated code in safety critical domains, such as aerospace control code generated from MathWorks Real-Time Workshop. AutoCert uses Automated Theorem Provers (ATPs) [5] based on First-Order Logic (FOL) to formally verify safety and functional correctness properties of the code. These ATPs try to build proofs based on user provided domain-specific axioms, which can be arbitrary First-Order Formulas (FOFs). These axioms are the most crucial part of the trusted base, since proofs can be submitted to a proof checker removing the need to trust the prover and AutoCert itself plays the part of checking the code generator. However, formulating axioms correctly (i.e. precisely as the user had really intended) is non-trivial in practice. The challenge of axiomatization arise from several dimensions. First, the domain knowledge has its own complexity. AutoCert has been used to verify mathematical requirements on navigation software that carries out various geometric coordinate transformations involving matrices and quaternions. Axiomatic theories for such constructs are complex enough that mistakes are not uncommon. Second, adjusting axioms for ATPs can add even more complexity. The axioms frequently need to be modified in order to have them in a form suitable for use with ATPs. Such modifications tend to obscure the axioms further. Thirdly, speculating validity of the axioms from the output of existing ATPs is very hard since theorem provers typically do not give any examples or counterexamples.

Ahn, Ki Yung

Demonstration of Rapid Development Through Containerization: OSE-SAT

Modern advancements in spacecraft technology have enabled engineers to develop radically smaller and lighter spacecraft, which has drastically reduced the cost of putting spacecraft into space. Despite these advancements and the shrinking cost to get spacecraft into space, space exploration is still prohibitively expensive. So much so that many space missions prefer to err on the side of caution than take on additional risk by trying newer, unproven technologies. This risk-averse mission design, while very reasonable from a program management point of view, significantly impacts engineers’ ability to solve newer, more complicated problems and limits scientists’ ability to develop more complex experiments that rely on newer technology. Often these new technologies remain stuck at lower technology readiness levels for many years due to the space community's reluctance to take on the additional risks of proving out unproven technology. The Distributed Spacecraft Autonomy (DSA) team at NASA Ames Research Center is developing a containerized solution to enable the rapid development of newer space technologies and accelerate their adoption into space missions. The Opportunistic Software Experiments for Spacecraft Autonomy Testbeds (OSE-SAT) is an on-orbit test bed that aims to reduce the amount of risk associated with newer, unproven space technologies by containerizing each experiment in its own isolated environment and providing a safe, robust, and controlled interface to access spacecraft host resources that is monitored in real time by thoroughly tested Trusted Container developed by DSA. This paper will describe DSA’s implementation of OSE-SAT and discuss the benefits, as well as challenges, of on-orbit containerization.

Aaron J Woodard

A prototype autonomous agent for crew and equipment retrieval in space

The ground-based demonstration of Extra Vehicular Activity (EVA) Retriever, a voice-supervised, intelligent, free-flying robot, is designed to evaluate the capability to retrieve objects (astronauts, equipment, and tools) which have accidentally separated from the Space Station. The EVA Retriever software is required to autonomously plan and execute a target rendezvous, grapple, and return to base while avoiding stationary and moving obstacles. The software architecture incorporates a hierarchical decomposition of the control system that is horizontally partitioned into five major functional subsystems: perception, world model, reasoning, sensing, and acting. The design provides for supervised autonomy as the primary mode of operation with teleoperation as the backup mode. It is intended to be an evolutionary system improving in capability over time and as it earns crew trust through reliable operation.

Erickson, J. D.

TrustDER: Trusted, Private and Scalable Coordination of Distributed Energy Resources

In this project, the Stanford and SLAC Teams have developed a Trusted, Private and Scalable platform for coordinating Coordination of Distributed Energy Resources (TrustDER). This is a layered system that ensures private, trusted and scalable coordination and monitoring of DERs. It accommodates a variety of resources, such as solar generation, gensets and loads, with a particular focus on battery systems-based resources, as they are a transformational technology experiencing fast growth in adoption by large critical facilities. The platform can be used as standalone or added to existing aggregation systems to enable trust, privacy and resilience. TrustDER consists of layers that address each of the shortcomings of the existing state of the art. Each layer in the platform can operate independently but provides information to the layers above it to enable a novel form of overall coordination architecture. The project consists of several tasks, with each task dedicated to the design of each layer. Task 2 Resource Virtualization defined a software abstraction layer for distributed energy resources (DERs). The goal of this abstraction was to simplify the implementation of algorithms utilizing cooperation of DERs resources in a variety of use cases. Task 3 is on Secure ID for Asset Authentication. Identity Management Systems (IDMS) are a foundational infrastructure for interactions between entities (organizations, users, devices, and services). Secure ID is blockchain-based a distributed identity management system allowing (1) identity provisioning, (2) authentication, (3) authorization, and (4) identity data sharing for IoT-enabled assets on the electricity grid. In this project, the SLAC team focused on designing and testing Keymaker, a protocol for authenticating device identity managed by Secure ID. Task 5 Private and Safe Integration is focused on the design and evaluation of a DER cooperation scheme which allows for the aggregation of DERs without impacting network reliability. The approach is designed based on realistic assumptions regarding data availability, communication infrastructure limitations, and privacy. Task 6 Scalable Distributed Privacy for Information explored how virtualized batteries could be managed privately. Specifically, it examined the case in which a principal provides a partitioned battery to multiple clients. Task 7 Use Cases was to ensure that this technology was applied in relevant situations and scenarios. Primarily, this means that virtualization needed to be employed in a manner that either improved flexibility, bolstered security or privacy, or decreased costs.

25 ENERGY STORAGE

Multi-Rigor Agile Verification and Rapid Prototyping for Formally Verified Software

We propose a novel approach to developing formally verified systems through Multi-rigor Agile Verification. Multi-rigor Agile Verification is rooted in the hypothesis of Rigor Independence, that a system’s specification and verification architecture depend primarily on the system requirements to be verified, and they depend very little on the rigor level of the methods used to verify those requirements. Due to its iterative nature, Multi-rigor Agile Verification promises to mitigate many of the high upfront design costs experienced by formally verified systems and to deliver a better-architected, and thus better-trusted, system in the end. We then discuss the tooling needed to perform Multi-rigor Agile Verification and go in depth to build one of those tools, which directly generates executable prototype code from declarative formal specifications using the Maude rewrite-logic framework.

97 MATHEMATICS AND COMPUTING