Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “assurance case”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Theorems in Service of Sound Composition, Rapid Modeling and Scalable Analysis

This project extends the state of the art in formal verification modeling with modules and automatically checkable data-sharing patterns such that component modules can retain their assurance case when composed within a larger system. For users, smaller models make reasoning easier and help to ensure they accurately reflect text specifications. For automated methods, smaller models give exponential benefits for verification algorithm execution time.

97 MATHEMATICS AND COMPUTING↗

Simulation and analysis of support hardware for multiple instruction rollback

Recently, a compiler-assisted approach to multiple instruction retry was developed. In this scheme, a read buffer of size 2N, where N represents the maximum instruction rollback distance, is used to resolve one type of data hazard. This hardware support helps to reduce code growth, compilation time, and some of the performance impacts associated with hazard resolution. The 2N read buffer size requirement of the compiler-assisted approach is worst case, assuring data redundancy for all data required but also providing some unnecessary redundancy. By adding extra bits in the operand field for source 1 and source 2 it becomes possible to design the read buffer to save only those values required, thus reducing the read buffer size requirement. This study measures the effect on performance of a DECstation 3100 running 10 application programs using 6 read buffer configurations at varying read buffer sizes.

Alewine, Neil J.↗

Proceedings of the Third International Workshop on Proof-Carrying Code and Software Certification

This NASA conference publication contains the proceedings of the Third International Workshop on Proof-Carrying Code and Software Certification, held as part of LICS in Los Angeles, CA, USA, on August 15, 2009. Software certification demonstrates the reliability, safety, or security of software systems in such a way that it can be checked by an independent authority with minimal trust in the techniques and tools used in the certification process itself. It can build on existing validation and verification (V&V) techniques but introduces the notion of explicit software certificates, Vvilich contain all the information necessary for an independent assessment of the demonstrated properties. One such example is proof-carrying code (PCC) which is an important and distinctive approach to enhancing trust in programs. It provides a practical framework for independent assurance of program behavior; especially where source code is not available, or the code author and user are unknown to each other. The workshop wiII address theoretical foundations of logic-based software certification as well as practical examples and work on alternative application domains. Here "certificate" is construed broadly, to include not just mathematical derivations and proofs but also safety and assurance cases, or any fonnal evidence that supports the semantic analysis of programs: that is, evidence about an intrinsic property of code and its behaviour that can be independently checked by any user, intermediary, or third party. These guarantees mean that software certificates raise trust in the code itself, distinct from and complementary to any existing trust in the creator of the code, the process used to produce it, or its distributor. In addition to the contributed talks, the workshop featured two invited talks, by Kelly Hayhurst and Andrew Appel. The PCC 2009 website can be found at http://ti.arc.nasa.gov /event/pcc 091.

Ewen, Denney, W.↗

Certification Strategies using Run-Time Safety Assurance for Part 23 Autopilot Systems

Part 23 aircraft operation, and in particular general aviation, is relatively unsafe when compared to other common forms of vehicle travel. Currently, there exists technologies that could increase safety statistics for these aircraft; however, the high burden and cost of performing the requisite safety critical certification processes for these systems limits their proliferation. For this reason, many entities, including the Federal Aviation Administration, NASA, and the US Air Force, are considering new options for certification for technologies that will improve aircraft safety. Of particular interest, are low cost autopilot systems for general aviation aircraft, as these systems have the potential to positively and significantly affect safety statistics. This paper proposes new systems and techniques, leveraging run-time verification, for the assurance of general aviation autopilot systems, which would be used to supplement the current certification process and provide a viable path for near-term low-cost implementation. In addition, discussions on preliminary experimentation and building the assurance case for a system, based on these principles, is provided.

automatic collision avoidance↗

Off-Nominal Planning for the Cryogenic Vacuum Test of the JWST Optical Telescope Element/Integrated Science Instrument Module at JSC

The cryogenic thermal vacuum/thermal balance test of the James Webb Space Telescope (JWST) combined Optical Telescope Element (OTE)/Integrated Science Instrument Module (ISIM), known as the OTIS, at the Johnson Space Center (JSC) Chamber A in 2017 was likely the most complex test ever performed by NASA for an unmanned mission. The test of the combined flight Optical Telescope and ISIM elements was prefaced by years of modifications to chamber facilities, and included three extensive precursor tests of non-flight and flight hardware to establish safe and optimal test operational procedures. One critical part of the test preparation was planning for off-nominal events that could arise, including appropriate responses. In some cases, assurance of personnel and payload safety required modification of original test hardware and procedures which had to be validated before the final test could begin. This planning proved especially prescient for the OTIS test, as Hurricane Harvey struck the Houston area during the test in August 2017, and consequences for the precious payload could have been severe. This paper describes the extent of the thermal off-nominal planning undertaken for the OTIS test, including including safing for hurricanes, and some real-life effects of Hurricane Harvey on the test conduct. Documentation of the consequences and mitigations for these events are discussed. The importance of off-nominal planning for future thermal vacuum/thermal balance tests is illustrated.

Off-Nominal Planning↗

The Friendly Argument Notation (FAN)

This document defines and explains through examples the Friendly Argument Notation (FAN). FAN builds on previous work investigating text-based ways to express arguments [2, 3]. Its primary intended use is for creating and evaluating arguments about safety-critical systems, especially the types of arguments common within safety and assurance cases [4], but nothing in its design constrains its use to that domain. Compared to existing notations commonly used within this domain (for example [6]), FAN corresponds more closely to traditional argument concepts (for example [1]), allows greater flexibility in expression, provides for including counter-arguments, and requires less knowledge of computer-science-specific concepts. Only time and use will determine how beneficial these differences are in practice. This paper concentrates on showing how FAN looks to someone who is using it manually to develop or assess arguments. A later document will concentrate on providing the information necessary for software tools to be created for FAN.

arugment↗

Software assurance of autonomous spacecraft control

The work described addresses assurance of a planning and execution software system being added to an in-orbit CubeSat to demonstrate autonomous control of that spacecraft. Our focus was on how to develop assurance of the correct operation of the added software in its operational context, our approach to which was to use an assurance case to guide and organize the information involved.

Bocchino, Robert↗

Evolution of NASA’s Nuclear Flight Safety Program to Meet Changing Needs

Over the past 4 years, the United States (U.S.) Government has issued several new National policies that fundamentally change the approach to nuclear flight safety for aerospace applications, including the complete revision of the Federal policy for handling launch of spacecraft containing space nuclear systems. In response, the National Aeronautics and Space Administration (NASA) is updating its nuclear flight safety program while still maintaining consistency with other Federal policies, international conventions, and NASA’s own policies. To achieve this evolution, NASA is factoring in an objectives-driven and assurance case mindset to develop a risk-informed and performance-based program. NASA and others have successfully applied this mindset in other disciplines and contexts and it is being pursued here via broad cooperation within NASA and with external stakeholders. This paper will briefly describe how the NASA nuclear flight safety program is evolving to meet these changing needs.

NASA↗

The Friendly Argument Notation (FAN): 2023 Version

This document constitutes the official description of the current iteration of the Friendly Argument Notation (FAN). This new version provides several enhancements to the original 2020 instantiation, while maintaining essential compatibility with it. Specifically, the new version enables distinguishing between deductive and non-deductive arguments, removes the requirement for always providing an explicit statement of reasoning, and relaxes the rules for when labels may be used. The primary intended use of FAN is unchanged: creating and evaluating arguments about safety-critical systems, specifically the types of arguments common within safety and assurance cases.

language↗

Unlocking the Spacecraft and Human Habitat Microbiome to Enable the Next Generation of Space Exploration

Planetary protection is the discipline that prevents harmful contamination of the solar system during exploration activities. The current international guidelines and NASA policy addressing biological contamination on spacecraft surfaces contains prescriptive guidelines of spore requirements (e.g., 300 spores/m2, 5×105 spores per spacecraft) applicable to spacecraft bound for Mars. To verify these requirements spacecraft engineers sample spacecraft surfaces throughout the assembly, test and launch operations phase of the mission using damp water cotton swabs and polyester wipes. After sampling, the potential biological contamination is enumerated using a series of traditional microbiology techniques to include sonication, heat shocking at 80°C for 15min to select for spores, and growth on tryptic soy agar at 32°C for 72 hours. To enable crewed missions to Mars and robotic exploration of the Ocean Worlds a risk informed decision making / performance-based approach to assess biological contamination offers a promising solution in the trade space. Recognizing the need for a performance-based approach, NASA’s new Planetary Protection policies now incorporate the agility for missions to be able to leverage a performance or prescriptive approach. One of top contenders in the option space is a coupled quantitative, descriptive and functional based approach to be able to assess the quantity, types and capabilities of the biological contamination present on spacecraft surfaces. A tailored, mission by mission assurance case could then be formulated by building an argument around the target body, projected capabilities surrounding the types of organisms their potential for survival and proliferation, and ability to be transported on the target body to contaminate an area of biological interest. A performance-based requirement would then be used to demonstrate the mission’s compliance in protecting the planetary environment safety objectives. This symposium talk will showcase the background and need case for NASA to develop such a capability as well as provide an update on the efforts underway in developing a transparent and responsible performance-based approach to biological contamination assessments on spacecraft surfaces.

Habitat Microbiome↗

Robotic and Crewed Mars Missions Increasing the Demand for Planetary Protection Technology Needs

Planetary protection (PP) policy seeks to avoid harmful contamination by limiting biological and relevant organic contamination from spacecraft as well as preventing adverse changes to Earth’s biosphere when extraterrestial samples are brought back to Earth. The PP policy at NASA was updated in 2021 (NPR 8715.24) and 2022 (NASA-STD-8719.27) to enable missions by expanding the decades old prescriptive requirements to allow for an option of adopting performance-based requirements that are objectivesdriven, risk-informed and case-assured. In parallel, the final PP knowledge gap workshop was completed representing the international consensus on the key areas to be considered in developing crew PP policy. These knowledge gaps focused on key technology development areas in 1) microbial and human health monitoring, 2) technical and operations needed for contamination control and 3) natural transport of contamination on Mars. As robotic missions start to implement performance-based approaches and research and technology efforts commence to inform crew policy the demand for data quality driven verification and validation in relevant space environments. Examples of the types of testing that is envisioned includes test as you fly validation and verification of decontamination systems in a relevant on-orbit and Mars environment, developing lethality curves of terrestrial organisms to further our understanding of the biocidal impacts of Mars and the space environment, and particle transport model validation and verification. Thus, the PP discipline has identified the need for groundbased space environments to perform preliminary testing as validation and verification of flight systems and to advance the technology readiness level prior to further testing on-orbit or lunar environments to prepare for Mars.

J. Nick Benardini↗

Robotic and Crewed Mars Missions Increasing the Demand for Planetary Protection Technology Needs

Planetary protection (PP) policy seeks to avoid harmful contamination by limiting biological and relevant organic contamination from spacecraft as well as preventing adverse changes to Earth’s biosphere when extraterrestrial samples are brought back to Earth. The PP policy at NASA was updated in 2021 (NPR 8715.24) and 2022 (NASA-STD-8719.27) to enable missions by expanding the decades old prescriptive requirements to allow for an option of adopting performance-based requirements that are objectives-driven, risk-informed and case-assured. In parallel, the final PP knowledge gap workshop was completed representing the international consensus on the key areas to be considered in developing crew PP policy. These knowledge gaps focused on key technology development areas in 1) microbial and human health monitoring, 2) technical and operations needed for contamination control and 3) natural transport of contamination on Mars. As robotic missions start to implement performance-based approaches and research and technology efforts commence to inform crew policy the demand for data quality driven verification and validation in relevant space environments. Examples of the types of testing that is envisioned includes test as you fly validation and verification of decontamination systems in a relevant on-orbit and Mars environment, developing lethality curves of terrestrial organisms to further our understanding of the biocidal impacts of Mars and the space environment, and particle transport model validation and verification. Thus, the PP discipline has identified the need for ground-based space environments to perform preliminary testing as validation and verification of flight systems and to advance the technology readiness level prior to further testing on-orbit or lunar environments to prepare for Mars.

J Nick Benardini↗

Evolution of NASA’s Nuclear Flight Safety Program to Infuse Risk Leadership and Assurance Framework Concepts

In recent years, the United States (U.S.) Government has issued several new National policies that fundamentally change the approach to nuclear flight safety for aerospace applications, including the complete revision of the Federal policy for handling launch of spacecraft containing space nuclear systems. In response, the National Aeronautics and Space Administration (NASA) is updating its nuclear flight safety program while still maintaining consistency with other Federal policies, international conventions, and NASA’s own policies. To achieve this evolution, NASA is factoring in an objectives-driven and assurance case mindset to develop a risk-informed and performance-based program. NASA and others have successfully applied this mindset in other disciplines and contexts and it is being pursued here via broad cooperation within NASA and with external stakeholders. This paper will briefly describe how the NASA nuclear flight safety program is evolving to meet these changing needs.

Matthew J. Forsbacka↗

Towards a Formal Basis for Modular Safety Cases

Safety assurance using argument-based safety cases is an accepted best-practice in many safety-critical sectors. Goal Structuring Notation (GSN), which is widely used for presenting safety arguments graphically, provides a notion of modular arguments to support the goal of incremental certification. Despite the efforts at standardization, GSN remains an informal notation whereas the GSN standard contains appreciable ambiguity especially concerning modular extensions. This, in turn, presents challenges when developing tools and methods to intelligently manipulate modular GSN arguments. This paper develops the elements of a theory of modular safety cases, leveraging our previous work on formalizing GSN arguments. Using example argument structures we highlight some ambiguities arising through the existing guidance, present the intuition underlying the theory, clarify syntax, and address modular arguments, contracts, well-formedness and well-scopedness of modules. Based on this theory, we have a preliminary implementation of modular arguments in our toolset, AdvoCATE.

Safety↗

Overarching Properties as Means of Compliance: An Industrial Case Study

The Overarching Properties (OPs) have been created by an inter-national working group and are being evaluated by the National Aeronautics and Space Administration (NASA), the Federal Aviation Administration (FAA), industry, and other certifying agencies in an effort to streamline certification processes. Their intent is to facilitate the use of alternative approaches and to al-low flexibility to combine the system, software, and complex hardware certification. The hope is that the FAA may eventually establish an Advisory Circular that offers the OPs as a Means of Compliance (MoC) for software approval (and eventually systems and hardware) by showing the product possesses the three OPs: Intent (specification of the intended behavior), Correctness (implementation of the intended behavior) and Innocuity (safety of unintended behavior). In the certification community, there is still a concern about the practicability of using such high level properties in certification. This paper aims to address that concern by showing possession of the OPs in an industrial case study using assurance arguments. The two main contributions of this paper are: a certification process based on OPs as Means of Compliance, and a certification argument for an on-board physical model of an UAV, as industrial example. We pro-pose a hybrid approach for the certification process that combines OPs with existing certification standards. Thus, OPs can be used for parts of a system that uses technologies that are not supported by current standards or for which existing standards require additional effort without commensurate additional safety assurance.

certification↗

Dynamic Safety Cases for Through-Life Safety Assurance

We describe dynamic safety cases, a novel operationalization of the concept of through-life safety assurance, whose goal is to enable proactive safety management. Using an example from the aviation systems domain, we motivate our approach, its underlying principles, and a lifecycle. We then identify the key elements required to move towards a formalization of the associated framework.

Dynamic Safety Case↗